Shadow KYC · Oversight for Cayman fund boards

Shadow KYC.Independent testing of your administrator's KYC.

Your administrator runs the KYC on your investors. We test those files against your fund's AML policy and give your board its own evidence of oversight under CIMA's AML Rule.

The idea

You already run a shadow NAV. Shadow KYC applies the same control to AML.

Your administrator calculates the NAV. Your team reproduces it, investigates the breaks and shows the board and the auditor that someone supervised the delegate. You run that check because the accountability stayed with you.

AML has the same structure. Your administrator performs the KYC, and your board signs off on a service report the administrator wrote about its own work. Shadow KYC gives your board a second, independent view of the files.

Shadow NAV compared with shadow KYC
Shadow NAVShadow KYC
Delegated to the administratorNAV calculationInvestor onboarding and CDD
The independent check coversPositions, pricing, cash and feesVerification, ownership, screening and risk rating
The board receivesBreaks, tolerances and a resolution trailExceptions by category and age, each traced to a file

Why now

CIMA's AML Rule took effect on 18 September 2026.

The Rule binds CIMA-registered mutual funds and private funds. Your fund may rely on its administrator, and it keeps ultimate responsibility for the work (s.5.3).

  • s.10.4

    On request, your fund gives CIMA “timely and sufficient evidence” that the functions it relies on comply.

    AML Rule

  • s.10.7

    Funds now carry binding outsourcing duties, from due diligence on each provider to an agreement that sets out both sides' obligations.

    AML Rule

  • FAQ 25

    CIMA expects ongoing monitoring of your providers and periodic testing of the work you outsource.

    CIMA FAQs

  • FAQ 43

    An audit that leans on a service-provider-level review, without evidence on your fund, “would not provide sufficient assurance”.

    CIMA FAQs

Read our guide to the CIMA AML Rule

The gap

Three layers of AML evidence. Your administrator can produce two.

  1. Layer 01

    Investor CDD records

    The execution layer. The administrator collects documents, screens investors and rates their risk.

    Produced byYour administrator, as delegate

  2. Layer 02

    The administrator's own assurance

    SOC report and group audit. The auditors conclude on the administrator's controls across all its clients, with no finding specific to your fund.

    Produced byYour administrator

  3. Layer 03

    Your oversight of the delegate

    Fund-level evidence that you tested the work. A delegate reporting on itself cannot supply this layer.

    Produced byYour board, through shadow KYC

CIMA's Guidance Notes say a provider “shall not contract or transfer” its compliance obligations. Your administrator cannot produce layer three for you, because a report on its own work gives your board no independent view.

How it works

Your policy goes in. Your exceptions come back.

We test the full population of investor files against the standard your board adopted, and we report in days.

  1. 01

    We load your fund's AML policy

    Your policy, risk appetite, jurisdiction rules and thresholds. We test against the standard your board adopted, with no generic checklist in between.

  2. 02

    Your board instructs the file release

    The records belong to the fund, and CIMA expects you to have timely access to them. We accept redacted copies wherever we can identify an exception without personal data.

  3. 03

    We test the full population

    Hundreds or thousands of files, each tested against your policy. If you prefer a sample, we fix the selection rule before requesting files: all PEP and high-risk investors, all onboarded in the last twelve months, and a random draw from the rest.

  4. 04

    Exceptions come back by category and age

    Each exception carries its file reference, so you can trace it to source and put it to the administrator.

  5. 05

    Your board adopts the pack

    Findings, severity, the Rule provision each one touches, and a remediation plan with owners and dates, written for the minutes.

  6. 06

    We run it again

    We re-test at the frequency your risk assessment sets, so your oversight runs as a standing control.

Scope

Eight tests on each investor file.

Each test runs against your policy. Where your policy is silent, we flag the gap and leave the standard to your board.

  • Identity and verification

    Completeness against your policy, document validity, and certification where your policy requires it.

  • Beneficial ownership

    Traced to your threshold, with evidence for each link in the ownership chain.

