CIMA AML Rule · Rule 12 audits · Grand Cayman

Independent AML audits for CIMA-regulated entities

We carry out independent AML compliance programme audits for CIMA-regulated funds and financial services providers. The audits are risk-based, test your own entity's controls, and end in a clear report you can file with CIMA.

  • AML/CFT/CPF and sanctions in one audit
  • Documented independence
  • Entity-specific testing
  • Based at Landmark Square, Grand Cayman
  • Senior, experienced AML team
  • Quote-based, no obligation
  • We audit only where we are independent

What the new CIMA AML Rule expects from your audit

CIMA's Rule on an Effective Compliance Programme came into force on 18 September 2026. Rule 12 sets out how regulated entities must demonstrate that their AML programme works.

Rule 12.1

Review and test the whole programme

Independent audit procedures must test whether your compliance programme is adequate, effective and aligned with the AML Regulations and CIMA's requirements, including prescribed returns.

Rule 12.2(b)–(c)

Independent, qualified people

The audit must be done by suitably qualified people who are separate from the design and operation of the controls and free of conflicts. CIMA can ask for the basis of that independence.

Rule 12.2(a), (d)

Risk-based frequency, report to CIMA

Your risk assessment sets how often you audit. The report is filed with CIMA as soon as practically possible after the audit is completed.

Independent audits for every type of CIMA-regulated entity

Each audit is scoped to your structure, outsourcing model and risk profile.

Investment funds

Fund-specific testing for mutual and private funds, including how your administrator's controls actually operate for your fund. This is the evidence CIMA says a service-provider-level report alone does not give.

AML audits for funds

SIBs, fund managers and other FSPs

Audits for securities investment businesses, managers and other regulated entities with their own staff, clients and systems, covering training, employee screening and monitoring.

AML audits for SIBs and managers

Sanctions compliance

Screening, re-screening "without delay", freezing, CRF reporting and TFS training tested against the CIMA Sanctions Rule, on its own or within your AML audit.

Sanctions compliance audit

How an audit with us runs

  1. Scoping call and conflict check

    We confirm we are independent of your programme and agree a risk-based scope.

  2. Engagement and document request

    A clear engagement letter, independence confirmation and a tailored document list.

  3. Fieldwork and testing

    Walkthroughs, interviews and sample testing of files, screening, escalations and training records.

  4. Findings and management responses

    Draft findings rated by risk, discussed with you before anything is final.

  5. Final report for filing with CIMA

    An audit report and remediation plan your board can approve and track.

See the full audit process

Why independence is our starting point

CIMA says an AMLCO, MLRO or DMLRO cannot audit a programme they are responsible for, and that an auditor must not be involved in operating, managing or overseeing it.

  • We do not audit entities where we act as AML officer or director.
  • We do not audit programmes we designed or wrote.
  • Every report comes with a written statement of the basis of our independence.

Read our independence standard

Experienced, Cayman-based people

Every member of our team holds ACAMS certification, provided by AML Cayman Ltd., and has at least ten years of relevant financial services and AML processing experience at senior levels.

We work from Landmark Square on Seven Mile Beach and understand how Cayman funds, administrators and boards operate in practice.

Other services

CIMA Rules gap analysis

Map your policies to both 2026 Rules and get a prioritised remediation plan.

Gap analysis

AML officers

AMLCO, MLRO and DMLRO appointments for CIMA-regulated entities.

AML officer services

Training

AML/CFT/CPF and sanctions training for boards and staff, with records.

AML training

Inspection readiness

A focused review before a CIMA inspection or desk-based review.

Readiness review

Common questions about AML audits

Is the independent AML audit a new requirement?

No. CIMA says the requirement to carry out effective, risk-based AML audits already exists under the Anti-Money Laundering Regulations. Rule 12 of the new AML Rule adds clarity on what CIMA expects and how effectiveness should be demonstrated (CIMA FAQ 32).

How often should an AML audit be carried out?

There is no fixed frequency. You decide and document it based on your risk profile (AML Rule 12.2(a)). CIMA gives examples: roughly every two years for higher-risk entities, every three for medium and every four for low risk. Annual audits are not mandated (CIMA FAQs 35 and 38).

Who can perform an AML audit?

CIMA lists internal audit functions, external auditors, independent consultants, or other suitably qualified and competent independent parties. Whoever does it must be independent of the AML/CFT/CPF/TFS function and must not be involved in operating, managing or overseeing the programme (AML Rule 12.2(b); CIMA FAQs 40–41).

Our fund outsources everything. Does it still need an AML audit?

Yes. CIMA says a regulated fund must still have an AML audit even if all or substantially all of its operations are outsourced. Scope and frequency are set using a risk-based approach (CIMA FAQ 42).

Do you audit entities where you are the AML officer or a director?

No. We do not audit an entity where we act as its AMLCO, MLRO, DMLRO or director, or where we designed or wrote its compliance programme. See our independence standard.

More answers on our FAQ page. Sources: CIMA AML Rule and CIMA FAQs.

Ready to scope your independent AML audit?

Tell us about your entity. We will come back with a proposed scope, timetable and quote. No obligation.