Rule

Digital Asset Issuance Rules 2020

Bermuda Monetary Authority (BMA) · Bermuda

In force

Status per Bermuda Laws Online (bermudalaws.bm) (as at 2026-07-30)

Current version last checked: 2026-07-07

Summary

These Rules, made by the Bermuda Monetary Authority under the Digital Asset Issuance Act 2020, set out detailed requirements for any undertaking conducting a digital asset issuance (e.g. an ICO or token sale) in or from within Bermuda. They govern the content of the issuance (disclosure) document, ongoing disclosure obligations to acquirers, IT/cybersecurity standards, custody of assets, AML/CFT compliance measures, and available exemptions.

  • Issuance document: Must contain an extensive list of minimum required information (issuer and group details, project description, technology and consensus mechanism, digital asset economics, offering terms, custody arrangements, risks, financing, soft cap/hard cap, cooling-off/refund mechanism, and data protection controls).
  • Ongoing disclosures: Issuers must give acquirers milestone progress updates at the disclosed frequency, notify material changes before they take effect (or as soon as practicable if unforeseeable), and disclose removal or replacement of service providers as soon as practicable.
  • Periodic returns: Issuers must file electronic periodic returns with the Authority within the period and intervals specified in their authorisation, covering organisational structure, directors/officers, revenue, transaction volumes, client profiles and outsourcing arrangements, accompanied by a signed director/officer declaration of accuracy.
  • Market abuse and risk management: Where digital assets are or will be traded on a secondary market, issuers must implement systems to prevent, detect and report insider market abuse, and must maintain a risk management and internal controls framework throughout authorisation and any specified wind-down period.
  • IT and cybersecurity: Issuers must ensure their technological and cybersecurity infrastructure meets international best practice, including data audit node, cyber security report and cyber security program requirements.
  • Custody and compliance: Rules cover custody of acquirer assets, AML/CFT due diligence (identity verification, enhanced due diligence, cessation of transactions), appointment of a Reporting Officer and Compliance Officer, reliance on third parties, five-year record-keeping, and an internal compliance audit submitted with a certificate of compliance.
  • Exemptions: Issuers relying on an accredited digital asset business, qualifying as a local issuer, or whose issuance is authorised/vetted by another competent authority benefit from reduced rule sets, but must file an exemption form with the Authority before proceeding.

The Rules took effect on their operative date of 7 December 2020 and remain in force, applying throughout the life of an issuer's authorisation and, for risk management purposes, for any further period specified in that authorisation.

Key obligations

  • Include all minimum required information listed in rule 6 in the issuance document before offering digital assets
  • Provide digital asset acquirers with milestone progress updates at the frequency disclosed in the issuance document, including explanations where milestones are missed
  • Inform acquirers of any material change to the issuance before it takes effect, or as soon as practically possible if the change could not have been foreseen
  • Inform acquirers of removal or replacement of any service provider named in the issuance document as soon as practically possible
  • File periodic electronic returns with the Authority within the period and intervals specified in the issuer's authorisation, containing the prescribed information
  • File a signed declaration by two directors, or a director and an officer, confirming the periodic return is fair and accurate at the time of filing
  • Implement effective internal arrangements to prevent, detect and report insider market abuse where digital assets are or will be traded on a secondary market
  • Establish and maintain a risk management and internal controls framework complying with Authority guidelines for the duration of authorisation and any further specified period
  • Ensure technological and cybersecurity infrastructure complies with international best practices, taking into account nature, scale and complexity of operations
  • Keep due diligence records, including on complex, unusually large or unusual linked transactions, for a minimum of five years and make them available to the Authority and other authorities on request
  • Provide requested identification/verification information to a relying party as soon as reasonably practicable and no later than five business days after request, when relied upon under rule 25
  • Carry out an internal compliance review of the digital asset issuance and financial operations and submit the outcome with the certificate of compliance required under section 70 of the Act
  • File an exemption form with the Authority in the specified format before proceeding with the issuance if relying on an exemption under section 16(2) of the Act

Applies to

issuers of digital asset issuances in or from within Bermuda, local issuers, accredited digital asset businesses, third-party custodians and service providers of issuers

Deadlines

  • 07 December 2020: Operative date on which the Digital Asset Issuance Rules 2020 took effect.
  • within the period and at such intervals specified in its authorization: Deadline for an issuer to file its periodic return with the Authority.
  • not later than five business days after the request: Timeframe for a relied-upon person to provide due diligence information/documents to the party relying on them.
  • minimum period of five years: Retention period for records and findings related to investigations of complex, unusually large, or unusual linked transactions.

Related documents

Topics

Version history

2026-07-07

source file (current)