Provider selection and independence

How to Choose an AML/CFT Independent Audit Provider for a Hong Kong TCSP

A practical framework for comparing Hong Kong TCSP AML audit providers on independence, expertise, testing, reporting, data handling and scope.

Key answer

Choose a Hong Kong TCSP AML/CFT audit provider by testing five things: independence from the controls under review, relevant TCSP expertise, a risk-based scope that includes operating evidence, a decision-useful report, and secure handling of confidential records. Ask who will do the work, how files will be sampled, what limitations will be disclosed and how findings will be supported. Do not select on a certificate, generic checklist or headline price alone; the Companies Registry focuses on an effective independent audit function, not a particular commercial label.

Start with the regulatory test

Paragraphs 3.11 to 3.13 of the Companies Registry’s March 2025 Guideline set the foundation. The function should communicate directly with senior management, have sufficient expertise and resources, and independently review whether AML/CFT systems are effective. The FAQ states that internal staff or external parties may perform the role, but the reviewer must be independent of the functions or parties being examined. A compliance officer or MLRO cannot simultaneously perform the independent audit function.

This means “external” is not enough by itself. Management should understand who actually performs the work, whether that person designed or operates the controls, what conflicts exist and whether findings can be reported without filtering by the control owner.

A seven-part provider comparison

QuestionEvidence to requestWarning sign
Is the reviewer independent?Team roles, conflicts assessment, prior work and direct reporting lineThe same person designed, operates and concludes on the controls without safeguards
Does the team understand Hong Kong TCSP requirements?Named reviewer, relevant experience and familiarity with the March 2025 Guideline and AMLOGeneric financial-crime claims with no TCSP-specific methodology
Will the work test operation?Walkthrough, population, risk-based sampling and evidence planPolicy read-through only, or a certificate issued after a short questionnaire
Is the scope proportionate?Connection between business risks, services, customer population and testingIdentical package regardless of trust services, complexity or prior findings
Will the report support decisions?Proposed structure covering scope, criteria, testing, evidence, findings, limitations and actionsScore or pass/fail result with no traceable basis
Are data controls appropriate?Secure transfer, access, retention, deletion and incident arrangementsUncontrolled email transfer or unnecessary collection of the full customer population
Is the commercial scope clear?Entity, period, deliverables, dependencies, exclusions, change control and professional feeLow headline price with key work deferred to undefined extras

Independence questions to ask before appointment

  • Did the proposed reviewer write the policy or build the workflow now being tested?
  • Does the reviewer provide ongoing outsourced compliance or MLRO work to the TCSP?
  • Who can change, suppress or delay a finding before it reaches senior management?
  • How will separate remediation support be governed if weaknesses are identified?
  • Will any subcontractor access customer files, and under what control?
  • Can the provider explain why its team, resources and timetable are adequate for the proposed population and services?

Independence is not necessarily destroyed by every prior contact, but threats should be identified and addressed. Where a provider previously advised on a limited matter, management should understand whether the audit scope includes that work and what safeguards are available. Material self-review may require a different reviewer.

What credible testing should look like

A provider should first understand the TCSP’s business, services, institutional risk assessment, customer population, systems, prior findings and changes. Testing normally combines policy review, walkthroughs, risk-based customer files, central registers, monitoring, STR governance, training and management oversight. The sample should reflect relevant risk characteristics rather than only recent or tidy files.

Ask the provider to explain the proposed population, selection method, sample rationale and limits on extrapolation. The exact sample may change after planning, but the method should be intelligible. See the document checklist and report guide for practical evidence and output expectations.

Separate assurance from remediation

The independent report should identify what was tested and the conclusion supported by the evidence. If policy, forms, training or file remediation is also required, management should own the control and the additional work should be distinguished from the independent conclusion. A provider should not quietly rewrite documents during the audit and then report that the original control was effective.

Where the same firm assists with remediation, define separate responsibilities, personnel, approvals and follow-up testing. For material self-review threats, an independent party may be required for the final assurance. The remediation guide explains evidence, ownership and retesting.

How to compare proposals without reducing the decision to price

Normalise each proposal into the same headings: entity, period, services, regulatory criteria, risk work, population, sampling, interviews, deliverables, limitations, data handling, timetable, dependencies, exclusions and professional fee. A quote that includes a separate remediation package or follow-up review is not directly comparable with one covering the independent report only.

Ask what happens when records are missing, the population is unreliable or a material issue appears outside the initial sample. A credible provider should describe escalation and scope-change controls, not promise that every situation is included at the same price. See the cost and scope guide for the three initial facts and proposal comparison questions.

Final appointment checklist

  1. Record why an external provider is appropriate and how the appointment meets the independence requirement.
  2. Confirm the named team, competence, resources, conflicts and reporting line.
  3. Approve a risk-based scope tied to actual services, customers and prior issues.
  4. Agree secure access, retention and deletion arrangements before transferring records.
  5. Define the report, factual review, management response and limitation process.
  6. Keep remediation ownership with management and define any separate assistance.
  7. Retain the selection rationale, proposal and approval as part of the governance record.

The public disciplinary benchmark shows which recurring control failures a useful review should be capable of detecting. No appointment guarantees a regulatory outcome.

Frequently asked questions

Must a Hong Kong TCSP use an external audit provider?
Not in every case. The Companies Registry FAQ says internal staff or external parties may assume the role, provided the function is independent, sufficiently expert and resourced, and reports directly to senior management. External assistance should be used where the TCSP cannot meet those conditions internally.
Can the compliance officer or MLRO perform the independent audit?
No. The Companies Registry FAQ states that the compliance officer or MLRO cannot perform the independent audit function at the same time because the function must be independent of the parties being reviewed.
Should a provider issue a compliance certificate?
A commercial provider may use its own labels, but management should focus on scope, evidence, findings and limitations. The Companies Registry guidance describes an effective independent audit function; it does not say that a provider-branded certificate guarantees compliance or a regulatory result.

Primary sources

Regulatory references were checked on 5 August 2026. Always consult the current official text for a live matter.

  1. Companies Registry — Guideline on AML/CFT for TCSP Licensees (March 2025)
  2. Companies Registry — FAQ on the independent audit function (3 March 2025)
  3. Companies Registry — Highlights of disciplinary cases
  4. Hong Kong e-Legislation — Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615)
Scope note: This guide provides general information for Hong Kong TCSP licensees. It is not legal advice and does not determine the treatment of any particular customer or guarantee a regulatory outcome.