Independent review document checklist

Hong Kong TCSP AML Independent Review Document Checklist 2026

A practical Hong Kong TCSP AML audit document checklist covering governance, risk, CDD files, monitoring, sampling and secure transfer.

Key answer

Prepare evidence in three groups: documents needed to understand the control framework, records used to test whether it operates, and conditional evidence relevant to the firm’s services and risks. Start with governance, the institutional risk assessment, AML/CFT policy, customer-population data, registers and prior findings. Then agree a risk-based customer-file sample and secure transfer process. Do not send an uncontrolled data dump or assume that a policy manual alone demonstrates effective implementation.

Start with a scoped request, not a data dump

The right document request depends on the services, active customer population, risk profile and review period. Before transferring records, confirm the legal entity under review, the business lines in scope, the relevant period, the secure exchange method and who is authorised to respond.

A staged request is usually more efficient. Stage one establishes governance, risk and process. Stage two selects customer files and exceptions based on that understanding. Stage three follows specific evidence gaps. This reduces unnecessary exposure of customer data and prevents the reviewer from choosing a sample without understanding the population.

Priority and evidence-readiness matrix

PriorityWhat belongs hereReadiness test
Core—prepare firstLicence and service profile, organisation and appointments, institutional risk assessment, current policy, customer population, prior reports and management actionsCurrent version, owner, approval and reporting period are identifiable; the document matches the actual business
Operating evidence—prepare for testingCustomer files, screening and EDD records, monitoring, STR governance, registers, training and quality-control resultsThe reviewer can trace a requirement from policy to workflow to a dated completed record
Conditional—prepare where relevantTrust and nominee controls, reliance or outsourcing, remote onboarding, group arrangements, new technology and higher-risk jurisdiction proceduresThe inclusion or exclusion follows the service inventory and institutional risk assessment
Exception and remediation evidenceOverdue reviews, missing-document logs, policy exceptions, complaints, incidents, findings, action plans and retestingThe affected population, owner, status, evidence and escalation are visible rather than hidden from the sample

A useful readiness assessment marks each item ready, available with follow-up, not applicable with a reason or missing. Calling a document “not applicable” should be supported by the service model and risk assessment, not used to avoid a difficult area.

Core governance and risk documents

Document or recordReadiness question
Current TCSP licence and service profileDo the documented services match what the firm actually provides?
Organisation chart and role appointmentsAre senior management, CO, MLRO, deputies and control owners identifiable?
Institutional ML/TF risk assessmentIs it approved, current and linked to customers, jurisdictions, services and delivery channels?
AML/CFT policy and proceduresAre version, approval, owner and effective date clear?
Management and compliance reportingCan the firm show oversight, exceptions, decisions and follow-up?
Previous review or inspection reportsAre findings, action owners, evidence and closure status available?
Customer population dataCan the firm produce an accurate list with service and risk attributes for sampling?

The Companies Registry Guideline expects institutional risk assessment to cover customer, country or jurisdiction, product, service, transaction and delivery-channel risk. If the assessment is only a generic template with no connection to the firm’s customer population, the reviewer will have difficulty relying on it.

Customer-file evidence

A complete customer file should tell a coherent story: who the customer is, who ultimately owns or controls it, who is authorised to act, why the relationship exists, how risk was assessed, what screening and verification occurred, what approvals were obtained and how the relationship has been monitored.

  • Customer identification and reliable independent verification.
  • Ownership and control structure, beneficial-owner identification and reasonable verification measures.
  • Identification and authority of persons purporting to act on behalf of the customer.
  • Purpose and intended nature of the business relationship.
  • Customer risk assessment, rationale, approval and review history.
  • PEP, sanctions, terrorist-financing and other screening records, including the disposition of potential matches.
  • EDD records for higher-risk relationships, including applicable senior-management approval and source-of-wealth/source-of-funds work.
  • Service agreements, material instructions and correspondence relevant to CDD or significant changes.
  • Ongoing CDD, monitoring, trigger reviews and unusual-activity enquiries.
  • Exit or termination records where the relationship ended.

The Guideline states that relevant CDD and transaction records should be kept throughout the relationship and generally for at least five years after the relationship ends. A reviewer should test both completeness and retrievability.

