Hong Kong International Corporate Secretaries

AML programme requirements for Hong Kong TCSPs and accountants under Cap. 615

Learn the mandatory components of an AML compliance programme for Hong Kong TCSPs and accountants under Cap. 615, including CDD and record-keeping.

AML Programme Hong Kong TCSP and Accountant Compliance Requirements

Hong Kong’s anti-money laundering regime requires trust or company service providers (TCSPs) and accountants to maintain a formal AML programme. The statutory framework is the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615). An aml programme hong kong tcsp accountant must include written policies, procedures and controls that address customer due diligence, record keeping, risk assessment and suspicious transaction reporting. Failure to implement an adequate programme carries enforcement action and penalties.

Hong Kong AML Compliance Programme Requirements

Schedule 2 of Cap. 615 sets out the mandatory components. Every TCSP and accountant must establish and maintain six elements:

  • Written AML policies and procedures approved by senior management
  • A risk-based approach to customer due diligence
  • Ongoing monitoring of business relationships
  • Record keeping systems that meet the statutory retention period
  • Internal reporting procedures for suspicious transactions
  • Employee training on AML obligations

The programme must be documented and made available to staff. The Companies Registry and the Hong Kong Institute of Certified Public Accountants expect to see a formal AML manual during inspections. A generic template is insufficient. The manual must reflect the firm’s actual client base, service lines and risk profile. A firm serving only low-risk domestic clients needs a different programme from one incorporating companies in multiple jurisdictions. Regulators will test whether documented procedures match what staff do in practice.

Cap. 615 AML Programme TCSP

A TCSP licensed under Cap. 615 must appoint an AML compliance officer responsible for overseeing the programme and reporting to the board. The compliance officer must have sufficient seniority and access to resources. If the compliance officer is overruled on a CDD or reporting decision, the firm should document the disagreement and the reasons for the final decision. A compliance officer who is ignored but has no record of raising concerns remains exposed.

The programme must cover a written AML policy statement, a risk assessment methodology for clients, CDD procedures for new and existing clients, enhanced due diligence for higher-risk clients, record keeping procedures (minimum 6 years), suspicious transaction reporting procedures, and employee screening and training.

TCSPs must also maintain a significant controllers register for each corporate client. This obligation arises under the Companies Ordinance (Cap. 622) rather than Cap. 615. The designated representative for the register assists law enforcement with access to ownership information. A TCSP that fails to maintain the register or to identify a significant controller commits an offence under Cap. 622. The Companies Registry can inspect the register and issue a notice of non-compliance.

Hong Kong Accountant AML Obligations

Accountants holding a practising certificate from the HKICPA are subject to AML obligations under Cap. 615. The HKICPA issues its own AML guidelines. These mirror the requirements in Schedule 2 but are tailored to the accountancy profession. The guidelines set out specific expectations for client acceptance in audit, tax and advisory engagements. An accountant who accepts a client without completing CDD first risks disciplinary proceedings even if no money laundering occurs.

An accountant’s AML programme must address client acceptance procedures, including CDD before engagement, ongoing monitoring of existing clients, record keeping for 6 years after the business relationship ends, internal reporting of suspicious transactions to the designated officer, and training for all professional staff.

Accountants who provide trust or company services are treated as TCSPs and must also hold a TCSP licence. The dual-regulated status means compliance with both the HKICPA guidelines and the TCSP licensing requirements under Cap. 615. The HKICPA and the Companies Registry do not coordinate their inspections. A firm can pass one inspection and fail the other on the same facts. The AML programme must satisfy both sets of expectations.

Hong Kong AML Policy and Procedures

The written AML policy and procedures form the core of the programme. The policy must state the firm’s commitment to preventing money laundering and terrorist financing. The procedures must describe step-by-step how staff will identify and verify clients, determine whether a client is a politically exposed person, assess the source of funds and source of wealth, monitor transactions for unusual activity, report suspicious transactions to the Joint Financial Intelligence Unit, and keep records in a retrievable format.

Review the procedures regularly. Update them when the risk environment changes. A risk assessment of the firm’s client base and services should inform the level of CDD applied. The policy must also address what happens when CDD cannot be completed. Schedule 2 of Cap. 615 prohibits a TCSP or accountant from establishing or continuing a business relationship if CDD cannot be performed. The firm must terminate the relationship and consider whether a suspicious transaction report is warranted. The procedures must give staff clear instructions for this scenario.

