Skip to content

Evidence request lists

Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct

Evidence request list. 27 controls, 27 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

BMA Code Section V: Identification of Assets and Risks

BMA-12
Board and Senior Management Oversight

Board and Senior Management Oversight. The board of directors and senior management team must have oversight of cyber risk and of the operational cyber risk management programme (para 14).

Artefacts an auditor will ask for
  • Board/committee minutes evidencing oversight of cyber risk
  • Cyber risk reporting to the board and senior management
  • Defined board accountability for the programme
Where this commonly fails
  • No board oversight of cyber risk
  • Cyber risk not reported to the board
  • Accountability undefined
BMA-13
Asset Inventory

Asset Inventory. An asset inventory detailing all information assets must be put in place and maintained (para 25).

Artefacts an auditor will ask for
  • Information asset inventory with owners and criticality
  • Process for keeping the inventory current
  • Linkage of assets to risk assessments
Where this commonly fails
  • Asset inventory incomplete or stale
  • No asset owners assigned
  • Critical assets not identified
BMA-27
Cyber Insurance

Cyber Insurance. RLEs should consider the benefits of purchasing a cyber insurance policy as part of their risk transfer strategy (para 24).

Artefacts an auditor will ask for
  • Assessment of cyber insurance need and coverage
  • Cyber insurance policy documentation where held
  • Linkage of residual risk to risk-transfer decisions
Where this commonly fails
  • Cyber insurance not considered
  • Coverage not matched to risk profile
  • Policy exclusions not understood
BMA-3
Operational Cyber Risk Management Programme

Operational Cyber Risk Management Programme. The objectives of the cyber risk policy must be delivered by an operational cyber risk management programme that defines, documents and communicates policies, processes and procedures (paras 15-16).

Artefacts an auditor will ask for
  • Board-approved cyber risk policy
  • Documented operational cyber risk management programme (policies, processes, procedures)
  • Evidence of communication of the programme across the organisation
Where this commonly fails
  • No documented programme delivering the policy
  • Policy not approved or communicated
  • Programme not maintained/reviewed
BMA-4
Chief Information Security Officer

Chief Information Security Officer (CISO). A CISO with the necessary experience and competencies must be appointed to deliver the operational cyber risk management programme (paras 17-18).

Artefacts an auditor will ask for
  • CISO appointment record, job description and reporting line
  • Evidence of CISO competencies/experience
  • CISO reports to the board/senior management on cyber risk
Where this commonly fails
  • No CISO appointed or role unfilled
  • CISO lacks authority/independence
  • CISO not reporting to the board
BMA-5
Three Lines of Defence

Three Lines of Defence. Cyber risk governance should follow a three lines of defence model (operational management; risk and compliance oversight; internal audit) (para 19).

Artefacts an auditor will ask for
  • Documented three-lines-of-defence model for cyber risk
  • Defined responsibilities for each line
  • Independence of the third line (IT audit)
Where this commonly fails
  • Lines of defence not defined or overlapping
  • No independent third line
  • Risk oversight conflated with operations
BMA-6
Risk Assessment Process

Risk Assessment Process. The programme must include a risk assessment process; assessments must be documented and retained for at least five years, and the control environment continuously monitored and evaluated (paras 20-22).

Artefacts an auditor will ask for
  • Documented cyber risk assessment methodology and results
  • Evidence assessments are retained for at least five years
  • Continuous monitoring and evaluation of the control environment
Where this commonly fails
  • Risk assessments not documented or retained 5 years
  • Control environment not continuously monitored
  • Assessment not updated when risk changes
BMA-7
Information Technology Audit Plan

IT Audit Plan. The third line of defence, IT audit, should provide the audit committee of the board (or equivalent) with independent assurance over the cyber risk programme through a risk-based IT audit plan (para 23).

Artefacts an auditor will ask for
  • Risk-based IT audit plan covering cyber risk
  • IT audit reports to the audit committee
  • Tracking of audit findings to remediation
Where this commonly fails
  • No IT audit coverage of cyber risk
  • Audit not independent of operations
  • Findings not remediated
BMA-8
Third-Party, Outsourcing and Cloud Risk

Third-Party, Outsourcing and Cloud Risk. Outsourced functions must be governed by service agreements with compliance terms; cloud services must be risk-assessed; end-user-developed systems and critical new projects must be assessed (paras 26-32).

