Customer ML/TF risk assessment

Customer Risk Assessment for Hong Kong TCSPs: Factors, Scoring and Examples

A practical Hong Kong TCSP customer risk assessment guide with risk factors, scoring governance, overrides, worked examples and evidence.

Key answer

A Hong Kong TCSP should assess each proposed relationship using customer and ownership, country or jurisdiction, service or transaction, and delivery-channel risk factors. The file should show the facts, inherent risk, methodology, any mandatory escalation, mitigating evidence, final rating, rationale, CDD or EDD response, approval and review triggers. A numerical score is a decision aid, not a substitute for judgement, and paragraph 2.15 of the Companies Registry Guideline expects records that demonstrate both the assessment and why the resulting controls are proportionate.

Institutional risk and customer risk are connected but different

The institutional ML/TF risk assessment identifies the risks facing the TCSP’s business as a whole. It considers customer segments, jurisdictions, services, transaction characteristics, delivery channels, technology, resources, findings and other relevant factors. The customer risk assessment applies that framework to an individual proposed or existing relationship.

The Companies Registry Guideline says the customer assessment at the initial CDD stage determines the extent of measures to apply and later informs ongoing monitoring and the decision to enter, continue or terminate the relationship. The customer framework should be commensurate with the nature and size of the firm and designed from the institutional assessment, not copied from an unrelated business.

Four core groups of customer risk factors

Factor groupIllustrative questions
Customer and ownershipIs the purpose transparent? Is ownership complex or involving nominees? Is the customer, UBO or connected person a PEP? Is adverse information relevant and credible?
Country or jurisdictionWhere are the customer, UBOs, operations and expected activity located? Are there sanctions, FATF concerns, corruption, secrecy or weak AML/CFT controls?
Service or transactionDoes the relationship involve trusts, nominees, director services, client money, complex structures, unusual urgency or activity without a clear commercial purpose?
Delivery channelIs onboarding non-face-to-face? Are intermediaries or introducers involved? Can identity, authority and purpose be verified effectively through the channel?

No single factor automatically determines the final result in every case. A PEP relationship, high-risk jurisdiction or complex structure requires the applicable measures and careful analysis, but the file should still consider the full context rather than applying an unexplained label.

A seven-step assessment method

  1. Collect reliable facts. Complete customer, beneficial-owner, authorised-person, purpose, service and expected activity information.
  2. Identify inherent risk factors. Record the risk before considering the firm’s mitigating controls.
  3. Apply the approved methodology. Use the firm’s defined categories, weights, rules and mandatory escalation factors.
  4. Consider mitigating evidence. Evaluate regulatory status, transparency, independent verification, financial information and other relevant controls without assuming they eliminate risk.
  5. Reach a holistic rating. Sense-check the output and document any override of the mechanical score.
  6. Determine measures and approval. Define CDD, EDD, senior-management approval and monitoring appropriate to the risk.
  7. Schedule review. Set the next periodic review and trigger events, then preserve the evidence and decision trail.

Designing a scoring model without false precision

A model may use low/medium/high categories, numerical points or a combination. Whatever the format, define each factor and prevent inappropriate offsetting. For example, a long business relationship should not automatically cancel a material PEP, sanctions or unexplained-ownership concern.

Good governance includes controlled factor definitions, version history, validation against actual cases, approval thresholds, mandatory escalation rules and a documented override process. Review rating distributions: if nearly every customer is “low” despite higher-risk services or jurisdictions, the model or its application may not reflect reality.

Practical test: a competent reviewer should be able to reproduce the rating from the facts and methodology, while understanding the narrative reason for the final decision. If the result depends on an undocumented spreadsheet formula or personal memory, the control is fragile.

Two worked customer-risk examples

The following examples are illustrations, not ratings for any actual customer and not a substitute for the firm’s approved methodology.

