Matter note: AML obligations for a Hong Kong corporate services provider
AML obligations for a Hong Kong corporate services provider. An anonymised matter and the route foreign counsel took. Write to info@lockhartyip.com.
Banking access is the point where anti-money laundering compliance becomes concrete. For a corporate services provider operating in Hong Kong, the question is rarely theoretical: a financial institution's correspondent-bank requirements, the regulators' customer-due-diligence standards, and the expectations of overseas counterparties all converge at the payment channel. When one of those lines closes, or threatens to close, the operational consequence is immediate.
Hong Kong corporate services providers are subject to the Anti-Money Laundering and Counter-Terrorist Financing Ordinance, which imposes customer due diligence, record-keeping, and reporting obligations and is enforced by the relevant regulators for each category of licensee. Where the provider's clients operate across jurisdictions – and where the payment channel is international – the compliance file must satisfy not only the Hong Kong regulatory standard but also the due-diligence expectations of correspondent banks and overseas counterparties.
This matter note describes, in anonymised form, how an international corporate services business worked through a compliance gap that was threatening its banking relationships and its ability to serve cross-border clients. Names, amounts, and identifying details have been removed. The lesson is in the sequence.
What was the situation, and why did it matter?
The provider was a mid-sized corporate services business operating from Hong Kong. Its client base was international: holding entities from the BVI and the Cayman Islands administered under Hong Kong management, with underlying operating companies in Mainland China and South-East Asia. The business provided registered-office, directorship, and administration services. It was not a bank, but its work sat between the client and the financial system at almost every step.
Two things changed at the same time. First, the provider's principal transactional bank indicated that its correspondent network was tightening customer-due-diligence standards for clients in the corporate-services and trust sector. Second, a new cohort of the provider's clients began asking for payment and settlement instructions involving jurisdictions the bank's automated screening flagged as higher-risk. Neither development was, by itself, a finding of wrongdoing. Together, they created a compliance gap the provider did not have the internal structure to close without external support.
The structural complexity here was not unusual. Corporate services providers in Hong Kong routinely sit at the intersection of multiple legal systems: the Hong Kong regulatory regime governing their own conduct, the law of the offshore jurisdiction in which their client entities are formed, and the policies of correspondent banks in Europe, the United States, and elsewhere. Each layer makes demands on the compliance file. The difficulty is that the demands are rarely synchronised.
What was the legal and regulatory issue?
The Anti-Money Laundering and Counter-Terrorist Financing Ordinance imposes obligations across several categories of regulated service providers, including corporate service providers designated under the relevant schedule. The core obligations – customer due diligence, enhanced due diligence for higher-risk relationships, ongoing monitoring, and transaction-record retention – are not options; they are threshold conditions for operating.
The provider had maintained a compliance manual and had conducted customer-due-diligence procedures at onboarding. The problem was that its procedures had not kept pace with the expanded guidance issued by the relevant regulators on the treatment of politically exposed persons, on the identification of ultimate beneficial ownership, and on the documentation standards for structures involving offshore holding vehicles. The regulators' guidance does not have the force of statute, but financial institutions treat it as a benchmark. A provider whose file does not meet that benchmark is, in practice, exposed – even if no individual transaction has been flagged.
There was also a sanctions dimension. Hong Kong implements United Nations sanctions and does not give domestic effect to unilateral measures of other states. Several of the provider's clients maintained counterparties in jurisdictions that appear on unilateral sanctions lists of other states but are not subject to UN-mandated restrictions. The provider needed a clear compliance position that was both legally accurate and operationally credible to its banking relationships. Those are different objectives, and both must be met.
For a discussion of the broader sanctions and AML practice in which this matter sits, see our Sanctions & AML service page.
What route did counsel choose, and why?
The first task was to separate two questions that the provider had been treating as one. The question of what the Anti-Money Laundering and Counter-Terrorist Financing Ordinance requires is a legal question with a defined answer. The question of what a particular correspondent bank expects is a commercial and reputational question with a much wider answer. Conflating them produces a compliance file that is simultaneously over-engineered in some areas and under-evidenced in the areas the bank actually reviews.
Counsel reviewed the provider's existing customer-due-diligence files for the higher-risk cohort of clients. The review produced three categories of finding. First, a set of files that were substantively adequate but poorly documented – the work had been done, but the paper trail was insufficient for a third-party reviewer. Second, a set of files where ultimate beneficial ownership had been identified at onboarding but not refreshed when the ownership structure changed. Third, a small cohort where the enhanced due-diligence rationale had never been clearly recorded, even though the relationship had been flagged as higher-risk in the system.
The route chosen was a structured remediation: rebuilding the file documentation in the first category, refreshing the beneficial-ownership record in the second, and constructing a documented enhanced-due-diligence rationale in the third. Critically, the remediation was sequenced so that the most operationally significant relationships – those where banking access was immediately at risk – were addressed first.
The sanctions position was handled separately. Counsel prepared a documented compliance analysis distinguishing between UN-mandated measures (which apply in Hong Kong) and unilateral measures of other states (which do not have domestic effect under Hong Kong law). That analysis was structured not only as an internal legal opinion but as a document the provider could show its banking relationships on request. The aim was to create a paper trail that answered the bank's actual question: is this provider operating in compliance with the applicable law?
