Key answer
Chronovate reviewed the 15 TCSP disciplinary decisions dated from 15 January 2025 to 30 June 2026 that appeared on the Companies Registry’s current Highlights of Disciplinary Cases page when checked on 5 August 2026. Fourteen decisions cited failures in safeguards under section 23 of Schedule 2 to the AMLO; eight cited ineffective AMLO procedures under section 19(3); seven cited PEP-procedure failures; and five cited customer, beneficial-owner or authorised-person identification or verification failures. Categories overlap, so percentages do not add to 100%.
Methodology and limits
This benchmark uses only the Companies Registry’s public current disciplinary table. The cohort contains every decision in that table dated from 15 January 2025 through 30 June 2026: 11 decisions in 2025 and four in 2026. Chronovate coded each decision by the statutory or licence-condition themes expressly stated in the table. A decision can appear in several categories.
The analysis is descriptive, not a measure of the prevalence of deficiencies across all Hong Kong TCSPs. Published cases reflect enforcement selection, the facts available to the Registrar and the way contraventions were recorded. The coding does not infer unstated failures, re-evaluate liability or rank individual licensees. The source page may change after the check date.
What the 15 published decisions show
| Published contravention theme | Decisions | Share of 15 | Independent-review evidence to test |
|---|---|---|---|
| Proper safeguards / mitigation under section 23, Schedule 2 | 14 | 93% | Governance, approved systems, monitoring, exceptions, management reporting and effective implementation |
| Effective AMLO procedures under section 19(3) | 8 | 53% | Policy-to-process mapping, completed records, quality control and evidence that required duties operate consistently |
| PEP procedures under section 19(1) | 7 | 47% | PEP methodology, screening, match disposition, approvals, EDD and ongoing review |
| Customer, beneficial-owner or authorised-person identification / verification under section 2 | 5 | 33% | Identity, ownership and control evidence, verification, authority to act and escalation of incomplete CDD |
| Non-face-to-face special requirements under section 9 | 3 | 20% | Remote-onboarding design, additional measures, technology controls and completed file evidence |
| Record-keeping under section 20 | 3 | 20% | Retention, completeness, retrievability, access and preservation of CDD records |
| Ongoing monitoring under section 5 | 2 | 13% | Periodic and trigger reviews, current CDD, expected-activity comparison and overdue-review management |
| Adequate written policies, procedures and controls under licence Condition 2 | 2 | 13% | Approved current policy, business-specific procedures, version control and implementation |
| Notification of changed particulars under section 53W | 1 | 7% | Regulatory-change register, ownership of notifications, deadlines and completion evidence |
The percentages are rounded to whole numbers. They describe this small published cohort only and should not be extrapolated to every TCSP or used as a risk score.
Disciplinary outcomes in the cohort
All 15 published decisions disclosed a pecuniary penalty. The stated penalties totalled HKD 180,000, with a median of HKD 8,000 and a range from HKD 4,000 to HKD 30,000. The table also records public reprimands in many cases and remedial-action orders in some cases.
Those figures should not be used as a price list for non-compliance. Outcomes are fact-specific, categories overlap and the operational, reputational and remediation cost is not captured by the penalty amount. The useful management question is whether current controls and independent testing could identify the recurring weaknesses before they persist across the customer population.
The concentration is in system operation, not one isolated form
The most common theme—section 23 safeguards—appears with a range of more specific failures. This supports a systems view: management needs approved controls, working procedures, reliable records, monitoring and evidence that exceptions are identified and corrected. Merely purchasing a policy template does not demonstrate that those controls operate.
The recurrence of section 19(3), PEP and identity-verification themes also shows why an independent review should connect policy to completed files. A reviewer should be able to follow a requirement into the form or workflow, inspect the supporting evidence, assess the decision and test whether the same control operates across a risk-based sample.
Five audit priorities triggered by the data
- Governance and safeguards: test whether senior management approves, receives information on and improves the AML/CFT systems, including exceptions and overdue actions.
- CDD ownership and authority: trace customers, beneficial owners and persons purporting to act through identification, verification and authority evidence.
- PEP and higher-risk handling: assess procedures, screening, match decisions, required approvals, EDD and monitoring.
- Remote onboarding and records: verify that the delivery channel receives appropriate measures and that evidence is complete and retrievable.
- Ongoing operation: inspect periodic reviews, trigger events, current information, monitoring and the treatment of backlogs or exceptions.
These priorities should inform—not replace—the TCSP’s institutional risk assessment. The document checklist converts them into evidence requests, while the customer-risk guide addresses risk-factor and decision records.
How management can use the benchmark
- Compare the recurring themes with the current institutional risk assessment, compliance plan and independent-review scope.
- Ask whether management information shows CDD gaps, PEP alerts, overdue reviews, missing records and policy exceptions across the full population.
- Use recent cases as scenarios in staff and management training without assuming that another licensee’s facts are identical.
- Challenge a review proposal that omits operational file testing or cannot explain how it would detect the recurring themes.
- Track future Companies Registry decisions and update the cohort, coding and conclusions transparently.
For appointment decisions, see how to compare AML audit providers. For timing, see how often a review should be conducted.
Citation and update policy
Readers may cite this analysis as: Chronovate AML, Hong Kong TCSP AML/CFT Disciplinary Benchmark 2025–2026, checked 5 August 2026, together with the page URL and access date. Cite the Companies Registry directly for the underlying decisions.
Chronovate will treat a changed source table, a new decision or a correction to the coding as a reason to update the benchmark date, cohort and counts. Historical versions should not be silently represented as current. This page is general information, not legal advice, and neither the absence of a theme nor a completed review can guarantee a regulatory outcome.
Frequently asked questions
Does 93% mean that 93% of all Hong Kong TCSPs breached section 23?
Why do the percentages add to more than 100%?
Can this benchmark replace an institutional risk assessment or independent review?
Primary sources
Regulatory references were checked on 5 August 2026. Always consult the current official text for a live matter.