Rule

Rule – Virtual Asset Custodians and Virtual Asset Trading Platforms

Cayman Islands Monetary Authority (CIMA) · Cayman Islands

Status not confirmed

Current version last checked: 2026-07-05

Summary

This is a CIMA regulatory Rule setting out the ongoing conduct, governance, prudential and operational requirements that apply to entities licensed or registered as virtual asset custodians and virtual asset trading platforms under the Virtual Asset (Service Providers) Act.

  • Governance: Governance and fitness-and-propriety expectations for governing bodies.
  • Conduct of business: Standards on conflicts of interest, fair treatment of clients, disclosure, marketing, complaints handling, and client agreements.
  • Outsourcing: Outsourcing controls.
  • Data and records: Data protection and record-keeping.
  • Prudential requirements: Minimum regulatory capital, capital adequacy reviews, recovery planning, stress testing and insurance.
  • Risk management: Risk management and internal controls.
  • Trading platform rules: Platform-specific rules covering market conduct, clearing/settlement, pricing transparency, listing rules, and leveraged trading protections.
  • Reporting and enforcement: Regulatory reporting obligations, with breaches dealt with under the Authority's Enforcement Manual and other statutory powers.

The Rule applies specifically to virtual asset custodians and virtual asset trading platforms regulated by CIMA under the Act, and is stated to be read alongside other CIMA measures on AML/CFT, governance, outsourcing, cybersecurity and related topics. Several individual provisions in the source text are marked 'Repealed', indicating that parts of the original Rule (e.g. certain conflicts-of-interest, client protection, data protection and enforcement clauses) have been removed or superseded, though the overall document's current legal status is not confirmed here. The Rule states it takes effect upon commencement of the relevant licensing provisions of the Act for custodians and trading platforms, with early adoption encouraged.

Because the source file is labeled 'Repealed' and several clauses within the body text are marked as repealed, readers should verify with CIMA's current regulatory measures page whether this version remains in force or has been replaced by a newer Rule before relying on it for compliance purposes.

Key obligations

  • Ensure the governing body is composed of fit-and-proper, suitably qualified individuals and obtain CIMA's prior written approval for changes to ownership, directors and senior officers
  • Conduct periodic risk assessments (cybersecurity, AML/CFT, sanctions, custody, data protection, client protection) and an annual assessment of directors'/senior officers' performance and suitability
  • Maintain documented policies to identify, manage and disclose conflicts of interest, and require directors/senior officers to disclose conflicts to the governing body at least annually
  • Provide clients with fair, clear, non-misleading information, full disclosure of fees/commissions/capacity, and written risk warnings, updated on an ongoing basis
  • Establish and maintain complaints-handling policies, log complaints, make the log available to CIMA, and report to CIMA any complaints indicating material risk or control failures
  • Notify CIMA and obtain approval of a wind-down plan before ceasing virtual asset services
  • Enter into written client agreements meeting Act requirements and provide written transaction confirmations
  • Develop a comprehensive outsourcing policy with due diligence, periodic review, contingency plans and exit strategies, and remain responsible for outsourced functions
  • Maintain systems to safeguard information security/confidentiality and keep orderly, auditable records of business, transactions and client interactions available to CIMA on request
  • Notify and/or seek CIMA's prior approval for specified changes (business plans, share issuance/transfer, senior officer appointments)
  • Hold regulatory capital equal to the higher of risk-based capital, six months' fixed overheads, or an amount set by CIMA, and review capital adequacy at least annually or on material business change
  • Notify CIMA of any breach of regulatory capital requirements and maintain a documented recovery plan with defined triggers
  • Undertake stress testing and sensitivity analysis when calculating required capital
  • Maintain appropriate insurance (professional liability, loss of custodied client assets, business interruption, cybersecurity) where appropriate
  • Establish sound internal controls and forward-looking risk management practices appropriate to the business's size and complexity
  • For trading platforms: establish robust, stress-resilient trading systems, clearing/settlement procedures, transparent and publicly available pricing policies, listing rules with due diligence for admitting virtual assets, and policies restricting listing of assets with anonymisation features unless holder/transaction identification is possible
  • For trading platforms offering financing/leveraged trading: disclose terms and risks, limit client losses, and maintain appropriate insurance
  • Establish a framework for regulatory reporting obligations to CIMA and other relevant authorities and provide requested reporting as prescribed by the Authority

Applies to

virtual asset custodians, virtual asset trading platforms

Deadlines

  • upon commencement of the relevant sections of the Act relating to licensing of virtual asset custodians and virtual asset trading platforms: Effective date of the Rule; early adoption is encouraged before this commencement
  • at least annually: Governing body must assess performance/suitability of directors and senior officers, and review capital adequacy, at least once a year (or sooner upon material business change)
  • at least annually: Directors and senior officers must disclose conflicts of interest to the governing body

Topics

Version history

2026-07-05

source file (current)