Skip to main content
Didit Raises $7.5M to Build the Infrastructure for Identity and Fraud
Didit
Back to blog
Blog · October 6, 2026

CIMA AML Rule: Cayman's audit filing duty explained

The CIMA AML Rule has been in force in the Cayman Islands since 18 September 2026. What it requires, who is in scope, the audit report filed with CIMA, the in-house cap, and what the updated FAQs say.

By DiditUpdated
cima-aml-compliance-programme-rule-2026-cover.png

In short

The CIMA AML Rule, formally the Rule on Effective Compliance Programme of the Cayman Islands Monetary Authority (CIMA), has been in force since 18 September 2026 and has the force of law.[1] What it adds to existing duties is proof: the independent audit report of the anti-money laundering (AML) programme now goes to the regulator.[1][2]

  • The audit may stay in-house for two consecutive audit cycles at most.[1]
  • A fund needs its own audit evidence, even when everything is outsourced.[2]
  • No audit is due on day one, and CIMA says the fines framework for the Rule is not yet in effect.[2]

Last reviewed: 6 October 2026 · Not legal advice

CIMA supervised 33,125 licensees and registrants at the end of 2024, and 30,150 of them, about 91%, were mutual funds and private funds.[8] In its own response in the consultation feedback statement, CIMA notes that "while investment funds largely rely on mutual fund administrators for compliance with the AMLRs, they also have their own obligations under the AMLRs and remain ultimately responsible for complying with them".[4] AMLRs are the Anti-Money Laundering Regulations.

What happened: the CIMA AML Rule took effect

CIMA issued two rules together: the Rule on Effective Compliance Programme for the Prevention and Detection of Money Laundering, Terrorist Financing and Proliferation Financing for Financial Services Providers, and a companion Rule on Compliance with Financial Sanctions and Targeted Financial Sanctions.[2] Both are dated July 2026. Each came into effect on 18 September 2026, sixty days after publication in the Gazette: Rule 14.1 of the AML Rule[1] and Rule 9.1 of the Sanctions Rule.[7] According to the law firm Walkers, the gazette date was 20 July 2026.[11]

Rule 13.2 gives it the force of law and puts it above CIMA's prior or existing guidance notes, policy statements and interpretative materials where they conflict.[1] Where the Rule conflicts with the AMLRs, Rule 4.4 says the regulations win.[1]

33,125Licensees and registrants, end of 2024
367Requirements issued so far from 2024 inspections
31%Deficiencies in the risk-based approach

The background is in CIMA's inspection data. In 2024 it conducted 83 AML on-site inspections, 72 of them completed when the report was written, and had by then issued 367 requirements for the 53 inspections concluded with deficiencies; 324 were Matters Requiring Immediate Attention.[8] One recorded finding was that a regulated entity "failed to maintain an independent audit function".[8]

The rule behind it: what the text requires

CIMA issued the Rule under section 34(1) of the Monetary Authority Act, which lets it issue rules after consulting the private sector and the minister.[1][2] The Rule also cites section 6(1)(b) of that Act, while CIMA's FAQs cite section 6(3)(b).[1][2] The Rule supplements Regulations 3, 4, 5, 6 and 8 of the AMLRs.[1] CIMA says "many of the provisions in the Rule do not introduce new obligations but rather enhance the Authority's expectations".[2]

Regulation 3(1) already required an Anti-Money Laundering Compliance Officer (AMLCO) at managerial level, and Regulation 5(a)(ix) already required "an appropriate effective risk-based independent audit function".[6] The Rule turns those lines into detailed minimum requirements across six sections.

SectionWhat the firm must haveParagraphs
GovernanceDocumented roles, an AMLCO, a Money Laundering Reporting Officer (MLRO) and a deputy at management level7.1, 8.2, 8.10
Risk-based approachA documented risk assessment that considers the latest National Risk Assessment9.2(b), 9.6
Policies and due diligencePolicies approved by the Governing Body; customers and beneficial owners verified from reliable, independent sources10.2, 10.5.1, 10.5.5
Records and outsourcingRecords kept at least five years after the relationship ends or the one-off transaction is completed; due diligence on service providers; written notice to CIMA of material outsourcing10.6.1, 10.7.2, 10.3(e), 10.7.6
Training and screeningTraining at least annually, with a record; staff screened at hiring and afterwards11.3, 11.5, 11.14
EffectivenessIndependent audit, a report filed with CIMA, remediation12.1 to 12.5

The Rule's six requirement sections.[1]

Rule 12.2(d)CIMA Rule on Effective Compliance Programme

"the audit report is filed with the Authority as soon as practically possible after the completion of the audit, or as otherwise prescribed by the Authority."

