HONG KONG · EAST ↔ WEST
info@lockhartyip.comResponse within 4 hours (UTC+8)
Discuss your matter
Home/Insights/Disputes & Arbitration
Tech & Web3

How to approach AML obligations for a virtual-asset service provider

AML obligations for a virtual-asset service provider. A practical guide for in-house counsel. The Hong Kong angle in focus. Write to info@lockhartyip.com.

The decision to operate as a virtual-asset service provider in or through Hong Kong does not begin with a technology question. It begins with a compliance question: which regulator applies, under which statute, and what the anti-money laundering programme must look like before the first client is onboarded. For an in-house team encountering this for the first time – or for a founder whose counsel is overseas and unfamiliar with the Hong Kong regime – the sequence of steps is not obvious. Getting it wrong early creates structural problems that compound at each subsequent stage.

A virtual-asset service provider operating in Hong Kong is subject to the licensing and anti-money laundering regime administered by the Securities and Futures Commission under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance. Where the virtual assets involved qualify as securities or futures contracts, a parallel licensing obligation under the Securities and Futures Ordinance also applies. The VATP licensing regime commenced on 1 June 2023, and AML compliance is a condition of licensing, not a post-licence formality.

This guide sets out the decision the reader faces, the sequence of steps in order, the gates at each step, and the common mistakes that cause delay or regulatory exposure. The cross-border dimension – particularly the interaction between the Hong Kong regime and a firm's home jurisdiction or offshore structure – is addressed at each stage.

What is the decision? Understanding the licensing threshold before anything else

The first question is whether the firm operates a centralised virtual-asset trading platform in Hong Kong or actively markets to Hong Kong investors. If the answer to either question is yes, the mandatory licensing regime under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance applies. This is not a matter of election; it is a condition of operating lawfully.

The Securities and Futures Commission – the SFC (Hong Kong's integrated financial regulator for securities, futures and now virtual assets) – is the licensing authority for VATPs (centralised virtual-asset trading platforms, meaning exchanges and similar venues that facilitate the trading of virtual assets for clients). A firm that is in scope cannot defer the licensing decision to a later funding round or a future expansion phase. The obligation runs from the point of operating.

The secondary question is the character of the assets traded. Where a virtual asset is a "security" – broadly, an interest in a collective investment scheme, a share or a debenture, assessed on the economic substance of the instrument – or a "futures contract", the Securities and Futures Ordinance applies alongside the VATP regime. Two licensing tracks can therefore apply to a single platform. That determination must be made asset by asset, and it shapes the entire compliance architecture.

For a firm incorporated offshore – in the British Virgin Islands, the Cayman Islands or elsewhere – but operating a platform accessible to Hong Kong users, the reach of the regime extends beyond entities incorporated in Hong Kong. Our desk regularly sees offshore structures that were designed without accounting for the Hong Kong nexus, and the remedial work at that point is substantially more demanding than the planning work at inception.

What does the AML programme need to look like? The governing instrument

The Anti-Money Laundering and Counter-Terrorist Financing Ordinance sets the statutory floor for AML obligations, and the SFC's published guidelines translate that floor into operational requirements for VATPs. The programme has several interlocking components, and a weakness in any one of them will surface in a licensing review or a supervisory examination.

The core components are: a written AML and counter-terrorist financing policy; a risk-based customer due diligence programme; a transaction monitoring system calibrated to the risk profile of the client base; a suspicious transaction reporting procedure; record-keeping for a minimum statutory period; and a senior compliance officer with genuine authority and sufficient resource. The compliance officer is not a formality. The SFC will assess the person's qualifications and the practical authority they hold within the firm's governance structure.

Customer due diligence – CDD (the process of identifying and verifying a client's identity and understanding the purpose and expected nature of the business relationship) – must be conducted before onboarding. For higher-risk clients, enhanced due diligence applies. The categories that trigger enhanced CDD include politically exposed persons, clients in higher-risk jurisdictions, and relationships involving complex structures or large transaction volumes. A risk-based approach means the programme must be documented, reviewable, and defensible – not simply adequate on paper.

