Bermuda
trust services
74 Bermuda regulatory document(s) tagged trust services.
Who is caught
The core instrument is the Trusts (Regulation of Trust Business) Act 2001, which requires any person carrying on trust business in or from within Bermuda to hold a trust licence unless exempted. Trust business means providing trustee services as a business, trade, profession or vocation. A number of codes, policies and guidance notes made under the Act apply the framework to licensed trust undertakings.
- Licensed undertakings: Companies carrying on trust business require an unlimited trust licence; partnerships and individuals require a limited trust licence.
- Controllers and officers: Controllers, shareholder controllers, directors and senior executives of licensed undertakings are brought within scope, including for fitness and propriety assessment.
- Reporting accountants: Auditors and accountants of licensed trust businesses are subject to notification duties under the Act.
- AML/ATF regulated institutions: Persons carrying on trust business under section 9(3) of the Act are designated AML/ATF regulated financial institutions.
- Cross-sector codes: The Operational Cyber Risk Management Code and the Operational Resilience and Outsourcing Code apply to trust companies (trust businesses) alongside other licensed sectors.
Limited versus unlimited
An unlimited licence is available to local or exempted companies and Overseas Permit Companies and allows soliciting trust business from the public generally. A limited licence is available to partnerships, overseas partnerships and other unincorporated entities or individuals; the holder cannot act as sole trustee and is restricted to holding trust assets not exceeding 30 million dollars unless the Authority approves a higher amount.
Sources: Trusts (Regulation of Trust Business) (Reporting Accountants) (Facts and Matters of Material Significance) Regulations 2006 · Trusts (Regulation of Trust Business) Order 2003 · Trusts (Regulation of Trust Business) Act 2001 · Annex I - Sector-Specific Guidance Notes for Trust Business (2022 Guidance Notes for AML/ATF Regulated Financial Institutions) · Operational Cyber Risk Management Code of Conduct - Corporate Service Providers, Trust Companies, Money Service Businesses, Investment Businesses and Fund Administration Providers (2022-03-15) · Operational Resilience and Outsourcing Code (September 2025) · Operational Resilience and Outsourcing Code (September 2025) (Tracked Changes) · Trusts (Regulation of Trust Business) Act 2001 - Information for Prospective Applicants (April 2020) · Trusts (Regulation of Trust Business) Act 2001 - Code of Practice (December 2019) · AML/ATF Sector Specific Guidance Notes for Trust Business on the Prevention and Detection of Money Laundering and the Financing of Terrorism · Operational Cyber Risk Management Code of Conduct (September 2022 Revised)
Key duties
The principal duty is to hold the appropriate trust licence before carrying on trust business, and thereafter to maintain the minimum licensing criteria and continuing obligations set out in the Act and its supporting codes, policies and guidance. Licensed undertakings must maintain a physical presence in Bermuda and be directed and managed from Bermuda.
Filings with deadlines
- Annual Certificate of Compliance: Each licensed trust undertaking must submit an annual Certificate of Compliance confirming compliance with minimum licensing criteria and codes; failure to do so is an offence under section 35.
- Audited accounts: Companies holding unlimited trust licences must submit audited financial information annually, no later than four months after the end of the financial year.
- Quarterly returns: All licensed undertakings must submit standard financial statements and liquidity analysis quarterly, within 21 business days of each calendar quarter.
- Annual fees: Licensees must pay the annual licence fee; the Bermuda Monetary Authority Amendment (No. 3) Act 2018 set the fee schedules for 2019 to 2021.
Governance and conduct
- Codes of practice: Licensees must have regard to the Code of Practice issued under section 7, covering client due diligence, conflicts of interest, segregation of client funds, complaints, fees and risk management.
- Corporate governance: The Corporate Governance Policy embeds a statutory minimum criterion requiring governance policies and processes, effective direction by at least two individuals (or one if the Authority approves), and non-executive oversight; corporate trustees must have boards comprised solely of individuals.
- Segregation of funds: Trust funds must be kept separate from the licensee's own funds and from other trusts' funds, with records reconciled at least monthly and policies reviewed at least annually.