Source: CIMA, Rule on Effective Compliance Programme, July 2026[1]

TopicAlready in the AMLRsAdded by the Rule
AuditAn independent audit function, Regulation 5(a)(ix)The report is filed with CIMA, Rule 12.2(d)
Who auditsNot specifiedNo more than two consecutive audit cycles in-house, Rule 12.3
IndependenceThe word "independent"Documentation of the auditor's independence, on request, Rule 12.2(c)
OutsourcingDelegation allowed, responsibility stays, Regulation 3(2) and 3(3)Written notice to CIMA of material outsourced compliance functions, Rule 10.3(e)

Section 12 is where the Rule goes beyond the regulations.[1][6]

The in-house cap is wider than it looks. A footnote to Rule 12.3 defines "internally" as any individual or unit employed by the firm, engaged under contract by it, or otherwise part of its structure, and subject to its direction, control or oversight.[1] CIMA's guidance adds that the AMLCO, the MLRO and the deputy cannot independently audit activities they are responsible for, whether those roles sit in-house or are outsourced.[2]

The consultation draft required the report "no later than 15 September of each year" and capped in-house audits at "two consecutive years".[5] The final Rule requires filing after completion under Rule 12.2(d), and Rule 12.3 caps in-house audits by consecutive audit cycles.[1]

Who it affects

Rule 5.1 applies to all financial service providers (FSPs) regulated and supervised by CIMA, including branches, subsidiaries, affiliates and other members of a CIMA-regulated financial group.[1] An FSP is any person conducting relevant financial business, a term defined in the Proceeds of Crime Act.[1]

SectorSupervised at 31 December 2024What to note
Mutual funds and private funds30,150In scope. Each fund needs its own audit evidence
Insurance865Only where the insurer or reinsurer conducts relevant financial business
Trust and corporate services providers467In scope
Mutual fund administrators69In scope. The funds they serve still need fund-specific testing

Four of the supervised sectors. Counts from CIMA's AML/CFT Activity Report 2024.[8][2]

Funds were the contested point. During consultation, a submission recorded in CIMA's feedback statement argued that "investment funds themselves would generally not be conducting RFB", meaning relevant financial business. CIMA disagreed, as quoted above, and added Rule 5.3 on reliance on third parties.[4] Its guidance now says a regulated fund must still undertake an AML audit "even if all, or substantially all, of its operations are outsourced".[2]

Not enough alone

Administrator-level audit

  • Tests the service provider's general framework
  • Reviews a population of clients together
  • Gives no conclusion on one fund's programme

CIMA FAQs 43 and 46

What CIMA expects

Fund-specific audit

  • Tests the fund's own policies and controls
  • Checks how outsourcing works for that fund
  • Concludes on design and operating effectiveness

CIMA FAQs 43, 45 and 46

Timeline

  1. 20 July 2026GazettedBoth rules published, according to Walkers.[11]
  2. 18 September 2026In forceRule 14.1, sixty days after the Gazette.[1]
  3. 24 September 2026FAQs updatedCIMA revises its guidance on audits.[3]
  4. 1 November 2026AML ReturnIssued to restricted and private trust companies.[13]
  5. 31 December 2026Return dueDeadline for that first AML Return.[13]

The AML Return is a separate data request. No audit deadline appears here: CIMA's guidance says the Rule sets no "universal first-filing date", and that the Rule "does not mandate annual AML Audits".[2]

What compliance teams should do now

Rule 12.2(a) sets the frequency by the firm's own risk assessment, or as CIMA requires.[1] CIMA gives an example, not a rule: every two years might be reasonable for a higher-risk firm, and every three and four years for medium and low risk.[2]

1Document the risk assessment

It sets the audit frequency and scope. Rules 9.6 and 12.2(a).

The last two audit cycles were both done internally

Yes

Use an external service provider

Rule 12.3 requires it for the next audit.

No

Internal or external

Either way, independent of the people who run the controls. Rule 12.2(b).

2Test evidence specific to the entity

Including how each outsourced function works for it.

3File the report with CIMA

As soon as practically possible after completion. Rule 12.2(d).

4Remediate and track

Within timeframes that match the risk. Rule 12.4.

