Key answer
A Hong Kong TCSP AML/CFT policy manual should translate the AMLO and Companies Registry guidance into the firm’s actual operating controls. It should define governance, institutional and customer risk assessment, CDD and beneficial ownership, PEP and sanctions measures, EDD, ongoing monitoring, suspicious transaction reporting, record-keeping, staff training, independent review and change control. A generic template is not enough if staff cannot follow it or records do not evidence the stated process.
Begin with the business and risk model
The manual should identify the licensed entity, services, customer types, jurisdictions, delivery channels and governance structure to which it applies. A company-secretarial-only firm should not silently carry trust procedures it never uses; a trust service provider should not omit controls for settlors, trustees, protectors, beneficiaries and persons exercising ultimate control.
The Companies Registry Guideline expects an institutional ML/TF risk assessment that addresses customers, jurisdictions, products, services, transactions and delivery channels. The manual should explain how that assessment shapes controls and when it is updated, including the two-year cycle and material trigger events described in the March 2025 Guideline.
Recommended policy architecture
| Section | Core content |
|---|---|
| Purpose, scope and definitions | Entities, staff, services, systems, laws, guidance and key AML/CFT terms |
| Governance | Senior-management responsibility, CO, MLRO, deputies, escalation and reporting |
| Institutional risk assessment | Method, risk factors, approvals, review cycle, triggers and mitigation |
| Customer risk assessment | Factors, rating method, overrides, approvals, review frequency and evidence |
| CDD | Customer, beneficial owner, authorised person, purpose and intended nature |
| Screening and EDD | PEP, sanctions and other screening; potential matches; higher-risk measures and approvals |
| Ongoing monitoring | Ongoing CDD, transaction/activity review, triggers and unusual-activity enquiries |
| Suspicious transaction reporting | Internal escalation, MLRO review, JFIU reporting, confidentiality and tipping off |
| Records and data | Required records, retention, retrieval, access, outsourcing and secure disposal |
| People and assurance | Screening, role-based training, independent review, findings and remediation |
Governance, CO and MLRO responsibilities
The manual should name roles, not necessarily individuals, and state who approves the AML/CFT systems, receives material compliance issues, decides exceptions and monitors remediation. It should reflect the actual organisation chart and include cover arrangements.
The Companies Registry Guideline describes the CO as the focal point for oversight of AML/CFT activities and support to senior management. The MLRO is the central point for internal suspicious transaction reporting and contact with the JFIU and law enforcement. In a small firm, one person may hold more than one role, but the responsibilities, authority, access and conflicts still need to be managed and documented.
CDD, beneficial ownership and authorised persons
The CDD section should describe when due diligence is required and how the firm identifies and verifies the customer using reliable and independent information. It should explain how staff identify natural persons who ultimately own or control a legal person, understand ownership and control structures, and deal with senior managing officials where no natural person meets the controlling-ownership test.
For trusts and similar arrangements, the procedure should cover the relevant parties and ultimate control. For persons purporting to act on behalf of a customer, staff should identify and reasonably verify the person and verify authority—for example through an appropriate board resolution or written authorisation. The manual should also require information on the purpose and intended nature of the relationship.
Risk-based EDD, PEP and screening controls
The manual should not treat screening as a single screenshot at onboarding. It should identify what is screened, which sources or systems are used, when rescreening occurs, who decides potential matches, what evidence is retained and how changes trigger a customer risk review.
PEP procedures should reflect the categories and measures in the current Guideline. For non-Hong Kong PEP relationships, the Guideline describes senior-management approval, reasonable measures to establish source of wealth and source of funds, and enhanced ongoing monitoring. The treatment of Hong Kong and international-organisation PEPs is risk-based under the applicable framework. Staff should not assume that every PEP has identical risk or that a “no match” system result removes the need to understand ownership and control.
Ongoing monitoring and suspicious transaction reporting
Ongoing monitoring should cover keeping CDD information current, reviewing activity against the firm’s knowledge of the customer and examining complex, unusually large or unusual patterns with no apparent economic or lawful purpose. The process should define frequency by risk and identify trigger events such as ownership, director, service, jurisdiction or activity changes.
The STR section should give staff a clear internal reporting line, protect confidentiality and require the MLRO’s review and rationale to be documented. It should reflect the JFIU’s current STREAMS 2 arrangements for regulated entities, rather than obsolete email, fax or post instructions. Staff should understand that suspicion does not require proof of a specific predicate offence and that tipping off must be avoided.
Records, training and independent review
The manual should identify the CDD, transaction, risk, analysis, correspondence, internal report, training and management records to retain. The Companies Registry Guideline generally requires relevant CDD and transaction records throughout the relationship and for at least five years after it ends, subject to any longer period directed by the Registrar. Records held through intermediaries do not remove the TCSP’s responsibility.
Training should be role-based and include induction and regular refreshers. Effectiveness matters: attendance alone does not prove staff can identify unusual activity or follow the escalation process. The independent audit function, its reporting line and risk-based review cycle should also be described, together with how findings are tracked and closed.
Version control and the policy-to-evidence test
Every approved manual should show its owner, approver, version, effective date, next review date and change history. Review should be triggered by legal or regulatory change, new services or systems, material findings, organisational change or developments in the risk assessment.
- Confirm each procedure has a responsible role and approval point.
- Map each material rule to a form, system field or operating record.
- Remove obsolete clauses and preserve an approved change history.
Before approval, test each major rule against three questions: Is there a form, system or workflow that implements it? Can staff explain what they do? Is there a completed record proving it happened? This policy-to-evidence test exposes generic clauses that do not operate.
Related guidance: designing the onboarding and EDD pack, customer risk assessment, independent review and remediation after findings.
Frequently asked questions
Can a TCSP use a standard policy template?
How often should the policy be updated?
Is the policy manual itself enough to demonstrate compliance?
Primary sources
Regulatory references were checked on 28 July 2026. Always consult the current official text for a live matter.
- Companies Registry — Guideline on AML/CFT for TCSP Licensees (March 2025)
- Hong Kong e-Legislation — Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615)
- Joint Financial Intelligence Unit — How to identify and report suspicious transactions
- Companies Registry — Highlights of disciplinary cases