Frequently Asked Questions (FAQs)
This section provides Frequently Asked Questions (FAQs) to assist financial services providers in understanding the Rule on Effective Compliance Programme for the Prevention and Detection of Money Laundering, Terrorist Financing and Proliferation Financing for Financial Services Providers and the Rule on Compliance with Financial Sanctions and Targeted Financial Sanctions.
The Cayman Islands Monetary Authority (the “Authority” or “CIMA”) has issued two (2) new Rules:
(together, the “Rules”) which will come into effect on Friday, 18 September 2026.
The objective of these Rules is to support and promote an effective, proportionate, and risk-based framework that enables regulated entities in scope to identify, assess, manage, and mitigate ML, TF, PF, and sanctions-related risks. These Rules also align with CIMA’s strategic objective to “provide support for improving effectiveness in combating financial crime and a positive assessment on the FATF 5th Round Review of the Cayman Islands.”
CIMA has developed these FAQs to support industry’s implementation and application of these Rules and to provide general clarification on their compliance obligations, with respect to:
The Rule is issued to provide clarity to Financial Service Providers (“FSPs") on Anti Money Laundering, Countering the Financing of Terrorism and Countering Proliferation Financing ("AML/CFT/CPF") obligations and to support the strengthening of the effectiveness of AML/CFT/CPF Compliance Programmes for Financial Services Providers ("FSPs"). The Rule is expected to enhance governance, accountability, and the consistent implementation of effective AML/CFT/CPF measures.
The Rule supports the Authority's efforts to enhance its risk-based supervisory approach by providing an additional supervisory tool to assess the design, implementation, and effectiveness of an FSP's AML/CFT/CPF Compliance Programme. This enables the Authority to undertake more informed, consistent, and targeted supervision based on the nature, scale, complexity, and risk profile of an FSP.
The framework remains risk-based. The Rule establishes minimum requirements while allowing flexibility in implementation, based on proportionality.
The Authority will apply the Rule as part of its risk-based supervisory framework. The nature of supervisory engagement will be proportionate to the size, nature, scale, complexity, and risk profile of the FSP.
The Rule will enable the Authority to utilise a broad range of additional risk-based on-site and off-site supervisory tools to assess the design, implementation, and effectiveness of an FSP's AML/CFT/CPF Compliance Programme and will be incorporated into the Authority's supervisory reviews and inspection activities. These risk-based supervisory tools will include, inter alia, on-site inspections, desk-based reviews, and risk and compliance meetings.
In general, for high and medium risk entities onsite inspections are a more appropriate supervisory tool. However, for those entities rated medium or otherwise, a desk based review would be more reasonable tool in accordance with a risk based approach. These reviews may also serve to supplement and bridge the period between onsite inspections.
The Authority's risk-based supervisory approach will continue to evolve based on emerging risks, supervisory findings, and changes in the risk profile of each regulated sector.
The Rule is intended to strengthen existing AML/CFT/CPF requirements under the Anti-Money Laundering Regulations ("AMLRs"). Accordingly, many of the provisions in the Rule do not introduce new obligations but rather enhance the Authority's expectations for the design, implementation, and maintenance of an Effective AML/CFT/CPF Compliance Programme.
Upon the Rule becoming effective, the Authority will continue to apply its risk-based supervisory approach when assessing compliance with AML/CFT/CPF obligations. Compliance with the Rule may be assessed through onsite inspections, desk-based reviews, thematic reviews, and other supervisory engagements, with the type of review being informed by the risk profile of the FSP.
Additionally, the Authority takes a risk-based approach to its enforcement actions. As such, the Authority does not intend to adopt a blanket enforcement approach upon the Rule's effective date. In particular, the Administrative Fines framework applicable to breaches of the Rule is not yet in effect. Rather, the Rule will form part of the Authority's risk-based supervisory toolkit for assessing the effectiveness of an FSP's AML/CFT/CPF Compliance Programme and its compliance with applicable AML/CFT/CPF requirements.
Any additional compliance costs will depend on the size, structure, complexity, and nature of the business, as well as the entity's risk profile and the extent to which it has already implemented its AML/CFT/CPF framework. FSPs with robust existing frameworks are expected to require only limited enhancements to align with the proposed requirements.
The AML/CFT/CPF Compliance Programme obligations apply to all FSPs that conduct “Relevant Financial Business” as defined under the Proceeds of Crime Act (as amended) ("POCA") and are regulated by the Authority under the Regulatory Acts, including branches, subsidiaries, affiliates, and any other members of a CIMA-regulated financial group, regardless of their business model or outsourcing arrangements.
