(Tax, eTax & Cross-Border Reporting)
PRACTICAL IMPLEMENTATION GUIDE
The 2027 change is an information-governance problem, not a portal task
Hong Kong’s Inland Revenue (Amendment) (Automatic Exchange of Information) Ordinance 2026 was gazetted on 26 June 2026 and will come into operation on 1 January 2027. It strengthens the Common Reporting Standard (CRS) administrative framework through mandatory registration for reporting financial institutions (RFIs), revised retention requirements and enhanced sanctions.[1] The operational challenge is not just gaining access to the AEOI Portal. It is being able to prove which entity is an RFI, what accounts it maintains, why each reporting decision was reached, what was filed and how errors were corrected.
A CPA firm or TCSP licensee is not automatically an RFI merely because it provides accounting, corporate, trust or administrative services. The starting point must be a documented entity-and-role analysis under the Inland Revenue Ordinance (IRO): identify each managed entity, its functional role, its RFI or non-reporting-financial-institution conclusion, the accounts it maintains, any trustee or umbrella arrangement and the person accountable for the conclusion. This is important because an outsourced service provider does not take over the reporting entity’s statutory responsibility.
The useful control objective is therefore an account-level evidence chain from entity classification to retained filing evidence. EQC’s suggested framework contains five stages: accountable population; statutory calendar; due-diligence evidence packet; controlled BIR80 data pipeline; and correction, retention and assurance governance. It gives an RFI or its service provider a way to show not merely that a return was submitted, but that its information-governance process operated.
1. Establish the accountable population before you set the deadlines
Maintain a version-controlled entity inventory. For every client, trust, fund, sub-fund, company and relevant arrangement, record the RFI or non-reporting-financial-institution assessment, basis for the conclusion, date assessed, reviewer, accounts maintained, service-provider role, trustee or umbrella relationship, and next reassessment date. A classification conclusion should be refreshed when a new entity starts operations, the business model changes, an account is opened or closed, a structure is reorganised, a trust is wound up or an outsourcing arrangement changes.
From 1 January 2027, all RFIs in Hong Kong must register in the AEOI Portal for CRS purposes, whether or not they have information to report. Existing unregistered RFIs must register by 31 March 2027. An entity becoming an RFI from 1 January 2027 must register by 31 January in the year following the calendar year in which it first becomes an RFI.[1] The IRD describes specified trustee-and-trust and umbrella-fund arrangements in which separate registration may not be required where another RFI is registered and reports the relevant data, including nil reporting. Document the factual basis before relying on such an arrangement.
Do not confuse the new statutory RFI registration with a Portal account or with a historical commencement notification. The AEOI Portal already supports notifications and Financial Account Information Returns (BIR80). The IRD states that a commencement notification is generally due within three months after an RFI first maintains a reportable account, while electronic notices to file BIR80 are issued in January and completed returns are due within five months of the notice.[2] Use a dual-date calendar so current process deadlines and the 2027 registration obligation are separately controlled.
2. Create an account-level evidence packet
For each account reviewed, retain a coherent packet that links the customer and controlling-person information to the reportability conclusion. The packet may include the self-certification, documentary evidence, validation and reasonableness checks, change-of-circumstance assessment, tax-residence/TIN logic, controlling-person analysis, final conclusion, reviewer approval and filing reference. The exact contents will depend on the entity and account type; the objective is that a reviewer can see how the conclusion was reached and whether the underlying facts were complete and current.
The IRD’s compliance programme provides a useful test of what a reviewable system looks like. Its published compliance work covers self-certifications, documentary evidence, records of due-diligence steps, return correctness and completeness, staff training, data-extraction controls, error root-cause remediation and corrected data.[3] These are not an optional checklist for a particular RFI. They are a practical indication that a filing cannot be defended solely with a final spreadsheet.
Lock the evidence packet after each filing cycle, but retain a controlled route for change-of-circumstance updates and corrections. A change in tax residence, controlling person, account status, entity classification or data quality should create a traceable task with an owner, due date, decision and review. This avoids the common control failure in which information exists in a client-management system but is never evaluated for CRS consequences.
