Cayman Islands Monetary Authority-regulated financial services providers, including investment funds, will need to prepare for the commencement of two new rules on 18 September 2026.
The rules largely reflect and clarify the existing regime, but they will also introduce new obligations, particularly around outsourcing and independent anti-money laundering (AML) audits, and will make it easier for CIMA to enforce compliance with key AML / countering the financing of terrorism (CFT) / counter-proliferation financing (CPF) and financial sanctions obligations.
We recommend that financial services providers (FSPs) review and update their AML compliance programmes and engage with their Cayman counsel and AML service providers as soon as possible.
What are CIMA's new rules?
After consultation with the financial services industry, the Cayman Islands Monetary Authority (CIMA) has issued two new rules that come into force on 18 September 2026 and will apply to all Cayman Islands FSPs regulated and supervised by CIMA, including investment funds, managers and advisors. The rules do not apply to persons who are not regulated and supervised by CIMA.
CIMA's new rules (the Rules) are:
- the Rule on an Effective Compliance Programme for the Prevention and Detection of Money Laundering, Terrorist Financing and Proliferation Financing for Financial Services Providers (the AML Rule)
- the Rule on Compliance with Financial Sanctions and Targeted Financial Sanctions (the Sanctions Rule)
The purpose and effect of the Rules
Until now, the Cayman Islands AML regime applicable to FSPs has been made up of three pillars:
- legislation: the primary statute being the Proceeds of Crime Act (Revised) (POCA)
- subordinate legislation: for example, the Anti-Money Laundering Regulations (Revised) (the Regulations)
- guidance: for example, the Guidance Notes on the Prevention and Detection of Money Laundering, Terrorist Financing and Proliferation Financing in the Cayman Islands, issued by CIMA (the Guidance)
In terms of enforceability, the Guidance, while not mandatory, can be taken into consideration by the courts when determining compliance with the POCA or the Regulations. In other words, the Guidance is persuasive and carries evidentiary weight.
However, CIMA does not technically have enforcement powers over FSPs for a breach of, or failure to follow, the Guidance. Accordingly, the Rules have been introduced to embed the key principles of the Guidance relating to compliance programs in an instrument that CIMA can directly enforce.
As such, if the Rules are breached, CIMA will be able to apply penalty procedures under its Enforcement Manual and, more importantly, will be able to impose administrative fines once the Rules have been added to the Schedule to the Monetary Authority (Administrative Fines) Regulations (Revision).
In terms of hierarchy, the rules take precedence over the Guidance where there is any inconsistency. However, if the Rules are inconsistent with the POCA, the Regulations, or other legislation (for example, the Terrorism Act (Revised) or Sanctions Orders), the legislation shall prevail.
The rules also provide that where there is a breach of both the Regulations and the Rules, CIMA will exercise its discretion when determining fines to avoid duplication of penalties or a double jeopardy scenario for the same breach.
The new CIMA rules explained
We have summarised below where the Rules substantively reflect or clarify the existing principles contained in the current three pillars of the AML regime without making a material change to the status quo. FSPs should already be in general compliance with the following requirements.
- Governance and overview of the compliance programme – the governing body of a FSP (such as the board of directors, general partner or trustee) (the Governing Body) should approve the FSP's AML, CFT, CPF compliance programme, as well as the financial sanctions (FS) and targeted financial sanctions (TFS) compliance programme (together, the Compliance Programme).
- Detailed policies, procedures and controls – the Compliance Programme must include written policies and procedures addressing customer due diligence, record retention, suspicious activity detection and reporting, outsourcing of material functions and financial sanctions compliance, many of the requirements of which must be applied "in a manner proportionate to the nature, type, and scope of the activities conducted by the FSP".
- Designation of officers – the FSP must designate and describe the roles of all senior persons involved in the implementation of the Compliance Programme, including without limitation the AML Compliance Officer (AMLCO), Money Laundering Reporting Officer and Deputy Money Laundering Reporting Officer (collectively, the AML Officers), who must be of good repute and have sufficient qualifications, skills and experience. Records of the AML Officers' fitness and propriety should be retained as CIMA may request them. The AMLCO must perform the compliance function independently and objectively from the business and operational functions of the FSP and, where full separation is not practicable, the FSP must ensure conflicts of interest are effectively managed. Although not fully described under the current AML regime, this is already an expectation of CIMA.
- Develop and document a risk-based approach – risk-based approach principles should be established to identify, assess, manage and mitigate money laundering, terrorism financing and proliferation financing risks.
