Satisfying the BMA’s regulatory requirements

Published: 13 Apr 2017
Type: Insight

In a recent article, we discussed the importance of licensed entities having a plan to ensure regulatory compliance rather than risking penalties being imposed because of deficiencies uncovered following a visit from the Bermuda Monetary Authority (BMA).

Here, we will discuss the means employed by the BMA to ensure that licensed entities have their house in order, including prudential meetings and on-site visits.

To recap, regulated entities (including those licensed under the Investment Business Act 2003, the Investment Funds Act 2006 and the Insurance Act 1978) must meet certain minimum criteria. Such entities must make an annual filing with the BMA, certifying that the entity has met these minimum criteria. Consequently, entities should evaluate the minimum criteria regularly (at least annually) and create a plan and timeline for any deficiencies found by their internal review or audit.

The minimum criteria include (but are not limited to):

  • Fit and proper person test.
  • Corporate governance.
  • Whether business is conducted in a prudent manner.

In addition, certain regulated entities may be required to:

  • Have a policy of insurance to cover risks inherent in the operation of its business of an amount that is commensurate with the nature and scale of operations.
  • Maintain adequate accounting and other records of its business and systems of control of its business and records.
  • Maintain minimum net asset, capital and liquidity requirements.

To ensure that regulatory requirements are being satisfied, senior management should audit and periodically test the entity’s policies, procedures and controls for effectiveness and must be made aware of the potential personal liability if legal obligations are not being met. Senior management must address in a timely manner any shortcomings revealed by the independent internal audit.

An independent audit function should include:

  • An evaluation of the Anti-Money Laundering / Anti-Terrorist Financing (AML/ATF) risk rating the entity assigns with respect to its size, customers, products, services, transactions, delivery channels, outsourcing arrangements and geographical connections.
  • An assessment of the adequacy of its policies, procedures and controls.
  • A testing of compliance with relevant laws and regulations.
  • A review of any outsourced activities.
  • An assessment of the adequacy of employee training and awareness.
  • Sample testing.

The audit should be documented and retained, and the results should be reported to senior management and the board. The results of each audit should be used to guide any improvements that the policies, procedures and controls require.

The BMA supervises licensed entities on an ongoing basis to evaluate whether they satisfy the minimum criteria for licensing — and reviews the nature of the provider’s business, the quality of management, the effectiveness of its controls and compliance, the fairness of its treatment of customers and its financial viability. This is designed to ensure that minimum standards are being maintained.

To evaluate a licensed entity, the BMA holds regular prudential meetings with senior management of the entity, scrutinises financial information and performs regular on-site compliance visits of the entity’s premises.

Prudential meetings are generally scheduled annually and provide an opportunity for the BMA to discuss with senior management the development of the licensed entity’s business including past performance and future direction for the business. Topics that are likely to be discussed include internal control issues, adequacy of procedure manuals, planned changes to the business strategy and operational changes.

On-site supervision enables the BMA to review compliance with policies and procedures as well as the processes that management has put in place to monitor and control key risks in the business. This will involve interviews with management and staff, reviews of a selection of documentation of files and a review of customer due diligence and record-keeping measures.

On-site visits are normally scheduled on a three-year rolling basis but may be more frequent depending on the BMA’s assessment of the degree of risk in the business and the effectiveness of the investment provider’s personnel, systems and controls for monitoring risk.

The BMA will generally request information prior to the on-site visit including a staff chart, job descriptions for key personnel, the entity’s questionnaire regarding AML/ATF compliance and copies of policies, procedures, as well as the staff training plan and disaster recovery plan.

Breaches uncovered by the BMA’s prudential meetings and on-site visits may result in a request to remediate or, if a breach is more serious, could result in severe fines, restrictions placed on the licence or even revocation of licence. The BMA may also publish details of any serious breaches and fines levied.

