The CIMA AML Rule 2026: a practical guide
CIMA's Rule on an Effective Compliance Programme for the Prevention and Detection of Money Laundering, Terrorist Financing and Proliferation Financing for Financial Services Providers came into force on 18 September 2026. Here is what it requires, section by section.
Who the Rule applies to
The Rule applies to financial services providers (FSPs) that conduct "relevant financial business" under the Proceeds of Crime Act and are regulated by CIMA under the Regulatory Acts. That includes branches, subsidiaries, affiliates and other members of a CIMA-regulated financial group, whatever their business model or outsourcing arrangements (CIMA FAQ 6). It supplements the Anti-Money Laundering Regulations (AMLRs), which prevail if there is any inconsistency (FAQ 8).
CIMA describes the framework as risk-based: the Rule sets minimum requirements but allows flexibility based on proportionality (FAQ 2). Many provisions strengthen existing AMLR obligations rather than creating new ones (FAQ 4).
1. Governance (section 7)
The governing body must set a clear governance framework that defines roles and responsibilities, promotes accountability, and designates an AMLCO, MLRO and DMLRO who are natural persons operating at no lower than management level (7.1). The compliance programme must include, at a minimum, a designated AMLCO, written policies and procedures, a risk management framework with periodic risk assessment, an ongoing training programme and plan, and ongoing evaluation of effectiveness (7.3).
CIMA expects boards to evidence oversight through minutes, reports, documented decisions and remediation tracking (FAQ 7).
2. AML officers (section 8)
- The AMLCO must be of good repute, suitably qualified and experienced, with evidence available to CIMA on request (8.1).
- The AMLCO must have authority, direct access to senior management and the board, independence from the business functions they oversee, sufficient resources, and knowledge of the business and its risks (8.2).
- The AMLCO keeps the board informed and provides periodic reports at least annually (8.8), and makes sure records are kept for declined business, PEPs, competent authority requests, SARs, transaction alerts and sanctions monitoring (8.5).
- The MLRO receives and assesses internal SARs and makes external SARs to the FRA (8.9). A DMLRO, also at managerial level, acts in the MLRO's absence (8.10).
The AMLCO may be employed or engaged through an outsourcing arrangement (FAQ 14), and one person may hold multiple roles where conflicts are managed (FAQ 15). See our AML officer services.
3. Risk-based approach (section 9)
FSPs must identify, assess, understand and mitigate their ML/TF/PF risks, considering customers, countries, products, services, transactions and delivery channels. They must document the assessment and keep it up to date (9.1–9.8). CIMA explains what the documentation should contain in FAQ 17. Group risk assessments can be used, provided the Cayman-specific risks are addressed (FAQ 20).
4. Policies, procedures and controls (section 10)
Policies must be approved by the governing body, and procedures by senior management or the board (10.2). At a minimum they must cover risk assessment, CDD and ongoing monitoring (including EDD for higher-risk customers such as PEPs), record keeping, outsourcing, notifying CIMA of material outsourced compliance functions, suspicious activity detection and reporting (including the travel rule where applicable), and sanctions compliance (10.3). Section 10 also covers reliance on third parties (10.4), detailed CDD requirements (10.5), records kept for at least five years (10.6) and outsourcing due diligence and agreements (10.7).
5. Training and employee screening (section 11)
FSPs must have a documented training programme and plan, delivered on an ongoing basis and at least annually (11.1, 11.5–11.7). Recipients include client-facing staff, those involved in transactions, and those responsible for the programme, including senior management, IT staff, the board and internal auditors (11.8). Training records must show dates, attendees and topics (11.14). Employees must be screened at recruitment and on an ongoing basis (11.3–11.4). See our AML training.
6. Demonstrating effectiveness: the independent audit (section 12)
This is the section most regulated entities are asking about. The Rule requires independent audit procedures that review and test the programme's adequacy, effectiveness and alignment with legal and regulatory requirements (12.1). The audit must be:
- carried out at a risk-based frequency (12.2(a));
- performed by suitably qualified persons independent of the design, implementation and operation of the controls (12.2(b));
- supported by documentation of the auditor's independence, which CIMA can request (12.2(c)); and
- filed with CIMA as soon as practically possible after completion (12.2(d)).
Internal audits are allowed for no more than two consecutive cycles (12.3). Deficiencies must be remediated within appropriate timeframes (12.4), and the FSP remains responsible even if the audit is outsourced (12.5). Section 12 also sets out SAR duties: internal escalation to the MLRO or DMLRO, no tipping off, and filing with the FRA without delay (12.6–12.8).
CIMA's FAQs add important context. The audit requirement is not new (FAQ 32). There is no universal first-filing date (FAQ 33), and no audit is needed merely because the Rule took effect (FAQ 34). Annual audits are not mandated (FAQ 35). There is no prescribed report format (FAQ 36). Read more about our independent AML compliance programme audit.
7. Enforcement (section 13)
The Rule has the force of law, and breaches fall under CIMA's Enforcement Manual (13.1–13.2). CIMA has said it does not intend to take a blanket enforcement approach from the effective date, and that the administrative fines framework for breaches of the Rule is not yet in effect (FAQ 4). The Rule forms part of CIMA's risk-based supervisory toolkit, used through inspections, desk-based reviews and thematic reviews (FAQs 3–4).
Practical next steps
- Map your policies and procedures to the Rule. A gap analysis is the quickest way.
- Confirm your AMLCO, MLRO and DMLRO meet the management-level and fitness requirements.
- Refresh your risk assessment and document your audit frequency based on it.
- Check your training plan and records against section 11.
- Plan your next independent audit and how you will document the auditor's independence.
Ready to scope your independent AML audit?
Tell us about your entity. We will come back with a proposed scope, timetable and quote. No obligation.