Key answer
Choose a Hong Kong TCSP AML/CFT audit provider by testing five things: independence from the controls under review, relevant TCSP expertise, a risk-based scope that includes operating evidence, a decision-useful report, and secure handling of confidential records. Ask who will do the work, how files will be sampled, what limitations will be disclosed and how findings will be supported. Do not select on a certificate, generic checklist or headline price alone; the Companies Registry focuses on an effective independent audit function, not a particular commercial label.
Start with the regulatory test
Paragraphs 3.11 to 3.13 of the Companies Registry’s March 2025 Guideline set the foundation. The function should communicate directly with senior management, have sufficient expertise and resources, and independently review whether AML/CFT systems are effective. The FAQ states that internal staff or external parties may perform the role, but the reviewer must be independent of the functions or parties being examined. A compliance officer or MLRO cannot simultaneously perform the independent audit function.
This means “external” is not enough by itself. Management should understand who actually performs the work, whether that person designed or operates the controls, what conflicts exist and whether findings can be reported without filtering by the control owner.
A seven-part provider comparison
| Question | Evidence to request | Warning sign |
|---|---|---|
| Is the reviewer independent? | Team roles, conflicts assessment, prior work and direct reporting line | The same person designed, operates and concludes on the controls without safeguards |
| Does the team understand Hong Kong TCSP requirements? | Named reviewer, relevant experience and familiarity with the March 2025 Guideline and AMLO | Generic financial-crime claims with no TCSP-specific methodology |
| Will the work test operation? | Walkthrough, population, risk-based sampling and evidence plan | Policy read-through only, or a certificate issued after a short questionnaire |
| Is the scope proportionate? | Connection between business risks, services, customer population and testing | Identical package regardless of trust services, complexity or prior findings |
| Will the report support decisions? | Proposed structure covering scope, criteria, testing, evidence, findings, limitations and actions | Score or pass/fail result with no traceable basis |
| Are data controls appropriate? | Secure transfer, access, retention, deletion and incident arrangements | Uncontrolled email transfer or unnecessary collection of the full customer population |
| Is the commercial scope clear? | Entity, period, deliverables, dependencies, exclusions, change control and professional fee | Low headline price with key work deferred to undefined extras |
Independence questions to ask before appointment
- Did the proposed reviewer write the policy or build the workflow now being tested?
- Does the reviewer provide ongoing outsourced compliance or MLRO work to the TCSP?
- Who can change, suppress or delay a finding before it reaches senior management?
- How will separate remediation support be governed if weaknesses are identified?
- Will any subcontractor access customer files, and under what control?
- Can the provider explain why its team, resources and timetable are adequate for the proposed population and services?
Independence is not necessarily destroyed by every prior contact, but threats should be identified and addressed. Where a provider previously advised on a limited matter, management should understand whether the audit scope includes that work and what safeguards are available. Material self-review may require a different reviewer.
What credible testing should look like
A provider should first understand the TCSP’s business, services, institutional risk assessment, customer population, systems, prior findings and changes. Testing normally combines policy review, walkthroughs, risk-based customer files, central registers, monitoring, STR governance, training and management oversight. The sample should reflect relevant risk characteristics rather than only recent or tidy files.
Ask the provider to explain the proposed population, selection method, sample rationale and limits on extrapolation. The exact sample may change after planning, but the method should be intelligible. See the document checklist and report guide for practical evidence and output expectations.
Separate assurance from remediation
The independent report should identify what was tested and the conclusion supported by the evidence. If policy, forms, training or file remediation is also required, management should own the control and the additional work should be distinguished from the independent conclusion. A provider should not quietly rewrite documents during the audit and then report that the original control was effective.
Where the same firm assists with remediation, define separate responsibilities, personnel, approvals and follow-up testing. For material self-review threats, an independent party may be required for the final assurance. The remediation guide explains evidence, ownership and retesting.
How to compare proposals without reducing the decision to price
Normalise each proposal into the same headings: entity, period, services, regulatory criteria, risk work, population, sampling, interviews, deliverables, limitations, data handling, timetable, dependencies, exclusions and professional fee. A quote that includes a separate remediation package or follow-up review is not directly comparable with one covering the independent report only.
Ask what happens when records are missing, the population is unreliable or a material issue appears outside the initial sample. A credible provider should describe escalation and scope-change controls, not promise that every situation is included at the same price. See the cost and scope guide for the three initial facts and proposal comparison questions.
Final appointment checklist
- Record why an external provider is appropriate and how the appointment meets the independence requirement.
- Confirm the named team, competence, resources, conflicts and reporting line.
- Approve a risk-based scope tied to actual services, customers and prior issues.
- Agree secure access, retention and deletion arrangements before transferring records.
- Define the report, factual review, management response and limitation process.
- Keep remediation ownership with management and define any separate assistance.
- Retain the selection rationale, proposal and approval as part of the governance record.
The public disciplinary benchmark shows which recurring control failures a useful review should be capable of detecting. No appointment guarantees a regulatory outcome.
Frequently asked questions
Must a Hong Kong TCSP use an external audit provider?
Can the compliance officer or MLRO perform the independent audit?
Should a provider issue a compliance certificate?
Primary sources
Regulatory references were checked on 5 August 2026. Always consult the current official text for a live matter.