For a better experience on Cayman Islands Monetary Authority, update your browser.

Frequently Asked Questions (FAQs)

This section provides Frequently Asked Questions (FAQs) to assist financial services providers in understanding the Rule on Effective Compliance Programme for the Prevention and Detection of Money Laundering, Terrorist Financing and Proliferation Financing for Financial Services Providers and the Rule on Compliance with Financial Sanctions and Targeted Financial Sanctions.

Introduction

The Cayman Islands Monetary Authority (the “Authority” or “CIMA”) has issued two (2) new Rules:

  1. The Rule on Effective Compliance Programme for the Prevention and Detection of Money Laundering, Terrorist Financing and Proliferation Financing for Financial Services Providers; and
  2. The Rule on Compliance with Financial Sanctions and Targeted Financial Sanctions. 

(together, the “Rules”) which will come into effect on Friday, 18 September 2026.

Background

The objective of these Rules is to support and promote an effective, proportionate, and risk-based framework that enables regulated entities in scope to identify, assess, manage, and mitigate ML, TF, PF, and sanctions-related risks. These Rules also align with CIMA’s strategic objective to “provide support for improving effectiveness in combating financial crime and a positive assessment on the FATF 5th Round Review of the Cayman Islands.”

CIMA has developed these FAQs to support industry’s implementation and application of these Rules and to provide general clarification on their compliance obligations, with respect to:

  • Governance and Anti-Money Laundering Compliance Officer (AMLCO) Requirements;
  • The Risk-Based Approach;
  • The Independent Audit Function; and
  • Financial Sanctions and Targeted Financial Sanctions.


Section 1: Frequently Asked Questions (FAQs) on the Rule on Effective Compliance Programme for the Prevention and Detection of Money Laundering, Terrorist Financing and Proliferation Financing for Financial Services Providers
 

General Questions


1. What is the Authority seeking to achieve through the Rule?

The Rule is intended to provide enhanced guidance with regards to applicable Anti-Money Laundering, Countering the Financing of Terrorism and Countering Proliferation Financing ("AML/CFT/CPF") obligations and to support the strengthening of the effectiveness of AML/CFT/CPF Compliance Programmes for Financial Services Providers ("FSPs"). It is expected to enhance governance, accountability, and the consistent implementation of effective AML/CFT/CPF measures, while supporting the Authority's risk-based supervisory approach.


2. Do the Rules create a more prescriptive AML framework?

The framework remains risk-based. The Rule establishes minimum requirements while allowing flexibility in implementation, based on proportionality.


3. Will FSPs’ compliance costs increase significantly?

Any additional compliance costs will depend on the size, structure, complexity, and nature of the business, as well as the entity's risk profile and the extent to which it has already implemented its AML/CFT/CPF framework. FSPs with robust existing frameworks are expected to require only limited enhancements to align with the proposed requirements.


4. Will sector-specific exemptions be granted?

The AML/CFT/CPF Compliance Programme obligations apply to all FSPs that conduct “Relevant Financial Business” as defined under the Proceeds of Crime Act (as amended) ("POCA") and are regulated by the Authority under the Regulatory Acts, including branches, subsidiaries, affiliates, and any other members of a CIMA-regulated financial group, regardless of their business model or outsourcing arrangements.


5. How should Governing Bodies of FSPs demonstrate effective oversight of the Compliance Programme?

The Governing Body should demonstrate effective oversight of the Compliance Programme by ensuring that it exercises appropriate and proportionate governance over the design, implementation and ongoing effectiveness of the programme. This includes, inter alia, ensuring that it:

  1. receives and reviews reports on the operation and effectiveness of the Compliance Programme;
  2. understands the FSP's exposure to Money Laundering, Terrorist Financing, Proliferation Financing and Targeted Financial Sanctions ("ML/TF/PF/TFS") risks arising from its business activities;
  3. provides appropriate challenge and oversight of management to support sound decision-making and effective management of ML/TF/PF/TFS risks;
  4. ensures that sufficient and appropriately qualified resources are allocated to implement and maintain an effective Compliance Programme; and
  5. oversees the timely implementation of corrective actions to address deficiencies or weaknesses identified through compliance monitoring, independent testing, internal audit, regulatory inspections, or other assessments of the Compliance Programme.

