Where a compliance review before contracting with a Mainland China entity stands now
A compliance review before contracting with a Mainland China entity. The instrument, the sequence and the risk most miss. Write to info@lockhartyip.com.
The commercial pressure to move quickly is real. A Mainland counterparty has been identified, a term sheet is in hand, and the deal team is asking how soon documentation can begin. The compliance question – whether this entity and this payment channel have been adequately checked – is where deals stall, and occasionally where they collapse entirely.
A compliance review before contracting with a Mainland China entity requires a structured assessment of three distinct risk layers: the entity-level screen under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance and its associated regulatory guidelines, the payment-channel exposure that determines banking access on both sides of the boundary, and the sanctions posture of each jurisdiction engaged. Since the Foreign States Immunity Law (the PRC statute on sovereign immunity, in force for transactions with state-linked entities since 1 January 2024) changed the legal environment for dealing with state-connected counterparties, the review sequence has become more involved, not less.
This analysis maps what a properly constructed review looks like, where the cross-border interface between Hong Kong and the Mainland bites, and where the risk most often sits when a review is done incompletely or in the wrong order.
What is actually at stake commercially?
The compliance review is not a formality. It is the mechanism by which a contracting party demonstrates to its bank, its insurer, and ultimately a regulator or court that it understood the counterparty before funds moved. Getting it right protects the payment channel. Getting it wrong risks account closure, correspondent-bank refusal, and in serious cases, enforcement action by the relevant regulator.
In our cross-border practice, the cost of a stalled payment is rarely the direct loss. It is the downstream effect: a supplier relationship that deteriorates because funds arrive late, a project that misses a drawdown window, a Mainland counterparty that reads the delay as credit weakness. The commercial stakes sit in the payment infrastructure, and the compliance file is the instrument that keeps that infrastructure open.
The Mainland China dimension adds a layer that pure domestic reviews do not carry. A Mainland entity may be state-owned at a level that is not visible from the registered corporate tree. It may sit within a group that has affiliates on a watchlist maintained by a jurisdiction whose unilateral measures Hong Kong does not implement domestically. And it operates within a regulatory environment where the flow of funds across the boundary is governed by capital-account rules that interact, at the banking level, with the checks applied in Hong Kong.
What does a bank's correspondent in New York or London actually see when it receives the SWIFT message? That is the question that should shape the review, not simply whether the Hong Kong-side boxes have been ticked.
How does the governing regime frame the obligation?
The primary instrument in Hong Kong is the Anti-Money Laundering and Counter-Terrorist Financing Ordinance, which imposes customer due-diligence and ongoing-monitoring obligations on financial institutions and designated non-financial businesses and professions. The Ordinance does not stand alone. The relevant regulators – principally the Hong Kong Monetary Authority and, for securities-related activity, the Securities and Futures Commission – issue guidelines that flesh out what reasonable due diligence looks like in practice. Those guidelines are not merely advisory: a departure from them is relevant to whether an entity has met its statutory obligation.
For sanctions, the position in Hong Kong is precise and must be stated accurately. Hong Kong implements United Nations sanctions under the United Nations Sanctions Ordinance. It does not give domestic effect to the unilateral measures of other states. That posture is legally stable and is not a compliance loophole. It is the applicable law, and a compliance review must reflect it accurately rather than treating every foreign watchlist as though it carried equivalent legal weight in Hong Kong.
The practical consequence is this: a Mainland counterparty that does not appear on a UN designation is not sanctioned from the perspective of Hong Kong law. But a correspondent bank operating under a different legal regime may apply its own jurisdiction's unilateral measures to the same payment. The compliance review must address both levels – the Hong Kong legal position and the payment-channel risk that flows from the regulatory posture of the currencies and correspondent institutions involved.
The governing instruments do not resolve this tension. They define the legal obligation in Hong Kong. The payment-channel risk is a commercial and structural matter that sits alongside the legal compliance file, not inside it. Conflating the two is the most common mistake we see in pre-contract reviews assembled without cross-border input.
Where does the cross-border interface actually bite?
The Hong Kong–Mainland interface creates three distinct points of friction that a review must address sequentially. Each has its own governing logic and its own documentary requirement.
The first is the entity-identification problem. A Mainland company exists within a legal system that uses a different corporate registry, different language, and different public-disclosure standards from those familiar to a Hong Kong or international review team. The registered name, the unified social credit code (the PRC's primary business-identification number, maintained by the State Administration for Market Regulation), and the actual beneficial-ownership structure may not be easily reconciled. A review that relies solely on the English-language presentation of the counterparty – a standard pitfall in cross-border settings – will miss discrepancies that a Chinese-language search would reveal.
