持牌 TCSP TC006716 香港灣仔軒尼詩道 253-261 號依時商業大廈 8 樓 803 室 週一至週五 09:00–17:00
香港牌照申請

AML CTF Compliance Documents in HK

Quick Answer

AML CTF compliance documents must reflect licensed activities, incorporating customer due diligence, record-keeping, and reporting obligations under Hong Kong regulations.

What Are AML CTF Compliance Documents and Why Do They Matter for Licensed Businesses in Hong Kong?

For any company operating under a Hong Kong licence—whether as a trust or company service provider (TCSP), a financial institution, or a designated non-financial business and profession (DNFBP)—anti-money laundering and counter-terrorist financing (AML/CTF) compliance documents form the operational backbone of regulatory adherence. These documents are not merely bureaucratic checklists; they are the practical tools that demonstrate a firm’s commitment to detecting, preventing, and reporting suspicious activities in line with the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615) and sector-specific guidelines issued by authorities such as the Hong Kong Monetary Authority (HKMA), the Securities and Futures Commission (SFC), and the Customs and Excise Department.

Defining the Core AML CTF Document Set

At a minimum, a licensed business must maintain a written AML/CTF policy, a risk assessment framework, customer due diligence (CDD) procedures, ongoing monitoring protocols, record-keeping systems, and a suspicious transaction reporting mechanism. These documents must be tailored to the firm’s specific risk profile, client base, and service offerings. For instance, a TCSP licensed under Cap. 615 must align its documents with the Guideline on Anti-Money Laundering and Counter-Terrorist Financing for Trust or Company Service Providers, while a bank follows the HKMA’s Guideline on Anti-Money Laundering and Counter-Financing of Terrorism. The practical scope extends beyond creation: documents must be regularly reviewed, updated to reflect regulatory changes, and embedded into daily operations to ensure staff can implement them effectively.

Who Should Prioritise AML/CTF Compliance Documents for Licensed Operations in Hong Kong?

Any business holding or applying for a licence in Hong Kong’s regulated sectors must treat AML/CTF compliance documents as a foundational requirement. This includes financial institutions supervised by the Hong Kong Monetary Authority, securities and futures intermediaries licensed by the Securities and Futures Commission, insurance intermediaries regulated by the Insurance Authority, and designated non-financial businesses and professions (DNFBPs) such as estate agents, legal professionals, and trust or company service providers. The Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615) imposes statutory customer due diligence and record-keeping duties on these entities, making tailored documentation essential to demonstrate adherence during inspections or licence renewals.

Key Planning Decisions for Your AML/CTF Document Framework

When structuring your compliance documents, start by mapping your specific licence conditions to the relevant regulatory guidance. For example, SFC-licensed corporations should align their policies with the SFC AML/CFT Guidelines, while estate agents must follow the EAA Licensing Requirements and the Customs and Excise Department’s DNFBP AML/CFT Guidelines. A critical early decision is whether to adopt a standalone AML/CTF manual or integrate controls into broader operational procedures—this depends on your business scale and complexity. Additionally, consider how you will maintain the Significant Controllers Register under the Companies Ordinance (Cap. 622) alongside client identification records, as these intersect with beneficial ownership transparency obligations. Planning should also address ongoing monitoring mechanisms and staff training schedules, which are recurring themes in supervisory expectations.

Preparing Your AML/CTF Compliance Documents: Information to Gather Before You Start

Before drafting or updating your AML/CTF compliance documents for a licensed business in Hong Kong, it is essential to gather foundational information that will shape your framework. This preparation stage ensures that your documentation aligns with both your specific business activities and the regulatory expectations under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615).

Identify Your Business’s Regulatory Profile

Start by clearly defining the nature of your licensed activities. Different sectors—such as banking, securities, insurance, or designated non-financial businesses and professions (DNFBPs)—are subject to distinct supervisory authorities and AML/CTF guidelines. For instance, the Hong Kong Monetary Authority (HKMA) provides specific guidance for banks and stored value facilities, while the Securities and Futures Commission (SFC) issues its own AML/CTF guidelines for licensed intermediaries. Review the relevant regulatory framework from your primary supervisor to understand the exact document types required, such as risk assessments, policies, procedures, and training records.

