Listen to this article
0:00 / 0:00

Key Takeaways

  • AML and KYC obligations in the Cayman Islands apply to relevant financial business and designated non-financial businesses, which can include foreign-owned entities.
  • Compliance follows a risk-based approach built on customer due diligence, enhanced checks for PEPs and sanctions, and ongoing monitoring of business relationships.
  • Businesses in scope must appoint AML officers such as an AMLCO, MLRO, and DMLRO, keep required records, and report suspicious activity to the Financial Reporting Authority.
  • Failing to meet these duties can lead to enforcement and penalties under the supervision of CIMA and the relevant authorities.

Anti-money laundering and know-your-customer rules in the Cayman Islands are mandatory for any business that conducts "relevant financial business," and they apply whether or not that business holds a licence from a regulator. The regime rests on the Proceeds of Crime Act and the Anti-Money Laundering Regulations, supervised principally by the Cayman Islands Monetary Authority. These rules reach far beyond banks: fund managers, fund administrators, virtual asset service providers, and several non-financial professions all fall within scope.

This article explains what AML/KYC compliance in the Cayman Islands actually requires of a foreign-owned entity, from customer due diligence and appointed officers through to suspicious activity reporting and the penalties for getting it wrong. It is written for non-resident owners, investors, and their advisers who control or operate a Cayman entity and must keep its AML obligations current.

The backbone of the regime is the Proceeds of Crime Act (POCA), which defines the money laundering offences, sitting alongside the Anti-Money Laundering Regulations (AMLRs), which set out the practical obligations every financial service provider must meet. The regulations were substantively amended on 19 April 2024, and the core offences of concealing, arrangements, and acquisition, use, and possession took effect in their amended form on 2 January 2025.

Three further statutes complete the picture. The Terrorism Act criminalises terrorist financing, the Proliferation Financing (Prohibition) Act addresses proliferation financing, and the Virtual Asset (Service Providers) Act extends the framework to firms dealing in virtual assets such as exchange, transfer, and custody.

CIMA's authority to monitor compliance comes from the Monetary Authority Act. Its detailed expectations are published in the CIMA Guidance Notes (February 2024), which interpret how the regulations should be applied in practice.

Guidance Notes carry weight

The Guidance Notes are not directly enforceable, but courts take non-compliance into account when deciding whether you breached the Act or the AMLRs, and CIMA weighs it when deciding whether to use its enforcement powers.

Cayman's standing has improved markedly. The jurisdiction was removed from the FATF grey list in October 2023 after completing all 63 recommended actions, the United Kingdom delisted it on 5 December 2023, and the European Union followed on 7 February 2024.

Cayman

Company Incorporation in Cayman Islands

Set up your company in Cayman Islands with Expanship handling registration end to end.

The obligation attaches to anyone conducting "relevant financial business" as defined in the Proceeds of Crime Act. The reach here is wide and catches firms that may not think of themselves as regulated.

  • Regulated mutual funds, meaning all funds registered with the Authority
  • Investment managers licensed by or registered with the regulator, including those holding a SIBL Exemption
  • Mutual fund administrators
  • Virtual asset service providers, including unregulated FinTech companies

A point that surprises many foreign owners: an entity must comply whether or not it is licensed or registered with the regulator. Providing a virtual asset service alone brings a firm within scope.

A second tier of obligation falls on Designated Non-Financial Businesses and Professions (DNFBPs). These include real estate brokers, dealers in precious metals and stones, company formation agents, and independent directors. All real estate agents and dealers in precious metals or stones operating in or from the islands must register as DNFBPs and, since April 2024, must notify their supervisor of any change to their AML risk assessment.

Two different thresholds

The beneficial owner trigger under the AML Regulations is 10% ownership or control, while the threshold under the Beneficial Ownership Transparency Act is 25%. Do not assume one figure covers both.

One concession applies to CIMA-regulated funds: although they remain subject to the AMLRs, they are exempt from completing and filing the annual AML surveys.

Supervision is split across several bodies according to sector. CIMA oversees financial institutions and trust and corporate service providers, while three other authorities cover the professions.

