Trackers
Trackers

AML & KYC in Hong Kong: 2026 Update

AML & KYC in Hong Kong is governed by a mature, multi-layered legal framework that applies to financial institutions, designated non-financial businesses and professions, and virtual asset service providers alike. Hong Kong maintains one of Asia';s most active compliance environments, shaped by the Financial Action Task Force (FATF) standards and enforced by several powerful regulators. Businesses operating in or through Hong Kong face real consequences for non-compliance, including licence revocations, substantial fines, and criminal liability. This guide covers the primary legislation, the key regulators, customer due diligence requirements, recent regulatory developments, and the practical steps businesses must take to remain compliant.

The legal framework governing AML & KYC in Hong Kong

The cornerstone statute is the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (AMLO), Cap. 615. The AMLO imposes customer due diligence (CDD) and record-keeping obligations on financial institutions and designated non-financial businesses and professions (DNFBPs). It is supplemented by the Drug Trafficking (Recovery of Proceeds) Ordinance (DTROP), Cap. 405, and the Organized and Serious Crimes Ordinance (OSCO), Cap. 455, both of which criminalise money laundering and require reporting of suspicious transactions.

The AMLO defines "financial institutions" broadly to include banks, money service operators, securities dealers, insurance companies, and - following recent amendments - virtual asset service providers (VASPs). DNFBPs covered by the AMLO include accountants, lawyers, real estate agents, trust and company service providers, and dealers in precious metals and stones. Each category faces sector-specific guidance issued by the relevant regulator.

The Crimes Ordinance, Cap. 200, and the United Nations (Anti-Terrorism Measures) Ordinance, Cap. 575, round out the criminal law dimension, addressing terrorist financing and proliferation financing. Together, these statutes create a comprehensive legal perimeter that aligns Hong Kong';s framework with FATF Recommendations.

Key regulators and their roles in AML & KYC enforcement

Several authorities share oversight responsibility, and understanding which regulator applies to a given business is a foundational compliance step.

The Hong Kong Monetary Authority (HKMA) supervises authorised institutions - banks, restricted licence banks, and deposit-taking companies - under the Banking Ordinance and the AMLO. The HKMA issues Supervisory Policy Manual modules, particularly AML/CFT-related modules such as AML/CFT SA-2, which provide detailed guidance on CDD, enhanced due diligence (EDD), and transaction monitoring expectations.

The Securities and Futures Commission (SFC) regulates licensed corporations under the Securities and Futures Ordinance (SFO), Cap. 571, and oversees VASPs licensed under the AMLO following the introduction of the VASP licensing regime. The SFC';s AML guidelines set out CDD requirements specific to securities and virtual asset activities.

The Insurance Authority (IA) supervises authorised insurers and licensed insurance intermediaries. The IA';s AML/CFT guidelines align with the AMLO and FATF standards, with particular attention to life insurance products that carry higher money laundering risk.

The Customs and Excise Department (C&ED) supervises money service operators and dealers in precious metals and stones. The Hong Kong Police Force';s Joint Financial Intelligence Unit (JFIU) receives and analyses suspicious transaction reports (STRs) filed under the OSCO and DTROP.

Customer due diligence and KYC requirements

CDD is the operational core of any AML & KYC programme in Hong Kong. The AMLO requires financial institutions and DNFBPs to identify and verify customers, understand the nature and purpose of business relationships, and conduct ongoing monitoring of transactions.

Standard CDD applies when establishing a business relationship, conducting occasional transactions above prescribed thresholds, or when there is suspicion of money laundering or terrorist financing. For natural persons, standard CDD involves collecting full legal name, date of birth, residential address, and verifying identity through a government-issued document. For legal entities, it requires collecting the entity';s name, registration number, registered address, and identifying beneficial owners who hold or control 25% or more of the entity.

Simplified due diligence (SDD) is permitted for lower-risk customers, such as listed companies on recognised exchanges or regulated financial institutions, provided the institution has assessed and documented the lower risk. Conversely, enhanced due diligence (EDD) is mandatory for higher-risk relationships. EDD triggers include politically exposed persons (PEPs), customers from high-risk jurisdictions identified by FATF, complex or unusual transaction structures, and correspondent banking relationships.