- Appointment of auditors: Licensees must prepare annual accounts and appoint auditors, whose reports and communications must be provided to the Authority.
Notification duties
- Change of control or officer: Licensees must notify the Authority of any change of controller or officer, and persons acquiring or increasing control must notify new or increased shareholder control.
- Material developments: Undertakings are expected to alert the Authority promptly of breaches or potential breaches, material business changes, key personnel changes, litigation, foreign regulator inquiries, cybersecurity incidents and concerns about a shareholder controller's suitability.
- Reporting accountants: A reporting accountant who identifies a fact or matter of material significance (such as material misstatement, going-concern doubt, material control weakness or evidence of fraud by a senior executive) must notify the Authority under sections 36(2) or 45(2A).
- Cyber reporting events: Under the Operational Cyber Risk Management Code, trust companies must notify the Authority of cyber reporting events, approve a cyber risk policy at least annually, appoint a CISO and retain risk assessments for at least five years.
Outsourcing and resilience
Under the 2019 outsourcing guidance, trust companies must submit a prior notification to the Authority before entering a new material outsourcing arrangement, allowing a 20 working day objection period, and maintain written outsourcing agreements and ongoing oversight. The Operational Resilience and Outsourcing Code (September 2025) adds requirements to identify important business services, set impact tolerances, test against disruption scenarios and prepare an annual self-assessment retained for at least five years, with compliance required by 31 March 2028 generally.
AML/ATF obligations
As AML/ATF regulated financial institutions, trust businesses must comply with the Proceeds of Crime (Anti-Money Laundering and Anti-Terrorist Financing) Regulations 2008 and follow the BMA's general and sector-specific guidance, applying a risk-based approach, conducting customer due diligence and beneficial ownership identification, ongoing monitoring, suspicious activity reporting to the Financial Intelligence Agency, record-keeping, and appointing compliance and reporting officers.
Sources: Bermuda Monetary Authority Amendment (No. 3) Act 2018 · Trusts (Regulation of Trust Business) (Reporting Accountants) (Facts and Matters of Material Significance) Regulations 2006 · Trusts (Regulation of Trust Business) Act 2001 · Annex I - Sector-Specific Guidance Notes for Trust Business (2022 Guidance Notes for AML/ATF Regulated Financial Institutions) · Operational Cyber Risk Management Code of Conduct - Corporate Service Providers, Trust Companies, Money Service Businesses, Investment Businesses and Fund Administration Providers (2022-03-15) · Operational Resilience and Outsourcing Code (September 2025) · Operational Resilience and Outsourcing Code (September 2025) (Tracked Changes) · Letter to Stakeholders on Outsourcing Guidance (2019-06-28) · Trusts (Regulation of Trust Business) Act 2001 - Information for Prospective Applicants (April 2020) · Trusts (Regulation of Trust Business) Act 2001 - Code of Practice (December 2019) · Trusts (Regulation of Trust Business) Act 2001 - Statement of Principles (December 2019) · AML/ATF Sector Specific Guidance Notes for Trust Business on the Prevention and Detection of Money Laundering and the Financing of Terrorism · BMA Corporate Governance Policy for Trust (Regulation of Trust Business) Act 2001, Investment Business Act 2003 and Investment Funds Act 2006 (October 2013) · Operational Cyber Risk Management Code of Conduct (September 2022 Revised) · Outsourcing for Banks, Deposit Companies, the Bermuda Stock Exchange, Corporate Service Providers, Trust Companies, Money Service Businesses, Investment Businesses, Fund Administrators and the Credit Union (28 June 2019) · Corporate Governance Policy for Trust (Regulation of Trust Business) Act 2001, Investment Business Act 2003, and Investment Funds Act 2006 (October 2013) · Corporate Governance Policy for Trust, Investment Business and Fund Administration Providers (Revised August 2022)
Exemptions and carve-outs
Trust business licensing is subject to exemption orders made under the Act. The Trusts (Regulation of Trust Business) Exemption Order 2002 exempts specified categories of trustee from the licensing requirement in section 9, while the Trusts (Regulation of Trust Business) Order 2003 narrows what counts as carrying on trust business in Bermuda.
