By Deanna Derrick, Senior Client Director, Cayman Islands
Key takeaways
The Cayman Islands Monetary Authority (CIMA) has strengthened its regulatory framework through the introduction of the Rule on Effective Compliance Programme for the Prevention and Detection of Money Laundering, Terrorist Financing and Proliferation Financing for Financial Services Providers (AML Rule) and the Rule on Compliance with Financial Sanctions and Targeted Financial Sanctions (Sanctions Rule).
Both Rules took effect on September 18, 2026 and intend to strengthen the effectiveness of anti-money laundering (AML), countering the financing of terrorism (CFT) and counter proliferation financing (CPF) compliance programmes and sanction compliance.
While many of the underlying obligations will be familiar to regulated entities, the introduction of the Rules gives CIMA greater enforceability by placing key supervisory expectations within a directly enforceable rules framework. They also sharpen regulatory focus on governance, accountability, independent assurance, sanctions risk management, documentation, and the ability of regulated entities to demonstrate that their compliance programmes are operating effectively.
The emphasis has shifted from simply maintaining policies and procedures to demonstrating – through oversight, testing and documentation – that those measures are both appropriate for the entity and operating effectively.
Smart compliance, practical oversight
What remains unchanged
- Customer due diligence is still required
- Risk assessments are still required
- AML Compliance Officer (AMLCO), Money Laundering Reporting Officer (MLRO) and Deputy Money Laundering Reporting Officer (DMLRO) appointments remain required
- AML/CFT/ CPF compliance programmes remain risk-based and should be commensurate with the nature, size and activities of the entity
- Existing Cayman Islands AML/CFT/CPF legislation remains in force
What has changed
- Greater emphasis on documented governance
- Increased accountability for governing bodies
- More formalised compliance program requirements
- Enhanced independent audit and testing expectations
- Standalone sanctions governance requirements
- Greater focus on evidencing compliance effectiveness rather than simply maintaining policies
Cayman AML and Sanctions Rules: before and after
| Area | Before September 18, 2026 | From September 18, 2026 |
| Regulatory framework | AML Regulations and CIMA Guidance Notes drove expectations | AML Rule and Sanctions Rule create directly enforceable requirements |
| Governance | Existing governance obligations | Enhanced focus on documented governance and accountability |
| Risk-based approach | Risk-based AML framework applies | Risk-based approach retained and clarified |
| Compliance programme | Required under AML Regulations | Explicit requirement for an effective, documented compliance programme |
| AML officers | AMLCO, MLRO and DMLRO required | Greater emphasis on responsibilities, documentation and independence. AMLCOs must have sufficient functional and reporting autonomy to discharge their responsibilities objectively and escalate issues where necessary |
| Independent audit | Independent testing expected | Independent audit becomes a formal compliance requirement |
| Sanctions compliance | Managed through sanctions legislation and internal controls | Dedicated Sanctions Rule and enhanced sanctions governance expectations |
| Documentation | Recordkeeping requirements remain in place | Greater emphasis on evidencing compliance and oversight |
| Regulatory focus | Compliance with regulations and guidance | Demonstrating the effectiveness of the compliance framework |
What regulated entities should review
CIMA-regulated entities should consider whether their compliance framework is appropriately documented, supported by effective oversight, and capable of demonstrating compliance in practice.
- Governance arrangements and oversight responsibilities
- AML, CFT, CPF and targeted financial sanctions (TFS) risk assessments
- Policies, procedures and control frameworks
- Customer due diligence and monitoring processes
- Internal reporting and escalation procedures
- Staff training and awareness programmes
- Outsourcing oversight arrangements
- Independent testing and effectiveness reviews
- Documentation and evidence supporting regulatory compliance
This review should not focus solely on whether controls exist, but whether the entity can demonstrate that those controls are operating effectively and are aligned with its risk profile.
Sanctions risk must be embedded into risk assessments
CIMA has reinforced that regulated entities should consider money laundering, terrorist financing, proliferation financing and targeted financial sanctions risks as part of their overall risk-based approach.
Documentation should clearly explain how these risks are identified, assessed, mitigated, monitored and reviewed. Importantly, sanctions risk extends beyond sanctions screening alone.
Regulated entities should consider whether the following present elevated sanctions risks:
- Clients and investors
- Jurisdictions
- Products and investment types
- Investment strategies
- Counterparties
- Transaction types
Geographic risk is receiving greater attention
The Sanctions Rule specifically requires firms to consider country and geographic risk factors as part of their sanctions risk assessment framework.
This includes jurisdictions subject to sanctions programmes and countries that present heightened sanctions risk.
Entities should be able to demonstrate how geographic risks are incorporated into both risk assessments and control measures.
Areas that should be reviewed include:
- Customer geography
- Beneficial owner geography
- Transaction geography
- Source of funds jurisdictions
- Source of wealth jurisdictions
- Sanctioned and high-risk countries
Independent audit becomes a formal requirement
One of the most notable developments is CIMA’s increased emphasis on independent assurance.
AML, CFT and CPF programmes must be independently reviewed. While internal audit functions may conduct reviews, they may not perform the review for more than two consecutive audit cycles.
The subsequent review must be undertaken by an independent external party at least once every third cycle.
As audit cycles are generally determined by an entity’s risk assessment, organisations should ensure that review schedules, resource planning and independent testing arrangements are appropriately documented and supported.
What regulated entities should do now
The new Rules do not fundamentally alter existing AML/CFT/CPF or sanctions obligations. Rather, they formalise key supervisory expectations and place increased emphasis on:
- Governance
- Accountability
- Risk management
- Independent assurance
- Demonstrable compliance
The ability to evidence the effectiveness of compliance programmes through robust documentation, oversight and testing is now central to regulatory expectations.
Regulated entities should use the implementation date as an opportunity to assess existing frameworks, identify gaps, and strengthen:
- Governance arrangements
- Sanctions controls
- Compliance monitoring
- Independent assurance processes
- Documentation and recordkeeping practices
Organisations that proactively enhance these areas will be better positioned to meet CIMA’s heightened expectations and demonstrate a strong culture of compliance.
How we can help
To support regulated entities in meeting both ongoing AML, CTF and CPF obligations and the requirements of the AML Rule and Sanctions Rule, we offer:
Governance and compliance framework reviews
- Gap analysis
- Governance framework design and enhancement
- Compliance programme development
- Implementation support
AML and sanctions support
- AML Officer appointments
- AML and sanctions risk assessments
- Compliance documentation reviews
- Regulatory compliance support
Assurance and training
- Independent internal audit services
- Compliance effectiveness reviews
- AML/CFT/CPF and sanctions training
- Governance and regulatory awareness training
Our global reach, local expertise and technology-enabled service delivery model allow us to tailor practical solutions that align with your regulatory obligations and operating model.
To learn more about how IQ-EQ can support your Cayman Islands AML and sanctions compliance programme, speak to our team today.
About the author
Deanna Derrick is a Senior Client Director at IQ-EQ Cayman Islands with over 30 years of experience in AML/CFT, sanctions compliance, governance, and regulatory risk management. She works with regulated entities to strengthen compliance programmes, manage regulatory risk, and meet evolving regulatory requirements.