
CIMA’s New AML and Sanctions Rules Take Effect on 18 September 2026
New CIMA Rules introduce more detailed requirements around AML compliance programmes, independent audits, and financial sanctions, with specific implications for regulated investment funds and their governing bodies.
The Cayman Islands Monetary Authority will bring two new Rules into effect on 18 September 2026, strengthening the regulatory framework around anti money laundering, countering the financing of terrorism, countering proliferation financing, and financial sanctions. The two measures are the Rule on Effective Compliance Programme for the Prevention and Detection of Money Laundering, Terrorist Financing and Proliferation Financing for Financial Services Providers, and the Rule on Compliance with Financial Sanctions and Targeted Financial Sanctions. CIMA says the Rules are intended to support an effective, proportionate, and risk based framework for identifying, assessing, managing, and mitigating money laundering, terrorist financing, proliferation financing, and sanctions related risks.
What Does the New AML Rule Cover
The AML Compliance Programme Rule applies to financial services providers that conduct Relevant Financial Business, as defined under the Proceeds of Crime Act, and are regulated by CIMA under the Regulatory Acts. The Rule supplements the existing Anti Money Laundering Regulations and should be read alongside them, since the Regulations remain the primary legal basis for AML, CFT, and CPF compliance and prevail where there is any inconsistency with the Rule.
CIMA says the framework remains risk based. The Rule establishes minimum requirements while allowing flexibility in implementation based on proportionality, and it is intended to strengthen the effectiveness of AML, CFT, and CPF compliance programmes, with greater emphasis on governance, accountability, and consistent implementation.
Independent AML Audits for Investment Funds
One area CIMA has specifically clarified is the independent AML audit requirement for regulated investment funds. CIMA confirms that a regulated investment fund must undertake an AML Audit under Regulation 5(a)(ix) of the AMLRs, even where all, or substantially all, of its operations are outsourced.
The requirement to conduct effective, risk based AML audits is not new, and already exists under the AMLRs. The new Rule provides additional clarity regarding CIMA’s supervisory requirements and how the effectiveness of a compliance programme should be demonstrated. For an individual fund, CIMA expects the audit to consider the fund’s specific policies, controls, and procedures, including investor onboarding controls, ongoing due diligence, investment objectives and policies, third party relationships and outsourcing, internal reporting, training, record keeping, and application of the risk based approach. The audit should obtain sufficient and appropriate evidence to reach conclusions on the design and operating effectiveness of the individual fund’s Compliance Programme.
Can a Fund Rely on Its Service Provider’s Audit
CIMA permits financial services providers, including funds regulated under the Mutual Funds Act and Private Funds Act, to consider independent audit reports from outsourced service providers as part of their internal control and oversight frameworks. However, this does not remove the fund’s own responsibilities.
CIMA states that the Governing Body remains responsible for demonstrating that such reports provide sufficient, objective assurance over the effectiveness of the fund’s Compliance Programme and its compliance with applicable AML, CFT, CPF, and targeted financial sanctions obligations. The Governing Body should therefore consider whether the scope of the service provider’s independent audit is sufficiently relevant to the AML activities performed on behalf of the fund.
How Often Must an AML Audit Be Conducted
CIMA does not prescribe a fixed audit frequency, and the new Rule does not require annual AML Audits. Instead, the frequency, scope, and depth of an AML Audit should be determined using a risk based approach, taking into account factors including the financial services provider’s size, complexity, business activities, and exposure to money laundering, terrorist financing, proliferation financing, and sanctions related risk.
| Risk Profile | Illustrative Audit Cycle |
|---|---|
| Higher risk financial services provider | Approximately every 2 years |
| Medium risk financial services provider | Approximately every 3 years |
| Lower risk financial services provider | Approximately every 4 years |
These are examples rather than prescribed audit cycles. The Rule does, however, require at least one external AML audit for every three independent audit cycles, a requirement CIMA says is intended to mitigate familiarity, self review, and objectivity risks by ensuring that the Compliance Programme periodically receives an external assessment.
Who Can Conduct the AML Audit
Independence is a key requirement. CIMA defines independence in this context as the auditor being free from actual or perceived conflicts of interest and not being responsible for the design, operation, management, or oversight of the Compliance Programme being reviewed. An AMLCO, MLRO, or DMLRO therefore cannot independently audit activities for which that person is responsible, including where those functions are outsourced.
CIMA does not prescribe a single risk based audit methodology for investment funds. The auditor may adopt an approach proportionate to the nature, scale, and complexity of the fund, but should obtain sufficient and appropriate evidence to support conclusions about the design and effectiveness of the fund’s Compliance Programme.
Governing Body Oversight
The new framework also places emphasis on effective oversight by the Governing Body. CIMA expects Governing Bodies to receive and review reports on the operation and effectiveness of the Compliance Programme, understand the financial services provider’s exposure to the relevant risks, provide appropriate challenge and oversight, ensure sufficient and appropriately qualified resources are available, and oversee the timely remediation of identified deficiencies. CIMA says this oversight should be evidenced through appropriate governance records, including minutes, reports, documented decisions, and the tracking of remediation actions where applicable.
A Separate Rule for Financial Sanctions
The second Rule addresses Compliance with Financial Sanctions and Targeted Financial Sanctions. CIMA says this Rule is intended to promote compliance by Regulated Persons with existing domestic and international legal obligations relating to financial sanctions that are in force in the Cayman Islands. Unlike the AML Compliance Programme Rule, the Financial Sanctions Rule applies to all Regulated Persons supervised by CIMA under the Regulatory Acts, irrespective of whether they conduct Relevant Financial Business.
What Should Investment Funds Consider Ahead of 18 September
For regulated investment funds, the new Rules provide an opportunity to review whether existing arrangements meet CIMA’s requirements and supervisory expectations. Areas for consideration include the effectiveness of the fund’s Compliance Programme, the scope and independence of AML audits, the adequacy of assurance obtained from outsourced service providers, oversight of outsourced activities, Governing Body documentation, and applicable financial sanctions controls.
For funds with substantially outsourced operating models, CIMA’s guidance makes an important distinction. Outsourced arrangements can form part of the fund’s compliance framework, but the fund and its Governing Body remain responsible for demonstrating the effectiveness of that framework.
Preparing Your Fund for CIMA’s 18 September Deadline
Auvene Operating Partners supports Cayman regulated funds with AML compliance programme reviews, audit coordination, and Governing Body reporting ahead of CIMA’s revised AML and financial sanctions requirements.
Visit auvenegroup.comSource: Cayman Islands Monetary Authority, AML/CFT FAQs and Investment Funds Regulatory Measures. This article is provided for general information only and does not constitute legal or regulatory advice.






Leave a Reply