AML supervisory authorities by sector
Supervised sector Supervisory authority
Financial institutions, trust/corporate service providers CIMA
Lawyers Legal Services Supervisory Authority (LSSA)
Accountants Cayman Islands Institute of Professional Accountants (CIIPA)
Real estate agents, dealers in precious metals and stones Department of Commerce and Investment (DCI)

Intelligence and investigation sit elsewhere. The Financial Reporting Authority (FRA) is the financial intelligence unit that receives suspicious activity reports, assesses them, and shares findings; the Royal Cayman Islands Police Service Financial Crime Unit investigates serious offences.

Regulated entities file through CIMA's REEFS portal, which also handles annual AML survey submissions. CIMA circulates those surveys in line with its reporting timeline, and both CIMA and the non-CIMA supervisors conduct periodic assessments of the firms they oversee.

Cayman

Ongoing Compliance in Cayman Islands

Keep your Cayman Islands entity compliant with filings, returns, and statutory obligations.

Every financial service provider must build its AML framework around a Risk-Based Approach (RBA). Rather than applying identical controls to every relationship, you identify, assess, and understand the money laundering, terrorist financing, and proliferation financing risks tied to your customers, products, services, transactions, and the countries you deal with.

The approach must be documented. Your policies, procedures, review results, and the actions you take in response all need to be recorded so that you can demonstrate compliance to your supervisor when asked.

CIMA regularly asks to see risk assessments during on-site inspections, and assessments must be kept current rather than completed once and shelved. The Grand Court has endorsed the RBA, recognising that firms are best placed to rate their own clients and apply measures tailored to the risk. Practical guidance on conducting these assessments appears in Part II of the CIMA Guidance Notes, and a 2023 update specifically addresses licensees onboarding customers through e-KYC and digital identity solutions.

Customer due diligence is the operational heart of KYC. Under Parts IV to VIII of the AML Regulations, you must identify and verify each customer, anyone acting on their behalf, and in certain cases the beneficial owners and their source of funds.

CDD is triggered in defined circumstances:

  1. When you establish a business relationship
  2. When you carry out a one-off transaction above CI$10,000 (roughly US$12,195), or any wire transfer
  3. Where you suspect money laundering or terrorist financing
  4. Where you doubt the veracity or adequacy of identification already held

The one-off transaction threshold was reduced to CI$10,000 to align with international standards, and the 2024 amendments cleaned up lingering references to the old CI$15,000 figure. The beneficial owner identification threshold under the AMLRs is 10% ownership or control.

For a natural person, verification means collecting identity documents such as a passport or photo identification together with proof of residential address, with copies certified by a suitable certifier. CIMA has confirmed that verification can be carried out by virtual means, including videoconferencing, digital ID platforms, and e-KYC technology, subject to certain caveats.

Risk drives the depth of checks. Lower-risk situations may permit Simplified Due Diligence, while higher-risk relationships demand Enhanced Due Diligence.

Cayman

Cayman Islands Incorporation Pricing

See transparent pricing to incorporate and maintain a company in Cayman Islands.

When a client or transaction presents elevated risk, standard checks are not enough. Enhanced due diligence applies to dealings with Politically Exposed Persons (PEPs) and clients from high-risk countries, and it requires you to verify the source of funds and wealth and to obtain senior management approval before proceeding.

Cayman's treatment of PEPs follows the European model. Beneficial owners should be analysed to determine whether they are a PEP or closely connected to one, and where they are, EDD must confirm that their funds are legitimate. The AML compliance officer is required to keep both a PEP register and a high-risk customer and transaction register.

Sanctions screening sits within the same higher-risk territory. UN and EU sanctions take effect in the islands through Overseas Orders in Council, and the 2024 amendments expanded EDD to add specific sanctions screening requirements in the context of proliferation financing risk.

The consequences of holding designated funds are immediate. Under the Proliferation Financing (Prohibition) Act, anyone holding funds or economic resources owned or controlled by a designated person must freeze them at once and report the freezing action to the FRA as soon as reasonably practicable.

Penalties under the Proliferation Financing (Prohibition) Act
Failure Penalty on summary conviction
Failure to freeze (Section 2B) US$60,976
Failure to report freezing (Section 2C) US$12,195

Monitoring under the regime is transaction-driven, not merely customer-driven. The distinction matters: a firm that watches only its direct customers, and not the activity flowing by, at, or through it, exposes itself to AML deficiencies. The duty is set out in Regulations 5 and 12 of the AMLRs.

