Key answer
A practical TCSP onboarding pack should do more than collect passport and company documents. It should create a traceable decision record: customer and beneficial-owner identity, ownership and control, authorised persons, purpose and intended nature, service requested, customer risk, PEP and sanctions screening, any EDD, approvals, outstanding items and the schedule for ongoing review. Forms should drive a real workflow and adapt to natural persons, legal persons and trusts.
The difference between collecting documents and performing CDD
Document collection is an input. CDD is the process of identifying the relevant persons, verifying them using reliable and independent information, understanding the relationship and assessing its ML/TF risk. A file can contain many documents and still fail to explain who ultimately controls the customer or why the proposed structure makes sense.
The Companies Registry Guideline identifies four central CDD measures: identify and verify the customer; identify and take reasonable measures to verify the beneficial owner and understand ownership and control; obtain information on purpose and intended nature; and identify, reasonably verify and confirm the authority of a person purporting to act for the customer.
A modular onboarding pack
| Module | What it should capture |
|---|---|
| Customer profile | Legal name, type, registration or identity details, contact, business and requested services |
| Ownership and control | Structure chart, intermediate entities, natural-person UBOs, control route and verification |
| Authorised persons | Identity, verification, role, authority evidence and permitted instructions |
| Purpose and expected activity | Reason for the relationship, services, expected jurisdictions, counterparties, funds or activity |
| Screening | PEP, sanctions and relevant searches, date, inputs, source, results and match disposition |
| Customer risk assessment | Customer, country, service/transaction and delivery-channel factors, overall rating and rationale |
| EDD | Higher-risk enquiries, source of wealth/funds, supporting evidence, enhanced monitoring and approvals |
| Approval and exceptions | Reviewer, approver, outstanding conditions, exception rationale and deadline |
| Ongoing review | Review frequency, trigger events, next date, record refresh and rescreening |
Beneficial ownership is a reasoning exercise
The form should lead staff through ownership layers to the natural person or persons who ultimately own or control the customer. Under the AMLO framework described in the Guideline, a corporation’s beneficial owner includes an individual with more than 25% ownership or voting control, an individual who exercises ultimate control over management, or the person on whose behalf the corporation acts. Where no natural person meets the applicable test, the relevant senior managing official should be identified and reasonably verified.
A declaration can support identification, but staff should apply reasonable verification measures proportionate to risk. Complex chains, nominees, trusts and unexplained control arrangements need more than copying the immediate shareholder register. Record the sources reviewed and how inconsistencies were resolved.
PEP and sanctions screening records
A defensible screening record shows who and what was searched, the names and identifiers used, the system or source, date and time, results, potential-match analysis, decision maker and any follow-up. A “clear” screenshot without search inputs may not show whether all customers, UBOs, authorised persons or relevant connected parties were screened.
Potential matches should be resolved using relevant identifiers and escalated where uncertainty remains. The outcome should feed the customer risk assessment and EDD decision. The process also needs rescreening and trigger events; onboarding is a point in time, while PEP status, sanctions exposure and ownership can change.
EDD and source-of-wealth/source-of-funds evidence
EDD should respond to the reason the relationship is higher risk. Possible measures include obtaining more information on the customer, beneficial owner, purpose, expected activity, source of wealth or source of funds; using additional independent verification; obtaining required senior-management approval; and applying enhanced ongoing monitoring.
The form should separate a statement from supporting evidence. “Business income” is a source description, not necessarily sufficient evidence. The appropriate documents and depth depend on the risk, plausibility, amount and context. The file should show what was obtained, how it was evaluated, inconsistencies, residual concerns and the approval conclusion—not merely whether a box was ticked.
Workflow controls that prevent incomplete onboarding
- Maker completion: the relationship manager or preparer records the customer, ownership, purpose and risk facts.
- Independent or supervisory check: a second person reviews required fields, verification and inconsistencies where the firm’s structure permits.
- Compliance escalation: higher-risk, PEP, potential-match or exception cases go to the authorised decision maker.
- Conditional approval: outstanding conditions have a named owner, restriction and expiry; they are not left as indefinite notes.
- Activation control: systems prevent or flag service commencement before required approval.
- Review scheduling: the approved risk drives ongoing monitoring and the next review date.
Electronic forms can improve completeness, but mandatory fields do not replace judgement. Free-text rationale, evidence attachments and an audit trail of changes remain important.
Ongoing CDD, privacy and record retention
The onboarding pack should become a living customer record. Changes in ownership, directors, authorised persons, services, activity, jurisdiction, adverse information or screening results should trigger reassessment. The Guideline expects customer information to remain up to date and relevant through ongoing monitoring.
Collect only information needed for the regulatory and risk purpose, restrict access, use secure transfer and preserve the record trail. The Companies Registry Guideline generally requires CDD and related records throughout the relationship and for at least five years after it ends. Retention does not justify uncontrolled duplication or sending identity documents through insecure channels.
Connect the forms to the customer risk method, the AML/CFT policy, the review evidence checklist and the remediation process.
Frequently asked questions
Is a UBO declaration enough?
Does every higher-risk customer need the same EDD documents?
Can onboarding be completed after services start?
Primary sources
Regulatory references were checked on 28 July 2026. Always consult the current official text for a live matter.
- Companies Registry — Guideline on AML/CFT for TCSP Licensees (March 2025)
- Hong Kong e-Legislation — Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615)
- Companies Registry — Highlights of disciplinary cases
- FATF — Guidance for a Risk-Based Approach for Trust and Company Service Providers