Hong Kong's licensed virtual-asset trading platforms and regulated intermediaries face one of the most precise AML/CFT (anti-money-laundering and counter-financing-of-terrorism) policy regimes in the Asia-Pacific region. The Securities and Futures Commission (SFC) and the Hong Kong Monetary Authority (HKMA) together set the supervisory standard, and the applicable VASP licensing provisions make a documented, board-approved AML/CFT program a prerequisite – not a post-licence formality. For any business operating or expanding into Hong Kong, the consequences of an inadequate policy are direct: enforcement action, suspended rails, and the loss of banking relationships that underpin day-to-day operations.
This page sets out the regulatory basis for AML/CFT policy drafting in Hong Kong, the elements the SFC expects to see on examination, and how an inbound digital-asset business should approach the process. The cross-border reality – where the licensed entity sits in Hong Kong but users, banking, and liquidity routes span multiple jurisdictions – shapes every drafting decision. A roadmap of the key sections follows.
What Is the Regulatory Basis for AML/CFT Policy in Hong Kong?
Any firm seeking or holding a VASP licence under the Hong Kong SFC regime is directly subject to the AML/CFT requirements set out under the applicable VASP provisions, which align closely with the FATF Recommendations – including Recommendation 15 on virtual assets and the Travel Rule obligation on data transmission. The SFC's licensing conditions for virtual-asset trading platforms (VATPs) incorporate these standards by reference, and the HKMA applies a parallel supervisory standard to banks that provide settlement or custody rails to licensed platforms.
The regime requires a written, risk-based AML/CFT policy that is approved by senior management, embedded in day-to-day operations, and reviewed at a frequency the regulator considers adequate. This is not a checkbox exercise. In our cross-border practice, we have seen the SFC question applicants on the granularity of their customer-risk scoring methodology before a VATP licence is granted – not after. An underdeveloped policy at the application stage signals to the examiner that the firm lacks the governance depth the regime demands.
The framework covers four interlocking obligations: customer due diligence (CDD) and enhanced due diligence (EDD) for higher-risk customers; ongoing transaction monitoring; suspicious transaction reporting; and the Travel Rule. Each must be addressed in the policy document itself, not merely referenced in a procedure manual appended as an exhibit.
For a scoped assessment of your AML/CFT policy against the SFC's current examination standard, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the customer base, the banking – change the analysis.
What CDD and EDD Requirements Apply to Crypto Firms in Hong Kong?
A Hong Kong VATP must apply risk-based customer due diligence at onboarding, at trigger events, and on an ongoing basis – the SFC's applicable provisions make no distinction between fiat-settled and crypto-native transactions for this purpose. The policy document must explain how the firm categorises customer risk: at minimum, it distinguishes individual retail users from institutional counterparties, from high-risk persons (politically exposed persons, customers in high-risk jurisdictions, and high-value transactors) and from customers whose ultimate beneficial ownership is unclear.
EDD procedures must be written out, not implied. Where a customer is classified as higher risk, the policy must specify: the additional information to be collected, who approves the relationship, and how frequently the profile is reviewed. In our practice, we find that many inbound operators underestimate this requirement. They copy a policy from another jurisdiction and assume the risk-appetite language transfers. The SFC's examination approach is document-specific. An examiner will ask: where in your policy does it say what happens when a counterparty fails EDD? If the answer is not in the policy, it does not exist for examination purposes.
The beneficial ownership provisions are particularly exacting for corporate customers. Where a customer is a corporate entity, the policy must address the chain of ownership down to natural persons meeting the applicable threshold, and it must require verification of that chain – not merely its collection. Firms that serve institutional traders, OTC desks, or other exchanges must build a tiered B2B CDD procedure that sits alongside the retail workflow.
How Does Transaction Monitoring Work Under the Hong Kong Regime?
Transaction monitoring under the SFC's VATP framework is a documented, systems-backed requirement: the policy must describe the rules, thresholds, and alert-escalation logic that the firm applies to on-chain and off-chain activity. It is not sufficient to name a third-party monitoring tool without specifying how its outputs feed into the firm's review process.
The policy must address two distinct monitoring layers. The first is rule-based monitoring – flagging transactions against defined parameters such as value thresholds, frequency patterns, and counterparty risk. The second is behavioural or blockchain-analytics monitoring, which traces the provenance of funds through on-chain forensics. Blockchain analytics tools are now an expected component of a VATP's AML infrastructure; the SFC has signalled in its licensing guidance that a platform's ability to assess the risk profile of on-chain assets – including exposure to sanctioned addresses and mixers – is part of the supervisory standard.
In a recent matter, a digital-asset exchange expanding into Hong Kong had a transaction monitoring policy that described its legacy fiat-banking logic but did not address crypto-specific typologies such as chain-hopping, mixer exposure, or rapid fund consolidation across multiple wallets. We worked through the gap analysis, redrafted the monitoring section to reflect the on-chain environment, and aligned the alert-escalation path with the firm's MLRO sign-off structure. The licensing process resumed without a further round of regulator queries on this point.