A common mistake among foreign businesses entering Hong Kong is treating KYC as a one-time onboarding exercise. The AMLO requires ongoing monitoring, meaning that CDD information must be refreshed periodically and transaction patterns must be reviewed against the customer';s stated profile. Failure to update records when material changes occur - such as a change in beneficial ownership - is a recurring finding in regulatory inspections.

Beneficial ownership verification deserves particular attention. Hong Kong';s Companies Ordinance, Cap. 622, requires companies to maintain a significant controllers register (SCR), and financial institutions must cross-reference this register as part of their CDD process. In practice, discrepancies between the SCR and information provided by customers are a red flag that warrants escalation.

Recent regulatory developments and the VASP licensing regime

Recent years have seen significant expansion of Hong Kong';s AML & KYC perimeter, most notably through the introduction of a mandatory licensing regime for VASPs. Under amendments to the AMLO that took effect in recent regulatory cycles, any person operating a virtual asset exchange in Hong Kong must obtain a licence from the SFC. Licensed VASPs are subject to the same CDD, record-keeping, and suspicious transaction reporting obligations as traditional financial institutions.

The SFC has issued detailed guidance on the AML/CFT obligations of VASPs, including requirements for travel rule compliance - the obligation to transmit originator and beneficiary information alongside virtual asset transfers. This aligns Hong Kong with FATF';s updated Recommendation 16 on wire transfers as applied to virtual assets. Non-compliant VASPs face licence refusal or revocation, and operating without a licence is a criminal offence.

The HKMA has also strengthened its supervisory approach to correspondent banking and trade finance, areas identified as higher risk for financial crime. Authorised institutions are expected to apply risk-based CDD to correspondent relationships and to conduct periodic reviews of trade finance transactions for red flags such as over- or under-invoicing.

Hong Kong';s FATF mutual evaluation results have influenced the current regulatory posture. Following the evaluation process, authorities have prioritised enforcement actions, increased the frequency of thematic inspections, and published detailed findings from supervisory reviews. Regulators have signalled that they expect institutions to move beyond checkbox compliance toward genuinely risk-based programmes.

For businesses that need to navigate these evolving requirements, early engagement with legal counsel is advisable. We can help structure the setup correctly the first time, ensuring your compliance programme meets current regulatory expectations before an inspection or licence application. Contact us at info@vlolawfirm.com.

Suspicious transaction reporting and record-keeping obligations

The obligation to file STRs is one of the most operationally significant AML requirements in Hong Kong. Under the OSCO and DTROP, any person - not just regulated entities - who knows or suspects that property represents the proceeds of an indictable offence must report that suspicion to the JFIU as soon as reasonably practicable. Failure to report is a criminal offence, and tipping off a subject about a report is separately criminalised.

Financial institutions and DNFBPs must have internal reporting procedures that allow staff to escalate suspicions to a nominated Money Laundering Reporting Officer (MLRO). The MLRO then assesses whether to file an STR with the JFIU. Best practice requires documenting the decision-making process regardless of whether a report is ultimately filed, as this creates an audit trail demonstrating good faith.

Record-keeping requirements under the AMLO mandate that CDD records and transaction records be retained for at least five years after the end of a business relationship or the completion of a transaction. Records must be sufficient to reconstruct individual transactions and to provide evidence in any future investigation or prosecution. A non-obvious requirement is that records must be kept in a form that allows them to be made available promptly to the relevant regulator upon request - cloud storage arrangements must therefore include provisions for timely retrieval and production.

Penalties for non-compliance are substantial. Under the AMLO, failure to comply with CDD or record-keeping requirements can result in fines at the criminal level for individuals and institutions. Regulatory sanctions include public reprimands, licence conditions, licence suspension, and revocation. The HKMA and SFC have both imposed significant financial penalties on authorised institutions and licensed corporations in recent enforcement actions, and the IA has followed suit in the insurance sector.

Compliance programme requirements for businesses operating in Hong Kong

Building a compliant AML & KYC programme in Hong Kong requires more than adopting a policy document. Regulators expect a risk-based approach that is proportionate to the nature, scale, and complexity of the business.

