This section provides Frequently Asked Questions (FAQs) to assist financial services providers in understanding the Rule on Effective Compliance Programme for the Prevention and Detection of Money Laundering, Terrorist Financing and Proliferation Financing for Financial Services Providers and the Rule on Compliance with Financial Sanctions and Targeted Financial Sanctions.
The Cayman Islands Monetary Authority (the “Authority” or “CIMA”) has issued two (2) new Rules:
(together, the “Rules”) which will come into effect on Friday, 18 September 2026.
The objective of these Rules is to support and promote an effective, proportionate, and risk-based framework that enables regulated entities in scope to identify, assess, manage, and mitigate ML, TF, PF, and sanctions-related risks. These Rules also align with CIMA’s strategic objective to “provide support for improving effectiveness in combating financial crime and a positive assessment on the FATF 5th Round Review of the Cayman Islands.”
CIMA has developed these FAQs to support industry’s implementation and application of these Rules and to provide general clarification on their compliance obligations, with respect to:
The Rule is intended to provide enhanced guidance with regards to applicable Anti-Money Laundering, Countering the Financing of Terrorism and Countering Proliferation Financing ("AML/CFT/CPF") obligations and to support the strengthening of the effectiveness of AML/CFT/CPF Compliance Programmes for Financial Services Providers ("FSPs"). It is expected to enhance governance, accountability, and the consistent implementation of effective AML/CFT/CPF measures, while supporting the Authority's risk-based supervisory approach.
The framework remains risk-based. The Rule establishes minimum requirements while allowing flexibility in implementation, based on proportionality.
Any additional compliance costs will depend on the size, structure, complexity, and nature of the business, as well as the entity's risk profile and the extent to which it has already implemented its AML/CFT/CPF framework. FSPs with robust existing frameworks are expected to require only limited enhancements to align with the proposed requirements.
The AML/CFT/CPF Compliance Programme obligations apply to all FSPs that conduct “Relevant Financial Business” as defined under the Proceeds of Crime Act (as amended) ("POCA") and are regulated by the Authority under the Regulatory Acts, including branches, subsidiaries, affiliates, and any other members of a CIMA-regulated financial group, regardless of their business model or outsourcing arrangements.
The Governing Body should demonstrate effective oversight of the Compliance Programme by ensuring that it exercises appropriate and proportionate governance over the design, implementation and ongoing effectiveness of the programme. This includes, inter alia, ensuring that it:
This oversight should be evidenced through appropriate governance records, including Governing Body or committee minutes, reports, documented decisions, and the tracking of remediation actions, where applicable.
The Rule supplements the Anti-Money Laundering Regulations (as amended) ("AMLRs") and should be read in conjunction with them. The AMLRs remain the primary legal basis for AML/CFT/CPF compliance, and if there is any inconsistency between the provisions of the Rule and the AMLRs, the AMLRs will prevail.
The Authority's power to issue the Rule is drawn from sections 6(3)(b) and 34(1) of the Monetary Authority Act (as amended).
The AMLCO is expected to ensure that the requirements set out in the Rule and the AMLRs are adopted by the FSP. An AMLCO may be personally liable for an FSP’s AML compliance failure where this amounts to a breach of the AMLRs and the breach is attributable to the AMLCO’s conduct. However, the FSP remains ultimately responsible for AML/CFT/CPF compliance.
The AMLCO should possess:
Independence refers to functional and reporting autonomy that is sufficient to allow the AMLCO to discharge their AML/CFT/CPF/TFS responsibilities objectively, free from conflict of interest, and have the authority to escalate issues directly to senior management and/or the Governing Body. It does not necessarily require complete separation from all business activities.
Depending on the size, nature, and complexity of the FSP, the AMLCO may perform additional operational duties. However, the FSP should be able to demonstrate to the Authority that these additional responsibilities do not impair the AMLCO's independence, create a conflict of interest, or impede the effective discharge of their AML/CFT/CPF/TFS responsibilities.
Subject to applicable AMLRs requirements, the AMLCO function may be performed by an appropriately qualified individual who is either employed by the FSP or engaged through an outsourcing arrangement. Where the function is outsourced, the FSP must ensure that the AMLCO has sufficient authority, independence, resources, and access to information to discharge their responsibilities effectively. Outsourcing does not transfer accountability away from the FSP or its Governing Body.
Where permitted under applicable laws and regulations, one individual may perform multiple AML roles, provided that the FSP can demonstrate to the Authority that any actual or potential conflicts of interest are appropriately managed and that the individual can effectively discharge all assigned responsibilities.
