Expand your corporate world!

Knowledge Base

Eltoma Corporate Services — Authorised Corporate Services Provider

Articles are provided for general informational purposes by an authorised corporate services provider and do not constitute legal advice.

Hong Kong AML/CFT Risk-Based Approach for TCSP Clients

August 26, 2026
Corwin Ashmere
( Eltoma Corporate Services — Authorised Corporate Services Provider )

Risk-Based AML/CFT Compliance in Hong Kong: What TCSP Clients Should Expect

Hong Kong AML/CFT compliance is not intended to operate as a one-size-fits-all checklist. A licensed trust or company service provider should identify, assess and understand the money-laundering and terrorist-financing risks connected with the client, structure, jurisdictions and services, and then apply customer due diligence, enhanced review and monitoring measures proportionate to those risks.

Hong Kong AML/CFT framework for TCSPs

Hong Kong’s anti-money laundering and counter-financing of terrorism framework is supported by legislation and regulator guidance. For trust or company service providers, the Anti-Money Laundering and Counter-Terrorist Financing Ordinance, Cap. 615, establishes statutory customer due diligence and record-keeping requirements. The Companies Registry is the regulatory body for TCSPs and monitors compliance with those obligations.

The March 2025 AML/CFT Guideline for TCSP licensees explains that the risk-based approach is central to effective AML/CFT implementation. A TCSP is expected to identify, assess and understand the risks to which it is exposed, and to apply policies, procedures and controls that are commensurate with those risks.

For clients, this is the reason why requests for passports, ownership charts, business descriptions, source-of-funds evidence, source-of-wealth explanations, bank statements or transaction details should not be viewed as isolated administrative requests. They form part of a regulated methodology.

What the risk-based approach means in practice

A risk-based approach does not mean weaker compliance. It means better targeted compliance. A simple company with direct ownership, a clear business model and low-risk jurisdictions should not normally require the same depth of review as a complex cross-border structure with nominee arrangements, unexplained funding, unusual transaction flows or higher-risk jurisdictions.

The approach also does not allow a TCSP to ignore mandatory obligations. Customer due diligence, beneficial ownership identification, authority checks, record-keeping and ongoing monitoring remain core requirements. The practical question is the extent of information, verification, scrutiny, approval and review required for the particular relationship.

Firm-wide risk assessment and client-specific risk assessment

There are two levels of risk assessment that should not be confused. The first is the institutional or business-wide risk assessment. This is the TCSP’s assessment of its own exposure to money-laundering and terrorist-financing risk across its business model, customer base, jurisdictions, products, services, delivery channels, staffing, technology and past regulatory or audit findings.

The second is the customer risk assessment. This applies the methodology to a particular client relationship. It is normally conducted during onboarding and updated during ongoing monitoring. It should determine the extent of due diligence required for that client.

Firm-wide risk assessment and client-specific risk assessment

There are two levels of risk assessment that should not be confused. The first is the institutional or business-wide risk assessment. This is the TCSP’s assessment of its own exposure to money-laundering and terrorist-financing risk across its business model, customer base, jurisdictions, products, services, delivery channels, staffing, technology and past regulatory or audit findings.

The second is the customer risk assessment. This applies the methodology to a particular client relationship. It is normally conducted during onboarding and updated during ongoing monitoring. It should determine the extent of due diligence required for that client.

Customer risk factors: ownership, countries, services and delivery channels

A practical customer risk assessment normally considers several categories of factors. No single factor should be assessed in isolation. A foreign company with a multi-layer structure may be acceptable if the ownership chain, purpose and funding can be explained. A simple structure may still require escalation if adverse information, sanctions exposure or suspicious activity is identified.

From risk rating to controls

A risk rating should change what happens next. If the rating has no practical consequence, it is only a label. A lower-risk file may require standard documents and ordinary review. A higher-risk file may require enhanced due diligence, senior management approval, a deeper funding narrative, evidence of wealth, more frequent reviews and closer monitoring of transactions or changes.

Enhanced due diligence should be proportionate

Enhanced due diligence is a proportionate response to higher risk. It is not an accusation and should not become a habit of asking for every possible document in every difficult case. The additional request should be connected to the risk identified.

Higher-risk factors may include shell vehicles without a clear and legitimate commercial purpose, nominee shareholders or nominee directors, cash-intensive business, unusual or excessively complex ownership structures, anonymous transactions, frequent payments from unknown or unassociated third parties, and countries identified by credible sources as having ineffective AML/CFT systems, corruption, criminal activity or sanctions exposure.

For example, a group holding structure using several jurisdictions may be legitimate, but it should be able to explain why each entity exists, who controls the structure, where funds come from and how transactions will flow. A nominee arrangement may also be legitimate, but it should be documented and consistent with the beneficial ownership and authority records.

Ongoing monitoring: risk is not frozen at onboarding

A risk-based approach continues after client acceptance. A client accepted at onboarding may later change its ownership, directors, authorised signatories, banks, investors, counterparties, business model, funding source or transaction behaviour. Those changes may alter the risk profile.

Review triggers may include a new beneficial owner, a new jurisdiction, a new bank account, a change in expected activity, expired identification documents, adverse media, a sanctions screening result, a request for powers of attorney, nominee arrangements or third-party payments.

This is why existing clients may receive further questions during a periodic review. The purpose is to confirm that the TCSP’s understanding of the client remains current and that the due diligence measures remain appropriate.

