Circular

TCSPs Onsite Inspections Findings & Administrative Fine Regime (2017-02-01)

Cayman Islands Monetary Authority (CIMA) · Cayman Islands

Issued 2017-02-01

Current version last checked: 2026-07-05

Summary

This is a Supervisory Information Circular issued by CIMA on 1 February 2017, sharing a non-exhaustive summary of common compliance deficiencies identified during its 2016 on-site inspection cycle of trust and company services providers (TCSPs). It also flags a 2016 amendment to the Monetary Authority Law that introduces a new administrative fines regime for regulatory breaches, noting that supporting regulations were still being finalised at the time of writing.

AML/CFT Findings

  • Inadequate periodic client reviews and risk-rating differentiation.
  • Generic (non-specific) descriptions of nature of business and source of funds.
  • Uncertified KYC documentation.
  • Failure to consistently apply the licensee's own KYC policies and procedures.
  • Illegible or non-English identification documents without certified translation.
  • AML policy/procedure manuals not kept current with legislative changes.
  • Training programmes that excluded the board of directors or did not address specialised business risks.
  • Failure to test the reliability of Eligible Introducer arrangements relied upon for KYC purposes.

The circular is directed at TCSP licensees and urges them to review these findings against their own practices and take remedial action where applicable. It does not itself create new legal rules but reiterates existing expectations under the Companies Management Law, the Banks and Trust Companies Law (2015 Revision), and the Guidance Notes on the Prevention and Detection of Money Laundering and Terrorist Financing.

Administrative Fines Regime

  • Minor breaches: Non-discretionary fines of $5,000 per breach, up to $20,000 if ongoing.
  • Serious/very serious breaches: Discretionary fines ranging from $50,000 to $1,000,000 per breach.

Key obligations

  • Conduct regular reviews of existing clients and appropriately differentiate risk ratings, with supporting documentation
  • Document the specific nature of business and source of funds for clients rather than using generic descriptions
  • Certify copies of KYC documentation in accordance with the minimum standard in the AML Guidance Notes
  • Collect and maintain KYC documentation in accordance with the licensee's own established policies and procedures
  • Ensure identification documents held on file are legible and in English, or supported by a certified translation
  • Regularly review and update AML policies and procedures manuals to reflect current legislation and the licensee's own risk assessments, including where group manuals are relied upon
  • Provide AML training to all staff and board members, tailored to their roles and the specialised risks of the business, at a frequency appropriate to risk and complexity
  • Test the reliability of Eligible Introducer arrangements to confirm introducers can meet their documentary obligations when required

Applies to

trust and company services providers (TCSPs), licensees under the Companies Management Law, licensees under the Banks and Trust Companies Law

Topics

Version history

2026-07-05

source file (current)