The second friction point is the ownership-and-control layer. State-owned enterprise structures in the Mainland can be several levels deep. An entity that presents as a private commercial company may have a state-owned enterprise as an indirect shareholder above a certain threshold. That connection is relevant to the risk profile, not because state ownership is itself a compliance concern, but because it affects the due-diligence steps required and the questions a correspondent bank will ask. A review that stops at the first level of ownership has not completed the analysis.
The third point is the payment channel itself. Cross-boundary payments between Hong Kong and the Mainland move through defined corridors – primarily the banking systems of both sides, which interact via settlement mechanisms governed by both the HKMA and the People's Bank of China. The practical availability of a given channel depends on the KYC and AML status of both the payer and the payee at their respective banks. A payment that clears the Hong Kong bank may be flagged or returned at the Mainland correspondent. The pre-contract review should map the intended payment route and identify whether any segment of that route presents a correspondent-bank risk that needs to be addressed before the contract is signed.
The comparative read: what the two systems expect, and where they diverge
Hong Kong and Mainland China operate distinct AML regimes, both broadly aligned with the recommendations of the Financial Action Task Force, but implemented through different legislative instruments, regulatory bodies, and enforcement cultures.
In Hong Kong, the Anti-Money Laundering and Counter-Terrorist Financing Ordinance places the primary due-diligence obligation on the regulated entity – typically the bank or the designated non-financial business. A counterparty that is not itself a regulated institution has a different, but related, obligation: it must be in a position to satisfy its bank's inquiries, which in practice means maintaining a file that mirrors what a regulated institution would hold.
In the Mainland, the comparable instrument is the Anti-Money Laundering Law of the People's Republic of China, which similarly imposes customer identification and transaction-monitoring obligations on financial institutions, with the People's Bank of China as the primary supervisory authority for AML. The Mainland regime has been strengthened in successive years, and the practical sophistication of compliance teams at major Mainland banks has increased markedly. That development matters: it means the Mainland-side bank is itself applying a review to the Hong Kong counterparty, and a file that satisfies the Hong Kong bank may not satisfy the Mainland correspondent without supplementary documentation.
The divergence that creates the most difficulty in practice is in the treatment of beneficial-ownership disclosure. Both systems require ultimate beneficial owner identification. But the thresholds, the acceptable forms of evidence, and the depth of the chain that must be traced differ. A Hong Kong company that has assembled a beneficial-ownership file adequate for its own Significant Controllers Register – in force since 1 March 2018 under the Companies Ordinance – may find that the Mainland bank's requirements go further, particularly for foreign-owned entities operating in sensitive sectors.
A parallel issue arises in reverse. The Mainland counterparty's legal team may have assembled a file that satisfies its own bank's requirements entirely, but that file, when presented to a Hong Kong bank processing the inbound payment, does not contain the specific form of certified documentation the Hong Kong correspondent requires. The mismatch is not a sign of bad faith; it is a structural feature of two well-intentioned regimes that have developed in parallel rather than in alignment.
What does a properly sequenced review actually look like?
A well-constructed pre-contract compliance review for a Mainland China counterparty has a defined sequence. The sequence matters because each step generates information that shapes the next, and short-cutting it is the primary source of the stalled-payment problems our desk sees.
The review opens with entity verification. The Mainland counterparty's corporate identity is confirmed against the relevant registry, the unified social credit code is obtained and verified, and the registered business scope is checked against the nature of the proposed transaction. A mismatch between registered scope and transaction type is a flag that warrants explanation before contracting.
Ownership mapping follows. The beneficial-ownership chain is traced to the level required by the applicable guidelines – in practice, to the individual natural person or persons who ultimately own or control the entity, or, where the entity is state-owned, to the level at which the state interest becomes the relevant fact. This step frequently requires Chinese-language document review and, where the structure is complex, engagement with the Mainland counterparty's own compliance or legal team to obtain the necessary certifications.
The watchlist screen is conducted against UN-maintained designations, consistent with the applicable Hong Kong legal position. The screen also covers the specific sanctions regimes of the currencies and correspondent institutions involved in the proposed payment route. This is not a Hong Kong legal obligation; it is a payment-channel risk assessment. The two should be clearly labelled as distinct in the compliance file, because conflating them creates a misleading picture of the legal exposure.
