Guide · CIMA AML Rule

The CIMA AML Rule: a guide for Cayman fund boards.

CIMA's AML Rule took effect on 18 September 2026. Scope, outsourcing duties, the fund-level AML audit and the evidence Cayman fund boards now need.

In force
18 September 2026
Applies to
CIMA-registered funds and other FSPs
Updated
Published by
AgentKYZ

The Rule in brief

  • Name. Rule on Effective Compliance Programme for the Prevention and Detection of Money Laundering, Terrorist Financing and Proliferation Financing for Financial Services Providers. Most firms call it the AML Rule.
  • In force. 18 September 2026, sixty days after CIMA published it in the Gazette (s.14.1). A companion Sanctions Rule took effect the same day.
  • Legal weight. The Rule has the force of law (s.13). It overrides CIMA guidance where the two conflict, and the Anti-Money Laundering Regulations prevail over the Rule (s.4.4).
  • Who it binds. Financial services providers that CIMA regulates and that conduct relevant financial business. CIMA counts registered mutual funds and private funds among them.
  • Enforcement. CIMA does not plan a blanket enforcement approach from day one, and the administrative fines framework for the Rule is not yet in effect (FAQ 4).
  • For fund boards. Your fund keeps ultimate responsibility for the AML work it delegates, and it must give CIMA evidence of its oversight on request (s.5.3, s.10.4).

Who the Rule covers

Section 5.1 applies the Rule to “all FSPs that are regulated and supervised by CIMA under the Regulatory Acts”. CIMA’s FAQ 6 narrows that to providers that conduct relevant financial business, “regardless of their business model or outsourcing arrangements”.

During the consultation, industry argued that funds do not carry on relevant financial business. CIMA disagreed. Its feedback statement places funds under paragraph 19 of the schedule: “Otherwise investing, administering or managing funds or money on behalf of other persons.” If CIMA registers your fund under the Mutual Funds Act or the Private Funds Act, the Rule applies to it.

Funds without CIMA registration fall outside the Rule. Check each vehicle in your structure, including feeders and SPVs, against its registration status.

Delegation leaves the responsibility with your fund

A typical Cayman fund has no employees. The administrator onboards investors, runs the screening and keeps the records, and the fund often appoints its AMLCO and MLRO from the administrator’s group or a specialist firm.

The Rule lets you rely on others for this work and keeps the obligation with you:

  • Section 5.3. A provider that relies on another person “shall, notwithstanding such reliance, remain satisfied” that it meets its obligations, and “shall retain ultimate responsibility for such compliance”.
  • Section 10.7.5. The provider “remains ultimately responsible … irrespective of any outsourcing arrangement”.
  • Section 10.4. On request, the provider must give CIMA “timely and sufficient evidence demonstrating how it remains satisfied” that the relied-upon functions comply.

CIMA’s Guidance Notes already told providers that they “shall not contract or transfer their compliance obligations” (Part II, s.2.C, para 8). FAQ 14 repeats the point: “Outsourcing does not transfer accountability away from the FSP or its Governing Body.”

For a fund board, s.10.4 sets the practical test. CIMA can ask your fund to show, with evidence specific to the fund, that it checked the work its administrator did.

Outsourcing requirements, now binding on funds

CIMA describes the outsourcing provisions as a reflection of “existing supervisory expectations” (FAQ 23). For funds the change runs deeper. The Statement of Guidance on Outsourcing excluded regulated mutual funds and private funds from its scope, and Ogier notes that the Rule reflects much of that guidance. Funds now carry those expectations as binding requirements.

Under s.10.7 your fund must:

  • assess the risks of each outsourcing arrangement, including country risk (s.10.7.1(a));
  • confirm the arrangement does not impair its ability to meet its obligations (s.10.7.1(b));
  • conduct and keep records of CDD on the service provider before the arrangement starts (s.10.7.1(c));
  • carry out due diligence on the provider’s “fitness and propriety, competence and capability” (s.10.7.2);
  • decline or exit an arrangement whose risks it cannot manage (s.10.7.3);
  • sign an agreement that sets out the rights and obligations of both parties (s.10.7.4);
  • avoid arrangements where confidentiality, secrecy, privacy or data protection rules could impede CIMA’s access (s.10.7.5).

Section 8.4 adds that your compliance programme documents “must clearly demonstrate allocation of roles and responsibilities”.

