A practical guide to CIMA’s new enforceable Rules published on 20 July 2026
On 20 July 2026, the Cayman Islands Monetary Authority (CIMA) published two new measures: the Rule on Effective Compliance Programme for the Prevention and Detection of Money Laundering, Terrorist Financing and Proliferation Financing for Financial Services Providers (the “Compliance Rule“) and the Rule on Compliance with Financial Sanctions and Targeted Financial Sanctions (the “Sanctions Rule” and, together with the Compliance Rule, the “Rules“). The Rules take effect on 18 September 2026 and apply to financial services providers (FSP) regulated and supervised by CIMA. Together, they establish enforceable minimum requirements for a documented, risk-based and demonstrably effective anti-money laundering (AML), countering the financing of terrorism (CFT) and counter proliferation financing (CPF) (together shall be referred to “AML/CFT/CPF“) compliance programme and for compliance with financial sanctions and targeted financial sanctions.
For the purposes of this article, we will focus on the effect of the Rules on private funds and mutual funds regulated by CIMA pursuant to the Private Funds Act (as revised) and the Mutual Funds Act (as revised).
Why the Rules Matter
The Rules give legal force to key compliance expectations that were previously addressed principally through CIMA’s Guidance Notes. Although many requirements will be familiar from the Anti-Money Laundering Regulations, the Cayman Islands sanctions framework and existing industry practice, CIMA can now assess and enforce compliance against clearer minimum standards. Whilst the Rules do not fundamentally change existing AML/CFT/CPF requirements for Cayman funds, the practical emphasis shifts from having policies on paper to being able to evidence governance, risk assessment, implementation, oversight, testing and effective sanctions controls.
Key Components
1. Governing Body Ownership and Accountability
The Governing Body must approve and oversee the compliance programme, ensure that it is appropriately resourced and receive sufficient management information to challenge its effectiveness. Compliance functions may be outsourced, but accountability/responsibility remains with the FSP and its Governing Body.
The Compliance Programme, at a minimum, must include the following key components:
- Designation of an anti-money laundering compliance officer who is responsible for the implementation and oversight of the Compliance Programme and requisite money laundering reporting officers.
- Documentation of detailed written policies and procedures of the Compliance Programme which will include sanctions monitoring and reporting requirements driven by the Sanctions Rule.
- Development, documentation and implementation of a risk management framework including a periodic risk assessment programme to evaluate the money laundering, terrorist financing and proliferation financing (ML/TF/PF) risks presented by investors, products/services, transactions, country or geographic area, and delivery channels, to effectively apply a risk-based approach and mitigate the risks occurring in the course of business.
- Delivery of ongoing compliance training programme and training plan for all staff, the Governing Body, and any other relevant parties, to ensure awareness of and compliance with applicable AML, CFT, CPF, and targeted financial sanctions (TFS) obligations.
- Development, maintenance, and conducting of ongoing evaluations of the effectiveness of the Compliance Programme in a manner proportionate to the nature, type, and scope of the activities conducted by the FSP including an independent audit of the Compliance Programme.
2. Designated Officers with Authority and Access
The FSP must designate an Anti-Money Laundering Compliance Officer (AMLCO), a Money Laundering Reporting Officer (MLRO) and a Deputy Money Laundering Reporting Officer (DMLRO) (together the AMLCO, MLRO and DMLRO shall be referred to as the “AML Officers“). AML Officers must be natural persons at an appropriate management level, with sufficient authority, independence, resources, information and direct access to the Governing Body.
The FSP is responsible for ensuring that the AML Officers are of good repute, possess integrity, are suitably qualified with sufficient skills and experience to perform their functions, and shall provide CIMA, upon request, such information and evidence as CIMA may require in this regard. It is suggested that an annual declaration including confirmation of annual training will assist the FSP to comply with the responsibility. The AML Officer should be added as a category to the FSPs risk assessment to assess the AML Officers capabilities for the role.
The AMLCO must have a sound understanding of the FSPs business model, activities, products, services, functions, and structure and possess the knowledge of the AML/CFT/CPF and sanctions-evasion risks relevant to the FSP’s business sector, as well as emerging issues, trends and typologies.