The cross-border interface raised its own practical question. Several of the BVI and Cayman entities required updated beneficial-ownership information to be filed with the relevant offshore registries as part of the same exercise. Counsel coordinated with allied counsel admitted in those jurisdictions to ensure that the registry filings and the Hong Kong compliance file were consistent. Inconsistency between the two – a known risk when remediation is done in silos – can itself create a red flag for a reviewing bank.
For a related discussion of the compliance approach to cross-border contracting, see our guide on compliance review before contracting through a Cyprus entity.
What was the turning point?
The remediation exercise exposed a procedural gap that had not been visible at the outset. The provider's compliance manual contained a procedure for identifying politically exposed persons at onboarding. It did not contain a procedure for handling a client who became a politically exposed person after onboarding – through a change in the underlying beneficial owner's professional or political position. Two files fell into that category. They were not the highest-risk files in the portfolio, but they were the ones most likely to create a regulatory exposure if reviewed without the enhanced-due-diligence record that the status change required.
Closing that gap was the turning point. It required not only updating those two files but revising the compliance manual to create a clear trigger for status-change reviews and to assign responsibility for monitoring to a named role within the business. That is a structural change, not a documentation exercise. A compliance manual that describes a procedure nobody owns is not a compliance manual; it is a liability.
In our cross-border AML practice, we see this pattern regularly. The onboarding procedure is often well-maintained. The ongoing-monitoring obligation – which the Anti-Money Laundering and Counter-Terrorist Financing Ordinance treats as continuous – receives less attention. The gap between the two is where enforcement exposure accumulates.
What was the outcome, and what is the transferable lesson?
The qualitative outcome was a restored banking relationship and a compliance file that could withstand a correspondent bank's due-diligence review. The provider was not the subject of any regulatory action. The work was preventive: identifying and closing the gap before it was identified by a third party.
The transferable lesson is about structure, not documentation. Documentation matters, but it is the product of a structure that assigns responsibility, schedules monitoring, and creates a trigger for enhanced review when the facts change. A corporate services provider whose compliance work consists of well-designed onboarding and nothing else has built a gate with no fence. The Anti-Money Laundering and Counter-Terrorist Financing Ordinance's ongoing monitoring obligation exists precisely because the risk profile of a client relationship is not static.
The cross-border dimension adds a further lesson. Where the provider's clients are formed under offshore law, the compliance file must be coherent across the full chain: the Hong Kong regulatory standard, the offshore registry position, and the correspondent bank's own due-diligence framework. Remediation done at only one point in that chain often creates a new inconsistency elsewhere. Coordinating the exercise – so that the Hong Kong file, the offshore filing, and the compliance analysis read as a single, consistent record – is where the practical work actually lies.
For the broader analytical picture of how sanctions due diligence works in a cross-border transaction, see our analysis of sanctions due diligence in a deal touching Singapore.
If your firm faces a similar position – a compliance file under pressure from a banking relationship, a beneficial-ownership record that has not kept pace with structural changes, or a sanctions analysis you need to be able to show a counterparty – the right step is a structured review before the issue surfaces externally.
To discuss how the Anti-Money Laundering and Counter-Terrorist Financing Ordinance applies to your position, and what a compliance review of your file would involve across the relevant jurisdictions, contact us at info@lockhartyip.com.
What foreign counsel frequently misread about Hong Kong AML requirements
The most common error foreign counsel make when advising Hong Kong corporate services providers is to treat the regulatory obligation and the banking expectation as the same thing. They are related but not identical. A provider may be fully compliant with the Anti-Money Laundering and Counter-Terrorist Financing Ordinance and still fail a correspondent bank's due-diligence review, because the bank is applying its own group-level policy – which may incorporate the standards of a home jurisdiction with a stricter or simply different approach.
The second common error is to treat the UN-sanctions / unilateral-sanctions distinction as too nuanced to explain to a financial institution. In practice, a well-drafted compliance analysis – one that clearly documents Hong Kong's legal posture, the applicable instruments, and the specific counterparty's position – is the document that resolves the banking relationship's concern. The nuance is not an obstacle; it is the answer. But it must be written down, clearly, and available on request.
The third error is to assume that offshore compliance is the offshore counsel's problem. Where a BVI or Cayman holding entity is the subject of a Hong Kong compliance file, the two must be consistent. If the offshore registry record shows a different beneficial owner than the Hong Kong file, or if the offshore filing has not been updated to reflect a change in ownership, the inconsistency is a red flag regardless of which jurisdiction created it.
If a previous attempt to resolve a compliance issue produced an incomplete or stalled result, a second review can identify the gap and the routes still available. Write to info@lockhartyip.com to describe your position.
Related practices
- Sanctions & AML – cross-border AML compliance, sanctions analysis, and counterparty due diligence
- Holding Structures – BVI, Cayman, and Hong Kong holding vehicle review and structuring
Frequently asked questions
What is the first step in AML obligations for a Hong Kong corporate services provider?
Which jurisdiction's law applies to AML obligations for a Hong Kong corporate services provider?
Do I need a Hong Kong adviser for AML obligations for a Hong Kong corporate services provider?
Speak with Lockhart & Yip
For a scoped view of your matter, contact info@lockhartyip.com. Discuss your matter →
Related
- Sanctions Aml
- Compliance Review Before Contracting Cyprus Entity Cyprus Guide
- Sanctions Due Diligence Deal Touching Singapore Singapore Analysis
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@lockhartyip.com.