Advisory

Advisory - AML/CFT Compliance During COVID-19 (2020-04-21)

Cayman Islands Monetary Authority (CIMA) · Cayman Islands

Issued 2020-04-21

Current version last checked: 2026-07-05

Summary

This is a non-binding advisory issued by CIMA on 21 April 2020 to help its regulated entities maintain adequate AML/CFT/CPF and sanctions compliance during the COVID-19 pandemic. It explicitly states it is not a legal document and cannot be relied upon for points of law; underlying obligations remain those set out in the relevant AML/CFT statutes and CIMA's Guidance Notes.

Heightened ML/TF Risks

The advisory highlights heightened money laundering and terrorist financing risks arising from COVID-19 and sets out CIMA's expectations for how regulated entities should adapt their AML/CFT systems and controls while working remotely.

  • Fraudulent investment schemes
  • Misuse of stimulus funds
  • Increased use of virtual assets
  • Increased use of cash-intensive businesses

Remote Customer Verification

The advisory addresses acceptable alternative methods for verifying customer identity remotely, while stressing that normal verification processes should be completed as soon as practicable.

  • Video conferencing
  • 'Selfie' verification
  • E-format statements/bills
  • Recently expired government ID issued after 1 March 2020

Other Compliance Expectations

  • Risk assessments: Updating institutional risk assessments
  • Deviations: Documenting any deviations from normal compliance practices and the plan to revert to them
  • Training: Providing AML/CFT training online
  • Electronic signatures: Considering the validity of electronic signatures
  • Engagement with CIMA: Continuing engagement with CIMA during remote/off-site supervision and inspections
  • Deadline extensions: Deadline extensions will be considered case-by-case

The document applies broadly to all CIMA-regulated entities subject to AML/CFT obligations.

Key obligations

  • Regulated entities must continue to comply with customer identity verification obligations, using risk-based remote verification methods (e.g. video conferencing, certified 'selfie' documents, e-format statements/bills, or recently expired government ID) where normal processes are impractical.
  • Where a deviated/remote verification method is used, the regulated entity must complete verification using normal processes as soon as practicable.
  • Regulated entities should impose risk-based restrictions (e.g. transaction limitations) on new relationships where verification has not yet been completed by normal means.
  • Regulated entities should update Institutional Risk Assessments to reflect heightened ML/TF risks arising from COVID-19 and consider recalibrating transaction monitoring systems.
  • Regulated entities must document steps taken to mitigate ML/TF/PF/sanctions risks due to COVID-19, including reasons for any deviation from normal compliance practices and evidence of the plan to return to normal practices afterward.
  • Regulated entities are encouraged to provide AML/CFT/CPF/sanctions training via online platforms, and must retain documentation where in-person training was postponed or cancelled.
  • Regulated entities must consider the legal and counterparty acceptability of electronic signatures and appropriate arrangements for witnessing them.
  • Regulated entities must continue to report suspicious activities and comply with sanctions obligations as required by relevant laws.
  • Regulated entities should continue to interact and communicate with CIMA during remote supervisory activities and inspections.

Applies to

regulated entities

Topics

Version history

2026-07-05

source file (current)