Regulatory Policy

CSP Corporate Governance Policy (February 2016)

Bermuda Monetary Authority (BMA) · Bermuda

Status not confirmed

Current version last checked: 2026-07-07

Summary

This is a corporate governance policy issued by the Bermuda Monetary Authority for entities licensed under the Corporate Service Provider Business Act 2012. It sets out eight principles, with accompanying guidance, that the Authority uses to assess whether a corporate service provider (CSP) meets the statutory minimum licensing criterion of having corporate governance policies and procedures in place. Compliance is assessed proportionately based on each licensee's nature, scale and complexity, with heightened expectations for holders of unlimited licences given their 'gatekeeper' role.

  • Board practices: Licensees should have an effective, appropriately sized and composed board; corporate directors are not considered appropriate, and boards should meet regularly with structured, minuted agendas.
  • Director qualification and conduct: Directors must be fit and proper, act honestly and in the institution's best interests, avoid conflicts of interest, receive induction and ongoing training, and have sufficient time to fulfil their role.
  • Senior management: Senior management must be fit and proper and accountable to the board for day to day management; wherever possible at least two individuals must effectively direct the business.
  • Risk management and internal controls: The board must set risk appetite, ensure adequate policies and an internal control system, and review the control framework, risk management framework and business continuity plans at least annually.
  • Remuneration: Remuneration arrangements must be consistent with effective risk management and not incentivise inappropriate risk taking.
  • Reporting: The board must ensure timely internal reporting, meet all statutory and regulatory reporting requirements, and provide adequate disclosure to shareholders and other stakeholders.
  • Special structures: Guidance is provided for unincorporated licence holders (partnerships/individuals), CSPs that are subsidiaries or group members, and licensed individuals, each of whom must adapt the principles to their structure.

The Policy is guidance-based rather than a strict checklist: licensees have discretion in how they meet the principles, and the Authority applies proportionality in its assessment, though it does not replace existing statutory requirements.

Key obligations

  • Implement corporate governance policies and procedures as a statutory minimum licensing criterion under the CSP Business Act 2012
  • Ensure the board is composed solely of individuals, not corporate directors
  • Ensure directors and senior management (officers/controllers) are fit and proper persons
  • Wherever possible, ensure at least two individuals effectively direct the business (for companies, partnerships or unincorporated associations)
  • Establish, implement, document and maintain an effective conflicts of interest policy for the board, management and staff
  • Approve the internal control framework and review its appropriateness at least annually
  • Assess the effectiveness of the institution's risk management framework at least annually and make necessary changes
  • Review business continuity and contingency plans at least annually
  • Ensure remuneration arrangements are consistent with effective risk management and do not incentivise inappropriate risk taking
  • Ensure all applicable statutory disclosure and regulatory reporting requirements are met
  • Provide shareholders and other relevant stakeholders with sufficient information/reporting mechanisms to assess board and management effectiveness

Applies to

corporate service providers licensed under the Corporate Service Provider Business Act 2012, holders of limited licences, holders of unlimited licences, unincorporated licence holders (partnerships and individuals), CSPs that are subsidiaries or members of larger groups

Deadlines

  • at least annually: The board should review and approve the internal control framework's appropriateness at least annually.
  • at least annually: The board should assess the effectiveness of the institution's risk management framework at least annually.
  • at least annually: The board should review business continuity and contingency plans at least annually.

Topics

Version history

2026-07-07

source file (current)