Rule
Insurance (Group Supervision) Rules 2011 (BR 76 / 2011)
In forceView on BMA's website Source document
Summary
These Rules, made by the Bermuda Monetary Authority under the Insurance Act 1978, set out group-level governance, risk management, capital and reporting requirements for insurance groups for which the BMA acts as group supervisor. They impose obligations on the group's designated insurer and parent company board and senior executives, covering corporate governance, internal audit, risk management, compliance and actuarial functions, group solvency assessment and capital requirements, financial reporting, cyber risk management, and financial condition reporting.
- Governance and functions: Insurance groups must establish group-level governance and communications structures and maintain independent internal audit, risk management, compliance and actuarial functions, with the parent board and senior executives bearing defined oversight responsibilities.
- Solvency and capital: Groups must perform an annual Group Solvency Self-Assessment reviewed by the parent board, and meet a Minimum Margin of Solvency and a Group Enhanced Capital Requirement (ECR).
- Financial reporting: Groups must prepare group financial statements, a Group Statutory financial return, and obtain an opinion of the group actuary, and keep records in Bermuda.
- Cyber risk: Groups must establish and maintain a cyber risk programme, appoint a Chief Information Security Officer, ensure board oversight of cyber risk posture, and report designated cyber reporting events to the Authority.
- Financial condition report and significant events: The designated insurer must file an annual Financial Condition Report and report and publish details of significant events occurring before or after the filing date, with declarations signed by senior executives.
The Rules were phased in over 2012 to 2014 and have since been amended several times, most recently to add cyber risk requirements effective 1 January 2023.
Key obligations
- Insurance groups must establish and maintain group-level organizational, governance and communications structures and maintain independent group internal audit, risk management, compliance and actuarial functions.
- The parent board must review its membership, committees and executive composition at least every three years and upon material change, and must review the group's solvency self-assessment annually.
- Insurance groups must conduct a Group Solvency Self-Assessment and comply with the Minimum Margin of Solvency and Group Enhanced Capital Requirement.
- Senior executives must file all required returns and financial statements accurately, completely and in a timely manner.
- Insurance groups must establish and maintain a cyber risk programme and appoint a Chief Information Security Officer, and report cyber reporting events to the Authority.
- The designated insurer must keep records in Bermuda and retain copies of significant event reports at its head office for five years from the filing date.
- Where a significant event occurs after the filing date, the insurance group must prepare and file a report with the Authority within 14 days of the event's occurrence.
- An insurance group with a website must publish a report on a post-filing-date significant event within 30 days of submitting it to the Authority; a group without a website must furnish a copy to the public within 30 days of a written request.
- Every financial condition report or significant event report must be signed by the chief executive and by the chief risk officer or chief financial officer of the parent company, declaring it fairly represents the group's financial condition.
Applies to
insurance groups, designated insurers, parent companies of insurance groups
Deadlines
- 16 January 2012: Commencement of rules 1, 2, 23 to 28 and Schedules 1 and 2.
- 1 January 2013: Commencement of rules 3 to 19, 21, 22 and 29.
- 1 January 2014: Commencement of rule 20.
- 1 January 2023: Effective date of cyber risk programme, CISO and cyber reporting event provisions inserted by BR 41/2022.
- within 14 days of the occurrence of a significant event (after the filing date): Insurance group must prepare and file a report on the significant event with the Authority.
- within 30 days of submission of the report to the Authority: Insurance group with a website must publish the significant event report on its website.
- within 30 days of receipt of a written request: Insurance group without a website must furnish the public with a copy of a significant event report.
- five years beginning with the filing date: Designated insurer must keep copies of significant event reports at its head office.
Related documents
- This document amends Insurance Act 1978
- This document is made under Insurance Act 1978