Circular

Onsite Inspections Findings, Licensees' AML/CFT Supervisory Approach & Thematic Review (2017-09-01)

Cayman Islands Monetary Authority (CIMA) · Cayman Islands

Issued 2017-09-01

Current version last checked: 2026-07-05

Summary

This is a CIMA Supervisory Information Circular dated 1 September 2017 covering three related topics: onsite inspection follow-up classification, CIMA's risk-based AML/CFT supervisory approach for general insurance business, and the aggregate findings of a thematic AML/CFT review of eight insurance licensees.

Onsite Inspection Findings

Following changes introduced in June 2016 and reflected in the July 2017 Regulatory Handbook amendments, all corrective actions arising from onsite inspection findings are now classified solely as 'Requirements'; the earlier categories of 'Recommendations' and 'suggestions' have been discontinued. The circular also clarifies that Statements of Guidance (SoGs) are binding as they buttress the Rules and Laws.

AML/CFT Supervisory Approach

The circular explains CIMA's risk-based AML/CFT supervisory approach as applied to licensees conducting general (non-life) insurance business. While general insurance is generally lower AML/CFT risk than life insurance, it is not risk-free and remains subject to the AML Guidance Notes.

Thematic Review Findings

The circular summarises the aggregate findings of a thematic AML/CFT review of eight insurance licensees, highlighting widespread compliance gaps.

  • Identification procedures
  • Introduced business
  • Monitoring
  • Suspicious activity reporting
  • Compliance management
  • Training
  • Record keeping

The document applies broadly to CIMA licensees generally with respect to onsite inspection follow-up, and more specifically to insurance licensees (including insurance managers, general insurers and life insurers) with respect to the AML/CFT supervisory approach and thematic review findings. It is primarily informational/explanatory but reiterates and reinforces existing binding obligations under the Money Laundering Regulations, AML Guidance Notes, Insurance Law and related legislation, and signals that CIMA is prepared to take enforcement action against licensees failing to comply.

No new law or rule is created by this circular itself; rather it restates CIMA's supervisory expectations and puts licensees on notice of areas of common weakness identified during the thematic review, urging the wider industry to review and strengthen their own AML/CFT policies, procedures and controls accordingly.

Key obligations

  • Licensees must adopt and implement onsite inspection 'Requirements' within the time frames specified in each Requirement.
  • Licensees must provide monthly update reports to CIMA until Requirements arising from onsite inspections are fully implemented, indicating status, remedial actions taken and estimated completion date.
  • If implementation of a Requirement is delayed beyond the dates stipulated in the onsite inspection report, the Licensee must bring this to CIMA's attention and highlight it in the monthly update report.
  • Insurance licensees, including general insurers, must adopt sound risk management and internal controls in line with the AML Guidance Notes; general insurers are not exempt from these requirements.
  • Licensees must maintain anti-money laundering policies, procedures and practices as required by section 5(1) of the Money Laundering Regulations, including customer identification, record-keeping, internal controls, communication procedures and employee training before forming business relationships or carrying out one-off transactions.
  • Licensees must obtain and verify full identity and documentary evidence for prospective customers, including nature of business and expected transaction patterns, before entering into a business relationship.
  • Licensees relying on Eligible Introducers for introduced business remain ultimately responsible for ensuring adequate due diligence and satisfactory documentary evidence of identity.
  • Licensees with business relationships predating 30 September 2003 must have established procedures to assess and risk-rate existing clients and prioritise obtaining required identification information for high-risk clients.
  • Licensees must conduct ongoing monitoring of business relationships, including routine reviews to keep identification data up to date.
  • Licensees must maintain written internal procedures for reporting suspicious activity and designate a suitably qualified Money Laundering Reporting Officer (and ideally a deputy).
  • Licensees must appoint a Compliance Officer (who may also be the MLRO) with sufficient seniority, resources and direct board access.
  • Licensees must provide regular AML/CFT training to appropriate staff.
  • Licensees must maintain transaction records for at least 5 years to enable prompt response to information requests from competent authorities.

Applies to

Licensees (CIMA-regulated entities generally), Insurance Managers, Class B insurers, general insurance licensees, life insurance licensees, Financial Service Providers

Topics

Version history

2026-07-05

source file (current)