Circular

AML/CFT & Sanctions Onsite Inspections & Findings Pt 1 (2019-03-08)

Cayman Islands Monetary Authority (CIMA) · Cayman Islands

Issued 2019-03-08

Current version last checked: 2026-07-05

Summary

This is a CIMA supervisory circular (Part 1) summarising the results of the Authority's 2018 onsite inspection programme, with a focus on AML/CFT and sanctions compliance. It explains the purpose and forms of onsite inspections (full-scope, limited-scope, thematic reviews) and reports that 164 inspections were conducted in 2018 (up from 117 in 2017), of which 53 focused primarily on AML/CFT and sanctions, generating 1,144 documented requirements across licensees.

Common Deficiency Areas

The circular breaks down the most common deficiency areas found, with AML/CFT and Sanctions risk accounting for 42% of requirements, followed by Corporate Governance, Operational Management, Business Continuity Management, and Internal/External Audit.

  • AML/CFT deficiencies: Outdated or deficient policies, inadequate PEP procedures, weak CDD/KYC documentation, insufficient training records, and RBA (risk-based approach) shortcomings.
  • Corporate Governance deficiencies: Failure to notify CIMA of director/auditor changes, lack of Board self-assessments, and missing conflict-of-interest policies.

The document urges all CIMA licensees to review these common findings, take remedial steps to strengthen their AML/CFT and governance frameworks, and remain alert to regulatory developments, including anticipated changes arising from the 2017 CFATF peer review and the Authority's new administrative fines powers under the Monetary Authority Law (2017) and related 2017 Regulations. It is primarily informational/awareness-raising rather than a source of new binding rules, restating and reinforcing existing regulatory expectations rather than creating new ones.

Key obligations

  • Licensees should review and remediate the AML/CFT policy, CDD/KYC, training, and risk-based approach deficiencies identified in the circular to ensure ongoing compliance with applicable AML/CFT laws, regulations and guidance notes.
  • Licensees should address corporate governance deficiencies noted, including notifying the Authority of changes or new appointments (e.g., directors, external auditors) as required under existing regulatory requirements.
  • Licensees are expected to perform periodic internal AML/CFT audits and maintain documented gap analyses against applicable regulatory requirements, consistent with existing obligations highlighted as areas of non-compliance.
  • Licensees are encouraged to remain proactive in monitoring industry and regulatory developments arising from the CFATF peer review and related legislative changes.

Applies to

Licensees (all CIMA-regulated Financial Service Providers across sectors)

Topics

Version history

2026-07-05

source file (current)