Circular

2017 AMLRs Key Changes, Outsourcing AML/CFT Operations & FASB Updates (2017-11-22)

Cayman Islands Monetary Authority (CIMA) · Cayman Islands

Issued 2017-11-22

Current version last checked: 2026-07-05

Summary

This is a 2017 CIMA supervisory circular summarizing major changes brought by the Anti-Money Laundering Regulations, 2017 (AMLRs), which replaced the Money Laundering Regulations (2015 Revision) and came into force on 2 October 2017.

Key AMLR Changes

  • Expanded scope: The scope of 'relevant financial business' has expanded, e.g. to cover fund/money management for others and life insurance underwriting/placement.
  • New definitions: New definitions have been added for beneficial owner, PEP, and legal person/arrangement.
  • Risk-based approach: Financial service providers (FSPs) must now adopt a risk-based approach (RBA) to AML/CFT, implement employee screening, and conduct sanctions and FATF non-compliant territory checks.
  • Deputy MLRO: Mandatory appointment of a Deputy Money Laundering Reporting Officer is required.
  • Due diligence changes: Enhanced due diligence requirements apply for higher-risk customers and PEPs, alongside changes to simplified due diligence and eligible-introducer assurances.
  • Equivalent-jurisdictions list: The old 'Schedule 3' equivalent-jurisdictions list has been removed and is now maintained by the AML Steering Group, with Mexico, Panama and Turkey excluded as of 5 October 2017.
  • Increased penalties: Penalties for contravention have increased substantially, up to CI$500,000 on summary conviction, or on indictment, fines and up to two years' imprisonment.

Outsourcing of AML/CFT Functions

The circular separately addresses outsourcing of AML/CFT functions, reminding FSPs that outsourcing arrangements, including intra-group ones, must comply with CIMA's Statement of Guidance on Outsourcing and must not diminish the FSP's ultimate responsibility for compliance.

  • Minimum expectations: Outsourcing arrangements must meet minimum expectations including a written agreement, a contingency/exit plan, monitoring processes, unimpeded data access, and audit/risk controls equivalent to the regulated entity's own standards.

Accounting Standard Changes

Finally, the circular flags upcoming accounting standard changes relevant to banks and insurers.

  • FASB CECL standard: FASB's current expected credit loss (CECL) standard (ASU 2016-13) takes effect for FASB-reporting banks on 1 January 2020.
  • IFRS 9 parallel calculations: Banks under the Banks and Trust Companies Law that follow IASB/IFRS 9 have been running parallel calculations since the June/July 2017 Quarterly Prudential Return to assess capital impact.
  • Insurance contract disclosures: FASB's ASU 2015-09 introduces disclosure enhancements for short-duration insurance contracts, which CIMA is still assessing for impact on licensees.

Key obligations

  • FSPs must adopt a documented risk-based approach (RBA) to AML/CFT, including identifying, assessing, managing, monitoring and periodically re-evaluating ML/TF risks.
  • FSPs must establish and implement employee screening procedures.
  • FSPs must conduct sanctions checks and checks against FATF non-compliant territories.
  • FSPs must appoint a Deputy Money Laundering Reporting Officer in addition to the Money Laundering Reporting Officer.
  • FSPs must apply enhanced due diligence (EDD) to higher-risk customers, including politically exposed persons, their family members and close associates, and to customers/business from high-risk jurisdictions or correspondent banking relationships.
  • Where relying on simplified due diligence, FSPs must ensure any lower-risk assessment is consistent with the national risk assessment or a Supervisory Authority's findings, not made unilaterally.
  • Where relying on eligible introducers, FSPs must obtain enhanced written assurances, including source-of-funds confirmation and assurance that identification/verification data will be made available on request.
  • FSPs outsourcing AML/CFT functions (including intra-group) must comply with CIMA's Statement of Guidance on Outsourcing and retain ultimate responsibility for compliance.
  • Before outsourcing a compliance function or MLRO/DMLRO position, an FSP must assess associated risks (including country risk) and must not proceed if risks cannot be effectively managed and mitigated.
  • Intra-group outsourcing arrangements must include, at minimum: a written outsourcing agreement, a contingency/exit plan, monitoring/reporting/oversight processes, unimpeded data access, and audit/risk controls equivalent to the regulated entity's own.
  • Banks licensed under the Banks and Trust Companies Law that follow IASB accounting standards (excluding branches of foreign banks) must continue performing parallel runs for IFRS 9 impairment impact as part of the Quarterly Prudential Return process.
  • Banks following FASB accounting standards must meet the requirements of ASU 2016-13 (CECL) by its effective date.

Applies to

financial service providers (FSPs), banks, trust companies, insurance entities/insurers, investment entities

Deadlines

  • 2 October 2017: Effective date on which the Anti-Money Laundering Regulations, 2017 came into force, replacing the Money Laundering Regulations (2015 Revision).
  • 5 October 2017: Date the updated equivalent-jurisdictions list (replacing former Schedule 3) was issued, excluding Mexico, Panama and Turkey.
  • January 1, 2020: Effective date by which banks following FASB accounting standards must meet the requirements of ASU 2016-13 (current expected credit loss approach).
  • since the June/July 2017 Quarterly Prudential Return: Banks under the BTCL following IASB standards have been performing parallel runs to assess IFRS 9 impairment impact from this QPR onward.

Topics

Version history

2026-07-05

source file (current)