The payment-route analysis is the step most often omitted. Before the contract is signed, the parties should identify the banks through which funds will move, confirm that each bank's correspondent-banking relationships support the intended currency and counterparty, and establish whether any supplementary documentation will be required at any point in the chain. In our experience, this step, done before contracting rather than after, prevents the majority of payment delays that arise on Mainland-related transactions.
The file is then assembled, documented, and retained. The documentation serves two purposes: it satisfies the bank's inquiry when the payment is initiated, and it provides evidence of reasonable diligence if the transaction is later questioned by a regulator. A review that is done thoroughly but not documented is not a compliance file; it is an undocumented internal conversation.
The sequence above describes the standard position. Your matter turns on the specific entity, the jurisdictions actually engaged, and the payment route – which is where the risk is won or lost. For a structured assessment of your pre-contract position across Hong Kong and the Mainland, write to us at info@lockhartyip.com.
A micro-scenario: where the review stalled and what reopened it
A mid-sized European trading group entered into a supply arrangement with a Mainland manufacturer in early 2025. The group's internal compliance team conducted a screen using a standard international watchlist tool and cleared the counterparty. The first payment, initiated through the group's Hong Kong banking entity, was held by the correspondent bank pending further documentation. The counterparty interpreted the delay as a credit problem and began looking at alternative buyers.
When the matter came to our desk, the issue was straightforward in diagnosis and more involved in remediation. The screen had been run against an external watchlist that included certain unilateral measures not applicable in Hong Kong. That screen had generated a false flag, which the team had noted and dismissed. But the underlying entity-verification step had not been completed: the unified social credit code had not been confirmed against the registry, and the ownership chain had been traced only to the first corporate level. The correspondent bank's inquiry related precisely to that gap.
We prepared a supplementary file: confirmed entity identity, completed ownership mapping with certified translation, and documented the Hong Kong sanctions position with reference to the applicable ordinance and the specific UN-designation status of the counterparty. The correspondent bank's inquiry was resolved. The payment moved within one cycle. The supply relationship was preserved, though the reputational cost of the initial delay was not fully recoverable.
A second matter, from a different sector, illustrates the reverse problem. A Hong Kong-based services firm contracting with a state-linked Mainland entity had assembled a detailed compliance file – entity verification, ownership mapping, watchlist screen – but had not considered the post-1 January 2024 position under the Foreign States Immunity Law for transactions with entities that carry a state connection. The file was technically sound for a private-company counterparty. For a state-linked entity, it omitted the additional analysis that the changed legal environment required. The contract had been signed; the issue surfaced when the firm's insurer reviewed the transaction. A revised file was prepared and accepted, but the oversight illustrated a real gap in how the post-2024 environment was understood.
Where the risk sits now: our analytical read
The risk environment for contracting with Mainland China entities has not simplified. It has stratified. The structural complexity sits at three levels.
At the entity level, the increased depth of ownership disclosure required by both the Hong Kong and Mainland banking systems means that a surface-level screen is no longer adequate. The practical bar for what a bank will accept before processing a cross-boundary payment has risen, and it is continuing to rise. A compliance file assembled to a standard that was adequate three years ago may not satisfy a correspondent bank today.
At the payment-channel level, the correspondent-banking landscape for cross-boundary transactions involving currencies that carry unilateral-measure exposure has become more variable. A payment that cleared without question in one quarter may encounter additional scrutiny in the next, depending on the evolving posture of correspondent institutions operating under different legal regimes. This is not a legal risk in the Hong Kong sense; it is an operational and banking-access risk that must be managed through the structure of the transaction and the choice of payment route.
At the regulatory-interface level, the interaction between the Hong Kong AML regime and the Mainland AML regime has become more important as cross-boundary compliance expectations converge in some respects and diverge in others. A party that has not engaged with both sides of the interface may find that its file, though internally consistent, does not address the questions that the other side's bank or regulator will ask.
If an earlier review, filing, or payment attempt has produced an adverse or stalled result, a second read can identify the structural gap and the routes still open. For a preliminary assessment of your cross-boundary contracting position, email info@lockhartyip.com.
Our read on where the risk is highest: mid-market transactions where neither party has a dedicated compliance function, where the review has been delegated to a generalist team without cross-border experience, and where the payment route has been left to the banks to sort out rather than mapped in advance. These are the fact patterns that generate the majority of the stalled-payment matters that come to our desk.