This oversight should be evidenced through appropriate governance records, including Governing Body or committee minutes, reports, documented decisions, and the tracking of remediation actions, where applicable.


Legal Authority and Interaction with the AML Regulations
 

6. How does the Rule interact with the AML Regulations?

The Rule supplements the Anti-Money Laundering Regulations (as amended) ("AMLRs") and should be read in conjunction with them. The AMLRs remain the primary legal basis for AML/CFT/CPF compliance, and if there is any inconsistency between the provisions of the Rule and the AMLRs, the AMLRs will prevail.


7.What is the Authority’s legal basis for issuing the Rule?

The Authority's power to issue the Rule is drawn from sections 6(3)(b) and 34(1) of the Monetary Authority Act (as amended).


Governance and Anti-Money Laundering Compliance Officer ("AMLCO") Requirements


8. Is the AMLCO personally accountable for all AML compliance failures?

The AMLCO is expected to ensure that the requirements set out in the Rule and the AMLRs are adopted by the FSP. An AMLCO may be personally liable for an FSP’s AML compliance failure where this amounts to a breach of the AMLRs and the breach is attributable to the AMLCO’s conduct. However, the FSP remains ultimately responsible for AML/CFT/CPF compliance.


9. What qualifications should an AMLCO possess?

The AMLCO should possess:

  • An appropriate professional qualification;
  • Relevant knowledge of the Cayman Islands AML/CFT/CPF/TFS framework;
  • Sufficient experience in AML/CFT/CPF/TFS compliance that is appropriate to the FSP's business activities, size, complexity, and risk profile; and
  • Good repute and integrity.

10. What does "independence" of the AMLCO mean?

Independence refers to functional and reporting autonomy that is sufficient to allow the AMLCO to discharge their AML/CFT/CPF/TFS responsibilities objectively, free from conflict of interest, and have the authority to escalate issues directly to senior management and/or the Governing Body.  It does not necessarily require complete separation from all business activities.


11. Can the AMLCO perform operational duties?

Depending on the size, nature, and complexity of the FSP, the AMLCO may perform additional operational duties. However, the FSP should be able to demonstrate to the Authority that these additional responsibilities do not impair the AMLCO's independence, create a conflict of interest, or impede the effective discharge of their AML/CFT/CPF/TFS responsibilities.


12. Must the AMLCO be employed by the FSP?

Subject to applicable AMLRs requirements, the AMLCO function may be performed by an appropriately qualified individual who is either employed by the FSP or engaged through an outsourcing arrangement. Where the function is outsourced, the FSP must ensure that the AMLCO has sufficient authority, independence, resources, and access to information to discharge their responsibilities effectively. Outsourcing does not transfer accountability away from the FSP or its Governing Body.


13. Can one individual perform multiple AML roles?

Where permitted under applicable laws and regulations, one individual may perform multiple AML roles, provided that the FSP can demonstrate to the Authority that any actual or potential conflicts of interest are appropriately managed and that the individual can effectively discharge all assigned responsibilities.


Risk-Based Approach


14. Why must the risk-based approach be documented?

Documentation demonstrates how ML/TF/PF/TFS risks have been identified, assessed, mitigated, monitored and reviewed. It provides evidence of compliance with applicable AML/CFT/CPF/TFS requirements; supports effective governance and decision-making; and enables the FSP to demonstrate the rationale for its risk assessments and control measures. Moreover, documenting the risk-based approach also facilitates independent review, internal oversight and supervisory assessment by the Authority.


