The Cayman Islands Monetary Authority (CIMA) has published two proposed rules for consultation that would reshape how regulated entities demonstrate compliance with anti-money laundering, counter-terrorist financing, proliferation financing and financial sanctions obligations.
While many of the underlying requirements already exist in Cayman Islands law, practice or in the existing Guidance Notes, the proposed rules significantly narrow discretion by converting expectations into prescriptive, auditable standards
A shift from principles to prescription
At present, the Anti-Money Laundering Regulations set out high-level obligations requiring regulated entities to maintain systems, controls and procedures, apply a risk-based approach and appoint key AML officers.
The proposed rules do not replace those regulations. Instead, they sit alongside them and define in much greater detail what CIMA expects an effective compliance framework to look like in practice. This marks a shift from broadly principles-based regulation to one where minimum structures, processes and outputs are more clearly specified.
Stronger focus on board accountability
One of the clearest areas of emphasis in the proposed changes is governance. The proposed rule on an effective compliance programme would require governing bodies to establish and maintain a documented AML governance framework. This includes clearly defined roles, responsibilities and lines of accountability.
While board oversight of AML matters has long been expected by CIMA, the proposed rule makes that responsibility explicit and enforceable, placing accountability for AML effectiveness firmly at governing body level rather than solely with management or compliance staff.
Codifying expectations around the AML compliance officer
The proposed rules also formalise expectations relating to the AML compliance officer. They introduce explicit fitness, integrity, competence and independence requirements, alongside expectations around authority, access to senior management and resourcing.
In practice, many Cayman Islands regulated entities already operate on this basis, but the rules would codify these standards and make them easier for CIMA to assess during inspections or enforcement action.
For example, ‘competence’ (whether the AML officer has sufficient credentials or experience to do the job) and ‘independence’ (which may not always exist when service providers offer a variety of services to a client) will now receive sharper focus going forward.
Risk assessments as an ongoing programme

Another important change is the treatment of risk assessments. The AML Regulations require firms to assess risks relating to clients, products, services, delivery channels and geography.
The proposed rule reframes this as a documented, enterprise-wide risk assessment programme that must be kept under review and informed by the national risk assessment. This places greater emphasis on the business risk assessment (BRA) which CIMA has always required (though the frequency is somewhat fluid) as a mandatory requirement.
Regulated entities must be concerned not only with risk assessing their clients and services but the broader firm wide risk assessment. To date, most firms have been doing BRAs infrequently (ranging from every two to five years), but this emphasis in the proposed rules suggests those timelines will need to be tightened up.
Annual AML audits and fixed reporting deadlines
The most substantive new obligation is the introduction of a mandatory annual independent AML audit.
Under the proposed rule, the audit must be completed and submitted to CIMA by 15 Sept. each year, with limits placed on how many consecutive audits may be conducted internally before an external or independent reviewer is required. The existing regulations refer to an independent audit function but do not mandate frequency, externalisation or submission to the regulator.
This proposal therefore introduces a clear, time-bound regulatory deliverable and strengthens CIMA’s supervisory leverage. The inclusion of a limit on how many consecutive audits can be carried out internally places strong emphasis on the importance of the need for external independent AML audits.
Training expectations set out in detail
Training is another area where the proposed rules tighten expectations. Regulated entities would be required to maintain a documented training plan covering staff, senior management and the governing body, together with defined scope, frequency and record-keeping requirements.
If you have ever been subjected to an onsite inspection you will already be familiar with these parameters, but the proposed rule would embed this more formally into your procedures.
A more structured approach to sanctions compliance
The second proposed rule addresses compliance with financial sanctions and targeted financial sanctions.
Rather than introducing entirely new legal obligations, it brings together requirements that currently sit across the AML Regulations and the Terrorism Law into a more coherent and operational framework.
The rule emphasises the need for a standalone sanctions compliance framework, clearer definition of who and what must be screened, prompt re-screening when sanctions lists are updated and defined procedures for handling false positives.
Operationalising existing legal duties
In several areas, particularly asset freezing and reporting, the proposed sanctions rule reflects obligations that already exist under the Terrorism Law. The key change is operational rather than substantive.
The rule specifies how firms are expected to comply, including reporting channels, formats, timing standards and procedures for delisting and unfreezing assets. This reduces ambiguity and increases consistency across the regulated sector.
Consultation, not final rules
It is important to note that both rules are currently out for consultation and are not yet in force. CIMA has invited industry feedback by 9 March, and the final form of the rules may change. See sidebar for a more concise summary, highlighting where key requirements are genuinely new, expanded or simply codified.
Taken together, the proposals signal a clear regulatory direction. CIMA is seeking to formalise long-standing expectations, reduce interpretive gaps and place greater emphasis on demonstrable effectiveness, governance and accountability across AML and sanctions compliance frameworks.



