Bermuda
banking
126 Bermuda regulatory document(s) tagged banking.
Who is caught
The banking regime in Bermuda is built on the Banks and Deposit Companies Act 1999, administered by the Bermuda Monetary Authority (BMA). The central trigger is activity: no person may carry on deposit-taking business in or from within Bermuda without a licence granted under the Act, subject to limited exemptions.
Entities caught
- Banks and deposit companies: The principal licensed institutions under the Banks and Deposit Companies Act 1999, and the subject of the fee, prudential, capital, liquidity and conduct instruments indexed here.
- Restricted banks: A distinct licensing classification under the Act, with its own minimum net asset threshold and exclusion criteria introduced by the Restricted Banks Amendment Order 2024.
- Credit unions: Regulated separately under the Credit Unions Act 2010, which transferred licensing and supervision to the BMA; no person may operate a credit union in or from Bermuda without a BMA licence.
- Associated persons: Controllers, shareholder controllers, directors, senior executives, auditors and reporting accountants of licensed institutions also carry duties under the Act and related regulations.
- Digital asset service recipients: The Third Schedule permits institutions licensed under section 14(5)(c) to provide services to certain persons engaged in, or applying to conduct, digital asset business or digital asset issuance in Bermuda, subject to specified criteria.
Several conduct and resilience codes reach a wider population of BMA-regulated entities but apply to banks and deposit companies among them. The Operational Cyber Risk Management Code and the Operational Resilience and Outsourcing Code apply to banks and deposit companies alongside corporate service providers, trust businesses, money service businesses, investment businesses, fund administration providers and various insurance and digital asset entities. For anti-terrorism financing purposes, deposit-taking business as defined under the Act is designated part of the regulated sector supervised by the BMA.
Sources: Anti-Terrorism (Financial and Other Measures) (Businesses in Regulated Sector) Order 2008 · Bermuda Monetary Authority Act 1969 · Banks and Deposit Companies Act 1999 · Banks and Deposit Companies (Restricted Banks) Amendment Order 2024 · Credit Unions Act 2010 · Operational Resilience and Outsourcing Code (September 2025) · Operational Resilience and Outsourcing Code (September 2025) (Tracked Changes) · Operational Cyber Risk Management Code of Conduct (September 2022 Revised)
Key duties
Licensed institutions carry continuing obligations spanning licensing criteria, fees, prudential returns, capital and risk standards, governance and notification. The obligations below that carry fixed deadlines or recur should be prioritised.
Licensing and minimum capital
- Minimum net assets: At the time a licence is granted, an institution must hold initial net assets of not less than $10 million for a bank, $5 million for a restricted bank, or $1 million for a deposit company (or equivalent), per the Second Schedule as amended by the 2024 Restricted Banks Order.
- Code of conduct: Institutions must comply with any code of conduct issued by the Authority under section 8A; the Banks and Deposit Companies Code of Conduct sets conduct-of-business, AML/CFT, internal control and disclosure standards applied proportionately to size and risk.
Fees and deadlines
- Licence grant fee: Payable within sixty days of the grant of the licence: $100,000 for a bank and $2,500 for a deposit company under the Banks and Deposit Companies (Fees) Act 1975.
- Bank annual fee: Payable by 31 January each year (after the year of licensing), tiered by consolidated gross assets, with a director-signed declaration of consolidated gross assets delivered at the time of payment.
- Deposit company annual fee: A flat $20,000 payable by 31 January each year after the year of licensing.
- Credit union annual fee: Payable by 30 April each year (from the year after licensing), plus a pro-rated fee on grant of licence.
Prudential returns and reporting
- Prudential Information Return: The Basel II Capital Adequacy Return, completed as at end March, June, September and December on both unconsolidated and consolidated bases.
- Liquidity Return: Completed quarterly on an unconsolidated basis using the Authority's mismatch and maturity rules.
- Foreign Currency Exposure Return (Form S3): Completed quarterly on an unconsolidated basis.
- Large exposures reporting: Under the Large Exposures framework, banks report quarterly all exposures at or above 10% of the Large Exposure Capital Base and their 20 largest counterparty exposures; prior written approval (generally at least 48 hours' notice) is required before any exposure reaching 25% of LECB, with immediate notification of any inadvertent breach.
