Original public enforcement analysis

Hong Kong TCSP AML/CFT Disciplinary Benchmark 2025–2026

Original analysis of 15 Hong Kong TCSP disciplinary decisions from 2025–2026, showing recurring AML/CFT control failures and audit evidence.

Key answer

Chronovate reviewed the 15 TCSP disciplinary decisions dated from 15 January 2025 to 30 June 2026 that appeared on the Companies Registry’s current Highlights of Disciplinary Cases page when checked on 5 August 2026. Fourteen decisions cited failures in safeguards under section 23 of Schedule 2 to the AMLO; eight cited ineffective AMLO procedures under section 19(3); seven cited PEP-procedure failures; and five cited customer, beneficial-owner or authorised-person identification or verification failures. Categories overlap, so percentages do not add to 100%.

Methodology and limits

This benchmark uses only the Companies Registry’s public current disciplinary table. The cohort contains every decision in that table dated from 15 January 2025 through 30 June 2026: 11 decisions in 2025 and four in 2026. Chronovate coded each decision by the statutory or licence-condition themes expressly stated in the table. A decision can appear in several categories.

The analysis is descriptive, not a measure of the prevalence of deficiencies across all Hong Kong TCSPs. Published cases reflect enforcement selection, the facts available to the Registrar and the way contraventions were recorded. The coding does not infer unstated failures, re-evaluate liability or rank individual licensees. The source page may change after the check date.

Reproducibility note: cohort start date 15 January 2025; cohort end date 30 June 2026; 15 decisions; public source checked 5 August 2026; category counts are non-exclusive.

What the 15 published decisions show

Published contravention themeDecisionsShare of 15Independent-review evidence to test
Proper safeguards / mitigation under section 23, Schedule 21493%Governance, approved systems, monitoring, exceptions, management reporting and effective implementation
Effective AMLO procedures under section 19(3)853%Policy-to-process mapping, completed records, quality control and evidence that required duties operate consistently
PEP procedures under section 19(1)747%PEP methodology, screening, match disposition, approvals, EDD and ongoing review
Customer, beneficial-owner or authorised-person identification / verification under section 2533%Identity, ownership and control evidence, verification, authority to act and escalation of incomplete CDD
Non-face-to-face special requirements under section 9320%Remote-onboarding design, additional measures, technology controls and completed file evidence
Record-keeping under section 20320%Retention, completeness, retrievability, access and preservation of CDD records
Ongoing monitoring under section 5213%Periodic and trigger reviews, current CDD, expected-activity comparison and overdue-review management
Adequate written policies, procedures and controls under licence Condition 2213%Approved current policy, business-specific procedures, version control and implementation
Notification of changed particulars under section 53W17%Regulatory-change register, ownership of notifications, deadlines and completion evidence

The percentages are rounded to whole numbers. They describe this small published cohort only and should not be extrapolated to every TCSP or used as a risk score.

Disciplinary outcomes in the cohort

All 15 published decisions disclosed a pecuniary penalty. The stated penalties totalled HKD 180,000, with a median of HKD 8,000 and a range from HKD 4,000 to HKD 30,000. The table also records public reprimands in many cases and remedial-action orders in some cases.

Those figures should not be used as a price list for non-compliance. Outcomes are fact-specific, categories overlap and the operational, reputational and remediation cost is not captured by the penalty amount. The useful management question is whether current controls and independent testing could identify the recurring weaknesses before they persist across the customer population.

The concentration is in system operation, not one isolated form

The most common theme—section 23 safeguards—appears with a range of more specific failures. This supports a systems view: management needs approved controls, working procedures, reliable records, monitoring and evidence that exceptions are identified and corrected. Merely purchasing a policy template does not demonstrate that those controls operate.

The recurrence of section 19(3), PEP and identity-verification themes also shows why an independent review should connect policy to completed files. A reviewer should be able to follow a requirement into the form or workflow, inspect the supporting evidence, assess the decision and test whether the same control operates across a risk-based sample.

Five audit priorities triggered by the data

  1. Governance and safeguards: test whether senior management approves, receives information on and improves the AML/CFT systems, including exceptions and overdue actions.
  2. CDD ownership and authority: trace customers, beneficial owners and persons purporting to act through identification, verification and authority evidence.
  3. PEP and higher-risk handling: assess procedures, screening, match decisions, required approvals, EDD and monitoring.
  4. Remote onboarding and records: verify that the delivery channel receives appropriate measures and that evidence is complete and retrievable.
  5. Ongoing operation: inspect periodic reviews, trigger events, current information, monitoring and the treatment of backlogs or exceptions.

These priorities should inform—not replace—the TCSP’s institutional risk assessment. The document checklist converts them into evidence requests, while the customer-risk guide addresses risk-factor and decision records.

How management can use the benchmark

  • Compare the recurring themes with the current institutional risk assessment, compliance plan and independent-review scope.
  • Ask whether management information shows CDD gaps, PEP alerts, overdue reviews, missing records and policy exceptions across the full population.
  • Use recent cases as scenarios in staff and management training without assuming that another licensee’s facts are identical.
  • Challenge a review proposal that omits operational file testing or cannot explain how it would detect the recurring themes.
  • Track future Companies Registry decisions and update the cohort, coding and conclusions transparently.

For appointment decisions, see how to compare AML audit providers. For timing, see how often a review should be conducted.

Citation and update policy

Readers may cite this analysis as: Chronovate AML, Hong Kong TCSP AML/CFT Disciplinary Benchmark 2025–2026, checked 5 August 2026, together with the page URL and access date. Cite the Companies Registry directly for the underlying decisions.

Chronovate will treat a changed source table, a new decision or a correction to the coding as a reason to update the benchmark date, cohort and counts. Historical versions should not be silently represented as current. This page is general information, not legal advice, and neither the absence of a theme nor a completed review can guarantee a regulatory outcome.

Frequently asked questions

Does 93% mean that 93% of all Hong Kong TCSPs breached section 23?
No. It means 14 of the 15 published disciplinary decisions in the defined current-page cohort cited section 23. The sample is enforcement-selected and cannot be used to estimate prevalence across all licensees.
Why do the percentages add to more than 100%?
A single disciplinary decision can cite several contraventions, so the categories overlap. Each percentage uses 15 decisions as the denominator and is rounded to the nearest whole number.
Can this benchmark replace an institutional risk assessment or independent review?
No. It is a public enforcement signal. A TCSP must assess its own business, customers, services, jurisdictions, delivery channels and controls, and design proportionate independent testing around that evidence.

Primary sources

Regulatory references were checked on 5 August 2026. Always consult the current official text for a live matter.

  1. Companies Registry — Highlights of disciplinary cases
  2. Companies Registry — Previous highlights of disciplinary cases
  3. Companies Registry — Guideline on AML/CFT for TCSP Licensees (March 2025)
  4. Companies Registry — FAQ on the independent audit function (3 March 2025)
Scope note: This guide provides general information for Hong Kong TCSP licensees. It is not legal advice and does not determine the treatment of any particular customer or guarantee a regulatory outcome.