Form

Draft Schedule I – Insurance Marketplace Provider Return (2019)

Bermuda Monetary Authority (BMA) · Bermuda

Draft

Current version last checked: 2026-07-07

Summary

This is a draft form (Schedule I) circulated by the Bermuda Monetary Authority as part of a consultation on a proposed annual return for Insurance Marketplace Providers. It sets out the information and questionnaires that such providers would be required to complete covering corporate structure, cyber risk management, AML/ATF compliance, corporate governance and sanctions screening. As a draft, it is not yet in force and reflects proposed rather than confirmed reporting requirements.

  • Section A - Organisational information: Directors, managers, officers and key staff details, organisational structure, outsourced services and affiliate relationships, professional indemnity/D&O/E&O insurance details, confirmation of meeting minimum registration criteria, client and platform activity data, and conflicts of interest policy confirmation.
  • Cyber Risk Management: Detailed business summary and NIST-aligned control questionnaire covering geographic/user data, data storage, internet-facing services, IT risk roles, cyber risk governance, identify/protect/detect/respond/recover controls, and technical security controls (antivirus, DLP, vulnerability scanning, IDS/IPS, DDoS defences).
  • AML-ATF Questionnaire: Required in full only for providers that are AML/ATF Regulated Financial Institutions under the Proceeds of Crime Act 1997, covering client numbers and risk ratings, products/services, delivery channels, UBO and PEP geography, GoAML registration and SAR filings, staff training, AML/ATF controls, and company data.
  • Corporate Governance (Sections I and J): Required for all insurance marketplace providers regardless of AML/ATF status, covering board/senior management roles, oversight of internal controls, risk management, employee integrity, knowledge and compliance, and Compliance Officer functions.
  • Sanctions Questionnaire: Applicable to all insurance marketplace providers, requiring confirmation of client and employee sanctions screening and disclosure of any frozen assets under Bermuda's sanctions regime, including designated person and asset value details.

Because this is a draft schedule published for consultation, it does not itself create binding filing deadlines or finalized obligations; it indicates the scope and level of detail the Authority is proposing to require from insurance marketplace providers in a future annual return.

Key obligations

  • If adopted, insurance marketplace providers would need to complete Section A covering director, officer and staff details, outsourcing arrangements, insurance policies, and confirmation of compliance with minimum registration criteria
  • If adopted, providers would need to complete a detailed cyber risk management questionnaire covering governance, technical controls, and incident history
  • AML/ATF Regulated Financial Institutions among insurance marketplace providers would need to complete the full AML-ATF questionnaire including client risk rating, GoAML registration, SAR filing history, and training records
  • All insurance marketplace providers would need to complete the Corporate Governance sections (I and J) regardless of AML/ATF regulated status
  • All insurance marketplace providers would need to complete the Sanctions Questionnaire, confirming client/employee screening and disclosing any frozen assets

Applies to

insurance marketplace providers

Topics

Version history

2026-07-07

source file (current)