The Governing Body should demonstrate effective oversight of the Compliance Programme by ensuring that it exercises appropriate and proportionate governance over the design, implementation and ongoing effectiveness of the programme. This includes, inter alia, ensuring that it:
This oversight should be evidenced through appropriate governance records, including Governing Body or committee minutes, reports, documented decisions, and the tracking of remediation actions, where applicable.
The Rule supplements the Anti-Money Laundering Regulations (as amended) ("AMLRs") and should be read in conjunction with them. The AMLRs remain the primary legal basis for AML/CFT/CPF compliance, and if there is any inconsistency between the provisions of the Rule and the AMLRs, the AMLRs will prevail.
The Authority's power to issue the Rule is drawn from sections 6(3)(b) and 34(1) of the Monetary Authority Act (as amended).
The AMLCO is expected to ensure that the requirements set out in the Rule and the AMLRs are adopted by the FSP. An AMLCO may be personally liable for an FSP’s AML compliance failure where this amounts to a breach of the AMLRs and the breach is attributable to the AMLCO’s conduct. However, the FSP remains ultimately responsible for AML/CFT/CPF compliance.
The AMLCO should possess:
Independence refers to functional and reporting autonomy that is sufficient to allow the AMLCO to discharge their AML/CFT/CPF/TFS responsibilities objectively, free from conflict of interest, and have the authority to escalate issues directly to senior management and/or the Governing Body. It does not necessarily require complete separation from all business activities.
Depending on the size, nature, and complexity of the FSP, the AMLCO may perform additional operational duties. However, the FSP should be able to demonstrate to the Authority that these additional responsibilities do not impair the AMLCO's independence, create a conflict of interest, or impede the effective discharge of their AML/CFT/CPF/TFS responsibilities.
Subject to applicable AMLRs requirements, the AMLCO function may be performed by an appropriately qualified individual who is either employed by the FSP or engaged through an outsourcing arrangement. Where the function is outsourced, the FSP must ensure that the AMLCO has sufficient authority, independence, resources, and access to information to discharge their responsibilities effectively. Outsourcing does not transfer accountability away from the FSP or its Governing Body.
Where permitted under applicable laws and regulations, one individual may perform multiple AML roles, provided that the FSP can demonstrate to the Authority that any actual or potential conflicts of interest are appropriately managed and that the individual can effectively discharge all assigned responsibilities.
Documentation demonstrates how ML/TF/PF/TFS risks have been identified, assessed, mitigated, monitored and reviewed. It provides evidence of compliance with applicable AML/CFT/CPF/TFS requirements; supports effective governance and decision-making; and enables the FSP to demonstrate the rationale for its risk assessments and control measures. Moreover, documenting the risk-based approach also facilitates independent review, internal oversight and supervisory assessment by the Authority.
The documentation supporting the risk-based approach should be proportionate to the nature, size, complexity, and risk profile of the FSP. As applicable, the documentation should include:
The documentation should be maintained to demonstrate how the FSP has applied its risk-based approach in practice. It should be reviewed and updated periodically, and whenever there are material changes to the FSP's business activities, customer base, products and services, delivery channels, geographic exposure, or other relevant risk factors, to ensure it remains appropriate to the FSP's risk profile.
Risk factors should include those identified in the AMLRs, including:
Customer due diligence and ongoing monitoring measures should be commensurate with the ML/TF/PF/TFS risks identified by the FSP. Accordingly, the risk-based approach requires that the nature and extent of these measures be proportionate to the customer's assessed risk profile.
Group assessments may be utilised where appropriate; however, FSPs must ensure ML/TF/PF/TFS risks specific to their Cayman Islands operations are adequately identified and addressed.
The Rule reinforces the existing AMLRs requirements for CDD, including the expectation that FSPs apply CDD using a risk-based approach that is commensurate with their ML/TF/PF/TFS risks.
Identification and verification should generally occur before or at the time of establishing a business relationship. In limited risk-based circumstances, completion may occur as soon as practicable thereafter, where permitted by the AMLRs and appropriately managed. These circumstances are when risks are presented as low, and there is no conflict with what is prescribed in the AMLRs.
The Rule reflects existing supervisory expectations regarding outsourcing arrangements and reinforces the responsibilities of FSPs to maintain effective oversight and accountability for outsourced functions.
The FSP and its Governing Body remain ultimately responsible for compliance with AML/CFT/CPF/TFS obligations.
FSPs and their Governing Body should maintain effective oversight of outsourced arrangements, including:
While an FSP may outsource certain AML/CFT/CPF/TFS activities, it remains ultimately responsible and accountable for compliance with applicable AML/CFT/CPF/TFS requirements. Accordingly, the FSP should maintain effective oversight of all outsourced activities and ensure that ML/TF/PF/TFS risks are appropriately identified, assessed, monitored, and managed.
