Independent AML audits for Cayman investment funds

Most Cayman funds outsource almost everything, but each regulated fund still needs its own independent AML audit. CIMA is clear that the audit must produce fund-specific evidence. We design our fund audits around that expectation.

What CIMA expects from a fund's AML audit

CIMA's FAQs on the new AML Rule set out four points that shape every fund audit:

  • Outsourcing does not remove the requirement. A regulated fund must undertake an AML audit under Regulation 5(a)(ix) of the AML Regulations even if all, or substantially all, of its operations are outsourced (FAQ 42).
  • The evidence must be fund-specific. The audit should obtain enough appropriate evidence to conclude on the design and operating effectiveness of the individual fund's compliance programme. Relying only on a service-provider-level internal audit or a population-based review does not give sufficient assurance (FAQ 43).
  • Outsourced functions are tested as they operate for your fund. A service provider audit may give comfort about the provider's own framework, but on its own it is not enough. The audit should include testing of how the outsourced arrangements work in practice for your fund (FAQ 45).
  • An administrator's audit can be relied on only if it covers your programme. It must include testing that is specific to your fund's own programme and controls (FAQ 46).

What we test for a fund

CIMA lists what a fund audit should consider: investor onboarding controls, ongoing due diligence, investment objective and policies, third-party relationships and outsourcing, internal reporting, the training programme, record keeping and the application of a risk-based approach (FAQ 43). Our work programme covers each one:

AreaHow we test it for your fund
GovernanceBoard-approved AML policies, AMLCO reports to the board, minutes showing challenge and remediation tracking
AML officersDesignation of the AMLCO, MLRO and DMLRO, fitness evidence, access to information, and how the roles operate in practice
Fund risk assessmentWhether the fund's own risk assessment reflects its strategy, investor base, distribution channels and geography
Investor due diligenceA risk-based sample of the fund's investor files held by the administrator: CDD, EDD, PEPs, beneficial ownership and periodic reviews
Sanctions screeningThe administrator's screening procedures, re-screening on list updates, and results relevant to your fund's investors and counterparties
Monitoring and SARsAlerts and escalations relating to the fund, escalation to the fund's MLRO, and FRA reporting
Outsourcing oversightDue diligence on providers, the service agreement, CIMA access to records, notification of material outsourcing, and the board's oversight of performance
Training and recordsTraining delivered to the board and relevant parties, and record retention and retrieval

Working with your administrator

We keep the burden on the administrator proportionate. Where the administrator already has relevant testing and results, we review them and focus our own sample on your fund. We agree the document request and timing with your administrator contact at the start, so fieldwork runs smoothly.

Fund platforms and umbrella structures: where several funds share the same administrator and controls, we can plan a coordinated engagement that shares common procedures while still testing and reporting on each fund individually, as CIMA expects.

How often should a fund be audited?

There is no fixed frequency. Your fund's risk assessment should determine it (AML Rule 12.2(a)). CIMA gives examples of roughly every two years for higher-risk entities, three for medium and four for low risk (FAQ 38). At least one audit in every three cycles must be external (AML Rule 12.3). Read more in our article on AML audit frequency.

Frequently asked questions

Our fund outsources everything. Does it still need an AML audit?

Yes. CIMA says a regulated fund must still have an AML audit even if all or substantially all of its operations are outsourced. Scope and frequency are set using a risk-based approach (CIMA FAQ 42).

Can we rely on our administrator's AML audit?

Only if it covers all elements of your fund's own programme with fund-specific testing. An audit of the service provider's general framework, or a population-based review, is not enough on its own (CIMA FAQs 43, 45 and 46).

Can the audit use sampling?

Yes. CIMA accepts risk-based sampling if it is proportionate and gives enough coverage to assess effectiveness. Outsourced functions must be tested as they operate for your entity (CIMA FAQ 45).

Our administrator performs our investor due diligence. What do you test?

We look at how the administrator's onboarding, screening and monitoring actually operate for your fund: its procedures, the testing it performed and the results relevant to your fund, plus a sample of your fund's own investor files. CIMA uses sanctions screening by an outsourced provider as its example of this approach (CIMA FAQ 45).

Need a fund-specific AML audit?

Tell us about your fund or platform. We will propose a scope that meets CIMA's fund-specific expectations, with a quote.