Action required: CIMA’s new AML Rule and Sanctions Rule
On 20 July 2026, two new CIMA rules were gazetted, and both take effect on 18 September 2026: the Rule on an Effective Compliance Programme (“the AML Rule”) and the Rule on Compliance with Financial Sanctions and Targeted Financial Sanctions (“the Sanctions Rule”).
Key change: Independent AML/CFT/CPF Audit
The change with the most practical impact is the requirement for independent AML/CFT/CPFaudits (“AML audit”) to review and test the Compliance Programme. Section 12 of the AML Rule expands on the existing AML audit requirements in four ways:
1. Independence must be evidenced. The auditor must be suitably qualified and independentfrom the design, implementation and operation of the controls under review and free of any conflicts. Financial Service Providers (“FSPs”) must be prepared to demonstrate toCIMA the basis on which independence is determined. Where the audit is conducted internally, FSPs must evidence that its internal auditor has received adequate AML/CFT/CPF and Sanctions training (Rule 11.8).
2. An AML audit can only be conducted internally for two consecutive cycles. The third AML audit must be conducted by an external service provider.
3. FSPs must file the AML audit report as soon as practically possible after the completion of the audit.
4. Remediation is now part of the obligation, with any deficiencies and gaps identified during the AML audit to be addressed within timeframes proportionate to their risk.
The frequency of the AML audit remains risk based and must be commensurate with the FSPs size, complexity, structure, nature of business and the risk profile as determined by the FSP’s business risk assessment. However, CIMA has the authority to determine the frequency an AML audit is required to be conducted.
Investment Funds: AML audit requirements
In the summary of private sector consultation and feedback statement for the AML Rule, CIMA clarified that as registered investment funds conduct relevant financial business, they are subject to AML audit requirements under the AMLRs.
CIMA acknowledges that many Cayman Islands investment funds place reliance on outsourced, regulated service providers and clarified that AML audits may be performed at the service provider level, with coverage of FSPs to be considered.
What you need to do next
1. FSPs should conduct a gap analysis of existing AML/CFT/CPF and Sanctions policies, procedures and controls against the new AML Rule and Sanctions Rule to identify any gaps and make the necessary updates.
2. Review your independent audit function and business risk assessment to ensure you comply with the expanded AML audit requirements. FSPs must demonstrate that the independent audit function reviews and tests the Compliance Programme, ensuring its adequacy, effectiveness, and alignment with the applicable legislative and regulatory obligations.
Grant Thornton (Cayman) LLP can assist you with policy and procedure gap analysis reviews, independent AML audits (co-sourced and outsourced), reviewing and enhancing your business risk assessment, pre-inspection support and readiness assessments, and with post-inspection remediation.
If you have any questions or would like to discuss the new AML and Sanctions Rules further, please get in touch.
