Cayman regulatory watch · CIMA

Who can audit your AML programme under the new CIMA rule

CIMA's guidance answers a question a number of Cayman firms have been getting wrong: the person who runs the compliance programme can't be the person who audits it, and outsourcing the role doesn't change that.

Published
12 August 2026
Last reviewed
12 August 2026
Regulator
Cayman Islands Monetary Authority
Effective date
Friday, 18 September 2026
Applies to
CIMA registered and licensed financial services providers
Source
CIMA guidance FAQs · the rule (PDF)

The independence question

CIMA's guidance addresses whether an outsourced AMLCO, MLRO or DMLRO can carry out the independent AML audit. The answer is no. Those officers form part of the compliance programme itself, so they can't independently audit activities they're responsible for. The guidance is explicit that this applies whether the function sits with an employee or with an outsourced provider.

That matters because outsourcing these roles is ordinary in the Cayman Islands, particularly among funds and smaller regulated entities. A firm that engaged one provider for both its AMLCO function and its audit has an independence problem to resolve, and resolving it means finding a second party and documenting why that party is independent.

CIMA describes independence as freedom from actual or perceived conflicts of interest, with the auditor having no responsibility for the design, operation, management or oversight of the programme. Perceived is doing work in that sentence. A firm needs to be able to show the separation, not just assert it.

Who is permitted to perform the audit

The guidance names four categories: internal audit functions, external auditors, independent consultants, and other suitably qualified and competent independent parties. The common requirement across all four is independence from the AML function and from the activities under review.

There's also a requirement that at least one audit in every three independent audit cycles is external. CIMA explains the reasoning directly, which is to reduce familiarity risk, self-review risk and loss of objectivity over time. A firm using the same internal reviewer indefinitely won't meet that expectation.

How often the audit has to happen

The rule doesn't mandate an annual AML audit. Frequency, scope and depth are determined using a risk-based approach that accounts for the firm's size, complexity, business activities and exposure. CIMA gives an illustration rather than a schedule: a higher risk firm might reasonably audit every two years, with medium and lower risk firms at three and four years respectively.

Because there's no prescribed interval, the burden moves to documentation. A firm has to determine its own frequency and record the reasoning, tied to its documented risk assessment and the level of assurance it needs. An interval chosen without a written rationale behind it is difficult to defend during an inspection.

Where firms tend to be exposed isn't the audit itself. It's the absence of a written record explaining why the chosen frequency, scope and auditor were appropriate.

Funds that outsource nearly everything

A regulated investment fund still has to undertake an AML audit even where all or substantially all of its operations are outsourced. CIMA is direct that relying only on a service provider's internal audit, or on a population-based review, without obtaining sufficient evidence about the individual fund's compliance programme, doesn't give adequate assurance.

The expectation is evidence sufficient to conclude on the design and operating effectiveness of that specific fund's programme, taking in investor onboarding controls, ongoing due diligence, third party arrangements, internal reporting, training and record keeping. For fund structures with dozens of entities under one administrator, that's a documentation exercise worth scoping now rather than in September.

Accountability doesn't transfer

One theme runs through the whole of CIMA's guidance. An AMLCO may be personally liable where a compliance failure amounts to a breach of the regulations and is attributable to their own conduct, but the firm remains ultimately responsible for its compliance programme. Outsourcing a function moves the work, not the accountability.

The same holds for the governing body. CIMA expects oversight evidenced through governance records, meaning minutes, reports, documented decisions and tracked remediation actions. Boards that discuss AML matters without recording the discussion have nothing to produce when asked.

What to have documented before 18 September

Five things, and none of them require regulatory interpretation to assemble. A written record of who performs your audit and why that party is independent of your compliance programme. A documented audit frequency with the risk-based reasoning behind it. A record of when your last external audit occurred and when the next one falls due. For funds, evidence tied to the individual entity rather than to the service provider alone. And governance records showing the board received, reviewed and acted on compliance reporting.

Firms that already run mature programmes will find most of this exists in some form. The work is locating it, organising it and confirming nothing is missing before the date arrives.

Source information above is drawn from CIMA's published guidance FAQs and the rule itself, both linked at the top of this article. Commentary about documentation priorities represents the view of Cayman Bid & Compliance Services.

This article is general information about a published regulatory measure. It isn't legal, regulatory or compliance advice, and it shouldn't be relied on in place of advice from appropriately qualified professional advisers. Cayman Bid & Compliance Services is an independent business and is not affiliated with, endorsed by, or acting on behalf of the Cayman Islands Monetary Authority or the Cayman Islands Government.

Check your implementation readiness

Call WhatsApp Request review