The designation of an AMLCO does not absolve an FSP of its obligations. The FSP must remain ultimately responsible for the development, implementation and effectiveness of the FSP’s Compliance Programme to ensure compliance with its obligations under the AML/CFT/CPF regime.
3. A Documented and Current Risk Assessment Programme
FSPs must identify, assess, document and keep under review their exposure to ML/TF/PF risk. The risk assessment should reflect investors, products and services, delivery channels, geographic exposure, transactions, new technologies and other relevant risk factors. It must drive the design and intensity of controls rather than operate as a stand-alone compliance document and be proportionate to the nature, size, complexity, structure and risk profile of its operations.
As a minimum (and specifically), the FSP must review and consider the findings and conclusions of the most recent Cayman Islands National Risk Assessment (NRA), together with any other relevant internal and external risk factors, as part of its internal risk assessment process. The key focus for the most recent 2025/2026 NRA (yet to be published) is likely to be on beneficial ownership, nominee arrangements, foundation company structures and the virtual asset service provider regime.
The risk assessment must without delay be updated upon the occurrence of any material trigger event that may impact on the effectiveness, adequacy, or relevance of the risk assessment, including, but not limited to:
- New products or business lines
- Expansion into higher risk geographical areas
- Mergers, acquisitions or significant corporate restructuring
- Economic or geopolitical developments affecting risk exposure
A fund should be prepared to provide its fund-level risk assessment to CIMA on request.
Where there are higher ML/TF/PF risks, FSPs must implement enhanced due diligence measures to manage and mitigate those risks; and correspondingly, where the ML/TF/PF risks are lower, simplified due diligence measures may be applied at the investor level, in accordance with applicable customer due diligence requirements.
4. More Explicit Minimum Standards for Policies and Procedures
The Compliance Rule requires detailed, risk-based policies, procedures and controls covering customer due diligence, beneficial ownership, enhanced and simplified due diligence, politically exposed persons, ongoing monitoring, suspicious activity escalation and reporting, record keeping, internal controls, new products and technologies, reliance and outsourcing – these requirements, in the main part, consolidate existing requirements. Procedures should identify who performs each role, when it is performed, what evidence is retained and how exceptions are managed.
The consolidation of the existing AML requirements is clarified in the Rules which confirm that the FSP will be directly responsible for understanding the beneficial owners of participating shares in the fund. This includes where the customer is a bank or other intermediary acting as nominee. The FSP has an obligation to understand the nominee arrangement to determine who has ultimate effective control. If the fund is placing reliance on a bank, for example, by way of a reliance letter whereby the bank confirms (i) it has conducted the customer due diligence in accordance with the laws of the Cayman Islands, (ii) it will provide copies of any identification and verification data obtained for the purposes of satisfying the nominee of the requirements of customer due diligence and (iii) it will provide the relevant information on request and without delay; the fund should ensure that it regularly reviews these arrangements, conducts internal audits and reliance testing so that the bank can provide the required information promptly and within 24 hours if a legitimate access request is made pursuant to the beneficial ownership regime.
For completeness, the definition of beneficial owner means an individual who:
- Ultimately owns or controls, whether through direct or indirect ownership or control, 25% or more of the shares, voting rights or partnership interests in the Legal Person.
- Exercises ultimate effective control (i.e. through a series of ownership layers or other forms of indirect control) over the management of the Legal Person.
- Is identified as exercising control of the Legal Person through other means.
A “Legal Person” is (a) a company, (b) a limited liability company, (c) a limited liability partnership, (iv) a limited partnership, (v) a foundation company, (vi) an exempted limited partnership or (vii) any other legal person that may be prescribed by the regulations.
5. Stronger Oversight of Outsourcing and Group Arrangements
Outsourcing by funds of the mechanics of ML/TF/PF compliance to an administrator or specialist AML service provider continues to be permitted but requires demonstrable oversight and does not transfer regulatory responsibility. FSPs should conduct due diligence before appointment, document the scope and standards of service, maintain access to relevant records, monitor performance and establish escalation, remediation and termination arrangements. The FSP must be able to demonstrate that outsourced controls remain appropriate for its own risk profile.
The FSP must notify CIMA of any outsourcing agreement that relates to material function of its Compliance Programme having conducted the materiality assessment described below.