Documentation: evidencing judgement, not only collecting papers

The central weakness in many compliance files is not always the absence of a passport or register. It is the absence of reasoning. Under a risk-based approach, the file should show why the client was rated in a particular way and why the due diligence measures were sufficient.

A good file should include the ownership rationale, jurisdiction analysis, business description, expected transactions, source-of-funds or source-of-wealth narrative where relevant, risk rating, escalation decision, review date and explanation of enhanced or simplified measures.

How clients can prepare

Clients can reduce onboarding delays by preparing information in a structured way. The objective is not to overload the TCSP with documents, but to make ownership, control, activity and funding understandable and verifiable.

  • Prepare a clear ownership and control chart showing each layer of the structure.
  • Provide corporate documents for each relevant entity in the chain.
  • Prepare identity and address evidence for beneficial owners, controllers and authorised persons.
  • Provide a concise business description and commercial rationale.
  • Explain expected transaction flows, jurisdictions, counterparties and funding sources.
  • Document source of funds and source of wealth where relevant.
  • Explain nominee, agency, power-of-attorney or third-party payment arrangements if used.
  • Notify the TCSP promptly when ownership, activity, funding or counterparties change.

Common mistakes by clients and intermediaries

A risk-based methodology can fail in two opposite ways. Under-assessment occurs when complex or unusual cases are treated as standard in order to onboard quickly. Over-collection occurs when every client is treated as high risk and excessive documents are requested without a recorded reason.

Professional intermediaries should avoid mechanical ratings, reliance on third-party introductions without understanding what was checked, simplified procedures where suspicion exists, failure to update risk profiles after material changes, and policies that do not match the firm’s actual business model.

Clients should avoid incomplete ownership explanations, unsupported funding narratives, inconsistent information between bank and TCSP files, late notification of changes, and the assumption that complexity will be accepted if enough documents are provided. Coherence is as important as paperwork.

How Eltoma may assist

Eltoma Global can assist clients and professional advisers with Hong Kong company onboarding, ownership and control reviews, AML/CFT information requests, source-of-funds and source-of-wealth file preparation, and coordination of corporate administration records. The objective is to build a file that is clear, evidence-based and suitable for regulated TCSP, banking and professional review.

Conclusion: proportionality, not box-ticking

The risk-based approach is not a shortcut and not a reason to ignore AML/CFT obligations. It is a disciplined method for matching customer due diligence, monitoring and controls to the risks presented by the client, structure, jurisdictions and services.

For clients, the practical lesson is to make ownership, control, business activity and funding clear from the beginning. For professional intermediaries, the practical lesson is to document methodology and professional judgement, not merely to collect documents. Effective Hong Kong AML/CFT compliance should be proportionate, evidence-based and capable of explanation.

Frequently asked questions

# What is the risk-based approach under Hong Kong AML/CFT rules?

The risk-based approach is the method by which a Hong Kong trust or company service provider identifies, assesses, understands, documents and mitigates money-laundering and terrorist-financing risks. It does not remove mandatory customer due diligence. It determines how much information, verification, senior review and ongoing monitoring are appropriate for the client, structure, jurisdictions and services involved.

# Why does a Hong Kong TCSP ask different clients for different documents?

Different document requests may reflect different risk profiles. A simple and transparent company with direct ownership may require a standard due diligence file, while a multi-jurisdictional group, nominee arrangement, third-party payer or higher-risk jurisdiction may require enhanced review. The request should be connected to the identified risk rather than treated as a generic checklist.

# Does a high-risk rating mean that a client must be rejected?

No. A high-risk rating does not automatically mean rejection. It means the risk must be understood, evidenced, approved where required and mitigated through enhanced controls. If the TCSP cannot understand the structure, verify the relevant parties, explain the funds or mitigate the risk, the relationship may need to be declined or terminated.

# What factors affect a customer risk assessment?

A customer risk assessment normally considers ownership and control, beneficial owners, politically exposed persons, adverse information, jurisdictions, business activity, products and services, transaction patterns, delivery channels, third-party introducers, nominee arrangements and source-of-funds or source-of-wealth evidence. The result should be a reasoned risk profile, not only a label.

# When is enhanced due diligence more likely?

Enhanced due diligence is more likely where the client has a complex or unusual ownership structure, nominee directors or shareholders, exposure to higher-risk jurisdictions, politically exposed persons, unclear commercial purpose, unusual transaction flows, third-party payments or information that does not match the expected business profile.

# Does risk-based compliance end after onboarding?

No. Risk is not frozen at onboarding. A TCSP should update the risk profile when ownership, control, directors, authorised persons, business activity, jurisdictions, banks, counterparties or transaction patterns change. Existing clients may therefore receive further questions during periodic reviews or after material changes.

# How can clients prepare for a risk-based AML/CFT review?

Clients can prepare by providing a clear ownership and control chart, corporate documents for each entity in the chain, identity and address evidence for key individuals, a concise business description, expected transaction flows, and source-of-funds or source-of-wealth explanations where relevant. Consistency across the company, bank and adviser files is often more important than volume of documents.

Articles are provided for general informational purposes by an authorised corporate services provider and do not constitute legal advice.

Learn how to solve problems in your business today
X

Become a member of our
private club for international business
and taxes

Receive updates with practical insights on international business, law, tax, accounting, and compliance.
Be the first to hear about our latest discounts and special offers!

Follow our Telegram channel for offshore industry news:

t.me/EltomaCorporateServices

Want updates by e-mail?
Enter your email address below to subscribe to our newsletter!

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.