Rule
Digital Asset Business (Client Disclosure) Rules 2018
In forceView on BMA's website Source document
Summary
These Rules, made by the Bermuda Monetary Authority under the Digital Asset Business Act 2018, set out mandatory client disclosure requirements for licensed digital asset business undertakings. They cover pre-transaction risk disclosures, disclosures required when entering into a service agreement, post-transaction confirmations, and notification of cyber reporting events affecting clients.
- Pre-transaction disclosure: Before an initial transaction with a client, a licensed undertaking must disclose all material risks associated with its products, services and activities, plus any additional disclosures the Authority deems necessary, provided separately and in a form the client can record.
- Agreement-time disclosures: When entering into an agreement to provide products or services, the undertaking must disclose (where applicable) its licence class, fee schedules, fee calculation and payment methods, insurance coverage (e.g. cyber or theft) and beneficiaries, whether digital asset transfers are irrevocable, custody governance/voting rights, liability and recovery bases for unauthorized or mistaken transfers, how clients update contact information, ability to stop pre-authorized transfers and related procedures, ability to obtain transfer receipts, and the requirement of at least 30 days prior notice of material changes to terms and conditions.
- Post-transaction confirmation: At the conclusion of a transaction, the undertaking must give the client written confirmation including its name and contact information, contact channels for account queries, general business enquiries and complaints, the type, value, date, precise time and amount of the transaction, and any fees charged including conversion charges.
- Cyber reporting event disclosure: Every licensed undertaking must disclose to affected clients any cyber reporting event (as defined in the Digital Asset Business Act 2018) involving a breach leading to unauthorized access to or misuse of client information.
The Rules took effect (operative date) on 11 September 2018 and remain in force, applying to all entities licensed under the Digital Asset Business Act 2018.
Key obligations
- Disclose all material risks of products, services and activities to a client before entering into an initial transaction, separately from other information and in a recordable manner
- Disclose any additional information the Authority determines necessary for client protection prior to an initial transaction
- At the time of entering into a service or product agreement, disclose licence class, fee schedules, fee calculation and payment methods, insurance/theft coverage details, irrevocability of digital asset transfers, custody governance/voting rights, liability and recovery terms for unauthorized transfers, contact information update procedures, stop-payment procedures, receipt entitlements, and give at least 30 days prior notice of material changes to terms and conditions
- Provide written confirmation at the conclusion of each transaction containing the undertaking's contact details, complaint and enquiry contacts, transaction details (type, value, date, time, amount) and fees charged
- Disclose to affected clients any cyber reporting event involving unauthorized access to or misuse of client information
Applies to
licensed digital asset business undertakings
Deadlines
- 30 days: Clients must receive not less than thirty days prior notice of any material change to the terms and conditions of services provided
- 11 September 2018: Operative date of the Rules
Related documents
- This document is made under Digital Asset Business Act 2018
- Consultation Paper: Conduct of Business Regulatory Regime - Digital Asset Business Act 2018 Code of Practice & Client Disclosure Amendment Rules 2022 (2022-10-19) amends this document
Topics
Version history
2026-07-07