Where AML obligations for a virtual-asset service provider stands now
AML obligations for a virtual-asset service provider. The current cross-border position and what it means in practice. Write to info@lockhartyip.com.
The question reaches our desk with increasing frequency. A virtual-asset service provider – whether a centralised exchange, an OTC desk, or a custody operation – has built its compliance programme around one set of rules. Then a regulator asks a pointed question, a counterparty triggers a due-diligence flag, or a cross-border transfer sequence falls foul of a travel-rule check. At that point, the gap between a programme designed in theory and one that functions under enforcement scrutiny becomes visible.
Anti-money laundering obligations for virtual-asset service providers in Hong Kong are governed primarily by the Anti-Money Laundering and Counter-Terrorist Financing Ordinance, which was extended to centralised virtual-asset trading platforms through a mandatory licensing regime that commenced on 1 June 2023. The Securities and Futures Commission is the licensing authority. Operators subject to the regime must maintain customer due diligence systems, beneficial-ownership records, and comply with the FATF travel rule for virtual-asset transfers. The cross-border dimension bites at every level: where the platform is incorporated, where its users are located, and where the assets move.
This analysis covers the commercial stakes, the governing instruments, how the cross-border interface complicates the position, and where we read the enforcement risk sitting today.
What is actually at stake commercially
Regulatory exposure in the virtual-asset sector carries consequences that extend well beyond an administrative fine. For a licensed platform, a formal finding on AML deficiencies can trigger licence suspension, a direction to cease onboarding, or a condition requiring an independent audit – each of which halts the commercial operation.
For an unlicensed operator that believes it falls outside the mandatory licensing perimeter, the risk is different but equally concrete. Operating a centralised virtual-asset trading platform in Hong Kong without a licence is itself a criminal offence under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance. The compliance question and the licensing question are therefore inseparable.
Beyond the operator, the downstream effects matter. A platform with a weak AML programme attracts institutional counterparties that cannot pass their own compliance cycles. Banks and prime-brokerage desks conducting enhanced due diligence on a virtual-asset business will scrutinise the AML framework, the travel-rule implementation, and the source-of-funds documentation as part of their own regulatory obligations. A gap in one feeds into a problem at the other. In our cross-border practice, we see this pattern regularly: the immediate trigger is a correspondent bank's due-diligence questionnaire, and the underlying issue is an AML programme that was built for another jurisdiction.
What is at stake, then, is not only regulatory standing. It is the commercial viability of the business – its ability to bank, to partner, and to scale.
What does the governing regime actually require?
The Anti-Money Laundering and Counter-Terrorist Financing Ordinance is the primary instrument. It was extended to virtual-asset trading platforms through the mandatory licensing regime that made the Securities and Futures Commission the regulatory authority for centralised platforms. The 1 June 2023 commencement date marks the point at which operating without a licence became a criminal offence for in-scope operators.
The obligations the regime imposes on licensed platforms fall into three distinct categories. First, customer due diligence: this means identity verification at onboarding, ongoing monitoring for changes in risk profile, and enhanced measures for high-risk clients. The standard follows the Financial Action Task Force recommendations and requires a risk-based approach – a phrase that, in enforcement practice, means documented risk assessments rather than a one-size threshold.
Second, beneficial-ownership identification. Institutional and entity clients require look-through analysis to the ultimate natural-person beneficial owner. For a virtual-asset business with a global client base, this frequently requires accepting identity documents from dozens of jurisdictions and assessing their equivalence to Hong Kong standards. The practical burden is material.
Third, the FATF travel rule for virtual-asset transfers. Where a platform facilitates a transfer of virtual assets, it is required to collect and transmit originator and beneficiary information alongside the transfer. The travel rule applies regardless of the amount. Implementation requires technical infrastructure for counterparty data exchange – and a clear position on what happens when the counterparty is a non-compliant provider or a non-custodial wallet.
