Regulatory Policy

Regulatory Policy - Approval of an Auditor for a Regulated Entity

Cayman Islands Monetary Authority (CIMA) · Cayman Islands

Status not confirmed

Current version last checked: 2026-07-05

Summary

This is a CIMA regulatory policy setting out the criteria and process by which the Cayman Islands Monetary Authority approves external auditors ('Approved Auditors') for entities it licenses or registers ('Regulated Entities'). It applies wherever a Regulatory Act under the Monetary Authority Act requires a Regulated Entity to have its financial statements audited by an Authority-approved auditor, unless an audit exemption has been granted.

Approval Criteria

  • Physical presence: Physical presence in the Cayman Islands.
  • CIIPA registration: CIIPA registration and good standing.
  • Independence and ethics: Independence and ethics compliance with the IESBA Code.
  • Competence: Competence of engagement partners, including a general expectation of five years' relevant auditing experience.
  • Quality management: Quality management systems aligned to ISQM1/ISQM2.
  • Insurance: Professional indemnity insurance compliance under the Accountants Act.

Practical Processes

The document also describes the practical processes firms and regulated entities must follow, and sets out CIMA's approach to notifying firms of approval or refusal. It also addresses what happens when a Regulated Entity changes its auditor, in which case CIMA may require disclosure of the circumstances.

  • Initial approval: Applying for initial approval.
  • Accepting an appointment: Accepting an appointment as an already-approved firm.
  • Amendments: Requesting amendments to approval terms.
  • Withdrawal: Withdrawing approval.

Effective Date and Transitional Provisions

The policy is not yet in force at the time of the document, dated June 2026 — it states an effective date of 1 January 2027. Transitional provisions grandfather firms already approved before that date, allowing them to retain approved status without re-evaluation, subject to ongoing compliance. Regulated Entities must comply with the auditor-approval requirement starting from their first accounting period beginning after the effective date.

Key obligations

  • Regulated Entities must have their financial statements audited and the audit report issued or signed off by a CIMA-Approved Auditor, unless an audit exemption has been granted.
  • A Firm seeking approval as an Approved Auditor must submit a formal written request with the documents required under the Auditor Approval Application Form, plus any other requested information and prescribed fees.
  • An already-approved Firm accepting a new appointment as Approved Auditor for a Regulated Entity must submit a letter of consent and the information/documents required under the Auditor Acceptance Form.
  • An already-approved Firm seeking to amend its approval terms or conditions must submit a formal written request specifying the amendment sought and its rationale.
  • A Firm ceasing to offer audit services and withdrawing its approval must submit a formal letter from CIIPA confirming withdrawal and the reasons for it, plus any prescribed fees.
  • Firms must be registered as a public practice firm under section 38 of the Accountants Act with CIIPA and remain in good standing.
  • Engagement Partners signing audit reports for Regulated Entities must be licensed as practicing members of CIIPA and in good standing.
  • Firms must comply with the Professional Indemnity Insurance requirements of the Accountants Act and Accountants Regulations.
  • Firms and Regulated Entities must, through governance mechanisms, ensure initial and ongoing compliance with the Policy's criteria (independence, competence, quality management, ethics).
  • When a Regulated Entity changes its Auditor, it (or the former Auditor) may be required by the Authority to disclose the circumstances surrounding the change.
  • Regulated Entities requiring an Approved Auditor must comply with the Policy starting from their first accounting period beginning after the Policy's effective date.

Applies to

Regulated Entities (entities licensed or registered by CIMA under the Regulatory Acts), Approved Auditors / audit Firms, Engagement Partners

Deadlines

  • January 1, 2027: Effective date on which this Policy comes into force.
  • first accounting period that begins after the Policy's effective date: Regulated Entities requiring appointment of an Auditor under this Policy must begin complying starting from this accounting period.

Topics

Version history

2026-07-05

source file (current)

2026-07-05

source file