The Regulatory Framework
The Anti-Money Laundering and Counter-Terrorist Financing Ordinance, Cap 615 came into full operation in 2012. The AMLO established the legal framework for customer due diligence, record-keeping, reporting of suspicious transactions, and the suppression of the financing of terrorism. It created criminal offences for money laundering related to serious offences and for dealing with property or funds connected to terrorist activity. It also introduced a licensing regime for trust or company service providers.
Supervisory authorities issue detailed guidance. The SFC publishes AML/CFT Guidelines for Licensed Corporations. The HKMA issues analogous guidance for authorised institutions through its AML/CFT Guidelines and related supervisory manuals.
FATF 40 Recommendations form the international standard. Hong Kong is subject through its membership of the Asia/Pacific Group on Money Laundering (APG). The FATF’s Mutual Evaluation Report on Hong Kong, published in 2019, identified both strengths and areas requiring further attention.
The United Nations (Anti-Terrorism Measures) Ordinance, Cap 575 , and the United Nations (Sanctions) Ordinance, Cap 537 , further impose screening and freezing obligations on regulated entities.
Who Is Regulated Under the AMLO
| Entity Type | Supervisory Authority | Key Obligations |
|---|---|---|
| Banks and authorised institutions | HKMA (Banking Ordinance, Cap 155) | Full AML/CFT obligations under AMLO and HKMA guidance |
| Licensed corporations | SFC (Securities and Futures Ordinance, Cap 571) | SFC AML/CFT Guidelines for Licensed Corporations |
| Trust or company service providers (TCSPs) | Companies Registry | Licence under Part 16, Companies Ordinance, Cap 622; CDD and record-keeping |
| Insurers and insurance intermediaries | Insurance Authority (Insurance Ordinance, Cap 41) | AML/CFT obligations; particularly relevant for policies with investment features |
| Money service operators | Customs and Excise Department (Cap 615A) | Remittance, money-changing obligations |
| Dealers in precious metals and stones (DPMS) | Applicable supervisor | Cash transaction reporting above threshold |
Customer Due Diligence Obligations
The SFC AML/CFT Guidelines describe a risk-based approach to CDD.
Standard CDD requires identifying and verifying the customer’s identity using reliable, independent source documents, identifying and verifying the beneficial owner’s identity, and understanding the purpose and intended nature of the business relationship.
Enhanced due diligence (EDD) applies in higher-risk situations: relationships with PEPs, complex or unusually large transactions, and business relationships with persons from high-risk jurisdictions. EDD requires senior management approval before establishing or continuing the relationship, gathering additional information on source of funds and source of wealth, and enhanced ongoing monitoring.
Simplified CDD may be applied in lower-risk situations, but the conditions are restrictive. The risk assessment must genuinely support the lower-risk conclusion. Regulated entities cannot apply simplified measures on the basis of commercial convenience alone.
Beneficial Ownership Identification
Identifying the ultimate beneficial owner is one of the most operationally demanding aspects of AML/CFT compliance.
For legal persons, the relevant threshold is generally a holding of more than 25% of shares or voting rights. Where no natural person meets the ownership threshold, the entity must identify the natural person who exercises significant control over the legal person.
For trusts, the entity must identify settlors, trustees, protectors (where applicable), beneficiaries with a material interest, and any other natural person exercising ultimate effective control over the trust.
The practical challenge lies in accessing reliable information to verify beneficial ownership claims. Corporate structures can involve multiple layers of ownership across different jurisdictions.
Ongoing Monitoring Obligations
Section 12 of the AMLO and the SFC AML/CFT Guidelines require ongoing monitoring of business relationships.
Maintenance of customer information. When an entity becomes aware of a material change in a customer’s circumstances, the entity should update its records and reassess the applicable CDD measures.
Transaction monitoring. The systematic review of transactions against the customer’s established profile and against typologies and red flags identified in FATF guidance, SFC circulars, and the entity’s own risk assessment.
