Key answer
A Hong Kong TCSP should set its AML independent-review frequency according to its business and ML/TF risk; there is no universal annual or two-year review rule. The Companies Registry requires an independent audit function to review AML/CFT systems regularly, and paragraph 3.13 of its March 2025 Guideline says the frequency and extent should match the nature, size and complexity of the business and its ML/TF risks. Management should document a defensible cycle, bring the review forward after material triggers, and use an external party where independence, expertise or resources cannot be achieved internally.
What the Companies Registry Guideline says
Paragraph 3.4 of the March 2025 TCSP AML/CFT Guideline includes an independent audit function within the AML/CFT systems a licensee should implement. Paragraphs 3.11 to 3.13 describe the function’s reporting line, expertise, resources, subject matter and risk-based frequency.
This is stronger than a general suggestion to obtain occasional advice. The function is expected to review whether AML/CFT systems operate effectively, including the risk assessment framework, suspicious transaction reporting, the compliance function and staff awareness. The Companies Registry can take disciplinary or other action for non-compliance with applicable AMLO requirements and the regulatory standards in its Guideline.
At the same time, careful wording matters. The Guideline says the frequency and extent should be commensurate with the business and its ML/TF risks; it does not say that every TCSP must buy the same external “annual certificate”.
Independent review, institutional risk assessment and customer review are different cycles
Three recurring AML/CFT activities are often confused. The independent audit function regularly tests whether the TCSP's AML/CFT systems are effective. The institutional ML/TF risk assessment is refreshed every two years and upon material trigger events under paragraph 2.9. Individual customer risk assessments are reviewed from time to time, particularly during ongoing monitoring, under paragraph 2.13. These are connected controls, but they do not share one automatic timetable.
| Activity | Purpose | Timing basis |
|---|---|---|
| Independent AML/CFT review or audit | Tests the adequacy and effectiveness of AML/CFT systems independently | Regularly; frequency and extent are proportionate to nature, size, complexity and ML/TF risk |
| Institutional ML/TF risk assessment | Assesses the TCSP's business-wide exposure and informs its control framework | Every two years and upon material trigger events |
| Customer risk assessment review | Keeps an individual relationship's risk rating and controls current | From time to time and particularly during ongoing monitoring or after relevant changes |
A defensible independent-review cycle should therefore refer to the latest institutional and customer-risk evidence without simply copying either review date. This distinction matters when management explains why the proposed timing and scope are proportionate.
A practical review-frequency decision matrix
The Guideline deliberately uses a risk-based standard rather than a fixed calendar rule. The matrix below is a management aid, not a substitute for the TCSP’s own assessment. It helps explain why a review should occur sooner, cover more controls or use broader file testing.
| Current position | Review response to consider | Evidence supporting the decision |
|---|---|---|
| Stable, small company-secretarial practice with no material change or prior finding | Set a documented recurring cycle with a proportionate scope; keep trigger monitoring active between reviews. | Institutional risk assessment, customer-risk distribution, exception data and last review results |
| Trust, nominee, director or complex cross-border services | Consider a shorter interval or broader testing because ownership, control, purpose and EDD evidence may be more complex. | Service inventory, jurisdiction exposure, higher-risk files and source-of-wealth/source-of-funds records |
| Rapid growth, portfolio acquisition or material staffing change | Bring forward a targeted or full review to test whether controls still operate at the new scale. | Customer-population movement, staffing ratios, backlogs, quality checks and management information |
| New remote onboarding, screening platform or outsourced process | Test the changed workflow after enough operating evidence exists; address urgent design concerns before launch. | Change approval, risk assessment, walkthroughs, access controls, alerts and completed files |
| Material prior findings, repeated exceptions or regulatory enquiry | Perform timely follow-up or a focused review; expand the scope if root cause or affected population is uncertain. | Action plan, closure evidence, retesting, complaints, inspection correspondence and exception trends |
A TCSP should avoid turning these examples into an automatic timetable. The decision remains one of documented judgement. The separate expectation to refresh the institutional ML/TF risk assessment every two years and upon material trigger events does not create a universal two-year independent audit cycle.
Trigger events that should prompt reconsideration
Even where a scheduled review is not yet due, a trigger event may justify targeted or full-scope work. Examples include a material change in services, entry into new jurisdictions, acquisition of a customer portfolio, a new onboarding platform, replacement of the compliance officer or MLRO, a serious internal escalation, persistent missing CDD, or an inspection request.
The Companies Registry Guideline separately expects an institutional risk assessment at least every two years and upon trigger events material to the business and risk exposure. That two-year risk-assessment expectation should not be confused with a universal two-year independent review rule. The two processes inform one another but serve different purposes.
What proportionate review looks like for a small TCSP
Proportionality does not mean exemption. A small company-secretarial practice may have simpler systems and a smaller sample, but it should still be able to demonstrate independence, competence, effective testing and direct reporting to management. A short review that examines the right evidence can be more valuable than a large generic checklist.
For a smaller firm, scope may focus on its institutional risk assessment, policy-to-practice walkthroughs, a risk-based selection of customer files, PEP and sanctions screening, ongoing review controls, STR escalation, record retention and staff understanding. The rationale for exclusions should be written down. For example, excluding trust controls is sensible only if the firm genuinely does not provide trust services and there is evidence supporting that boundary.
What management should record when setting the cycle
A short decision record makes the review cycle explainable to directors, the reviewer and, if requested, the Registrar. It should identify the decision date, last completed review, proposed next review window, relevant changes, current institutional-risk conclusion, unresolved findings, exception trends, proposed scope and reviewer-independence assessment.
- Owner: name the person responsible for monitoring the cycle and escalating a trigger event.
- Basis: refer to actual customer, service, jurisdiction, delivery-channel and control information rather than size alone.
- Triggers: list events that override the scheduled date, including new services, material incidents, control backlogs and regulatory contact.
- Scope: explain whether the next work will be full-scope, targeted follow-up or another form of independent testing.
- Independence: record why the reviewer is independent of the functions being tested and has sufficient expertise and resources.
- Approval: preserve senior-management consideration and any challenge to the proposed timing or scope.
This record does not prove the cycle is appropriate by itself. Its value is that it connects the decision to evidence and creates a clear prompt for reconsideration.
Warning signs that the current arrangement is not enough
- The reviewer created or operates the controls and no conflict safeguard exists.
- The work checks only the policy manual and does not test completed customer files or operational records.
- Management cannot explain the review frequency or why the scope matches the risk profile.
- Prior findings were marked complete without evidence or retesting.
- The report has no limitations, evidence trail, risk assessment or accountable action owners.
- The exercise is marketed as a guaranteed pass or regulatory certificate.
The Companies Registry’s public disciplinary cases demonstrate that current enforcement attention is not theoretical. Recent cases identify failures involving customer and beneficial-owner verification, PEP procedures, ongoing monitoring, record-keeping and effective AML/CFT procedures. An independent review should be designed to detect such weaknesses before they become entrenched.
A practical management decision
Management can frame the decision in four questions: when was the last independent review, what has changed since then, what do the institutional risk assessment and exception data show, and is the proposed reviewer sufficiently independent and capable? The answers should lead to a documented review plan rather than a purchase driven only by price or a standard package label.
Start with the independent review overview, use the document preparation checklist, and understand what the final report should contain. If an earlier review found issues, see the remediation guide.
Frequently asked questions
Is an external reviewer always mandatory?
Does a small TCSP need an independent review?
Is an independent review required every two years?
Primary sources
Regulatory references were checked on 25 August 2026. Always consult the current official text for a live matter.