15. What should be included in risk-based approach documentation?

The documentation supporting the risk-based approach should be proportionate to the nature, size, complexity, and risk profile of the FSP. As applicable, the documentation should include:

  • the policies, controls and procedures used to identify, assess, understand, and document ML/TF/PF/TFS risks in relation to customers, the country or geography in which the customer resides or operates, the products, services, transactions, and delivery channels;
  • the risk factors considered in assessing inherent and residual risks;
  • the risk rating policies, controls, and procedures, including the rationale for assigning risk ratings;
  • policies, procedures, controls and other risk mitigation measures implemented to manage identified risks;
  • the policies, controls and procedures for ongoing monitoring, periodic reviews, and updating risk assessments; and
  • the governance, approval and oversight arrangements supporting the application of the risk-based approach.

The documentation should be maintained to demonstrate how the FSP has applied its risk-based approach in practice. It should be reviewed and updated periodically, and whenever there are material changes to the FSP's business activities, customer base, products and services, delivery channels, geographic exposure, or other relevant risk factors, to ensure it remains appropriate to the FSP's risk profile.


16. What risk factors should be considered?

Risk factors should include those identified in the AMLRs, including:

  • Customer risks;
  • Geographic or country risks;
  • Product or service risks
  • Transaction risks;  
  • Delivery channel risks; and
  • Other relevant ML/TF/PF/TFS risk indicators.

17. Must all customers be treated the same?

Customer due diligence and ongoing monitoring measures should be commensurate with the ML/TF/PF/TFS risks identified by the FSP. Accordingly, the risk-based approach requires that the nature and extent of these measures be proportionate to the customer's assessed risk profile.


18. Can risk assessments be performed at a group level?

Group assessments may be utilised where appropriate; however, FSPs must ensure ML/TF/PF/TFS risks specific to their Cayman Islands operations are adequately identified and addressed.

 

Policies, Procedures, and Operational Flexibility
 

19. Does the Rule change Customer Due Diligence (“CDD”) requirements?

The Rule reinforces the existing AMLRs requirements for CDD, including the expectation that FSPs apply CDD using a risk-based approach that is commensurate with their ML/TF/PF/TFS risks.


20. Must identification and verification always be completed before a business relationship is established?

Identification and verification should generally occur before or at the time of establishing a business relationship. In limited risk-based circumstances, completion may occur as soon as practicable thereafter, where permitted by the AMLRs and appropriately managed. These circumstances are when risks are presented as low, and there is no conflict with what is prescribed in the AMLRs.


21. Does the Rule introduce new outsourcing obligations?

The Rule reflects existing supervisory expectations regarding outsourcing arrangements and reinforces the responsibilities of FSPs to maintain effective oversight and accountability for outsourced functions.
 

22. If AML functions are outsourced, who remains responsible for compliance?

The FSP and its Governing Body remain ultimately responsible for compliance with AML/CFT/CPF/TFS obligations.


23. How should FSPs oversee outsourced AML activities?

FSPs and their Governing Body should maintain effective oversight of outsourced arrangements, including:

  • Clearly defined roles and responsibilities;
  • Appropriate reporting and escalation arrangements;
  • Ongoing monitoring of performance and effectiveness;
  • Timely access to relevant information and records; 
  • Periodic review and testing of outsourced activities; and
  • Periodic review of the risks associated with the service provider/outsourced arrangements
     
24. Can an FSP rely entirely on service providers to manage AML risks?

While an FSP may outsource certain AML/CFT/CPF/TFS activities, it remains ultimately responsible and accountable for compliance with applicable AML/CFT/CPF/TFS requirements. Accordingly, the FSP should maintain effective oversight of all outsourced activities and ensure that ML/TF/PF/TFS risks are appropriately identified, assessed, monitored, and managed.


Training and Employee Screening


25. Why is a documented training programme required?

A documented programme helps to ensure that AML/CFT/CPF/TFS training is structured, risk-based and appropriate to employees' roles and responsibilities. It also enables the FSP to demonstrate compliance with applicable training requirements and monitor the effectiveness of its training programme.
 

26. What should an AML training programme include?

The content and frequency of training should be appropriate to employees' roles, responsibilities, and risk exposure. The programme should include, inter alia:

  • AML/CFT/CPF/TFS legal and regulatory requirements applicable in the Cayman Islands;
  • Internal policies and procedures developed to meet the requirements under relevant acts and associated regulations;
  • FSP’s risk-based approach and risk management framework;
  • Emerging risks, trends, and typologies;
  • Internal and external reporting obligations, such as the filing of Suspicious Activity Reports;
  • Sanctions and TFS obligations; and
  • Recordkeeping requirements.
     
