Client Advisories

Primary contacts
Cayman Islands

Simon Thomas

Partner, Head of Investment Funds & Co-Head of Corporate
Cayman Islands

Tim Dawson

Partner
Hong Kong

James McKeon

Partner
21 August 2026

New CIMA rules on AML/CFT compliance and financial sanctions

Campbells provides an overview of two new CIMA rules on AML/CFT/CPF compliance and financial sanctions, coming into force on 18 September 2026, highlighting key requirements and actions for CIMA-regulated entities.

The Cayman Islands Monetary Authority (“CIMA“) has issued two new rules (the “Rules“) which come into force on 18 September 2026:

  • the Rule on Effective Compliance Programme for the Prevention and Detection of Money Laundering, Terrorist Financing and Proliferation Financing for Financial Services Providers (the “Compliance Programme Rule“); and
  • the Rule on Compliance with Financial Sanctions and Targeted Financial Sanctions (the “Sanctions Rule“).

CIMA has also published accompanying FAQs (the “FAQS”), available at www.cima.ky/aml-cft-faqs.

What are these rules?

The Rules apply to all CIMA regulated entities, including investment funds. They do not introduce fundamentally new substantive obligations. Rather, they consolidate requirements that already exist under existing legislation including the Anti-Money Laundering Regulations (2025 Revision) (the “AMLRs“) and CIMA’s Guidance Notes (broadly, the “Cayman AML and Sanctions Regime”).

However, the Rules have the force of law, which strengthens CIMA’s ability to take direct enforcement action for non-compliance.

Although the Rules stress the importance of each given entity implementing a risk-based approach commensurate to its operations which allows for variability in approach, we expect that the Rules will be used as a yardstick for compliance with the Cayman AML and Sanctions Regime.

The Compliance Programme Rule

This Rule sets out the minimum requirements for an effective AML/CFT/CPF compliance programme. Its core components will be familiar to regulated entities and include:

  • Governance: a clear governance framework with defined roles and responsibilities, including designation of an AML Compliance Officer, Money Laundering Reporting Officer and Deputy MLRO at managerial level;
  • Risk-based approach: documented risk assessments in order to identify the risks applicable to each entity in order that they may be mitigated. This includes the factors set out in the AMLRs, including customers, products, geographies and delivery channels. The risk assessments must be kept current and reported to the governing body;
  • Policies and procedures: written policies approved by the governing body documenting each entity’s policies, procedures and control mechanisms and which at a minimum address risk assessment and application of a risk-based approach, customer due diligence, ongoing monitoring, record-keeping, suspicious activity reporting, outsourcing and notification to CIMA of material outsourced functions and sanctions compliance.
  • Training: an ongoing, documented training programme delivered at least annually and tailored to the entity’s risk profile; and
  • Demonstration of effectiveness: periodic independent audits of the compliance programme, with internal audits limited to two consecutive cycles before an external review is required. Such audits are required to be filed with CIMA.

The Sanctions Rule

The Sanctions Rule consolidates existing obligations regarding financial sanctions and targeted financial sanctions (“TFS“) compliance. Particular stipulations include:

  • Screening obligations — applicants, customers, beneficial owners, transactions and service providers must be screened against applicable sanctions lists;
  • Re-screening on list updates — all customers must be re-screened whenever a sanctions list is updated, regardless of their risk classification (i.e. simplified due diligence does not reduce screening obligations);
  • Asset freezing without delay — funds or economic resources of designated persons must be frozen without delay and without prior notice; and
  • Geographic risk — a customer’s geographic risk cannot be assessed as “low” where the relevant country is subject to sanctions related to ML/TF/PF risks.

Internal audit requirements

The requirement for risk-based AML audits of an entity’s Cayman AML and Sanctions Regime compliance function already exists under the AMLRs. There is no prescribed frequency for internal audits, with the appropriate frequency depending on a given entity’s risk profile. CIMA gives the example of a higher risk rated business carrying out an internal audit every two years and a lower risk business every four years.

However, there is a requirement to file each internal audit report with CIMA as soon as reasonably practicable after its completion.

An AML Audit may be conducted by internal audit functions; external auditors; independent consultants; or other suitably qualified and competent independent parties.

The auditor must be independent of the AML/CFT/CPF/TFS function and activities being audited and must not be involved in the operation, management or oversight of the Compliance Programme.

With respect to investment funds in particular, the FAQs provide that:

[CIMA] expects that an AML Audit of an individual Fund(s) should obtain sufficient and appropriate evidence to conclude on the design and operating effectiveness of the Compliance Programme of the individual Fund(s). Accordingly, relying solely on a service-provider-level internal audit or a population-based review, without obtaining sufficient evidence regarding the individual Fund’s Compliance Programme, would not provide sufficient assurance of the effectiveness of the AML Audit.”

On the one hand this indicates that it is permissible for a fund to rely on the independent internal audit function of an appointed AML service provider, subject to the governing body remaining responsible for demonstrating to CIMA that such audits provide sufficient objective assurance of the service provider’s compliance programme. On the other hand, consideration will need to be given as to how each given fund will be able to demonstrate that the AML service provider’s compliance programme is effective for it specifically.

We expect that market practice with respect to meeting this compliance obligation will develop.

What should clients be doing?

We recommend that all CIMA regulated clients:

  1. Review existing compliance programmes against the specific requirements of the new Rules and the FAQS to confirm alignment and identify any gaps. The publication of the Rules creates an opportunity to assess whether the current compliance framework is demonstrably effective or whether an alternative structure should be implemented. For instance, if clients are currently maintaining compliance programmes themselves, they should consider whether it adequately meets the requirements of the Cayman AML and Sanctions Regime or whether they ought to outsource any functions to AML compliance service specialists.
  2. Ensure documentation is comprehensive, as the Rules and the FAQs place particular emphasis on the ability to demonstrate compliance to CIMA upon request. This goes to both ensuring a documented compliance framework is in place, including any outsourcing arrangements, even if as between a fund and its sponsor (where relevant) and that regular records are maintained of performance of all elements of the compliance programme and tracking of remediation actions, where applicable; and
  3. Confirm governance arrangements — particularly that the AMLCO, MLRO and DMLRO designations meet the requirements and that reporting lines to the governing body are clearly documented.

Please reach out to us for any queries on the rules, as we would be very happy to assist.