Statement of Guidance
The Management of Operational Risk (May 2007)
In forceView on BMA's website Source document
Summary
This is Bermuda Monetary Authority guidance, issued under the Banks and Deposit Companies Act 1999, setting out the Authority's expectations for how licensed banks and deposit companies must manage operational risk. It defines operational risk, sets out the framework institutions must establish, and describes the Authority's supervisory approach, including expected reporting.
- Operational risk framework: Each institution must develop and document a policy and procedures for identifying, assessing, monitoring and controlling/mitigating operational risk, scaled to the size and complexity of its business.
- Board and senior management oversight: The Board must set strategy, approve and periodically review the operational risk policy, and ensure effective independent internal audit; senior management must implement the framework and ensure staff training/awareness.
- Responsibility for implementation: Institutions should generally designate a Head of Operational Risk (or equivalent) responsible for strategy, policies, assessment methodology and reporting systems.
- Independent control review: The operational risk framework must be subject to periodic independent review (e.g. internal audit) covering business units, the Head of Operational Risk's activities, and loss data accuracy.
- Loss event data collection: Institutions must track all material operational loss events, generally using a $10,000 materiality threshold, using the event-type/business-line mapping in the Appendices.
- Monitoring and reporting: Each institution must prepare a regular (normally quarterly) operational risk report for the Board and senior management, to be shared with the Authority upon request.
- Authority oversight: The Authority reviews institutions' business resumption/contingency plans, IT policies, and outsourcing arrangements as part of its ongoing supervision of operational risk management.
Appendices to the guidance provide detailed loss event type categories, business line mappings, a sample operational risk report, and additional guidance on identifying, assessing, monitoring and controlling operational losses.
Key obligations
- Institutions must develop, document and maintain an operational risk framework (policy and procedures) commensurate with the scale and complexity of their business.
- The Board of directors must set strategy for operational risk, approve and periodically review the operational risk policy, and ensure effective independent internal audit of the framework.
- Senior management must approve and periodically review the operational risk framework and ensure it is implemented consistently, including staff training/awareness programs.
- Institutions should designate a person (e.g. Head of Operational Risk) with day-to-day responsibility for implementing the framework, assessment methodology and reporting system.
- Institutions must subject their operational risk framework to periodic independent review, including review of loss data accuracy and completeness.
- Institutions must put in place systems to identify and systematically track all material operational loss events, generally using a $10,000 materiality threshold.
- Institutions must prepare a regular (normally quarterly) operational risk report for the Board and senior management and share it with the Authority upon request.
- Changes in an institution's operational risk strategy and general policy must be reviewed and approved by the Board of directors.
- Institutions must keep their operational risk framework and arrangements under regular review and amend them as necessary in light of changes in risk profile or market developments.
Applies to
banks, deposit companies
Deadlines
- normally quarterly: Institutions must prepare a regular operational risk report for the Board and senior management, normally on a quarterly basis.
Topics
Version history
2026-07-07