Where a virtual asset is classified as a "security" or "futures contract" under the Securities and Futures Ordinance, the Securities and Futures Commission's licensing requirements under that ordinance apply in addition to the Anti-Money Laundering and Counter-Terrorist Financing Ordinance framework. The two regimes can run in parallel, and an operator that has correctly identified its Anti-Money Laundering and Counter-Terrorist Financing Ordinance obligations may still face a gap on the securities side.
The contextual bridge here is important. Understanding what the regime requires is a necessary first step. Mapping which requirements apply to a specific operator's product mix, client base, and transfer architecture is where the analysis actually starts.
The sequence above describes the standard position. Your matter turns on the documents, the jurisdictions actually engaged, and the order of steps – which is where the route is won or lost. To discuss how the Anti-Money Laundering and Counter-Terrorist Financing Ordinance framework applies to your cross-border position, contact info@lockhartyip.com.
How does the cross-border interface bite in practice?
A virtual-asset service provider operating through Hong Kong rarely has a purely domestic footprint. Its incorporation may be in the British Virgin Islands or the Cayman Islands. Its users may be resident across the Mainland, Southeast Asia, or the Middle East. Its assets may move across chains that route through multiple jurisdictions simultaneously. Each of those dimensions creates a separate regulatory interface.
Take the incorporation question first. A platform incorporated in the BVI or the Cayman Islands and serving users in Hong Kong, or actively marketing to Hong Kong users, is within the perimeter of the Anti-Money Laundering and Counter-Terrorist Financing Ordinance licensing requirement. The test is not the jurisdiction of incorporation; it is the nature and location of the business activity. Operators in offshore holding centres who assumed that Hong Kong AML rules applied only to Hong Kong-incorporated entities should verify that assumption carefully.
The Mainland dimension adds a further layer. Hong Kong implements United Nations sanctions and does not give domestic effect to unilateral measures of other states. That creates a different sanctions overlay from the one that applies in the United States, the European Union, or the United Kingdom. A platform with users or counterparties in the Mainland may face a compliance architecture that is simultaneously compliant under Hong Kong rules and problematic under the rules of another jurisdiction – or vice versa. Counsel on our desk regularly see this tension in cross-border deals and transaction structures where the same counterparty sits on multiple screening lists depending on which regime governs.
Travel-rule implementation illustrates the cross-border difficulty concretely. The obligation requires passing originator and beneficiary data alongside a transfer. When the counterparty wallet belongs to a provider in a jurisdiction that has not yet implemented the travel rule, or belongs to a non-custodial address, there is no compliant counterparty to receive or transmit the data. The Hong Kong platform must then decide how to handle the transfer: block it, limit it, or document the inability to comply with enhanced due diligence on the counterparty. Each option carries a different risk profile, and the right answer depends on the specific facts.
For a platform with a Southeast Asian or Middle Eastern client base, the cross-border element produces a further complication. Customer due diligence documents from those jurisdictions vary in their recognition under Hong Kong standards. An AML programme that accepts a document type from one jurisdiction without verifying its equivalence risks a gap that will appear in any regulatory examination.
The comparative read: where other systems draw the line differently
Hong Kong sits within a cluster of jurisdictions that have moved towards mandatory licensing of centralised virtual-asset platforms. Singapore, the UAE, and the United Kingdom have each established regulatory regimes, and the Financial Action Task Force recommendations form the common baseline. But the perimeters, the licensing authorities, and the enforcement posture differ in ways that matter to an operator with a cross-border footprint.
In Singapore, the Payment Services Act governs digital-payment token service providers, and the Monetary Authority of Singapore is the licensing authority. The customer due diligence and record-keeping obligations track the FATF standard, but the product perimeter is drawn differently from the Hong Kong position. A platform that is in-scope in Hong Kong may or may not require a separate licence in Singapore depending on its product structure. The question is not academic: operating in both markets without assessing both perimeters is an enforcement risk on both sides.
The United Arab Emirates has fragmented its approach across onshore UAE, the Abu Dhabi Global Market, and the Dubai International Financial Centre. Each has its own regulatory authority and its own AML rules. For a platform that routes capital through the UAE – common in cross-border structures serving Mainland and Middle Eastern principals – the compliance architecture must address which UAE regime actually applies to which entity in the structure.