27. How often should AML training be delivered?

The FSP’s training programme should be administered on an ongoing basis and delivered at least annually. The frequency of the ongoing training should be determined using a risk-based approach and must ensure that employees remain competent and aware of evolving risks and obligations.
 

28. Does every employee require the same training?

All staff require AML training, but the type, depth, and frequency should be tailored to align with an employee’s role, responsibilities, and exposure to ML/TF/PF/TFS risks.


29. What employee screening measures are expected?

FSPs should implement risk-based screening measures appropriate to their size, structure, nature, and risk profile to help ensure that employees, particularly those performing AML-related functions, are fit and proper for their roles.
 

Independent Audit Function


30. Is the independent AML audit (“AML Audit”) requirement a new obligation?

The requirement for FSPs to carry out effective, risk-based AML audits of the AML/CFT/CPF/TFS function already exists under the AMLRs. The Rule provides additional clarity regarding supervisory requirements and how effectiveness should be demonstrated.


31. Does the Rule require annual AML Audits?

The Rule does not mandate annual AML Audits. The frequency, scope and depth of AML Audits should be determined using a risk-based approach, considering the FSP's size, complexity, business activities and ML/TF/PF/TFS risk exposure.


32. How often should an AML Audit be conducted?

There is no prescribed frequency. FSPs should determine and document the appropriate frequency, taking into account their risk profile, documented risk assessment and level of assurance required over the effectiveness of their AML/ CFT/CPF/TFS Compliance Programme. For example, if an FSP is rated higher risk, it might be reasonable that an AML Audit is conducted every two (2) years. Whereas for medium and low risk, the frequency of AML Audits may be every 3 and 4 years respectively. The frequency and intensity of an AML Audit should depend on the FSP’s overall risk rating while incorporating the nature, size and complexity of the operations. 


33. Can an outsourced AMLCO, MLRO, or DMLRO perform the AML Audit?

The AMLCO, MLRO, and DMLRO form part of the Compliance Programme and therefore cannot independently audit activities for which they have responsibility. This applies regardless of whether those functions are performed internally or through an outsourcing arrangement.


34. Who can perform an AML audit?

An AML Audit may be conducted by:

  • Internal audit functions;
  • External auditors;
  • Independent consultants; or
  • Other suitably qualified and competent independent parties.

The auditor must be independent of the AML/CFT/CPF/TFS function and activities being audited and must not be involved in the operation, management or oversight of the Compliance Programme.
 

35. What does independence mean in practice in the context of the AML Audit?

Independence means that the auditor is free from actual or perceived conflicts of interest and is not responsible for the design, operation, management or oversight of the Compliance Programme. This enables the auditor to provide an objective and impartial assessment of the effectiveness of the Compliance Programme.

 

36. How does the audit requirement apply to investment funds with operating models relying on outsourcing?

A regulated investment fund (the “Fund” or “Funds”) must still undertake an AML Audit, as required under Regulation 5(a)(ix) of the AMLRs, even if all, or substantially all, of its operations are outsourced. The scope and frequency of the independent audit should be determined using a risk-based approach, considering the Fund’s structure, business activities, outsourced service provider arrangements and ML/TF/PF/TFS risk profile.

 

37. What is CIMA's expectation regarding the scope and evidence required for an AML Audit of an individual Fund?

For AML Audits of Funds, consideration needs to be given to the specific Fund’s policies, controls and procedures, which should incorporate investor onboarding controls, ongoing due diligence, investment objective and policies, third party relationships/outsourcing, internal reporting, training programme, record keeping and the application of a risk-based approach.  

The Authority expects that an AML Audit of an individual Fund(s) should obtain sufficient and appropriate evidence to conclude on the design and operating effectiveness of the Compliance Programme of the individual Fund(s). Accordingly, relying solely on a service-provider-level internal audit or a population-based review, without obtaining sufficient evidence regarding the individual Fund's Compliance Programme, would not provide sufficient assurance of the effectiveness of the AML Audit.
 