A materiality assessment of the outsourcing arrangements with the outsourced provider/administrator should be reviewed and the Statement of Guidance for Outsourcing for Regulated Entities states that the following should be considered as part of the assessment:
- The impact of the outsourcing arrangement on its finances, reputation and operations, or a significant business line, particularly if the service provider, or group of affiliated service providers, should fail to perform over a given period of time depending on the nature of the outsourced function/service.
- Its ability to maintain appropriate internal controls and meet regulatory requirements, particularly if the service provider were to experience problems.
- The cost of the outsourcing arrangement.
- The risk of potential loss, temporarily or permanently, of access to important data.
- The degree of difficulty and time required to find an alternative service provider or to bring the business activity ‘in-house’.
6. Ongoing Training and Employee Screening
FSPs must establish, document, and implement an effective training programme and plan that ensures all relevant directors, employees, agents, and other persons authorised to act on their behalf understand and comply with the requirements of the Proceeds of Crime Act, the Anti Money Laundering Regulations, the Terrorist Act, the Proliferation Financing (Prohibition) Act, and all applicable legislation.
Training must be timely, ongoing, role-specific and proportionate to the FSP’s risk profile. FSPs should also maintain risk-based screening arrangements and records demonstrating attendance, comprehension, follow-up and remediation.
Although a fund may not have employees of its own, the training obligation should be applied functionally to the persons who perform relevant activities for or on behalf of the fund. Accordingly, the governing body should ensure that directors, AML officers and relevant personnel of outsourced service providers and, where applicable, the investment manager, receive appropriate AML/CFT/CPF and sanctions training that is proportionate to their role and the fund’s risk profile. The fund should not need to duplicate training already provided by a regulated administrator or investment manager, provided it has obtained sufficient evidence that the training is current, role-appropriate, covers Cayman Islands AML/CFT/CPF and sanctions obligations where relevant, and is subject to appropriate completion monitoring and record keeping.
The FSPs recruitment and selection programme should include screening prospective directors and staff through fitness and propriety checks, integrity screening, due diligence, and background checks, to ensure staff competence and integrity, and to prevent ML/TF/PF. Usually a fund uses the employees of outsourced providers such as the investment manager and administrator to perform the operations of the fund. The fitness and propriety of staff providing the outsourced services should be factored in the risk assessment for the outsourcing arrangements.
The training programmes must be administered on an ongoing basis and delivered at least annually.
7. Independent Effectiveness Reviews/Audits
The compliance programme must be independently audited/tested at a frequency and scope appropriate to the FSP’s size, nature, complexity and risk. Reviewers must have the competence, authority and independence needed to assess design and operating effectiveness. The independence criteria means a person who is separate from those involved in the design, implementation, or operation of the policies, procedures, systems, and controls under audit, and who are free from any conflict of interest that could impair their objective judgment.
There is no prescribed frequency for audits and the FSP should determine and document the appropriate frequency, taking into account their risk profile, documented risk assessment and level of assurance required over the effectiveness of the AML/CPF/CFT Compliance Programme. CIMA have however indicated that if an FSP is rated higher risk, it may be reasonable that an audit is conducted every two years whereas an audit for medium and low risk may be every three or four years.
An internal audit may be conducted but such audit must not be undertaken internally for more than two (2) consecutive audit cycles. On the third audit cycle an external provider must then be engaged.
CIMA recognises that independent audit reports of an outsourced service provider may also be considered by an FSP but has highlighted that the Governing Body of the FSP must assess whether the scope of the relevant independent audit includes, and is sufficiently relevant to, the AML activities performed by the outsourced provider on behalf of the FSP.
An audit report must be filed with CIMA as soon as practically possible after the completion of the audit.
FSPs must establish and implement effective remediation measures to address any deficiencies, breaches, or weaknesses identified through the audit within appropriate timeframes commensurate with their nature, materiality, and associated risk. Such remediation measures should be reported to and tracked by the Governing Body.