The argument-led position: what a compliance review is actually for
There is a version of the compliance review that is done to satisfy a bank's inquiry. And there is a version that is done to understand the counterparty before the contract is signed. The second is materially more valuable, and it is the version that tends not to surface the problems that cause payment disruption later.
The prevailing myth in this space is that a clean watchlist screen is a compliance review. It is not. It is one step in a multi-step process. A screen that returns no hits against a UN designation list tells you one specific thing: the counterparty does not appear on the UN consolidated sanctions list as of the date the screen was run. It does not tell you who owns the entity, whether the payment route is operationally clean, whether the registered business scope is consistent with the transaction, or whether a state connection requires additional analysis under the current legal environment.
The consequence of treating the screen as the review is that the gaps appear at the moment when the contract has been signed and the payment needs to move. At that point, the leverage sits with the bank or the correspondent, not with the contracting parties. A complete review, done before signing, gives the contracting parties the information they need to structure the transaction – including the payment route – in a way that is operationally sustainable.
Is every Mainland China transaction a high-complexity compliance exercise? No. Many are straightforward once the entity-verification and payment-route steps are done correctly. But the assumption that a transaction is straightforward without doing those steps is where the exposure accumulates.
The Sanctions & AML practice at Lockhart & Yip approaches pre-contract compliance review from the cross-border interface outward. We look at the payment channel first, because that is where the operational risk sits. We look at the entity structure second, because that is what the bank will ask. And we look at the governing legal position in Hong Kong accurately, which means neither over-stating nor under-stating the sanctions posture that applies. For further context on Hong Kong's sanctions position in cross-border transactions, see our guide to Hong Kong's sanctions posture in cross-border transactions. For a worked illustration of a source-of-funds file in a CIS counterparty matter, see the AML source-of-funds matter note on our site.
Decision map: situation, instrument, route, timing, risk
The appropriate scope and urgency of the compliance review depends on the specific fact pattern. The following mapping reflects our desk's read on the principal scenarios.
Where the Mainland counterparty is a privately held operating company with a single corporate level and no state-ownership interest, and the payment is in a currency that does not engage correspondent-bank sensitivity, the review is contained: entity verification, beneficial-ownership mapping to the natural-person level, UN screen, payment-route confirmation. The review should be completed before the contract is signed, and the file should be retained. Timing: a well-prepared review of this type can be completed within a short working period if the counterparty is cooperative in providing documentation.
Where the Mainland counterparty has a multi-level corporate structure, state-linked ownership at any level, or operates in a sector that is subject to heightened scrutiny under applicable regulatory guidance, the review expands materially. The ownership-mapping step requires more depth, the payment-route analysis must consider a broader set of correspondent-banking dependencies, and the file must address the post-1 January 2024 legal environment for state-connected entities. Timing is longer and depends substantially on the counterparty's responsiveness in providing certified documentation.
Where the transaction involves a currency that carries unilateral-measure exposure in a correspondent-bank jurisdiction – meaning the currency or the payment route passes through a banking system that applies its own jurisdiction's measures to the counterparty – the payment-route analysis becomes the critical step. The legal position in Hong Kong does not resolve this exposure. It must be managed through the choice of currency, the choice of correspondent, and in some cases the structure of the payment itself. This is a commercial and banking-access matter, not an AML-law matter, and the two should be handled in parallel rather than in sequence.
Where a prior payment has been held, returned, or flagged, the diagnostic step is to identify at which point in the correspondent chain the flag arose and why. The remediation is then targeted at that specific gap in the file or the payment route. A general strengthening of the compliance file without identifying the specific gap is unlikely to resolve the problem.
Related practices
- Sanctions & AML – cross-border compliance review, counterparty screening, and payment-channel risk assessment
- Corporate Counsel – entity structuring, governance, and cross-boundary documentation for Mainland-connected groups
Frequently asked questions
How does the cross-border element affect a compliance review before contracting with a Mainland China entity?
What is the first step in a compliance review before contracting with a Mainland China entity?
What documents are needed for a compliance review before contracting with a Mainland China entity?
Speak with Lockhart & Yip
For a scoped view of your matter, contact info@lockhartyip.com. Discuss your matter →
Related
- Sanctions Aml
- Hong Kong S Sanctions Posture Cross Border Transaction 7
- Aml Source Funds File Cis Counterparty Cis Matter
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@lockhartyip.com.