HKMA Banking Documentation: Compliance Review for Authorised Institutions
HKMA-authorised institutions must maintain extensive compliance documentation across AML/CFT, credit risk, and operational risk. Here's what's required, common supervisory findings, and how to review.
Hong Kong's position as Asia's premier international financial centre means its banking regulatory framework is among the most rigorous in the world. The Hong Kong Monetary Authority supervises over 190 authorised institutions — licensed banks, restricted licence banks, and deposit-taking companies — each maintaining hundreds of compliance documents across multiple regulatory domains.
HKMA supervisory reviews are thorough and documentation-intensive. Examiners expect not just that policies exist, but that they are current, specific to the institution's risk profile, and supported by evidence of implementation. The gap between "we have a policy" and "we have an implemented, documented, and tested policy" is where most supervisory findings originate.
HKMA Regulatory Documentation Framework
Supervisory Policy Manual (SPM) Modules
The SPM is the HKMA's primary regulatory guidance, organised into modules that each generate documentation requirements:
| Module Category | Key Areas | Documentation Required |
|---|---|---|
| Corporate Governance (CG) | Board oversight, risk governance, remuneration | Board charters, committee terms of reference, governance policies |
| Risk Management (RR) | Enterprise risk, stress testing, recovery planning | Risk appetite statements, risk management frameworks, stress test documentation |
| Credit Risk (CR) | Credit policies, loan classification, provisioning | Credit policies, classification criteria, provisioning methodology |
| Market Risk (MR) | Trading book policies, VaR models, limit frameworks | Market risk policies, model documentation, limit structures |
| Operational Risk (OR) | Operational risk framework, business continuity, outsourcing | Operational risk policies, BCP/DRP, outsourcing agreements |
| AML/CFT (ML) | Customer due diligence, transaction monitoring, sanctions | AML/CFT policies, CDD procedures, STR procedures |
| Capital Adequacy (CA) | Basel III implementation, capital planning | ICAAP documentation, capital planning documents |
| Liquidity Risk (LM) | Liquidity risk management, LCR, NSFR | Liquidity risk policies, contingency funding plans |
Core Documentation Requirements
1. AML/CFT Documentation (AMLO and HKMA Guidelines)
The most scrutinised documentation area for authorised institutions.
| Document | Requirement |
|---|---|
| Institutional risk assessment | Enterprise-wide ML/TF risk assessment, reviewed annually |
| CDD policies and procedures | Customer identification, verification, ongoing monitoring, enhanced due diligence |
| Transaction monitoring programme | Rules/scenarios documentation, alert investigation procedures, tuning methodology |
| STR procedures | Suspicious transaction reporting process, escalation procedures, JFIU filing records |
| Sanctions screening programme | Screening methodology, list management, hit resolution procedures |
| Training programme | AML/CFT training curriculum, attendance records, assessment results |
| Independent audit/review | Periodic independent review of AML/CFT programme effectiveness |
2. Credit Risk Documentation
| Document | Requirement |
|---|---|
| Credit policy | Lending criteria, approval authorities, concentration limits |
| Loan classification policy | Classification categories, criteria for each category, review frequency |
| Provisioning policy | Expected credit loss methodology (HKFRS 9), model documentation |
| Large exposure policy | Limits, monitoring, reporting for connected lending and large exposures |
| Collateral management | Valuation policies, haircuts, revaluation frequency |
3. Operational Risk Documentation
| Document | Requirement |
|---|---|
| Operational risk framework | Risk identification, assessment, monitoring, mitigation |
| Business continuity plan | Recovery strategies, testing schedule, contact procedures |
| Disaster recovery plan | IT recovery procedures, RTO/RPO, testing evidence |
| Outsourcing policy | Due diligence requirements, oversight procedures, HKMA notification requirements |
| Incident management | Reporting procedures, root cause analysis, remediation tracking |
| Technology risk management | Cybersecurity policies, access management, change management |
4. Governance Documentation
| Document | Requirement |
|---|---|
| Board charter | Board responsibilities, composition requirements, meeting procedures |
| Committee terms of reference | Audit committee, risk committee, remuneration committee |
| Risk appetite statement | Board-approved risk appetite metrics and limits |
| Three lines of defence model | Documented roles for business, risk/compliance, and internal audit |
| Fit and proper records | Documentation for senior management and key personnel |
Common HKMA Supervisory Findings
Finding 1: AML/CFT Programme Deficiencies
Transaction monitoring systems that generate alerts but lack documented investigation procedures. CDD files missing required documentation for higher-risk customers. Sanctions screening without documented hit resolution.
Prevention: Implement structured documentation for every AML/CFT process: alert investigation templates with mandatory fields, CDD checklists per customer risk category, and sanctions hit resolution workflows with documented rationale.
