Matter note: an internal sanctions and AML policy for an Asia group
An internal sanctions and AML policy for an Asia group. An anonymised matter and the route taken. The Hong Kong angle in focus. Write to info@lockhartyip.com.
An internal sanctions and AML policy for an Asia group must reconcile at least three legal environments at once: the sanctions posture of the group's home jurisdiction, the United Nations-based regime that Hong Kong implements, and the compliance expectations of the correspondent banks that move money across the group's payment channels. When those three environments pull in different directions, the policy document becomes the point where enforcement risk either crystallises or is contained.
This matter note describes an anonymised engagement. No client-identifying information appears. The note is published because the structural problem the group faced – a multi-entity Asia operation with no consolidated sanctions and AML policy, banking access deteriorating, and a compliance gap the group's auditors had flagged – is one we see regularly in cross-border practice. The route taken, and the turning point, are transferable.
What was the situation, and what was the constraint?
The group was a mid-market trading and distribution operation. It held entities in Hong Kong, a Mainland China wholly foreign-owned enterprise (WFOE – a company incorporated under Mainland law and wholly owned by a foreign investor), and an intermediate holding entity incorporated in a common-law offshore centre. Revenue moved across all three nodes.
The group's payment channels ran through correspondent banks in Hong Kong and one European centre. Both correspondent relationships had been flagged for enhanced due diligence. One bank had requested a formal written compliance policy before it would continue processing the group's cross-border payments. The other had placed the account under review.
The constraint was real. The group had no single, consolidated sanctions and AML policy document. Individual entities had fragments: a WFOE registration-level compliance note, a holding-entity memorandum prepared for a legacy transaction, and a set of internal process descriptions that were product-specific and outdated. None of them addressed the group's actual payment flows, the multi-jurisdictional counterparty base, or the governing instruments by name.
What the banks were asking for was not a theoretical document. They wanted evidence that the group understood the regime it operated under, had mapped its own risk exposure, and had put controls in place that a compliance officer at the bank could review and be satisfied by. That is a precise and answerable ask – but only if the policy is built to answer it.
What was the legal issue, and how was the route chosen?
The governing instrument for the group's Hong Kong entities is the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (AMLO – the primary Hong Kong statute governing AML and CTF obligations for financial institutions and designated non-financial businesses). Hong Kong implements United Nations sanctions through the United Nations Sanctions Ordinance. The group itself was not a financial institution and therefore did not fall within the AMLO's licensing perimeter directly. But every bank it dealt with did. The banks' own compliance obligations flowed downstream into their due diligence on the group.
The legal issue was therefore indirect but consequential. The group did not face a regulator. It faced the compliance teams of its own correspondent banks. Those compliance teams were applying their obligations under the AMLO and under their own internal AML frameworks to assess whether the group was an acceptable customer. The question was not whether the group had broken a rule. The question was whether the group could demonstrate, in writing, that it understood and managed the risks the banks were identifying.
The route chosen was to build the policy from the governing instruments outward – not from the group's existing fragments inward. That sequence matters. A policy built by tidying up existing documents tends to reflect what the group has always done. A policy built from the instruments maps what the instruments require and then describes the group's controls in those terms. The second approach is the one a bank compliance team can verify against its own checklist.
The cross-border structure of the group shaped the policy's architecture. Hong Kong was the hub for payment flows and for external compliance review. The WFOE operated under a distinct legal environment. The offshore holding entity introduced a third jurisdiction. The policy had to address each node, name the applicable regime at each node, and describe how controls at the Hong Kong level caught what the other nodes might generate. That three-layer structure is the transferable architecture of this matter.
For a structured read on how Hong Kong's sanctions posture interacts with cross-border transactions of this kind, see our guide at Hong Kong's sanctions posture and cross-border transactions.
What was the sequence, and where was the turning point?
The engagement ran in four stages. Each stage produced a discrete output that fed the next.
The first stage was a risk-mapping exercise. We reviewed the group's counterparty base, the jurisdictions in which counterparties operated, the nature of the goods and services traded, and the payment routes. This produced a written risk assessment – not a policy, but the factual foundation the policy would rest on. The risk assessment identified two areas of genuine exposure: a sub-set of counterparties in jurisdictions subject to UN-level measures, and a payment channel that routed through an intermediary the group had not subjected to its own due diligence.
The second stage was instrument mapping. We identified each governing instrument by name – the UN sanctions instruments applicable by virtue of the United Nations Sanctions Ordinance, the AMLO's customer due diligence requirements as they applied to the banks, and the offshore centre's own AML requirements at the holding-entity level. We described what each instrument required and what the group's exposure was. This stage produced the instrument annex to the policy.