Artefacts an auditor will ask for
  • Inventory of outsourced/third-party and cloud services
  • Service agreements with security and compliance terms
  • Cloud and end-user-computing risk assessments
  • Technology risk assessment for critical new projects
Where this commonly fails
  • Third-party/cloud services not risk-assessed
  • Service agreements lacking security terms
  • End-user-developed or critical-project systems unassessed

BMA Code Section VI: Detect and Protect Controls

BMA-10
Threat Intelligence and Vulnerability Alerting

Threat Intelligence and Vulnerability Alerting. RLEs should use threat intelligence and vulnerability alerting services to obtain information about new cyber threats and vulnerabilities to inform protective measures (para 34).

Artefacts an auditor will ask for
  • Subscription to threat intelligence / vulnerability alerting sources
  • Process for actioning threat and vulnerability information
  • Records of protective measures taken in response
Where this commonly fails
  • No threat-intelligence input to defence
  • Vulnerability alerts not actioned
  • Threat information not integrated into risk decisions
BMA-11
Information Technology Incident Management

IT Incident Management. An incident management process must be in place to restore normal IT service following an unexpected disruption, with minimal impact to business operations (para 35).

Artefacts an auditor will ask for
  • Documented IT incident management process
  • Incident tickets with timelines and resolution
  • Service-restoration objectives
Where this commonly fails
  • No formal incident management process
  • Incidents not logged or timed
  • No restoration objectives
BMA-14
IT Security Incident Management and Response Team

IT Security Incident Management. A formal IT security incident response process must be established, with consideration of a computer security incident response team, post-incident root-cause review, defined crisis escalation, and annual tabletop exercises (paras 36-40).

Artefacts an auditor will ask for
  • Documented security incident response process and CSIRT arrangements
  • Post-incident review reports with root cause and remedial actions
  • Crisis escalation criteria and communications plan
  • Annual tabletop exercise records
Where this commonly fails
  • No formal security incident response process
  • Post-incident reviews not performed
  • No tabletop exercises
  • Crisis escalation undefined
BMA-15
Notification of Cyber Reporting Events to the Authority

Notification of Cyber Reporting Events to the Authority. RLEs must report cyber reporting events that result in significant adverse impact to the BMA, consult the Authority when in doubt, and maintain logs of all cybersecurity incidents with timelines (paras 41-44).

Artefacts an auditor will ask for
  • Procedure for assessing and reporting cyber reporting events to the BMA
  • Records of notifications made to the Authority within required timeframes
  • Log of all cybersecurity incidents with timelines
Where this commonly fails
  • Reportable events not notified to the BMA
  • No criteria for significant adverse impact
  • Incident logs not maintained
BMA-16
Access Management and Segregation of Duties

Access Management and Segregation of Duties. Procedures must manage the allocation of access rights to information systems, and roles and areas of responsibility should be segregated to minimise the risk of unauthorised or unintentional modification or misuse (paras 45-46).

Artefacts an auditor will ask for
  • Access provisioning/de-provisioning procedures and approvals
  • Periodic access reviews
  • Segregation-of-duties matrix and conflict monitoring
Where this commonly fails
  • Access rights not reviewed
  • No segregation of duties
  • Privileged access uncontrolled
BMA-17
Staff Cyber Risk Awareness Training

Staff Cyber Risk Awareness Training. Staff cyber risk awareness training must be completed at least annually, with additional training for staff in roles responsible for cyber risk (para 47).

Artefacts an auditor will ask for
  • Annual security awareness training programme and completion records
  • Role-specific training for cyber-risk personnel
  • Phishing/awareness assessment results
Where this commonly fails
  • Annual training not completed by all staff
  • No role-specific training
  • Effectiveness not measured
BMA-18
Data Classification and Security

Data Classification and Security. Information must be classified and protected commensurate with its sensitivity, and data classified as non-public must be protected by an appropriate level of security (paras 48, 52, 54).

Artefacts an auditor will ask for
  • Data classification scheme and labelling
  • Protective controls mapped to classification levels
  • Inventory of non-public data and its protections
Where this commonly fails
  • No data classification scheme
  • Non-public data not adequately protected
  • Classification not applied consistently
BMA-19
Data Protection, Governance and Loss Prevention

Data Protection, Governance and Loss Prevention. RLEs must have Data Loss Prevention controls for primary business data, assess compliance with applicable data protection/privacy laws, and document data governance controls (paras 49-51).

Artefacts an auditor will ask for
  • DLP controls and monitoring for primary business data
  • Data protection/privacy compliance assessment per jurisdiction
  • Documented data governance controls
Where this commonly fails
  • No DLP controls
  • Data-protection compliance not assessed
  • Data governance undocumented
BMA-20
Malicious Code Controls

Malicious Code Controls. Controls to detect and block malicious code (or suitable mitigating controls) must be deployed at both endpoint and network level, covering viruses, ransomware, spyware, worms and trojans (para 53).

