Bermuda insurers need internal audit and risk professionals who understand the business they challenge. That does not make the two functions interchangeable. Risk management helps the business identify, assess and manage risk. Internal audit provides independent assurance on governance, risk management and controls.
The BMA Insurance Code of Conduct says the internal audit function should be independent of operational functions, including risk management, compliance, underwriting, claims, operations and finance. A vacancy that combines ownership of a control with independent assurance over the same control creates a structural problem before recruitment begins.
How does the BMA agenda affect audit and risk hiring?
It widens what assurance and risk functions must cover, from group supervision and cyber to documented annual accountability, without proving a measured rise in vacancies.
The BMA 2026 Business Plan proposes stronger management and governance accountability alongside further work on climate, investment disclosure and group supervision; our ComFrame article covers the actuarial side. Two measures already in force add to the assurance agenda. From 1 January 2026, Class C, Class D and Class E insurers other than those carrying on domestic business must file an annual Asset and Liability Statement signed by the chief executive and a senior executive responsible for actuarial or investment management, risk management, internal audit or compliance. Relevant entities must also adhere to the Operational Resilience and Outsourcing Code by 31 March 2028. Together the measures expand documented accountability and the assurance work that audit and risk functions may need to support, although their governance requirements differ.
The Code is direct about internal audit: a clear charter, unrestricted access, suitable authority, sufficient resources and fit and proper staff, examining whether governance, risk management, policies, procedures and controls are adequate and effective. For employers, that turns a broad request for an auditor into several possible mandates.
Which role does the organisation need?
One of six, each with a different independence question: head of internal audit, insurance audit specialist, captive audit specialist, enterprise risk leader, technology and cyber audit specialist, or model and investment risk specialist.
Head of internal audit
Needs independence, access to the board or audit committee, authority to set a risk based plan and the judgement to escalate difficult findings. Insurance knowledge matters because the audit universe may include underwriting, claims, reserving, investments, reinsurance, BSCR capital reporting, outsourcing and regulatory reporting.
Insurance internal audit specialist
Leads or supports reviews in one part of that universe. Name the area and the level of assurance required. A general auditor with strong method may be viable when the organisation can support domain learning; a BMA facing or technically complex review may require insurance evidence from the start.
Captive insurance audit specialist
Bermuda is home to more than 600 captives. Captive audit is a distinct specialism: a captive is owned by a corporate parent, writes the parent’s own risks and often sits in a complex multi line structure, so its governance has to be understood in both insurance and corporate terms. Test that combination directly rather than assuming a reinsurance auditor transfers.
Enterprise risk leader
Helps management and the board understand material exposures, risk appetite, limits and responses. Should not be described as independent assurance if it also designs or operates the framework being reviewed.
Technology and cyber audit specialist
The BMA’s 2025 operational cyber report says regulated entities should maintain a cyber risk programme proportionate to their nature, scale and complexity, and recognises third party technology services. Briefs should state whether the immediate problem is governance, resilience, access, data, outsourcing, incident response or technical testing.
Model or investment risk specialist
In Bermuda this includes catastrophe models, pricing models and the BSCR capital calculation. A second line model risk professional sets standards and challenges model owners; internal audit assesses the framework’s design and effectiveness without becoming its operator.
What should an audit or risk hiring brief contain?
The same six elements answered differently for assurance and for risk.
Brief element | Internal audit question | Risk management question |
|---|
Purpose | What independent assurance must the board receive? | Which exposure or decision must management improve? |
Reporting line | Who protects the function’s independence and access? | Which executive is accountable for the framework and accepts the advice? |
Scope | Which entities, processes and risks enter the audit universe? | Which risks, limits and management actions enter the mandate? |
Technical evidence | What has the candidate audited and how did they test it? | What has the candidate measured, challenged or changed? |
Regulatory context | Which BMA requirements must the person interpret for assurance? | Which requirements shape the control or risk process? |
First year result | What assurance gap must close? | What decision, limit or response must improve? |
In our audit and risk searches, unclear independence is often visible in the job description: the same role is asked to design the framework, approve a decision and audit the result. Separating those responsibilities makes the search more credible and tells candidates whether they are joining management, oversight or independent assurance.
How should employers assess specialist evidence?
With a case from the real mandate, scored on method, domain, judgement, communication and independence separately, and references that test personal contribution.
For an audit role, give a process, a stated control and incomplete evidence, and ask how they would define the objective, test design and operation, judge the finding and communicate it. For a risk role, give a material exposure, a limit and conflicting management views, and ask what is missing, which decision belongs to management and when they would escalate. A credential is evidence of professional foundation, not proof of insurance application. References should test what the person reviewed or decided, which evidence changed their view and what remained after the engagement. The IIA’s Global Internal Audit Standards, effective 9 January 2025, give a current basis for framing the mandate; do not turn every principle into a keyword.
Our audit recruitment practice covers internal audit and assurance roles, our risk and financial advisory practice covers enterprise risk and controls mandates, and our reinsurance industry practice supplies the market context. Our guide to the India to Bermuda talent corridor covers international audit and risk evidence.
Should the function build, buy or combine capability?
Delegation is permitted, but an internal owner of the plan, the board relationship and follow through is still required.
The Code permits an internal audit function to be delegated to a third party without removing the need for authority, access and oversight. A permanent hire is stronger when the work is recurring or the board needs a stable accountable relationship; external support suits a rare technical review or temporary capacity. Use both when the boundary is explicit: who sets the plan, who performs the work, who judges the result and who tracks management action.