Circular

Non-Face-to-Face Customer Due Diligence Measures (2023-11-09)

Cayman Islands Monetary Authority (CIMA) · Cayman Islands

Issued 2023-11-09

Current version last checked: 2026-07-05

Summary

This is a Supervisory Information Circular issued by the Cayman Islands Monetary Authority (CIMA) on 9 November 2023, explaining amendments made in August 2023 to CIMA's Guidance Notes on the Prevention and Detection of Money Laundering and Terrorist Financing. The amendments incorporate new provisions on electronic KYC (e-KYC) and remote/non-face-to-face customer due diligence (CDD) and ongoing monitoring, in response to queries from financial service providers about whether CIMA's AML/CFT/CPF framework permits technology-based, non-face-to-face onboarding.

The circular summarises, without being exhaustive, the key changes to the Guidance Notes:

  • New definitions: Remote onboarding, e-KYC, video-conferencing and non-face-to-face business relationships are newly defined.
  • Risk assessment of delivery channels: FSPs must assess ML/TF risks associated with remote delivery channels and align verification methods to risk, including tiered CDD.
  • Technology risk assessment: FSPs must perform formal risk assessments of any new e-KYC/digital ID technology used.
  • Policies and procedures: Documented policies and procedures are expected covering technology use, record retention, anti-fraud/cyber-security, back-up plans, and ongoing review of system effectiveness.
  • Verification of legal persons/arrangements: Guidance is provided on verifying legal persons/arrangements via public registries and video-conferencing.
  • 'Selfie' verification: Standards are set for 'selfie' document verification.
  • Simplified due diligence: Use of lower-assurance digital ID is permitted for simplified due diligence in low-risk cases.
  • Record-keeping: Record-keeping requirements apply to identification data obtained through digital systems.

The circular applies to CIMA-regulated financial service providers and is intended as guidance highlighting changes already embedded in the Guidance Notes and underlying AML Regulations, rather than creating new standalone legal obligations itself. Actual obligations stem from the Anti-Money Laundering Regulations, 2023 and the amended Guidance Notes referenced throughout.

Key obligations

  • FSPs must verify customer identity using reliable, independent source documents, data or information (per AMLR s.12(1)(a) and Guidance Notes 4A3(1))
  • FSPs should assess ML/TF risks associated with their delivery channels, including remote onboarding and ongoing monitoring, and align CDD/verification methods to that risk assessment
  • FSPs must carry out formal risk assessments of any new e-KYC or digital ID technology before use
  • FSPs should conduct additional verification measures where a customer, product, service or jurisdiction presents higher ML/TF risk
  • FSPs should maintain robust documented policies and procedures governing use of digital ID/e-KYC technology, covering tiered CDD, secure record retention, authority access to underlying identity data, anti-fraud/cyber-security controls, back-up plans for technology failure, risk indicators for reverting to non-remote methods, and ongoing review of system effectiveness
  • Where constitutive/formation documents cannot be verified via video-conferencing or electronic methods due to unavailable public sources, FSPs must seek alternative verification measures (e.g. certified true copies or digitally signed soft copies)
  • Where using photograph/'selfie' verification, FSPs should obtain a colour photograph clearly showing the person's face holding the identity document, plus a clear scanned or photographed copy of the identity document itself
  • FSPs must ensure records of identification data obtained through digital ID/e-KYC systems are easily accessible, properly maintained, and available to competent authorities upon request

Applies to

financial service providers (FSPs)

Topics

Version history

2026-07-05

source file (current)