Map Your Customer Base and Delivery Channels

Collect data on your typical customer profiles, geographic exposure, and the products or services you offer. This information is critical for conducting a thorough business-wide risk assessment, which is a cornerstone of any AML/CTF compliance program. Consider whether you deal with high-risk jurisdictions, politically exposed persons (PEPs), or complex corporate structures. Also, document your customer onboarding channels—whether face-to-face, online, or through intermediaries—as these affect your customer due diligence (CDD) measures and the supporting documentation you must maintain.

Compile Existing Internal Policies and Controls

Gather all current internal policies related to client acceptance, transaction monitoring, record-keeping, and suspicious transaction reporting. If your business is part of a larger group, determine whether group-wide AML/CTF policies apply and how they interact with local requirements. This step helps identify gaps and ensures that your compliance documents are consistent and comprehensive. Additionally, review your data protection practices in light of the Personal Data (Privacy) Ordinance, as CDD processes involve handling sensitive personal information.

Step-by-Step Process for Aligning AML/CTF Compliance Documents with Licensed Operations

Aligning your AML/CTF compliance documents with your licensed business activities is a structured process that begins with a thorough risk assessment. Under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615), licensed entities must identify, assess, and understand their money laundering and terrorist financing risks. This involves mapping out your client base, delivery channels, and the jurisdictions you operate in. The Hong Kong Monetary Authority’s guidelines on commercial customer account opening stress the importance of documenting these risks to tailor your internal controls effectively. Once risks are identified, the next step is to draft or update your AML/CTF policies and procedures to address them specifically. These documents should cover customer due diligence (CDD), ongoing monitoring, record-keeping, and suspicious transaction reporting, as outlined by the Securities and Futures Commission’s AML/CTF guidelines. For instance, if your licensed business deals with high-risk jurisdictions, your policies must detail enhanced due diligence measures. After drafting, the documents must be approved by senior management and integrated into daily operations. Regular training for staff is essential to ensure they understand and can implement the procedures. Finally, an independent audit function should periodically review the compliance framework to ensure it remains effective and up-to-date with regulatory changes, such as those issued by the Customs and Excise Department for designated non-financial businesses and professions. This cyclical process ensures that your AML/CTF documents are not static but evolve with your business and the regulatory landscape.

AML/CTF Compliance Document Checklist for Licensed Businesses

Maintaining a robust set of AML/CTF compliance documents is not merely a regulatory formality—it is the operational backbone that demonstrates your firm’s commitment to preventing financial crime. For licensed businesses in Hong Kong, the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615) sets out clear expectations for record-keeping, risk assessment, and ongoing monitoring. Below is a practical checklist of essential document categories, each explained with its relevance to your licensed operations.

1. Customer Due Diligence (CDD) Records

CDD records form the foundation of your AML framework. These include identification documents (e.g., passports, business registration certificates), proof of address, and information on the customer’s business nature and ownership structure. For corporate clients, you must also maintain a Significant Controllers Register as required under the Companies Ordinance (Cap. 622), which helps identify ultimate beneficial owners. Proper CDD documentation enables your firm to verify customer identities, assess risk profiles, and detect potential red flags early. Without it, you risk facilitating illicit transactions and facing regulatory sanctions.

2. Risk Assessment Framework

A documented risk assessment methodology is critical for tailoring your AML measures to the specific threats your business faces. This should cover customer risk (e.g., politically exposed persons, high-risk jurisdictions), product/service risk, and delivery channel risk. The Hong Kong Monetary Authority and other regulators expect licensed entities to periodically review and update their risk assessments. By formalizing this process, you not only comply with supervisory expectations but also create a defensible audit trail that shows your firm’s proactive stance.

3. Suspicious Transaction Reporting (STR) Logs

Under Cap. 615, you are obligated to report suspicious transactions to the Joint Financial Intelligence Unit. Maintaining a confidential STR log—detailing the date, nature of suspicion, and supporting evidence—ensures consistency and accountability. These records are often reviewed during regulatory inspections and can protect your firm if a transaction is later questioned. A well-kept log also helps refine your detection systems over time.

