Rule

Digital Asset Business (Client Disclosure) Rules 2018

Bermuda Monetary Authority (BMA) · Bermuda

In force

Status per Bermuda Laws Online (bermudalaws.bm) (as at 2026-07-30)

Current version last checked: 2026-07-07

Summary

These Rules, made by the Bermuda Monetary Authority under the Digital Asset Business Act 2018, set out mandatory client disclosure requirements for licensed digital asset business undertakings. They cover pre-transaction risk disclosures, disclosures required when entering into a service agreement, post-transaction confirmations, and notification of cyber reporting events affecting clients.

  • Pre-transaction disclosure: Before an initial transaction with a client, a licensed undertaking must disclose all material risks associated with its products, services and activities, plus any additional disclosures the Authority deems necessary, provided separately and in a form the client can record.
  • Agreement-time disclosures: When entering into an agreement to provide products or services, the undertaking must disclose (where applicable) its licence class, fee schedules, fee calculation and payment methods, insurance coverage (e.g. cyber or theft) and beneficiaries, whether digital asset transfers are irrevocable, custody governance/voting rights, liability and recovery bases for unauthorized or mistaken transfers, how clients update contact information, ability to stop pre-authorized transfers and related procedures, ability to obtain transfer receipts, and the requirement of at least 30 days prior notice of material changes to terms and conditions.
  • Post-transaction confirmation: At the conclusion of a transaction, the undertaking must give the client written confirmation including its name and contact information, contact channels for account queries, general business enquiries and complaints, the type, value, date, precise time and amount of the transaction, and any fees charged including conversion charges.
  • Cyber reporting event disclosure: Every licensed undertaking must disclose to affected clients any cyber reporting event (as defined in the Digital Asset Business Act 2018) involving a breach leading to unauthorized access to or misuse of client information.

The Rules took effect (operative date) on 11 September 2018 and remain in force, applying to all entities licensed under the Digital Asset Business Act 2018.

Key obligations

  • Disclose all material risks of products, services and activities to a client before entering into an initial transaction, separately from other information and in a recordable manner
  • Disclose any additional information the Authority determines necessary for client protection prior to an initial transaction
  • At the time of entering into a service or product agreement, disclose licence class, fee schedules, fee calculation and payment methods, insurance/theft coverage details, irrevocability of digital asset transfers, custody governance/voting rights, liability and recovery terms for unauthorized transfers, contact information update procedures, stop-payment procedures, receipt entitlements, and give at least 30 days prior notice of material changes to terms and conditions
  • Provide written confirmation at the conclusion of each transaction containing the undertaking's contact details, complaint and enquiry contacts, transaction details (type, value, date, time, amount) and fees charged
  • Disclose to affected clients any cyber reporting event involving unauthorized access to or misuse of client information

Applies to

licensed digital asset business undertakings

Deadlines

  • 30 days: Clients must receive not less than thirty days prior notice of any material change to the terms and conditions of services provided
  • 11 September 2018: Operative date of the Rules

Related documents

Topics

Version history

2026-07-07

source file (current)