  • Confirm the AMLCO, MLRO and deputy are natural persons at management level.[1]
  • Update the risk assessment with inherent and residual risk and the latest National Risk Assessment.[1]
  • Write down the audit frequency and the reason for it.[2]
  • Count how many consecutive audit cycles were internal, including contractors under your direction, control or oversight.[1]
  • Document the independence of whoever audits, and the basis for it.[1]
  • List outsourced compliance functions, decide which are material, and notify CIMA in writing.[1]
  • Ask each service provider for testing results that are specific to your entity.[2]
  • Check that records are kept for at least five years after the relationship ends or the one-off transaction is completed, and can reach CIMA without delay.[1]

Watch out

Some summaries still describe the consultation draft: an annual filing by 15 September. The final Rule has no such date.[1][5]

What is still open, and the latest developments

On 24 September 2026, CIMA updated its FAQs "in response to various queries and scenarios raised by industry". The notice lists the key amendments: firms need not run a new audit solely because the Rules are in force, and deficiencies found in an audit do not automatically undermine its validity.[3]

Fines. The Rule states no amount. Rule 13.1 points to CIMA's Enforcement Manual, and CIMA says "the Administrative Fines framework applicable to breaches of the Rule is not yet in effect".[1][2] No start date appeared on CIMA's notices pages by 6 October 2026. Separately, Regulation 56(1) of the AMLRs makes a contravention of the regulations an offence, with a fine of five hundred thousand dollars on summary conviction, or a fine and two years of imprisonment on conviction on indictment.[6]

How to file. CIMA does not prescribe a report format or methodology.[2] According to Walkers, there is no set process for submitting audit reports, a complex filing process is not anticipated, and CIMA has not indicated a fee.[12] I found no CIMA notice naming a filing channel.

What "material" means. The Rule borrows the definition from CIMA's Statement of Guidance on Outsourcing, and the judgment is the firm's.[1] CIMA's January 2026 thematic review of outsourcing states that "outsourcing does not diminish regulatory responsibility" and that governing bodies and senior management remain ultimately accountable for all outsourced material functions.[9]

Note

The FAQs are guidance. CIMA states that they "do not replace or amend the Rules".[2]

How Didit helps with the checks the Rule lists

Most of this Rule is governance, and no vendor supplies governance. Didit runs some of the checks the programme has to contain, starting with AML screening.

Rule 10.3(g) requires screening against official sanctions lists, and Rule 10.5.23 keeps that screening in place under simplified due diligence.[1] Didit screens people and companies against 1,300+ sanctions, politically exposed person (PEP) and watchlists, refreshed daily, at $0.20 per check. PEP lists and watchlists are separate from official sanctions lists, and which lists your programme must cover is your decision. Ongoing monitoring re-screens daily, sends alerts by webhook and keeps evidence of each run, at $0.07 per person per year.

Rule 10.5.1 requires verifying customers, beneficial owners and people acting for them.[1] A full Know Your Customer (KYC) check costs $0.33. Business verification returns company registry data and links an identity check to each owner or officer; tier availability varies by country and the price is on the pricing page. Retention is configurable from 1 month to 10 years.

Didit provides

  • Sanctions, PEP and watchlist screening with daily re-screening
  • Identity checks for customers, owners and representatives
  • Company registry data and linked owner checks
  • Evidence of each screening run and each check

Stays with you

  • The governance framework and the AMLCO, MLRO and deputy
  • The risk assessment and the policies
  • The independent audit and the report filed with CIMA
  • The outsourcing assessment and any notice to CIMA
  • Match decisions, suspicious activity reports and the liability

When screening is outsourced, the auditor reviews the provider's procedures and "testing results relevant to the specific FSP".[2] Evidence about Didit's controls is not evidence about your programme, so plan to pull your own check records for the audit.

Run screening that leaves an audit trail

Screen customers and owners, keep the evidence of each run, and hand your auditor records that are specific to your entity.

Start freeTalk to us

Key takeaways

  • The CIMA AML Rule has been in force since 18 September 2026 and has the force of law.[1]
  • The duties are mostly old; the new part is evidence: the audit report is filed with CIMA.[1][2]
  • In-house audits are capped at two consecutive audit cycles; a contractor under the firm's direction, control or oversight counts as in-house.[1]
  • A fund cannot rely solely on an administrator-level audit that does not assess all elements of the fund's own AML programme.[2]
  • No audit is due because of the effective date, and the fines framework for the Rule is not yet in effect.[2]

Frequently asked questions

When did the CIMA AML Rule take effect?