Notifying CIMA of outsourcing

Section 10.7.6 reads: “FSPs must notify the Authority of any outsourcing agreement that relates to material functions of its Compliance Programme.” The Rule sets no fixed deadline. Section 10.3(e) asks for policies that cover notice in writing “within a reasonable timeframe”, and the Statement of Guidance on Outsourcing (s.14.1) lists the content CIMA expects: the function, the provider and whether it sits in the same group, its location, the start and end dates, and your reasons for outsourcing.

Industry asked CIMA to exempt regulated funds, arguing that funds already disclose their service providers at registration. CIMA refused. Registration disclosure, it said, “serves a separate purpose and does not necessarily capture material compliance‑related outsourcing” (feedback statement, item 199). Cayman counsel still differ on whether updated offering documents and AML officer filings satisfy s.10.7.6. Take advice on your own structure and record the decision in the board minutes.

The oversight CIMA expects

The Rule text prescribes no monitoring method. CIMA’s FAQ 25 fills that gap. It expects providers and their Governing Bodies to keep:

  • defined roles and responsibilities;
  • reporting and escalation arrangements;
  • ongoing monitoring of performance and effectiveness;
  • timely access to relevant information and records;
  • periodic review and testing of outsourced activities;
  • periodic review of the risks tied to each service provider.

FAQ 7 describes the evidence CIMA looks for: “Governing Body or committee minutes, reports, documented decisions, and the tracking of remediation actions”.

Your board should confirm it can get investor files out of the administrator. The Guidance Notes say a provider “should have access to all the information or documents relevant to the outsourced activity” (Part II, s.10.C, para 6). Part VI accepts that a fund may not hold records itself, and adds that “it must ensure that all appropriate records are maintained on its behalf”. If your board has never asked the administrator for a set of investor files, you have not tested that access.

The independent AML audit

Section 12 requires an independent audit of your compliance programme:

  • you set the frequency by risk (s.12.2(a));
  • the auditor must be independent of the programme’s design and operation (s.12.2(b)), and you must evidence that independence on request (s.12.2(c));
  • you file the report with CIMA “as soon as practically possible after the completion” (s.12.2(d));
  • internal staff may not perform the audit for more than two consecutive cycles (s.12.3);
  • you must remediate the findings (s.12.4).

CIMA’s FAQs add detail. FAQ 38 gives example frequencies of about two years for higher-risk providers, three for medium and four for low. Your AMLCO, MLRO and DMLRO cannot perform the audit (FAQ 39). CIMA does not require an audit “solely because the Rule has become effective” (FAQ 34), and it has set no universal first filing date (FAQ 33).

FAQ 43 carries the fund-level point. An audit of an individual fund should conclude on that fund’s compliance programme, and “relying solely on a service-provider-level internal audit or a population-based review, without obtaining sufficient evidence regarding the individual Fund’s Compliance Programme, would not provide sufficient assurance”. FAQ 45 adds that the audit “should also include testing that is specific to the FSP”. Your auditor can use the administrator’s group audit report as one input and still needs to test your fund’s own files.

AMLCO, MLRO and DMLRO

  • Your board designates an AMLCO, MLRO and DMLRO, each “a natural person operating at no lower than a management level” (s.7.1).
  • The AMLCO must be fit and proper (s.8.1) and must “perform the compliance function independently and objectively” (s.8.2(c)).
  • The AMLCO may delegate duties and “must retain the overall responsibility” (s.8.6).
  • The AMLCO reports to the board “at least annually” (s.8.8).
  • CIMA expects a professional qualification, knowledge of the Cayman framework and relevant experience (FAQ 11). It notes that an AMLCO “may be personally liable” where a breach follows from their conduct (FAQ 10).

Risk assessment, training and records

  • Risk assessment. Document it, take account of the latest National Risk Assessment, and cover inherent and residual risk (s.9, s.9.6). Update it “without delay” after trigger events such as new products, higher-risk geographies or geopolitical developments (s.9.2(f)).
  • Training. Deliver it “at least annually” under a documented plan, and keep the training records (s.11.5 to s.11.7, s.11.14).
  • Records. Keep them for “at least five (5) years after the end of a business relationship” and make them available to CIMA on request without delay (s.10.6.1). Keep beneficial ownership records for five years after the customer ceases to be a customer (s.10.6.4).

The Sanctions Rule

The Rule on Compliance with Financial Sanctions and Targeted Financial Sanctions took effect on the same day. For a fund, these points land on the administrator’s desk:

  • screen applicants, customers, beneficial owners, transactions, connected persons and service providers (s.7.4);
  • re-screen the customer base “Without Delay” each time a sanctions list changes, whatever the risk rating (s.7.5, s.7.11);
  • freeze assets without delay on a match (s.7.17);
  • report to the Financial Reporting Authority on a Compliance Reporting Form (s.7.7, s.7.13);
  • rate no customer as low geographic risk if its country falls under UK, UN, US or OFAC sanctions (s.7.3).

