Independent AML audits for CIMA-regulated entities
We carry out independent AML compliance programme audits for CIMA-regulated funds and financial services providers. The audits are risk-based, test your own entity's controls, and end in a clear report you can file with CIMA.
- AML/CFT/CPF and sanctions in one audit
- Documented independence
- Entity-specific testing
- Based at Landmark Square, Grand Cayman
- Senior, experienced AML team
- Quote-based, no obligation
- We audit only where we are independent
What the new CIMA AML Rule expects from your audit
CIMA's Rule on an Effective Compliance Programme came into force on 18 September 2026. Rule 12 sets out how regulated entities must demonstrate that their AML programme works.
Rule 12.1
Review and test the whole programme
Independent audit procedures must test whether your compliance programme is adequate, effective and aligned with the AML Regulations and CIMA's requirements, including prescribed returns.
Rule 12.2(b)–(c)
Independent, qualified people
The audit must be done by suitably qualified people who are separate from the design and operation of the controls and free of conflicts. CIMA can ask for the basis of that independence.
Rule 12.2(a), (d)
Risk-based frequency, report to CIMA
Your risk assessment sets how often you audit. The report is filed with CIMA as soon as practically possible after the audit is completed.
Independent audits for every type of CIMA-regulated entity
Each audit is scoped to your structure, outsourcing model and risk profile.
Investment funds
Fund-specific testing for mutual and private funds, including how your administrator's controls actually operate for your fund. This is the evidence CIMA says a service-provider-level report alone does not give.
AML audits for fundsSIBs, fund managers and other FSPs
Audits for securities investment businesses, managers and other regulated entities with their own staff, clients and systems, covering training, employee screening and monitoring.
AML audits for SIBs and managersSanctions compliance
Screening, re-screening "without delay", freezing, CRF reporting and TFS training tested against the CIMA Sanctions Rule, on its own or within your AML audit.
Sanctions compliance auditHow an audit with us runs
Scoping call and conflict check
We confirm we are independent of your programme and agree a risk-based scope.
Engagement and document request
A clear engagement letter, independence confirmation and a tailored document list.
Fieldwork and testing
Walkthroughs, interviews and sample testing of files, screening, escalations and training records.
Findings and management responses
Draft findings rated by risk, discussed with you before anything is final.
Final report for filing with CIMA
An audit report and remediation plan your board can approve and track.
Why independence is our starting point
CIMA says an AMLCO, MLRO or DMLRO cannot audit a programme they are responsible for, and that an auditor must not be involved in operating, managing or overseeing it.
- We do not audit entities where we act as AML officer or director.
- We do not audit programmes we designed or wrote.
- Every report comes with a written statement of the basis of our independence.
Experienced, Cayman-based people
Every member of our team holds ACAMS certification, provided by AML Cayman Ltd., and has at least ten years of relevant financial services and AML processing experience at senior levels.
We work from Landmark Square on Seven Mile Beach and understand how Cayman funds, administrators and boards operate in practice.
Other services
CIMA Rules gap analysis
Map your policies to both 2026 Rules and get a prioritised remediation plan.
Gap analysisCommon questions about AML audits
Is the independent AML audit a new requirement?
No. CIMA says the requirement to carry out effective, risk-based AML audits already exists under the Anti-Money Laundering Regulations. Rule 12 of the new AML Rule adds clarity on what CIMA expects and how effectiveness should be demonstrated (CIMA FAQ 32).
How often should an AML audit be carried out?
There is no fixed frequency. You decide and document it based on your risk profile (AML Rule 12.2(a)). CIMA gives examples: roughly every two years for higher-risk entities, every three for medium and every four for low risk. Annual audits are not mandated (CIMA FAQs 35 and 38).
Who can perform an AML audit?
CIMA lists internal audit functions, external auditors, independent consultants, or other suitably qualified and competent independent parties. Whoever does it must be independent of the AML/CFT/CPF/TFS function and must not be involved in operating, managing or overseeing the programme (AML Rule 12.2(b); CIMA FAQs 40–41).
Our fund outsources everything. Does it still need an AML audit?
Yes. CIMA says a regulated fund must still have an AML audit even if all or substantially all of its operations are outsourced. Scope and frequency are set using a risk-based approach (CIMA FAQ 42).
Do you audit entities where you are the AML officer or a director?
No. We do not audit an entity where we act as its AMLCO, MLRO, DMLRO or director, or where we designed or wrote its compliance programme. See our independence standard.
More answers on our FAQ page. Sources: CIMA AML Rule and CIMA FAQs.
Ready to scope your independent AML audit?
Tell us about your entity. We will come back with a proposed scope, timetable and quote. No obligation.