The third stage was control design. For each identified risk, we specified a control: a counterparty screening procedure referenced against the UN consolidated list, a due diligence template for new counterparties, a payment-channel review process for the intermediary route, and a senior-approval requirement for transactions touching the flagged jurisdictions. The controls were proportionate to the group's size. A policy that specifies controls a mid-market group cannot operationally sustain is not a policy – it is a liability.
The turning point came in the third stage. The intermediary payment channel, when reviewed, involved a correspondent bank that itself had a compliance profile the group could not adequately document. The group's instinct was to paper over this with a general statement of intent. That would not have worked – and more importantly, it would have been the wrong answer. The correct response, which the group accepted, was to route payments through a channel the group could document, and to close the undocumented route. That decision, and the written record of it, was what changed the compliance conversation with both banks.
The fourth stage was policy drafting and review. The policy document addressed: scope (which entities and which persons within those entities were covered); the governing instruments by name and jurisdiction; the risk assessment methodology and the current risk rating; the controls in place; the escalation and reporting procedure; the record-keeping standard; and the review cycle. The document was structured so that a bank compliance officer could move from section to section in the order their own internal checklist would require.
Before contracting with Mainland-connected counterparties, the due diligence steps described in this engagement map closely to the framework we set out in our guide at compliance review before contracting with a Mainland China entity.
What was the outcome, and what is the transferable lesson?
Both correspondent banking relationships were preserved. The bank that had formally requested a compliance policy received the document, reviewed it, and confirmed the account would continue without enhanced due diligence. The bank under review lifted the review flag within a reasonable period after receiving the policy and the supporting risk assessment. The group's payment channels were restored to normal processing.
The qualitative outcome was predictable, in retrospect. Banks making enhanced due diligence decisions about mid-market clients are not making legal judgments. They are making risk-management decisions. A well-structured policy document shifts the bank's assessment from "this client cannot demonstrate compliance awareness" to "this client has documented its position and we can verify it." That shift is achievable. It does not require a large compliance operation. It requires a document that is built to answer the questions the bank is actually asking.
The transferable lesson concerns sequencing. Groups facing banking access pressure tend to respond by producing the simplest possible document as quickly as possible. That is understandable. It is also frequently the wrong move. A document produced quickly to satisfy an immediate request often fails at the first detailed review, because it was not built from the instruments and does not map the group's actual controls. The result is a second round of bank queries, a longer review period, and a policy document that now has to be revised under more pressure.
Building the policy from the instruments outward – risk mapping first, instrument analysis second, control design third, document drafting last – takes longer at the front end. It produces a document that holds up. In our cross-border practice, the groups that resolve banking access issues most efficiently are those that commit to the correct sequence even when the commercial pressure is to move faster.
A second lesson concerns the multi-entity structure. The group in this matter had three entities across three jurisdictions. The policy had to address all three. A policy that covers only the Hong Kong entity and is silent on the WFOE and the offshore holding entity will not satisfy a bank that processes payments touching all three. The group-wide scope, and the clear explanation of which regime governs which entity, is what made the document useful to the bank's compliance team.
The centre of gravity in this kind of engagement is banking access and the payment channel. Sanctions and AML compliance work in this context is never about circumvention. It is about understanding the applicable regime, mapping the group's actual exposure within that regime, and putting controls in place that are honest about what the group can and cannot do. That is the compliance approach. It is also the approach that preserves commercial relationships over time.
For a fuller description of our sanctions and AML practice and the matters we handle for Asia groups, see our practice page.
The sequence above describes the standard approach in a matter of this kind. Your group's position turns on the entities actually engaged, the jurisdictions in the payment chain, and the specific requests your banks have made – which is where the route is won or lost.
To discuss how an internal sanctions and AML policy would be structured for your group's cross-border position, contact info@lockhartyip.com.
Related practices
- Sanctions & AML – cross-border compliance, policy structuring and banking access for Asia groups
- Holding Structures – multi-entity offshore and Hong Kong holding architecture for international groups
Frequently asked questions
What does the route look like for an internal sanctions and AML policy for an Asia group?
How does the cross-border element affect an internal sanctions and AML policy for an Asia group?
Do I need a Hong Kong adviser for an internal sanctions and AML policy for an Asia group?
Speak with Lockhart & Yip
For a scoped view of your matter, contact info@lockhartyip.com. Discuss your matter →
Related
- Sanctions Aml
- Compliance Review Before Contracting Mainland China Entity Mainland 2
- Hong Kong S Sanctions Posture Cross Border Transaction 6
This publication is general information and does not constitute legal advice. For advice on your situation, contact info@lockhartyip.com.