Expand your corporate world!

Knowledge Base

Eltoma Corporate Services — Authorised Corporate Services Provider

Articles are provided for general informational purposes by an authorised corporate services provider and do not constitute legal advice.

When Can a Hong Kong TCSP Refuse or Terminate a Client?

September 23, 2026
Corwin Ashmere
( Eltoma Corporate Services — Authorised Corporate Services Provider )

When Can a Hong Kong TCSP Decline or Terminate a Client Relationship?

Direct answer

A Hong Kong trust or company service provider may decline, suspend or terminate a client relationship where it cannot complete customer due diligence, cannot understand beneficial ownership or control, cannot verify the purpose and intended nature of the relationship, or cannot manage identified money-laundering, terrorist-financing, proliferation-financing or sanctions risks. High risk is not automatically prohibited, but unexplained or unmitigated risk should not be accepted as a routine commercial matter.

When risk assessment becomes a decision

Hong Kong trust or company service providers are often asked why a client cannot simply be accepted once incorporation documents, passports and ownership information have been provided. The practical answer is that AML/CFT compliance does not end with collecting documents. A licensed TCSP must decide whether the relationship can be accepted, continued, escalated, suspended or terminated on the basis of risk, evidence and regulatory obligations.

This article follows the earlier discussion of the risk-based approach. That earlier article explained how risk is assessed. This article focuses on the next question: what happens when the risk assessment, missing information or customer behaviour means that the service provider cannot responsibly proceed?

The risk-based approach is not only a scoring exercise

The official Hong Kong guidance treats the risk-based approach as central to effective AML/CFT controls. A TCSP licensee is expected to identify, assess and understand the money-laundering and terrorist-financing risks to which it is exposed, and to apply measures commensurate with those risks.

In practice, this means that a customer risk assessment should support decisions on whether to enter into, continue or terminate a business relationship. It is not enough to assign a client a low, normal or high risk rating. The file should explain what that rating means for acceptance, monitoring, escalation and any conditions attached to the relationship.

High risk does not automatically mean unacceptable

A higher-risk customer is not automatically prohibited. The Hong Kong framework allows a service provider to deal with higher-risk relationships where the risk is understood, documented and mitigated. The practical consequence may be enhanced due diligence, senior management approval, more frequent review and closer monitoring.

This distinction is important for legitimate international structures. A foreign holding chain, nominee arrangement, politically exposed person connection or higher-risk jurisdiction may justify deeper review, but it does not automatically mean that the client must be rejected. The decision should be based on the facts, the evidence obtained and the service provider’s ability to manage the risk.

When a TCSP should not establish a relationship

A licensed service provider should not establish a business relationship where it cannot comply with the relevant customer due diligence requirements. This may arise where the customer’s identity cannot be verified, the beneficial owner cannot be identified with sufficient confidence, the ownership and control structure is not understood, or the purpose and intended nature of the relationship cannot be established.

The issue is not whether the client is commercially convenient. The issue is whether the service provider can satisfy itself, using reliable information and a documented process, that it knows who the client is, who controls the client and why the services are being requested.

Incomplete information and delayed verification

Hong Kong guidance recognises that identity verification may sometimes be completed after a business relationship has been established, but this is subject to risk management conditions. The provider should set a reasonable timeframe, restrict or monitor activity before verification is complete, keep senior management informed of pending cases and have follow-up actions where the timeframe is exceeded.

The guidance gives practical timing expectations. Verification should generally be completed no later than 30 working days after the relationship is established. If verification remains incomplete after that period, the relationship should be suspended and further transactions should not be carried out, except in limited circumstances such as returning funds to their source where possible. If verification remains incomplete 120 working days after establishment, the relationship should be terminated.

When an existing relationship may need to be suspended or terminated

Termination is not limited to new onboarding. A service provider may have to reassess an existing relationship where the customer’s circumstances change or where previously obtained information becomes doubtful.

Examples include a change in beneficial ownership or control, reactivation of a dormant relationship, unusual or suspicious transactions, a material change in how the relationship is operated, inconsistent information about the source of funds, or doubts about the adequacy or truthfulness of documents previously provided.

Where the issue can be resolved through updated documents, enhanced due diligence and senior approval, the relationship may continue. Where the provider cannot complete required due diligence or ongoing monitoring, the guidance expects termination as soon as reasonably practicable where applicable.

Client behaviour that may justify refusal or escalation

A client relationship may become difficult to accept or continue not because the structure is complex, but because the client cannot explain it. Warning signs include refusal or reluctance to answer questions, refusal or reluctance to provide supporting documents, inconsistent explanations of ownership or control, lack of any clear Hong Kong nexus, unexplained third-party payments, adverse open-source information, or pressure to proceed before checks are complete.

The Registry’s suspicious transaction materials refer to indicators such as complex multi-jurisdictional structures, obscured beneficial ownership, politically exposed person involvement, high-risk jurisdictions, no known Hong Kong nexus, unfavourable information, failure to disclose specific roles or ownership, and reluctance to provide convincing answers or documents.