- Stress testing / CARP: Banks must run stress tests at least annually and submit results within the Capital Assessment and Risk Profile (CARP) submission, with prescribed shocks and remedial plans where the stressed CET1 ratio falls below the 7% target.
- General information duties: Institutions must submit prudential and other returns, report large exposures, and produce documents and reports when required by the Authority.
Capital and risk standards
- Basel III capital ratios: Maintain at all times CET1 of at least 4.5% of RWA, Tier 1 of at least 6.0% and Total Capital of at least 8.0%, plus buffers, and meet Liquidity Coverage Ratio, operational risk, credit risk and Pillar 3 disclosure requirements.
- Real property lending: Apply the supervisory LTV limits (80% residential owner-occupied, 75% otherwise) and standardised TDSR methodology, treating loans with TDSR above 60% as imprudent absent mitigating factors.
- Operational and interest rate risk: Maintain documented frameworks for operational risk (with material loss-event tracking, generally at a $10,000 threshold) and for measuring, monitoring and controlling interest rate risk, with regular board and Authority reporting.
- Cyber and operational resilience: Under the Operational Cyber Risk Management Code and the Operational Resilience and Outsourcing Code, boards must oversee and annually approve relevant policies, firms must run programmes and annual testing, retain records for at least five years, and notify the Authority of significant developments or cyber reporting events.
Governance and notifications
- Control and shareholding changes: Persons acquiring new or increased control, or a significant shareholding, must notify the Authority, which may object to controllers or restrict shares.
- Officer changes: Institutions must notify the Authority of any change of director, controller or senior executive.
- Audit: Institutions must appoint approved auditors annually and have financial statements audited; auditors and reporting accountants must communicate specified facts and matters of material significance directly to the Authority.
- Branch and office control: Under the 1994 Control Regulations, prior written approval is required before establishing or relocating a branch, subsidiary or representative office, and closures must be notified within fourteen days.
- Outsourcing: Institutions must manage and risk-assess outsourcing, submitting a prior notification letter before new material outsourcing arrangements (subject to a 20 working day review period) under the 2019 outsourcing guidance.
Sources: Banks and Deposit Companies Act 1999 · Banks and Deposit Companies (Restricted Banks) Amendment Order 2024 · Banks and Deposit Companies (Fees) Act 1975 · Credit Unions Act 2010 · Guidance Notes - Large Exposures Framework for Bermuda Banks and Deposit Companies (December 2024) · Basel III for Bermuda Banks and Deposit Companies - Guidance Notes (Amended February 2024) · Banks and Deposit Companies Act 1999 - Code of Conduct (August 2022) · Annual Update - Stress Testing in the Capital Assessment and Risk Profile (CARP) for Bermuda's Banking Sector 2018 · Guidance Note - Banks and Deposit Companies Supervisory LTV Limits and Supervisory Guidelines on TDSR for Real Property Loans (May 2014) · Guidelines on the Enhancement of Stress Testing in the CARP for Bermuda's Banking Sector (April 2014) · The Bermuda Monetary Authority's Relationship with Auditors and Reporting Accountants of Banks and Deposit Companies (December 2012) · The Measurement and Monitoring of Liquidity (December 2010) · Guidance on Completion of the Prudential Information Return for Banks (December 2008) · The Approach to Consolidated Supervision (May 2007) · The Management and Control of Credit Risks and the Implementation of the Statutory Provisions for Large Exposures (May 2007) · The Management of Operational Risk (May 2007) · The Monitoring and Control of Interest Rate Risk (May 2007) · Operational Resilience and Outsourcing Code (September 2025) · Liquidity Return Guidance Notes · Foreign Currency Exposure Return Guidance Notes · Operational Cyber Risk Management Code of Conduct (September 2022 Revised) · Outsourcing for Banks, Deposit Companies, the Bermuda Stock Exchange, Corporate Service Providers, Trust Companies, Money Service Businesses, Investment Businesses, Fund Administrators and the Credit Union (28 June 2019)
Exemptions and carve-outs
The Act's licensing requirement is subject to exemptions set out in the First Schedule and related orders, plus classification carve-outs and technical exemptions within the prudential and code frameworks.
- Credit unions: A credit union registered under the Credit Unions Act 1982 is an exempt entity under the First Schedule, falling outside the bank/deposit company licensing regime (credit unions are instead regulated under the Credit Unions Act 2010).
- Insurance registrants: Persons registered under the Insurance Act 1978 are exempt from deposit-taking licensing, but only to the extent they accept deposits in the course of the insurance business for which they are registered.