- Private trust companies: A trust company providing trustee services only to trusts specified in its memorandum or overseas permit is exempt, but must notify the Authority of its qualification, give particulars of its business, notify changes, and file an annual declaration by 31 March each year.
- Members of recognised bodies: A trustee who is a member of a professional body recognised by the Minister and holds a certificate under the Order is exempt.
- Co-trustees: A trustee acting as co-trustee alongside at least one licensed trustee is exempt.
- Records held by a licensed trustee: A professional person acting as trustee is exempt if he appoints a specified connected licensed trust company to maintain the trust's records.
- Other categories: Bare trustees, and trustees of registered pension plans, registered pension trust funds, and authorised or exempted investment funds, are exempt.
- Trusts administered abroad: Under the 2003 Order, a trustee of a trust administered outside Bermuda is not regarded as carrying on trust business in Bermuda where corporate trustees are incorporated outside Bermuda with a majority of directors ordinarily resident abroad, or where a majority of individual trustees are ordinarily resident abroad.
Exempted private trust companies remain within scope of AML/ATF guidance unless they use a licensed Corporate Service Provider or licensed trust business in their structure. Exempt status depends on maintaining the ongoing notification and annual declaration requirements.
Sources: Trusts (Regulation of Trust Business) Order 2003 · Trusts (Regulation of Trust Business) Exemption Order 2002 · Trusts (Regulation of Trust Business) Act 2001 · Annex I - Sector-Specific Guidance Notes for Trust Business (2022 Guidance Notes for AML/ATF Regulated Financial Institutions)
Enforcement and penalties
The Act gives the Authority a broad range of disciplinary and enforcement powers, and carrying on trust business without a licence is a criminal offence. The Authority may restrict or revoke licences, impose civil penalties, issue public censures, make prohibition orders, seek injunctions, issue warning and decision notices, and publish enforcement action, subject to a right of appeal to the Trust Business Appeal Tribunal.
Civil penalty amounts
- Late filing: The Statement of Principles describes a civil penalty of up to 5,000 dollars per week that may be imposed directly for late lodgment of statutory filings.
- Breach of obligations: A penalty of up to 500,000 dollars per breach may be imposed by the Enforcement Committee for breaches of obligations under the relevant Act.
- Other tools: Directions, conditions and restrictions on a licence, objections to controllers, prohibition orders against directors and officers, licence revocation, winding up and referral to the police are also available.
Enforcement examples
- Conyers Trust Company: Civil penalties totalling 1,118,500 dollars in 2022 for historic AML/ATF and Trusts Act minimum-criteria deficiencies identified in 2017 and 2018 inspections.
- Meritus Trust Company: Civil penalties of 600,000 dollars in 2024 for AML/ATF and licensing-criteria breaches identified in 2022 inspections.
- Estera Services (Bermuda): Civil penalties totalling 500,000 dollars in 2019 under sections 29A and 33B for failure to remediate AML/ATF deficiencies within the Authority's timeframe.
The Authority raises breaches with senior management or the board first, escalating to the Enforcement Committee only where unresolved or where the breach is grave or wilful, and applies its powers transparently, proportionately and consistently. Appeals against decisions such as licence revocation, civil penalties, public censure and prohibition orders lie to the Tribunal, whose procedure is governed by the Trust Business Appeal Tribunal Regulations 2004.
Sources: Trust Business Appeal Tribunal Regulations 2004 · Trusts (Regulation of Trust Business) Act 2001 · Statement of Principles on the Use of Enforcement Powers · Notice - Statement of Principles on the Use of Enforcement Powers · Civil Penalties - Meritus Trust Company Limited (2024-12-30) · Statement of Principles on the Use of Enforcement Powers (2012-12-13) · Civil Penalties - Conyers Trust Company (Bermuda) Limited (2022-05-02) · Civil Penalty - Estera Services (Bermuda) Limited (2019-06-14)