Rule

Insurance (Group Supervision) Rules 2011

Bermuda Monetary Authority (BMA) · Bermuda

In force

Status per Bermuda Laws Online (bermudalaws.bm) (as at 2026-07-30)

Current version last checked: 2026-07-07

Summary

These Rules, made by the Bermuda Monetary Authority under section 27F of the Insurance Act 1978, set out the group-level governance, risk management, capital, reporting and cyber risk requirements that apply to insurance groups for which the BMA acts as group supervisor. They impose duties on the designated insurer, the parent board and senior executives of the parent company to establish adequate governance structures, control functions, solvency assessments and reporting to the Authority.

  • Governance: Insurance groups must establish group-level organisational, governance and communications structures; parent boards must review board and executive composition at least every three years and review conflict-of-interest policies and the group solvency self-assessment annually.
  • Control functions: Groups must maintain independent internal audit, risk management, compliance and actuarial functions with direct access and reporting lines to the parent board.
  • Risk management framework: Groups must maintain a risk management and internal controls framework covering investment/market, liquidity, concentration, credit, operational and insurance underwriting risk, plus a Group Solvency Self-Assessment, minimum margin of solvency and Group Enhanced Capital Requirement calculations.
  • Cyber risk: Groups must appoint a Chief Information Security Officer, maintain a cyber risk programme, and report defined 'cyber reporting events' to the Authority; the parent board must exercise oversight of the group's cyber risk posture.
  • Reporting and disclosure: Groups must prepare group financial statements, a Group Statutory financial return, an actuarial opinion, and an annual Financial Condition Report; senior executives are responsible for filing all required returns accurately and on time.
  • Significant events: A significant event occurring before the filing date must be reported within the Financial Condition Report; one occurring after the filing date must be reported to the Authority within 14 days, published on the group's website within 30 days of submission (or furnished to the public within 30 days of a written request if there is no website), and retained on file for five years.
  • Declarations: Every Financial Condition Report and significant event report must be signed by the chief executive and a chief risk officer or chief financial officer of the parent company, declaring it fairly represents the group's financial condition.

The Rules commenced in stages: certain interpretive and reporting rules and Schedules took effect on 16 January 2012, most governance, risk and eligible-capital rules took effect on 1 January 2013, and the rule on the Group Enhanced Capital Requirement took effect on 1 January 2014. Cyber risk provisions were later inserted with effect from 1 January 2023, and financial condition/significant event reporting provisions were inserted with effect from 1 January 2016.

Key obligations

  • An insurance group must establish and maintain organisational, governance and communications structures at group level to support the designated insurer's duties
  • The designated insurer must facilitate and maintain the group's compliance with the Act and these Rules
  • The parent board must review the membership of the board, its committees, and the composition of chief and senior executives no less frequently than every three years and upon material change in the group's business or risk profile
  • The parent board must establish and maintain, annually, policies and procedures addressing actual or potential conflicts of interest
  • The parent board must review annually the group's solvency self-assessment and any changes to it
  • Senior executives must file all required returns and financial statements in an accurate, complete and timely manner
  • An insurance group must appoint a Chief Information Security Officer and establish and maintain a cyber risk programme
  • An insurance group must report 'cyber reporting events' to the Authority
  • Where a significant event occurs after the filing date, the insurance group must prepare and file a report with the Authority within 14 days of the event
  • An insurance group with a website must publish a report on a post-filing significant event within 30 days of submitting it to the Authority
  • An insurance group without a website must furnish a copy of a significant event report to the public within 30 days of a written request
  • The designated insurer must keep copies of significant event reports at its head office for five years from the filing date
  • Every Financial Condition Report or significant event report must be signed and declared by the chief executive and a chief risk officer or chief financial officer of the parent company

Applies to

insurance groups, designated insurers, parent companies, parent boards, senior executives of parent companies

Deadlines

  • 16 January 2012: Commencement of rules 1, 2, 23 to 28 and Schedules 1 and 2
  • 1 January 2013: Commencement of rules 3 to 19, 21, 22 and 29
  • 1 January 2014: Commencement of rule 20 (Group Enhanced Capital Requirement)
  • 1 January 2016: Effective date for financial condition report, subsequent event and declaration provisions (rules 23-32 inserted by BR 54/2015)
  • 1 January 2023: Effective date for cyber risk programme and CISO related provisions inserted by BR 41/2022
  • every three years: Parent board must review board, committee and executive composition no less frequently than every three years
  • annually: Parent board must review conflict-of-interest policies and the group solvency self-assessment
  • within 14 days of the occurrence: Insurance group must file a report on a significant event occurring after the filing date
  • within 30 days of submission of the report to the Authority: Insurance group with a website must publish the significant event report
  • within 30 days of receipt of a written request: Insurance group without a website must furnish a copy of a significant event report to the public
  • five years beginning with the filing date: Designated insurer must keep copies of significant event reports at its head office

Related documents

Topics

Version history

2026-07-07

source file (current)