HONG KONG · EAST ↔ WEST
info@lockhartyip.comResponse within 4 hours (UTC+8)
Discuss your matter
Home/Insights/Disputes & Arbitration
Tech & Web3

AML obligations for a virtual-asset service provider

AML obligations for a virtual-asset service provider. Hong Kong as the neutral forum and hub. The Hong Kong angle in focus. Write to info@lockhartyip.com.

A virtual-asset service provider that has ignored its anti-money laundering position is not simply behind on paperwork. It is operating on borrowed time. Hong Kong's mandatory licensing regime for centralised virtual-asset trading platforms – in force since 1 June 2023 under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance – makes customer due diligence, transaction monitoring and the FATF travel rule conditions of continued operation, not suggestions. The Securities and Futures Commission is the licensing authority, and its supervisory posture has hardened.

AML obligations for a virtual-asset service provider in Hong Kong are governed by the Anti-Money Laundering and Counter-Terrorist Financing Ordinance, with the Securities and Futures Commission as the primary enforcement body; the regime requires customer due diligence, continuous transaction monitoring, source-of-funds verification, and compliance with the FATF travel rule for virtual-asset transfers, all as conditions of licensing under a regime that commenced on 1 June 2023.

This note sets out the governing regime, the practical sequence a provider must run, the cross-border dimension that catches foreign-managed platforms off guard, and the documents and decisions the principal must own before an examination or enforcement event arrives.

Why the trigger is arriving now for most providers

Most virtual-asset service providers operating through or into Hong Kong are at a decision point. The mandatory licensing regime is not new, but supervisory examination cycles and enforcement referrals are now reaching platforms that treated the June 2023 commencement as a future compliance date.

The window for orderly remediation is not permanent. A platform examined before its AML programme is documented and tested faces a different conversation with the Securities and Futures Commission than one that arrives with a complete compliance file. In our cross-border practice, we see the damage asymmetry repeatedly: the cost of a well-run remediation is a fraction of the cost of responding to a supervisory action.

What brings matters to a head is typically one of three events. An institutional counterparty or banking partner requests a compliance attestation. A regulator in another jurisdiction – Singapore, the UAE, or a European authority – asks about the Hong Kong entity's AML programme as part of a group-wide review. Or the Securities and Futures Commission issues a supervisory enquiry that arrives before the internal programme is ready. Each of these is, at that moment, a window-closing event (a trigger that accelerates a timeline the provider had assumed was still open).

What does the Hong Kong AML regime actually require?

The Anti-Money Laundering and Counter-Terrorist Financing Ordinance imposes a comprehensive set of obligations on virtual-asset trading platforms (centralised platforms that operate an exchange for buying and selling virtual assets). Where a virtual asset constitutes a "security" or "futures contract" as defined under the Securities and Futures Ordinance, a parallel licensing and conduct regime also applies, and the AML obligations are layered accordingly.

The core obligations fall into five categories. First, customer due diligence (CDD): identification and verification of customers, beneficial owners and, where applicable, persons acting on behalf of a customer. The standard requires verification against reliable, independent source documents. Enhanced due diligence applies to higher-risk customers, including politically exposed persons (PEPs – individuals who hold or have held prominent public functions, and their close associates and family members). Second, ongoing monitoring: reviewing transactions to ensure they are consistent with the platform's knowledge of the customer and their risk profile, including the source of funds. Third, the FATF travel rule (the Financial Action Task Force requirement that originator and beneficiary information accompanies virtual-asset transfers): platforms must collect, verify and transmit the required information on transfers above the applicable threshold. Fourth, suspicious transaction reporting: reporting to the Joint Financial Intelligence Unit where there are grounds to suspect that a transaction involves proceeds of crime. Fifth, record-keeping: maintaining all CDD records and transaction records for a minimum period as prescribed under the Ordinance.

The Securities and Futures Commission has issued detailed AML guidelines that sit alongside the Ordinance. These guidelines are not aspirational – they are the benchmark against which examiners assess programme adequacy. A platform that has the Ordinance text in its compliance manual but has not mapped its controls to the guidelines is, operationally, non-compliant.

