Circular

General Overview: Audit Firms, BEC Schemes, Board Proxies & Other (2019-09-06)

Cayman Islands Monetary Authority (CIMA) · Cayman Islands

Issued 2019-09-06

Current version last checked: 2026-07-05

Summary

This is a CIMA supervisory circular from September 2019 that bundles together several unrelated supervisory topics for Licensees and Financial Service Providers in the Cayman Islands. It applies broadly to CIMA-regulated Licensees and Financial Service Providers, board directors of such entities, and Class A insurers.

  • Audit firm selection: Offers guidance on factors to weigh when choosing an audit firm: experience, staffing, independence, fees, reputation, and peer reviews.
  • BEC cyber-fraud: Warns about a rise in successful Business Email Compromise (BEC) cyber-fraud attacks and sets expectations for internal controls and incident reporting.
  • Board proxies: Raises concerns about overuse/misuse of proxies at board meetings.
  • Ownership/control changes: Reiterates the requirement to obtain CIMA's prior approval before any change in ownership or control of a Licensee.
  • Class A health insurance statistics: Announces a change in how the Authority will present Class A health insurance statistics going forward, splitting 'domestic health' and 'international health', with historical 2011-2017 figures restated.

The circular does not create a single new regulatory regime but reinforces existing legal requirements, such as the prior approval requirement for changes in ownership or control, while also giving softer supervisory expectations around audit firm selection, cybersecurity controls, and proxy usage that Licensees should factor into their governance and risk practices.

Overall it functions as an advisory/reminder circular rather than a rule-making instrument, though it does restate binding obligations under existing regulatory laws, notably the prior-approval requirement for ownership/control changes, and imposes an expectation of immediate incident reporting for cyber fraud.

Key obligations

  • Financial Service Providers and Licensees should implement robust internal controls (e.g., call-back verification, additional proof of identity, restricting fund transfers to previously verified accounts, in-person meetings for large transfers) to verify identity and approve transactional email instructions.
  • Where a Licensee suspects it has been the victim of a BEC attack or other cybercrime, it must immediately file an incident report with the Financial Crime Unit of the Royal Cayman Islands Police Service and the Financial Reporting Authority.
  • Licensees must also notify the Authority of a suspected cyber incident and complete the Authority's Cyber Incident Report.
  • The board and senior management of Financial Service Providers and Licensees are responsible for ensuring effective, comprehensive cybercrime policies and procedures are implemented, embedded, independently reviewed, tested, and updated.
  • Shares of Licensees must not be issued or transferred without the Authority's prior approval; applications for change in ownership or control must be submitted and approved before the transfer takes place.
  • Licensees and those acting on their behalf must carry out their own due diligence and submit comprehensive change-in-ownership/control applications, including the full group structure and all Ultimate Beneficial Owner (UBO) information.
  • An audit firm engaged by a Licensee must be independent, and Licensees may not appoint an audit firm that is a closely related entity or has common ownership with the Licensee.

Applies to

Licensees, Financial Service Providers, Class A Insurers, audit firms, board of directors

Deadlines

  • immediately: A Licensee that suspects it has been the victim of a BEC attack or other cybercrime must immediately file an incident report with the Financial Crime Unit and the Financial Reporting Authority, and notify the Authority via the Cyber Incident Report.

Topics

Version history

2026-07-05

source file (current)