Skip to content
TB
TeamBenchResources

HKMA Banking Documentation: Compliance Review for Authorised Institutions

HKMA-authorised institutions must maintain extensive compliance documentation across AML/CFT, credit risk, and operational risk. Here's what's required, common supervisory findings, and how to review.

TeamBench· Content Quality PlatformFebruary 9, 20268 min read

Hong Kong's position as Asia's premier international financial centre means its banking regulatory framework is among the most rigorous in the world. The Hong Kong Monetary Authority supervises over 190 authorised institutions — licensed banks, restricted licence banks, and deposit-taking companies — each maintaining hundreds of compliance documents across multiple regulatory domains.

HKMA supervisory reviews are thorough and documentation-intensive. Examiners expect not just that policies exist, but that they are current, specific to the institution's risk profile, and supported by evidence of implementation. The gap between "we have a policy" and "we have an implemented, documented, and tested policy" is where most supervisory findings originate.

HKMA Regulatory Documentation Framework

Supervisory Policy Manual (SPM) Modules

The SPM is the HKMA's primary regulatory guidance, organised into modules that each generate documentation requirements:

Module CategoryKey AreasDocumentation Required
Corporate Governance (CG)Board oversight, risk governance, remunerationBoard charters, committee terms of reference, governance policies
Risk Management (RR)Enterprise risk, stress testing, recovery planningRisk appetite statements, risk management frameworks, stress test documentation
Credit Risk (CR)Credit policies, loan classification, provisioningCredit policies, classification criteria, provisioning methodology
Market Risk (MR)Trading book policies, VaR models, limit frameworksMarket risk policies, model documentation, limit structures
Operational Risk (OR)Operational risk framework, business continuity, outsourcingOperational risk policies, BCP/DRP, outsourcing agreements
AML/CFT (ML)Customer due diligence, transaction monitoring, sanctionsAML/CFT policies, CDD procedures, STR procedures
Capital Adequacy (CA)Basel III implementation, capital planningICAAP documentation, capital planning documents
Liquidity Risk (LM)Liquidity risk management, LCR, NSFRLiquidity risk policies, contingency funding plans

Core Documentation Requirements

1. AML/CFT Documentation (AMLO and HKMA Guidelines)

The most scrutinised documentation area for authorised institutions.

DocumentRequirement
Institutional risk assessmentEnterprise-wide ML/TF risk assessment, reviewed annually
CDD policies and proceduresCustomer identification, verification, ongoing monitoring, enhanced due diligence
Transaction monitoring programmeRules/scenarios documentation, alert investigation procedures, tuning methodology
STR proceduresSuspicious transaction reporting process, escalation procedures, JFIU filing records
Sanctions screening programmeScreening methodology, list management, hit resolution procedures
Training programmeAML/CFT training curriculum, attendance records, assessment results
Independent audit/reviewPeriodic independent review of AML/CFT programme effectiveness

2. Credit Risk Documentation

DocumentRequirement
Credit policyLending criteria, approval authorities, concentration limits
Loan classification policyClassification categories, criteria for each category, review frequency
Provisioning policyExpected credit loss methodology (HKFRS 9), model documentation
Large exposure policyLimits, monitoring, reporting for connected lending and large exposures
Collateral managementValuation policies, haircuts, revaluation frequency

3. Operational Risk Documentation

DocumentRequirement
Operational risk frameworkRisk identification, assessment, monitoring, mitigation
Business continuity planRecovery strategies, testing schedule, contact procedures
Disaster recovery planIT recovery procedures, RTO/RPO, testing evidence
Outsourcing policyDue diligence requirements, oversight procedures, HKMA notification requirements
Incident managementReporting procedures, root cause analysis, remediation tracking
Technology risk managementCybersecurity policies, access management, change management

4. Governance Documentation

DocumentRequirement
Board charterBoard responsibilities, composition requirements, meeting procedures
Committee terms of referenceAudit committee, risk committee, remuneration committee
Risk appetite statementBoard-approved risk appetite metrics and limits
Three lines of defence modelDocumented roles for business, risk/compliance, and internal audit
Fit and proper recordsDocumentation for senior management and key personnel

Common HKMA Supervisory Findings

Finding 1: AML/CFT Programme Deficiencies

Transaction monitoring systems that generate alerts but lack documented investigation procedures. CDD files missing required documentation for higher-risk customers. Sanctions screening without documented hit resolution.

Prevention: Implement structured documentation for every AML/CFT process: alert investigation templates with mandatory fields, CDD checklists per customer risk category, and sanctions hit resolution workflows with documented rationale.

Finding 2: Outdated Policies

Policies that reference superseded HKMA guidelines, previous organisational structures, or legacy systems. The HKMA expects policies to be reviewed at least annually and updated promptly when regulatory requirements change.