38. Does the Authority require a specific risk-based methodology for conducting AML Audits of Funds? 

The Authority does not prescribe a single risk-based audit methodology. The auditor may adopt an approach proportionate to the nature, scale and complexity of a Fund(s). However, using a risk-based approach, the auditor should obtain sufficient and appropriate evidence to support conclusions regarding the design and effectiveness of the Compliance Programme as applicable to each Fund, considering its individual risk profile, governance arrangements, outsourced activities and AML/CFT/CPF/TFS obligations.
 

39. Can an FSP rely on an independent audit report of an outsourced service provider?

All FSPs (including Funds regulated under the Mutual Funds and Private Funds Acts, and Securities Investment Businesses regulated under the Securities Investment Business Act) may consider independent audit reports from an outsourced service provider as part of their internal control and oversight frameworks.

However, the Governing Body of the FSP, through its governance mechanisms, remains responsible for demonstrating to the Authority that such reports provide sufficient, objective assurance of the effectiveness of the FSP’s Compliance Programme and its compliance with AML/CFT/CPF/TFS obligations. In doing so, the Governing Body should assess whether the scope of the independent audit includes, and is sufficiently relevant to, the AML activities performed by the outsourced service provider on behalf of the FSP.

As a reminder, where outsourced service providers perform activities for or on behalf of an FSP, the FSP must implement a programme to evaluate the effectiveness of the system of internal controls over such activities. Such a programme should be commensurate with the nature, complexity and risk profile of the outsourced activity.

 

40. Why does the Rule require at least one external AML audit for every three independent audit cycles?

This requirement helps mitigate the risks of familiarity, self-review, and loss of objectivity by ensuring that a periodic external assessment of the Compliance Programme is carried out.  It provides an additional level of assurance and helps identify potential gaps or weaknesses in the effectiveness of an FSP’s internal control procedures through an objective and independent review.
 

(Re)Insurance Sector in Scope
 

41. Does the Rule apply to all insurers and reinsurers?

The Rule applies only where an insurer or reinsurer is conducting "Relevant Financial Business" as defined under the POCA (as amended).
 

42. If an insurer or reinsurer is conducting Relevant Financial Business, can the completion of the Relevant Financial Business Self‑Declaration ("RFB Self-Declaration") replace the independent audit requirement?

The RFB Self‑Declaration does not replace the requirement for independent audit and testing of the insurer or reinsurer’s AML/CFT/CPF/TFS Compliance Programme. The RFB Return is an attestation by the FSP and is not a substitute for objective assurance of the effectiveness of its Compliance Programme.
 

Section 2: Frequently Asked Questions (FAQs) on the Rule on Compliance with Financial Sanctions and Targeted Financial Sanctions

 

43. What is the Authority seeking to achieve through this Rule?

This Rule is issued to promote compliance by Regulated Persons with existing domestic and international legal obligations related to financial sanctions that are in force in the Cayman Islands.

 

44. Does the scope of this Rule extend to reinsurers who do not conduct Relevant Financial Business?

Sanctions obligations apply to all natural persons, legal arrangements and legal persons in the Cayman Islands. Therefore, this Rule applies to all Regulated Persons supervised by the Authority pursuant to the Regulatory Acts, whether or not they conduct Relevant Financial Business.
 

45. Does this Rule duplicate the Financial Reporting Authority’s (FRA’s) mandate?

CIMA recognises the FRA’s role as the Competent Authority for handling financial sanctions, as designated by the Governor of the Cayman Islands. This Rule reinforces requirements for Regulated Persons to comply with the FRA’s reporting guidelines and their obligations under Cayman’s TFS legislative framework.
 

Conclusion

These FAQs are a part of the Authority’s ongoing outreach efforts and continued engagement with industry. The FAQs do not replace or amend the Rules and should be read in conjunction with the Rules and relevant legislation.

Sign up for our E-alerts

Be the first to know about releases and industry news and insights.