Skip to content
an aerial view of a beach and city

CIMA's AML and Sanction Rules 2026: What Cayman FSPs Need to Know

Published
Sep 8, 2026
By
Isatou Smith
Share

The Cayman Islands Monetary Authority (CIMA) will enforce enhanced regulatory compliance obligations starting September 18, 2026. Previously offered as guidance, these concepts are not new, but how they are enforced is. The two rules are now legally binding, significantly increasing enforceability for Financial Services Providers (FSPs) regulated by CIMA.

Key Takeaways

  • The Rules take effect September 18, 2026, just 60 days after publication.
  • CIMA converted existing AML/CFT/CPF/TFS guidance into binding law. Noncompliance can result in direct fines or penalties.
  • The Rules apply to all CIMA-regulated or supervised FSPs, including registered investment funds.
  • Sanction screening and independent audit requirements introduce concrete operational changes for most FSPs, including registered investment funds.
  • FSP’s should begin performing gap assessments now.

What Are the New CIMA Rules?

The Rule on Effective Compliance Program for the Prevention and Detection of Money Laundering, Terrorist Financing, and Proliferation Financing for Financial Services Providers

The Rule, also known as the AML/CFT/CPF rule, establishes a minimum requirement for financial services providers compliance programs to help anti-money laundering (AML), counter terrorist financing (CTF), and counter-proliferation financing (CPF) efforts. All CIMA-regulated or supervised FSPs must abide by the new rules, even when outsourcing a function to a third-party.

The Rule on Compliance with Financial Sanctions and Targeted Financial Sanctions

As a complementary rule to the AML/CFT/CPF Rule, this rule outlines how CIMA-regulated FSPs should comply with financial sanctions and targeted financial sanctions. This rule supports an effective, proportionate, risk-based framework that enables FSPs to better identify, assess, manage, and mitigate financial or sanctions-related risks.

What Is Actually Changing?

Much of what is required is already familiar to FSPs, but the legal landscape is now changing. The new rules make compliance binding so that CIMA can enforce legal or financial penalties for noncompliance. Ultimately, organizations or providers that didn't put any weight behind the recommendations now need to treat the same content as a fixed requirement.

What Are the New Independent Audit Requirements?

The Rules also formalize how FSPs should demonstrate compliance effectiveness beyond program documentation alone, making independent audits crucial.

Key independent audit expectations include:

  • Independent audits are mandatory.
  • CIMA will not accept compliance audits from internal audit teams for more than two consecutive audit cycles. Afterward, the next audit must come from an external source.
  • FSPs should send audit reports to CIMA on a timely basis, in accordance with the timeline outlined by the Authority.
  • It's the FSP’s responsibility to address audit deficiencies within a responsible timeframe to mitigate the risk. Outsourcing the audit or any function does not shift the ultimate responsibility away from the FSP.

How Does the Rule Impact Sanction Screenings?

The Sanctions Rule strengthens screening obligations, making it imperative for organizations to implement proactive screening processes. Screenings should happen continuously, and connected persons (applicants, service providers, controllers, signatories, owners, etc.) should be screened at onboarding and on an ongoing basis. Furthermore, when a sanctions list is updated, organizations should re-screen even existing customers to maintain proper due diligence. This will be one of the biggest operational changes for FSPs.

What FSPs Should Be Doing Now to Prepare

Organizations that fail to comply with the rules are subject to fines and penalties. Ahead of the effective date, FPSs should follow the outlined steps to find compliance.

  • Perform gap assessments to compare current compliance programs against the new rules
  • Review outsourcing or vendor contracts to make sure data is accessible by CIMA
  • Update and formalize training plans
  • Check screening processes to verify that processes can respond within hours of a sanctions update
  • Confirm the audit function is staying up-to-date with external cycles and implementing protocols for filing reports with the CIMA

How EisnerAmper Helps You Find Compliance

FSPs should treat this as an opportunity to formalize governance, tighten screening infrastructure, and confirm that audit and training functions can meet the new cadence and independence requirements. The organizations best positioned for the effective date are the ones already underway with a structured gap assessment rather than a last-minute review.

EisnerAmper Cayman Islands works with FSPs to assess current compliance programs against the new CIMA Rules and identify gaps in governance, screening, and audit structure. Interested in building your own path toward compliance? Contact our team below.

This article was prepared with AI assistance and edited and enhanced by EisnerAmper professionals for accuracy and completeness. All technical content, analysis, and recommendations reflect the knowledge of our team.

Contact EisnerAmper

Ready to take the next step? Share your information and we’ll reach out to discuss how we can help.


Receive the latest business insights, analysis, and perspectives from EisnerAmper professionals.