Who can perform an AML audit in the Cayman Islands?

Internal audit, external auditors or independent consultants can all perform an AML audit, but only if they are genuinely independent. Here is how CIMA's AML Rule and FAQs define who qualifies.

By AML Cayman Ltd. · · 6 min read

What the Rule says

Rule 12.2(b) of CIMA's Rule on an Effective Compliance Programme requires the audit to be "carried out by suitably qualified persons who are independent and separate from those involved in the design, implementation, or operation of the policies, procedures, systems, and controls under audit, and who are free from any conflict of interest that could impair their objective judgment".

That sentence contains three tests:

  1. Suitably qualified. The auditor needs the knowledge and experience to assess an AML/CFT/CPF and sanctions programme for your type of business.
  2. Separate from the programme. The auditor must not have been involved in designing, implementing or operating the controls being audited.
  3. Free from conflicts. No relationship or interest that could impair their objective judgment.

Who CIMA says can do it

CIMA's FAQ 40 lists who may conduct an AML audit:

  • internal audit functions;
  • external auditors;
  • independent consultants; or
  • other suitably qualified and competent independent parties.

In every case, "the auditor must be independent of the AML/CFT/CPF/TFS function and activities being audited and must not be involved in the operation, management or oversight of the Compliance Programme". FAQ 41 adds that independence means being "free from actual or perceived conflicts of interest" and "not responsible for the design, operation, management or oversight of the Compliance Programme".

Note that "external auditors" here does not mean the audit has to be done by your financial statement auditor, or that an AML audit is a financial statement audit. It is a separate review of your compliance programme.

Who cannot do it

Your AML officers

CIMA is explicit. The AMLCO, MLRO and DMLRO "form part of the Compliance Programme and therefore cannot independently audit activities for which they have responsibility", whether those roles are performed in-house or outsourced (FAQ 39). An outsourced AML officer provider cannot audit the programme it runs.

Whoever designed or wrote the programme

Because Rule 12.2(b) excludes anyone involved in design, a consultant who drafted your AML manual, built your risk assessment methodology or designed your screening process is not independent of those controls. If you have used a consultant to rewrite your programme for the 2026 Rules, plan for a different party to audit it.

People who operate or oversee the controls

Staff or service providers who carry out the CDD, screening or monitoring being tested, and managers who oversee them, are not separate from the controls. This matters for small firms, where the same few people often wear several hats.

Internal audit: allowed, with limits

An internal audit function can perform the AML audit if it meets the independence tests. But Rule 12.3 caps internal audits at two consecutive cycles, after which the next audit must be carried out by an external service provider. CIMA's reasoning is to mitigate familiarity, self-review and loss of objectivity (FAQ 47).

Footnote 7 to Rule 12.3 defines "internally" as any individual or unit that is employed by, engaged under contract by, or otherwise forms part of the entity's organisational structure and is subject to its direction, control or oversight. Group internal audit teams and contracted individuals embedded in your structure may therefore count as internal.

Can you rely on your administrator's audit?

For funds this is the key question. CIMA says a regulated entity may rely on a service provider's AML audit only "where the audit adequately assesses all elements of the regulated entity's AML Compliance Programme", including testing specific to that entity's own programme and controls. An audit of the provider's general framework is not sufficient (FAQ 46). A service-provider-level internal audit or a population-based review, on its own, will not give sufficient assurance for an individual fund (FAQ 43). See our page on AML audits for investment funds.

Documenting independence

Independence has to be shown, not assumed. Under Rule 12.2(c), the entity must give CIMA, on request, "the documentation of the independence of any person who performed the audit … including the basis on which such independence was determined". Good practice is to get:

  • a written independence confirmation from the auditor before the engagement starts;
  • disclosure of any other services the auditor provides to the entity, its AML officers or its service providers, with an explanation of why they do not impair independence;
  • an independence statement in the final report;
  • evidence of the auditor's qualifications and relevant experience.

A quick checklist

QuestionIf the answer is "yes"
Does the proposed auditor act as your AMLCO, MLRO or DMLRO?Not independent (FAQ 39)
Did they design, write or implement your AML programme or its key controls?Not independent (Rule 12.2(b); FAQ 41)
Do they operate, manage or oversee any part of the programme?Not independent (FAQ 40)
Are they internal, and have the last two audits also been internal?The next audit must be external (Rule 12.3)
Can they evidence relevant AML qualifications and experience?Required: "suitably qualified" (Rule 12.2(b))

Our approach

We do not audit entities where we act as AMLCO, MLRO, DMLRO or director, or where we designed the programme, and we document our independence for every engagement. Every member of our team holds ACAMS certification, provided by AML Cayman Ltd., and has at least ten years of relevant financial services and AML processing experience at senior levels. Read our independence standard.

This article is general information, not legal advice, and reflects the Rules and CIMA FAQs as at 30 September 2026.

Ready to scope your independent AML audit?

Tell us about your entity. We will come back with a proposed scope, timetable and quote. No obligation.