Skip to main content
Link to Walkers homepage

What you need to know about Bermuda's new Digital Identity Service Provider Regime

May 1, 2025

Advisory
A sleek black pen with 'Walkers' branding lies atop a closed notebook, both featuring raised 'Walkers' logos.

Key Takeaways

  • A new licensing regime for digital identity service providers is to be introduced in Bermuda.
  • The new licensing regime should pave the way for a smoother CDD journey for consumers, without compromising Bermuda's high AML/ATF standards.
  • The tiered licensing regime will be mandatory for businesses that provide digital identity services.

The key role for DISPs is in the onboarding journey for consumers in financial services.

Introduction

In November 2024, the Bermuda Monetary Authority (the "BMA") released a consultation on a proposed new framework for the licensing and supervision of providers of non-governmental digital identities for individuals in Bermuda, digital identity service providers or "DISPs". 

On 29 April, the BMA released a "Dear Stakeholders" letter outlining the key responses to the consultation and the resulting regulatory approach to the supervision of DISPs.

In this advisory we explain the role of DISPs, the need for regulation and the proposed new framework for DISPs' supervision.

What is a digital identity?

A digital identity is a body of information that allows the identity of an individual to be verified in an online environment.  

A digital identity system comprises of core components:

  • Identity proofing and enrolment, with initial binding and credentialing, answering the question, "who are you?".
  • Authentication and identity lifecycle information, answering the question, "are you the person who has been identified and verified?".  
  • Portability and interoperability mechanisms, enabling the digital identity to be used to prove identity at multiple places, public and private.

The role of DISPs and the need for regulation

The key role for DISPs is in the onboarding journey for consumers in financial services. Financial institutions are legally obliged to conduct customer due diligence ("CDD") to ensure they know who they are transacting with and what that person is eligible to do. Identity theft means that organisations cannot rely on a person simply claiming to be who they are, instead robust independent identity verification is required.

Increasingly, consumers expect onboarding to be online and immediate. Friction points commonly experienced by domestic customers of Bermuda financial institutions arise during an account opening when, to establish an account, a customer's identity must be verified by submitting documents that first need to be obtained and certified. Friction points also arise when customers need to interact separately with each of their financial service providers, repeating the same process. Further, they may be required on a regular basis to update their identity information as part of ongoing CDD process.

DISPs provide benefits to the CDD journey that can greatly accelerate consumer access to financial services whilst also alleviating burden on financial institutions inherent in CDD, if they can rely on the DISPs services for verification of their customers' identities. 

Whilst such benefits are significant, DISPs also come with risk. The most significant risk related to DISPs is the creation of a repository of personal information that is extremely attractive to threat actors that hack, misuse and sell personal data. Introducing a regulatory regime that scrutinises the cyber security and data controls in place should assist with ensuring a high level of minimum standards are in place to sufficiently mitigate this risk and allow for the benefits described.

Scope of the New Framework

The BMA's consultation put forward five activities that make up the end-to-end processes in a digital identity service:

  • Conducting identity proofing by validating evidence and verifying that the validated evidence relates to the applicant. 
  • Managing a subscriber's primary authentication credentials and issuing assertions derived from those credentials to the party relying on the DISP's services. 
  • Issuing and/or registering authenticators and corresponding electronic credentials (binding the authenticators to the verified identity) to subscribers. 
  • Provision of enrolment services; and
  • Verify the claimant's identity for a relying party by confirming the claimant's possession and control of one or more authenticators using an authentication protocol. 

We anticipate these will inform what will become the "licensable activities" under the new regime. Further details regarding licensable activities will be set out in an illustrative draft bill and subject to appropriate consultation.

In the November consultation, the BMA asked stakeholders whether companies providing limited activities (e.g. only 2 of the 5 above), rather than the full end-to-end services, should be in scope of the new framework. 

The Dear Stakeholder letter confirms that all providers engaging in licensable activities under the Act will be required to comply with the regulatory provisions, even if not providing all end-to-end services, unless they are operating solely as an outsourced service provider to a licensed DISP. This result is positive as the alternative gave rise to the risk of regulatory arbitrage. 

Outsourcing 

As the above foreshadows, DISPs will be permitted to rely on outsource providers for certain activities, though with the DISP retaining full responsibility for oversight.

Vetting Responsibilities

The consultation sought feedback on whether vetting responsibilities should be a required element of a DISP issuing a digital identity.

The proposed framework defines the role of DISPs as limited to identification and processes, which rely on official documents. Vetting responsibilities introduce CDD obligations, which the BMA considers more appropriately assigned to financial institutions and other relying parties. Given that AML/ATF requirements are risk based and differ by sector, under the regime DISPs will focus solely on issuing Digital IDs, while relying parties will determine the level of vetting required based on their regulatory compliance obligations and risk appetites.

Assurance, Portability and Interoperability

At this stage, the BMA does not intend to prescribe specific standards regarding international best practice. Nonetheless, the framework will establish core cybersecurity standards to ensure data protection which are aligned with the existing international standards applicable to Bermuda.

Licensing Approach

A tiered licensing framework will be implemented, designed to promote responsible innovation while upholding consumer protection and security.  This mirrors the digital asset business licensing model and the approach currently under consultation for payment service providers. 

It was also determined that the framework will be mandatory, rather than opt-in. It is not yet clear who it will be mandatory for, in relation to jurisdictional nexus.

Physical Presence Requirement

The BMA has determined that physical presence will continue to be a requirement to obtain a DISP licence. This requirement can be satisfied by appointing a designated senior representative in Bermuda.

Public-Private Partnership

The BMA confirmed that many stakeholders expressed support for a public-private partnership initiative, emphasising that a government issued Digital ID would likely encourage broader adoption and extend usage beyond financial services within Bermuda. The BMA has communicated this to Government. 

Next steps

The BMA will proceed with finalising the framework’s provisions and developing supporting regulatory instruments for further public consultation. 

Walkers is committed to engaging in the consultation and working with digital identity service providers in applying for DISP licenses in future.

 

 

FintechRegulatory & ComplianceBermuda

Authors

Leonie Tear

Leonie Tear

Partner/Bermuda

T/+1 441 242 1567
M/+1 441 525 1567
E/Email Leonie Tear
More articles from this author View profile

Key Contacts

Get in touch with our team

Leonie Tear
Leonie Tear

Leonie Tear

Partner

Bermuda

T

+1 441 242 1567

M

+1 441 525 1567

E

Email Leonie Tear
View profile

Get the latest insights and expertise in your inbox 

Fluid ink image
Sign up
logo footer

Connect with us

FacebookFacebook
InstagramInstagram
LinkedInLinkedIn

Employee login

Self Service Password ResetWalkers AnywhereWalkers Sharefile
Legal notices/Cookies policy

All rights reserved - © 2025 Walkers Global