Policies and procedures

What Should Be Included in a Hong Kong TCSP AML/CFT Policy Manual?

A practical structure for a Hong Kong TCSP AML/CFT policy manual, covering governance, risk, CDD, monitoring, STRs, records, training and review.

Key answer

A Hong Kong TCSP AML/CFT policy manual should translate the AMLO and Companies Registry guidance into the firm’s actual operating controls. It should define governance, institutional and customer risk assessment, CDD and beneficial ownership, PEP and sanctions measures, EDD, ongoing monitoring, suspicious transaction reporting, record-keeping, staff training, independent review and change control. A generic template is not enough if staff cannot follow it or records do not evidence the stated process.

Begin with the business and risk model

The manual should identify the licensed entity, services, customer types, jurisdictions, delivery channels and governance structure to which it applies. A company-secretarial-only firm should not silently carry trust procedures it never uses; a trust service provider should not omit controls for settlors, trustees, protectors, beneficiaries and persons exercising ultimate control.

The Companies Registry Guideline expects an institutional ML/TF risk assessment that addresses customers, jurisdictions, products, services, transactions and delivery channels. The manual should explain how that assessment shapes controls and when it is updated, including the two-year cycle and material trigger events described in the March 2025 Guideline.

Recommended policy architecture

SectionCore content
Purpose, scope and definitionsEntities, staff, services, systems, laws, guidance and key AML/CFT terms
GovernanceSenior-management responsibility, CO, MLRO, deputies, escalation and reporting
Institutional risk assessmentMethod, risk factors, approvals, review cycle, triggers and mitigation
Customer risk assessmentFactors, rating method, overrides, approvals, review frequency and evidence
CDDCustomer, beneficial owner, authorised person, purpose and intended nature
Screening and EDDPEP, sanctions and other screening; potential matches; higher-risk measures and approvals
Ongoing monitoringOngoing CDD, transaction/activity review, triggers and unusual-activity enquiries
Suspicious transaction reportingInternal escalation, MLRO review, JFIU reporting, confidentiality and tipping off
Records and dataRequired records, retention, retrieval, access, outsourcing and secure disposal
People and assuranceScreening, role-based training, independent review, findings and remediation

Governance, CO and MLRO responsibilities

The manual should name roles, not necessarily individuals, and state who approves the AML/CFT systems, receives material compliance issues, decides exceptions and monitors remediation. It should reflect the actual organisation chart and include cover arrangements.

The Companies Registry Guideline describes the CO as the focal point for oversight of AML/CFT activities and support to senior management. The MLRO is the central point for internal suspicious transaction reporting and contact with the JFIU and law enforcement. In a small firm, one person may hold more than one role, but the responsibilities, authority, access and conflicts still need to be managed and documented.

CDD, beneficial ownership and authorised persons

The CDD section should describe when due diligence is required and how the firm identifies and verifies the customer using reliable and independent information. It should explain how staff identify natural persons who ultimately own or control a legal person, understand ownership and control structures, and deal with senior managing officials where no natural person meets the controlling-ownership test.

For trusts and similar arrangements, the procedure should cover the relevant parties and ultimate control. For persons purporting to act on behalf of a customer, staff should identify and reasonably verify the person and verify authority—for example through an appropriate board resolution or written authorisation. The manual should also require information on the purpose and intended nature of the relationship.

Risk-based EDD, PEP and screening controls

The manual should not treat screening as a single screenshot at onboarding. It should identify what is screened, which sources or systems are used, when rescreening occurs, who decides potential matches, what evidence is retained and how changes trigger a customer risk review.

PEP procedures should reflect the categories and measures in the current Guideline. For non-Hong Kong PEP relationships, the Guideline describes senior-management approval, reasonable measures to establish source of wealth and source of funds, and enhanced ongoing monitoring. The treatment of Hong Kong and international-organisation PEPs is risk-based under the applicable framework. Staff should not assume that every PEP has identical risk or that a “no match” system result removes the need to understand ownership and control.

Ongoing monitoring and suspicious transaction reporting

Ongoing monitoring should cover keeping CDD information current, reviewing activity against the firm’s knowledge of the customer and examining complex, unusually large or unusual patterns with no apparent economic or lawful purpose. The process should define frequency by risk and identify trigger events such as ownership, director, service, jurisdiction or activity changes.

The STR section should give staff a clear internal reporting line, protect confidentiality and require the MLRO’s review and rationale to be documented. It should reflect the JFIU’s current STREAMS 2 arrangements for regulated entities, rather than obsolete email, fax or post instructions. Staff should understand that suspicion does not require proof of a specific predicate offence and that tipping off must be avoided.

Records, training and independent review

The manual should identify the CDD, transaction, risk, analysis, correspondence, internal report, training and management records to retain. The Companies Registry Guideline generally requires relevant CDD and transaction records throughout the relationship and for at least five years after it ends, subject to any longer period directed by the Registrar. Records held through intermediaries do not remove the TCSP’s responsibility.

Training should be role-based and include induction and regular refreshers. Effectiveness matters: attendance alone does not prove staff can identify unusual activity or follow the escalation process. The independent audit function, its reporting line and risk-based review cycle should also be described, together with how findings are tracked and closed.

Version control and the policy-to-evidence test

Every approved manual should show its owner, approver, version, effective date, next review date and change history. Review should be triggered by legal or regulatory change, new services or systems, material findings, organisational change or developments in the risk assessment.

  • Confirm each procedure has a responsible role and approval point.
  • Map each material rule to a form, system field or operating record.
  • Remove obsolete clauses and preserve an approved change history.

Before approval, test each major rule against three questions: Is there a form, system or workflow that implements it? Can staff explain what they do? Is there a completed record proving it happened? This policy-to-evidence test exposes generic clauses that do not operate.

Related guidance: designing the onboarding and EDD pack, customer risk assessment, independent review and remediation after findings.

Frequently asked questions

Can a TCSP use a standard policy template?
A template can be a starting point, but it must be adapted to the licensed entity’s services, risks, governance, systems and actual procedures. Unsupported or irrelevant clauses can create a policy-to-practice gap.
How often should the policy be updated?
Set a regular review cycle and update sooner when legal guidance, services, systems, risk exposure, roles or material findings change. The date and rationale for each review should be recorded.
Is the policy manual itself enough to demonstrate compliance?
No. The manual states the intended controls. Management also needs completed forms, approvals, screening, monitoring, escalation, training and other records showing that those controls operate.

Primary sources

Regulatory references were checked on 28 July 2026. Always consult the current official text for a live matter.

  1. Companies Registry — Guideline on AML/CFT for TCSP Licensees (March 2025)
  2. Hong Kong e-Legislation — Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615)
  3. Joint Financial Intelligence Unit — How to identify and report suspicious transactions
  4. Companies Registry — Highlights of disciplinary cases
Scope note: This guide provides general information for Hong Kong TCSP licensees. It is not legal advice and does not determine the treatment of any particular customer or guarantee a regulatory outcome.