(AML/CTF, Sanctions & TCSP Compliance)

PRACTICAL IMPLEMENTATION GUIDE

The decision is about evidence that controls operate

On 30 June 2026, the Registrar of Companies publicly reprimanded CY BUSINESS CONSULTANT LIMITED, licence number TC010309 (previously TC006635), and imposed a pecuniary penalty of HK$25,000. The Registry recorded three contraventions: inadequate and improper AML/CTF policies, procedures and controls evidenced by policy statements or other written documents; failure to establish and maintain effective procedures for the specified Schedule 2 duties; and failure to take all reasonable measures to ensure proper safeguards exist to prevent breaches and mitigate money-laundering and terrorist-financing risk.[1]

The useful lesson is not “keep better policies.” That instruction is too vague to change practice. The decision points to an evidence chain: licence condition and statutory duty → written control → staff workflow → client-file evidence → sample testing → management challenge and remediation. If any link is absent, a licence holder may be unable to demonstrate that the safeguard exists and works.

The Registry’s public case summary does not identify a particular customer, transaction, failure to file a suspicious-transaction report, or specific customer-due-diligence event. It should not be described as proof of a particular customer-level breach. The article therefore uses the decision for what it establishes: a concrete example of policy-to-practice, procedure and safeguard obligations in the TCSP framework, and a basis for designing controls that can be tested.

What the Registrar recorded—and what it did not record

The first recorded contravention concerned Condition 2 of the licence imposed by the Registrar under section 53J of the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (AMLO). The Registry states that the licensee failed to put in place adequate and proper AML/CTF policies, procedures and controls, evidenced by policy statements or other written documents.[1] The wording matters. A verbal expectation, an undated template or an unowned external manual may not show that the licensee’s own controls exist and are fit for its services.

The second recorded contravention was section 19(3) of Schedule 2: failure to establish and maintain effective procedures, not inconsistent with AMLO, for carrying out duties under sections 3, 4, 5, 9, 10 and 15 of Schedule 2. The third was section 23 of Schedule 2: failure to take all reasonable measures to ensure proper safeguards exist to prevent a contravention of a Part 2 or Part 3 requirement and to mitigate money-laundering and terrorist-financing risks.[1] These are connected but different questions: is the policy documented; are there effective procedures; and do the safeguards actually prevent or mitigate failure?

The TCSP AML/CTF Guideline issued by the Registrar can help licensees translate obligations into procedures. It is guidance issued under section 7 of AMLO, not a substitute for the statute or licence conditions.[2] A firm should therefore map its controls to the binding duty first, then use guidance to design practical workflows and evidence standards.

1. Map each obligation to an owned written control

Begin with a compliance inventory. Identify the TCSP licence holder, services within the licence perimeter, current licence conditions, applicable AMLO Schedule 2 duties, policy documents, work instructions, forms, systems, responsible officers and next review dates. This inventory should answer a simple question: which approved document tells staff what to do when a particular AML/CTF trigger occurs?

A written policy should do more than restate legislation. It should identify the firm’s risk governance, client-acceptance principles, customer due-diligence process, beneficial-owner procedures, non-face-to-face controls where relevant, ongoing-monitoring approach, recordkeeping, escalation, training, internal reporting, management oversight and independent testing. Each statement should lead to an operational procedure. A policy that says “perform ongoing monitoring” without identifying triggers, evidence, reviewer, timing and escalation is not yet a usable control.

Apply version control. Record the policy title, owner, approval date, effective date, scope, changes from the prior version, staff communication, training delivered and next review date. Store current and superseded versions in a controlled location. This is not clerical work: it enables the firm to demonstrate what requirement applied at a given time and whether staff had access to the approved process.

2. Translate the policy into client-file workflows

For every mapped duty, create a short workflow with six components: trigger, required information, performer, reviewer, escalation route and record location. For example, a change in beneficial ownership should trigger an update task; the task should define the information needed, how the relationship is assessed, who approves a risk-rating change, where evidence is retained and what happens if information is missing. This structure can be applied across onboarding, periodic review, non-face-to-face engagement, enhanced measures, monitoring and recordkeeping.