All regulated entities should take a pro-active approach, ensuring that they create a clear and consistent plan of action to evaluate their ability to meet the minimum criteria of licensing under the relevant legislation. It is better to plan than to wait for prudential meetings and/or on-site visits to reveal deficiencies

Share
More publications
Appleby-Website-Private-Client-and-Trusts-Practice-1905px-x-1400px
15 Apr 2026

Purpose trusts: Bermuda’s answer to modern asset structuring

Purpose trusts represent a notable development in modern trust law, particularly within offshore financial jurisdictions such as Bermuda. Unlike traditional private trusts, which are established for the benefit of identifiable beneficiaries, purpose trusts are created to achieve specific objectives or purposes. Historically, common law jurisdictions were reluctant to recognise such arrangements due to the absence of beneficiaries capable of enforcing the trust. However, legislative reforms in Bermuda have significantly expanded the scope of trust law by expressly validating noncharitable purpose trusts. Through the enactment of the Trusts (Special Provisions) Act 1989 (‘the 1989 Act’), Bermuda introduced a statutory framework that allows trusts to exist for defined purposes, provided certain legal requirements are satisfied. This innovation has made Bermuda a leading jurisdiction for the establishment of purpose trusts, particularly in the fields of international finance, corporate structuring and private wealth management. This article examines the legal foundations of purpose trusts under Bermuda law, focusing on their historical development, statutory framework, requirements for validity, enforcement mechanisms and practical applications.

Website-Code-Bermuda-1
10 Apr 2026

Bermuda Regulatory Update – Economic Substance Amendment Act 2026

On 31 March 2026, the Economic Substance Amendment Act 2026 and the Economic Substance Amendment Regulations 2026 (together, the “2026 Amendments”) came into force, enacting changes to the Economic Substance Act 2018 (“ES Act”) and Economic Substance Regulations 2018.

ICLG Fintech 21 cover
10 Apr 2026

Digital asset developments and Bermuda’s regulatory readiness

While frightening to some, “finance bros” and “tech bros” are now wearing the same gilets as traditional finance products and structures are being infused with digital asset adaptation.

Appleby-Website-Insurance-and-Reinsurance
1 Apr 2026

Q1’26 Suggests Cat Bond Issuance Could Reach $20bn Again, Private ILS & Sidecar Surge to Continue

It’s been an exceptionally busy start to the year for the catastrophe bond sector, with Q1’26 officially becoming the second highest Q1 on record in terms of total catastrophe bond issuance, which indicates that 2026 could end up reaching the $20 billion+ milestone once again, Brad Adderley, Managing Partner at law firm Appleby has said.

Trust Disputes
27 Mar 2026

Privy Council decision in X Trusts – redefining the role of the protector

On 19 March 2026, the Judicial Committee of the Privy Council (JCPC) delivered its long-awaited judgment regarding the role of a fiduciary protector in the administration of a trust (A and 6 others (Appellants) v C and 13 others (Respondents) [2026] UKPC 11, on appeal from the Court of Appeal of Bermuda). The decision of the JCPC was unanimous, with the judgment being given by Lords Briggs and Richards.

Appleby-Website-Insurance-and-Reinsurance
26 Mar 2026

Latin American risks and the Bermuda market

Bermuda’s decades-long efforts to welcome Latin American risks to the island’s re/insurance market have borne fruit in the form of the many LatAm captive insurers that have become domiciled here.

Appleby-Website-Insurance-and-Reinsurance
24 Mar 2026

Navigating Bermuda’s New Recovery Planning Requirements: A Roadmap for Commercial Insurers

On 20 March 2026, the Bermuda Monetary Authority (BMA) issued an updated Guidance Note for Recovery Planning Requirements (Guidance Note). The Guidance Note assists Bermuda commercial insurers’ compliance with the obligations set out in the Insurance (Prudential Standards) (Recovery Plan) Rules 2024 (Rules), which became operative on 1 May 2025.

Appleby-Website-Private-Client-and-Trusts-Practice-1905px-x-1400px
13 Mar 2026

A will trust can keep a home in the family

In Bermuda, a family homestead represents more than financial value; it embodies ancestral heritage and housing security.

Appleby-Website-Employment-and-Immigration
12 Mar 2026

Privacy at Work: What PIPA Means for Bermuda Employers

The Personal Information Protection Act 2016 (PIPA), which came into force on 1 January 2025, represents Bermuda’s first comprehensive date protection regime. The legislation regulates the collection, use, disclosure and storage of personal information with the objective of protecting individuals’ privacy while allowing organisations to use data in a responsible and transparent manner. PIPA applies broadly to organisations operating in Bermuda, including employers. As a result, the employment relationship is one of the contexts in which the practical impact of PIPA is the most significant. Employers routinely process large volumes of personal information relating to employees and job applicants, and PIPA imposes obligations that affect recruitment, workplace monitoring, record-keeping, and disciplinary processes.