Notice

Notice - Operational Cyber Risk Management Code of Conduct: Banks and Deposit Companies (2022-09-26)

Bermuda Monetary Authority (BMA) · Bermuda

Issued 2022-09-26

Current version last checked: 2026-07-07

Summary

This notice from the Bermuda Monetary Authority confirms the in force date and compliance deadline for the Operational Cyber Risk Management Code of Conduct as applied to banks and deposit companies. It follows a stakeholder letter on the Authority's consultation on the Code and clarifies timing that had previously been left open for this sector.

  • Prior status: The Code already came into force on 15 March 2022 for corporate service providers, trust companies, money service businesses, investment businesses and fund administration providers, with a compliance deadline of 15 February 2023 for those entities.
  • New in force date: Following amendments to the Banks and Deposit Companies Act 1999, the Code comes into force on 26 September 2022 for banks and deposit companies.
  • Compliance deadline: Banks and deposit companies (Relevant Licensed Entities) must comply with the Code by 15 February 2023.
  • Support: Banks and deposit companies with implementation questions are encouraged to contact their usual BMA contact.

Key obligations

  • Banks and deposit companies must achieve compliance with the Operational Cyber Risk Management Code of Conduct by 15 February 2023.

Applies to

banks, deposit companies

Deadlines

  • 26 September 2022: Code comes into force for banks and deposit companies
  • 15 February 2023: Deadline for banks and deposit companies to become compliant with the Code

Related documents

Topics

Version history

2026-07-07

source file (current)