Assessment stepExample A: transparent local operating companyExample B: complex remote cross-border structure
FactsHong Kong trading company, two resident individual owners, clear operating purpose, direct contact and straightforward company-secretarial servicesOverseas holding chain, remote onboarding, nominee-director request, several jurisdictions and a former non-Hong Kong PEP among the ultimate owners
Inherent factorsRelatively transparent ownership and delivery channel; ordinary service profile; expected activity is coherent with the businessOwnership, PEP, jurisdiction, delivery-channel and service-complexity factors require closer analysis
Evidence and measuresComplete CDD and beneficial-owner verification, purpose, screening, expected activity and proportionate approvalFull control-chain work, PEP analysis, applicable source-of-wealth/source-of-funds evidence, reasons for nominee service, enhanced approval and monitoring
Decision recordExplain why the overall rating and routine monitoring are consistent with the evidence; do not call the relationship low risk merely because it is localExplain how risks will be managed, whether they remain acceptable, who approved the relationship and what would trigger reassessment

Neither outcome should be predetermined. Missing, contradictory or unreliable information can change the assessment. A higher-risk relationship is not automatically prohibited, but the TCSP must be able to complete the applicable measures, manage the risk within its appetite and decline or end the relationship where requirements cannot be met.

The minimum scoring and override record

A controlled scoring worksheet should make the decision reproducible without pretending that ML/TF risk is mathematically exact. At minimum, keep the methodology version, factor responses, evidence references, calculated result, mandatory escalation flags, proposed rating, final rating, narrative rationale, reviewer or approver and effective date.

  • Factor definitions: describe what each answer means and prevent staff from choosing the lowest response without evidence.
  • Escalation rules: identify matters that cannot be averaged away, such as an unresolved sanctions concern or required PEP treatment.
  • Overrides: record the original output, revised rating, reason, supporting evidence and approval; monitor whether overrides cluster around a particular factor or employee.
  • Rating response: connect each level to CDD depth, approval, monitoring frequency and quality assurance.
  • Distribution review: compare actual low, medium and high ratings with the institutional risk assessment and service population.

A model that produces nearly all low-risk outcomes for a business with complex or higher-risk exposure deserves challenge. Equally, a model should not inflate ratings through poorly defined factors that double-count the same risk.

Periodic and trigger-event reviews

Customer risk is not fixed at onboarding. The Guideline expects assessments to be reviewed and updated from time to time, particularly through ongoing monitoring. The firm should set frequency by risk and react to trigger events.

  • change in ownership, control, directors or authorised persons;
  • new service, structure, jurisdiction or expected activity;
  • new PEP, sanctions or credible adverse-information result;
  • unusual or inconsistent activity and unexplained urgency;
  • expired, contradictory or inadequate CDD information;
  • law-enforcement, regulatory or court-related information;
  • material policy, system or risk-methodology change; or
  • finding from quality assurance, compliance or independent review.

The record should show the prior rating, new information, analysis, revised rating, measures, approver and effective date.

Evidence the firm should retain

Paragraph 2.15 of the Companies Registry Guideline says the TCSP should keep risk-assessment records and documents so it can demonstrate how it assesses the customer’s ML/TF risk and why the extent of CDD and ongoing monitoring is appropriate. That means the form, supporting documents, screening, research, calculations, rationale, approvals, overrides, EDD and review history should form one coherent audit trail.

Use the onboarding and EDD form guide, align the method with the AML/CFT policy manual, prepare evidence through the review checklist, and test the control through an independent review.

Frequently asked questions

Does every customer need a documented risk assessment?
The Guideline expects the TCSP to assess the ML/TF risks associated with a proposed business relationship and keep records that demonstrate the assessment and proportionate CDD and monitoring.
Can software decide the customer risk rating?
Software can support consistency, but the methodology, inputs, mandatory escalation factors, overrides and final approval remain governance responsibilities. The result should be explainable from the evidence.
Is a high-risk customer prohibited?
Not automatically. The firm must apply the applicable legal and regulatory requirements, assess whether the risk can be managed, perform appropriate EDD and approvals, and decline or terminate relationships where requirements cannot be met or risk is unacceptable.

Primary sources

Regulatory references were checked on 5 August 2026. Always consult the current official text for a live matter.

  1. Companies Registry — Guideline on AML/CFT for TCSP Licensees (March 2025)
  2. Companies Registry — Highlights of disciplinary cases
  3. Hong Kong e-Legislation — Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615)
  4. FATF — Guidance for a Risk-Based Approach for Trust and Company Service Providers
Scope note: This guide provides general information for Hong Kong TCSP licensees. It is not legal advice and does not determine the treatment of any particular customer or guarantee a regulatory outcome.