Suspicion, internal reporting and external reporting

A decision to refuse or terminate a relationship should be separated from the question whether a suspicious transaction report is required. Not every declined client gives rise to reportable suspicion. However, if relevant knowledge or suspicion of money laundering, terrorist financing or related criminal proceeds arises, the service provider should consider reporting to the Joint Financial Intelligence Unit.

The official guidance makes clear that suspicious transaction reporting obligations may arise even where no transaction has actually been carried out. It also emphasises internal reporting procedures, a money laundering reporting officer and controls to prevent tipping off. Staff should therefore avoid explaining a refusal or termination in a way that reveals or prejudices an internal or external suspicious transaction report.

Sanctions, terrorist financing and proliferation financing

Some relationships cannot be viewed only through ordinary commercial risk. Hong Kong’s framework also includes terrorist-financing, financial-sanctions and proliferation-financing controls. The official guidance reminds service providers that United Nations sanctions are implemented in Hong Kong under the United Nations Sanctions Ordinance and that service provision connected with weapons of mass destruction may be prohibited where there are reasonable grounds for belief or suspicion.

Where sanctions, terrorist-financing or proliferation-financing concerns arise, the decision may move quickly from enhanced due diligence to refusal, suspension, termination or reporting. A service provider should not treat such concerns as a negotiable commercial issue.

Documentation of the decision

A refusal or termination decision should be documented. The record should not simply say “not accepted” or “terminated”. It should show the information requested, the information received, the risk issues identified, the escalation steps taken, management approval where required, the conclusion reached and any reporting considerations.

This matters because Hong Kong’s regulatory enforcement record shows that failures in customer verification, beneficial-owner verification, ongoing monitoring, policies, procedures, politically exposed person controls and record-keeping can lead to disciplinary action. The quality of the file is therefore part of the control environment.

How clients can reduce refusal risk

Clients can reduce the risk of refusal or delay by explaining the structure clearly from the beginning. In practice, this means providing a current ownership chart, identifying beneficial owners and controllers, explaining the commercial purpose of the Hong Kong company, providing source-of-funds and source-of-wealth evidence where relevant, disclosing nominee or trust arrangements, explaining expected transactions and updating the service provider when circumstances change.

A client should also understand that a request for additional information is not necessarily an accusation. It may be the service provider applying the risk-based approach and documenting why the relationship can be accepted or continued.

Practical decision framework for TCSPs

A practical internal framework can be structured around five questions: can the customer, beneficial owners and persons acting on behalf of the customer be identified and verified; is the ownership and control structure understood and commercially explainable; is the purpose and intended nature of the relationship consistent with the services requested; can the risk be mitigated through enhanced due diligence, monitoring and senior approval; and, if the risk cannot be mitigated, is refusal, suspension, termination or reporting required?

This framework helps keep the decision proportionate. It avoids both extremes: accepting unclear relationships without sufficient evidence, and rejecting legitimate clients merely because they are cross-border or complex.

Refusal is sometimes part of compliance

A Hong Kong TCSP does not have to accept every client, and in some circumstances it should not proceed. The risk-based approach requires a provider to make a reasoned decision based on customer due diligence, ongoing monitoring, escalation and the ability to mitigate risk.

The practical lesson is simple. High risk is not automatically unacceptable, but unmanaged risk is. Where the provider cannot understand the client, verify the key parties, document the commercial rationale, complete due diligence or manage suspicion without tipping off, refusal or termination may be the correct compliance outcome.

Frequently asked questions

# Can a Hong Kong TCSP refuse to accept a client?

Yes. A TCSP may refuse to act where it cannot complete customer due diligence, verify beneficial ownership, understand the structure, or manage AML/CFT, sanctions or other regulatory risks.

# Does a high-risk rating mean the client must be rejected?

Not necessarily. High risk may be acceptable where it is understood, documented, approved where required and mitigated through appropriate controls.

# When should verification be completed after a relationship starts?

Where delayed verification is allowed, the guidance expects verification generally to be completed within 30 working days after establishment, with suspension and termination consequences if it remains incomplete.

# Can a relationship be terminated after onboarding?

Yes. Existing relationships may need to be suspended or terminated if circumstances change, documents become doubtful, ongoing monitoring cannot be completed or the risk can no longer be mitigated.

# Does every refusal require a suspicious transaction report?

No. Refusal and suspicious transaction reporting are separate questions. A report should be considered where knowledge or suspicion of money laundering, terrorist financing or criminal proceeds arises.

# What should clients provide to reduce delays?

A clear ownership chart, beneficial-owner details, source-of-funds and source-of-wealth evidence where relevant, commercial rationale, expected transaction profile and explanations of nominee or trust arrangements.

# Why is documentation important?

The file must show why the provider accepted, refused, suspended or terminated a relationship. A short note saying “not accepted” is usually not enough for a defensible AML/CFT record.

Articles are provided for general informational purposes by an authorised corporate services provider and do not constitute legal advice.

Learn how to solve problems in your business today
X

Become a member of our
private club for international business
and taxes

Receive updates with practical insights on international business, law, tax, accounting, and compliance.
Be the first to hear about our latest discounts and special offers!

Follow our Telegram channel for offshore industry news:

t.me/EltomaCorporateServices

Want updates by e-mail?
Enter your email address below to subscribe to our newsletter!

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.