Cayman's AML Rules Become Enforceable on 18 September: What Fund Boards Must Do Now
On 18 September 2026 two new CIMA measures take effect: the Rule on Effective Compliance Programme for the Prevention and Detection of Money Laundering, Terrorist Financing and Proliferation Financing for Financial Services Providers, and the Rule on Compliance with Financial Sanctions and Targeted Financial Sanctions. Both were gazetted on 20 July 2026, carry the force of law and apply to every fund regulated by CIMA under the regulatory acts. The substance is largely familiar, because Cayman funds already operate under the Proceeds of Crime Act, the Anti-Money Laundering Regulations and CIMA's Guidance Notes. What changes is enforceability, and with it what a governing body must be able to prove. This article sets out the CIMA AML rules fund boards must evidence before the effective date, with clause references for the minute.
The compliance programme has stopped being a document the administrator holds. It is now a board obligation the fund must be able to evidence, on request, in writing. We see the same pattern across the funds on our platform: the controls exist, but the record that the governing body reviewed them at fund level often does not. The work before 18 September is not designing new controls. It is assembling the risk assessment, the officer arrangements, the audit cycle and the training plan into one file, putting that file in front of the board, and minuting the outcome.David Lloyd, Chief Executive Officer at CV5 Capital
Executive Summary
The two Rules do not create a new AML regime. They lift CIMA's supervisory expectations into binding measures, attach documentation and testing obligations to each, and place the record of oversight with the governing body of each regulated fund. Figures and dates in this article are current as at 5 September 2026.
- Both Rules take effect on 18 September 2026 and apply to all financial services providers regulated by CIMA under the regulatory acts, with no sector exemption.
- The Rules supplement the Anti-Money Laundering Regulations, which prevail in the event of inconsistency, and take precedence over the Guidance Notes.
- Each regulated fund is a financial services provider in its own right, so the governance framework, risk assessment and audit are owed at fund level.
- The independent audit runs at a risk-based frequency, may not be internal for more than two consecutive cycles, and is filed with CIMA.
- The Sanctions Rule requires screening of investors, beneficial owners, transactions, service providers and connected persons, and screening survives simplified due diligence.
What the Two Rules Change, and What They Do Not
The Cayman framework is layered. The Compliance Programme Rule states at Rule 4.3 that it supplements Regulations 3, 4, 5, 6, 8 and 8A of the Anti-Money Laundering Regulations, and at Rule 4.4 that the Regulations prevail where the two conflict. The Sanctions Rule says the same at Rule 5.4. Both Rules take precedence over prior guidance notes, so the Guidance Notes now sit beneath them.
Enforceability is the practical change. Each Rule is issued under the Monetary Authority Act, states that it has the force of law, and engages the Authority's Enforcement Manual on breach. The Sanctions Rule adds, at Rule 8.3, that where the same facts breach both the Regulations and a corresponding rule the Authority will exercise its discretion to avoid double jeopardy. Obligations that were previously guidance can now attract an administrative fine directly.
Scope is wide. Rule 5.1 of the Compliance Programme Rule applies it to all financial services providers regulated and supervised by CIMA under the regulatory acts, including branches, subsidiaries, affiliates and other group members. CIMA's published FAQs confirm that no sector exemptions will be granted, regardless of business model or outsourcing arrangements. Registered mutual funds, private funds and Securities Investment Business Act registrants are all within scope, and digital asset and tokenised funds are treated no differently.
The FAQs state that the measures support CIMA's objective of a positive assessment in the FATF fifth round review of the Cayman Islands, and that providers with robust existing frameworks should need only limited enhancements. That is consistent with the earlier CV5 analysis of what the two Rules mean for Cayman funds. The difficulty for most boards is not the standard. It is the evidence.
Keep the categories separate. A statutory requirement comes from the Proceeds of Crime Act or the Anti-Money Laundering Regulations. A regulatory requirement now also comes from the two Rules. The Guidance Notes and the FAQs are guidance, and the way an administrator structures an onboarding file is market practice. A board minute should be able to say which category each control sits in.