4. Staff Training Materials and Attendance Records

AML/CTF training is a regulatory requirement for all relevant employees. Your compliance file should include training curricula, presentation slides, and signed attendance sheets. This demonstrates that your staff understands their obligations, from recognizing suspicious behavior to handling CDD updates. In the event of a compliance breach, documented training can mitigate liability by showing that the firm took reasonable steps to educate its workforce.

5. Independent Audit and Review Reports

Periodic independent audits of your AML/CTF program are essential for identifying gaps and ensuring continuous improvement. Retain all audit reports, management responses, and remediation plans. These documents provide evidence of your commitment to a dynamic compliance culture and are often requested by regulators during thematic examinations.

By systematically organizing these document categories, your licensed business can align with Hong Kong’s AML/CTF regime while building operational resilience. For tailored guidance on compiling your compliance dossier, consider a professional consultation.

Integrating AML/CTF Compliance Documents Across Licensed Business Operations

For licensed TCSPs, AML/CTF compliance documents must be woven into every stage of client engagement and internal control. A common scenario involves onboarding a corporate client incorporated in a jurisdiction with less stringent disclosure requirements, such as a BVI business company. Under the BVI Business Companies Act 2004, beneficial ownership information is not publicly filed, which heightens the risk of opaque structures. In such cases, the TCSP must apply enhanced due diligence (EDD) measures as outlined in the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615). This includes obtaining and verifying the identity of the ultimate beneficial owner, understanding the source of funds, and documenting the rationale for the business relationship. The compliance file should contain a completed EDD form, certified copies of constitutional documents, and a written assessment approved by the compliance officer.

Another decision point arises when handling client funds. If the TCSP facilitates property transactions, it may be subject to the Estate Agents Ordinance (Cap. 511) and guidance from the Estate Agents Authority. Compliance documents must demonstrate segregation of client money, proper record-keeping, and adherence to the relevant AML/CTF guidelines issued by the Customs and Excise Department for designated non-financial businesses and professions (DNFBPs). Regular independent audits of these procedures, with findings documented and reported to senior management, help ensure ongoing compliance and provide a defensible audit trail in the event of a regulatory inspection.

Common Mistakes, Risk Controls, and Practical Next Steps in AML/CTF Compliance Documentation

Even well-intentioned licensed businesses can fall into common pitfalls when preparing and maintaining AML/CTF compliance documents. One frequent mistake is treating the documentation as a one-time exercise rather than a living framework. Under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615), firms are expected to continuously update their risk assessments, policies, and procedures to reflect changes in their business, customer base, and emerging threats. Another error is generic or boilerplate documentation that does not reflect the specific risks of the licensee’s operations. For instance, a trust or company service provider (TCSP) should tailor its customer due diligence (CDD) measures to the types of entities it serves, such as those incorporated in jurisdictions with different transparency standards, as highlighted by the Companies Registry’s guidance on significant controllers registers.

Implementing Robust Risk Controls

Effective risk controls begin with a thorough and documented risk assessment that considers customer, product, delivery channel, and geographic risk factors. The Securities and Futures Commission’s AML/CFT guidelines emphasize the need for a risk-based approach, where enhanced due diligence (EDD) is applied to higher-risk situations, such as dealings with politically exposed persons (PEPs) or complex corporate structures. Licensees should also implement strong internal controls, including independent audit functions and regular staff training, to ensure that policies are not only documented but also effectively executed. The Hong Kong Monetary Authority’s guidance on corporate account opening illustrates how banks and other financial institutions integrate these controls into their onboarding processes, which can serve as a model for other licensed sectors.

Practical Next Steps for Compliance

To align AML/CTF documentation with licensed operations, businesses should first conduct a gap analysis against the requirements of their primary regulator—whether the SFC, IA, HKMA, or the Customs and Excise Department for DNFBPs. This analysis should be documented and lead to a remediation plan with clear timelines. Next, firms should ensure that their compliance manuals and related documents are accessible to all relevant staff and that version control is maintained. Finally, engaging with a professional compliance consultant can provide an objective review and help navigate complex areas such as cross-border entity structures, where understanding the interplay between Hong Kong’s Cap. 622 and overseas regulations like the BVI Business Companies Act or the Cayman Islands Companies Act is essential. Regular updates and independent audits will not only satisfy regulatory expectations but also protect the business from financial crime risks.