How does the regime sit across multiple jurisdictions?

A virtual-asset service provider is almost never a single-jurisdiction entity. The structural reality – a Cayman or BVI holding company, a Hong Kong operating entity licensed or seeking licensing, distribution into Mainland China or Southeast Asian markets, a technology infrastructure layer in one territory and treasury in another – creates a compliance position that no single jurisdiction's rules resolve on their own.

Hong Kong implements United Nations sanctions and does not give domestic effect to unilateral measures of other states. That posture matters to platforms with counterparties, investors or customers across jurisdictions that apply competing sanctions regimes. The compliance work requires a clear mapping of which sanctions list applies to which legal entity in the group, and a contracting approach that documents the group's position without implying any circumvention of any regime.

The cross-border dimension also arises in the travel rule. A Hong Kong-licensed platform transferring virtual assets to or from a platform incorporated in the BVI, the Cayman Islands, Singapore or the UAE must ensure that the travel rule data flows correctly across the transfer chain. Where the counterpart platform is in a jurisdiction with a different travel rule implementation standard, the Hong Kong entity bears the compliance burden for its end of the chain. We regularly advise on the practical mechanics of this: the onboarding of virtual-asset service provider counterparts (VASPs – any entity conducting exchange, transfer or custody of virtual assets for customers), the data exchange protocols, and the documentation of residual risk where a counterpart VASP operates under a lighter or newer regime.

For a group with a Mainland China management team and a Hong Kong licensed entity, there is a further dimension. The Mainland's own virtual-asset restrictions mean that the compliance file must be clear about the scope of the Hong Kong entity's customer base and the basis on which it operates separately from any Mainland-connected activity. See our related matter note on digital-asset fund structures through Hong Kong and the UAE for the structural considerations that typically accompany the AML programme design.

The practical sequence: how we run the engagement

Every AML compliance engagement for a virtual-asset service provider runs through the same sequence, though the depth of work at each stage varies by the platform's starting position.

The first step is a gap assessment: a structured review of the existing compliance programme against the Anti-Money Laundering and Counter-Terrorist Financing Ordinance and the Securities and Futures Commission's AML guidelines. This produces a documented gap map – not a general observation, but a line-by-line comparison of what the platform has against what the regulator will examine. In our cross-border practice, we find that most foreign-managed platforms have a well-intentioned programme that was designed for a different jurisdiction and has not been adapted to the Hong Kong-specific requirements.

The second step is a risk assessment: the platform's own documented assessment of its AML/CTF risk, covering customer types, product and service types, delivery channels and geographic exposure. This is a document the platform must own. It cannot be delegated entirely to counsel. We prepare the methodology and the template; the platform populates and signs off the risk conclusions.

The third step is programme design or remediation: drafting or revising the AML policies and procedures to close the gaps identified in step one, aligned to the risk assessment from step two. This includes CDD procedures, enhanced due diligence triggers, travel rule protocols, suspicious transaction reporting procedures, and the record-keeping regime.

The fourth step is a controls test: a transaction-sample review and an internal audit of the controls as implemented, not just as written. A policy document that describes a control that is not operational is worse than no policy, because it creates a documented gap between the stated and actual position. We coordinate this stage with the platform's compliance officer and, where appropriate, with the locally licensed Hong Kong firms we work alongside for matters touching Hong Kong regulatory law.

The fifth step is documentation: preparation of the compliance file that the platform would produce in response to a supervisory examination. This includes the risk assessment, the gap assessment and its remediation record, the policies and procedures, the controls test results, and the senior management sign-off trail.

The sequence above describes the standard position. Your matter turns on the documents, the jurisdictions actually engaged, and the order of steps – which is where the programme is built or lost.

For a structured assessment of your platform's AML position across the relevant jurisdictions, write to us at info@lockhartyip.com.

Documents and decisions the client must own

A compliance programme that lives in counsel's files is not a compliance programme. The Securities and Futures Commission expects the platform's senior management to own the AML position, not to have delegated it to external advisers and forgotten it. That distinction matters when an examiner asks the compliance officer to walk through the risk assessment methodology.

