Statement of Guidance

Statement of Guidance - Nature, Accessibility and Retention of Records (April 2023)

Cayman Islands Monetary Authority (CIMA) · Cayman Islands

In force

Current version last checked: 2026-07-05

Summary

This is a CIMA Statement of Guidance, effective April 2023, setting out the Authority's minimum expectations for how entities it regulates should keep, secure, and retain their records. It is not itself a law and does not override any Act, but CIMA says it will take the guidance into account in its supervisory work, including onsite inspections.

  • Scope: Applies to all entities regulated or registered under the regulatory Acts as defined in the Monetary Authority Act, regardless of sector.
  • Related guidance: Meant to be read alongside the Statement of Guidance on Outsourcing, the Anti-Money Laundering Regulations, and CIMA's AML/CFT Guidance Notes.
  • Records to be kept: Corporate, accounting, organisational, risk management, client, service provider, CDD and annual return records, among others.
  • Accessibility: Records must generally be accessible to CIMA within 1-3 business days.
  • Retention period: A general minimum retention period of five years from the transaction date applies, unless another Act specifies differently.
  • Accounting record content: The guidance addresses requirements for the content of accounting records.
  • Third parties and group structures: Addresses use of third parties and group structures for record-keeping.
  • Records held outside the Cayman Islands: Addresses maintenance of records outside the Cayman Islands.
  • Language: Records must be in English.
  • Electronic records: The guidance addresses the use of electronic records.
  • Mergers, transfers, and cessation: Addresses what should happen to records when an entity merges, transfers, or ceases business.

Because it is guidance rather than binding rules, most of its provisions are framed as expectations ('should'), though some paragraphs use 'must' (for example, regarding accessibility to CIMA, accounting record adequacy, and safeguarding records), which entities should treat as firm requirements CIMA will look for during supervision.

Key obligations

  • Regulated entities must maintain records that are legible, accessible, and provided to CIMA generally within 1-3 business days of request (or such other timeframe as CIMA determines), regardless of where the records are stored.
  • Regulated entities must maintain records in their original format (including electronic copies) for a minimum of five years after the transaction date, or any longer period stipulated in applicable regulatory or other Acts.
  • Each legal entity within a group must adopt record-keeping practices meeting the objectives of this Guidance, appropriate to its own operations, even if a group-wide standard is used; records kept by another group member must remain accessible to CIMA.
  • Regulated entities must establish a records management system covering categorisation, retention periods, and disposal of records, with a comprehensive record retention policy aligned with regulatory Acts.
  • Regulated entities must maintain adequate procedures for the availability, maintenance, security, privacy and preservation of records (including electronic records) to safeguard against loss, unauthorised access, alteration or destruction.
  • Records must be kept in English or professionally translated into English without delay at CIMA's request, with the original-language version retained.
  • Where a third party maintains records on behalf of a regulated entity, the regulated entity retains ultimate responsibility for record retention, compliance, and ensuring CIMA can access the records in a timely fashion.
  • Regulated entities must keep proper accounting records sufficient to show and explain their transactions and commitments, including specified minimum content (assets/liabilities, income/expenditure, investments/documents of title, day-to-day transaction entries), for a minimum of five years or as required under the AML Regulations.
  • Where records are held outside the Cayman Islands, the regulated entity must ensure the data is kept secure, operational risk is mitigated, the Confidential Information Disclosure Act is complied with, and CIMA has access at all reasonable times within the timeframe in section 4.2.
  • A regulated entity should not keep records outside the Cayman Islands if access by CIMA is likely to be restricted or delayed by confidentiality or data protection restrictions; in that case the same records should be maintained within the Cayman Islands.
  • Regulated entities are expected to have a plan for treatment of records upon merger, transfer or cessation of business, and to inform CIMA of where and how records may be accessed once the entity ceases business; record-keeping requirements continue to apply for the period required by applicable Acts.
  • Electronic records must be of good quality, accurately reflect any underlying paper record, be complete, unaltered, and easily accessible and reproducible in hard copy; safeguards must be in place before destroying paper records that have been converted to electronic form.

Applies to

entities regulated or registered under the regulatory Acts as defined in the Monetary Authority Act ("Regulated Entities")

Deadlines

  • 1-3 business days: Expected timeframe within which most records should be provided to CIMA from the time they are requested (or such other timeframe as determined by CIMA from time to time).
  • five years after the transaction date: Minimum period regulated entities should maintain records in their original format, unless another applicable Act specifies a different period.

Topics

Version history

2026-07-05

source file (current)