Rule

Insurance (Prudential Standards)(Insurance Managers Annual Return) Rules 2017 - Schedule

Bermuda Monetary Authority (BMA) · Bermuda

In force

Status per Bermuda Laws Online (bermudalaws.bm) (as at 2026-07-30)

Current version last checked: 2026-07-07

Summary

This Schedule sets out the detailed content requirements for the annual return that insurance managers in Bermuda must file under the Insurance (Prudential Standards) (Insurance Managers Annual Return) Rules 2017. It does not create new licensing categories but specifies, in granular detail, the information insurance managers must compile and submit each year covering governance, cyber risk, anti-money laundering/anti-terrorist financing (AML/ATF), and sanctions compliance.

  • General/organisational information: Directors and officers, organisational structure, staff, outsourced service providers, insurers managed, any known breaches or non-compliance by managed insurers, professional indemnity/D&O/E&O insurance details, and confirmation of meeting minimum registration criteria.
  • Cyber risk management: Board approval and review of cyber risk strategy, adoption of cyber-security standards, internal audit and vulnerability/penetration testing, cyber insurance, employee training, third-party/outsourcing cyber risk assessments, data protection and patching policies, network monitoring, incident response plans and history, and percentage of budget allocated to cyber security.
  • AML/ATF questionnaire: Client numbers and ML/TF risk ratings, products/services (including direct long-term insurers and outsourcing/CSP services), SAR filing activity and GoAML registration, delivery channels, geographic distribution of UBOs and PEPs by defined zones, training and personnel practices, AML/ATF controls, risk assessments, audits, and Compliance/Reporting Officer reports.
  • Corporate governance confirmations: A series of yes/no confirmations on board oversight, segregation of duties, AML/ATF information flow to the board, employee training and compliance, disciplinary processes, and Senior Compliance Officer responsibilities.
  • International sanctions questionnaire: Whether policyholders, beneficiaries and employees are screened against the Bermuda sanctions regime, whether client assets have been frozen in the last 12 months, and details of any assets frozen relative to the UK OFSI consolidated list.

Together these schedules operationalise the annual return obligation by prescribing exactly what data, confirmations and supporting documentation insurance managers must gather and submit to the Bermuda Monetary Authority each reporting cycle.

Key obligations

  • Insurance managers must compile and submit in their annual return details of directors, officers, staff, organisational structure and outsourced service providers.
  • Insurance managers must disclose all insurers they manage or service, including registration numbers, insurance classes, and any known breaches or non-compliance by those insurers.
  • Insurance managers must confirm compliance with minimum criteria for registration, or describe any non-compliance and remedial action taken.
  • Insurance managers must report on cyber risk governance, controls, testing, insurance, incident history and budget allocation.
  • Insurance managers must complete a detailed AML/ATF questionnaire covering client risk ratings, products/services, SAR filings, GoAML registration, training, controls and audit history.
  • Insurance managers must answer corporate governance confirmations regarding board oversight, AML/ATF reporting lines, employee compliance and training.
  • Insurance managers must confirm whether they screen policyholders, beneficiaries and employees under the Bermuda sanctions regime and report any frozen assets, including details matched to the UK OFSI consolidated list.

Applies to

insurance managers

Topics

Version history

2026-07-07

source file (current)