Registers, monitoring and control evidence

Customer files are only one part of the control environment. Prepare central or system-generated records that show consistent operation across the population:

  • customer master list and risk-rating distribution;
  • periodic-review and overdue-review reports;
  • PEP and sanctions screening logs, rescreening frequency and potential-match decisions;
  • higher-risk customer and EDD approval registers;
  • internal unusual-activity reports and the MLRO decision register, held with appropriate confidentiality;
  • STR records and relevant post-report monitoring controls;
  • policy exceptions, missing-document lists and quality-control results;
  • staff induction and refresher training content, attendance and effectiveness evidence;
  • outsourcing or reliance arrangements and oversight records; and
  • record-retention, access and destruction controls.

Where no event occurred—for example, no internal suspicion was reported—the reviewer may still test whether staff know the process, whether the forms and reporting line exist, and whether the absence is plausible in context.

Building a risk-based sample

A sample should not be selected only from the most recent or easiest files. Start with a reliable population and deliberately include relevant characteristics. Depending on the firm, these may include higher- and lower-risk customers, different services, PEP or potential-match cases, complex ownership, non-face-to-face onboarding, overseas exposure, overdue reviews, new and long-standing relationships, terminated customers and files handled by different staff.

Sample size is a matter of professional judgement. The number alone does not establish quality: ten homogenous low-risk files may provide less assurance than a smaller but deliberately stratified sample. The report should explain the population, selection method and limits on extrapolation.

Protecting confidential and personal information

Independent review involves sensitive information. Agree access, encryption, authorised users, retention and secure deletion before transfer. Use a secure portal or controlled workspace rather than ordinary messaging for customer identity records. Do not send passwords in the same channel as protected files.

Apply data minimisation. The reviewer may initially need a pseudonymised population with risk attributes, followed by selected files through a restricted channel. Working papers and the main report should avoid unnecessary personal data while still preserving an evidence trail. Suspicion and STR information requires especially careful handling to avoid inappropriate disclosure or tipping off.

Download the one-page document checklist

The printable checklist groups the principal records into governance and scope, population and sampling, customer-file evidence, and central-control evidence. It includes status boxes and a management action area so missing items are recorded rather than concealed.

Download the one-page checklist (PDF)

Use the PDF as a preparation aid only. The agreed request should still be tailored to the firm’s services, risk profile, review period and secure data arrangements.

A practical seven-step readiness plan

  1. Step 1: confirm scope, owner, secure workspace and document index.
  2. Step 2: validate the customer population and reconcile counts to operational records.
  3. Step 3: assemble governance, risk assessment, policy and prior findings.
  4. Step 4: export registers and monitoring exception reports.
  5. Step 5: perform an internal completeness check on likely sample categories.
  6. Step 6: record known gaps honestly, identify owners and avoid backdating or reconstructing evidence as if it were contemporaneous.
  7. Step 7: approve the transfer manifest and hold the opening walkthrough.

This plan is a preparation aid, not a fixed timetable. Steps may be combined or completed over a different period depending on complexity, document readiness and the agreed review scope.

For the broader context, read what the review tests, what the report should include, how the onboarding record should work and how to document customer risk.

Frequently asked questions

Should we correct incomplete files before the review?
You may remediate known gaps, but preserve an honest record of what was missing, when it was identified and what was done. Do not backdate forms or present reconstructed evidence as contemporaneous.
Must we send every customer file?
Usually not at the start. A risk-based population and sample can provide focused assurance while reducing unnecessary data transfer. Scope may expand if the initial work identifies systemic concerns.
What if records are held by an intermediary?
The Companies Registry Guideline states that the TCSP remains responsible for record-keeping where it relies on an intermediary and should be able to obtain the relevant data and documents promptly.

Primary sources

Regulatory references were checked on 14 August 2026. Always consult the current official text for a live matter.

  1. Companies Registry — Guideline on AML/CFT for TCSP Licensees (March 2025)
  2. Companies Registry — FAQ on the independent audit function (3 March 2025)
  3. Companies Registry — Highlights of disciplinary cases
  4. Hong Kong e-Legislation — Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615)
Scope note: This guide provides general information for Hong Kong TCSP licensees. It is not legal advice and does not determine the treatment of any particular customer or guarantee a regulatory outcome.