Key answer
A Hong Kong TCSP should assess each proposed relationship using customer and ownership, country or jurisdiction, service or transaction, and delivery-channel risk factors. The file should show the facts, inherent risk, methodology, any mandatory escalation, mitigating evidence, final rating, rationale, CDD or EDD response, approval and review triggers. A numerical score is a decision aid, not a substitute for judgement, and paragraph 2.15 of the Companies Registry Guideline expects records that demonstrate both the assessment and why the resulting controls are proportionate.
Institutional risk and customer risk are connected but different
The institutional ML/TF risk assessment identifies the risks facing the TCSP’s business as a whole. It considers customer segments, jurisdictions, services, transaction characteristics, delivery channels, technology, resources, findings and other relevant factors. The customer risk assessment applies that framework to an individual proposed or existing relationship.
The Companies Registry Guideline says the customer assessment at the initial CDD stage determines the extent of measures to apply and later informs ongoing monitoring and the decision to enter, continue or terminate the relationship. The customer framework should be commensurate with the nature and size of the firm and designed from the institutional assessment, not copied from an unrelated business.
Four core groups of customer risk factors
| Factor group | Illustrative questions |
|---|---|
| Customer and ownership | Is the purpose transparent? Is ownership complex or involving nominees? Is the customer, UBO or connected person a PEP? Is adverse information relevant and credible? |
| Country or jurisdiction | Where are the customer, UBOs, operations and expected activity located? Are there sanctions, FATF concerns, corruption, secrecy or weak AML/CFT controls? |
| Service or transaction | Does the relationship involve trusts, nominees, director services, client money, complex structures, unusual urgency or activity without a clear commercial purpose? |
| Delivery channel | Is onboarding non-face-to-face? Are intermediaries or introducers involved? Can identity, authority and purpose be verified effectively through the channel? |
No single factor automatically determines the final result in every case. A PEP relationship, high-risk jurisdiction or complex structure requires the applicable measures and careful analysis, but the file should still consider the full context rather than applying an unexplained label.
A seven-step assessment method
- Collect reliable facts. Complete customer, beneficial-owner, authorised-person, purpose, service and expected activity information.
- Identify inherent risk factors. Record the risk before considering the firm’s mitigating controls.
- Apply the approved methodology. Use the firm’s defined categories, weights, rules and mandatory escalation factors.
- Consider mitigating evidence. Evaluate regulatory status, transparency, independent verification, financial information and other relevant controls without assuming they eliminate risk.
- Reach a holistic rating. Sense-check the output and document any override of the mechanical score.
- Determine measures and approval. Define CDD, EDD, senior-management approval and monitoring appropriate to the risk.
- Schedule review. Set the next periodic review and trigger events, then preserve the evidence and decision trail.
Designing a scoring model without false precision
A model may use low/medium/high categories, numerical points or a combination. Whatever the format, define each factor and prevent inappropriate offsetting. For example, a long business relationship should not automatically cancel a material PEP, sanctions or unexplained-ownership concern.
Good governance includes controlled factor definitions, version history, validation against actual cases, approval thresholds, mandatory escalation rules and a documented override process. Review rating distributions: if nearly every customer is “low” despite higher-risk services or jurisdictions, the model or its application may not reflect reality.
Two worked customer-risk examples
The following examples are illustrations, not ratings for any actual customer and not a substitute for the firm’s approved methodology.
| Assessment step | Example A: transparent local operating company | Example B: complex remote cross-border structure |
|---|---|---|
| Facts | Hong Kong trading company, two resident individual owners, clear operating purpose, direct contact and straightforward company-secretarial services | Overseas holding chain, remote onboarding, nominee-director request, several jurisdictions and a former non-Hong Kong PEP among the ultimate owners |
| Inherent factors | Relatively transparent ownership and delivery channel; ordinary service profile; expected activity is coherent with the business | Ownership, PEP, jurisdiction, delivery-channel and service-complexity factors require closer analysis |
| Evidence and measures | Complete CDD and beneficial-owner verification, purpose, screening, expected activity and proportionate approval | Full control-chain work, PEP analysis, applicable source-of-wealth/source-of-funds evidence, reasons for nominee service, enhanced approval and monitoring |
| Decision record | Explain why the overall rating and routine monitoring are consistent with the evidence; do not call the relationship low risk merely because it is local | Explain how risks will be managed, whether they remain acceptable, who approved the relationship and what would trigger reassessment |
Neither outcome should be predetermined. Missing, contradictory or unreliable information can change the assessment. A higher-risk relationship is not automatically prohibited, but the TCSP must be able to complete the applicable measures, manage the risk within its appetite and decline or end the relationship where requirements cannot be met.
The minimum scoring and override record
A controlled scoring worksheet should make the decision reproducible without pretending that ML/TF risk is mathematically exact. At minimum, keep the methodology version, factor responses, evidence references, calculated result, mandatory escalation flags, proposed rating, final rating, narrative rationale, reviewer or approver and effective date.
- Factor definitions: describe what each answer means and prevent staff from choosing the lowest response without evidence.
- Escalation rules: identify matters that cannot be averaged away, such as an unresolved sanctions concern or required PEP treatment.
- Overrides: record the original output, revised rating, reason, supporting evidence and approval; monitor whether overrides cluster around a particular factor or employee.
- Rating response: connect each level to CDD depth, approval, monitoring frequency and quality assurance.
- Distribution review: compare actual low, medium and high ratings with the institutional risk assessment and service population.
A model that produces nearly all low-risk outcomes for a business with complex or higher-risk exposure deserves challenge. Equally, a model should not inflate ratings through poorly defined factors that double-count the same risk.
Periodic and trigger-event reviews
Customer risk is not fixed at onboarding. The Guideline expects assessments to be reviewed and updated from time to time, particularly through ongoing monitoring. The firm should set frequency by risk and react to trigger events.
- change in ownership, control, directors or authorised persons;
- new service, structure, jurisdiction or expected activity;
- new PEP, sanctions or credible adverse-information result;
- unusual or inconsistent activity and unexplained urgency;
- expired, contradictory or inadequate CDD information;
- law-enforcement, regulatory or court-related information;
- material policy, system or risk-methodology change; or
- finding from quality assurance, compliance or independent review.
The record should show the prior rating, new information, analysis, revised rating, measures, approver and effective date.
Evidence the firm should retain
Paragraph 2.15 of the Companies Registry Guideline says the TCSP should keep risk-assessment records and documents so it can demonstrate how it assesses the customer’s ML/TF risk and why the extent of CDD and ongoing monitoring is appropriate. That means the form, supporting documents, screening, research, calculations, rationale, approvals, overrides, EDD and review history should form one coherent audit trail.
Use the onboarding and EDD form guide, align the method with the AML/CFT policy manual, prepare evidence through the review checklist, and test the control through an independent review.
Frequently asked questions
Does every customer need a documented risk assessment?
Can software decide the customer risk rating?
Is a high-risk customer prohibited?
Primary sources
Regulatory references were checked on 5 August 2026. Always consult the current official text for a live matter.
- Companies Registry — Guideline on AML/CFT for TCSP Licensees (March 2025)
- Companies Registry — Highlights of disciplinary cases
- Hong Kong e-Legislation — Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615)
- FATF — Guidance for a Risk-Based Approach for Trust and Company Service Providers