Review frequency and regulatory expectation

How Often Should a Hong Kong TCSP Conduct an AML Review?

How often a Hong Kong TCSP should conduct an independent AML/CFT review, including risk-based frequency, trigger events and the separate two-year IRA cycle.

Key answer

A Hong Kong TCSP should set its AML independent-review frequency according to its business and ML/TF risk; there is no universal annual or two-year review rule. The Companies Registry requires an independent audit function to review AML/CFT systems regularly, and paragraph 3.13 of its March 2025 Guideline says the frequency and extent should match the nature, size and complexity of the business and its ML/TF risks. Management should document a defensible cycle, bring the review forward after material triggers, and use an external party where independence, expertise or resources cannot be achieved internally.

What the Companies Registry Guideline says

Paragraph 3.4 of the March 2025 TCSP AML/CFT Guideline includes an independent audit function within the AML/CFT systems a licensee should implement. Paragraphs 3.11 to 3.13 describe the function’s reporting line, expertise, resources, subject matter and risk-based frequency.

This is stronger than a general suggestion to obtain occasional advice. The function is expected to review whether AML/CFT systems operate effectively, including the risk assessment framework, suspicious transaction reporting, the compliance function and staff awareness. The Companies Registry can take disciplinary or other action for non-compliance with applicable AMLO requirements and the regulatory standards in its Guideline.

At the same time, careful wording matters. The Guideline says the frequency and extent should be commensurate with the business and its ML/TF risks; it does not say that every TCSP must buy the same external “annual certificate”.

Independent review, institutional risk assessment and customer review are different cycles

Three recurring AML/CFT activities are often confused. The independent audit function regularly tests whether the TCSP's AML/CFT systems are effective. The institutional ML/TF risk assessment is refreshed every two years and upon material trigger events under paragraph 2.9. Individual customer risk assessments are reviewed from time to time, particularly during ongoing monitoring, under paragraph 2.13. These are connected controls, but they do not share one automatic timetable.

ActivityPurposeTiming basis
Independent AML/CFT review or auditTests the adequacy and effectiveness of AML/CFT systems independentlyRegularly; frequency and extent are proportionate to nature, size, complexity and ML/TF risk
Institutional ML/TF risk assessmentAssesses the TCSP's business-wide exposure and informs its control frameworkEvery two years and upon material trigger events
Customer risk assessment reviewKeeps an individual relationship's risk rating and controls currentFrom time to time and particularly during ongoing monitoring or after relevant changes

A defensible independent-review cycle should therefore refer to the latest institutional and customer-risk evidence without simply copying either review date. This distinction matters when management explains why the proposed timing and scope are proportionate.

A practical review-frequency decision matrix

The Guideline deliberately uses a risk-based standard rather than a fixed calendar rule. The matrix below is a management aid, not a substitute for the TCSP’s own assessment. It helps explain why a review should occur sooner, cover more controls or use broader file testing.

Current positionReview response to considerEvidence supporting the decision
Stable, small company-secretarial practice with no material change or prior findingSet a documented recurring cycle with a proportionate scope; keep trigger monitoring active between reviews.Institutional risk assessment, customer-risk distribution, exception data and last review results
Trust, nominee, director or complex cross-border servicesConsider a shorter interval or broader testing because ownership, control, purpose and EDD evidence may be more complex.Service inventory, jurisdiction exposure, higher-risk files and source-of-wealth/source-of-funds records
Rapid growth, portfolio acquisition or material staffing changeBring forward a targeted or full review to test whether controls still operate at the new scale.Customer-population movement, staffing ratios, backlogs, quality checks and management information
New remote onboarding, screening platform or outsourced processTest the changed workflow after enough operating evidence exists; address urgent design concerns before launch.Change approval, risk assessment, walkthroughs, access controls, alerts and completed files
Material prior findings, repeated exceptions or regulatory enquiryPerform timely follow-up or a focused review; expand the scope if root cause or affected population is uncertain.Action plan, closure evidence, retesting, complaints, inspection correspondence and exception trends

A TCSP should avoid turning these examples into an automatic timetable. The decision remains one of documented judgement. The separate expectation to refresh the institutional ML/TF risk assessment every two years and upon material trigger events does not create a universal two-year independent audit cycle.