FraudShield provides transaction monitoring capabilities that can support compliance teams in meeting this obligation.
Politically Exposed Persons: Screening and Enhanced Obligations
The SFC AML/CFT Guidelines define three PEP categories.
Foreign PEPs. Individuals who are currently entrusted with prominent public functions in a foreign country or territory.
Domestic PEPs. Individuals who hold or have held equivalent positions within Hong Kong.
International organisation PEPs. Senior officials in organisations such as the World Bank, IMF, or United Nations.
The risk is not limited to the PEP themselves. Close associates and immediate family members are treated as presenting elevated risk. EDD measures apply when a customer or beneficial owner is a PEP: senior management approval, reasonable measures to establish source of wealth and source of funds, and enhanced ongoing monitoring.
MemberCheck provides PEP screening capabilities that support Hong Kong compliance teams in meeting these obligations.
Terrorist Financing Screening
The United Nations (Anti-Terrorism Measures) Ordinance, Cap 575, creates offences relating to the collection and use of funds for terrorist purposes. Regulated entities must implement controls to prevent terrorist financing, screen against UN Security Council sanctions designations, and freeze without delay the funds or assets of designated persons.
Suspicious Transaction Reporting and the JFIU
Where a regulated entity knows, suspects, or has reasonable grounds to suspect that a transaction is related to money laundering or terrorism financing, it must submit a suspicious transaction report (STR) to the Joint Financial Intelligence Unit (JFIU) without delay.
The tipping-off prohibition under Section 12 of the AMLO prohibits disclosing to another person information likely to prejudice an investigation following a report to the JFIU. Staff handling customer-facing communications in these situations require specific training.
Record-Keeping Requirements
Section 21 of the AMLO and the SFC AML/CFT Guidelines impose a mandatory seven-year retention period for records relating to CDD, transactions, and internal analysis of suspicious activity. Records must be retrievable without unreasonable delay if requested by a law enforcement authority or supervisory body.
SFC Supervisory Powers and Examination Expectations
The SFC has broad powers to examine, investigate, and take disciplinary action including revocation of licence, suspension, or financial penalties in cases of serious non-compliance.
Examinations typically assess whether AML/CFT policies and procedures are implemented, whether CDD measures are applied consistently, whether records are maintained and retrievable, whether staff are appropriately trained, and whether suspicious transactions are identified and reported in a timely manner.
TCSP Licensing Under the Companies Ordinance
The TCSP licensing regime, effective from March 2018, brought a previously largely unregulated sector within the formal AML/CFT perimeter. TCSPs must hold a licence from the Companies Registry and must comply with CDD and record-keeping obligations.
TCSPs must be alert to red flags such as requests to rush entity formation without clear commercial justification, reluctance to provide beneficial ownership information, or requests to act as a registered office for entities incorporated in high-risk jurisdictions.
Conclusion
Hong Kong’s AML/CFT regime under the AMLO is comprehensive, layered, and demanding. It places significant obligations on regulated entities across the financial and commercial sector, from initial CDD through to ongoing transaction monitoring, beneficial ownership identification, PEP management, terrorist financing screening, and the timely reporting of suspicious activity.
Regulated entities remain responsible for assessing their own risk profile, designing and implementing their AML/CFT controls, maintaining all required records, and ensuring that staff are trained and competent to identify and report suspicious activity. Technology solutions such as MemberCheck and FraudShield can support these obligations, but they are tools within a programme, not substitutes for the professional judgement and organisational accountability that Hong Kong law demands.
Hong Kong AML/CFT Requirements Under the AMLO: A Compliance Guide
A practical guide to AML/CFT obligations under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (AMLO), Cap 615. Covers CDD, PEP screening, STR reporting, TCSP licensing, and SFC supervisory expectations.
Speak to our teamThis article was accurate at the time of publication in August 2026 and is intended for general informational purposes only. It does not constitute legal, regulatory or compliance advice. Organisations should seek qualified professional guidance in relation to their specific obligations.