- Investment business licensees: Persons licensed under the Investment Business Act 1998 are exempt from deposit-taking licensing, but only to the extent they accept deposits in the course of that investment business.
- Restricted bank exclusions: An institution licensed as a casino under the Casino Gaming Act 2014, or one not ordinarily resident, incorporated, registered or formed in Bermuda, is excluded from qualifying under Third Schedule paragraph 1.
- Sandbox / test licensees: Entities under a regulatory sandbox or test licence are excluded from the Operational Resilience and Outsourcing Code.
- Large exposure carve-outs: Certain sovereign, public sector entity and qualifying central counterparty exposures are exempt from the pre-approval requirement, subject to specified conditions, though they remain subject to reporting thresholds.
- LTV limit exclusions: The supervisory LTV limits do not apply to loans taken as additional collateral out of caution, loans sold promptly without recourse, business loans not primarily reliant on real estate, or loans exceeding limits only due to a later decline in property value.
The codes of conduct and resilience instruments also apply proportionately to the nature, scale and complexity of the business, which functions as a scaling mechanism rather than a formal exemption.
Sources: Banks and Deposit Companies (Restricted Banks) Amendment Order 2024 · Banks and Deposit Companies (Exemption) Order 2001 · Banks and Deposit Companies (Exemption) Order 1999 · Guidance Notes - Large Exposures Framework for Bermuda Banks and Deposit Companies (December 2024) · Banks and Deposit Companies Act 1999 - Code of Conduct (August 2022) · Guidance Note - Banks and Deposit Companies Supervisory LTV Limits and Supervisory Guidelines on TDSR for Real Property Loans (May 2014) · Operational Resilience and Outsourcing Code (September 2025) · Operational Cyber Risk Management Code of Conduct (September 2022 Revised)
Enforcement and penalties
Enforcement and penalties arise both from specific offence provisions in the fee and licensing instruments and from the BMA's general supervisory and disciplinary powers.
Fee and offence provisions
- Late or non-payment of fees: Failure to pay the annual fee is an offence carrying a fine of $100 for every day the default continues, unless the Authority accepts late payment plus a $1,000 penalty where non-payment was not due to wilful neglect or default; fees and penalties are recoverable as a civil debt.
- False fee declaration: Knowingly or recklessly making a false or misleading statement in the bank's annual consolidated-gross-assets declaration is an offence punishable by a fine of $50,000.
- Credit union late fees: Late payment of a credit union's annual fee attracts a $500 per week civil penalty; operating unlicensed, misusing the 'credit union' name, or breaching licence conditions are criminal offences carrying fines and, in some cases, imprisonment.
- False information and obstruction: Providing false documents or information to the Authority is an offence, as is obstructing an investigation; directors and managers who contravene the branch-control approval, notification or information requirements or submit false information are guilty of an offence.
Supervisory and disciplinary powers
- Disciplinary measures: Under the Banks and Deposit Companies Act 1999 the Authority may impose civil penalties, issue public censures, make prohibition orders, seek injunctions, restrict or revoke licences, and issue warning and decision notices following specified procedures.
- Civil penalty framework: The Enforcement Guide sets a four-step process for determining civil penalties, with prudential penalties capped at $500,000 and penalties under the Proceeds of Crime supervision and enforcement regime (SEA) capped at $10 million.
- Code non-adherence: Non-adherence to the Codes of Conduct is not itself an offence, but the Authority takes it into account in assessing prudent conduct and it may lead to formal supervisory or enforcement action, including licence revocation.
- Appeals: Decisions on licences, restrictions and shareholder controller objections may be appealed to the Banking Appeal Tribunal within the time limits set by the Banking Appeal Tribunal Regulations 2001; branch-control decisions may be appealed to the Minister within twenty-one days.
Sources: Banks and Deposit Companies Act 1999 · Banks and Deposit Companies (Fees) Act 1975 · Banking Appeal Tribunal Regulations 2001 · Credit Unions Act 2010 · Bermuda Monetary Authority (Financial Institutions) (Control) Regulations 1994 · Banks and Deposit Companies Act 1999 - Code of Conduct (August 2022) · Banks and Deposit Companies Code of Conduct (August 2022) · Enforcement Guide: Statement of Principles & Guidance on the Exercise of Enforcement Powers (September 2018)