Lucy Frew
Partner
Cayman Islands
Oct 7, 2026

Key takeaways
CIMA is introducing AML desk-based reviews as part of its risk-based supervisory approach. The reviews are intended to strengthen supervisory oversight, support implementation of the AML Rule and Sanctions Rule, assess the effectiveness of compliance programmes and align with broader international AML and FATF expectations.
At an industry briefing on 30 September 2026, CIMA announced that it will commence desk-based AML reviews of regulated entities including investment funds.
Desk-based reviews are expected to commence in October. The desk-based review process will involve a letter sent to the regulated entity asking for documents such as a copy of the regulated entity's business plan (if applicable) and its risk assessment and risk assessment methodology. CIMA will send letters in tranches, applying a risk-based approach. Regulated entities will typically have five business days to provide the requested documentation. CIMA will assess the information provided, issue a summary report setting out any findings and take further steps if appropriate. CIMA indicated that repeat findings may be treated more seriously when determining whether escalation is appropriate.
Regulated entities including investment funds are already required to have documented risk assessments. Pursuant to the Anti-Money Laundering Regulations (AMLRs), the Guidance Notes on the Prevention and Detection of Money Laundering, Terrorist Financing and Proliferation Financing in the Cayman Islands, and the Rule on Effective Compliance Programme for the Prevention and Detection of Money Laundering, Terrorist Financing and Proliferation Financing for Financial Service Providers (AML Rule), a financial service provider (FSP) must conduct and document a risk assessment of its own exposure to money laundering, terrorism financing and proliferation financing risks. The risk assessment must address a number of statutory data points prescribed by the AMLRs.
To the extent that any FSP has not already documented its risk assessment (which in the case of investment funds must be at fund level, not manager or advisor level), this should be addressed now. Risk assessments which have been documented in the past should be reviewed to confirm that they remain up-to-date and appropriately address all matters required by the AMLRs.
Not only does the AML Rule and commencement of desk-based reviews make clear that having a documented risk assessment will be an area of focus for CIMA, but such risk assessment will be vital in underpinning any risk-based approach, particularly in determining the frequency of independent audits.
For example, if a CIMA Regulated FSP considers that independent audits should be carried out less frequently than annually, it will need to have documented the basis for such conclusion in its documented risk assessment. In practice, once a risk assessment has been completed, it will be relatively easy to keep up-to-date. Please click here if you would like details of our risk assessment tool.
While the content of an AML risk assessment will depend on an entity's business model and risk profile, each entity should ensure that the assessment considers its money laundering, terrorist financing and proliferation financing risks in relation to at least the following key risk areas:
• the entity's customers or investors
• the countries or geographic areas in which the entity and its customers or investors reside or operate
• products, services and transactions
• the entity's delivery channels (including any remote onboarding or technology solutions used)
Please see here for our advisory on the new AML Rule and new Rule on Compliance with Financial Sanctions and Targeted Financial Sanctions (Sanctions Rule) and here for our advisory with practical guidance for investment funds.
CIMA Regulated FSPs should ensure their risk assessments and methodologies are up-to-date and readily available ahead of the commencement of CIMA's desk-based reviews. In particular:
• any FSP that has not yet documented its risk assessment should do so
• for an investment fund, the risk assessment should address the risks of the fund itself, rather than relying solely on a manager or adviser-level assessment
• existing risk assessments should be reviewed to ensure they remain current and address all matters required by the AMLRs
Non-investment fund CIMA Regulated FSPs should ensure their business plans are up to date and readily available. If updates are required, consider with Cayman Islands counsel whether such updates are subject to prior approval from CIMA.
CIMA Regulated FSPs should review their Compliance Programmes and AML governance frameworks (meaning their entire framework of policies, procedures, controls, oversight and reporting mechanisms designed to ensure ongoing compliance with the Cayman Islands' anti-money laundering, countering the financing of terrorism and countering proliferation financing regime) to assess if they meet the requirements of the AML Rule and Sanctions Rule and make necessary changes.
CIMA Regulated FSPs should ensure the governance framework for their Compliance Programme is properly documented and readily available in the form of the relevant resolutions, agreements with service providers and policies and procedures.
• AML health checks
• independent AML audits
• fund-level risk assessment reviews
• compliance programme reviews
• sanctions framework assessments
• governance documentation reviews
Please click here if you would like details of our risk assessment tool and here to register for our AML and Sanctions Rule compliance checklist.
Authors
Partner/Cayman Islands
Partner/Cayman Islands
Key contacts
Partner
Cayman Islands
Senior Counsel
Cayman Islands
Global Head of AML Services
Cayman Islands