Rule

Rule and Statement of Guidance - Market Conduct for Virtual Asset Service Providers

Cayman Islands Monetary Authority (CIMA) · Cayman Islands

In force

Current version last checked: 2026-07-05

Summary

This document is a Rule and Statement of Guidance (RSOG) issued by CIMA setting out market conduct requirements for Virtual Asset Service Providers (VASPs) authorised under the Virtual Asset (Service Providers) Act. It applies to all CIMA-regulated entities licensed, registered, or granted a waiver to provide virtual asset services, and is intended to be read alongside CIMA's other regulatory measures (AML regulations, cybersecurity rules, outsourcing guidance, corporate governance rules, etc.).

  • Integrity and conflicts of interest
  • Client asset safeguards
  • Insurance
  • Marketing and promotions
  • Client onboarding and agreements
  • Complaints handling
  • Public disclosures
  • Cross-border transactions
  • Proprietary trading
  • Specific obligations for Virtual Asset Trading Platforms (VATPs) and Virtual Asset Custodians

Among the visible provisions, the document sets out several specific requirements for Regulated Entities.

  • Conduct standard: Act honestly, with due skill and care, and in clients' best interests.
  • Conflicts of interest: Establish written policies for identifying and managing conflicts of interest, including a conflicts register and periodic disclosure by directors and senior officers.
  • Confidentiality: Maintain confidentiality of client information.
  • Authorisation and documentation: Ensure decisions and transactions are properly authorised, documented and actioned without delay.
  • Withdrawal/closure disclosures: Disclose withdrawal/closure timeframes and limits to clients.

Later sections, not fully reproduced here, address incident and breach notification obligations for custodians, including 72-hour notification to CIMA and to clients, as well as detailed reconciliation and recordkeeping requirements for Virtual Asset Custodians, such as maintaining client position registers and performing at least daily reconciliations.

The RSOG contains both binding rules and guidance provisions.

Key obligations

  • Rule
  • ,
  • the document takes effect upon publication in the Gazette, and breaches are subject to enforcement action under CIMA's Enforcement Manual and its statutory powers.
  • key_obligations must document and implement written policies ensuring the firm acts in clients' best interests (Section 6.2).
  • Regulated Entities must maintain adequate segregation of duties among critical functions (e.g., onboarding, execution, custody, compliance) commensurate with size and risk profile (Sections 6.13, 6.17).
  • Regulated Entities must disclose conflicts of interest (or potential conflicts) to clients in writing with sufficient detail to enable informed decisions (Section 6.15).
  • Directors and senior officers must disclose conflicts of interest to the Governing Body at least annually, and declare and recuse themselves from new conflicts as they arise (Section 6.16).
  • Regulated Entities must maintain confidentiality of client information and demonstrate it is used only for the purpose obtained (Sections 6.6-6.7).
  • Regulated Entities must inform clients of typical timeframes and any limits for withdrawals or account closures (Section 6.12).
  • Virtual Asset Custodians must notify CIMA no later than 72 hours after discovery of a material security/incident, and notify affected clients promptly (and in any event within 72 hours) unless directed otherwise by authorities.
  • Virtual Asset Custodians must document all incidents (material or not) internally and make records available to CIMA upon request.
  • Virtual Asset Custodians must reconcile client asset balances at suitable, frequent intervals (at minimum daily for own and client assets) and maintain a register of client positions.
  • Virtual Asset Custodians must provide clients with mechanisms to verify their balances or positions.
  • Regulated Entities must observe all RSOG requirements on an ongoing basis and must not circumvent them.

Applies to

Virtual Asset Service Providers (VASPs), Regulated Entities licensed or registered under the Virtual Asset (Service Providers) Act, Virtual Asset Trading Platforms (VATPs), Virtual Asset Custodians

Deadlines

  • upon publication in the Gazette: Effective date of the Rule and Statement of Guidance.
  • no later than 72 hours after discovery of a material incident: Virtual Asset Custodians must notify CIMA of a material security/operational incident.
  • no later than 72 hours from detection: Virtual Asset Custodians must notify affected clients of a material incident, unless directed otherwise by investigative or regulatory authorities.
  • at least an annual basis: Directors and senior officers must disclose conflicts of interest to the Governing Body.

Topics

Version history

2026-07-05

source file (current)