Circular
Supervisory Issues & Information Circular (2017-10-17)
Issued 2017-10-17View on CIMA's website Source document
Summary
This is the inaugural edition of CIMA's Supervisory Issues & Information Circular, a bi-annual publication in which the Authority highlights thematic and regulatory issues it has identified through its on-site and off-site supervisory work. It is an informational communication rather than a new law or rule, intended to alert licensees to current concerns and encourage best practices in areas such as AML/CFT, outsourcing, cybersecurity, and risk management.
Topics Covered
- De-risking: 'De-risking' of high-risk clients, particularly affecting money service businesses' access to banking.
- CFATF and National Risk Assessment: The Cayman Islands' upcoming CFATF mutual evaluation and the National AML/CFT Risk Assessment.
- Outsourcing: Expectations around outsourcing governance under the 2015 Statement of Guidance on Outsourcing.
- Cybersecurity: Growing attention to data security and cybersecurity risk management.
- Risk registers: The use of dynamic 'risk registers' for enterprise risk management.
- Fraud and AML convergence: The convergence of fraud prevention with AML programmes.
- AML/CFT programme expectations: Detailed expectations for a well-functioning AML/CFT programme, including client risk rating methodologies, review frequencies, and monitoring of suspicious activity.
The document applies broadly to CIMA-regulated licensees across sectors, with specific reference to money service businesses. While much of the content is framed as guidance, reminders, and forward-looking supervisory focus areas (for example, the Authority stating it will examine data security practices and inquire about risk register practices), it also restates existing binding requirements, such as the obligation to risk-rate clients under section 3.109 of the Guidance Notes on the Prevention and Detection of Money Laundering and Terrorist Financing, and suggests indicative periodic review timelines for high, medium, and low risk clients.
Key obligations
- Licensees must conduct a risk assessment of their clients and distinguish between high and low risk cases in accordance with section 3.109 of the Guidance Notes on the Prevention and Detection of Money Laundering and Terrorist Financing in the Cayman Islands.
- Clients given a default/initial risk rating at on-boarding should be reviewed under a full risk assessment methodology within one year at the latest.
- Licensees should conduct periodic AML/KYC reviews of clients at risk-appropriate intervals (generally every 6-12 months for high-risk, 12-24 months for medium-risk, and 24-36 months for low-risk clients).
- Licensees should document the rationale whenever a risk-based decision is made to exclude certain customer transactions from AML surveillance.
- Licensees conducting outsourcing arrangements must perform due diligence and risk assessment of service providers and maintain supervisory responsibility for outsourced functions, consistent with the 2015 Statement of Guidance on Outsourcing.
- Licensees should review and, where appropriate, streamline or expand their AML programmes to incorporate fraud prevention and detection measures.
- Licensees should maintain robust AML/CFT programmes covering risk assessment, designated compliance responsibility, risk-based CDD, reportable transaction identification, segregation of duties, staff training, and recordkeeping.
Applies to
licensees, money service businesses
Deadlines
- within a year after on-boarding at most: Clients assigned a default risk rating at on-boarding should be reviewed under a full risk assessment methodology.
- every 6-12 months: Suggested periodic AML/KYC review frequency for high-risk clients.
- every 12-24 months: Suggested periodic AML/KYC review frequency for medium-risk clients.
- every 24-36 months: Suggested periodic AML/KYC review frequency for low-risk clients.