The suspicious transaction reporting obligation flows directly from monitoring outputs. The policy must specify: who is responsible for reviewing alerts, the timeframe for escalation to the MLRO, the MLRO's decision-making standard, and the route to the Joint Financial Intelligence Unit (JFIU) in Hong Kong. These steps must be written out in sequence. An examiner reviewing the policy should be able to trace a transaction from alert to report – or to documented non-report – without interviewing staff.
What Does the Travel Rule Require From a Hong Kong VASP?
The Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer) applies to licensed VATPs in Hong Kong under the applicable VASP provisions, aligning the regime with the FATF standard. The AML/CFT policy must contain a dedicated Travel Rule section that identifies: which transfers are in scope, the data elements required, the technical solution in use, and the procedure for handling transfers where the counterparty VASP is unable to receive or transmit Travel Rule data.
The cross-border dimension of the Travel Rule creates significant policy complexity for Hong Kong-licensed firms. A platform serving users in the EU, Singapore, or the United States will transact with counterparty VASPs in those jurisdictions – each operating under its own Travel Rule regime. Where a counterparty VASP is unhosted-wallet-originated, or where the jurisdiction of the counterparty is unclear, the policy must specify a risk-based procedure for handling the gap. The SFC does not prescribe a single technical standard, but it expects the policy to be explicit about the chosen interoperability approach and the fallback when that approach fails.
Data-minimisation obligations add another drafting layer. Travel Rule data collected from counterparty VASPs must be handled in accordance with Hong Kong's personal data ordinance provisions, and the policy must address how that data is stored, accessed, and deleted. Firms that transfer Travel Rule data cross-border – as most do, given the nature of global crypto flows – need a section addressing the lawful basis for that transfer under each relevant data-protection regime.
Who Must Act as MLRO for a Crypto Firm in Hong Kong?
A Hong Kong VATP must designate a Money Laundering Reporting Officer (MLRO) who is a senior individual resident or sufficiently present in Hong Kong, with clear authority to act independently of business lines. The SFC's VATP framework treats the MLRO appointment as a fitness-and-propriety matter: the individual's experience, understanding of crypto-specific AML typologies, and access to senior management are all in scope at the licensing stage.
The AML/CFT policy must define the MLRO's role with precision. This includes: the MLRO's authority to suspend or reject a customer relationship without business-line override; the escalation path from frontline compliance staff; the reporting line to the board; and the process for MLRO succession if the designated individual leaves. Regulators in the leading hubs increasingly expect the MLRO function to be supported by documented evidence of training, attendance at compliance meetings, and regular reporting to senior management – not simply a name on a licence application.
For inbound operators structured outside Hong Kong – a common scenario where the group parent sits in the BVI or Cayman Islands, and the licensed entity in Hong Kong is a subsidiary – the policy must address how the group compliance function and the local MLRO interact. The SFC is explicit that the Hong Kong entity must retain autonomous compliance capability. A policy that defers all MLRO decisions to a parent-company compliance team will not satisfy the examination standard.
If a prior application stalled on the governance section or a banking relationship was closed, a structured review can identify the structural reason and the route forward. Write to OBOLUS at info@oboluslaw.com or message us via t.me/oboluslaw.
How Does Cross-Border Structuring Interact With Hong Kong AML Policy?
Operating a digital-asset business across multiple jurisdictions means that a Hong Kong AML/CFT policy rarely operates in isolation. The licensed VATP or regulated intermediary sits inside a group that may hold licences or registrations in the EU under MiCA (the Markets in Crypto-Assets Regulation), in Singapore under the MAS Payment Services Act, or in the UAE under the VARA regime – each with its own AML/CFT documentation standard. A single global policy document written to the highest common denominator is a coherent starting point, but it will need a Hong Kong-specific annex that addresses the SFC's particular requirements, the local JFIU reporting path, and the data-protection obligations under Hong Kong law.
Banking interaction is a related pressure point. Correspondent and domestic banks serving Hong Kong VATPs are supervised by the HKMA and apply their own AML due-diligence standard to virtual-asset business clients – one that is typically more conservative than the minimum statutory requirement. Operators we advise routinely find that their banking application requires a more detailed policy submission than the licensing application itself. A policy drafted solely to the SFC examination standard may still be insufficient to open or maintain a bank account in Hong Kong. The drafting process must therefore anticipate both audiences: the regulator and the correspondent bank.
Tax and banking flows interact further. Where a Hong Kong VATP routes settlement through an EMI or payment institution in another jurisdiction – a structure common among businesses that cannot access local banking – the AML policy must address the risk of layering across the payment layer. The firm must document how it monitors settlement flows that pass through a non-Hong-Kong payment partner, and how it ensures that Travel Rule data is not lost in that transit. Failure to address this cross-border gap is a recurring finding in SFC examination reports on platforms that use third-party payment rails.
How Do Regulators Audit Crypto AML Programs in Hong Kong?
