Statement of Guidance
Operational Resilience and Outsourcing Guidance Notes (September 2025, Tracked Changes)
Status not confirmedView on BMA's website Source document
Summary
This is a Bermuda Monetary Authority guidance note, issued in a tracked-changes format, that accompanies and explains the Operational Resilience and Outsourcing Code. It sets out how regulated entities should identify important client-facing business services, map the resources that support them, set impact tolerances, build communication plans, test resilience against severe but plausible disruption scenarios, and record lessons learned and self-assessments.
- Applies to: Corporate service providers, trust businesses, money service businesses, investment businesses, fund administration provider businesses, banks and deposit companies, digital asset businesses, commercial insurers, IIGB and IILT insurers, insurance managers, insurance brokers, insurance marketplace providers and agents.
- Operational resilience lifecycle: Identify important business services, map underlying people/process/technology/facilities/information resources, set impact tolerances, develop communication plans, test against severe but plausible disruption scenarios, remediate and capture lessons learned, and produce a self-assessment or statutory return.
- Outsourcing: Guidance on distinguishing outsourcing from 'purchased services', assessing materiality of outsourced activities, conducting risk evaluation before outsourcing, performing due diligence on service providers, and managing concentration and sub-outsourcing risk.
- Board role: The board is accountable for operational resilience, must have adequate oversight arrangements, and must review and approve documentation for each lifecycle element annually, plus approve self-assessments and statutory returns before submission.
Even entities that determine they have no 'important business service' remain obliged to comply with the Code's outsourcing and third-party oversight requirements. The guidance also clarifies terminology (e.g., material outsourcing, important critical activity, outsourcing agreement) used throughout the Code.
Key obligations
- The board must review and approve, on an annual basis, documentation covering identification of important business services, mapping of resources, setting of impact tolerances, and testing (including communication plan testing).
- The board must review and approve the self-assessment and any statutory return required by the BMA prior to submission.
- Relevant Entities must make their self-assessment available to the Authority upon request.
- Where important business services fall outside impact tolerance thresholds, the self-assessment must describe planned remediation actions and completion timelines.
- Relevant Entities must conduct a risk evaluation process before entering an outsourcing arrangement, articulating the rationale and mitigation of risks.
- Relevant Entities must perform due diligence on prospective outsourcing service providers, including assessing staffing, skills, authorisations, technology and cybersecurity arrangements.
- Materiality/criticality metrics used to assess outsourced activities must be formalised and clearly articulated in the RE's policy and procedures.
- Where an outsourced function cannot feasibly be transferred back in-house, the RE must exercise greater oversight and implement contingency plans, including alternative providers or reintegration.
- Entities relying on non-outsourced but material outsourcing determinations must be able to justify why full Code provisions are not applied.
Applies to
corporate service providers, trust businesses, money service businesses, investment businesses, fund administration provider businesses, banks and deposit companies, digital asset businesses, commercial insurers, IIGB and IILT insurers, insurance managers, insurance brokers, insurance marketplace providers and agents
Deadlines
- annual basis: Board must review and approve documentation for each element of the operational resilience lifecycle, and approve the self-assessment/statutory return, annually.