Prevention: Maintain a regulatory change log that maps HKMA circulars and guideline amendments to specific policies requiring updates. Assign policy owners with documented review deadlines.

Finding 3: Inadequate Board Documentation

Board and committee meeting minutes that don't demonstrate meaningful discussion of risk issues. Risk appetite statements that are generic rather than institution-specific. Missing evidence of board challenge and oversight.

Prevention: Board minutes should document: topics discussed, questions raised, decisions made, and follow-up actions assigned. Risk reporting to the board should include specific metrics against approved risk appetite limits.

Finding 4: Technology Risk Gaps

Cybersecurity documentation that doesn't address current threats, access management records with gaps, and change management processes that aren't consistently followed or documented.

Prevention: Review technology risk documentation against the HKMA's Technology Risk Management module (TM-G-1). Ensure access reviews are documented quarterly and change management records are complete for every production change.

Finding 5: Stress Testing Documentation

Stress test documentation that doesn't explain scenario selection rationale, uses unrealistic assumptions, or lacks documented management actions for adverse scenarios.

Prevention: Stress test documentation should include: scenario description and rationale, methodology, assumptions (and justification for each), results, management actions, and board discussion of results.

Documentation Review Criteria for AIs

AML/CFT Documentation Review

CriterionWeightWhat to Check
Completeness3All AMLO and HKMA guideline requirements addressed
Risk-based approach3Documentation reflects the institution's specific ML/TF risk profile
Procedures specificity2Procedures are detailed enough for staff to follow consistently
Currency2References current regulations and HKMA guidance
Testing evidence2Independent review and testing results documented

Credit Risk Documentation Review

CriterionWeightWhat to Check
Policy completeness3All credit risk areas covered per HKMA SPM requirements
Classification accuracy3Loan classification criteria are specific and consistently applied
HKFRS 9 alignment2ECL methodology properly documented and validated
Limit framework2Concentration limits defined, monitored, and escalation procedures documented

Governance Documentation Review

CriterionWeightWhat to Check
Board effectiveness evidence3Minutes demonstrate meaningful discussion and challenge
Risk appetite specificity3Quantitative metrics with defined limits, not generic statements
Committee coverage2Terms of reference cover all required responsibilities
Succession planning1Key personnel succession documented

Frequently Asked Questions

How often does the HKMA inspect authorised institutions?

The frequency depends on the institution's systemic importance and risk profile. Large banks: annually. Medium institutions: every 1-2 years. Smaller DTCs: every 2-3 years. Thematic reviews (e.g., AML/CFT, cybersecurity) may occur more frequently and target specific documentation areas.

What are the consequences of documentation deficiencies?

Supervisory findings range from recommendations (requiring action within a specified timeframe) to formal directions under the Banking Ordinance. Serious or persistent deficiencies can result in additional licence conditions, restrictions on activities, or enforcement action. The HKMA publishes disciplinary actions — reputational consequences can be severe.

Do we need separate documentation for each regulated entity in a group?

Each authorised institution must maintain its own documentation, even within a group. Group-level policies can be adopted, but must be supplemented with entity-specific procedures that reflect the local entity's risk profile, organisational structure, and regulatory requirements.

Can AI review help with HKMA compliance documentation?

AI review can check for completeness (all required elements present), currency (references to current regulations), consistency (alignment across related policies), and clarity (procedures specific enough to follow). Regulatory adequacy assessment — whether the documentation actually meets the HKMA's expectations — requires qualified compliance professionals.

Key Takeaways

  • HKMA supervisory reviews are documentation-intensive — examiners expect current, specific, and implemented policies.
  • AML/CFT documentation is the most scrutinised area — institutional risk assessments, CDD procedures, and transaction monitoring documentation are priority review targets.
  • Policies must be institution-specific, not generic boilerplate — the HKMA expects documentation that reflects your specific risk profile and business model.
  • Review documentation annually and after every significant HKMA circular or guideline amendment.
  • Board documentation must demonstrate meaningful oversight — not just attendance, but discussion, challenge, and decision-making.
  • AI review checks completeness, currency, and consistency — regulatory adequacy requires qualified compliance review.

This article is for informational purposes only. HKMA regulatory requirements are complex and evolve through circulars, guidelines, and supervisory expectations. Consult a qualified compliance professional or legal adviser for guidance specific to your authorised institution.

hkma-compliancehong-kong-bankingauthorised-institutionbanking-documentationhkma-supervisoryaml-hong-kong

Need consistent content quality across your team?

TeamBench lets you create custom AI reviewers that score content against your specific criteria. Submit content, get instant scored feedback, and improve with one click.

  • Create custom AI reviewers for your brand
  • Score content against your specific criteria
  • Instant feedback, one-click improvement
  • Free to start — no credit card required