CIMA has issued two new Rules covering sanctions compliance and AML/CFT/CPF compliance programmes, and they take effect on 18 September 2026 for CIMA-regulated and supervised financial services providers, including registered investment funds, managers and advisers.
Most of what they require isn’t new. It simply reflects what’s already been expected practice for years. What is genuinely new is the more prescriptive treatment of independence, the requirement to file completed audit reports with CIMA, and the requirement for an external provider after no more than two consecutive internal audit cycles.
September isn’t a deadline to panic about. Rather, it is the point from which the new Rules apply. Where a fund undertakes two consecutive internal audit cycles, the quality of those audits will determine how smoothly the subsequent external audit goes.
From existing obligations to enforceable Rules
The two instruments are the Rule on Compliance with Financial Sanctions and Targeted Financial Sanctions, and the Rule on Effective Compliance Programme for the Prevention and Detection of Money Laundering, Terrorist Financing and Proliferation Financing.
Historically, the underlying requirements and expectations were spread across the binding AML Regulations, CIMA’s AML Guidance Notes and, for regulated entities, its Rule and Statement of Guidance on Internal Controls and its Statement of Guidance on Outsourcing. The new Rules consolidate and make many of those existing obligations more prescriptive. Both Rules now state plainly that they are issued under CIMA’s statutory powers and “shall have the force of law,” meaning CIMA can point directly to the Rule itself and to the fact of any breach.
There’s a lot of noise right now calling this a sweeping change. It mostly isn’t. This largely codifies and makes more prescriptive what was already required or expected.
But one area where the substance has genuinely moved is independent audit.
The big change: independent AML audits and external review
CIMA has been building toward this for several years. The AML Regulations already required an effective risk-based independent audit function, while the Guidance Notes required AML audits to be conducted regularly at a frequency appropriate to the entity’s nature, size, complexity and risk. CIMA has also increasingly tested these arrangements during inspections and requested evidence of completed audits.
The new Rule now codifies much of this: every financial service provider (FSP) must establish and maintain independent audit procedures, with the frequency determined on a risk-based approach, and file the completed audit report with CIMA. Every audit must be conducted by suitably qualified persons who are independent and separate from those involved in designing, implementing or operating the controls being reviewed. The audit may be conducted internally for no more than two consecutive audit cycles, after which the next audit must be conducted by an external service provider. For entities adopting an annual audit cycle, this will typically mean an external review every third year.
The requirement has not previously been expressed in this level of prescriptive detail, and it does not apply only to licensees. It applies to every fund regulated by CIMA, which means roughly 31,000 Cayman funds will need to ensure that they have formal independent AML audit procedures meeting the new requirements. Many have been getting by with reports produced solely by their own appointed AML officer. This will no longer be enough where that officer is involved in designing, implementing or operating the compliance programme being reviewed.
The independence requirement is genuine: an appointed AML officer, or any person who designed or operates the policies and procedures, will not ordinarily be regarded as sufficiently independent to sign off on the audit of those same controls. Using a separate firm will usually provide the clearest evidence of independence. Where another team within the same service provider is proposed, the fund must be able to demonstrate genuine functional separation and the absence of conflicts.
Funds have other new requirements too.
The requirements applying to funds are also stated more explicitly than before, including those covering AML functions outsourced to a third party, which is common practice for funds relying on a fund administrator or an appointed AML officer. We’ll cover the detail of this in a later post.
The sanctions Rule also deserves attention. It requires sanctions compliance to form part of the broader AML/CFT/CPF framework, including screening customers, beneficial owners, connected persons and transactions against applicable sanctions lists, maintaining appropriate records, and responding to sanctions designations without delay.
Who’s in scope?
The Sanctions Rule applies to “Regulated Persons”: any natural person, legal person or legal arrangement regulated by CIMA under the Regulatory Acts. The Compliance Programme Rule applies to FSPs regulated and supervised by CIMA, including CIMA-regulated funds.
The Compliance Programme Rule is explicit that it extends to branches, subsidiaries, affiliates and other members of a CIMA-regulated financial group. Registration as a fund does not place you outside these requirements, and outsourcing an AML function to a third party or group member does not transfer away your responsibility for it. CIMA can ask you to demonstrate that outsourced functions actually comply.
What you need to do
The good news is that 18 September does not mean every fund must complete an audit on that date. It does mean that the Rule takes effect and that funds should determine and document their risk-based audit frequency and plan for an external review after no more than two consecutive internal audit cycles:
- * Get a risk-based AML audit cycle into your calendar now. For funds adopting an annual cycle, two consecutive internal audits will provide the record an external reviewer will expect to see when the following audit is undertaken externally.
- * If your AML officer or administrator also built or operates your policies and procedures, work out now who’s actually independent enough to perform the audit, and establish that relationship before the external audit cycle arrives.
- * File each completed audit report with CIMA as soon as practically possible, as the Rule requires, and keep the supporting documentation in a form you can hand over quickly.
- * Treat this as proactive governance rather than a compliance emergency. The risk is not an immediate requirement to complete an audit by 18 September. It is failing to establish a defensible audit cycle or arriving at the external audit without adequate evidence from the preceding cycles.
There’s plenty of time to get this right, and no reason to wait until there isn’t. So please get in touch, and we’ll set up a call to go through what your review programme should look like from here.