Cayman Islands’ new AML and Sanctions Rules: from compliance to demonstrating effectiveness

Published: 22 Sep 2026

By Deanna Derrick, Senior Client Director, Cayman Islands

Key takeaways

  • The new AML Rule and Sanctions Rule took effect on September 18, 2026
  • Existing AML/CFT/CPF and sanctions obligations remain largely unchanged
  • The new Rules give CIMA greater ability to enforce existing supervisory expectations through a dedicated rules framework
  • Governing bodies face greater accountability for compliance oversight
  • Independent audit requirements are now clearly defined
  • Documentation, sanctions governance and evidence of compliance are receiving increased regulatory focus

The Cayman Islands Monetary Authority (CIMA) has strengthened its regulatory framework through the introduction of the Rule on Effective Compliance Programme for the Prevention and Detection of Money Laundering, Terrorist Financing and Proliferation Financing for Financial Services Providers (AML Rule) and the Rule on Compliance with Financial Sanctions and Targeted Financial Sanctions (Sanctions Rule).

Both Rules took effect on September 18, 2026 and intend to strengthen the effectiveness of anti-money laundering (AML), countering the financing of terrorism (CFT) and counter proliferation financing (CPF) compliance programmes and sanction compliance.

While many of the underlying obligations will be familiar to regulated entities, the introduction of the Rules gives CIMA greater enforceability by placing key supervisory expectations within a directly enforceable rules framework. They also sharpen regulatory focus on governance, accountability, independent assurance, sanctions risk management, documentation, and the ability of regulated entities to demonstrate that their compliance programmes are operating effectively.

The emphasis has shifted from simply maintaining policies and procedures to demonstrating – through oversight, testing and documentation – that those measures are both appropriate for the entity and  operating effectively.

Smart compliance, practical oversight

What remains unchanged

  • Customer due diligence is still required
  • Risk assessments are still required
  • AML Compliance Officer (AMLCO), Money Laundering Reporting Officer (MLRO) and Deputy Money Laundering Reporting Officer (DMLRO) appointments remain required
  • AML/CFT/ CPF compliance programmes remain risk-based and should be commensurate with the nature, size and activities of the entity
  • Existing Cayman Islands AML/CFT/CPF legislation remains in force

What has changed

  • Greater emphasis on documented governance
  • Increased accountability for governing bodies
  • More formalised compliance program requirements
  • Enhanced independent audit and testing expectations
  • Standalone sanctions governance requirements
  • Greater focus on evidencing compliance effectiveness rather than simply maintaining policies

Cayman AML and Sanctions Rules: before and after

Area Before September 18, 2026 From September 18, 2026
Regulatory framework AML Regulations and CIMA Guidance Notes drove expectations AML Rule and Sanctions Rule create directly enforceable requirements
Governance Existing governance obligations Enhanced focus on documented governance and accountability
Risk-based approach Risk-based AML framework applies Risk-based approach retained and clarified
Compliance programme Required under AML Regulations Explicit requirement for an effective, documented compliance programme
AML officers AMLCO, MLRO and DMLRO required Greater emphasis on responsibilities, documentation and independence. AMLCOs must have sufficient functional and reporting autonomy to discharge their responsibilities objectively and escalate issues where necessary
Independent audit Independent testing expected Independent audit becomes a formal compliance requirement
Sanctions compliance Managed through sanctions legislation and internal controls Dedicated Sanctions Rule and enhanced sanctions governance expectations
Documentation Recordkeeping requirements remain in place Greater emphasis on evidencing compliance and oversight
Regulatory focus Compliance with regulations and guidance Demonstrating the effectiveness of the compliance framework

 

What regulated entities should review

CIMA-regulated entities should consider whether their compliance framework is appropriately documented, supported by effective oversight, and capable of demonstrating compliance in practice.

  • Governance arrangements and oversight responsibilities
  • AML, CFT, CPF and targeted financial sanctions (TFS) risk assessments
  • Policies, procedures and control frameworks
  • Customer due diligence and monitoring processes
  • Internal reporting and escalation procedures
  • Staff training and awareness programmes
  • Outsourcing oversight arrangements
  • Independent testing and effectiveness reviews
  • Documentation and evidence supporting regulatory compliance

This review should not focus solely on whether controls exist, but whether the entity can demonstrate that those controls are operating effectively and are aligned with its risk profile.