The FATF travel rule – the Financial Action Task Force requirement that originators and beneficiaries of virtual-asset transfers above a defined threshold exchange identifying information – applies to VATPs in Hong Kong. This is a technical and operational requirement as much as a legal one. The firm must be able to transmit and receive travel-rule data and must have counterparty due diligence procedures for transfers to or from non-compliant VATPs. Many cross-border platforms underestimate the implementation time for travel-rule compliance. In our experience, it is consistently the element that delays licence applications.

Step one: Determine the regulatory perimeter before structuring the entity

The structuring decision and the regulatory perimeter analysis should happen in parallel, not in sequence. A firm that selects its corporate domicile and then maps its regulatory position often finds that the structure it has chosen creates unnecessary friction with the licensing requirements or AML obligations in the jurisdiction it intends to use as its hub.

The gate at this step is a written perimeter analysis addressing: which activities trigger the VATP licensing obligation; whether any virtual assets on the proposed platform qualify as securities; the jurisdiction of incorporation and its interaction with the Hong Kong nexus; and whether any exemption or transitional provision applies. The transitional provisions that applied at the commencement of the regime in 2023 had defined windows; parties should verify whether any transitional relief remains available to their specific situation before acting.

For a cross-border structure – for example, a Hong Kong-incorporated operating entity with a Cayman parent and a BVI treasury vehicle – the perimeter analysis must trace each entity's role in the platform's operations. Regulatory exposure does not necessarily stop at the entity that holds the licence. Affiliate flows, intragroup funding arrangements, and marketing activities can each independently engage the AML obligations of entities that are not the licensed entity.

The sequence above describes the standard position. Your specific perimeter turns on the assets traded, the jurisdictions actually engaged, and the role of each entity in the group – which is where the analysis is won or lost before a single application is filed.

For a structured assessment of your platform's regulatory perimeter across the relevant jurisdictions, write to us at info@lockhartyip.com.

Step two: Build the AML programme, not the application

The licence application is downstream of the compliance programme. Firms that sequence these steps in reverse – preparing an application first and building the programme to match the application – face a predictable problem: the programme, when scrutinised, does not reflect actual operations, and the SFC's review identifies the gap.

The programme must be built around the firm's actual risk profile. That means documenting the client types the platform is designed to serve, the jurisdictions from which clients will be sourced, the transaction volumes and patterns anticipated at each risk tier, and the technical infrastructure that supports monitoring. The programme then maps controls to each risk element. This is not a template exercise. A programme copied from another jurisdiction's standards – or from a generic compliance framework – will not satisfy the SFC's requirements if it is not calibrated to the firm's specific business model and client base.

The specific elements the SFC expects to see in a VATP's AML programme track the requirements set out in its published guidelines for VATPs. Those guidelines are detailed. They address CDD, enhanced CDD, travel-rule implementation, suspicious transaction reporting, staff training, and internal audit. Each element requires documented policies, assigned responsibility, and evidence of operation. Assertions of intent are not compliance. The SFC expects to see records that demonstrate the programme has been tested and that it functions as described.

A common mistake at this stage is treating the compliance officer role as an administrative appointment rather than a substantive governance position. The individual must have the authority to escalate concerns, the access to transaction data needed to discharge the role, and the reporting line that makes escalation effective. A compliance officer who lacks authority or information is a liability, not an asset, in a supervisory examination.

How does the cross-border dimension affect the AML obligations?

The cross-border dimension is not incidental to VATP AML compliance. It is central to it. A Hong Kong-regulated platform that accepts clients from the Mainland, the Middle East, Europe or the CIS states faces a client-risk profile that is inherently cross-border, and the AML programme must reflect that.

For Mainland-connected clients, source-of-funds verification is a particularly sensitive point. The combination of capital controls under Mainland law, the potential for complex holding structures, and the volume of cross-border transactions that flow through Hong Kong means that a genuinely risk-based approach to Mainland-sourced clients requires more than standard CDD. Enhanced due diligence, documentation of the source of funds, and periodic review of the relationship are consistent requirements in our cross-border practice.