There are five documents the principal cannot outsource to its advisers. The AML/CTF risk assessment: signed by senior management, reviewed at least annually or on a material change to the business. The AML/CTF policy: approved at board level, version-controlled, and referenced in the platform's operating procedures. The customer risk-rating methodology: the criteria by which customers are assigned a risk tier, the enhanced due diligence triggers, and the sign-off authority for accepting high-risk customers. The travel rule operational procedures: how the platform collects, verifies, transmits and receives originator and beneficiary data, and how it handles transfers to or from counterpart VASPs that cannot match its data standards. The suspicious transaction reporting log: a record of reports made to the Joint Financial Intelligence Unit, and a record of the decisions not to report where suspicion was considered and rejected with documented reasoning.

Each of these is a board-level governance item, not a compliance department filing. In our experience, the most common failure mode is a platform where the compliance officer has produced excellent technical documentation but senior management cannot speak to it. That gap is what examiners probe.

What do foreign counsel and foreign-managed platforms get wrong?

Counsel familiar with European or US AML regimes consistently underestimate the specificity of the Securities and Futures Commission's expectations. The AML guidelines for virtual-asset trading platforms go beyond the general AML framework and specify requirements that are particular to the virtual-asset context: the onboarding of counterpart VASPs, the treatment of unhosted wallets, the documentation of blockchain analytics tools and their integration into the transaction-monitoring programme.

A second error is treating the travel rule as a technical problem rather than a compliance programme element. The travel rule requires not just the technical transmission of data but a documented procedure for handling cases where data is unavailable, where the counterpart VASP is in a jurisdiction without a travel rule implementation, or where the transaction is above threshold but the counterpart cannot verify originator identity. A platform that has a travel rule solution integrated into its technology stack but no written procedure for the exception cases has not met its obligations.

A third error is conflating the AML obligations that apply to the licensed platform with those that apply to other entities in the group. A Cayman holding company that provides services to the Hong Kong-licensed entity may itself have AML obligations under Cayman law. A BVI entity that manages client assets has its own economic-substance and AML considerations. The compliance file for the Hong Kong entity cannot simply assume that the rest of the group is clean. See our Tech & Web3 practice overview for the broader structuring considerations that sit alongside the AML programme.

For groups with cross-border data flows, there is also the intersection of AML obligations and data agreements. A platform that routes customer data through a third-party travel rule solution or shares CDD records with a group entity in another jurisdiction should review the agreement governing that data flow. Our briefing on cross-border SaaS and data agreements addresses the contracting dimension that often sits adjacent to the AML compliance build.

Micro-scenario: a Southeast Asian platform entering the Hong Kong market

A platform incorporated in Singapore with customers across Southeast Asia and a Cayman holding structure engaged our desk in late 2025 as it was preparing a Hong Kong VASP licence application. Its existing AML programme had been designed for its Singapore regulatory position. The gap assessment showed that the programme met MAS expectations in several respects but had three material gaps against the Securities and Futures Commission's AML guidelines: its counterpart VASP onboarding procedures did not address unhosted wallets, its risk-rating methodology did not differentiate by product type, and its travel rule exception procedures were undocumented.

We ran the five-stage sequence described above. The remediation of the three gaps, the production of a Hong Kong-specific risk assessment, and the controls test took approximately three months. The platform's compliance officer was involved throughout. The senior management sign-off trail was documented at each stage. The programme was ready before the licence application examination period.

Decision matrix: situation, instrument, route, risk

A platform that has no AML programme at all faces the most significant remediation scope. The instrument is the Anti-Money Laundering and Counter-Terrorist Financing Ordinance, combined with the Securities and Futures Commission's AML guidelines. The route is a full programme build across all five document categories. The timing is urgent, because licensing or examination could be concurrent with the build. The risk is supervisory action during the build period.

A platform that has a programme adapted from another jurisdiction – typically Singapore, the UAE, or a European framework – faces a gap remediation rather than a full build. The instrument and guidelines remain the same. The route is a gap assessment followed by targeted remediation of the Hong Kong-specific requirements. The timing is manageable if the platform acts before an examination event. The risk is that the gaps are in exactly the areas the Securities and Futures Commission examines most closely: travel rule exception handling and counterpart VASP onboarding.

