Rule
Rule and Statement of Guidance – Internal Controls for Regulated Entities (April 2023)
In forceIn force effective 2023-10-14, gazetted in Rule and Statement of Guidance - Internal Controls for Regulated Entities. (EX27, S3) (computed: published 2023-04-14 + 6 months)
View on CIMA's website Source document
Summary
This is a Rule and Statement of Guidance issued by the Cayman Islands Monetary Authority (CIMA) in April 2023 setting out minimum requirements for internal controls at all entities CIMA regulates under the regulatory acts. It is built around five components of internal control: control environment, risk identification and assessment, control activities and segregation of duties, information and communication, and monitoring activities/correcting deficiencies. Requirements are proportional to each entity's size, complexity, structure and risk profile, and entities may rely on a service provider's or group's internal control system if the Governing Body can demonstrate it meets the Rule's requirements.
Part I: General Requirements
Part I applies generally to all regulated entities and imposes binding rules (marked 'R') on the Governing Body and Senior Management.
- Establishing and documenting internal control systems and organisational structure
- Demonstrating independence or managing conflicts of interest
- Ensuring staff competence
- Fostering an ethical control culture
- Holding individuals accountable for internal control responsibilities
Part II: Sector-Specific Operational Controls
Part II adds sector-specific operational control rules for two groups.
- Trust companies, company managers and corporate services providers: Covers segregation of client assets/money, disclosure of terms on which client money is held, prompt reconciliation, dual-signatory authorisation for payouts, and prevention of misuse of client money
- Securities investment business licensees and registered persons (market makers, broker-dealers, securities arrangers, advisors, managers): Covers conflict-of-interest management, discretionary account procedures, dealing/review controls, and segregation of client funds and property
Breach of the rules is enforced under CIMA's Enforcement Manual and its powers under the regulatory acts and the Monetary Authority Act. The Rule and Statement of Guidance takes effect six months after its publication in the Gazette.
Key obligations
- The Governing Body must ensure an adequate and effective system of internal control is established, documented, and maintained.
- The Governing Body must demonstrate independence from Management or, where not reasonably possible, put in place documented policies and procedures to identify and manage conflicts of interest.
- A regulated entity must establish and document its organisational structure, including functions, reporting lines, responsibility and authority, and keep it current.
- A regulated entity must demonstrate that activities are conducted by persons with sufficient knowledge, skills and experience, with regularly updated staff training.
- Regulated entities must demonstrate a commitment to integrity and ethical values and establish a culture reinforcing internal controls.
- Regulated entities must hold persons assigned internal control responsibilities accountable for performance of those responsibilities.
- Trust companies, company managers and corporate services providers must segregate client assets and client money from other clients' assets/money and from the entity's own assets/money.
- Trust companies, company managers and corporate services providers must provide appropriate written disclosure to clients on the terms on which client money is held and reconcile client money accounts promptly.
- Trust companies, company managers and corporate services providers must implement at least dual-signatory authorisation for client money pay-outs and policies preventing inappropriate use of client money (e.g. for settling the entity's own fees).
- Securities investment business licensees and registered persons must establish policies and procedures to minimise conflicts of interest and ensure clients are fully informed and treated fairly where conflicts cannot be avoided.
- Securities investment business licensees and registered persons exercising discretionary authority over a client account must establish procedures ensuring terms are communicated to clients and only strategy-consistent transactions are executed.
- Securities investment business licensees and registered persons must maintain procedures to prevent/detect errors, omissions, fraud and unauthorised activity, and ensure fair and timely allocation of trades.
- Securities investment business licensees and registered persons must ensure client funds and property are clearly segregated from the entity's own funds and property.
Applies to
all entities regulated by CIMA under the regulatory acts, trust companies, company managers, corporate services providers, securities investment business licensees, registered persons undertaking regulated activities of market makers, broker-dealers, securities arrangers, securities advisors, and securities managers
Deadlines
- within six months of the date of publication in the Gazette: The Rule and Statement of Guidance comes into effect.