Financial service providers and virtual asset service providers must keep monitoring customers and counterparties to detect changes in the KYC information already gathered. PEP transactions in particular call for continuous scrutiny so that anomalies are caught, investigated, and reported where necessary.

AML policies, including monitoring protocols, should be reviewed at least annually, and more often if the business model, products, client base, or applicable law changes. A September 2025 CIMA circular on virtual asset supervision flagged recurring weaknesses across the sector, including thin transaction scrutiny, failure to apply EDD, and poor escalation of compliance problems, all of which point to where supervisory attention is heading.

Records must be kept for at least five years from the date of the last transaction, and they must be ready for examination by regulators on request. This covers customer identification information, transaction history, and the supporting documentation behind both.

Beyond the basic transaction trail, firms must retain KYC files, training logs, and records of SAR decisions, all kept current and accessible. The compliance officer must also maintain the high-risk customer and transaction register and the PEP register.

Two changes are worth noting for a foreign owner reviewing existing systems. Following the 2024 amendments, proliferation financing considerations must now be built into record-keeping, regulatory reporting, and suspicious activity reporting. And where verification is done through digital ID systems or e-KYC, those records must be retained and produced to supervisors on the same terms as any other.

Every financial service provider must appoint three officers, each with a distinct function:

  • Anti-Money Laundering Compliance Officer (AMLCO) — oversees the compliance framework, serves as regulatory point of contact, maintains the PEP and high-risk registers, and reports to management at least annually
  • Money Laundering Reporting Officer (MLRO) — receives and assesses internal suspicious activity reports
  • Deputy Money Laundering Reporting Officer (DMLRO) — discharges the MLRO's functions in their absence

All three must be filled by individuals with suitable experience and genuine independence. The MLRO and DMLRO cannot be the same person, though a firm may have one individual serve as both AMLCO and MLRO if that person is competent, understands the separate duties, and has time to do both jobs properly.

The AMLCO's brief includes responding promptly to authority requests, reviewing and maintaining the AML/CFT/CPF systems, and ensuring at least annual audits of the programme. Outsourcing of certain AML tasks is permitted, but not where confidentiality, secrecy, privacy, or data protection rules would block the firm's access to data without delay.

Officers face personal exposure

Individuals who act as AML officers can be held personally liable for failing to carry out their functions or for certain illegal activity. This is not a role to fill nominally.

The reporting duties carry criminal teeth. Under Section 136 of POCA, you commit the Failure to Disclose Offence if, having formed reasonable grounds to know or suspect criminal conduct in the course of business, you do not report it to the nominated officer or the FRA. Section 139 creates the separate Tipping Off Offence, committed where you make a disclosure likely to prejudice an investigation.

Firms need two layers of process: internal procedures by which staff report to the MLRO or DMLRO, and external procedures by which those officers, after investigation, report to the FRA. A report must be filed for any suspicious activity, regardless of transaction value, asset type, or the parties involved. Filings go through the FRA's online AMLive Portal or by secure email.

A significant change took effect on 2 January 2025. Beyond filing a report, you must now obtain prior consent (Defence Against Money Laundering, or DAML) from the FRA before proceeding with a suspicious transaction in order to have a defence against money laundering offences. A DAML SAR must be flagged as such, and the "Reason for Suspicion" field must explain why consent is sought and give full details of the activity.

DAML consent timeline
Stage Period
FRA notice period before deemed consent 7 working days
Moratorium period if consent is refused 30 calendar days from the first working day after refusal notice

Filing a report, and from 2 January 2025 receiving a DAML, can serve as a defence to the offences under the AML/CFT/CPF legislation. The protection is real, but only if the process is followed before the transaction proceeds.

Two enforcement tracks run in parallel: criminal prosecution under POCA and administrative fines imposed by CIMA. Both can reach a foreign-owned entity and, in some cases, its officers personally.

On the criminal side, the Act sets out five primary offences, from concealing or transferring criminal property through to tipping off. Penalties run from a fine of around US$6,000 or two years' imprisonment on summary conviction to fourteen years' imprisonment or an unlimited fine on conviction on indictment. Failure to disclose a suspicion to the FRA carries up to two years and a CI$4,000 fine summarily, or up to five years on indictment.

