COMPLIANCE & ACCOUNTABILITY

Clear controls. Clear accountability.

A risk-based framework for the proposed remittance and money-changing business, aligning controls with its actual risks.

01 · Scope and readiness

This framework sets out intended AML/CFT principles with reference to Hong Kong’s Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615) and Customs guidance for MSOs. Implementation must reflect the actual business model.

Policy and implementation status

The MSO application is in progress. This framework is not a statement of licence approval, completed internal deployment or regulatory validation. Policy approval, appointments, tools, training and operational verification must be completed before commencement.

Hong Kong Customs: guidance for MSOs

02 · Governance and responsibilities

  • Management: approve policies and risk appetite, provide resources and review material risks and remediation.
  • Compliance Officer (CO): coordinate policies, review procedures, monitoring, training and control reviews, reporting to management.
  • Money Laundering Reporting Officer (MLRO): receive internal suspicious-activity reports, assess cases and report to the JFIU as applicable.
  • Business and operations staff: perform checks without bypassing controls, escalate unusual matters promptly and retain records.

Appointments, reporting lines, delegated authority and cover arrangements must be documented before commencement.

03 · Risk assessment and classification

Assess risks arising from customers, countries or regions, services, transaction characteristics and delivery channels. Document the assessment and align due diligence, approval and monitoring with the risk level.

Reassess risk when new services or channels, material business changes or important risk information arise.

04 · Customer due diligence (CDD)

  • Verify customer identity and the authority of representatives, and understand the purpose of the relationship.
  • Understand the legal structure, control, beneficial ownership and actual activities of legal entities.
  • Understand the purpose, sender, beneficiary, source of funds and proportionate supporting information.
  • Do not establish or continue the relevant arrangement when required checks cannot be completed; consider whether suspicion arises.

Anonymous, fictitious or deliberately concealed ownership is not accepted. Information purposes will be explained before collection.

05 · Enhanced checks, sanctions and PEPs

Apply enhanced due diligence (EDD) to higher-risk relationships or transactions, including further funds and wealth enquiries, appropriate management approval and enhanced monitoring.

At appropriate points, check relevant parties against applicable sanctions, terrorist designations, PEP information and relevant adverse information. Potential matches require human verification and escalation. PEP status is not itself unlawful; applicable risk-based requirements must be followed.

06 · Monitoring and unusual activity

Review the consistency of purpose and amount, payment and beneficiary information, unusual frequency, structuring, unexplained third-party payments and activity inconsistent with the customer’s business.

Record the basis for concerns, further information, reviews and outcomes. Staff must not remove controls without authority. Customer information and risk assessments should remain current.

07 · Suspicious reporting and confidentiality

Staff should promptly refer concerns and supporting information to the MLRO. Where statutory knowledge or suspicion arises, reporting must follow applicable requirements and the JFIU’s designated channel as soon as practicable; low value or an incomplete transaction does not remove a concern.

Handle reporting information on a need-to-know basis, avoid unlawful tipping-off and respond lawfully to authorities.

JFIU: suspicious activity and reporting information

08 · Records and data protection

Retain required due-diligence, transaction, approval and monitoring records from the applicable statutory starting point. Relevant regulated customer and transaction records generally require at least five years, subject to any lawful extension requirement.

Use role-appropriate access, confidentiality, secure storage and necessary backups so records are available for lawful review and protected against unauthorised use. The regulated-record rule does not automatically impose five-year retention on general website enquiries.

09 · Training, review and remediation

Provide role-appropriate training before commencement and on an ongoing basis, covering checks, unusual activity, reporting, confidentiality and updated requirements, with attendance and learning records.

Review controls regularly in light of risks and change. Arrange appropriately independent testing or review and report findings, owners, deadlines and remediation to management.

10 · Third parties and regulatory cooperation

Before using agents, outsourced services or third-party channels, assess qualifications, compliance and data protection, define contracts and responsibilities and maintain oversight. Outsourcing does not transfer the company’s compliance responsibility.

Cooperate lawfully with Hong Kong Customs and other relevant authorities, provide required records and reflect regulatory and business changes in policy updates.

Official reference material

Reference to official guidance does not imply regulatory approval or endorsement.

Version 1.0 · Updated 9 October 2026