Artefacts an auditor will ask for
  • Anti-malware/EDR deployment at endpoint and network
  • Malware signature/behavioural update process
  • Detection and response records for malicious code
Where this commonly fails
  • Anti-malware not deployed at all layers
  • Definitions/behaviour models not updated
  • No response process for detections
BMA-21
Security Testing Programme

Security Testing Programme. RLEs must assess their risk and determine a suitable security testing programme (for example vulnerability assessment and penetration testing) commensurate with that risk (para 56).

Artefacts an auditor will ask for
  • Risk-based security testing programme (VA/penetration testing schedule)
  • Test reports and remediation tracking
  • Retesting evidence for closed findings
Where this commonly fails
  • No security testing programme
  • Testing not risk-based
  • Findings not remediated/retested
BMA-22
Patch Management

Patch Management. RLEs must have patch management procedures that define the identification, categorisation, prioritisation and timely deployment of patches (para 57).

Artefacts an auditor will ask for
  • Patch management policy and SLAs by severity
  • Patch deployment records and exceptions
  • Evidence of timely remediation of critical patches
Where this commonly fails
  • No patch management SLAs
  • Critical patches delayed
  • Exceptions not tracked or risk-accepted
BMA-23
Data Deletion, Sanitisation and Disposal

Data Deletion, Sanitisation and Disposal. RLEs must have documented procedures for the deletion, sanitisation and disposal of all storage media and data (para 58).

Artefacts an auditor will ask for
  • Media sanitisation/disposal procedures and certificates
  • Asset disposal records
  • Verification of sanitisation before reuse/disposal
Where this commonly fails
  • Media not sanitised before disposal/reuse
  • No disposal records
  • Cryptographic erasure not verified
BMA-24
Network Security Management

Network Security Management. Network security standards must be documented in a formal document, and network segregation should be applied to limit the spread of compromise (para 59).

Artefacts an auditor will ask for
  • Documented network security standards
  • Network architecture/segmentation diagrams
  • Firewall and boundary control configurations and reviews
Where this commonly fails
  • No documented network standards
  • Flat network without segmentation
  • Boundary controls not reviewed
BMA-25
Use of Cryptography

Use of Cryptography. RLEs must protect information using appropriate cryptography, including encryption of non-public data at rest and in transit, with documented key management.

Artefacts an auditor will ask for
  • Cryptography standard and approved algorithms
  • Encryption of non-public data at rest and in transit
  • Key management policy and procedures
Where this commonly fails
  • Sensitive data not encrypted
  • Weak/unapproved algorithms
  • No key management
BMA-9
Information Technology Services Management

IT Services Management. IT service management processes must support stable services, covering configuration management, change management, software release management, incident and problem management, and performance and capacity management (para 33).

Artefacts an auditor will ask for
  • Documented configuration and change management processes
  • Software release and problem management records
  • Capacity/performance management evidence
Where this commonly fails
  • Changes made without change control
  • No configuration baseline
  • Capacity not managed

BMA Code Section VII: Response and Recovery Controls

BMA-26
Business Continuity and Disaster Recovery Planning

Business Continuity and Disaster Recovery Planning. RLEs must implement effective BCP and DR policies and procedures, including regular documented business impact analysis and BCP/DR plans tested at least annually with issues tracked to remediation (para 66).

Artefacts an auditor will ask for
  • BCP and DR policies and plans
  • Documented business impact analysis
  • Annual BCP/DR test results with issues tracked to remediation
Where this commonly fails
  • BCP/DR plans untested
  • No business impact analysis
  • Test issues not remediated

BMA Code Sections III-IV: Interpretation and Proportionality

BMA-1
Interpretation

Interpretation. Section III defines how the Code is to be read, including the regulated licensed entities (RLEs) in scope and the meaning of operational cyber risk for the purposes of the Code.

Artefacts an auditor will ask for
  • Confirmation of RLE status and which sector code applies
  • Scoping document identifying systems and operations subject to the Code
Where this commonly fails
  • RLE status or scope misidentified
  • Code obligations not mapped to the entity's operations
BMA-2
Proportionality Principle

Proportionality Principle. Section IV requires that the operational cyber risk management framework be proportionate to the nature, scale and complexity of the RLE's business and its cyber risk profile.

Artefacts an auditor will ask for
  • Documented proportionality assessment linking control depth to business scale and risk
  • Board rationale for the chosen maturity of the programme
Where this commonly fails
  • Controls not scaled to risk/complexity
  • No documented proportionality rationale
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.