  • Source of funds and wealth

    Present where your risk rating calls for it, and backed by documents.

  • Screening

    Proof of screening against the right lists, a recorded disposition for each hit, and re-screening after sanctions list updates.

  • Risk rating

    Applied to each investor, with a rationale a reviewer can follow.

  • Periodic refresh

    Due dates set and met, with overdue reviews aged.

  • Maker-checker

    Evidence that a second person reviewed the file before approval.

  • Record retention

    Complete, retrievable and held for at least five years after the relationship ends (s.10.6.1).

Output

Your board receives a pack it can minute.

  • An exception rate per category across the tested population, aged, as a number a director can record.
  • A file reference behind each finding, so you can put it to the administrator and track the fix.
  • Each finding mapped to the Rule provision it touches.
  • A remediation plan with owners and dates.
  • A documented record of your fund's monitoring and testing of its delegate, ready for CIMA on request.
  • A standing record your AML auditor can test against.
Shadow KYC report · Q3 2026Sample

Meridian Growth Partners III

412 investor files · 412 tested

CategoryExceptionsRateOldest
Identity and verification61.5%212 days
Beneficial ownership112.7%340 days
Source of funds and wealth92.2%188 days
Screening30.7%41 days
Risk rating143.4%263 days
Periodic refresh235.6%402 days

Illustrative figures. Each exception opens to its file reference.

Questions

Questions boards ask us.

Our full guide to the Rule covers scope, outsourcing, notification and the AML audit.

Read the CIMA AML Rule guide

What is shadow KYC?

Shadow KYC is an independent, parallel review of the investor KYC files your fund administrator maintains. We test the files against your fund’s own AML policy and give the board exceptions it can act on. The name comes from shadow NAV, where a manager reproduces the administrator’s NAV to supervise it.

Does the CIMA AML Rule require shadow KYC?

The Rule does not use the term. It requires your fund to remain satisfied that the functions it relies on comply, and to give CIMA evidence of that on request (s.5.3, s.10.4). CIMA’s FAQ 25 expects ongoing monitoring and periodic testing of outsourced activities. Shadow KYC produces that evidence at fund level.

Is shadow KYC the same as the independent AML audit?

No. Section 12 of the Rule requires an independent audit of your whole compliance programme. Shadow KYC is the board’s ongoing monitoring of the administrator’s file work. CIMA’s FAQ 43 says an audit that relies on a service-provider-level review, without evidence on the individual fund, would not provide sufficient assurance. Your auditor can test against the shadow KYC record.

Can we get the files from our administrator?

Yes. The records belong to the fund, and CIMA’s FAQ 25 expects timely access to relevant information and records. The request comes from your board under the fund’s own engagement. We work alongside the administrator and never around it.

How long does it take?

Days. Our agents test the files at machine speed, and qualified reviewers check each exception. The timeline depends on how fast the administrator releases the files and how many exceptions need human review.

We are a fund administrator. Can we use this?

Yes, in two ways. You can run your own KYC case review on our platform, and you can offer your clients shadow KYC results as evidence of their oversight of you. Boards will ask their administrators for that evidence this year.

Does this apply to Hong Kong and Singapore managers?

The Rule binds the Cayman fund and any manager registered with CIMA. A manager licensed by the SFC or MAS alone sits outside its direct scope, but the fund it manages sits inside, and that fund’s board carries the oversight duty. This is our reading, not legal advice.

Next step

Find out what sits in your files.

Send us your AML policy and the size of your investor population. We reply with scope, timeline and a fixed price within one business day.

Scope a review

Or send the case list to [email protected]

Shadow KYC is a service of AgentKYZ, operated by Cortexa Research Lab Limited.

References to the AML Rule and the Sanctions Rule are to the CIMA rules in force from 18 September 2026. Section numbers point to the AML Rule and FAQ numbers to CIMA’s AML/CFT FAQs. This page is general information and not legal advice.