Hong Kong and Singapore managers

CIMA has published nothing aimed at Asia-based managers, so this section gives our own reading. The Rule binds the Cayman fund and any manager registered with CIMA. A manager licensed by the SFC or MAS alone sits outside its direct scope. The fund it manages sits inside, and the board of that fund carries the oversight duty.

Three provisions matter for Asian structures:

  • Country risk. Section 10.7.1(a) requires a country risk assessment for each outsourcing arrangement, including administrators and transfer agents in Hong Kong or Singapore.
  • Data access. Section 10.7.5 bars arrangements where secrecy or data protection rules could impede CIMA’s access. Check your administration agreement against the data laws where the records sit.
  • Group risk assessments. FAQ 20 says a group-level assessment must still address “risks specific to their Cayman Islands operations”. Where a provider’s home standards fall below Cayman’s, the Guidance Notes say it “should adopt the Cayman Islands’ standards” (Part II, s.10.C, para 10).

A checklist for your next board meeting

  1. Confirm the CIMA registration status of each vehicle in the structure.
  2. List the functions the fund relies on others for, and the provider behind each one.
  3. Put CDD on each provider, and your assessment of its fitness, competence and capability, on file (s.10.7.1(c), s.10.7.2).
  4. Check that each agreement sets out both parties’ rights and obligations and preserves CIMA’s access (s.10.7.4, s.10.7.5).
  5. Decide with counsel whether to notify CIMA of material outsourcing (s.10.7.6), and minute the decision.
  6. Confirm your AMLCO, MLRO and DMLRO pass the natural person and management level tests (s.7.1).
  7. Agree how the board will monitor and test the administrator’s work, and how often (FAQ 25).
  8. Request a set of investor files from the administrator to prove you can get them.
  9. Set the date of the next independent AML audit and put fund-specific file testing in its scope (s.12, FAQ 43).
  10. Record the oversight in minutes, reports and a remediation tracker (FAQ 7).

Evidence of oversight: shadow KYC

Items 7, 8 and 10 need evidence your administrator cannot produce about itself. We call that control shadow KYC. You already run a shadow NAV to check the administrator’s valuation. Shadow KYC applies the same discipline to AML: an independent review of the investor files your administrator keeps, tested against your fund’s own AML policy.

We test the full population of files and return exceptions by category and age, with a file reference behind each one and the Rule provision it touches. Your board minutes the result, and your AML auditor can test against it. See how shadow KYC works.

Questions

When did the CIMA AML Rule take effect?

On 18 September 2026, sixty days after CIMA published it in the Gazette (Rule s.14.1). The companion Sanctions Rule took effect on the same day.

Does the CIMA AML Rule apply to mutual funds and private funds?

Yes, if CIMA registers the fund. In its feedback statement CIMA said funds fall within relevant financial business because they invest, administer or manage funds or money on behalf of other persons. Funds registered under the Mutual Funds Act or the Private Funds Act sit within the Rule.

Can a fund rely on its administrator's AML audit?

Not on its own. CIMA's FAQ 43 says that "relying solely on a service-provider-level internal audit or a population-based review, without obtaining sufficient evidence regarding the individual Fund's Compliance Programme, would not provide sufficient assurance". FAQ 45 says the audit should include testing specific to your fund.

Will CIMA fine funds for breaching the AML Rule?

CIMA says it does not intend a blanket enforcement approach from the effective date, and the administrative fines framework for breaches of the Rule is not yet in effect (FAQ 4). CIMA keeps supervising through onsite inspections, desk-based reviews and thematic reviews, and the Rule has the force of law (s.13).

Does a fund have to notify CIMA about its administrator?

Section 10.7.6 requires notice of any outsourcing agreement that relates to material functions of the compliance programme, and CIMA refused to carve regulated funds out of it. Cayman counsel differ on whether a fund's existing filings meet the requirement, so take advice on your own structure and minute the decision.

Sources

Shadow KYC

Evidence your board owns, on the KYC your administrator runs.

We test your administrator's investor files against your fund's AML policy and return exceptions by category and age, each traced to a file and mapped to the Rule.

This guide is general information and not legal advice. Section references point to the AML Rule unless stated, and FAQ references point to CIMA's published AML/CFT FAQs. Check the current texts before relying on them.