Reporting and assurance

What Should a TCSP AML Independent Review Report Include?

See the essential sections of a Hong Kong TCSP AML independent review report, from scope and testing to findings, limitations and action plans.

Key answer

A decision-useful TCSP AML independent review report should explain the review objective, independence, period, scope, criteria, work performed, evidence tested, findings, limitations and recommended actions. It should distinguish control design from operating effectiveness, connect each finding to evidence and risk, and give senior management enough information to approve and monitor a proportionate remediation plan. It is not a generic certificate or a guarantee of regulatory compliance. A reader should be able to tell exactly what was tested and how the conclusion was reached.

Why report quality matters

The report is the durable record of what the independent function examined and concluded. A meeting or verbal assurance may be useful, but it does not allow management, a future reviewer or an authorised inspector to understand the exact scope, evidence and limitations.

The Companies Registry Guideline expects the independent audit function to assess the adequacy of the AML/CFT systems and risk-based approach, suspicious transaction reporting, the compliance function and staff awareness. A report should therefore show how the work addressed those areas or explain why an area was outside scope. A short document can be adequate for a simple firm, but brevity should not erase the evidence trail.

The essential sections

Report sectionWhat a useful section explains
Executive summaryOverall position, significant findings, priority actions and any urgent management decision.
Objective and criteriaWhy the review was performed and the AMLO, Companies Registry guidance and internal rules used to assess controls.
Independence and competenceWho performed the work, reporting line, relevant expertise and material relationships or safeguards.
Period and scopeBusiness units, services, systems, control areas and review period covered or excluded.
MethodologyInterviews, walkthroughs, document inspection, data analysis, file sampling and other procedures.
Observations and findingsCondition, expected control, evidence, cause, impact or risk, and the reviewer’s conclusion.
Management responseAgreed action, accountable owner, target date and any reason management does not accept a recommendation.
LimitationsMissing records, unavailable personnel, restricted samples or other matters affecting assurance.
Follow-upHow completion will be evidenced and when higher-risk actions will be retested.

Scope should reflect the TCSP’s real business

A report should not imply coverage of controls that were never relevant or tested. The planning section should identify whether the licensee provides company formation, company-secretarial, registered office, director, nominee, trust or other services; the approximate active customer population; material customer and jurisdiction risk; and major changes during the period.

For example, a firm that provides trust services may require work on settlors, trustees, protectors, beneficiaries and other persons who exercise ultimate control. A company-secretarial-only practice may have a different risk profile, but still needs appropriate customer, beneficial-owner, authorised-person, PEP, monitoring and record controls. The report should make this relationship between business model and testing explicit.

How to write a finding that management can act on

Labels such as “CDD weak” or “policy outdated” are not enough. A strong finding normally contains five connected elements:

  1. Expected position. Identify the applicable requirement, guidance or approved internal procedure.
  2. Condition. State what the reviewer actually observed, without exaggeration.
  3. Evidence and extent. Describe the records or samples supporting the observation and whether it is isolated or recurring.
  4. Risk and cause. Explain why the gap matters and, where evidence permits, what allowed it to occur.
  5. Action. Recommend a proportionate control outcome, not simply “ensure compliance”.
Example structure: “Three of six higher-risk files tested did not contain evidence of the documented source-of-wealth enquiry required by the firm’s EDD procedure. Without that evidence, management cannot demonstrate that the enhanced measures were completed. Management should define the evidence standard, remediate the affected files, identify whether other files share the gap and introduce a pre-approval completeness check.”

The example is illustrative, not a finding about any actual firm.

Rating findings without creating false precision

A rating framework helps management sequence work, but the report should define it. “High”, “medium” and “low” can otherwise mean different things to different readers. A practical framework may consider regulatory significance, customer or transaction exposure, control failure extent, likelihood of recurrence and the time needed to reduce the risk.

  • Critical or high: a material or systemic weakness needing prompt senior-management attention.
  • Medium: a meaningful deficiency that should be corrected through a dated plan and monitored.
  • Low or improvement: a narrower weakness or enhancement that does not displace higher-priority action.

A report should not downgrade a statutory or significant control failure merely because no suspicious customer was found in the sample. Control effectiveness and customer misconduct are different questions.

Design effectiveness and operating effectiveness

Design effectiveness asks whether the control, if performed as intended, is capable of addressing the risk. Operating effectiveness asks whether the control was actually performed by the right person, at the right time, with sufficient evidence. A policy can be well designed while customer files show that it was not followed; conversely, staff may be doing useful work that the policy and forms do not accurately describe.

The report should state which conclusion is supported. If the reviewer only read policies, it should not claim that controls operated effectively. If sample records were unavailable, that is a limitation and may itself indicate a record-keeping concern.

Management response, closure and retesting

Management owns the AML/CFT systems and the remediation decision. The report should record an accountable owner and realistic target date for each agreed action. For material matters, closure should require more than an email saying “done”. Evidence may include an approved policy, revised workflow, completed back-book review, training attendance and testing, or a sample showing the new control operates.

Use the remediation framework to design follow-up. Before the review begins, the document checklist can reduce avoidable limitations. For context, read what an independent review examines and how it differs from statutory audit.

Frequently asked questions

Should the report give an overall pass or fail?
An overall conclusion may be useful if the criteria and limitations are clear, but a simple pass/fail label can hide important differences between control areas. The evidence, findings and required actions remain essential.
Should customer names appear in the main report?
Usually the report can use controlled sample references and keep detailed personal data in a restricted working-paper schedule. The format should support evidence while applying appropriate confidentiality and data-minimisation controls.
Can the reviewer also prepare the remediation documents?
Remediation support can be separately agreed, but independence threats should be identified and managed. Management remains responsible for approving and operating the controls, and later assurance should not amount to uncritical review of the reviewer’s own work.

Primary sources

Regulatory references were checked on 28 July 2026. Always consult the current official text for a live matter.

  1. Companies Registry — Guideline on AML/CFT for TCSP Licensees (March 2025)
  2. Hong Kong e-Legislation — Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615)
  3. Companies Registry — Highlights of disciplinary cases
  4. FATF — Guidance for a Risk-Based Approach for Trust and Company Service Providers
Scope note: This guide provides general information for Hong Kong TCSP licensees. It is not legal advice and does not determine the treatment of any particular customer or guarantee a regulatory outcome.