The foundational elements of a compliant programme include a documented business-wide risk assessment, written AML/CFT policies and procedures, a designated MLRO with appropriate seniority and resources, staff training delivered at onboarding and at regular intervals thereafter, and an independent audit or review function. For larger institutions, the HKMA expects a three-lines-of-defence model with clear accountability at each level.

Customer risk assessment is the engine of a risk-based programme. Each customer must be assigned a risk rating - typically low, medium, or high - based on factors such as customer type, geography, product or service used, and transaction behaviour. The risk rating determines the level of CDD applied and the frequency of ongoing monitoring reviews. Regulators scrutinise the methodology and consistency of risk rating decisions during inspections.

Technology plays an increasing role in AML & KYC compliance. Transaction monitoring systems, sanctions screening tools, and adverse media screening are now standard expectations for financial institutions. The HKMA has published guidance on the responsible use of technology in AML/CFT, including the use of artificial intelligence and machine learning for transaction monitoring. Institutions using automated tools remain responsible for the quality of outputs and must be able to explain their models to regulators.

Two practical scenarios illustrate the compliance challenges businesses face. First, a foreign bank establishing a branch in Hong Kong must implement a CDD programme that meets HKMA standards from day one of operations, even if its home jurisdiction has different thresholds or documentation requirements. Relying on group-level policies without localising them to Hong Kong requirements is a common and costly mistake. Second, a fintech company launching a virtual asset exchange must obtain an SFC licence before commencing operations, implement travel rule compliance, and demonstrate to the SFC that its AML/CFT controls are equivalent to those of a traditional securities firm. Many applicants underestimate the documentation burden and the time required to satisfy the SFC';s pre-licensing review.

FAQ

What triggers enhanced due diligence under Hong Kong';s AML rules?

Enhanced due diligence is required whenever a financial institution or DNFBP identifies a higher-risk relationship or transaction. The AMLO and associated guidelines specify mandatory EDD triggers, including customers who are politically exposed persons, customers or counterparties connected to jurisdictions identified by FATF as high-risk or subject to increased monitoring, and transactions that are complex, unusually large, or have no apparent economic purpose. EDD involves obtaining additional information about the customer';s source of wealth and source of funds, seeking senior management approval before establishing or continuing the relationship, and conducting more frequent ongoing monitoring. Institutions must document the EDD measures taken and the rationale for any decisions made.

How long does it take to build a compliant AML programme, and what does it cost?

The timeline and cost depend heavily on the size and complexity of the business. A small DNFBP such as a trust and company service provider can typically implement a basic compliant programme within a few weeks, with professional fees in the low thousands of USD for policy drafting and staff training. A licensed bank or VASP faces a significantly more demanding exercise: developing a risk assessment methodology, implementing transaction monitoring technology, training staff across multiple functions, and establishing governance structures can take several months and involve costs in the mid-to-high tens of thousands of USD or more, depending on the technology chosen and the extent of external advisory support. Ongoing costs include annual training, periodic independent reviews, and technology licensing fees.

Can a foreign company rely on CDD conducted by an overseas group entity?

Hong Kong';s AMLO permits reliance on CDD conducted by a third party, including an overseas group entity, provided specific conditions are met. The relying institution must satisfy itself that the third party is subject to AML/CFT requirements consistent with FATF standards, is supervised for compliance with those requirements, and has consented to provide CDD information promptly upon request. The relying institution remains ultimately responsible for the adequacy of the CDD and cannot outsource that responsibility. In practice, regulators expect institutions to have a formal reliance agreement in place, to conduct periodic assessments of the third party';s compliance standards, and to step in with direct CDD where the third party';s standards are found to be insufficient.

Conclusion

Hong Kong';s AML & KYC framework is comprehensive, actively enforced, and continuing to evolve. Businesses operating in the jurisdiction - whether in banking, securities, insurance, virtual assets, or professional services - must maintain risk-based compliance programmes that meet the standards set by the HKMA, SFC, IA, and other relevant regulators. The cost of non-compliance, measured in fines, reputational damage, and licence loss, far exceeds the investment required to build a sound programme.

VLO Law Firms advises international clients on AML & KYC compliance in Hong Kong. We can assist with compliance programme design, regulatory submissions, MLRO support, and licence applications. To request a consultation, contact: info@vlolawfirm.com