Briefing Contents 简报目录
Top
New CIMA AML Rule and Sanctions Rule: what regulated entities need to consider
Created Date: 14 September 2026
创作日期:14 September 2026

New CIMA AML Rule and Sanctions Rule: what regulated entities need to consider

Briefing Summary:

This briefing outlines the key implications of CIMA’s new AML and Sanctions Rules for any CIMA regulated entity.

Location:
地点:

Key implications for Regulated Entities 

On 18 September 2026, new Rules published by the Cayman Islands Monetary Authority ("CIMA") relating to anti-money laundering ("AML") and sanctions compliance ("Rules") will come into force.  CIMA has also published FAQs on its website concerning the application of the new Rules. These new Rules are not intended to significantly extend the substantive obligations in this area, but there is now greater clarity around their enforceability and the extent to which they apply to regulated entities ("Regulated Entities").

In particular, the governing body of any regulated entity ("Governing Body"), whether directors, general partner or trustee (or the governing body of any of the foregoing, as applicable) should take note of the following:

  • Elements of the new Rules that were previously only covered by CIMA guidance, will now be directly enforceable under the administrative penalty regime.
  • Each member of the Governing Body must receive annual AML training, even when the Regulated Entity has no employees and has outsourced its AML compliance programme.
  • Each Regulated Entity's AML compliance programme must be independently audited at appropriate intervals (and every third audit must be an external audit).
  • A Regulated Entity's AML compliance officer ("AMLCO") should be independent from its business and operational functions, and the AMLCO's obligations are more clearly defined.
  • While Regulated Entities are already required to comply with applicable sanctions, the new Rule on sanctions turns existing CIMA guidance into enforceable requirements for Regulated Entities to have appropriate sanctions policies and procedures, to conduct sanctions screening, on-going monitoring of business relationships and re-screening when sanctions lists are updated.

Preparing for the new Rules

Specific actions needed will depend on whether the Regulated Entity's AML compliance programme (including the provision of its AMLCO and other AML officers) has been outsourced to an external service provider or is delivered from within the organisation.  In either case, the Regulated Entity's Governing Body remains ultimately responsible for compliance with Cayman Islands laws, regulations and CIMA rules relating to AML and sanctions compliance (the "Cayman AML Regime").  

In addition to ensuring the Regulated Entity's AML compliance programme has been developed in line with the Cayman AML Regime more generally, we recommend the following specific steps:

  • Review the company's AMLCO and other AML officers. In particular: 
    1. Ensure that any service provider is fit and proper, competent and capable of complying with the Cayman AML Regime.  For example, is the service provider (or an affiliate to which it sub-contracts these services) itself subject to the Cayman AML Regime? If not, additional review of the policies and procedures it applies to the Regulated Entity is called for, to ensure they are fully compliant with the Cayman AML Regime.
    2. If the AMLCO is a member of the Governing Body or otherwise involved in its operations, or the AMLCO is not suitably qualified with sufficient skills and experience to perform the required functions, an appropriately independent role should be created and filled with a suitably skilled candidate. If that is not possible, the AMLCO role should be outsourced in line with the guidance above.
  • Review the training plan the Governing Body has in place across the Regulated Entity to ensure compliance with the Cayman AML Regime. In particular, the training plan should ensure that the Governing Body is trained no less than once annually, along with any employees, agents or other persons authorised to act on behalf of the Regulated Entity. 
  • A plan for periodic independent audits of the Regulated Entity's AML compliance programme should be implemented if there is not one in place already.  For these purposes, an audit is "independent" if it is not conducted by persons involved in carrying out the audited functions and, every third audit (at least), must be conducted by a party external to the Regulated Entity and any outsourced AML service provider. Any AML service provider that is itself subject to the Cayman AML Regime will usually have a separate team that conducts these independent internal audits, and, being subject to the Cayman AML Regime, they will also be required to conduct independent external audits.  

Further information and support

To review copies of CIMA's new Rules and FAQs click on the links below:

Please get in touch with your usual attorney contact at Carey Olsen for more information on the subject matter of this update.

Frequently asked questions

常见问题解答

What are the independence requirements for an AMLCO under the new CIMA Rules?

Under the new Rules effective 18 September 2026, the Anti-Money Laundering Compliance Officer (AMLCO) must maintain independence from the Regulated Entity's business and operational functions. If the AMLCO is a member of the Governing Body or otherwise involved in operations, or lacks suitable qualifications and experience, the Regulated Entity must either create an appropriately independent role with a suitably skilled candidate or outsource the AMLCO function to a qualified external service provider that complies with the Cayman AML Regime.

What constitutes an 'independent audit' under the periodic audit requirements for AML compliance programmes?

An audit is considered 'independent' under the new Rules when it is not conducted by persons involved in carrying out the audited functions. Critically, every third audit must be conducted by a party external to both the Regulated Entity and any outsourced AML service provider. External service providers subject to the Cayman AML Regime typically maintain separate teams for conducting independent internal audits and are themselves required to conduct independent external audits, which can satisfy these requirements.

How do the new sanctions compliance requirements differ from previous CIMA guidance?

The new Sanctions Rule converts previously non-binding CIMA guidance into directly enforceable requirements under the administrative penalty regime. Regulated Entities must now implement formal sanctions policies and procedures, conduct sanctions screening of customers and transactions, perform on-going monitoring of business relationships, and re-screen when sanctions lists are updated. These obligations are now subject to CIMA's enforcement powers, making non-compliance subject to potential administrative penalties.

What are the mandatory AML training requirements for Governing Bodies under the new Rules?

Each member of a Regulated Entity's Governing Body—whether directors, general partner, trustee, or their respective governing bodies—must receive annual AML training without exception. This requirement applies even when the Regulated Entity has no employees and has fully outsourced its AML compliance programme to an external service provider. The training plan must also extend to any employees, agents, or other persons authorised to act on behalf of the Regulated Entity.

What due diligence should be conducted when outsourcing AML compliance functions to external service providers?

When outsourcing AML compliance functions, the Governing Body must ensure the service provider is fit and proper, competent, and capable of complying with the Cayman AML Regime, as ultimate responsibility remains with the Governing Body. Key considerations include whether the service provider (or any affiliate to which it sub-contracts services) is itself subject to the Cayman AML Regime. If not, enhanced review of the policies and procedures applied to the Regulated Entity is necessary to ensure full compliance with the Cayman AML Regime, as providers not subject to these requirements may apply different standards.

“Carey Olsen” in the Cayman Islands is the business name of Carey Olsen Cayman Limited, a body corporate recognised under the Legal Practitioners (Incorporated Practice) Regulations (as revised). The use of the title “Partner” is merely to denote seniority. Services are provided on the basis of our current terms of business.

CO Services Cayman Limited is regulated by the Cayman Islands Monetary Authority as the holder of a corporate services licence (No. 624643) under the Companies Management Act (as revised).

CO Foundation Services Cayman Limited is regulated by the Cayman Islands Monetary Authority as the holder of a companies management license (No.2226571) under the Companies Management Act (as revised).

Please note that this briefing is intended to provide a very general overview of the matters to which it relates. It is not intended as legal advice and should not be relied upon as such. © Carey Olsen 2026