Customer Due Diligence and Risk Assessment

CDD is the foundation of any AML programme. Under Schedule 2 of Cap. 615, TCSPs and accountants must identify the client and any beneficial owner, verify identity using reliable independent source documents, understand the purpose and intended nature of the business relationship, and conduct ongoing monitoring throughout the relationship.

Perform a risk assessment for each client. Higher-risk clients require enhanced due diligence. This includes clients from jurisdictions with weak AML controls and those involving complex ownership structures. Enhanced due diligence means obtaining additional information on the client’s background, the source of funds and the reasons for the transaction. It also means obtaining senior management approval before establishing or continuing the relationship. Document the risk assessment. Review it periodically. A client’s risk rating can change. A domestic trading company that begins transacting with a sanctioned jurisdiction moves from low risk to high risk. The programme must specify how and when staff reassess risk ratings.

Record Keeping for 6 Years

Cap. 615 requires TCSPs and accountants to keep records for at least 6 years after the business relationship ends. The records must include copies of identification documents obtained during CDD, records of transactions and account files, correspondence relating to the business relationship, and records of any suspicious transaction reports made to JFIU.

The records must be retrievable without undue delay. The 6-year retention period applies even if the client relationship ends earlier. Failure to maintain records is a criminal offence under Cap. 615. The obligation survives the dissolution of the firm. A sole practitioner who retires must still ensure records are kept for the remainder of the retention period. The programme should designate who holds that responsibility if the firm ceases to exist.

Suspicious Transaction Reporting to JFIU

Every AML programme must include procedures for reporting suspicious transactions. If a TCSP or accountant knows or suspects that a transaction involves proceeds of crime or terrorist financing, file a suspicious transaction report with the JFIU.

Make the report as soon as practicable after the suspicion arises. Designate a person responsible for submitting reports. Train staff to recognise red flags: unusual transaction patterns, inconsistent client behaviour, requests to circumvent normal procedures. The reporting obligation overrides any duty of confidentiality to the client. Cap. 615 provides a statutory defence for reports made in good faith. The programme must instruct staff not to tip off the client that a report has been made. Tipping off is a separate criminal offence. The procedures must explain how to handle client enquiries without revealing the existence of a report.

Enforcement and Penalties

The Companies Registry enforces AML compliance for TCSPs. The HKICPA enforces compliance for accountants. Both regulators conduct inspections and can impose sanctions.

Penalties for non-compliance include revocation or suspension of a TCSP licence, disciplinary action by the HKICPA including fines or removal from the register, and criminal prosecution under Cap. 615 with fines up to HK$500,000 and imprisonment for up to 7 years. The criminal penalties apply to individuals as well as firms. A compliance officer or a partner who turns a blind eye can be prosecuted personally. The defence of reasonable excuse requires evidence that the firm took its obligations seriously and implemented a programme that was appropriate for its risk profile.

Adequate documentation of the AML programme and its implementation is the best defence. Regulators expect to see evidence of training, risk assessments and CDD records during inspections.

Sources

More on ongoing compliance.

Common questions

Do I need a different AML programme for my accounting and TCSP work?

Yes, if you provide both services you must satisfy both sets of expectations. Accountants providing trust or company services are treated as TCSPs and must hold a TCSP licence. The AML programme must comply with both the HKICPA guidelines and the TCSP licensing requirements under Cap. 615, as inspections are not coordinated.

What happens if I can't complete customer due diligence on a client?

You must not establish or continue the business relationship. Schedule 2 of Cap. 615 prohibits proceeding if CDD cannot be performed. The firm must terminate the relationship and consider whether a suspicious transaction report is warranted. Your procedures must give staff clear instructions for this scenario.

How long do I have to keep AML records for?

You must keep records for at least 6 years after the business relationship ends. This includes CDD documents, transaction records, correspondence and suspicious transaction reports. The obligation survives the dissolution of the firm, and sole practitioners must ensure records are retained even after retirement.

Can I be prosecuted personally for AML failures?

Yes, criminal penalties under Cap. 615 apply to individuals as well as firms. A compliance officer or partner who turns a blind eye can be prosecuted personally. The defence of reasonable excuse requires evidence that you took obligations seriously and implemented a programme appropriate for your risk profile.

Get help with an upcoming or overdue filing

Tell us which deadline you are dealing with. Providers who handle that filing will come back to you.

We pass your enquiry to providers whose licence we have checked against the register that issued it. Free to you.