EST · MMXXVI
Home/Jurisdictions/Hong Kong/AML and travel rule regime in Hong Kong: Legal Requirements for Businesses
Compliance, AML & Travel Rule

AML and travel rule regime in Hong Kong: Legal Requirements for Businesses

Aml and travel rule regime in Hong Kong. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Hong Kong's anti-money laundering (AML) and Travel Rule obligations for virtual-asset businesses are now among the most demanding in the Asia-Pacific region. The Securities and Futures Commission (SFC) licenses virtual-asset trading platforms under the VASP licensing regime, and AML/CFT compliance – including the Travel Rule obligation to pass originator and beneficiary data with qualifying transfers – sits at the core of every licence condition. For any business operating or expanding into Hong Kong, getting this right is not optional: the SFC has made clear that sub-standard AML programs are a primary reason applications stall or licences are refused. This page maps the legal framework, the practical compliance architecture, and the cross-border considerations that shape every inbound operator's decision.

The Regulatory Basis: SFC, AML Ordinance and FATF Alignment

Hong Kong's AML framework for virtual-asset businesses rests on two interlocking pillars. The Anti-Money Laundering and Counter-Terrorist Financing Ordinance (AMLO) – the primary statute – imposes customer due-diligence, record-keeping and suspicious-transaction-reporting obligations on licensed virtual-asset service providers. Sitting above it, the SFC's licensing conditions and conduct requirements under the VASP regime layer on detailed operational standards that go materially further than the AMLO baseline. Together, they implement FATF Recommendation 15 (the obligation to extend AML/CFT controls to virtual-asset activities) and the FATF Travel Rule standard across the sector. Any firm seeking or holding an SFC VASP licence is subject to both sets of obligations simultaneously. There is no lighter-touch alternative track.

The SFC introduced its VASP licensing regime through amendments to the AMLO, bringing centralized virtual-asset trading platforms within a mandatory licensing perimeter. Prior to those amendments, Hong Kong operated an opt-in sandbox scheme; the current position is mandatory and enforceable. Firms that operated under the sandbox must have transitioned. New entrants must obtain a licence before commencing regulated activity. In our practice, the single most common error by inbound operators is assuming that a licence obtained elsewhere in the region – Singapore's Payment Services Act registration, for example – creates any coverage in Hong Kong. It does not.

For a scoped assessment of your AML compliance posture before you apply, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base, the jurisdictions you serve – change the analysis. Map your options

Who Needs a VASP Licence in Hong Kong?

Any person operating a virtual-asset trading platform (VATP) in Hong Kong – centralized exchanges that match buyer and seller orders in virtual assets – must obtain an SFC VASP licence, regardless of where the operating entity is incorporated. The regime is activity-based, not entity-based. A BVI or Cayman company actively soliciting Hong Kong clients and maintaining any operational nexus in the territory will fall within scope. The SFC has been explicit on this point in its published guidance.

The licence applies to trading in virtual assets generally, including those that are not classified as securities. Where a platform also offers trading in virtual assets that constitute securities or futures contracts under Hong Kong law, additional authorization under the Securities and Futures Ordinance applies. In practice, most full-service exchanges carry or must carry both types of authorization. Custody services provided in connection with a licensed platform are also regulated. Businesses offering only over-the-counter services, payment solutions or pure custody – without operating an order-matching platform – fall into different regulatory categories and should take separate advice on their specific activity profile.

What Does a Compliant AML Programme Look Like Under Hong Kong Law?

A compliant AML programme for a Hong Kong VASP licence must satisfy the SFC's conduct requirements as well as the AMLO, and the SFC applies a genuinely high standard at the licensing gate. The core components are customer due diligence, ongoing transaction monitoring, a risk-based approach to enhanced due diligence for higher-risk customers, suspicious-transaction reporting to the Joint Financial Intelligence Unit (JFIU), and internal governance including a qualified Money Laundering Reporting Officer (MLRO).

On customer due diligence, the AMLO mandates identification and verification of customers, beneficial owners and, in certain circumstances, counterparties. The SFC's licence conditions add a requirement for operators to assess whether a customer's source of funds and wealth are consistent with their trading activity. This is not a box-tick exercise. The SFC expects documented, risk-calibrated procedures with evidence of ongoing monitoring rather than one-time onboarding. Firms that present a compliance manual without an operational audit trail consistently draw SFC scrutiny.

