Circular
Common Regulatory and Thematic Issues Pt 1 (2016-02-01)
Issued 2016-02-01View on CIMA's website Source document
Summary
This is the first edition of CIMA's Supervisory Issues & Information Circular, a bi-annual publication intended to raise industry awareness of common regulatory and thematic issues identified through CIMA's supervisory work, and to flag emerging regulatory developments. It applies broadly to CIMA licensees across the Cayman Islands financial sector rather than to a single license type.
- De-risking: Financial institutions withdrawing banking services from perceived high-risk clients, particularly money service businesses.
- CFATF mutual evaluation: The upcoming CFATF mutual evaluation of the Cayman Islands scheduled for Q2 2017.
- Outsourcing risk management: Expectations tied to CIMA's August 2015 Statement of Guidance on Outsourcing.
- Data security: Cybersecurity risk management expectations.
- Risk registers: The use of dynamic risk registers as a governance tool.
- Fraud and AML convergence: The convergence of fraud prevention and AML programmes.
A substantial portion of the document sets out CIMA's expectations for AML/CFT programmes, including required elements of a risk-based approach, client risk rating methodologies, timelines for periodic KYC reviews based on risk classification, and monitoring of suspicious activity.
Most content is guidance and expectation-setting rather than new binding rules, though it references existing binding requirements, such as the Guidance Notes on the Prevention and Detection of Money Laundering and Terrorist Financing.
Key obligations
- Licensees must conduct a risk assessment of their clients and distinguish between high and low risk cases in accordance with section 3.109 of the Guidance Notes on the Prevention and Detection of Money Laundering and Terrorist Financing (as updated August 2015).
- Clients given a default risk rating at on-boarding should be reviewed under a full risk assessment methodology within a year after on-boarding at most.
- Licensees should apply periodic AML/KYC reviews at risk-based intervals: high-risk clients every 6-12 months, medium-risk clients every 12-24 months, and low-risk clients every 24-36 months.
- Licensees must document the rationale when a risk-based decision is made to exclude certain customer transactions from AML surveillance.
- Licensees conducting due diligence and risk assessment of outsourced service providers must do so in accordance with the Statement of Guidance on Outsourcing (August 2015), and retain supervisory responsibility for outsourced covered activities.
- Licensees should maintain clearly documented and accessible client risk classification records and be able to generate risk-classification reports for regulatory review.
- Licensees should ensure appropriate delegation and communication between the AML function and personnel outside it who monitor suspicious activity.
Applies to
licensees, money service businesses
Deadlines
- Q2 2017: Cayman Islands scheduled to be reviewed by the Caribbean Financial Action Task Force (CFATF).
- within a year after on-boarding at most: Clients given a default risk rating at on-boarding should be reviewed under a full risk assessment methodology.
- every 6-12 months: Generally applied periodic AML/KYC review timeline for high-risk clients.
- every 12-24 months: Generally applied periodic AML/KYC review timeline for medium-risk clients.
- every 24-36 months: Generally applied periodic AML/KYC review timeline for low-risk clients.