On 18 September 2026. Rule 14.1 says it comes into effect sixty days after publication in the Gazette, and Rule 13.2 says it has the force of law.[1]

Who has to comply with the Rule?

All financial service providers regulated and supervised by CIMA, including branches, subsidiaries, affiliates and other members of a CIMA-regulated financial group.[1] Outsourcing does not change this: CIMA's FAQs say the firm and its Governing Body remain ultimately responsible.[2]

Is the independent AML audit a new requirement?

No. Regulation 5(a)(ix) of the Anti-Money Laundering Regulations already required an independent audit function.[6] The Rule adds that the report is filed with CIMA, that in-house audits are capped, and that independence must be documented.[1]

Do firms have to run an AML audit now that the Rule is in force?

No. CIMA's FAQs say the Rule does not require an audit solely because it has become effective, and that it sets no universal first-filing date, industry-wide completion date or simultaneous submission requirement.[2]

How often must the AML audit be done?

There is no prescribed frequency. Rule 12.2(a) sets it by the firm's risk assessment.[1] CIMA's example is every two years for a higher-risk firm, and every three and four years for medium and low risk.[2]

Can the AML audit be done internally?

Yes, for at most two consecutive audit cycles. After that, Rule 12.3 requires an external service provider for the next audit.[1]

Does a Cayman fund need its own AML audit if everything is outsourced?

Yes. CIMA's FAQs say a regulated investment fund must still undertake an AML audit even if all or substantially all of its operations are outsourced. A service provider's audit can be relied on only where it assesses the fund's own programme.[2]

When and how is the audit report filed with CIMA?

As soon as practically possible after the audit is completed, or as CIMA prescribes.[1] CIMA does not prescribe a report format.[2] According to Walkers, there is no set process for submitting audit reports.[12]

What is the penalty for breaching the Rule?

The Rule states no amount. Rule 13.1 says CIMA's Enforcement Manual applies.[1] CIMA's FAQs say the Administrative Fines framework applicable to breaches of the Rule is not yet in effect.[2]

Does using a screening or identity vendor count as outsourcing?

It can. The Rule requires risk assessment and due diligence on service providers, and written notice to CIMA where a material compliance function is outsourced.[1]

Sources

  1. Rule on Effective Compliance Programme for the Prevention and Detection of Money Laundering, Terrorist Financing and Proliferation Financing for Financial Services Providers, Cayman Islands Monetary Authority, July 2026.
  2. Frequently Asked Questions on the AML and Sanctions Rules, Cayman Islands Monetary Authority, as updated 24 September 2026.
  3. Updated AML and Sanctions Rules FAQs Now Available, Cayman Islands Monetary Authority, general industry notice, 24 September 2026.
  4. Summary of Private Sector Consultation and Feedback Statement, Rule on Effective Compliance Programme, Cayman Islands Monetary Authority.
  5. Appendix I, consultation draft of the Rule, Cayman Islands Monetary Authority.
  6. Anti-Money Laundering Regulations (2025 Revision), Cayman Islands, revised as at 31 December 2024.
  7. Rule on Compliance with Financial Sanctions and Targeted Financial Sanctions, Cayman Islands Monetary Authority, July 2026.
  8. AML/CFT Activity Report 2024, Cayman Islands Monetary Authority.
  9. Thematic Review on Outsourcing, Cayman Islands Monetary Authority, January 2026.
  10. Investment Funds Regulatory Measures, Cayman Islands Monetary Authority, listing of both rules with their effective date.
  11. Cayman Islands new AML Rule and new Sanctions Rule, Walkers, July 2026.
  12. Cayman Islands new AML Rule and new Sanctions Rule: practical guide for investment funds, Walkers, August 2026.
  13. AML Return Requirement for Restricted Trust Companies and Private Trust Companies, Cayman Islands Monetary Authority, general industry notice, 7 September 2026.

CIMA's regulatory measures page lists the Rule as effective.[10] The work now is evidence: a documented risk assessment, an entity-specific audit, and records you can hand over without delay. For the screening part of that evidence, see Didit AML screening, and transaction monitoring for the monitoring procedures Rule 10.3(f) lists.[1]

Build the evidence before the audit asks for it

Keep every screening and identity check result ready for auditor and regulator.

Start freeTalk to us

Infrastructure for identity and fraud.

One API for KYC, KYB, Transaction Monitoring, and Wallet Screening. Integrate in 5 minutes.

Ask an AI to summarise this page