TCSP Anti-Money Laundering Obligations Under Cap. 615 in Hong Kong
Understand the anti-money laundering obligations for Hong Kong TCSPs under Cap. 615, including CDD, record keeping, and suspicious transaction reporting.
TCSP Anti-Money Laundering Obligations Hong Kong
A licensed trust or company service provider in Hong Kong must comply with statutory anti-money laundering obligations under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615). These obligations bite from the moment a client is onboarded and continue throughout the business relationship. The Registrar of Companies is the supervisory authority for TCSP licensees and enforces compliance with the AMLO.
Hong Kong TCSP AML Requirements
The AMLO (Cap. 615) sets out the core anti-money laundering and counter-terrorist financing requirements for TCSP licensees. Every licensed TCSP must establish and maintain policies, procedures and controls to prevent money laundering and terrorist financing. These measures must be documented and approved by senior management. The Registrar of Companies may inspect a licensee’s AML systems at any time and can impose sanctions for non-compliance, including licence suspension or revocation.
Hong Kong Trust and Company Service Provider AML
A trust and company service provider in Hong Kong must apply a risk-based approach to its AML obligations. The TCSP must assess the money laundering and terrorist financing risks associated with each client, jurisdiction, product and delivery channel. That assessment must be documented and kept up to date. Higher-risk clients require enhanced due diligence measures, such as those from jurisdictions with weak AML controls or those involving complex ownership structures.
Hong Kong AMLO Obligations for TCSP
The AMLO obligations for a TCSP divide into four areas: customer due diligence, record keeping, ongoing monitoring, and suspicious transaction reporting. Each area carries specific statutory requirements. Failure to comply with any of these obligations is an offence under Cap. 615 and can result in a fine of up to HK$1,000,000 and imprisonment for up to seven years.
Customer Due Diligence (CDD)
A TCSP must perform customer due diligence before establishing a business relationship or carrying out a transaction. The CDD measures include:
- Identifying the customer and verifying their identity using reliable, independent source documents, data or information.
- Identifying the beneficial owner of the customer and taking reasonable measures to verify that person’s identity.
- Understanding the ownership and control structure of the customer.
- Obtaining information on the purpose and intended nature of the business relationship.
For a corporate client, the TCSP must identify the natural persons who ultimately own or control the entity. Trace through any intermediate entities to reach the individual beneficial owner. If the beneficial owner is a politically exposed person (PEP), the TCSP must apply enhanced due diligence measures, including establishing the source of wealth and funds.
Record Keeping
A TCSP must keep records of all CDD information and transaction documents for a prescribed period. The AMLO requires records to be retained for at least five years after the business relationship ends or after the date of the transaction. The records must be sufficient to allow reconstruction of individual transactions and to provide evidence of the CDD measures taken. The TCSP must also keep copies of all suspicious transaction reports made to the Joint Financial Intelligence Unit (JFIU).
Ongoing Monitoring
A TCSP must conduct ongoing monitoring of its business relationships. This means scrutinising transactions undertaken throughout the relationship to ensure they are consistent with the TCSP’s knowledge of the customer, their business and risk profile. CDD information must be kept up to date. Review and update it at least annually, or when a trigger event occurs, a change in ownership or control, for instance. Apply enhanced monitoring to complex or unusually large transactions and to transactions that have no apparent economic or lawful purpose.
Suspicious Transaction Reports
A TCSP must report any transaction or attempted transaction that it knows or suspects involves proceeds of crime or terrorist financing. The report must be made to the JFIU as soon as is reasonably practicable. Do not disclose to the customer or any third party that a suspicious transaction report has been made. Failure to report a suspicious transaction is an offence under Cap. 615.
Risk Assessment and Policies
Every TCSP must conduct a business-wide risk assessment to identify and evaluate the money laundering and terrorist financing risks it faces. The risk assessment must consider the types of clients the TCSP serves, the jurisdictions in which the TCSP or its clients operate, the products and services the TCSP offers, and the delivery channels used. Based on that assessment, the TCSP must develop and implement written policies, procedures and controls to manage and mitigate the identified risks. Senior management must approve these policies. They must be reviewed regularly.
Consequences of Non-Compliance
The Registrar of Companies has enforcement powers under Cap. 615. If a TCSP licensee fails to comply with its AML obligations, the Registrar may issue a warning or direction, impose a financial penalty, suspend or revoke the TCSP licence, or refer the matter to the police or the JFIU for criminal investigation. Criminal penalties for non-compliance include a fine of up to HK$1,000,000 and imprisonment for up to seven years for individuals. For bodies corporate, the fine reaches HK$5,000,000. Directors and officers of a TCSP may also be personally liable if the offence was committed with their consent or connivance.
Role of the Registrar of Companies
The Registrar of Companies is the supervisory authority for TCSP licensees under Cap. 615. The Registrar maintains a public register of TCSP licensees, conducts inspections, and enforces compliance with the AMLO. Licensees must cooperate with any inspection and provide access to records, premises and personnel as required. The Registrar may also issue guidelines and codes of practice.
Practical Steps for Compliance
A TCSP should take the following steps to meet its AML obligations:
- Appoint a compliance officer responsible for AML policies and procedures.
- Provide regular training to all staff on AML obligations and suspicious transaction reporting.
- Implement a system for monitoring transactions and identifying unusual activity.
- Establish a clear process for making suspicious transaction reports to the JFIU.
- Conduct periodic reviews of the AML framework to ensure it remains effective and up to date.
The Companies Registry website (cr.gov.hk) and the TCSP Licensee Register (tcsp.cr.gov.hk) provide further guidance and resources for licensees.
Sources
More on the company secretary role.