3. Make BIR80 preparation a gated data pipeline
A reliable BIR80 process has a defined start and end point. Begin by reconciling source systems to the approved RFI and account population. Then test mandatory data fields, tax-residence/TIN logic, account values, controlling-person details, nil-reporting decisions and exception items. Retain the reconciliation from system extract to review file to final return. The person who prepares the data should not be the only person who decides whether it is complete enough to submit.
Use final-submission gates. Before filing, require a designated reviewer to approve the account population, material exceptions, data-quality results, reportability decisions and final output. Retain the BIR80 receipt or Portal acknowledgement, the version submitted, the reviewer’s sign-off and the rationale for nil reporting, where relevant. If a service provider prepares the return, the RFI should still keep the approval and evidence that it understood the output submitted in its name.
Build a correction log alongside the filing pack. It should identify the issue, affected account or data field, discovery date, whether the error affects information already furnished, factual investigation, decision on correction or Commissioner notification, implementation date, root cause and preventive action. This design makes a correction an accountable regulatory event rather than an informal update to a spreadsheet.
4. Design records and sanctions controls for the enacted 2027 regime
From 1 January 2027, the 2026 Ordinance requires RFIs to keep sufficient records for six years after the due date of the relevant BIR80, whether or not the RFI has ceased to be an RFI or has dissolved. For a dissolved RFI, the IRD states that every person who was a director immediately before dissolution—or the trustee or person responsible for management if there was no director—must ensure the records remain kept until the end of the retention period.[1] Record retention should therefore be designed into cessation, handover and dissolution procedures, not left to an archive owner who may no longer be involved.
The enacted changes also introduce sanctions for non-compliance without reasonable excuse, including failures to register and provision of incorrect or incomplete information. Certain penalties are calculated by reference to the number of financial accounts involved, and an administrative-penalty mechanism can apply instead of prosecution for the same facts where no prosecution has begun.[1] These changes are final enacted law but future-effective until 1 January 2027. They should not be described as a current penalty regime before that date.
The control response should be proportionate and specific. Maintain a records index that can retrieve the account evidence packet, return version, Portal acknowledgement, correction history and responsible officer for the required period. Test retrieval from a closed account and a dissolved or transferred structure. This is more useful than simply setting a generic “six years” retention rule in a policy.
5. Keep accountability with the RFI when work is outsourced
External administrators, trustees, tax advisers and technology providers can assist with classification, due diligence, data preparation and filing. They do not remove the need for the RFI to understand and control its regulatory output. The 2026 reforms make this distinction especially important because the statutory registration, recordkeeping, error and sanction rules apply to the RFI. Contracts should therefore define deliverables, data ownership, validation responsibilities, filing authority, evidence retention, error escalation, correction support, access to underlying records and handover arrangements.
Ask one practical question of every outsourced process: if the service provider’s staff changed tomorrow, could the RFI retrieve the classification conclusion, the account evidence, the submitted return and the correction history without relying on personal inboxes? If not, the arrangement may be operationally convenient but is not yet a robust information-governance control.
EQC Compliance Advisory can provide a Hong Kong AEOI/CRS readiness review for CPA firms and TCSP licensees. The review can examine the documented RFI-status assessment, registration and notification calendar, due-diligence evidence, BIR80 data lineage, retention design and correction governance against Part 8A and applicable IRD materials, then provide a prioritised findings report. It does not determine tax residence or legal status, make client representations, submit filings or assume a client’s statutory responsibility for classification, reporting or record retention.
A 90-day readiness sequence
In the first 30 days, establish the entity inventory and statutory calendar. Identify unregistered RFIs, responsible officers, trustee or umbrella arrangements, Portal authorities and retained-data locations. Record the specific basis for every classification conclusion and unresolved question.
In days 31–60, test the account-level evidence chain. Select a sample of reportable, non-reportable and nil-reporting outcomes; trace the self-certification and documentary evidence to the final conclusion; reconcile source data to the BIR80 output; and test whether a second person approved exceptions and final submission.
In days 61–90, test retrieval and correction. Retrieve a completed packet, a prior return and a closed-account record. Run an error scenario through the correction log, owner and escalation route. Use findings to improve the 2027 registration, retention and outsourcing controls before the compliance window becomes time-critical.
This article provides general information only. It is not legal, tax, audit, accounting or regulatory advice and should be considered in light of a firm’s own circumstances.