For clients from jurisdictions subject to heightened FATF scrutiny – the "grey list" and "black list" jurisdictions – the obligation to apply enhanced CDD is statutory, not discretionary. The SFC expects the platform to have a current list of such jurisdictions and a procedure for applying the relevant enhanced measures from the point of onboarding. Maintaining that list requires an ongoing process, not a one-time check at programme inception.

Sanctions screening is a related but distinct obligation. Hong Kong implements United Nations sanctions. The Anti-Money Laundering and Counter-Terrorist Financing Ordinance and the United Nations Sanctions Ordinance together establish the screening obligation. A VATP must screen clients and transactions against UN-designated lists and maintain a procedure for handling a potential match. Hong Kong does not give domestic effect to the unilateral sanctions regimes of other states, but a platform with international counterparties or investors may face contractual or correspondent-banking pressure that requires the compliance file to address those regimes as a matter of commercial risk, distinct from the legal obligation.

The interaction with the platform's banking relationships is practical and immediate. Banks that provide fiat settlement for VATPs in Hong Kong conduct their own AML due diligence on the platform. A VATP whose AML programme does not meet the bank's correspondent standards may find its banking arrangements withdrawn or restricted – which is operationally catastrophic. Building the programme to a standard that is defensible both to the SFC and to the firm's banking counterparties is not gold-plating. It is the minimum for sustainable operation.

Step three: The licence application and what follows

Once the AML programme is built and tested – not merely drafted – the licence application to the SFC can be prepared. The application requires detailed disclosure of the firm's ownership structure, the identity and qualifications of key personnel, the governance arrangements, the technology infrastructure, the proposed product set, and the AML and risk-management framework. Each element is assessed. Incomplete applications cause delay; inconsistent applications cause deeper scrutiny.

The SFC's review process is substantive and can be prolonged. Applicants should not assume that filing the application begins a defined calendar window at the end of which a licence will issue. The review involves written questions, requests for additional documentation, and – in some cases – meetings with senior personnel. A firm that is not prepared for that level of engagement will find the process significantly longer than anticipated.

Post-licensing, the AML obligations do not diminish. They intensify in one respect: the firm is now accountable to a named regulator with inspection authority. The compliance programme must be maintained, updated for regulatory guidance, and audited. Annual reporting, suspicious transaction reporting, and the ongoing training obligations each have their own rhythm. A firm that treats licensing as the destination, rather than the beginning of a regulated operating relationship, is likely to encounter supervisory difficulty.

For a firm that has already filed an application and encountered a request for additional information, a second read of the AML programme and the application documents can identify the gap and the response approach.

If an earlier filing or application produced an adverse result or stalled, a review of the programme and the application documents can identify where the gap arose and what remains available. To discuss your position, contact us at info@lockhartyip.com.

Common mistakes and how the route avoids them

The most consistent mistake is sequencing: building the application before the programme, or designing the entity structure before the regulatory perimeter. Both errors generate remedial work that is more expensive and more time-consuming than the planning work would have been.

The second common mistake is treating the AML obligations as a Hong Kong-only question. A VATP that operates cross-border – which is most of them – is subject to AML obligations in each jurisdiction where it has a regulatory nexus. The Hong Kong programme must be capable of meeting the SFC's requirements; it must also be consistent with the obligations in the firm's other operating jurisdictions. Where those obligations diverge, the more demanding standard should set the floor for the programme globally.

The third mistake is underestimating travel-rule implementation. The FATF travel rule requires technical integration with counterparty VATPs, a process that takes calendar time and requires the cooperation of counterparties who may themselves be at different stages of implementation. Treating travel-rule compliance as a post-licensing matter is a category error. The SFC expects it to be addressed in the application.