Finding 2: Outdated Policies
Policies that reference superseded HKMA guidelines, previous organisational structures, or legacy systems. The HKMA expects policies to be reviewed at least annually and updated promptly when regulatory requirements change.
Prevention: Maintain a regulatory change log that maps HKMA circulars and guideline amendments to specific policies requiring updates. Assign policy owners with documented review deadlines.
Finding 3: Inadequate Board Documentation
Board and committee meeting minutes that don't demonstrate meaningful discussion of risk issues. Risk appetite statements that are generic rather than institution-specific. Missing evidence of board challenge and oversight.
Prevention: Board minutes should document: topics discussed, questions raised, decisions made, and follow-up actions assigned. Risk reporting to the board should include specific metrics against approved risk appetite limits.
Finding 4: Technology Risk Gaps
Cybersecurity documentation that doesn't address current threats, access management records with gaps, and change management processes that aren't consistently followed or documented.
Prevention: Review technology risk documentation against the HKMA's Technology Risk Management module (TM-G-1). Ensure access reviews are documented quarterly and change management records are complete for every production change.
Finding 5: Stress Testing Documentation
Stress test documentation that doesn't explain scenario selection rationale, uses unrealistic assumptions, or lacks documented management actions for adverse scenarios.
Prevention: Stress test documentation should include: scenario description and rationale, methodology, assumptions (and justification for each), results, management actions, and board discussion of results.
Documentation Review Criteria for AIs
AML/CFT Documentation Review
| Criterion | Weight | What to Check |
|---|---|---|
| Completeness | 3 | All AMLO and HKMA guideline requirements addressed |
| Risk-based approach | 3 | Documentation reflects the institution's specific ML/TF risk profile |
| Procedures specificity | 2 | Procedures are detailed enough for staff to follow consistently |
| Currency | 2 | References current regulations and HKMA guidance |
| Testing evidence | 2 | Independent review and testing results documented |
Credit Risk Documentation Review
| Criterion | Weight | What to Check |
|---|---|---|
| Policy completeness | 3 | All credit risk areas covered per HKMA SPM requirements |
| Classification accuracy | 3 | Loan classification criteria are specific and consistently applied |
| HKFRS 9 alignment | 2 | ECL methodology properly documented and validated |
| Limit framework | 2 | Concentration limits defined, monitored, and escalation procedures documented |
Governance Documentation Review
| Criterion | Weight | What to Check |
|---|---|---|
| Board effectiveness evidence | 3 | Minutes demonstrate meaningful discussion and challenge |
| Risk appetite specificity | 3 | Quantitative metrics with defined limits, not generic statements |
| Committee coverage | 2 | Terms of reference cover all required responsibilities |
| Succession planning | 1 | Key personnel succession documented |
Frequently Asked Questions
How often does the HKMA inspect authorised institutions?
The frequency depends on the institution's systemic importance and risk profile. Large banks: annually. Medium institutions: every 1-2 years. Smaller DTCs: every 2-3 years. Thematic reviews (e.g., AML/CFT, cybersecurity) may occur more frequently and target specific documentation areas.
What are the consequences of documentation deficiencies?
Supervisory findings range from recommendations (requiring action within a specified timeframe) to formal directions under the Banking Ordinance. Serious or persistent deficiencies can result in additional licence conditions, restrictions on activities, or enforcement action. The HKMA publishes disciplinary actions — reputational consequences can be severe.
Do we need separate documentation for each regulated entity in a group?
Each authorised institution must maintain its own documentation, even within a group. Group-level policies can be adopted, but must be supplemented with entity-specific procedures that reflect the local entity's risk profile, organisational structure, and regulatory requirements.
Can AI review help with HKMA compliance documentation?
AI review can check for completeness (all required elements present), currency (references to current regulations), consistency (alignment across related policies), and clarity (procedures specific enough to follow). Regulatory adequacy assessment — whether the documentation actually meets the HKMA's expectations — requires qualified compliance professionals.
Key Takeaways
- HKMA supervisory reviews are documentation-intensive — examiners expect current, specific, and implemented policies.
- AML/CFT documentation is the most scrutinised area — institutional risk assessments, CDD procedures, and transaction monitoring documentation are priority review targets.
- Policies must be institution-specific, not generic boilerplate — the HKMA expects documentation that reflects your specific risk profile and business model.
- Review documentation annually and after every significant HKMA circular or guideline amendment.
- Board documentation must demonstrate meaningful oversight — not just attendance, but discussion, challenge, and decision-making.
- AI review checks completeness, currency, and consistency — regulatory adequacy requires qualified compliance review.
This article is for informational purposes only. HKMA regulatory requirements are complex and evolve through circulars, guidelines, and supervisory expectations. Consult a qualified compliance professional or legal adviser for guidance specific to your authorised institution.