A controlled checklist can help, but it cannot replace judgement. Use it to demonstrate that required steps were considered, then require a concise narrative where risk factors, exceptions, limitations or escalation are present. The strongest client file is not the one with the most tick marks. It is the file that allows a reviewer to understand the customer, beneficial ownership, service rationale, risk conclusion, evidence obtained, unresolved issue and decision-maker.

Ensure that central policies and file-level workflows agree. If a policy requires senior approval for a high-risk relationship, the client file should show the approval, its date, the information considered and any conditions. If the policy requires periodic review, the firm should be able to show a review date, work performed, findings and the effect on the risk profile. A gap between the manual and the file is a control failure even where the document itself is well drafted.

3. Test safeguards rather than merely collecting templates

Section 23 directs attention to safeguards that prevent breaches and mitigate risk. The appropriate response is an operating-effectiveness test. Each month or quarter, select a risk-based sample of new and existing clients, including higher-risk relationships and files with changes in ownership, activity, jurisdictions, services or adverse information. Reperform the applicable workflow and document whether the required evidence, review and escalation occurred.

A useful testing paper records the population, selection rationale, file tested, exact obligation or internal control, evidence inspected, exception, risk implication, root cause, owner, remediation date and re-test result. Do not record only “compliant” or “non-compliant.” A reviewer should be able to see whether the problem was incomplete information, unclear policy, staff training, a system limitation, reviewer oversight, workload, escalation failure or management tolerance of exceptions.

Separate remediation design from remediation closure. Rewriting a procedure does not demonstrate that the safeguard now operates. Require a closure test: select a later file, inspect the revised workflow in use, verify that the original failure did not recur and document the conclusion. This is the point at which a management dashboard becomes useful; it should show overdue actions, repeated root causes, exception rates, control owners and whether closed actions were independently re-tested.

4. Give management a decision-grade dashboard

Senior management does not need every client-file detail, but it does need information that enables oversight. A quarterly AML/CTF dashboard can show policy currency, overdue reviews, high-risk client population, customer-information exceptions, monitoring triggers, training completion, internal testing results, remediation status and recurring themes. It should also record the challenge made, decisions taken, resources allocated and date for follow-up.

The dashboard should distinguish between a one-off data gap and a systemic failure. For instance, a missing document on one file might be corrected through a targeted follow-up. Repeated gaps in beneficial-owner verification, periodic review, escalation or file approval may indicate that the procedure is unclear, the system is poorly configured or the staffing model is unsuitable. Treating both issues as identical prevents management from identifying the real cause.

CPA practices that are TCSP licensees should apply this analysis only after confirming their own service and licensing perimeter. The licence condition and the cited TCSP framework do not automatically apply to every CPA firm. But where a practice carries on a trust or company service business, the policy-to-practice control chain is highly relevant to demonstrating that its AML/CTF framework is active rather than merely documented.

5. Run a 90-day policy-to-practice reset

In the first 30 days, build the obligation-to-control inventory. Confirm the licence details, current policies, procedures, client forms, systems, control owners and evidence locations. Identify policies that are undated, unapproved, generic, inconsistent with current services or not linked to a client-file workflow.

In days 31–60, conduct a sample-based operating-effectiveness review. Test onboarding, beneficial ownership, monitoring, exception handling, recordkeeping and any relevant non-face-to-face procedures. Classify every finding by policy, procedure, evidence, reviewer, system, training or governance root cause. Assign an accountable owner and a deadline for each remediation action.

In days 61–90, re-test selected remediations and report to senior management. Confirm that staff use the revised procedure, required approvals and evidence appear in files, exceptions are escalated, and management can see recurring risks. EQC Compliance Advisory can assist through a document-led AML/CTF control gap assessment and implementation roadmap for Hong Kong TCSP licensees. The work can map stated licence conditions and applicable AMLO Schedule 2 duties to written procedures, evidence requirements and sample-based control testing. It does not provide legal opinions, act as a Compliance Officer or MLRO, submit regulatory reports or certify that a client is compliant.

This article provides general information only. It is not legal, tax, audit, accounting or regulatory advice and should be considered in light of a firm’s own circumstances.

Scroll to Top