Sanctions compliance audit under the CIMA Sanctions Rule

An independent review of your financial sanctions and targeted financial sanctions (TFS) controls against CIMA's Rule on Compliance with Financial Sanctions and TFS, in force since 18 September 2026. Available on its own or as part of your AML audit.

Who the Sanctions Rule applies to

The Sanctions Rule applies to every Regulated Person that CIMA supervises under the Regulatory Acts (Rule 6.3). CIMA's FAQs confirm this is so whether or not the entity carries on relevant financial business (FAQ 52). It also requires sanctions compliance to be an integral part of the overall AML/CFT/CPF compliance programme (Rule 7.1).

What we test

ControlRuleWhat we look for
Sanctions risk assessment7.2–7.3Sanctions considered in risk assessments; no "low" geographic rating for countries subject to relevant UK, UN or US sanctions
Screening scope7.4Applicants, customers, beneficial owners, transactions, service providers and connected persons all screened
Re-screening7.5, 7.11All customers re-screened on list updates, "without delay", whatever their CDD risk rating
Lists and local designations7.10, 7.13.1–7.13.2Lists maintained, including the UK Sanctions List and local designations by the Governor
Alert handling and false positives7.19Potential matches verified against other identifiers, with documented rationale (7.9)
Freezing7.17–7.18Ability to freeze without delay and without prior notice; no funds made available to designated persons
Reporting to the FRA7.7, 7.13.3–7.13.4, 7.21Compliance Reporting Form (CRF) procedures, including frozen assets and attempted transactions
Unfreezing and licensing7.22–7.23Procedures for delisting, unfreezing and licence applications to the Governor, with a copy to the FRA
Training7.20Regular staff training on identifying designated persons and frozen assets, and the steps to follow

What "without delay" means in practice

The Sanctions Rule defines "without delay" as, ideally, within a matter of hours of a designation by the UN Security Council or its relevant Sanctions Committee (Rule 2.1.23). We test how quickly list updates reach your screening tool, how alerts are cleared, and whether outsourced screening providers meet that standard for your entity. Where screening is outsourced, CIMA expects the audit to review the provider's procedures, its testing and the results relevant to your entity (FAQ 45).

For a fuller overview of the Rule, read our guide to the CIMA Sanctions Rule.

Frequently asked questions

Does the Sanctions Rule apply to entities that do not carry on relevant financial business?

Yes. CIMA says the Sanctions Rule applies to all Regulated Persons it supervises, whether or not they conduct relevant financial business (Sanctions Rule 6.3; CIMA FAQ 52).

What does "without delay" mean?

The Sanctions Rule defines it as, ideally, within a matter of hours of a designation by the UN Security Council or its relevant Sanctions Committee (Sanctions Rule 2.1.23). It applies to re-screening after list updates and to freezing.

Who do we report a match to?

To the Financial Reporting Authority, using the Compliance Reporting Form (CRF), without delay (Sanctions Rule 7.7 and 7.13.3–7.13.4). The FRA can be contacted at financialsanctions@gov.ky.

Can the sanctions audit be combined with the AML audit?

Yes. The Sanctions Rule requires sanctions compliance to be part of your overall AML/CFT/CPF programme (Rule 7.1), so most clients include it in one audit. We can also review it on its own.

Test your sanctions controls

Add a sanctions review to your AML audit or commission it on its own. Tell us about your screening set-up for a quote.