Independent review fundamentals

What Is an AML Independent Review for a Hong Kong TCSP?

A practical guide to Hong Kong TCSP AML independent reviews: purpose, scope, evidence, independence, process and management outcomes.

Key answer

An AML/CFT independent review is an objective assessment of whether a Hong Kong trust or company service provider’s AML/CFT systems are appropriately designed and operating effectively. It is not merely a check that a policy manual exists. A useful review tests governance, risk assessment, customer due diligence, ongoing monitoring, suspicious transaction reporting, record-keeping and staff awareness against the TCSP’s actual business and risk profile. It should leave management with evidenced conclusions, prioritised actions and a transparent record of any scope limitations.

The regulatory basis for an independent review

The Companies Registry’s March 2025 AML/CFT Guideline says that a TCSP licensee’s AML/CFT systems should include an independent audit function. Paragraphs 3.11 to 3.13 explain that the function should have a direct line of communication to senior management, sufficient expertise and resources, and responsibility for independent reviews of the licensee’s AML/CFT systems.

The same paragraphs identify four minimum areas of attention: adequacy of the AML/CFT systems and risk-based approach, effectiveness of suspicious transaction reporting, effectiveness of the compliance function, and staff awareness. The frequency and extent of the review should be proportionate to the nature, size and complexity of the business and its money-laundering and terrorist-financing risks. The Guideline does not prescribe one universal annual timetable for every TCSP.

Important distinction: the regulatory expectation is for an effective, risk-appropriate independent audit function. Whether a particular firm should review every year, every two years or after a material trigger requires a documented assessment of its own circumstances.

What an effective review examines

A well-scoped review connects written rules to operational evidence. The reviewer should be able to follow a control from the policy, to the form or workflow, to a completed customer file, and finally to management oversight. Typical review areas include:

Control areaWhat the reviewer asksIllustrative evidence
GovernanceAre AML/CFT responsibilities clear and escalations effective?Appointments, reporting lines, management minutes and compliance reports
Risk assessmentDo institutional and customer assessments drive proportionate controls?Risk methodology, approvals, customer ratings and trigger reviews
CDD and beneficial ownershipCan the firm identify the customer, ultimate controllers and authorised persons?Identification records, ownership charts, verification evidence and authorities
Screening and EDDAre PEP, sanctions and higher-risk cases identified and handled?Search results, match dispositions, source-of-wealth evidence and approvals
Ongoing monitoringAre records refreshed and unusual activity considered?Periodic reviews, trigger events, exception logs and follow-up enquiries
STR arrangementsCan staff recognise, escalate and document suspicion without tipping off?Internal reports, MLRO decisions, registers and training records
Record-keepingIs the audit trail complete, retrievable and retained for the required period?CDD files, correspondence, analysis records and retention controls

Independence is more than using an external provider

Independence is about objectivity and freedom from reviewing one’s own work. An external reviewer can provide useful separation, but the label “external” does not by itself establish competence or independence. Equally, an internal person may be able to perform the function if the role, reporting line, expertise and conflicts are appropriately managed.

Before appointing a reviewer, management should consider whether the person helped design or operate the controls being tested, whether findings can be reported directly to senior management, whether the reviewer understands Hong Kong TCSP obligations, and whether the scope provides access to enough evidence. A reviewer who only edits the policy manual cannot independently conclude that the controls operate effectively.

How the review normally proceeds

  1. Scope and planning. Confirm the business model, customer population, services, risk profile, prior review history and material changes.
  2. Document request. Obtain the current policy, risk assessments, registers, training records and other control evidence.
  3. Walkthroughs. Understand how onboarding, screening, approvals, monitoring and escalation work in practice.
  4. Risk-based file testing. Select customer files that reflect relevant risk categories and services, rather than choosing only easy or complete files.
  5. Evaluation. Compare design and implementation with the AMLO, applicable guidance and the firm’s own procedures.
  6. Reporting. Set out evidence, findings, risk, recommendations and management actions clearly.
  7. Follow-up. Track remediation and, for material matters, verify that the fix operates rather than merely exists on paper.

See the detailed document readiness checklist and the guide to what a review report should contain.

What the review should produce for management

The central output is a decision-useful report, not a certificate or guarantee of regulatory outcome. Management should be able to see what was tested, what evidence was available, where controls are effective, where gaps exist, and which actions should be prioritised. Limitations—such as missing records, unavailable samples or an excluded service line—should be stated rather than hidden.

A review may also reveal that the policy, onboarding pack or risk assessment needs updating. Those remediation deliverables are separate from the independent conclusion and should not be allowed to blur who owns the control. Read more about remediation after findings and the difference between an AML review and a statutory audit.

Frequently asked questions

Is an AML independent review the same as a statutory audit?
No. A statutory audit focuses on financial statements under its applicable reporting framework. An AML/CFT independent review examines the design and effectiveness of AML/CFT systems and evidence.
Must every Hong Kong TCSP obtain an external review every year?
The Companies Registry Guideline calls for an independent audit function and regular review, with frequency and extent proportionate to the business and its ML/TF risks. It does not state one identical annual timetable for every TCSP.
Does a clean review guarantee that the regulator will find no issues?
No. A review is based on an agreed scope, evidence and point-in-time testing. It can provide assurance and identify improvements, but it cannot guarantee a future regulatory outcome.

Primary sources

Regulatory references were checked on 28 July 2026. Always consult the current official text for a live matter.

  1. Companies Registry — Guideline on AML/CFT for TCSP Licensees (March 2025)
  2. Hong Kong e-Legislation — Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615)
  3. Companies Registry — Highlights of disciplinary cases
  4. FATF — Guidance for a Risk-Based Approach for Trust and Company Service Providers
Scope note: This guide provides general information for Hong Kong TCSP licensees. It is not legal advice and does not determine the treatment of any particular customer or guarantee a regulatory outcome.