Notice
AML/CFT Obligations and Requirements for Excluded Persons (2019-02-01)
Issued 2019-02-01View on CIMA's website Source document
Summary
This is a CIMA general industry notice dated 1 February 2019 addressed to companies registered as Securities Investment Business Law (SIBL) 'Excluded Persons'. It reminds these entities that, despite being excluded from full licensing under SIBL, they remain subject to the Anti-Money Laundering Regulations (2018 Revision) and the AML/CFT Guidance Notes, and are required to prevent and report money laundering, terrorist financing and proliferation financing. The notice explains that CIMA has been exercising its power under Section 5(5) of SIBL to require Excluded Persons to have their AML/CFT systems and procedures independently audited by suitably qualified entities, and that CIMA uses these audit reports to assess ongoing AML/CFT compliance and to set the frequency of future audits for each company.
Expected Audit Coverage
- Adequacy of AML/CFT policies, internal controls and risk management
- Fitness and propriety of the company and its directors
- Periodic reviews against best practice
- Client risk matrices and due diligence/KYC procedures
- Suspicious activity reporting logs
- Record-keeping, including for wire transfers
- AML training for staff and the MLRO
- Gap analysis where group-wide policies are adopted
- Separation of the AML Compliance Officer and MLRO roles from shareholders
- Accuracy of marketing materials
Common Deficiencies Found in 2018 Audit Reports
- Undocumented or unimplemented policies
- Unvetted group-wide policy adoption
- Missing or inconsistent client risk matrices
- Weak ongoing monitoring
- Inconsistent suspicious activity reporting
- Inadequate training evidence
CIMA encourages Excluded Persons to strengthen their AML/CFT frameworks in these areas. The notice is primarily informational/reminder in nature, reiterating existing statutory and regulatory obligations rather than creating new ones, though it confirms CIMA's practice of requiring periodic independent AML/CFT audits from this sector.
Key obligations
- Comply with the Anti-Money Laundering Regulations (2018 Revision) and AML/CFT Guidance Notes applicable to relevant financial business, including securities investment business.
- When requested by CIMA, arrange for AML/CFT systems and procedures to be audited by a suitably qualified entity.
- Maintain adequate AML/CFT policies, procedures, internal controls and risk management, and ensure their implementation.
- Ensure the company and its directors carry on business in a fit and proper manner.
- Conduct periodic reviews of operations against AML/CFT requirements and current industry best practice.
- Maintain a client risk matrix and adequate client identification/due diligence procedures, including KYC, customer risk rating and enhanced due diligence.
- Maintain adequate internal reporting procedures, including a suspicious activity reporting log.
- Maintain adequate record-keeping procedures in accordance with prescribed retention periods under the AMLRs, including for wire transfers.
- Provide adequate AML training to management, staff and the Money Laundering Reporting Officer (MLRO).
- Where group-wide AML policies are adopted, conduct a gap analysis to confirm compliance with the Cayman Islands AML/CFT framework.
- Maintain separation between the roles of Anti-Money Laundering Compliance Officer and MLRO from the company's shareholders.
- Ensure marketing materials do not contain false or misleading representations or omissions that could mislead investors.
Applies to
SIBL Excluded Persons (companies registered to conduct securities investment business as Excluded Persons)