Circular
Key Findings of Registered Persons from On-site Inspections (2022-07-12)
Issued 2022-07-12View on CIMA's website Source document
Summary
This is a Supervisory Information Circular issued by the Cayman Islands Monetary Authority (CIMA) on 12 July 2022, summarizing key weaknesses found during on-site AML/CFT/CPF/Sanctions inspections of Registered Persons (RPs) under the Securities Investment Business Act (SIBA), covering inspections finalized between 24 October 2020 and 31 December 2021. It is not a new rule but a findings report intended to alert RPs and, more broadly, all Financial Service Providers (FSPs), to common compliance gaps observed in 53 inspected RPs (mainly Securities Managers, Advisors, Arrangers and Broker Dealers).
The circular details statistical findings across nine areas, plus separate findings from a sample of 205 customer files (covering CDD documentation, risk assessments, ongoing monitoring, sanctions screening, source of wealth/funds, and EDD/SDD). For each area it references the specific Anti-Money Laundering Regulations (AMLRs) provisions and AML Guidance Notes sections that set out the underlying legal requirements.
- AML/CFT policies and procedures
- CDD and ongoing monitoring
- Employee training
- Oversight of outsourced compliance functions
- Independent AML/CFT audit function
- Board/governance oversight
- Internal reporting
- Risk-based approach application
- Record keeping
While the circular itself does not create new legal obligations, it reiterates existing AMLR/Guidance Notes obligations and warns that non-compliance may lead to enforcement action, including administrative fines. These reiterated obligations include:
- Maintaining documented AML/CFT policies
- Conducting CDD/EDD/SDD
- Ongoing monitoring
- Training
- Independent audit
- Board oversight
- Outsourcing due diligence
- Internal reporting via MLRO/DMLRO
- Risk assessments
- Record keeping
- Sanctions screening
RPs are told to review their own frameworks against these findings, and the Authority notes it is pursuing individual enforcement actions against inspected RPs where appropriate.
Key obligations
- Maintain AML/CFT policies, procedures, systems and controls appropriate to the nature, size and complexity of the business, and review procedural manuals at least annually or upon significant regulatory changes (AMLR reg. 5(a)).
- Conduct a gap analysis between group-wide AML/CFT programmes and Cayman Islands AML/CFT requirements before relying on group programmes, and whenever regulatory or group programme changes occur, remediating any gaps identified.
- Obtain and document reliable identification and verification information for beneficial owners, directors, authorised persons and other relevant parties as part of CDD (AMLR reg. 12).
- Implement and document ongoing monitoring systems, including periodic customer file reviews and transaction monitoring, to keep CDD records current.
- Establish and document employee AML/CFT training and awareness programmes, including tailored training for the AMLCO/MLRO and directors, and maintain training records (AMLR reg. 5(c)-(d)).
- Ensure Board (or equivalent) oversight of the AML/CFT compliance function, including documented approval of AML/CFT policies and governance structures, and periodic reporting by the AMLCO to the Board (AMLR reg. 3(1), 5(e)).
- Establish an effective, independent, risk-based AML/CFT audit function to periodically evaluate AML/CFT systems and controls (AMLR reg. 5(a)(ix)).
- Where AML/CFT compliance functions are outsourced/delegated, maintain documented outsourcing policies, agreements, service provider due diligence, periodic risk assessments, and Board oversight of outsourced functions (AMLR reg. 3(2)).
- Maintain adequate internal reporting procedures, including designation of an independent MLRO/DMLRO not conflicted by business duties, SAR/FRA registers, and logs of FRA enquiries (AMLR reg. 34).
- Document a business-wide and customer-level risk assessment and risk-based approach methodology, review and update customer risk assessments, and have them approved by senior management (AMLR reg. 8).
- Maintain records in accordance with AMLR reg. 31 so that they are accessible to the Authority, the FRA, and law enforcement upon request.
- Maintain sanctions screening documentation to evidence compliance with applicable Cayman Islands sanctions obligations (AMLR reg. 5(a)(v) and (viiib)).
Applies to
Registered Persons (RPs) under Schedule 4 and section 5(4) of the Securities Investment Business Act, Financial Service Providers (FSPs) more broadly