Documentation demonstrates how ML/TF/PF/TFS risks have been identified, assessed, mitigated, monitored and reviewed. It provides evidence of compliance with applicable AML/CFT/CPF/TFS requirements; supports effective governance and decision-making; and enables the FSP to demonstrate the rationale for its risk assessments and control measures. Moreover, documenting the risk-based approach also facilitates independent review, internal oversight and supervisory assessment by the Authority.
The documentation supporting the risk-based approach should be proportionate to the nature, size, complexity, and risk profile of the FSP. As applicable, the documentation should include:
The documentation should be maintained to demonstrate how the FSP has applied its risk-based approach in practice. It should be reviewed and updated periodically, and whenever there are material changes to the FSP's business activities, customer base, products and services, delivery channels, geographic exposure, or other relevant risk factors, to ensure it remains appropriate to the FSP's risk profile.
Risk factors should include those identified in the AMLRs, including:
Customer due diligence and ongoing monitoring measures should be commensurate with the ML/TF/PF/TFS risks identified by the FSP. Accordingly, the risk-based approach requires that the nature and extent of these measures be proportionate to the customer's assessed risk profile.
Group assessments may be utilised where appropriate; however, FSPs must ensure ML/TF/PF/TFS risks specific to their Cayman Islands operations are adequately identified and addressed.
The Rule reinforces the existing AMLRs requirements for CDD, including the expectation that FSPs apply CDD using a risk-based approach that is commensurate with their ML/TF/PF/TFS risks.
Identification and verification should generally occur before or at the time of establishing a business relationship. In limited risk-based circumstances, completion may occur as soon as practicable thereafter, where permitted by the AMLRs and appropriately managed. These circumstances are when risks are presented as low, and there is no conflict with what is prescribed in the AMLRs.
The Rule reflects existing supervisory expectations regarding outsourcing arrangements and reinforces the responsibilities of FSPs to maintain effective oversight and accountability for outsourced functions.
The FSP and its Governing Body remain ultimately responsible for compliance with AML/CFT/CPF/TFS obligations.
FSPs and their Governing Body should maintain effective oversight of outsourced arrangements, including:
While an FSP may outsource certain AML/CFT/CPF/TFS activities, it remains ultimately responsible and accountable for compliance with applicable AML/CFT/CPF/TFS requirements. Accordingly, the FSP should maintain effective oversight of all outsourced activities and ensure that ML/TF/PF/TFS risks are appropriately identified, assessed, monitored, and managed.
A documented programme helps to ensure that AML/CFT/CPF/TFS training is structured, risk-based and appropriate to employees' roles and responsibilities. It also enables the FSP to demonstrate compliance with applicable training requirements and monitor the effectiveness of its training programme.
The content and frequency of training should be appropriate to employees' roles, responsibilities, and risk exposure. The programme should include, inter alia:
The FSP’s training programme should be administered on an ongoing basis and delivered at least annually. The frequency of the ongoing training should be determined using a risk-based approach and must ensure that employees remain competent and aware of evolving risks and obligations.
All staff require AML training, but the type, depth, and frequency should be tailored to align with an employee’s role, responsibilities, and exposure to ML/TF/PF/TFS risks.
FSPs should implement risk-based screening measures appropriate to their size, structure, nature, and risk profile to help ensure that employees, particularly those performing AML-related functions, are fit and proper for their roles.
The requirement for FSPs to carry out effective, risk-based AML audits of the AML/CFT/CPF/TFS function already exists under the AMLRs. The Rule provides additional clarity regarding supervisory requirements and how effectiveness should be demonstrated.
The Rule does not mandate annual AML Audits. The frequency, scope and depth of AML Audits should be determined using a risk-based approach, considering the FSP's size, complexity, business activities and ML/TF/PF/TFS risk exposure.
There is no prescribed frequency. FSPs should determine and document the appropriate frequency, taking into account their risk profile, documented risk assessment and level of assurance required over the effectiveness of their AML/ CFT/CPF/TFS Compliance Programme. For example, if an FSP is rated higher risk, it might be reasonable that an AML Audit is conducted every two (2) years. Whereas for medium and low risk, the frequency of AML Audits may be every 3 and 4 years respectively. The frequency and intensity of an AML Audit should depend on the FSP’s overall risk rating while incorporating the nature, size and complexity of the operations.
