Circular
AML/CFT On-site and Off-site Supervision of the Virtual Asset Service Providers (2025-09-18)
Issued 2025-09-18View on CIMA's website Source document
Summary
This is a CIMA supervisory circular explaining how the Authority carries out AML/CFT (including CFT, proliferation financing and sanctions) supervision of Virtual Asset Service Providers (VASPs) through on-site inspections and off-site desk-based reviews. It describes CIMA's risk-based supervisory approach, its use of the Strix SupTech system to score AML risk and analyse Travel Rule return data, and summarises key findings from inspections and a targeted desk-based review conducted between 2023 and February 2025.
The circular sets out common deficiencies CIMA identified across VASPs.
- Inadequate or undocumented business/customer risk assessments
- Weak oversight of technology used for AML/CFT compliance
- Gaps in customer due diligence and enhanced due diligence
- Poor ongoing transaction monitoring
- Deficient sanctions screening and record-keeping
- Insufficient board oversight of the compliance function
- Missing outsourcing agreements
- Absent or non-independent AML/CFT audit functions
- Generic or non-Cayman-specific staff training
- Delays or errors in Travel Rule return submissions
It also notes that one VASP's registration was cancelled on 5 June 2025 due to serious corporate governance and AML/CFT control failures.
While the circular is largely informational and does not create new legal obligations beyond those already contained in the Anti-Money Laundering Regulations (AMLRs) and AML Guidance Notes, it reiterates CIMA's expectation that all VASPs review these findings, remediate any similar deficiencies in their own AML/CFT frameworks within timeframes set by CIMA, and periodically reassess their compliance programmes for adequacy relative to their nature, size and complexity. It reminds all financial service providers that breaches of AML/CFT laws, regulations or rules may result in enforcement action, including administrative fines.
Key obligations
- VASPs must ensure business and customer risk assessments are properly documented, cover all relevant risk factors (customer, jurisdiction, transaction, delivery channel) and are kept up to date.
- VASPs relying on technology solutions (e.g. e-KYC, transaction monitoring, screening tools) must conduct adequate risk assessments and assurance reviews of those solutions.
- VASPs must conduct and document customer due diligence, including verification using reliable independent sources, and maintain constitutional documents for legal-person customers.
- VASPs must apply enhanced due diligence where required (e.g. PEPs, suspicious activity, high-risk jurisdictions) and document EDD procedures, including identification/verification of beneficial owners and controlling directors.
- VASPs must conduct timely ongoing monitoring of business relationships and scrutinise transactions, including fiat currency transactions, with proper escalation procedures.
- VASPs must maintain sanctions compliance policies and procedures applicable to the Cayman Islands, including obligations to freeze funds and report to the Financial Reporting Authority, and must conduct and document sanctions screening at onboarding and on an ongoing basis.
- VASPs must designate an AMLCO who reports periodically to the Board, and the Board must actively oversee and approve/review AML/CFT policies and procedures.
- VASPs outsourcing or delegating AML/CFT compliance functions must have outsourcing agreements in place and retain ultimate responsibility for compliance.
- VASPs must establish an operationally independent AML/CFT audit function to periodically evaluate AML/CFT systems and controls.
- VASPs must provide AML/CFT/CPF training relevant to the Cayman Islands regulatory framework and maintain records evidencing such training.
- VASPs must maintain adequate record-keeping systems to ensure timely provision of information to CIMA upon request, including CDD, transaction and sanctions screening records.
- VASPs must comply with Travel Rule requirements, including verifying originator/beneficiary information and submitting quarterly Travel Rule Returns on time.
- VASPs must remediate deficiencies identified by CIMA within the timeframes (or approved extended timeframes) specified in CIMA's remediation reports and engage with CIMA through progress reports during remediation.
- VASPs must periodically assess their AML/CFT compliance programmes to ensure they remain appropriate for the nature, size and complexity of their business.
Applies to
Virtual Asset Service Providers (VASPs), financial service providers (FSPs)