On 20 July 2026 CIMA introduced 2 new Rules, effective 18 September. Most of what they contain has been in the Guidance Notes for years. The change is that it now sits in a Rule, which is enforceable, and the Guidance Notes ran to 245 pages while the Rules run to a few dozen.
4 things are genuinely new.
The audit is independent, and it is filed. The audit of your Compliance Program must be performed by suitably qualified persons independent and separate from anyone involved in designing, implementing or operating the controls under audit. The report goes to CIMA after completion. Most entities have never filed one.
Internal audit has a cap. It can be used for no more than two consecutive cycles. Every third audit goes external. Worth mapping your audit history now, because it is a budget line most entities have not planned for.
The training plan is a new artifact. Most entities hold training records. Very few hold a forward-looking plan setting out recipients, topics and materials, delivery method and frequency, with the rationale where training differs by role. It is a one-page document, and it is an easy thing for an inspector to ask for and not receive.
Screening moves from periodic to event driven. Under the Sanctions Rule you must rescreen all customers when a sanctions list is updated, regardless of their due diligence risk classification. For most entities that is a systems change rather than a policy change, which is why it wants the longest runway.
One thing that has not changed, despite what you may be told: the Rule does not mandate an annual audit. Frequency is risk-based, and the reasoning belongs in your risk assessment. Entities defaulting to twelve months out of caution may be buying work they cannot justify. Entities stretching the interval with nothing written down are exposed.
LeapBridge provides independent AML Compliance Program audits to CIMA-regulated entities in the Cayman Islands.