A myth worth addressing directly: some founders believe that incorporating an operating entity offshore – in the BVI or Cayman, for example – places them outside the Hong Kong regulatory perimeter. It does not. The test is the nature of the activities and whether they are conducted in Hong Kong or directed at Hong Kong users. Offshore incorporation does not resolve a Hong Kong regulatory exposure. It may, in some cases, create additional complexity because the governance and AML requirements of two jurisdictions then apply simultaneously.

Decision checklist

Before approaching the SFC, and before building the compliance programme, the following questions should be answered in writing:

  • Does the platform's proposed activity fall within the definition of operating a VATP in Hong Kong? Consider the jurisdictional nexus carefully, including marketing and client acceptance.
  • Do any of the proposed virtual assets qualify as securities or futures contracts under the Securities and Futures Ordinance? This assessment must be made asset by asset.
  • Is the firm's corporate structure – including any offshore parent, treasury or marketing entities – mapped for regulatory and AML exposure in each relevant jurisdiction?
  • Has the AML programme been drafted around the firm's actual risk profile, client types and anticipated transaction patterns – not a generic template?
  • Is the compliance officer identified, genuinely empowered, and resourced? Does the firm's governance structure make the role effective?
  • Is travel-rule compliance technically implemented and tested, not merely planned?
  • Are sanctions screening procedures in place for UN-designated lists, with a documented procedure for handling a potential match?
  • Has the firm's banking relationship been assessed for the counterpart AML due diligence the bank will apply to the platform?
  • Is the enhanced CDD procedure documented for the client categories and jurisdictions that will trigger it from day one?

A yes to each question, supported by documentation, is the position from which a licensing application and a regulatory relationship can be managed with confidence. A provisional yes – where the answer is partially correct or documented only in intent – is a risk that will surface at a point in the process where it is harder to address.

For related perspectives on structuring digital-asset operations through Hong Kong, see our analysis on digital-asset fund structures through Hong Kong and Cyprus and our briefing on cross-border agreements touching the Mainland. For an overview of our Tech & Web3 practice and the range of matters we handle, see the Tech & Web3 practice page.

Related practices

  • Sanctions & AML – counterparty screening, AML programme review, and sanctions-neutral contracting across Greater China
  • Holding Structures – offshore parent, operating entity and treasury design for cross-border platforms

Frequently asked questions

What documents are needed for AML obligations for a virtual-asset service provider?
A VATP operating in Hong Kong must prepare and maintain a written AML and counter-terrorist financing policy, a risk-based CDD programme, transaction monitoring records, a suspicious transaction reporting procedure, and evidence of staff training. For the SFC licence application, the firm must also provide full disclosure of its ownership structure, key personnel qualifications, governance arrangements, technology infrastructure, and the full AML framework as it will operate in practice. Document quality and internal coherence are assessed; assertions of intent without operational evidence are insufficient.
How long does AML obligations for a virtual-asset service provider usually take?
There is no fixed statutory period for the SFC's VATP licence review. The process is substantive and involves written questions, document requests, and in some cases meetings with senior personnel. In our cross-border practice, the most consistent source of delay is travel-rule implementation and gaps between the documented programme and actual operations. A firm that begins compliance programme development in parallel with entity structuring – rather than after – materially reduces the risk of delay at the application stage. Parties should plan for a review period of several months as a working assumption.
Do I need a Hong Kong adviser for AML obligations for a virtual-asset service provider?
A Hong Kong-qualified legal adviser is necessary for matters of Hong Kong law, including the specific application of the Anti-Money Laundering and Counter-Terrorist Financing Ordinance and the SFC's licensing requirements to the firm's facts. International and cross-border counsel – working alongside locally licensed firms – adds value on the structuring and multi-jurisdictional dimensions: offshore entity design, the interaction of the Hong Kong AML obligations with those of the firm's other operating jurisdictions, and the preparation of a compliance architecture that is defensible across all relevant regulators. Most VATP matters of any scale engage both roles.

Speak with Lockhart & Yip

For a scoped view of your matter, contact info@lockhartyip.com. Discuss your matter →

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@lockhartyip.com.

This site uses only strictly necessary cookies. Non-essential cookies are declined by default. Cookie policy