The SFC audits a VATP's AML/CFT program through a combination of desktop review, on-site inspection, and targeted enquiry – and the HKMA applies an equivalent process to banks with significant virtual-asset exposure. The examination is document-led: the examiner starts with the policy, tests whether the documented procedure matches actual practice, and then samples case files to validate the claim.
A documented policy that cannot be demonstrated in practice is, from the examiner's perspective, the same as no policy. We have seen this dynamic play out across multiple regulatory hubs: the firm drafts a policy at the application stage, passes initial review, and then fails a subsequent examination because the operational team was never trained on the document, the monitoring alerts were not being actioned within the specified timeframe, or the MLRO sign-off was recorded retrospectively. The policy must be a living document, updated at a minimum annually and whenever there is a material change to the business, the customer base, or the risk environment.
Independent testing is increasingly expected under the SFC's framework. A VATP should build into its policy a requirement for periodic internal or external audit of the AML/CFT function, with findings reported to the board and tracked through to remediation. Where the SFC finds systemic gaps in AML controls, it has the authority to impose conditions on the licence, require remediation on a defined timeline, or – in serious cases – revoke the licence. Operating without an adequate AML/CFT policy is therefore not a technical deficiency: it is an existential risk to the licence.
AML/CFT Policy Self-Assessment: Key Questions for a Hong Kong VASP
Before engaging counsel or submitting to the SFC, a firm can pressure-test its AML/CFT policy against the following threshold questions. These are not a substitute for a full review, but they identify the most common structural gaps we encounter in practice.
- Is the policy formally approved by the board or a duly authorised board committee, with a dated resolution on file?
- Does the CDD section specify, by customer type, the documents and data required at each risk tier – including a written EDD procedure for higher-risk customers?
- Does the transaction monitoring section name the systems in use, describe the rule-set or alert logic, and specify the escalation timeline to the MLRO?
- Is there a standalone Travel Rule section that identifies in-scope transfers, the technical solution, and the procedure for non-compliant counterparty VASPs?
- Does the policy specify the MLRO's authority, succession plan, and reporting line to the board?
- Is there a sanctions screening section covering both counterparty and wallet-address screening?
- Does the policy include a testing and audit requirement, with a defined frequency and reporting path?
- Has the policy been reviewed by a person with demonstrable knowledge of crypto-specific AML typologies – not simply adapted from a fiat-banking template?
A "no" or "unclear" answer to any of these points is a gap that the SFC is likely to identify. A firm that maps these gaps before the application is submitted is in a materially better position than one that addresses them in response to a regulatory query.
Related at OBOLUS
- AML/CFT and Travel Rule Compliance for Digital-Asset Businesses – the full practice overview covering policy design, MLRO support, and cross-border AML obligations across leading hubs
- Regulatory Trends in Digital-Asset Custody Across Common-Law Forums – how custody regulation is evolving in Hong Kong, Singapore, England and the Cayman Islands
- PSP and Acquiring Agreements for Institutional Clients – structuring payment and acquiring relationships when banking access is conditional on AML documentation
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule requires a virtual-asset service provider to collect, verify, and transmit originator and beneficiary information with every qualifying virtual-asset transfer. Under the FATF standard, which the Hong Kong SFC incorporates into its VASP provisions, the data must accompany the transfer in real time, and the receiving VASP must be able to process and retain it. A VASP must also have a documented procedure for transfers where the counterparty cannot receive Travel Rule data, including a risk-based decision on whether to proceed. The applicable data threshold varies by jurisdiction and should be confirmed against current SFC guidance.
Who must act as MLRO for a crypto firm?
A Hong Kong VATP must appoint a senior, fit-and-proper individual as MLRO, with direct authority over suspicious transaction reporting and sufficient independence from revenue-generating functions. The SFC assesses the MLRO's crypto-specific AML knowledge, access to senior management, and capacity to act without business-line interference. For group structures where the parent is offshore, the Hong Kong entity must retain an autonomous MLRO function: deference to a group compliance team will not satisfy the regime. MLRO succession planning must also be documented in the AML/CFT policy.
How do regulators audit crypto AML programs?
The SFC examines a VATP's AML/CFT program through desktop policy review, targeted regulatory queries, and on-site inspection. Examiners test whether documented procedures match actual operations by sampling case files, reviewing monitoring alert logs, and verifying that the MLRO sign-off trail is contemporaneous. A policy that exists on paper but is not demonstrably operational will fail examination. The SFC increasingly expects independent testing – internal audit or external review – of the AML/CFT function, with results reported to the board and tracked to remediation.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance obligations that sit around them. In our practice, we map the licence, banking and AML policy stack across operating, custody and payment layers before a client commits – because operating without the right policy risks enforcement, frozen rails and lost banking relationships. We regularly advise crypto firms on Hong Kong SFC AML/CFT requirements and cross-border policy design. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML/CFT policy design, VASP licensing documentation, and cross-border compliance frameworks for digital-asset businesses in Hong Kong and across the Asia-Pacific region.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.