Trigger events that should prompt reconsideration

Even where a scheduled review is not yet due, a trigger event may justify targeted or full-scope work. Examples include a material change in services, entry into new jurisdictions, acquisition of a customer portfolio, a new onboarding platform, replacement of the compliance officer or MLRO, a serious internal escalation, persistent missing CDD, or an inspection request.

The Companies Registry Guideline separately expects an institutional risk assessment at least every two years and upon trigger events material to the business and risk exposure. That two-year risk-assessment expectation should not be confused with a universal two-year independent review rule. The two processes inform one another but serve different purposes.

What proportionate review looks like for a small TCSP

Proportionality does not mean exemption. A small company-secretarial practice may have simpler systems and a smaller sample, but it should still be able to demonstrate independence, competence, effective testing and direct reporting to management. A short review that examines the right evidence can be more valuable than a large generic checklist.

For a smaller firm, scope may focus on its institutional risk assessment, policy-to-practice walkthroughs, a risk-based selection of customer files, PEP and sanctions screening, ongoing review controls, STR escalation, record retention and staff understanding. The rationale for exclusions should be written down. For example, excluding trust controls is sensible only if the firm genuinely does not provide trust services and there is evidence supporting that boundary.

What management should record when setting the cycle

A short decision record makes the review cycle explainable to directors, the reviewer and, if requested, the Registrar. It should identify the decision date, last completed review, proposed next review window, relevant changes, current institutional-risk conclusion, unresolved findings, exception trends, proposed scope and reviewer-independence assessment.

  • Owner: name the person responsible for monitoring the cycle and escalating a trigger event.
  • Basis: refer to actual customer, service, jurisdiction, delivery-channel and control information rather than size alone.
  • Triggers: list events that override the scheduled date, including new services, material incidents, control backlogs and regulatory contact.
  • Scope: explain whether the next work will be full-scope, targeted follow-up or another form of independent testing.
  • Independence: record why the reviewer is independent of the functions being tested and has sufficient expertise and resources.
  • Approval: preserve senior-management consideration and any challenge to the proposed timing or scope.

This record does not prove the cycle is appropriate by itself. Its value is that it connects the decision to evidence and creates a clear prompt for reconsideration.

Warning signs that the current arrangement is not enough

  • The reviewer created or operates the controls and no conflict safeguard exists.
  • The work checks only the policy manual and does not test completed customer files or operational records.
  • Management cannot explain the review frequency or why the scope matches the risk profile.
  • Prior findings were marked complete without evidence or retesting.
  • The report has no limitations, evidence trail, risk assessment or accountable action owners.
  • The exercise is marketed as a guaranteed pass or regulatory certificate.

The Companies Registry’s public disciplinary cases demonstrate that current enforcement attention is not theoretical. Recent cases identify failures involving customer and beneficial-owner verification, PEP procedures, ongoing monitoring, record-keeping and effective AML/CFT procedures. An independent review should be designed to detect such weaknesses before they become entrenched.

A practical management decision

Management can frame the decision in four questions: when was the last independent review, what has changed since then, what do the institutional risk assessment and exception data show, and is the proposed reviewer sufficiently independent and capable? The answers should lead to a documented review plan rather than a purchase driven only by price or a standard package label.

Start with the independent review overview, use the document preparation checklist, and understand what the final report should contain. If an earlier review found issues, see the remediation guide.

Frequently asked questions

Is an external reviewer always mandatory?
The Guideline requires an independent audit function and says external review should be sought where appropriate. The correct arrangement depends on whether independence, expertise, resources and direct reporting to senior management are achieved.
Does a small TCSP need an independent review?
Small size affects proportionality, not the need for effective AML/CFT systems and independent assurance. The scope and extent may be simpler where the business and risks are genuinely less complex.
Is an independent review required every two years?
The March 2025 Guideline states that the institutional ML/TF risk assessment should be conducted every two years and on material triggers. Review frequency is addressed separately and should be commensurate with the business and its ML/TF risks.

Primary sources

Regulatory references were checked on 25 August 2026. Always consult the current official text for a live matter.

  1. Companies Registry — Guideline on AML/CFT for TCSP Licensees (March 2025)
  2. Companies Registry — FAQ on the independent audit function (3 March 2025)
  3. Companies Registry — Highlights of disciplinary cases
  4. Hong Kong e-Legislation — Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615)
Scope note: This guide provides general information for Hong Kong TCSP licensees. It is not legal advice and does not determine the treatment of any particular customer or guarantee a regulatory outcome.