8. A Formal Financial Sanctions and Targeted Financial Sanctions Framework
The Sanctions Rule requires FSPs to maintain effective, documented and risk-based systems and controls for compliance with applicable financial sanctions and targeted financial sanctions. These should include governance and accountability, assessment of sanctions exposure, screening of customers, beneficial owners and relevant transactions, ongoing and event-driven rescreening, escalation and investigation of potential matches, freezing or other legally required action, record keeping, staff training, independent testing and timely reporting by way of Compliance Reporting Form to the Financial Reporting Authority (FRA) where required. FSPs should ensure that screening tools, data quality, lists, matching thresholds, alert handling and outsourcing arrangements are demonstrably appropriate for their business and risk profile.
Although not directly referenced in the Sanctions Rules, the FRA introduced new annual reporting obligation in 2025 which requires entities holding frozen assets linked to Designated Persons (DP) under the UK sanctions law to file a report by 30 November 2025. If accounts are blocked solely by other national agencies i.e. OFAC, you do not need to report. This obligation applies to all entities holding funds or economic resources owned, held or controlled by a DP listed under the UK sanctions laws. The report must detail all funds or economic resources, including asset types, values and account details as at 30 September 2025 and details provided in the Frozen Asset Reporting Template. The annual reporting should thereafter take place using the Compliance Reporting Form. The forms can be found here: Forms & Documents – Financial Reporting Authority
Key Action Points Before 18 September 2026
- Complete a documented gap analysis against the requirements of both Rules and (where needed) maintain a clear remediation tracker.
- Demonstrate Governing Body awareness of the Rules, steps taken to implement and approval of the updated compliance programme, risk assessment and implementation plan, with decisions recorded in board minutes.
- Confirm officer appointments and document the authority, independence, reporting lines, capacity and resources of the AMLCO, MLRO and DMLRO.
- Refresh the business risk assessment so that ML/TF/PF risks, control effectiveness, residual risk and approval are clearly evidenced (including reference to the Cayman Islands NRA).
- Update policies and operating procedures to describe procedures and controls covering customer due diligence, beneficial ownership, enhanced and simplified due diligence, politically exposed persons, ongoing monitoring, suspicious activity escalation and reporting, record keeping, internal controls, new products and technologies, reliance and outsourcing, including the frequency of review, evidence, escalation for any remediation measures and demonstration of the oversight of the Governing Body.
- Review all outsourcing arrangements, including contracts, due diligence (on suitability and qualifications), basis of outsourcing, service levels, information access, monitoring, breach notification and exit planning.
- Assess/implement training and screening for all relevant personnel and Governing Body members; address role-specific knowledge gaps.
- Establish an independent audit review plan, identify the next review date and reviewer, and confirm compliance with the external-review cycle requirement.
- Consider improving management information so the Governing Body receives meaningful indicators on onboarding, monitoring, overdue reviews, alerts, suspicious activity, training, breaches and remediation.
- Strengthen sanctions controls by documenting the sanctions risk assessment, confirming list update and rescreening processes, testing matching thresholds and data quality, validating alert escalation and reporting procedures (including SARS and Compliance Reporting Forms to the Cayman Islands FRA), and reviewing any outsourced screening service.
- Frozen assets — ensure awareness of obligations to freeze accounts and assess whether any assets have been frozen which have not yet been reported to the FRA and, if so, file the report.
- Create an evidence pack containing approvals, minutes, risk assessments, policies, registers, contracts, monitoring records, training evidence, review reports and remediation closure.
Preparing for Supervisory Scrutiny
Following the 18 September 2026, FSPs should expect scrutiny to focus not only on whether required documents exist and can be made available to CIMA, but on whether arrangements under both Rules are tailored, implemented, tested and supported by reliable records. A defensible framework will link the AML/CFT/CPF and sanctions risk assessments to controls, demonstrate active Governing Body oversight, show that outsourced providers have been diligenced and outsourced functions are monitored, evidence effective sanctions screening and escalation, and provide a credible audit trail from issue identification through to remediation.
Official Rules Source:
Rule on Effective Compliance Programme for the Prevention and Detection of ML/TF/PF
Rule on Compliance with Financial Sanctions and Targeted Financial Sanctions
This article is a general regulatory overview and does not constitute legal advice. Financial services providers should assess both Rules against their particular activities, sanctions exposure, risk profile and existing arrangements, and seek Cayman Islands legal or regulatory advice where appropriate.
August 2026