Key answer
A decision-useful TCSP AML independent review report should explain the review objective, independence, period, scope, criteria, work performed, evidence tested, findings, limitations and recommended actions. It should distinguish control design from operating effectiveness, connect each finding to evidence and risk, and give senior management enough information to approve and monitor a proportionate remediation plan. It is not a generic certificate or a guarantee of regulatory compliance. A reader should be able to tell exactly what was tested and how the conclusion was reached.
Why report quality matters
The report is the durable record of what the independent function examined and concluded. A meeting or verbal assurance may be useful, but it does not allow management, a future reviewer or an authorised inspector to understand the exact scope, evidence and limitations.
The Companies Registry Guideline expects the independent audit function to assess the adequacy of the AML/CFT systems and risk-based approach, suspicious transaction reporting, the compliance function and staff awareness. A report should therefore show how the work addressed those areas or explain why an area was outside scope. A short document can be adequate for a simple firm, but brevity should not erase the evidence trail.
The essential sections
| Report section | What a useful section explains |
|---|---|
| Executive summary | Overall position, significant findings, priority actions and any urgent management decision. |
| Objective and criteria | Why the review was performed and the AMLO, Companies Registry guidance and internal rules used to assess controls. |
| Independence and competence | Who performed the work, reporting line, relevant expertise and material relationships or safeguards. |
| Period and scope | Business units, services, systems, control areas and review period covered or excluded. |
| Methodology | Interviews, walkthroughs, document inspection, data analysis, file sampling and other procedures. |
| Observations and findings | Condition, expected control, evidence, cause, impact or risk, and the reviewer’s conclusion. |
| Management response | Agreed action, accountable owner, target date and any reason management does not accept a recommendation. |
| Limitations | Missing records, unavailable personnel, restricted samples or other matters affecting assurance. |
| Follow-up | How completion will be evidenced and when higher-risk actions will be retested. |
Scope should reflect the TCSP’s real business
A report should not imply coverage of controls that were never relevant or tested. The planning section should identify whether the licensee provides company formation, company-secretarial, registered office, director, nominee, trust or other services; the approximate active customer population; material customer and jurisdiction risk; and major changes during the period.
For example, a firm that provides trust services may require work on settlors, trustees, protectors, beneficiaries and other persons who exercise ultimate control. A company-secretarial-only practice may have a different risk profile, but still needs appropriate customer, beneficial-owner, authorised-person, PEP, monitoring and record controls. The report should make this relationship between business model and testing explicit.
How to write a finding that management can act on
Labels such as “CDD weak” or “policy outdated” are not enough. A strong finding normally contains five connected elements:
- Expected position. Identify the applicable requirement, guidance or approved internal procedure.
- Condition. State what the reviewer actually observed, without exaggeration.
- Evidence and extent. Describe the records or samples supporting the observation and whether it is isolated or recurring.
- Risk and cause. Explain why the gap matters and, where evidence permits, what allowed it to occur.
- Action. Recommend a proportionate control outcome, not simply “ensure compliance”.
The example is illustrative, not a finding about any actual firm.
Rating findings without creating false precision
A rating framework helps management sequence work, but the report should define it. “High”, “medium” and “low” can otherwise mean different things to different readers. A practical framework may consider regulatory significance, customer or transaction exposure, control failure extent, likelihood of recurrence and the time needed to reduce the risk.
- Critical or high: a material or systemic weakness needing prompt senior-management attention.
- Medium: a meaningful deficiency that should be corrected through a dated plan and monitored.
- Low or improvement: a narrower weakness or enhancement that does not displace higher-priority action.
A report should not downgrade a statutory or significant control failure merely because no suspicious customer was found in the sample. Control effectiveness and customer misconduct are different questions.
Design effectiveness and operating effectiveness
Design effectiveness asks whether the control, if performed as intended, is capable of addressing the risk. Operating effectiveness asks whether the control was actually performed by the right person, at the right time, with sufficient evidence. A policy can be well designed while customer files show that it was not followed; conversely, staff may be doing useful work that the policy and forms do not accurately describe.
The report should state which conclusion is supported. If the reviewer only read policies, it should not claim that controls operated effectively. If sample records were unavailable, that is a limitation and may itself indicate a record-keeping concern.
Management response, closure and retesting
Management owns the AML/CFT systems and the remediation decision. The report should record an accountable owner and realistic target date for each agreed action. For material matters, closure should require more than an email saying “done”. Evidence may include an approved policy, revised workflow, completed back-book review, training attendance and testing, or a sample showing the new control operates.
Use the remediation framework to design follow-up. Before the review begins, the document checklist can reduce avoidable limitations. For context, read what an independent review examines and how it differs from statutory audit.
Frequently asked questions
Should the report give an overall pass or fail?
Should customer names appear in the main report?
Can the reviewer also prepare the remediation documents?
Primary sources
Regulatory references were checked on 28 July 2026. Always consult the current official text for a live matter.
- Companies Registry — Guideline on AML/CFT for TCSP Licensees (March 2025)
- Hong Kong e-Legislation — Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615)
- Companies Registry — Highlights of disciplinary cases
- FATF — Guidance for a Risk-Based Approach for Trust and Company Service Providers