Circular

2021 Review of TCSPs Compliance with AMLRs - Customer Verification and Identity (2022-01-19)

Cayman Islands Monetary Authority (CIMA) · Cayman Islands

Issued 2022-01-19

Current version last checked: 2026-07-05

Summary

This is a CIMA supervisory circular reporting the findings of onsite AML/CFT/CPF inspections conducted in 2021 of Trust and Corporate Services Providers (TCSPs), comparing results to an earlier 2020 thematic review. It covers compliance with regulation 12 of the Anti-Money Laundering Regulations (AMLRs), which governs customer due diligence (CDD), identification and verification of beneficial owners, understanding the purpose and intended nature of business relationships, ongoing monitoring, and source of funds/wealth documentation. The review, based on 359 client files across 16 regulated entities, found significant improvement compared to 2020 but continuing weaknesses, particularly in ongoing monitoring (25% of files) and missing/inadequate CDD documentation (32% of files).

The circular does not create new legal requirements but reiterates existing obligations under regulation 12 of the AMLRs and the AML/CFT Guidance Notes, using specific examples of deficiencies found to illustrate expectations. It urges TCSPs to review their own AML/CFT frameworks against these findings and to strengthen compliance, particularly around ongoing monitoring and CDD documentation quality.

  • Expired IDs
  • Missing UBO information
  • Inadequate risk rating
  • Lack of sanctions screening evidence
  • Incomplete purpose-of-business documentation
  • Inadequate source-of-funds evidence

CIMA reminds TCSPs that breaches of the AMLRs or non-compliance with a Statement of Guidance may result in enforcement action, including administrative fines. The circular is informational/supervisory in nature, reporting inspection outcomes and reinforcing existing statutory obligations rather than introducing new rules or deadlines.

Key obligations

  • Identify and verify a customer's identity using reliable, independent source documents, data or information, per regulation 12(1) of the AMLRs.
  • Verify that any person purporting to act on behalf of a customer is properly authorised, and identify and verify that person's identity.
  • Identify beneficial owners and take reasonable measures to verify their identity using relevant information or data from reliable sources.
  • Conduct ongoing due diligence on business relationships, including scrutinising transactions to ensure consistency with the customer's known business, risk profile, and source of funds.
  • Obtain and document information on the purpose and intended nature of each business relationship.
  • Obtain, verify and retain adequate documentation on customers' source of funds/source of wealth.
  • Maintain accurate, up-to-date and properly certified CDD documentation, including timely renewal of expired identification documents.
  • Implement periodic client file reviews and ongoing monitoring systems to keep CDD information current.
  • Periodically assess and update AML/CFT compliance programmes to ensure they are commensurate with the nature, size and complexity of the business.

Applies to

Trust and Corporate Services Providers (TCSPs), Financial service providers (FSPs) generally

Topics

Version history

2026-07-05

source file (current)