A documented programme helps to ensure that AML/CFT/CPF/TFS training is structured, risk-based and appropriate to employees' roles and responsibilities. It also enables the FSP to demonstrate compliance with applicable training requirements and monitor the effectiveness of its training programme.
The content and frequency of training should be appropriate to employees' roles, responsibilities, and risk exposure. The programme should include, inter alia:
The FSP’s training programme should be administered on an ongoing basis and delivered at least annually. The frequency of the ongoing training should be determined using a risk-based approach and must ensure that employees remain competent and aware of evolving risks and obligations.
All staff require AML training, but the type, depth, and frequency should be tailored to align with an employee’s role, responsibilities, and exposure to ML/TF/PF/TFS risks.
FSPs should implement risk-based screening measures appropriate to their size, structure, nature, and risk profile to help ensure that employees, particularly those performing AML-related functions, are fit and proper for their roles.
The requirement for FSPs to carry out effective, risk-based AML Audits of the AML/CFT/CPF/TFS function already exists under the AMLRs. The Rule provides additional clarity regarding supervisory requirements and how effectiveness should be demonstrated.
The requirement for Regulated Entities to carry out effective, risk-based AML Audits of the AML/CFT/CPF/TFS function already exists under the AMLRs.
As such, the Rule does not prescribe a universal first-filing date, an industry-wide completion date, or a simultaneous submission requirement. Regulated entities may submit the final report for an audit completed in accordance with their existing risk-based audit plan. If this is the first instance of an audit being completed, then an audit must be completed in compliance with the pre-existing audit regulatory requirements, and the audit report must be submitted after the completion of the audit. Thereafter, AML Audit reports should be submitted to the Authority in accordance with the Regulated Entity’s applicable audit cycle.
No. The Rule does not require FSPs to conduct or commission an AML/CFT/CPF audit solely because the Rule has become effective.
As part of its risk-based supervisory approach, the Authority intends to first consider the FSP’s risk assessment and resulting risk profile. This assessment will inform the Authority’s consideration of the FSP’s audit arrangements and whether the frequency and scope of the audit are appropriate and commensurate with the risks identified.
Accordingly, the Authority expects an FSP’s risk assessment to inform its audit programme, including when an audit should be conducted, how frequently it should be undertaken, and the areas that should be included within its scope.
For example, where an FSP is newly established, and its risk assessment supports a low-risk profile, the Authority would not ordinarily expect the FSP to have conducted an AML/CFT/CPF audit solely to meet the effective date of the Rule. Conversely, the risk profile of a higher-risk or more complex FSP may warrant more frequent or comprehensive audit coverage.
This does not, however, restrict the Authority from requiring an FSP to conduct an AML/CFT/CPF audit where the Authority considers it appropriate, including where such a requirement arises from the findings of a supervisory review, inspection, or other assessment of the FSP’s Compliance Programme.
The Rule does not mandate annual AML Audits. The frequency, scope and depth of AML Audits should be determined using a risk-based approach, considering the FSP's size, complexity, business activities and ML/TF/PF/TFS risk exposure.
The Authority does not prescribe a standardised audit report format or methodology. Consistent with the risk-based framework, each regulated entity is expected to develop and implement an audit plan, scope, and testing programme that is proportionate to the size, nature, and risk profile. Consequently, a uniform audit template or report format would not be appropriate across all regulated entities.
Notwithstanding the absence of a prescribed format, audit reports should include an assessment of the effectiveness of all applicable components of the Regulated Entity’s AML/CFT/CPF Compliance Programmes outlined in the Rule and any applicable regulatory requirements and clearly document the deficiencies identified, including instances of substantive non-compliance with the applicable requirements.
The scope of the audit should be proportionate to the size, nature, scale, and complexity of the FSP's business and operations. In determining the audit scope, the Governing Body and Senior Management should consider the following areas:
There is no prescribed frequency. FSPs should determine and document the appropriate frequency, taking into account their risk profile, documented risk assessment and level of assurance required over the effectiveness of their AML/ CFT/CPF/TFS Compliance Programme. For example, if an FSP is rated higher risk, it might be reasonable that an AML Audit is conducted every two (2) years. Whereas for medium and low risk, the frequency of AML Audits may be every 3 and 4 years respectively. The frequency and intensity of an AML Audit should depend on the FSP’s overall risk rating while incorporating the nature, size and complexity of the operations.
The AMLCO, MLRO, and DMLRO form part of the Compliance Programme and therefore cannot independently audit activities for which they have responsibility. This applies regardless of whether those functions are performed internally or through an outsourcing arrangement.
An AML Audit may be conducted by:
The auditor must be independent of the AML/CFT/CPF/TFS function and activities being audited and must not be involved in the operation, management or oversight of the Compliance Programme.