Sanctions risk must be embedded into risk assessments

CIMA has reinforced that regulated entities should consider money laundering, terrorist financing, proliferation financing and targeted financial sanctions risks as part of their overall risk-based approach.

Documentation should clearly explain how these risks are identified, assessed, mitigated, monitored and reviewed. Importantly, sanctions risk extends beyond sanctions screening alone.

Regulated entities should consider whether the following present elevated sanctions risks:

  • Clients and investors
  • Jurisdictions
  • Products and investment types
  • Investment strategies
  • Counterparties
  • Transaction types

Geographic risk is receiving greater attention

The Sanctions Rule specifically requires firms to consider country and geographic risk factors as part of their sanctions risk assessment framework.

This includes jurisdictions subject to sanctions programmes and countries that present heightened sanctions risk.

Entities should be able to demonstrate how geographic risks are incorporated into both risk assessments and control measures.

Areas that should be reviewed include:

  • Customer geography
  • Beneficial owner geography
  • Transaction geography
  • Source of funds jurisdictions
  • Source of wealth jurisdictions
  • Sanctioned and high-risk countries

Independent audit becomes a formal requirement

One of the most notable developments is CIMA’s increased emphasis on independent assurance.

AML, CFT and CPF programmes must be independently reviewed. While internal audit functions may conduct reviews, they may not perform the review for more than two consecutive audit cycles.

The subsequent review must be undertaken by an independent external party at least once every third cycle.

As audit cycles are generally determined by an entity’s risk assessment, organisations should ensure that review schedules, resource planning and independent testing arrangements are appropriately documented and supported.

What regulated entities should do now

The new Rules do not fundamentally alter existing AML/CFT/CPF or sanctions obligations. Rather, they formalise key supervisory expectations and place increased emphasis on:

  • Governance
  • Accountability
  • Risk management
  • Independent assurance
  • Demonstrable compliance

The ability to evidence the effectiveness of compliance programmes through robust documentation, oversight and testing is now central to regulatory expectations.

Regulated entities should use the implementation date as an opportunity to assess existing frameworks, identify gaps, and strengthen:

  • Governance arrangements
  • Sanctions controls
  • Compliance monitoring
  • Independent assurance processes
  • Documentation and recordkeeping practices

Organisations that proactively enhance these areas will be better positioned to meet CIMA’s heightened expectations and demonstrate a strong culture of compliance.

How we can help

To support regulated entities in meeting both ongoing AML, CTF and CPF obligations and the requirements of the AML Rule and Sanctions Rule, we offer:

Governance and compliance framework reviews

  • Gap analysis
  • Governance framework design and enhancement
  • Compliance programme development
  • Implementation support

AML and sanctions support

  • AML Officer appointments
  • AML and sanctions risk assessments
  • Compliance documentation reviews
  • Regulatory compliance support

Assurance and training

  • Independent internal audit services
  • Compliance effectiveness reviews
  • AML/CFT/CPF and sanctions training
  • Governance and regulatory awareness training

Our global reach, local expertise and technology-enabled service delivery model allow us to tailor practical solutions that align with your regulatory obligations and operating model.

To learn more about how IQ-EQ can support your Cayman Islands AML and sanctions compliance programme, speak to our team today.

 


About the author

Deanna Derrick is a Senior Client Director at IQ-EQ Cayman Islands with over 30 years of experience in AML/CFT, sanctions compliance, governance, and regulatory risk management. She works with regulated entities to strengthen compliance programmes, manage regulatory risk, and meet evolving regulatory requirements.

Working with IQ-EQ has been seamless – you and your team understand our business, advise us appropriately, and handle your side of our collective partnership so that we can focus on making good investment decisions. Evan Gibson SVP, Merchants Capital

Get in touch with us today

We’re ready to listen.

Make an enquiry

Interested in joining our team?

We are always on the lookout for passionate people that possess IQ and EQ to join our growing team.

View job vacancies