CIMA's administrative fines regime, in force since December 2017 under the Monetary Authority Act, grades breaches into three tiers.

CIMA administrative fine categories (per breach)
Category Individual Body corporate
Minor KYD 5,000 (approx. USD 6,000) fixed KYD 5,000 (approx. USD 6,000) fixed
Serious up to KYD 50,000 (approx. USD 61,000) up to KYD 100,000 (approx. USD 122,000)
Very serious up to KYD 100,000 (approx. USD 122,000) up to KYD 1,000,000 (approx. USD 1.2 million)

A minor breach can attract continuing fines of CI$5,000 until the running total reaches CI$20,000. Following the 2024 amendments, where a breach was committed with the consent, connivance, or neglect of a director, manager, or secretary, fines can now be levied on those individuals personally. For DNFBPs, the maximum very serious fine, imposed by the DCI, CIIPA, or LSSA, is US$250,000, against up to US$1 million for CIMA-regulated entities.

CIMA operates under time limits: it cannot impose a fine more than two years after becoming aware of a breach, or six months for a minor breach. Fines are published in full, including names, the provisions breached, and the supporting facts, and a fined party has 30 days to apply to the Grand Court for leave to appeal a discretionary fine.

Enforcement is not theoretical. Cayman National Bank was fined KYD 1.3 million in 2019 and Banca del Gottardo KYD 1 million in 2016, and since February 2021 CIMA has issued penalties ranging from tens of thousands to over USD 5 million, to firms of every size. With the FATF 5th Round Mutual Evaluation in view, inspections and enforcement are expected to intensify, with particular attention to virtual asset risk.

AML/KYC is the heaviest ongoing compliance burden most Cayman entities carry, and it bites regardless of whether your firm is licensed, with officers, monitoring, reporting, and record-keeping all expected to function from day one. The DAML consent requirement and personal liability for officers raise the stakes well beyond a paperwork exercise.

The practical step is to confirm whether your entity conducts "relevant financial business" at all, because that single answer determines the entire weight of obligation that follows. If it does, appoint qualified officers and document a current risk assessment before regulators ask to see one.

Expanship supports foreign-owned entities in meeting their Cayman AML/KYC duties, from drafting risk assessments and CDD procedures to arranging suitably qualified AML officers and managing the supervisory relationship. The same team handles the broader compliance needs of an offshore entity, so a single point of contact covers formation through to ongoing obligations.

  • Company incorporation and structuring
  • Registered agent and registered office services
  • Ongoing compliance and filing management
  • Accounting and bookkeeping support
  • Economic substance and beneficial ownership assistance
  • Introductions to banking providers

To discuss your AML/KYC obligations and wider compliance needs, contact Expanship Cayman Islands.

Yes. An entity must comply with the AML Regulations if it conducts "relevant financial business," whether or not it is registered with or licensed by the regulator, which can include unregulated FinTech companies providing virtual asset services.

Customer due diligence is required for any one-off transaction above CI$10,000, roughly US$12,195, and for any wire transfer regardless of value. The threshold was reduced to this level to align with international standards, replacing the former CI$15,000 figure.

You must appoint an Anti-Money Laundering Compliance Officer, a Money Laundering Reporting Officer, and a Deputy MLRO, each suitably experienced and independent. The MLRO and DMLRO cannot be the same person, although one individual may serve as both AMLCO and MLRO if competent and able to do both roles properly.

Beyond filing a suspicious activity report, you must now obtain prior consent, known as Defence Against Money Laundering or DAML, from the Financial Reporting Authority before proceeding with a suspicious transaction in order to keep a defence against money laundering offences. The FRA has seven working days to respond, after which consent is deemed.

Records of transactions, customer identification, and supporting documentation must be retained for at least five years from the date of the last transaction. They must remain readily available for examination by the supervisory authority on request.

CIMA can impose administrative fines of up to KYD 1,000,000, approximately USD 1.2 million, on a body corporate for a very serious breach, per breach. Criminal conviction on indictment under the Proceeds of Crime Act can reach fourteen years' imprisonment or an unlimited fine, and individual officers can now be fined personally where a breach involved their consent, connivance, or neglect.