Rule

Rule - Effective Compliance Programme for the Prevention and Detection of ML, TF, PF

Cayman Islands Monetary Authority (CIMA) · Cayman Islands

Status not confirmed

Current version last checked: 2026-07-26

Summary

This CIMA Rule sets minimum requirements for an effective anti-money laundering, counter-terrorist financing and counter-proliferation financing (ML/TF/PF) compliance programme for all Financial Services Providers (FSPs) it regulates. It supplements existing Anti-Money Laundering Regulations (Regulations 3, 4, 5, 6, 8 and 8A) and has the force of law, taking precedence over prior guidance notes or policy statements where inconsistent.

  • Governance and designations: The Governing Body must establish a governance framework and designate an AMLCO, MLRO and DMLRO, each a natural person at management level or above, with defined roles, independence and adequate resources.
  • Risk-based approach: FSPs must develop and document a risk management framework, including periodic risk assessments covering customers, products, transactions, geography and delivery channels.
  • Policies, procedures and controls: FSPs must maintain detailed written policies, procedures and controls covering the full compliance programme, including record-keeping, PEP registers, SAR handling and sanctions monitoring.
  • Training and screening: FSPs must deliver an ongoing compliance training programme for staff and the Governing Body, and screen employees appropriately.
  • Effectiveness testing: FSPs must conduct periodic independent audits of the compliance programme (internal audits allowed for no more than two consecutive cycles), remediate deficiencies, and file audit reports with CIMA.
  • Suspicious activity reporting: FSPs must ensure suspicious activity is reported internally to the MLRO/DMLRO, file SARs with the Financial Reporting Authority without delay, and must not tip off customers or third parties about a SAR or related investigation.
  • Reliance on third parties: An FSP that relies on a third party or group member to perform AML/CFT/CPF functions remains ultimately responsible for compliance.

The Rule applies to all FSPs regulated and supervised by CIMA under the Regulatory Acts, including their branches, subsidiaries, affiliates and other members of a CIMA-regulated financial group. It takes effect on 18 September 2026, sixty days after Gazette publication, and breaches are subject to CIMA's enforcement powers under its Enforcement Manual and other statutory provisions.

Key obligations

  • Establish and maintain a Compliance Programme commensurate with the FSP's size, complexity, structure, nature of business and risk profile.
  • Designate an AMLCO, MLRO and DMLRO who are natural persons operating at no lower than management level, and ensure they are fit, qualified and independent.
  • Develop, document and implement a risk-based approach including periodic ML/TF/PF risk assessments.
  • Maintain detailed written policies, procedures and controls, including records of declined business, PEP registers, SARs, transaction alerts and sanctions monitoring.
  • Deliver an ongoing compliance training programme and training plan for staff, the Governing Body and other relevant parties, and screen employees appropriately.
  • Conduct periodic audits of the effectiveness of the Compliance Programme by independent, suitably qualified persons, not internally for more than two consecutive audit cycles.
  • File the audit report with CIMA as soon as practically possible after completion, or as otherwise prescribed by the Authority.
  • Implement remediation measures to address deficiencies identified in audits within timeframes proportionate to their nature, materiality and risk.
  • Report suspicious activities or transactions to the MLRO or DMLRO and safeguard confidentiality of such information.
  • File a Suspicious Activity Report with the Financial Reporting Authority without delay where ML/TF/PF is known, suspected, or reasonably suspected.
  • Do not disclose to a customer or third party that a SAR has been or will be made, or that an investigation is or may be underway.
  • Remain ultimately responsible for compliance even where AML/CFT/CPF functions or audits are outsourced to a third party or group member.

Applies to

Financial Services Providers (FSPs) regulated and supervised by CIMA under the Regulatory Acts, branches, subsidiaries and affiliates of CIMA-regulated entities, members of a CIMA-regulated financial group

Deadlines

  • 18 September 2026: Effective date of the Rule, being sixty days after publication in the Gazette.

Topics

Version history

2026-07-26

source file (current)