Statement of Guidance
Operational Resilience and Outsourcing - Guidance Notes
Status not confirmedView on BMA's website Source document
Summary
This Guidance Note explains how the Bermuda Monetary Authority expects Relevant Entities to implement its Operational Resilience and Outsourcing Code. It sets out the practical approach to operational resilience (Op Res) and to outsourcing risk management, distinguishing Op Res from traditional Business Continuity Planning and IT Disaster Recovery, and should be read alongside the Code itself.
- Identify important business services: Entities must identify client-facing services whose disruption could cause significant harm to clients or pose contagion risk to Bermuda's financial stability.
- Map resources: Document the people, processes, technology, facilities and information (the five 'resources' or 'enablers') underpinning each important business service.
- Set impact tolerances: Establish thresholds for maximum tolerable disruption, expressed principally via Maximum Tolerable Period of Disruption (MTPD).
- Communication plans: Develop internal and external communication plans for use when important business services are disrupted.
- Testing and remediation: Test resilience against severe but plausible disruption scenarios, including vendors and their resources, and remediate to stay within impact tolerances.
- Lessons learned and self-assessment: Conduct lessons-learned exercises after disruptions/tests and produce an annual self-assessment (and any required statutory returns) documenting the Op Res lifecycle.
- Board governance: The board must approve, at least annually, the documentation for identifying important business services, resource mapping, impact tolerances and testing (including communication plan testing), and must approve the self-assessment and any statutory return before submission.
- Outsourcing due diligence and materiality: Entities must assess and formalise criteria for what constitutes outsourcing and material outsourcing, perform risk evaluations before entering outsourcing arrangements, and conduct due diligence on service providers (staff competence, technology/cybersecurity, financial capacity, authorisations).
- Outsourcing agreements and oversight: Maintain written outsourcing agreements covering rights, responsibilities, performance levels and KPIs, exercise heightened oversight and contingency planning where reintegration of an outsourced function is not feasible, and pay particular attention to concentration risk from multiple activities outsourced to one provider.
Proportionality applies: entities without important business services meeting the harm/contagion criteria need not perform full Op Res reviews, but all Relevant Entities remain subject to the outsourcing and third-party oversight provisions regardless of size.
Key obligations
- Boards must approve, on an annual basis, the documentation generated for identifying important business services, mapping resources, setting impact tolerances and testing (including communication plan testing)
- Boards must approve the self-assessment and any statutory return required by the BMA prior to submission
- Entities must identify important business services that, if disrupted, could cause harm to clients or the wider Bermuda financial sector
- Entities must document (map) the people, processes, technology, facilities and information supporting each important business service
- Entities must set impact tolerances (including MTPD) for each important business service
- Entities must develop internal and external communication plans for disruptions to important business services
- Entities must test their ability to remain within impact tolerances against severe but plausible disruption scenarios, including vendors and their resources, and must test communication plans
- Entities must remediate to stay within impact tolerances and conduct lessons-learned exercises following disruptions or tests
- Entities must create an annual self-assessment document and make it available to the BMA upon request, describing actions and timelines for services outside impact tolerance
- Entities must formalise and clearly articulate the criteria used to determine outsourcing materiality in policy and procedures
- Entities must conduct a risk evaluation, including rationale for outsourcing decisions and risk mitigation, prior to entering an outsourcing arrangement
- Entities must conduct due diligence on outsourcing service providers covering staff competence, technology/cybersecurity, operational infrastructure and financial capacity
- Entities must maintain written, legally enforceable outsourcing agreements setting out terms, responsibilities, performance levels and KPIs
- Entities must implement contingency plans (including alternative providers or reintegration plans) where an outsourced function cannot feasibly be brought back in-house
- All entities, even those without qualifying important business services, must comply with outsourcing and third-party oversight requirements
Applies to
Corporate Service Providers, Trust Businesses, Money Service Businesses, Investment Businesses, Fund Administration Provider Businesses, Banks and Deposit Companies, Digital Asset Businesses, Commercial Insurers, IIGB and IILT Insurers, Insurance Managers, Insurance Brokers, Insurance Marketplace Providers and Agents
Deadlines
- annually: The board must approve, on an annual basis, the documentation for identifying important business services, mapping resources, setting impact tolerances and testing
- annually: Self-assessment and review of services, disruption scenarios must be updated year over year (nil if no qualifying important business services)