Independence means that the auditor is free from actual or perceived conflicts of interest and is not responsible for the design, operation, management or oversight of the Compliance Programme. This enables the auditor to provide an objective and impartial assessment of the effectiveness of the Compliance Programme.
A regulated investment fund (the “Fund” or “Funds”) must still undertake an AML Audit, as required under Regulation 5(a)(ix) of the AMLRs, even if all, or substantially all, of its operations are outsourced. The scope and frequency of the independent audit should be determined using a risk-based approach, considering the Fund’s structure, business activities, outsourced service provider arrangements and ML/TF/PF/TFS risk profile.
For AML Audits of Funds, consideration needs to be given to the specific Fund’s policies, controls and procedures, which should incorporate investor onboarding controls, ongoing due diligence, investment objective and policies, third party relationships/outsourcing, internal reporting, training programme, record keeping and the application of a risk-based approach.
The Authority expects that an AML Audit of an individual Fund(s) should obtain sufficient and appropriate evidence to conclude on the design and operating effectiveness of the Compliance Programme of the individual Fund(s). Accordingly, relying solely on a service-provider-level internal audit or a population-based review, without obtaining sufficient evidence regarding the individual Fund's Compliance Programme, would not provide sufficient assurance of the effectiveness of the AML Audit.
The Authority does not prescribe a single risk-based audit methodology. The auditor may adopt an approach proportionate to the nature, scale and complexity of a Fund(s). However, using a risk-based approach, the auditor should obtain sufficient and appropriate evidence to support conclusions regarding the design and effectiveness of the Compliance Programme as applicable to each Fund, considering its individual risk profile, governance arrangements, outsourced activities and AML/CFT/CPF/TFS obligations.
AML Audits may use risk-based sampling methodologies, provided the sampling approach is proportionate to the FSP's size, nature, complexity, and ML/TF/PF risk profile. The Independent Auditor should be able to demonstrate that the sample selected provides sufficient coverage to assess the effectiveness of the FSP's AML Compliance Programme.
Where AML functions have been outsourced, the regulated fund remains responsible for ensuring that its AML Compliance Programme is independently audited. While a service provider-level audit may provide assurance regarding the service provider's processes, controls, and the operation of its compliance framework, it will not, on its own, provide sufficient assurance over the FSP's compliance with its AML obligations. Accordingly, the AML Audit should also include testing that is specific to the FSP, including review of how the outsourced arrangements are implemented and operate in practice for that FSP.
Example: Where sanctions screening has been outsourced to an outsourced service provider (“OSP”), the Independent Auditor would obtain and review evidence of the OSP's sanctions screening policies and procedures, testing performed by the OSP, and testing results relevant to the specific FSP.
A regulated entity may rely on a service provider's AML Audit where the audit adequately assesses all elements of the regulated entity's AML Compliance Programme.
The service provider's AML Audit must include testing and assessment that is specific to the FSP's own AML Compliance Programme and controls. An audit of the service provider's general AML framework, without consideration of the FSP's specific programme, would not be sufficient.
This requirement helps mitigate the risks of familiarity, self-review, and loss of objectivity by ensuring that a periodic external assessment of the Compliance Programme is carried out. It provides an additional level of assurance and helps identify potential gaps or weaknesses in the effectiveness of an FSP’s internal control procedures through an objective and independent review.
Yes. Findings, exceptions, or deficiencies do not automatically invalidate an AML Audit. These findings highlight areas requiring remediation and may inform the Authority's supervisory assessment.
The Rule applies only where an insurer or reinsurer is conducting "Relevant Financial Business" as defined under the POCA (as amended).
The RFB Self‑Declaration does not replace the requirement for independent audit and testing of the insurer or reinsurer’s AML/CFT/CPF/TFS Compliance Programme. The RFB Return is an attestation by the FSP and is not a substitute for objective assurance of the effectiveness of its Compliance Programme.
This Rule is issued to promote compliance by Regulated Persons with existing domestic and international legal obligations related to financial sanctions that are in force in the Cayman Islands.
Sanctions obligations apply to all natural persons, legal arrangements and legal persons in the Cayman Islands. Therefore, this Rule applies to all Regulated Persons supervised by the Authority pursuant to the Regulatory Acts, whether or not they conduct Relevant Financial Business.
CIMA recognises the FRA’s role as the Competent Authority for handling financial sanctions, as designated by the Governor of the Cayman Islands. This Rule reinforces requirements for Regulated Persons to comply with the FRA’s reporting guidelines and their obligations under Cayman’s TFS legislative framework.
These FAQs are a part of the Authority’s ongoing outreach efforts and continued engagement with industry. The FAQs do not replace or amend the Rules and should be read in conjunction with the Rules and relevant legislation.
Be the first to know about releases and industry news and insights.