The United Kingdom has adopted a registration approach for crypto-asset businesses under the Money Laundering, Terrorist Financing and Transfer of Funds Regulations, with the Financial Conduct Authority as the competent authority. The travel rule applies. The threshold and product scope questions differ from Hong Kong. An operator with a UK-facing business running through a Hong Kong licensed entity must assess whether the UK arm requires its own registration.
What emerges from the comparative read is a picture of convergence on the FATF baseline but divergence on scope, thresholds, and enforcement intensity. A compliance programme designed for one jurisdiction frequently contains gaps when exported to another. The cross-border operator needs a programme designed for the multi-jurisdiction position from the outset, not a Hong Kong programme with additions bolted on later.
A micro-scenario: where the gap appears under examination
A Central Asian operator with a BVI holding entity and a Hong Kong-licensed exchange subsidiary came to us in early 2026 following a correspondent bank's enhanced-due-diligence request. The bank had identified a pattern of transfers to non-custodial wallets without travel-rule data. The platform's AML programme had a travel-rule policy for transfers between licensed counterparties but no documented procedure for the non-custodial scenario.
The gap was not malicious. The programme had been designed when the travel rule was first implemented, and the non-custodial question had been deferred pending industry guidance. By the time the bank asked the question, the deferral had become a documented omission in the compliance file.
We reviewed the AML programme, mapped the transfer architecture against the Anti-Money Laundering and Counter-Terrorist Financing Ordinance requirements, and identified the specific points at which the programme required updating. We then prepared the documentation the bank needed and the internal procedure the platform required. The correspondent banking relationship was preserved. The platform had a programme that could withstand the next examination.
A second scenario: a Southeast Asian group operating a custody service through a Hong Kong entity had designed its customer due diligence programme around the identity-document types common in its home market. A regulatory examination identified that several document types accepted as standard in the home market had not been assessed for equivalence under Hong Kong standards. The remediation required a retrospective review of a portion of the client base and a revised onboarding procedure. The lesson from our desk's perspective is that a programme built for one market's document set does not transfer without assessment.
Where the enforcement risk sits today
The Securities and Futures Commission has been direct in its public communications about its enforcement approach to unlicensed virtual-asset trading activity. The combination of criminal liability for unlicensed operation and civil consequences for AML failings creates a layered exposure for operators who have not assessed their position carefully.
The enforcement risk in the current environment concentrates in three areas.
First, the unlicensed-operation question. A number of platforms that were operating before 1 June 2023 applied for licences under the transitional provisions. Those transitional provisions did not extend indefinitely. A platform that applied during the transitional window but has not yet received a decision sits in a different position from one that never applied. The precise current status of any transitional position should be verified, as the position continues to develop.
Second, the travel-rule implementation gap. The FATF travel rule is a regulatory requirement, not a best-practice suggestion. An operator with documented procedures for licensed-counterparty transfers but no procedure for non-custodial wallets has a gap that will appear in any examination. The SFC's examination focus in recent cycles has included travel-rule implementation as a specific area of enquiry.
Third, the beneficial-ownership question for institutional clients. For platforms serving funds, family offices, and corporate treasury desks, the look-through obligation to the ultimate natural-person beneficial owner creates a recurring compliance burden. An entity client that restructures – a common occurrence in cross-border holding structures – may change the beneficial-ownership picture without triggering an automatic notification to the platform. The AML programme needs a mechanism for periodic re-verification, not only initial onboarding review.
If an earlier filing, structure or enforcement attempt produced an adverse or stalled result, a second read can identify the strategic error and the routes still open. To discuss your current AML programme and where the gaps may sit, contact info@lockhartyip.com.
What foreign counsel – and operators structuring without Hong Kong advice – frequently miss
The most common analytical error we observe in cross-border virtual-asset structures is the assumption that a compliance programme designed under the rules of a home jurisdiction – whether that is a European Union member state, Singapore, or the United States – satisfies the Hong Kong position by equivalence. It does not, automatically.
