The Cayman FRA consent regime (DAML): a guide for financial services providers

Since 2 January 2025, a SAR may need to include a request for consent (a defence against money laundering, or DAML) from the Financial Reporting Authority before a transaction goes ahead. Here is how the regime works in practice while supporting regulations remain pending.

By AML Cayman Ltd. · · 7 min read

Check for updates: this summary reflects the Proceeds of Crime Act (POCA) amendments in force and the FRA's Industry Advisory on the DAML/consent regime (January 2025), as we understand them at 30 September 2026. Supporting regulations were anticipated but, to our knowledge, have not yet been issued. Always check the FRA's industry advisories for the latest position and take legal advice on specific cases.

What changed

On 2 January 2025, sections 11, 12 and 13 of the Proceeds of Crime (Amendment) Act, 2023 came into force. They introduced a formal consent regime. A person who files a suspicious activity report (SAR) and wishes to proceed with a transaction or activity that may involve criminal property can request the FRA's consent. Consent provides a defence to the principal money laundering offences in sections 133, 134 and 135 of POCA. This is commonly called a Defence Against Money Laundering (DAML) or consent request.

The existing SAR obligations in sections 136 and 137 of POCA are unchanged. The consent regime sits on top of them. For CIMA-regulated entities, CIMA's AML Rule also requires internal escalation of suspicions to the MLRO or DMLRO and external SARs to the FRA without delay (AML Rule 8.9, 12.6, 12.8).

How a consent request works

  1. Suspicion arises about a transaction or activity your entity is asked to carry out, such as a redemption, transfer or subscription.
  2. Internal report to the MLRO. The MLRO, or the DMLRO in the MLRO's absence, assesses it (AML Rule 8.9–8.10).
  3. SAR with a consent request. If the MLRO decides to seek consent, the SAR is filed with the FRA and must clearly show that it contains a DAML/consent request. The FRA has asked filers to say so in the subject line or the name of the SAR on its online reporting system.
  4. Notice period. The FRA has seven working days to respond, starting on the first working day after a valid, complete request is received and accepted. The FRA can treat an incomplete SAR as not yet valid.
  5. Outcome: consent granted, consent refused, or no response within the notice period, in which case consent is deemed to have been given.

Deemed consent

If the FRA does not refuse consent within the seven-working-day notice period, the filer is treated as having consent to proceed. This is an important safeguard for entities that need certainty on timing, for example when a redemption request is pending. It also makes the quality of the SAR critical. If the request is not clear, or the "reason for suspicion" does not properly describe the activity and why consent is sought, the notice period may not start when you expect.

Refusal and the moratorium period

If the FRA refuses consent within the notice period, a moratorium period of 30 calendar days begins. During the moratorium the transaction must not be carried out, because doing so could expose the filer to a money laundering offence. The moratorium gives law enforcement time to act, for example by seeking a restraint or freezing order. If no such action is taken by the end of the moratorium, the filer is treated as having consent.

The advisory anticipated that further detail, for example on extending the moratorium by court application, would be set out in regulations.

Key time periods
StagePeriodEffect
Notice period7 working days from the first working day after a valid requestNo refusal within the period: consent is deemed
Moratorium period30 calendar days after a refusalDo not proceed. Consent is treated as given at the end if no further action is taken

Tipping off

Waiting for consent creates a practical risk: a client or investor may ask why their transaction is delayed. It is an offence under section 139 of POCA to disclose that a SAR has been made or that an investigation is under way, where the disclosure is likely to prejudice an investigation. CIMA's AML Rule also prohibits disclosing to any customer or third party that a SAR has been or will be made (Rule 12.7). Prepare approved holding language for client-facing staff and service providers, and make sure your administrator's escalation process routes queries to the MLRO.

What AML officers should do now

  • Update SAR procedures to cover when to seek consent, how to mark a DAML request, and who decides.
  • Build the notice period and moratorium into operational processes such as redemption and payment workflows, with a way to hold a transaction pending consent.
  • Agree with your administrator and other service providers how they escalate to your MLRO and how holds are applied.
  • Keep a SAR and consent register, recording dates submitted, accepted, and when the notice and moratorium periods expire. AML Rule 8.5 requires records of SARs.
  • Train the MLRO, the DMLRO and relevant staff on the regime and on tipping off (AML Rule 11.5).
  • Watch for the regulations and any updated FRA guidance, and revise procedures when they arrive.

How this links to your AML audit

SAR escalation and reporting procedures are on CIMA's list of areas to consider when scoping an AML audit (FAQ 37). Our independent AML compliance programme audit tests whether suspicions are escalated, assessed and reported properly. That includes how consent requests, notice periods and holds are managed in practice. We can also include the consent regime in AML officer training.

This article is general information, not legal advice. It summarises the position as we understand it at 30 September 2026. The FRA's advisory and any regulations issued since take precedence.

Ready to scope your independent AML audit?

Tell us about your entity. We will come back with a proposed scope, timetable and quote. No obligation.