The AMLCO, MLRO, and DMLRO form part of the Compliance Programme and therefore cannot independently audit activities for which they have responsibility. This applies regardless of whether those functions are performed internally or through an outsourcing arrangement.
An AML Audit may be conducted by:
The auditor must be independent of the AML/CFT/CPF/TFS function and activities being audited and must not be involved in the operation, management or oversight of the Compliance Programme.
Independence means that the auditor is free from actual or perceived conflicts of interest and is not responsible for the design, operation, management or oversight of the Compliance Programme. This enables the auditor to provide an objective and impartial assessment of the effectiveness of the Compliance Programme.
A regulated investment fund (the “Fund” or “Funds”) must still undertake an AML Audit, as required under Regulation 5(a)(ix) of the AMLRs, even if all, or substantially all, of its operations are outsourced. The scope and frequency of the independent audit should be determined using a risk-based approach, considering the Fund’s structure, business activities, outsourced service provider arrangements and ML/TF/PF/TFS risk profile.
For AML Audits of Funds, consideration needs to be given to the specific Fund’s policies, controls and procedures, which should incorporate investor onboarding controls, ongoing due diligence, investment objective and policies, third party relationships/outsourcing, internal reporting, training programme, record keeping and the application of a risk-based approach.
The Authority expects that an AML Audit of an individual Fund(s) should obtain sufficient and appropriate evidence to conclude on the design and operating effectiveness of the Compliance Programme of the individual Fund(s). Accordingly, relying solely on a service-provider-level internal audit or a population-based review, without obtaining sufficient evidence regarding the individual Fund's Compliance Programme, would not provide sufficient assurance of the effectiveness of the AML Audit.
The Authority does not prescribe a single risk-based audit methodology. The auditor may adopt an approach proportionate to the nature, scale and complexity of a Fund(s). However, using a risk-based approach, the auditor should obtain sufficient and appropriate evidence to support conclusions regarding the design and effectiveness of the Compliance Programme as applicable to each Fund, considering its individual risk profile, governance arrangements, outsourced activities and AML/CFT/CPF/TFS obligations.
All FSPs (including Funds regulated under the Mutual Funds and Private Funds Acts, and Securities Investment Businesses regulated under the Securities Investment Business Act) may consider independent audit reports from an outsourced service provider as part of their internal control and oversight frameworks.
However, the Governing Body of the FSP, through its governance mechanisms, remains responsible for demonstrating to the Authority that such reports provide sufficient, objective assurance of the effectiveness of the FSP’s Compliance Programme and its compliance with AML/CFT/CPF/TFS obligations. In doing so, the Governing Body should assess whether the scope of the independent audit includes, and is sufficiently relevant to, the AML activities performed by the outsourced service provider on behalf of the FSP.
As a reminder, where outsourced service providers perform activities for or on behalf of an FSP, the FSP must implement a programme to evaluate the effectiveness of the system of internal controls over such activities. Such a programme should be commensurate with the nature, complexity and risk profile of the outsourced activity.
This requirement helps mitigate the risks of familiarity, self-review, and loss of objectivity by ensuring that a periodic external assessment of the Compliance Programme is carried out. It provides an additional level of assurance and helps identify potential gaps or weaknesses in the effectiveness of an FSP’s internal control procedures through an objective and independent review.
The Rule applies only where an insurer or reinsurer is conducting "Relevant Financial Business" as defined under the POCA (as amended).
The RFB Self‑Declaration does not replace the requirement for independent audit and testing of the insurer or reinsurer’s AML/CFT/CPF/TFS Compliance Programme. The RFB Return is an attestation by the FSP and is not a substitute for objective assurance of the effectiveness of its Compliance Programme.
This Rule is issued to promote compliance by Regulated Persons with existing domestic and international legal obligations related to financial sanctions that are in force in the Cayman Islands.
Sanctions obligations apply to all natural persons, legal arrangements and legal persons in the Cayman Islands. Therefore, this Rule applies to all Regulated Persons supervised by the Authority pursuant to the Regulatory Acts, whether or not they conduct Relevant Financial Business.
CIMA recognises the FRA’s role as the Competent Authority for handling financial sanctions, as designated by the Governor of the Cayman Islands. This Rule reinforces requirements for Regulated Persons to comply with the FRA’s reporting guidelines and their obligations under Cayman’s TFS legislative framework.
These FAQs are a part of the Authority’s ongoing outreach efforts and continued engagement with industry. The FAQs do not replace or amend the Rules and should be read in conjunction with the Rules and relevant legislation.
Be the first to know about releases and industry news and insights.