- Compliance training and employee screening – a training programme and plan must be developed and applied for all employees, agents and authorised persons and delivered at least annually. External training service providers should be assessed for competency and the training materials for appropriateness.
- Demonstration of effectiveness – maintain independent, risk-based audit procedures (see further below) to review and test the adequacy and effectiveness of the Compliance Programme and to align with the regulatory and legislative requirements.
- Sanctions compliance – FSPs must maintain written procedures and internal controls to provide for customer and counterparty / connected person screening, asset freezing and unfreezing, monitoring sanctions lists and Sanctions Orders, undertake and update risk assessments, training, licensing procedures, as well as reporting to the Financial Reporting Authority and, separately, to CIMA. FSPs should note that, while the sanctions regime may be applicable to all Cayman persons, CIMA expects the FS and TFS Compliance Programme to be maintained by all Regulated Persons, which includes an authorised person, registered person, registrant, licensee, licence-holder and supervised person under the Regulatory Acts.
- Annual governing body reporting – the AMLCO must report to the Governing Body on the Compliance Programme at least annually.
Key changes
The Rules do extend certain principles under the Guidance, introducing certain new requirements which will require consideration by FSPs to ensure compliance, including:
- Outsourcing controls – the AML Rule largely reflects the Statement of Guidance on Outsourcing (the Outsourcing SoG), which does not directly apply to regulated investment funds, and the Guidance. Accordingly, the AML Rule extends certain elements of the Outsourcing SoG to investment funds and makes them enforceable against all FSPs. FSPs other than investment funds should already be familiar with these requirements under the Outsourcing SoG. See our recommended actions below regarding the required outsourcing controls.
- Independent audit function – all FSPs, including investment funds, must now maintain independent audit procedures and undertake independent AML audits to review and test their Compliance Programme. This is in addition to the oversight of the Compliance Programme, which is already undertaken by the AMLCO. Importantly:
- the frequency of the audit should be commensurate with the size, complexity, structure, nature and risk profile of the FSP's business
- the auditor must be a suitably qualified person who is independent and separate from those involved in the design, implementation and operation of the subject matter of the audit to avoid conflicts of interest or impaired judgment (that is to say, not an AML Officer). CIMA may require the FSP to provide documentation of the independence of the auditor including the basis upon which the independence was determined
- the audit may be conducted internally, which includes any individual who forms part of the FSP's organisational structure and is subject to the direction, control or oversight of the FSP - this would include an investment fund's administrator and investment manager
- the audit cannot be conducted internally for more than two consecutive audit cycles, and after two consecutive internal audits, the next audit must be conducted by an external service provider
- the FSP must establish and maintain effective remediation measures to address deficiencies, breaches and weaknesses, commensurate with the nature, materiality and associated risk
- the audit report must be filed with CIMA as soon as possible after completion
Recommended actions for FSPs
Given the Rules clarify and extend procedural principles from the Guidance, we recommend clients consider the following actions as soon as possible:
- Review the existing Compliance Programme by performing a gap analysis and update where required. This includes a review of the FSP's own policies and procedures, as well as seeking confirmations of compliance with the new Rules from any service provider to which the FSP has outsourced an AML function.
- With respect to aspects of its AML function that may be outsourced, an FSP, including an investment fund (FSPs which are not investment funds should already be attending to these matters with respect to all outsourcing arrangements) should:
- assess the associated risks, including the country risk of the associated outsourcing arrangement
- ensure that the outsourcing arrangement does not impair the FSP's ability to meet AML / CFT / CPF obligations or manage its risks effectively
- conduct due diligence on the service provider prior to entering into the outsourcing arrangement (or soon thereafter for existing arrangements) and keep the records of such due diligence
- ensure that the outsourcing agreement sets out the respective rights and obligations of the parties
- not enter into or continue an outsourcing arrangement where the associated risks cannot be effectively identified, managed or mitigated or where CIMA's access to data, information or systems may be impeded
- where the service provider is undertaking the AML Officer roles on behalf of the FSP, ensure that the AML Officers are trained and understand the obligations under the Cayman AML / CFT / CPF / TFS regime
- notify CIMA of the outsourcing arrangement
- identify an appropriate independent auditor of the Compliance Programme, whether internally (subject to conflicts / impairment etc.) or externally, and agree the audit frequency
How Ogier can help
Ogier's Regulatory team in the Cayman Islands can assist with all of the above action points. Reach out to our Regulatory team or your usual Ogier contact and we can advise further on the requirements and ramifications of the new rules.