Hong Kong's regulatory perimeter is defined by the Anti-Money Laundering and Counter-Terrorist Financing Ordinance and the Securities and Futures Commission's licensing framework. Those instruments have their own scope rules, their own definitions, and their own enforcement mechanisms. The fact that a platform has a Financial Conduct Authority registration, a MAS licence, or a VARA approval in the UAE is relevant context but not a substitute for a Hong Kong compliance assessment.
A second frequent gap is in the sanctions overlay. Because Hong Kong implements United Nations sanctions and does not give domestic effect to unilateral measures, the sanctions screening obligations for a Hong Kong-licensed platform differ from those applicable to a US-regulated or EU-regulated entity. An operator that screens against the OFAC list and the EU consolidated list – both unilateral measures – is doing more than Hong Kong requires in one direction and potentially something different in another. The compliance programme needs to reflect the specific regime that applies, not the most conservative available screen.
Third, the structure question. Counsel on our desk regularly see virtual-asset operators who have used an offshore holding entity – BVI or Cayman – as the top structure, with a Hong Kong-licensed entity below it. The AML obligations attach to the Hong Kong licensed entity. But the beneficial-ownership and source-of-funds position of the offshore holding entity is relevant to the licensed entity's own due diligence on its corporate client – which is the holding entity itself. The compliance programme needs to address this internal-group dimension, not only the external client-facing obligations.
Our read on where the position is going
The virtual-asset regulatory environment in Hong Kong has moved from a voluntary opt-in to a mandatory licensing regime in a relatively short period. The trajectory points towards further convergence with the FATF standard, expanded travel-rule implementation requirements, and closer attention to the boundary between licensed centralised platforms and decentralised or non-custodial services.
The stablecoin dimension represents the next significant perimeter question. The Hong Kong Monetary Authority licensing regime for fiat-referenced stablecoin issuers commenced in 2025. The precise current scope and requirements should be verified before an operator relies on any specific position, as the regime continues to develop. But the direction is clear: entities that issue, redeem, or intermediately handle fiat-referenced stablecoins in Hong Kong are within a regulated perimeter that carries its own AML and licensing obligations distinct from the Securities and Futures Commission's virtual-asset trading platform framework.
For operators who have built their compliance programme on the current state of the rules, the forward risk is that those rules continue to develop. A programme that was adequate in 2023 may contain gaps by 2025 standards. A programme that was built only for the current licensing framework may not address the stablecoin or non-custodial questions that are now arriving in the regulatory conversation.
The read from our desk is that enforcement intensity is likely to increase as the licensing regime matures. Early enforcement actions in any newly licensed sector tend to concentrate on the operators who are most obviously non-compliant. As the regime settles, the enforcement focus typically shifts to the technical quality of compliance programmes at licensed operators. The question for a platform that is already licensed is not whether it will attract scrutiny but whether its programme is examination-ready when scrutiny comes.
For matters involving cross-border structures, the tax and holding-structure position often intersects with the AML and licensing questions. Our Tech & Web3 practice addresses the full range of those interactions, and we work alongside locally licensed Hong Kong firms on matters that require Hong Kong-law advice. Operators considering their position on cross-border agreements with a SaaS or data component that touches multiple jurisdictions may also find our analysis of cross-border SaaS and data agreements relevant to their wider compliance architecture. Separately, our analysis of the virtual-asset trading platform licence in Hong Kong addresses the licensing mechanics in detail.
Related practices
- Sanctions & AML – cross-border AML compliance, sanctions-neutral contracting, source-of-funds files
- Holding Structures – BVI and Cayman holding architecture, substance, and beneficial-ownership mapping
Frequently asked questions
Do I need a Hong Kong adviser for AML obligations for a virtual-asset service provider?
How does the cross-border element affect AML obligations for a virtual-asset service provider?
What is the first step in AML obligations for a virtual-asset service provider?
Speak with Lockhart & Yip
For a scoped view of your matter, contact info@lockhartyip.com. Discuss your matter →
Related
- Tech Web3
- Cross Border Saas Or Data Agreement Touching Cyprus 3
- Virtual Asset Trading Platform Licence Hong Kong Analysis 2
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@lockhartyip.com.