Today (18 September 2026), CIMA’s new AML and sanctions Rules come into effect. In conversations I have been having over the past few weeks, much of the attention has understandably focused on what funds and their service providers need to do. For fund boards, however, the more fundamental question is this: if a fund delegates most of its day-to-day compliance work, how does the board know that the arrangements are actually working?
The Rules cover compliance programmes addressing money laundering, terrorist financing and proliferation financing, alongside financial sanctions. Much of the substance will be familiar, as the Rules largely place expectations previously contained in CIMA’s Guidance Notes on a binding footing. Why is CIMA doing this? One important driver is to give CIMA a clearer basis for taking enforcement action where regulated entities fail to comply. This brings renewed attention to how fund boards oversee their compliance arrangements and demonstrate that oversight in practice.
Who is responsible?
A fund might have an administrator handling investor due diligence, an investment manager responsible for investment activity and external AML officers overseeing compliance and reporting. Each appointment serves a purpose, but the board still needs to understand how those responsibilities fit together. Under CIMA’s Compliance Programme Rule, reliance on third parties does not remove the fund’s ultimate responsibility for compliance.
Funds can still appoint third-party service providers, but they need to assess those providers, document the arrangements and supervise what is being done. What have they actually agreed to do? Are they applying Cayman requirements, or standards that meet them? Can the fund and its AML officers obtain the information they need? Where a task falls between the administrator’s engagement and the investment manager’s responsibilities, who picks it up?
Sanctions screening is a useful example. A board should ask who covers the investment side as well as investors, and how the arrangements respond to changes in applicable sanctions lists. Those questions matter where the investment manager operates outside Cayman: the board needs to understand how the fund’s Cayman obligations are being met across its delegated activities.
What information does the board need?
CIMA’s FAQs place clear emphasis on boards reviewing reports, understanding risks and challenging management appropriately. They also call for evidence of that oversight through minutes, decisions and follow-up on deficiencies.
For me, the practical implication is that the quality of reporting matters. A report confirming that policies exist offers limited help if it does not explain outstanding issues or changes in the fund’s risk profile. Directors should be able to understand what needs attention, who is dealing with it and whether an issue raised at the last meeting has actually been resolved.
The fund’s business risk assessment provides an important starting point. It should reflect the fund’s own activities and exposures, informing the controls it needs and how they are reviewed. A material change in investment strategy or geographic exposure should prompt consideration of whether the existing arrangements remain appropriate.
Independent AML audits provide another test. An administrator’s audit report may be relevant, but the fund needs sufficient evidence about the effectiveness of its own compliance programme. The board therefore needs to understand what the audit covers and whether any gaps remain. This is a particularly useful question for funds that outsource substantially all their operations.
Building the arrangements from the outset
For an existing fund, the changes provide a timely reason to review how the board works with its providers. For a new fund, I would argue that these questions belong in the formation process, while responsibilities and engagement terms are being agreed. Leaving them until after launch makes it easier for assumptions about who does what to go untested.
This is particularly relevant to my role with Altura Governance. Altura provides both independent directorship and specialist AML officer services, two roles that are distinct but can make complementary contributions. An independent director can help the board question the arrangements and follow through on concerns, while the AML compliance officer brings focused expertise and oversight of the programme. One is not a substitute for the other, and their respective responsibilities, reporting lines, access to information and independence need proper consideration.
The response should remain proportionate to the fund’s risks. The useful outcome is a board that can explain how its fund’s compliance arrangements work, identify where they need attention and show what it has done about it. That is the governance conversation I think these changes should encourage.