1. CIMA’s Revised Auditor Approval Policy: What Insurance Licensees Need to Know
The Cayman Islands Monetary Authority (“CIMA”) has issued a comprehensive new Regulatory Policy on the Approval of an Auditor for a Regulated Entity, set to take effect on 1 January 2027 (“Revised Policy”). The Revised Policy replaces the existing framework, originally issued in May 2002 and last revised in October 2003. The changes introduce expanded criteria, greater formality, and heightened expectations around auditor qualifications.
The principal changes are:
Physical Presence and Local Licensing
The Revised Policy introduces a significant shift towards local substance and oversight.
A key change is the introduction of the requirement for approved auditors to maintain a physical presence and suitable place of business in the Cayman Islands, supported by adequate human, technological, intellectual and other resources. Importantly, this does not require all audit work to be performed in the Islands or solely by the Approved Auditor. However, the Approved Auditor must issue the audit report and, before doing so, satisfy itself that the applicable accounting standards and auditing requirements have been met.
Additionally, the Revised Policy replaces the former reliance on broadly recognised international accounting qualifications with mandatory local requirements: firms must be registered with CIIPA as public practice firms, while engagement partners must be licensed as practitioner members of CIIPA and remain in good standing.
Enhanced Quality Management Standards
The original policy set out general quality assurance expectations, including concurring partner reviews and internal quality control reviews. The Revised Policy introduces a clearer benchmark: when assessing a firm’s quality management and assurance systems, CIMA will consider the requirements of the International Standards on Quality Management (ISQM 1 and ISQM 2) issued by the International Auditing and Assurance Standards Board. Firms are also now expected to establish quality objectives for obtaining, developing, maintaining and assigning resources promptly to support effective audit performance.
Expanded Independence and Ethical Standards Framework
While the original policy referenced the IFAC Code of Ethics on independence, the Revised Policy provides a far more detailed framework. It sets out specific categories of independence threats — self-interest, self-review, advocacy, familiarity, and intimidation — and requires firms to adopt the full IESBA International Code of Ethics for Professional Accountants. A new standalone section on ethical standards and conduct requires firms to ensure that personnel, network firms, and service providers all understand and fulfil relevant ethical requirements.
Reporting Obligations and Notification Requirements
The Revised Policy restates auditors’ statutory obligations to notify CIMA. For example, section 20(1) of the Insurance Act, 2010 requires an auditor to notify CIMA immediately in writing if it obtains information or suspects that a licensee cannot meet its obligations, is acting fraudulently or is failing to comply with applicable law. This was not previously reflected in policy.
Additionally, the Revised Policy introduces a direct obligation on auditors to formally document significant deficiencies and material weaknesses or other internal control observations identified during audit engagement and communicate them in writing to management and otherwise provide copies upon request by CIMA. While an indirect mechanism for this already exists — section 9(1)(a) of the Insurance Act requires insurers to submit, with audited financial statements, management letters to CIMA (which are the typical vehicle through which auditors communicate deficiencies and internal control observations), and the Internal Controls Rule requires regulated entities to report deficiencies internally — the Revised Policy frames this as a standalone duty on the auditor rather than the regulated entity.
Formal Approval and Withdrawal Processes
The Revised Policy establishes a structured approval process requiring a formal written request, supporting documentation via a prescribed application form, and payment of applicable fees. Separate procedures now govern amendments to approval conditions and voluntary withdrawal. These processes replace the existing, more informal framework.
What This Means for Insurance Licensees
The Revised Policy takes effect on 1 January 2027. Auditors approved before this date will retain their approved status without the need for re-evaluation, if they remain in compliance with all ongoing requirements, including continuing education, ethical standards, and other relevant provisions outlined in the Revised Policy. Licensees should therefore engage with their auditors now to confirm that they will be able to meet the enhanced requirements, particularly those relating to CIIPA licensing, physical presence and quality management.
2. Thematic Review of Reinsurance Companies (June 2026)
In June 2026, CIMA published its Thematic Review of Reinsurance Companies, presenting its findings following a supervisory review of selected Class B(iii) and Class D regulated reinsurance entities conducted between mid-2025 and the first quarter of 2026. The review assessed compliance with the Insurance Act, applicable regulations, rules and statements of guidance across four thematic areas: corporate governance, stress testing, cash flow testing, and capital and collateral adequacy management.
Corporate governance deficiencies were the most prevalent, accounting for 68% of all identified weaknesses, with the principal concerns being inadequate sub-committee governance and Board oversight, poor documentation and lack of oversight over outsourced service providers, insufficient segregation of duties, and the lack of effective internal audit functions. Other findings concerned stress testing (14%) and cash flow testing (9%), including a lack of independent or peer review of testing frameworks and outputs. Capital and collateral adequacy management accounted for a further 9%, where the Authority identified omissions of capital and collateral adequacy from internal audit coverage, and unresolved internal audit findings.
Regulated entities should use the review as an opportunity to assess whether corporate governance arrangements are robust and properly documented, including sub-committee governance, Board oversight, outsourcing arrangements and segregation of duties, and the effectiveness of the internal audit function. They should also ensure that stress testing is clearly evidenced, related frameworks and outputs are independently reviewed, and capital and collateral adequacy are covered by internal audit, with any findings addressed promptly.
The Authority expects regulated entities to maintain policies, procedures, systems and controls that are appropriate, effective and proportionate to the nature, scale and complexity of their business, in line with evolving risks, business changes and the applicable regulatory environment.
Conyers regularly advises reinsurance clients on regulatory and compliance matters and can help entities strengthen their processes, procedures and operations in line with CIMA’s expectations.
3. Cayman Beneficial Ownership Regime — Key Statistics from the First 14 Months
New data from the Cayman Islands Registrar reveals very low demand for access to beneficial ownership information under the Beneficial Ownership Legitimate Interest Access (“LIA”) framework. (which permits access to journalists, researchers, civil society organisations and business counterparties, subject to criteria)
Under the LIA framework certain members of the public (including journalists, researchers, civil society organisations and business counterparties) can request access to the beneficial ownership information in relation to a specific Cayman entity if they can demonstrate a legitimate interest in that information for the purposes of forestalling money laundering and terrorist financing.
As of 7 May 2026:
- There were only 12 beneficial ownership access applications under the LIA framework in 14 months.
- Most of these applications were made by journalists (5), followed by civil society organisations (3), academic researchers (2), and business counterparties (2).
- A majority of beneficial ownership access requests were approved (7 applications were approved, 3 were refused, 1 was withdrawn, and 1 was under active consideration as of May 2026).
- There had been 24 beneficial ownership access restriction applications filed. A separate application is required in respect of each beneficial owner and on a per entity basis, which makes the figure appear higher.
- 60% of access restriction applications were refused, demonstrating rigorous application of the serious harm threshold.
The low volume of beneficial ownership access requests is particularly interesting given the continued pressure from the UK government on the Cayman Islands and other British Overseas Territories to move toward fully public beneficial ownership registers. These recent statistics show that actual demand for this information under the LIA framework is remarkably limited. The lack of demand for this data provides an alternative perspective in the ongoing debate about whether the push for fully open registers is proportionate to real-world need and the balance against privacy and data protection rights.
Conyers was involved in several of the successful access restrictions applications on behalf of clients. If you are considering an application, please get in touch with your usual Conyers regulatory contact to discuss.
For the latest Cayman Islands regulatory updates from our team, please refer to the most recent Regulatory & Risk Advisory Outlook, available here.
