Why the Operative Unit Is the Fund, Not the Manager
The Compliance Programme Rule is addressed to each financial services provider, and a registered fund is a provider in its own right. Rule 6.1(g) defines the governing body as the board of a company, the general partner of a partnership, the manager of a limited liability company and the trustees of a trust. For a segregated portfolio company, the board is the governing body for the funds it operates.
Rule 7.1 requires the governing body to establish and maintain a governance framework for the compliance programme, documenting and assigning the roles of all senior persons involved. Rule 9.1 requires each provider to apply its own risk-based approach. CIMA's FAQs allow a group assessment where appropriate, provided the risks specific to the Cayman operation are identified and addressed. A manager-level document covering several funds will not, on its own, discharge each fund's obligation.
Reliance on service providers remains expressly permitted. Rule 5.3 provides that a provider relying on a third party must remain satisfied that the relied-upon functions comply, and retains ultimate responsibility. Rule 10.4 adds that the provider must, on request, give the Authority timely and sufficient evidence of how it remains satisfied. The role of the Cayman compliance officer for a fund is where that evidence is usually assembled, but the board owns it.
Building a fund into this standard from day one?
A fund launched after 18 September 2026 will be examined against the Rules from its first subscription. The governance framework, the officer appointments, the fund level risk assessment and the audit cycle are part of the launch build, not a later tidy up.
The Fund Terms Questionnaire is the first structuring step. It captures the proposed strategy, the investment manager, launch AUM, target investors, dealing and liquidity terms, fees, custody and banking, and the operational requirements that determine how the compliance file is constructed and who maintains it.
Start the Hedge Fund QuestionnaireThe Six Workstreams to Close Before 18 September
The operational load resolves into six workstreams. Most well-run funds will find four substantially in place and two requiring new work: fund-specific audit evidence and a forward-looking training plan.
| Workstream | Rule reference | Typical current state | Action before 18 September 2026 |
|---|---|---|---|
| Governance framework | Compliance Programme Rule 7.1, 10.2 | Roles understood, rarely documented at fund level | Adopt a written framework per fund defining governing body, AMLCO, MLRO and DMLRO roles; board approves policies |
| Fund level risk assessment | Compliance Programme Rule 9.2, 9.6 | Held at manager level, or not refreshed | Complete or refresh at fund level, document inherent and residual risk, consider the National Risk Assessment, define trigger events |
| Officer designation and independence | Compliance Programme Rule 7.1(c) and (d), 8.1, 8.2, 8.11 | Officers appointed, independence assumed | Confirm qualification, resources and independence in writing; record how conflicts are managed |
| Independent audit | Compliance Programme Rule 12.1 to 12.5 | Performed at service provider level, if at all | Set the frequency from the risk assessment, diarise the external cycle, define scope and confirm the filing route |
| Sanctions screening | Sanctions Rule 7.4, 7.5, 7.11; Compliance Programme Rule 10.5.23 | Delegated to the administrator | Confirm list coverage, re-screening on list updates, escalation routes, and that screening survives simplified due diligence |
| Training plan and record | Compliance Programme Rule 11.5 to 11.8, 11.14 | Ad hoc or manager level | Adopt a forward-looking plan covering the governing body and delegates, deliver at least annually, retain records |
Two approval points are easy to miss. Rule 10.2 requires policies to be approved by the governing body, while procedures and controls may be approved by senior management or the governing body. Rule 10.1 requires both to be accessible to all relevant parties, including those performing outsourced functions. Policies adopted by the administrator and never approved by the board leave a gap at the first line of the file.
Rule 8.8 requires the AMLCO to keep the governing body informed of the programme's operation, escalating issues and reporting at least annually. Funds that maintain an annual compliance calendar for a Cayman hedge fund should add the AMLCO report, the training cycle and the audit cycle to it now.
The Independent Audit: Frequency, Rotation, Filing and Fund-Specific Scope
Rule 12.1 requires each provider to maintain independent audit procedures to review and test the compliance programme. The obligation is not new; CIMA's FAQs note that Regulation 5(a)(ix) of the Anti-Money Laundering Regulations already requires a risk-based independent audit function. What the Rule adds is structure. Under Rule 12.2(a) the audit must run at a frequency commensurate with the provider's size, complexity, nature of business and risk profile, as determined by its own risk assessment or as otherwise required by the Authority. The FAQs state that annual audits are not mandated and offer illustrations: roughly every two years for higher risk, three for medium and four for lower risk.