A platform that has a Hong Kong AML programme but has not updated it since the HKIAC administered arbitration rules or the travel rule implementation guidance evolved faces a programme maintenance issue. The route is an annual review cycle, a controls test, and a documented sign-off that the programme remains aligned to current guidance. The risk is low if the review cycle is operational; it becomes material the moment the review is deferred past a material change in the regulatory guidance.

If an earlier filing, structure or enforcement attempt produced an adverse or stalled result, a second read can identify the strategic error and the routes still open. To discuss how the Anti-Money Laundering and Counter-Terrorist Financing Ordinance applies to your platform's cross-border position, contact info@lockhartyip.com.

Self-assessment checklist for senior management

Before the next supervisory examination or licensing review, a virtual-asset service provider's senior management should be able to answer yes to each of the following questions.

  • Has the platform produced a documented AML/CTF risk assessment, signed by senior management, and reviewed within the last twelve months?
  • Is the AML/CTF policy approved at board level and version-controlled?
  • Does the customer risk-rating methodology differentiate by customer type, product type, delivery channel and geography?
  • Is there a documented procedure for enhanced due diligence of politically exposed persons, high-risk jurisdictions and high-risk transaction types?
  • Does the travel rule procedure address exception cases: unhosted wallets, counterpart VASPs that cannot provide required data, and transactions where originator verification fails?
  • Is there a documented counterpart VASP onboarding procedure aligned to the Securities and Futures Commission's AML guidelines?
  • Is the suspicious transaction reporting log maintained, with documented reasoning for decisions not to report?
  • Has a controls test been conducted within the last twelve months, and is the result documented?
  • Is the compliance file ready to be produced in response to a supervisory examination, without a gap between the written policies and the implemented controls?

A no on any of these is a gap that should be addressed before the next regulatory interaction, not during it.

Related practices

  • Sanctions & AML – cross-border AML compliance, sanctions screening, and source-of-funds documentation
  • Holding Structures – offshore holding entity design for virtual-asset groups, BVI and Cayman

Frequently asked questions

How long does AML obligations for a virtual-asset service provider usually take?
The timeline depends on the platform's starting position. A full programme build for a platform with no existing AML documentation typically runs three to five months, covering gap assessment, risk assessment, policy drafting, controls testing and the senior management sign-off sequence. A gap remediation for a platform with an existing programme adapted from another jurisdiction is ordinarily shorter. The controlling variable is the speed at which the platform's compliance officer and senior management can review and sign off each stage, as those are the steps that cannot be shortened without undermining the compliance value of the exercise.
What is the first step in AML obligations for a virtual-asset service provider?
The first step is a documented gap assessment: a structured comparison of the platform's existing AML programme against the Anti-Money Laundering and Counter-Terrorist Financing Ordinance and the Securities and Futures Commission's AML guidelines for virtual-asset trading platforms. This produces a prioritised remediation map and establishes the scope of work. Without a gap assessment, it is not possible to advise the platform on what needs to be built, what needs to be revised, and what the residual risk position is going into a licensing examination or a supervisory enquiry.
What are the main risks in AML obligations for a virtual-asset service provider?
The primary risk is a supervisory action by the Securities and Futures Commission before the programme is complete and documented. A secondary risk is a gap between the written policies and the implemented controls – the area examiners probe most directly. For cross-border groups, there is a further risk in travel rule exception handling: a platform that has a technical solution but no written procedure for the exception cases has a documented compliance gap. Finally, for groups with entities in multiple jurisdictions, the risk of a group-wide AML review by a regulator in one jurisdiction exposing gaps in another is material and is increasing as cooperation between virtual-asset regulators intensifies.

Speak with Lockhart & Yip

For a scoped view of your matter, contact info@lockhartyip.com. Discuss your matter →

Related

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@lockhartyip.com.

This site uses only strictly necessary cookies. Non-essential cookies are declined by default. Cookie policy