Circular

Registered Persons: Key Findings from On-site Inspections 2020 (2020-12-14)

Cayman Islands Monetary Authority (CIMA) · Cayman Islands

Issued 2020-12-14

Current version last checked: 2026-07-05

Summary

This is a Supervisory Information Circular in which CIMA reports the preliminary findings from its 2020 on-site inspections of Registered Persons (RPs) — securities managers, advisors, arrangers, broker-dealers and market makers who fall under Schedule 4 and section 5(4) of the Securities Investment Business Act (SIBA), formerly known as Excluded Persons before mandatory re-registration in 2020. The circular does not create new rules but summarizes widespread AML/CFT weaknesses found across 24 inspected RPs and 214 customer files reviewed, and reminds RPs (and more broadly all financial service providers) of their existing obligations under the Anti-Money Laundering Regulations (AMLRs) and the AML Guidance Notes.

Deficiency Rates Among Inspected RPs

  • AML/CFT policies and procedures: Deficient in 79% of RPs.
  • CDD and ongoing monitoring documentation: Deficient in 50% of RPs.
  • Outsourced compliance functions: Deficient in 33% of RPs.
  • Employee training: Deficient in 33% of RPs.
  • Risk assessment/RBA application: Deficient in 25% of RPs.
  • Board oversight of compliance: Deficient in 25% of RPs.
  • Internal reporting/MLRO independence: Deficient in 21% of RPs.
  • Independent audit function: Deficient in 17% of RPs.
  • Record-keeping: Deficient in 13% of RPs.

Customer file reviews also revealed gaps in CDD documentation, risk assessments, sanctions screening, source of wealth/funds evidence, ongoing monitoring, and SDD/EDD application.

CIMA states it has issued specific requirements to the inspected RPs to remediate identified deficiencies and may take enforcement action, including administrative fines, where appropriate. All RPs (and FSPs generally) are urged to review their own AML/CFT frameworks against these findings, noting they may be subject to future inspection.

Key obligations

  • RPs must develop, maintain and periodically review (at least annually or upon significant regulatory change) AML/CFT policies and procedures appropriate to the nature, size and complexity of their business.
  • RPs relying on group-wide AML/CFT programmes must conduct and document a gap analysis against Cayman Islands AML/CFT legislative and regulatory requirements before relying on those programmes and whenever requirements or programmes change, and must remediate any gaps identified.
  • RPs must obtain and document CDD information from reliable sources to identify and verify beneficial owners, directors, authorised parties and other relevant parties, including for one-off wire transfer transactions.
  • RPs must implement and document adequate ongoing monitoring systems to keep CDD records current, updated by risk level or upon a triggering event.
  • RPs that outsource or delegate compliance functions must maintain documented outsourcing policies, agreements setting out each party's obligations, service-provider due diligence, periodic risk assessments, and Board-level oversight of outsourced AML/CFT functions.
  • RPs must provide AML/CFT training commensurate with role and seniority to all employees, including in-depth training for the AMLCO/MLRO and training for directors/equivalent.
  • RPs must conduct and document a business-wide AML/CFT risk assessment and a documented risk-based approach (RBA) methodology, applied consistently to customer risk classifications.
  • RPs must designate an independent AMLCO/MLRO at managerial level who reports periodically to the Board or equivalent, and the Board must actively oversee AML/CFT compliance (including approving procedural manuals, receiving compliance reports, and periodic self-assessment).
  • RPs must screen customers, relevant parties and transactions against applicable sanctions lists and document the screening and resolution of potential matches.
  • RPs must maintain records management systems ensuring all relevant AML/CFT records are appropriately maintained and readily accessible to the Authority.

Applies to

Registered Persons (securities managers, securities advisors, securities arrangers, broker-dealers, market makers), financial service providers (FSPs) more broadly

Topics

Version history

2026-07-05

source file (current)