Rotation is prescribed. Rule 12.3 permits the audit to be conducted internally, but not for more than two consecutive cycles, after which the next audit must be external. The Rule's footnote defines internally as any individual or unit employed by, engaged under contract by, or forming part of the provider's organisational structure under its direction or control. The FAQs add that the AMLCO, MLRO and DMLRO form part of the programme and cannot audit activities for which they are responsible, whether employed or outsourced. Under Rule 12.2(b) and (c) the auditor must be independent of the design and operation of the controls, and the provider must be able to document how independence was determined.
Filing changes the regulator's line of sight. Rule 12.2(d) requires the audit report to be filed with the Authority as soon as practically possible after completion, and Rule 12.4 requires remediation within timeframes commensurate with materiality. A report that identifies weaknesses is now a document the supervisor will read, so a remediation plan should accompany any adverse finding.
Scope is the point that most affects funds. The FAQs state that a regulated investment fund must still undertake an AML audit even where substantially all of its operations are outsourced. Relying solely on a service-provider-level internal audit or a population-based review, without sufficient evidence about the individual fund's programme, would not provide sufficient assurance. A fund may consider its administrator's audit report, but the governing body must be able to show that its scope covered the activities performed for that fund. A common effective date also concentrates demand on audit resource, which argues for fixing the cycle and the provider now.
Governance Actions the Board Should Minute
CIMA's FAQs describe effective oversight. The governing body receives and reviews reports on the programme, understands the fund's exposure to money laundering, terrorist financing, proliferation financing and sanctions risk, challenges management, allocates qualified resources and oversees corrective action. The FAQs state that this should be evidenced through minutes, reports, documented decisions and the tracking of remediation. Undocumented oversight is indistinguishable from no oversight.
- Minute the review. Record that the programme was reviewed against both Rules, that the fund level risk assessment was approved, that the audit frequency and provider were determined, and that the training plan was adopted. Date each document and reference it in the minute.
- Confirm officer independence in writing. Rule 8.2(c) requires the AMLCO to perform the compliance function independently and objectively from the business functions under oversight, and where full separation is not practicable, to manage conflicts effectively. The FAQs add that independence means functional and reporting autonomy with a direct escalation route to the governing body, and that one individual may hold several roles where conflicts are demonstrably managed.
- Own the delegate relationship. The FAQs list what oversight of outsourced activities should include: defined roles, reporting and escalation arrangements, ongoing monitoring, timely access to records, periodic testing and periodic review of the provider. Rule 10.7.6 separately requires notification to the Authority of any outsourcing agreement relating to material functions of the programme.
Boards with independent directors already institutionalise this challenge function. Boards composed solely of manager principals should consider how they evidence objective review of their own arrangements. They should also consider the position of the AMLCO, who the FAQs say may be personally liable where a breach of the Regulations is attributable to that officer's conduct. The obligations sit alongside the delegation oversight already required by the CIMA corporate governance rule for regulated funds.
Structure the fund so the board can evidence it
Strategy: any traditional hedge fund strategy. Vehicle: Cayman segregated portfolio within an established multi-manager platform. Governance: a board that already receives AMLCO reporting, approves policies and runs a defined audit cycle at fund level.
Complete the Fund Terms Questionnaire to set out the proposed strategy, the investment manager, launch AUM, target investors, dealing and liquidity terms, fees, custody and banking, and the operational requirements. It is the first structuring step, and the answers determine how the compliance framework is applied to the new fund.