Transaction monitoring must cover both fiat and virtual-asset flows. The SFC expects platforms to detect structuring, layering and the use of mixing or privacy-enhancing protocols. A credible on-chain analytics capability – using blockchain forensics tools that can trace transaction histories and identify exposure to sanctioned addresses or high-risk counterparties – is now effectively a licence condition in substance, even where not stated in those exact words. In our cross-border practice, we have seen applications rejected principally on the grounds that the proposed transaction-monitoring system could not demonstrate adequate on-chain coverage.

Travel Rule Obligations: What Hong Kong Requires in Practice

The Travel Rule – the obligation derived from FATF Recommendation 16 to transmit originator and beneficiary information alongside virtual-asset transfers – applies to licensed VASPs in Hong Kong and sits within the AMLO's amended provisions. When a Hong Kong-licensed VASP sends a virtual-asset transfer to another VASP, it must pass the required originator and beneficiary data to the receiving institution. When it receives a transfer, it must obtain and verify that data before crediting the beneficiary.

The compliance challenge is practical as well as legal. The Travel Rule requires interoperability between the originating and receiving VASP's compliance systems. Where the counterparty is an unhosted wallet – a self-custodied address not held by a regulated VASP – the Hong Kong rules require the operator to apply enhanced due diligence to assess the risk. Operators we advise routinely face the problem that their counterparty is a VASP in a jurisdiction that either has not yet implemented the Travel Rule or uses an incompatible data standard. The SFC's expectation is that a licensed VASP must have documented policies for handling both situations – it cannot simply pass through a transfer and disclaim responsibility for the data gap.

From an operational architecture standpoint, Travel Rule compliance requires a technology solution that can interface with the major interoperability protocols currently used in the market, as well as manual procedures for lower-volume flows where automated solutions are not available. The SFC does not mandate a specific vendor or protocol, but it expects the solution to be proportionate to the firm's transaction volumes and risk profile.

Cross-Border Dimension: Banking, Licensing and Tax Interaction

Operating in Hong Kong creates a specific cross-border compliance architecture that operators frequently underestimate. The SFC licence covers the trading platform activity in Hong Kong, but it does not resolve the AML and licensing questions in the jurisdictions where the firm also operates, where its customers are located, or where its banking relationships are held. A business with a Hong Kong VASP licence serving users in the European Union remains subject to MiCA's CASP authorisation requirements for EU-facing activity. A business banking its fiat settlement flows through a Singapore correspondent may face MAS scrutiny on those flows independently of the Hong Kong licence.

Banking for Hong Kong VASPs is a live and material constraint. Licensed VASPs may maintain accounts with banks authorized in Hong Kong, but in practice the banking relationships available to crypto businesses remain limited. Several operators we advise have found that their corporate account applications with Hong Kong licensed banks have been refused or significantly delayed, notwithstanding their VASP licence status. The licence is necessary; it is not sufficient. A credible and well-documented AML programme, pre-approved by the SFC, is typically the single strongest lever in a bank account application. Firms that approach the bank before the compliance infrastructure is documented consistently encounter greater resistance.

On tax, virtual-asset trading activity in Hong Kong may generate profits subject to profits tax if the source of those profits is Hong Kong. The profits-tax regime applies on a source basis, which for a trading platform creates questions about where the platform's operations – matching, settlement, and risk management – are genuinely located. Operators with regional structures spanning Hong Kong, Singapore and offshore holding entities need a clear analysis of where income arises and where it is taxable. We work with allied counsel in the relevant jurisdictions to map the tax position alongside the licence stack.

If your AML architecture needs a second read before your SFC application or your banking meeting, contact OBOLUS at info@oboluslaw.com. If a prior application stalled or an account was closed, a structural review can surface the reason and the route forward. Map your options

MLRO Appointment and Internal Governance Requirements

Every SFC-licensed VASP must appoint a Money Laundering Reporting Officer – an individual with genuine authority, appropriate seniority, and demonstrable AML expertise – who is responsible for the firm's suspicious-transaction reporting and for oversight of the AML programme. The MLRO is a named individual known to the SFC. This is not a role that can be outsourced to a third-party compliance firm without the individual being identifiable and responsible. In practice, the SFC scrutinizes the MLRO's qualifications and operational capacity as part of the licence application review.

Beyond the MLRO, the SFC expects a defined governance structure for AML compliance: a board-level risk appetite statement, documented policies and procedures, a regular AML risk assessment that covers the platform's customer base and product risk, and an independent audit or review function. For a smaller or newly established platform, the independent review function may be provided by an external compliance consultant, but the SFC expects evidence that the review is genuinely independent and that its findings are acted on. In our experience advising platforms on licence applications, the quality of the governance documentation is as important as the technical AML systems – the two are evaluated together.