Aligning AML/CTF Compliance Documents with Your Licensed Business Operations

Integrating anti-money laundering and counter-terrorist financing (AML/CTF) compliance documents into daily operations is not merely a regulatory checkbox—it is a strategic necessity for licensed businesses in Hong Kong. As the regulatory landscape evolves toward 2026-06-05, firms must ensure their AML/CTF frameworks are robust, up-to-date, and tailored to their specific licensing requirements. The Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615) mandates that financial institutions and designated non-financial businesses and professions (DNFBPs) implement risk-based policies, procedures, and controls. For TCSP licensees, this means maintaining comprehensive records of customer due diligence (CDD), ongoing monitoring, and suspicious transaction reporting, all aligned with guidelines from regulators such as the Hong Kong Monetary Authority and the Securities and Futures Commission.

Key Compliance Documents for Licensed Entities

To effectively meet AML/CTF obligations, licensed businesses should maintain a suite of core documents. These include a written AML/CTF policy manual, CDD procedures, risk assessment frameworks, staff training records, and independent audit reports. The Companies Registry requires TCSP licensees to keep a significant controllers register under the Companies Ordinance (Cap. 622), which complements AML efforts by enhancing transparency of beneficial ownership. Additionally, sector-specific guidance—such as the Customs and Excise Department’s DNFBP AML/CTF Guidelines—provides practical steps for compliance. Regularly reviewing and updating these documents in light of regulatory changes ensures your business remains compliant and resilient against financial crime risks.

Frequently Asked Questions

Preparing Your AML/CTF Compliance Documentation for a Licensed Business

Key Evidence to Compile Before Engaging Professional Services

Before seeking external guidance on AML/CTF compliance documents for your licensed business in Hong Kong, it is prudent to gather foundational records. Under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615), licensed entities must maintain a risk assessment, customer due diligence files, and ongoing monitoring records. Start by collating your business registration certificate, company incorporation documents, and any existing policies on client identification. If your firm operates as a trust or company service provider (TCSP), ensure you have the licence details and records of significant controllers as required by the Companies Ordinance (Cap. 622). Having these materials organised will streamline the consultation process and help your advisor tailor the compliance framework to your specific licence type and risk profile.

FAQ

What are the essential AML/CTF documents for a TCSP licensee in Hong Kong?

A TCSP licensee should maintain an AML/CTF policy manual, customer due diligence procedures, risk assessment records, ongoing monitoring documentation, suspicious transaction reporting procedures, staff training records, and a significant controllers register as required by the Companies Ordinance.

How often should AML/CTF compliance documents be reviewed?

Compliance documents should be reviewed at least annually or whenever there are material changes to the business, regulatory updates, or identified deficiencies. Regular independent audits are also recommended to ensure effectiveness.

Do AML/CTF requirements apply to non-financial businesses in Hong Kong?

Yes, designated non-financial businesses and professions (DNFBPs), such as trust or company service providers, estate agents, and accountants, are subject to AML/CTF obligations under Cap. 615 and relevant guidelines from regulators like the Customs and Excise Department.

How can I ensure my CDD procedures meet regulatory expectations?

CDD procedures should be risk-based, include identification and verification of customers and beneficial owners, and involve ongoing monitoring. Aligning with guidelines from the HKMA, SFC, or other relevant regulators is essential.

What role does the significant controllers register play in AML compliance?

The significant controllers register, mandated by the Companies Ordinance, enhances transparency by identifying individuals with significant control over a company, thereby supporting AML efforts by making beneficial ownership information readily available to law enforcement and regulators.

Sources and Verification

This article is general information only and is not legal, tax, bank approval or licensing advice.

藥物進口批發牌照差別

本文探討藥物進口商牌照與批發牌照的差別,涵蓋申請條件、監管機構及合規要求。

香港牌照申請 EN

先拿一份報價,再決定要不要辦

告訴我們要辦的服務,我們在一個工作天內回覆可行方案、所需文件與費用區間。

  • +852 5119 0964 香港電話 · 週一至週五 09:00–17:00
  • 13590408182 中國內地電話
  • 灣仔辦公室 香港灣仔軒尼詩道 253-261 號依時商業大廈 8 樓 803 室
微信二維碼 微信號 W13590408182 大陸客戶可掃碼加微信