Start the Fund Terms QuestionnaireThe Sanctions Rule Perimeter
The Sanctions Rule is a separate measure, but Rule 7.1 requires the sanctions compliance programme to be an integral part of the overall AML compliance programme. Its scope is wider: Rule 6.3 applies it to all regulated persons supervised by CIMA under the regulatory acts, and the FAQs confirm that it applies whether or not the person conducts relevant financial business. The Governor is the competent authority for financial sanctions and has delegated the receipt of reports and licence applications to the Financial Reporting Authority. The Sanctions List includes the UK Sanctions List and any other list applying to the Cayman Islands through the Overseas Orders in Council.
| Obligation | Sanctions Rule reference | What the board should ask |
|---|---|---|
| Consider sanctions in the risk assessment; never rate geographic risk low where a country is subject to UK, UN, US or OFAC sanctions related to its ML, TF or PF risks | 7.2, 7.3 | Does the fund's country risk model apply that rule mechanically? |
| Screen applicants, customers, beneficial owners, transactions, service providers and other relevant parties including connected persons | 7.4 | Who screens the fund's service providers and counterparties, not only its investors? |
| Re-screen all customers on every list update, regardless of due diligence classification; simplified due diligence does not reduce screening | 7.5, 7.11 | How quickly do list updates reach the screening system? |
| Freeze without delay and without prior notice; do not make funds or services available to designated persons or entities they own or control | 7.17, 7.18 | Who has authority to freeze, and is the redemption process able to stop a payment? |
| Report to the Financial Reporting Authority via the Compliance Reporting Form; document every action and its rationale | 7.7, 7.9, 7.13.3 | Where is the escalation file and who signs it? |
| Verify potential matches against other identifying information to resolve false positives | 7.19 | Is false positive resolution recorded, or cleared informally? |
| Regular staff training on identifying designated persons and frozen assets; licence applications to the Governor with a copy to the FRA | 7.20, 7.23 | Has the board itself been trained, and does anyone know the licence route? |
Two points are easy to underestimate. The first is timing: the Rule defines without delay as ideally within a matter of hours of a United Nations Security Council designation. The second is perimeter: Rule 7.4 brings service providers and transactions inside the screening obligation, which an administrator's investor-facing screening does not obviously satisfy. The AML and KYC framework for investor onboarding in Cayman funds covers the investor side; the board should ask who covers the rest.
The two Rules lock together on simplified due diligence. Rule 10.5.23 of the Compliance Programme Rule requires sanctions screening to continue where simplified due diligence is applied, and Rule 7.5 of the Sanctions Rule says the same. Screening logic should not switch off with the due diligence tier.
Digital Asset Funds: Same Obligations, Harder Evidence
Digital asset funds carry identical obligations against a more demanding operating environment. Both Rules define targeted financial sanctions to include measures preventing virtual assets from being made available to designated persons. Rule 10.3(f) of the Compliance Programme Rule includes travel rule requirements, as applicable, within the minimum content of policies and procedures, and Rule 11.8(c) brings anyone who handles virtual currency for the provider within the training population.
Provenance and source of funds
Subscriptions received in digital assets require an evidence trail that differs from a bank transfer. The fund level risk assessment should address how provenance is established for in-kind or stablecoin subscriptions and what on-chain analytics coverage supports it, starting from the source of funds evidence standard for on-chain subscriptions.
Counterparty screening and tokenised registers
Exchanges, over-the-counter desks, custodians, lending counterparties and protocol interactions all sit within the Sanctions Rule 7.4 perimeter as service providers, transactions or connected persons. Where investor interests are digital tokens under the tokenised mutual fund provisions of the Mutual Funds (Amendment) Act, 2026, the programme must reconcile token transfer controls with customer due diligence. Rule 10.6.1 requires records to be retained for at least five years after the relationship ends.
Audit scope
The FAQs state that a fund audit should consider third party relationships and outsourcing alongside onboarding and ongoing due diligence. An audit of a digital asset fund that does not test wallet governance, counterparty onboarding and on-chain screening is unlikely to be adequate in substance. Managers on the CV5 digital asset fund platform should expect those areas in scope from the first cycle.
Where Boards Go Wrong
The failures likely to surface after 18 September are evidential rather than substantive. The controls will usually exist; what will be missing is the record that the governing body of the particular fund reviewed and approved them. The same file that closes those gaps shortens institutional due diligence, because an allocator can now ask for the audit report, its filing date and the basis of the auditor's independence.
- The evidence gap. Controls operated by the administrator with no fund level approval, no dated risk assessment and no minute.
- The delegation illusion. Treating the administrator's policies as the fund's programme without the satisfaction Rules 5.3 and 10.4 require.