In Practice: A Cross-Border AML Remediation

In a recent matter, a digital-asset exchange with a VASP licence application pending before the SFC approached us after receiving a request for additional information focused on Travel Rule compliance and transaction monitoring. The firm had built its AML programme around a documentation framework designed for an EU regulatory submission and had not adapted it to the SFC's specific conduct requirements. We conducted a gap analysis against the AMLO obligations and the SFC's published guidance, identified deficiencies in the on-chain analytics coverage and the unhosted-wallet policy, and rebuilt the relevant sections of the compliance manual with a Hong Kong-specific risk framework. The application subsequently advanced. The principal lesson was that a programme adequate for one regulatory regime is not automatically adequate for another, even when both implement FATF standards – the implementation detail matters significantly.

A Common Assumption: "Our Existing Offshore Licence Covers This"

A persistent misconception among businesses expanding into Hong Kong is that an existing VASP registration or licence – in the BVI, Cayman Islands, Malta or Singapore – provides meaningful coverage for Hong Kong regulatory purposes. It does not. The SFC's jurisdiction is activity-based. If you are operating a virtual-asset trading platform in or from Hong Kong, or actively marketing to Hong Kong clients, you need an SFC VASP licence regardless of what you hold elsewhere. Your offshore entity may still serve a purpose – as a holding company, as the vehicle for activity in other markets, or as the structure for token issuance – but it cannot substitute for Hong Kong authorization. Operating without a required SFC licence exposes the business to criminal sanctions, enforcement action, account closure and reputational damage with banking counterparties across the region. We regularly advise businesses that have discovered this position only after committing to Hong Kong operations.

Decision Point: Which Operator Profile Needs What

The right compliance architecture in Hong Kong depends on the operator's profile, activity scope and cross-border footprint. Three common profiles illustrate the range.

A pure-play centralized exchange with Hong Kong as its primary market needs a full SFC VASP licence, a Hong Kong-domiciled MLRO with operational authority, a transaction-monitoring system with genuine on-chain coverage, Travel Rule infrastructure capable of interfacing with its major counterparty VASPs, and a documented unhosted-wallet policy. The timeline for a well-prepared application is a matter of months, not weeks. Capital and operational requirements are set by the SFC and should be confirmed from current official sources before any application is submitted.

A regional exchange using Hong Kong as a licensing hub while serving users in Singapore, the EU and the United Kingdom needs the SFC VASP licence for Hong Kong activity, plus an analysis of whether MiCA CASP authorisation and MAS Digital Payment Token licensing are also required for the non-Hong Kong business. A single SFC licence does not passport into the EU or Singapore. The AML programme must be calibrated to the highest standard across the jurisdictions served, because a regulator in any of those jurisdictions can audit the firm on its own requirements.

An operator structuring a custody or OTC business alongside a trading platform needs to assess whether the custody activity independently requires authorization. The SFC's published guidance on regulated activities in the virtual-asset space addresses this, and the analysis turns on whether the custody is incidental to the licensed trading business or a standalone service offered to third parties. For standalone custody, separate authorization is generally required.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule – derived from FATF Recommendation 16 – requires a virtual-asset service provider (VASP) to collect, verify and transmit originator and beneficiary information alongside qualifying virtual-asset transfers. In Hong Kong, the SFC's VASP licence conditions incorporate this obligation. When sending funds to another VASP, the originating firm must pass the required data. When receiving, it must obtain and verify that data before crediting the beneficiary. For transfers to or from unhosted wallets, enhanced due diligence applies.

Who must act as MLRO for a crypto firm?

A Money Laundering Reporting Officer (MLRO) must be a named individual – typically a senior employee – with genuine authority over the firm's AML programme, responsibility for suspicious-transaction reporting, and demonstrable expertise in AML/CFT. The SFC expects the MLRO to be identifiable and operationally responsible; the role cannot be fully outsourced. The individual's qualifications and operational capacity are reviewed as part of the VASP licence application process. Regulators in most leading hubs apply similar expectations.

How do regulators audit crypto AML programs?

Regulators including the SFC typically audit AML programmes through a combination of documentation review, on-site inspection and transaction-data sampling. They assess whether the written policies match operational practice, whether the transaction-monitoring system generates and acts on alerts proportionate to the platform's risk profile, whether the MLRO has genuine authority and adequate resource, and whether the Travel Rule compliance architecture addresses both VASP-to-VASP flows and unhosted-wallet risk. A programme that looks complete on paper but lacks an operational audit trail consistently draws heightened scrutiny.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and we work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML programme architecture and VASP licensing across the SFC, MAS and MiCA regulatory regimes.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours