THE CAYMAN ISLANDS MONETARY AUTHORITY (CIMA) HAS ISSUED TWO NEW RULES THAT WILL COME INTO FORCE ON 18 SEPTEMBER 2026: THE RULE ON EFFECTIVE COMPLIANCE PROGRAMME FOR THE PREVENTION AND DETECTION OF MONEY LAUNDERING (ML), TERRORIST FINANCING (TF) AND PROLIFERATION FINANCING (PF) FOR FINANCIAL SERVICES PROVIDERS (AML/CFT/CPF RULE), AND THE RULE ON COMPLIANCE WITH FINANCIAL SANCTIONS AND TARGETED FINANCIAL SANCTIONS (SANCTIONS RULE).
They apply to all CIMA-regulated financial services providers, including private funds, mutual funds, and all other CIMA-registered and licensed entities.
Collectively, the Rules form part of the Cayman Islands' ongoing efforts to strengthen its AML/CFT/CPF framework and address recommendations arising from international assessments of the jurisdiction's regulatory regime. Their key objective is to ensure that critical AML and sanctions obligations are enforceable through direct regulatory action where necessary. The Rules elevate key requirements previously contained within CIMA's Guidance Notes into binding and enforceable obligations.
NEW RULES AT A GLANCE AND CONSIDERATIONS
Effective Governance Responsibilities
The governing body of a regulated entity remains ultimately responsible for ensuring that an effective AML/CFT/CPF compliance programme is established, documented, maintained and periodically reviewed.
Key governance and oversight responsibilities include:
The governing body must appoint and oversee the Anti-Money Laundering Compliance Officer (AMLCO), Money Laundering Reporting Officer (MLRO), and Deputy Money Laundering Reporting Officer (DMLRO), ensuring that each role has clearly defined responsibilities
Periodic review of the effectiveness of the compliance programme, including:
Risk Assessment and AML/CFT/CPF controls
Customer due diligence and screening processes
Oversight of utsourced arrangements
AML/CFT/CPF training for relevant personnel at least annually
Effective independent audit arrangements
Appropriate record-keeping procedures
Fund-Specific Risk Assessments
A significant area of focus under the new Rule is the requirement for a documented risk-based approach. Regulated entities must identify, assess, understand and document their ML/TF/PF risks, taking into account factors such as:
For investment funds that outsource AML administration functions, directors should consider whether the fund's risk assessment adequately reflects its specific risks and whether reliance solely on a service provider's assessment methodology remains appropriate.
Policies, Procedures and Controls
Regulated entities must maintain documented policies, procedures and controls proportionate to their risk profile.
These documents must address:
Risk assessment and application of a risk-based approach
Customer due diligence, ongoing monitoring, and enhanced measures for higher-risk customers, including politically exposed persons
Record-keeping and document retention
Outsourcing of compliance functions
Timely notification to the CIMA of any material outsourced compliance functions
Detection, monitoring, investigation, escalation, and reporting of suspicious activity, including applicable travel rule requirements
Financial sanctions compliance and screening
Many funds currently rely heavily on third-party administrators and other service providers. Directors should therefore assess whether existing policies and procedures remain sufficient or whether additional fund-specific documentation may be required to demonstrate compliance with the new requirements.
Oversight of Outsourced Arrangements
The Rules reinforce the principle that, while certain functions may be outsourced, ultimate responsibility for AML/CFT/CPF compliance remains with the regulated entity and its governing body.
Where activities are outsourced, regulated entities must ensure that:
Responsibilities are clearly documented
Appropriate reporting arrangements are in place
Performance is monitored
Compliance obligations continue to be met
Fund boards should review existing service agreements and governance arrangements to ensure they adequately meet these requirements.
Independent AML Audit Requirements
The Rules formally incorporate requirements for independent testing of AML/CFT/CPF programmes.
The independent audit should assess the effectiveness of:
Of particular note, industry guidance indicates that no more than two consecutive audit cycles should be conducted internally. A third consecutive audit should be undertaken by an external provider before any further internal audit cycle is performed.
The Rules require that compliance programme audits be conducted by ‘suitably qualified persons who are independent and separate from those involved in design, implementation or operation of the policies, procedures, systems and controls under audit, and who are free from any conflict of interest that could impair their objective judgment.’
AMLCO, MLRO and DMLRO Appointments
The Rules confirm the requirement for regulated entities to appoint:
An Anti-Money Laundering Compliance Officer (AMLCO)
A Money Laundering Reporting Officer (MLRO)
A Deputy Money Laundering Reporting Officer (DMLRO)
These appointments must be held by natural persons at management level and supported by clearly defined responsibilities for each. Each Officer must be suitably qualified and ‘perform the compliance function independently and objectively from the business and operational functions subject to their oversight, and, where full separation is not practicable, ensure conflicts of interest are effectively managed’.
Continuous Compliance Training
Regulated entities must maintain an ongoing AML/CFT/CPF training programme appropriate to their business activities and risk profile. The programme should provide relevant personnel with sufficient knowledge to identify and respond to ML/TF/PF risks and financial sanctions obligations.
FINANCIAL SANCTIONS COMPLIANCE
The new Sanctions Rule introduces standalone and enforceable sanctions obligations.
Key requirements include:
Screening of all applicants, customers, investors, beneficial owners, transactions, service providers and connected parties against applicable sanctions lists
Monitoring transactions for sanctions concerns
Freezing accounts, funds or economic resources of a designated person without delay
Reporting to the appropriate Cayman authorities without delay
Maintaining clear records of sanctions-related reviews, decisions, actions taken and the rationale supporting those decisions
The Rule also emphasizes the importance of sanctions training and integration of sanctions compliance into the broader AML/CFT/CPF framework.
RECOMMENDED NEXT STEPS
In preparation for the 18 September 2026 implementation date, regulated entities should consider taking the following steps:
Conduct a gap analysis against the new Rules
Review existing AML/CFT/CPF frameworks
Assess whether current risk assessments remain appropriate
Review outsourced AML arrangements and oversight mechanisms
Evaluate the need for fund-specific policies, procedures and risk assessments
Review independent audit schedules
Ensure directors and key service providers understand the new requirements
HOW WE CAN HELP
Trident Trust is supporting clients in assessing the impact of the new Rules and can assist with:
Providing suitably qualified AMLCO, MLRO and DMLRO appointments (AML Officers)
Review AML/CFT/CPF risk assessments where Trident delegates serve as AML Officers
Compliance programme reviews
Sanctions compliance reviews
Independent AML audit planning and coordination
How Trident is Preparing
For structures where Trident Trust Company (Cayman) Limited acts as the AML Delegate under a reliance model and is responsible for fulfilling the obligations set out in the AML Regulations, Trident is currently conducting a detailed review of its AML policies and procedures. This exercise is intended to ensure that our framework appropriately reflects the requirements of both the AML/CFT/CPF Rule and the Sanctions Rule.
Where Trident has also been appointed to provide AML Officer services, the relevant AML Officers will issue a separate communication containing further guidance and any entity-specific recommendations arising from the review of the new requirements.
If you would like to discuss the application of these rules to your fund structure, please contact your usual Trident Trust representative.
DISCLAIMER
This update is intended as a general summary of regulatory developments and does not constitute legal advice. Specific advice should be obtained in relation to the circumstances of each regulated entity.