- The audit assumption. Relying on a provider-level report whose scope the board has never assessed against the FAQ standard.
Key Takeaways
- Put both Rules on the next board agenda and minute a review against each workstream before 18 September 2026.
- Commission or refresh the fund level risk assessment, documenting inherent and residual risk and the trigger events that will force an update.
- Set the audit frequency from that risk assessment, diarise the external cycle so no more than two consecutive audits are internal, and confirm the filing route.
- Confirm in writing that the AMLCO, MLRO and DMLRO are qualified, resourced and independent, and that none of them performs the audit.
- Ask who screens service providers and transactions, not only investors, confirm screening continues under simplified due diligence, and adopt a training plan that includes the directors.
Reviewing a Cayman structure ahead of 18 September, or launching one after it?
Whether the fund is traditional or digital asset, the governing body must be able to evidence the governance framework, the fund level risk assessment, the officer arrangements, the audit cycle and the sanctions screening file. Managers launching on the CV5 SPC and CV5 Digital SPC platforms operate within a governance and oversight framework already built around those obligations, with the investment manager retaining responsibility for the strategy and trading decisions.
The Fund Terms Questionnaire is the first structuring step. It captures the proposed strategy, the investment manager, launch AUM, target investors, dealing and liquidity terms, fees, custody and banking, exchanges where applicable, and the operational requirements that determine how the compliance file is built and maintained.
Start the Hedge Fund Questionnaire Start the Digital Asset Fund QuestionnaireFrequently Asked Questions
When do CIMA's new AML and sanctions rules take effect?
Both the Rule on Effective Compliance Programme for the Prevention and Detection of Money Laundering, Terrorist Financing and Proliferation Financing for Financial Services Providers and the Rule on Compliance with Financial Sanctions and Targeted Financial Sanctions come into effect on 18 September 2026. Each Rule states that this is sixty days after its publication in the Gazette, which took place on 20 July 2026.
Do the CIMA AML rules apply to registered mutual funds and private funds?
Yes. The Compliance Programme Rule applies to all financial services providers regulated and supervised by CIMA under the regulatory acts, and CIMA's FAQs state that no sector exemptions will be granted regardless of business model or outsourcing arrangements. The Sanctions Rule applies to all regulated persons supervised by CIMA, whether or not they conduct relevant financial business.
Does a fund board have to hold its own AML risk assessment?
Each regulated fund is a financial services provider in its own right and must establish and document its own risk-based approach under the Compliance Programme Rule. CIMA's FAQs allow a group assessment to be used where appropriate, provided the risks specific to the Cayman operation are identified and addressed. A manager level document does not on its own discharge the fund's obligation.
How often must a Cayman fund have an independent AML audit?
The Rule does not set a fixed period. Frequency must be commensurate with the fund's size, complexity and risk profile as determined by its own risk assessment, or as otherwise required by CIMA. The FAQs give illustrations of roughly every two years for higher risk, three for medium and four for lower risk. The audit may not be internal for more than two consecutive cycles, and the report must be filed with CIMA as soon as practically possible after completion.
Can a fund rely on its administrator's AML audit?
Only in part. CIMA's FAQs state that a regulated fund must undertake its own AML audit even where substantially all of its operations are outsourced, and that relying solely on a service-provider-level audit or a population-based review would not provide sufficient assurance. The governing body may consider the provider's report but must be able to show that its scope covered the activities performed for that fund.
Does sanctions screening still apply where simplified due diligence is used?
Yes. Rule 7.5 of the Sanctions Rule provides that simplified due diligence does not reduce or waive screening obligations and requires all customers to be re-screened on every sanctions list update. Rule 10.5.23 of the Compliance Programme Rule separately requires screening to continue where simplified measures are applied.
Cayman Fund Intelligence, Direct to Your Inbox
Receive concise analysis on Cayman fund formation, digital asset funds, regulation, governance and institutional infrastructure.
Considering launching a Cayman fund?
Complete the relevant CV5 Fund Terms Questionnaire to provide the core information required to assess the proposed structure.
Stay current on Cayman fund formation
Receive practical updates on Cayman hedge funds, digital asset funds, CIMA regulation, governance and institutional infrastructure.