SFC Revises AML/CFT Guidelines for Securities Sector
The proposed amendments seek to align the SFC’s guidelines with the FATF guidance for adopting a risk-based approach in the securities sector.
Hong Kong’s SFC (Securities and Futures Commission) has launched a three-month consultation on proposals to amend its AML/CFT guidelines to incorporate FATF (Financial Action Task Force) standards and address findings from Hong Kong’s latest mutual evaluation report.
The SFC last amended its AML/CFT guidelines in November 2018, indicating at the time that it would consider further amendments to align with the FATF’s publication of guidance for adopting a risk-based approach in the securities sector.
Institutional and customer risk assessments
The amendments set out the sources of information which licensed corporations should consider in their institutional risk assessments, and include guidance on the range of risk factors that should be taken into account when conducting such assessments.
While licensed corporations are already required to keep their institutional risk assessments up-to-date, the amendments clarify that periodic reviews should be conducted at least once every two years, or more frequently upon the occurrence of ‘trigger events’.
In line with the FATF guidance, the amendments also require licensed corporations with overseas branches and subsidiaries to conduct a group-wide risk assessment, which the SFC says will facilitate the design and implementation of the requisite group-wide AML/CFT systems which currently in place.
Licensed corporations that are part of a financial group may make reference to or rely on a group-wide or regional institutional risk assessment.
The SFC has included an expanded list of risk indicators and illustrative examples for country risk, customer risk, product/service/transaction risk and delivery/distribution channel risk.
The illustrative risk indicators may be used for conducting a risk assessment at an institutional level and a customer level, where appropriate, to determine the level of risks which may be present in the licensed corporation’s business operations or customer base, the SFC says.
Cross-border correspondent relationships
The amendments also address some areas for enhancement identified in Hong Kong’s latest mutual evaluation report, published in September 2019.
In particular, the SFC proposes additional measures to mitigate risks associated with business arrangements such as cross-border correspondent relationships, such as in cases where a Hong Kong securities broker executes trades for an overseas broker acting for or on behalf of its own customers.
The additional measures include due diligence obligations to determine the nature of the respondent institution’s business, its reputation and quality of supervision, and the adequacy and effectiveness of its AML/CFT controls – using a risk-based approach.
This includes an assessment of how CDD measures are conducted by the respondent institution, the types of underlying customers, the extent to which their transactions are considered high risk, and the possible involvement of shell financial institutions.
“Cross-border correspondent relationships involving shell financial institutions would expose an LC to heightened ML/TF risks which should be avoided,” the SFC says. “LCs are prohibited from entering into or continuing direct or nested correspondent relationships with shell financial institutions.”
A more in-depth review of AML/CFT controls conducted for cross-border correspondent relationships which present higher risks may include review of independent audit findings, interviews with compliance officers, on-site visits or requests for an ad hoc third-party review.
Licensed corporations should also monitor the transactions of the respondent institution to detect any unexpected or unusual activities or transactions as well as any changes in their risk profiles.
Simplified and enhanced measures
The SFC proposes to limit the type or extent of CDD measures used for verifying the identity of low-risk customers, in line with the risk-based approach. Enhanced CDD measures should be implemented for customers transferring funds to higher risk jurisdictions.
In cases where an licensed corporation is acting as delegated asset manager, and does not have a business relationship with the overseas delegating management company’s investment vehicle, the licensed corporation should obtain additional customer information on the underlying investor base, the reputation of the overseas delegating management company, and its AML/CFT controls.
The SFC provides an expanded list of illustrative examples of possible simplified and enhanced measures under a risk-based approach.
Red-flag indicators
The SFC’s latest amendments also enhance the list of red-flag indicators for suspicious transactions and activities, to reflect the evolution of products, services and transaction methods in the securities sector, as well as changing trends in predicate offences and terrorism and different methods of laundering money or financing terrorism.
New red-flag indicators incorporated into the SFC’s guidelines include instances where a customer has no discernible reason for using a licensed corporation’s service, and where customers open accounts for discretionary management services but end up directing the investments themselves.
The current list of red-flag indicators is expanded from five to six groups, disaggregations the “trading-related” group into “trading-related” and “selected indicators of market manipulation and insider dealing”. Some existing red-flag indicators have also been removed due to their diminishing significance.
Third-party deposits and payments
The SFC proposes to incorporate its May 2019 guidance on handling third-party deposits and payments into the AML/CFT guidelines, requiring licensed corporations to perform third-party deposit due diligence before settling transactions with the funds deposited by their clients.
The SFC allows for occasional and exceptional circumstances where it is reasonable for licensed corporations to complete some of these due diligence procedures after settling transactions with the deposited funds, such as in cases where information is collected from multiple parties and more time is needed.
The revised guidelines set out the risk management policies and procedures licensed corporations should adopt for delayed third-party deposit due diligence.
These include the establishment of timelines for completion of due diligence, follow-up actions if the stipulated timeline is exceeded (suspension or termination of business relationships), limits on the transctions that can be performed for the customer, and enhanced monitoring on those transactions while due diligence is being carried out.
Others
The SFC also proposes amendments to address risks related to persons purporting to act on behalf of the customer (PPTA), to provide more guidance on source nd funds and source of wealth assessments, and to rearrange other parts of the AML/CFT guidelines.
Subscribe Now

