Home Updates

Cayman Islands AML and Sanctions Rules 2026

Cayman Islands AML and Sanctions Rules 2026

AUGUST 6, 2026

Cayman Islands AML and Sanctions Rules 2026

Cayman Islands AML and Sanctions Rules 2026

Quick Read

  • Effective Date: CIMA’s new AML Rule and Sanctions Rule take effect on 18 September 2026 and apply to Cayman Islands financial service providers registered with or licensed by CIMA.

  • Key Compliance Impact: The Rules make AML/CFT/CPF and sanctions compliance expectations binding, including requirements around governance, risk assessments, AML officers, audits, training, screening, reporting and remediation.

  • Recommended Action: FSPs should review their compliance frameworks now, identify gaps and prepare remediation plans ahead of the September 2026 deadline.

Following industry consultation, on 20 July 2026, the Cayman Islands Monetary Authority (CIMA) published a new Rule on Effective Compliance Programme for the Prevention and Detection of Money Laundering, Terrorist Financing and Proliferation Financing for Financial Services Providers (AML Rule) and a new Rule on Compliance with Financial Sanctions and Targeted Financial Sanctions (Sanctions Rule).

Both Rules take effect on 18 September 2026, 60 days after publication in the Gazette. The Rules establish binding, enforceable standards for all financial service providers (“FSPs”) registered with or licensed by CIMA. Whether you operate an actively regulated mutual fund, a private fund or act as a “Registered Person” under the Securities Investment Business Act (SIBA), your compliance framework must meet these new requirements by the September 18 deadline.

What is the Purpose of the Rules?

FSPs are already subject to POCA, the Terrorism Act, the PFPA, applicable sanctions legislation, the AML Regulations and CIMA’s Guidance Notes. While the Guidance Notes have been treated as market standard, they were not themselves enforceable. The AML Rule and Sanctions Rule make key aspects of the Guidance Notes binding and enforceable, aligning the Cayman Islands’ AML/CFT/CPF framework more closely with FATF recommendations.

What is New?

The AML Rule and Sanctions Rule largely restate requirements that FSPs should already have implemented. However, the Rules introduce certain additional obligations that FSPs will need to address.

The New CIMA AML Rule

  • Codification of the Compliance Programme: Introduces a formal definition requiring a documented framework of policies, procedures, controls, oversight and reporting mechanisms designed to ensure ongoing alignment with the AML/CFT/CPF regime.

  • Managerial-Level Officer Requirements: Reaffirms the mandatory appointment of an AMLCO, MLRO, and DMLRO, and adds an ongoing obligation to ensure these individuals are of managerial level and have the qualifications, skills and experience to perform effectively.

  • Independent Compliance Function: Requires the AMLCO to operate independently and objectively from business and operational functions. Where full separation is not practical, conflicts of interest must be formally and effectively managed.

  • Trigger-Based Risk Assessments: Requires business-wide risk assessments to be reviewed and updated without delay following any material trigger event that may affect their effectiveness, adequacy or relevance.

  • National Risk Assessment Alignment: Requires FSPs to consider the findings and conclusions of the most recent Cayman Islands National Risk Assessment, along with relevant internal and external factors, in their risk assessment process.

  • Validation of Digital ID and e-KYC: Reiterates that electronic Know Your Client (e-KYC) and digital ID technologies may be used, provided remote onboarding decisions are based on the specific risks presented and assessed.

  • Mandatory Employee Screening: Requires FSPs to implement recruitment procedures, including fitness and propriety checks, integrity screening and background checks, to ensure staff competence and prevent financial crime.

  • Strict Audit Rotation Limit: Allows internal audits only when conducted by individuals independent of the audited activities, and limits internal testing to two consecutive cycles before engaging an external service provider.

  • Risk-Commensurate Remediation: Requires the timely implementation of appropriate remediation measures to address deficiencies, breaches or weaknesses identified in an audit, within timeframes that reflect the severity of the findings.

  • Ultimate Board Responsibility: Confirms that, regardless of whether an audit is conducted internally or externally, the governing body remains ultimately responsible for ensuring the compliance programme operates effectively.

  • Evidence of Independence and Filing: Requires FSPs to provide CIMA, upon request, with documentation evidencing the auditor’s independence and to file the audit report with CIMA as soon as reasonably practicable after completion, or as otherwise required by CIMA.

  • Documented Training Programmes: Requires a documented training plan and schedule covering staff, senior management and the governing body. Records of dates, attendees and topics must be maintained and scaled to the firm’s risk profile.

The New Sanctions Rule

  • Policies and Procedures Requirement: FSPs must ensure that clear, comprehensive policies and procedures are in place to guide staff and support compliance with their legal obligations and the Rule.

  • Mandatory Framework Integration: Sanctions compliance can no longer operate as a standalone process; it must be fully embedded into the FSP’s AML/CFT/CPF programme and enterprise-wide risk assessments.

  • Codified Timeline for Action: Mandates that once a sanctions target is designated, assets must be frozen “without delay” (explicitly defined by CIMA as “within a matter of hours”). Any formal reports or confirmed true matches must then be submitted to the Financial Reporting Authority (FRA) “as soon as practically possible.”

  • Broader Screening Scope: Requires written screening policies covering not only direct clients but also connected persons, including UBOs, directors and authorised signatories.

How Bolder Group Can Assist

At Bolder Group, we provide comprehensive governance, compliance and regulatory solutions designed to align your operations with CIMA’s updated expectations. From conducting gap analyses to providing experienced, managerial-level AML officers and managing independent compliance reporting, our team is equipped to support your compliance framework.

To discuss how these new rules may affect your entity or to prepare your compliance readiness plan, please contact David Payne, Global Head of Governance at Bolder Group.

David Payne

Global Head of Governance

background-image
David Payne