Insurance Authority Compliance: Documentation Review for Hong Kong Insurers and Intermediaries
Hong Kong's Insurance Authority requires extensive documentation from insurers and intermediaries. Here's what's required, common compliance gaps, and how to review your documentation.
The Insurance Authority (IA) assumed direct regulatory oversight of insurance intermediaries in 2019, replacing the previous self-regulatory regime. This shift significantly increased documentation requirements for both insurers and intermediaries — many of which are still catching up with the new expectations.
The IA's supervisory approach is risk-based and documentation-centric. Inspections assess whether firms have adequate documented policies, whether those policies are implemented, and whether there is evidence of ongoing compliance. The transition from self-regulation to IA oversight means the documentation bar is higher than many intermediaries were accustomed to.
Documentation Requirements by Entity Type
Authorised Insurers
| Documentation Area | Key Requirements |
|---|---|
| Corporate governance | Board charter, committee terms of reference, fit and proper policies, remuneration policies |
| Risk management framework | Enterprise risk management policy, Own Risk and Solvency Assessment (ORSA), risk appetite statement |
| Underwriting policies | Underwriting guidelines, pricing methodology, reinsurance arrangements |
| Claims management | Claims handling procedures, reserving policies, complaints procedures |
| AML/CFT programme | CDD policies, transaction monitoring, STR procedures, sanctions screening |
| Conduct requirements | Treating Customers Fairly policy, product governance, sales practices |
| Actuarial function | Appointed actuary reports, valuation methodology, assumptions documentation |
| Outsourcing | Outsourcing policy, due diligence records, oversight procedures |
Licensed Insurance Intermediaries
| Documentation Area | Key Requirements |
|---|---|
| Conduct requirements | Code of Conduct compliance, customer needs analysis, product suitability |
| Financial needs analysis (FNA) | Documented assessment for each client, signed by client |
| Product recommendations | Documented rationale linking recommendation to client needs |
| Disclosure requirements | Commission disclosure, capacity disclosure, material interest disclosure |
| AML/CFT | CDD policies adapted to insurance, ongoing monitoring |
| Complaints handling | Procedures for receiving, investigating, and resolving complaints |
| Continuing professional development | CPD records for all licensed individuals |
| Internal controls | Policies and procedures manual, supervision arrangements |
Conduct Requirements Documentation
The IA's conduct requirements are the most documentation-intensive area for intermediaries.
Financial Needs Analysis (FNA)
For every long-term insurance policy recommendation, intermediaries must document:
| Element | What to Document |
|---|---|
| Client's financial situation | Income, assets, liabilities, existing coverage |
| Protection needs | Risk exposure, dependants, lifestyle requirements |
| Investment objectives | If applicable — risk tolerance, time horizon, return expectations |
| Affordability | Whether the recommended premium is affordable given the client's financial situation |
| Recommendation rationale | Why this specific product meets the client's identified needs |
| Client acknowledgement | Client's signature confirming the FNA was conducted |
Common finding: FNA documentation that is generic or pre-filled rather than client-specific. The IA expects genuine analysis, not box-ticking.
Product Suitability Documentation
Beyond the FNA, intermediaries must document why a specific product is suitable:
| Check | Documentation Required |
|---|---|
| Product features match needs | How does this product address the identified needs? |
| Risk profile alignment | Does the product's risk level match the client's risk tolerance? |
| Alternatives considered | What alternatives were considered and why this product was selected? |
| Charges and fees | Client informed of all charges; documentation of disclosure |
| Cooling-off period | Client informed of cooling-off rights |
Common IA Inspection Findings
Finding 1: Inadequate FNA Documentation
The most frequent finding for intermediaries. FNA forms that are incomplete, generic, or clearly filled in after the fact rather than during the client meeting.
Finding 2: Missing Disclosure Records
Commission disclosure, capacity disclosure (acting for insurer or client?), and material interest disclosure not documented or not provided at the required time.
Finding 3: Insufficient AML/CFT for Insurance
AML/CFT programmes that don't adequately address insurance-specific risks: single premium policies, early surrender patterns, change of beneficiary requests, and third-party premium payments.
Finding 4: CPD Non-Compliance
Licensed individuals without complete CPD records, or CPD activities that don't meet the IA's requirements for content and hours.
Finding 5: Complaints Not Properly Documented
Complaints received but not logged, investigated, or resolved within defined timeframes. The IA expects a complaints register and documented investigation for each complaint.
Documentation Review Criteria
FNA and Suitability Review
| Criterion | Weight | What to Check |
|---|---|---|
| Client-specific analysis | 3 | FNA reflects the individual client's situation, not generic content |
| Needs-recommendation link | 3 | Clear documented connection between identified needs and recommended product |
| Completeness | 2 | All required FNA elements documented |
| Disclosure | 2 | Commission, capacity, and material interest disclosures documented |
| Client acknowledgement | 1 | Client signature and date present |
AML/CFT Review (Insurance-Specific)
| Criterion | Weight | What to Check |
|---|---|---|
| Insurance-specific risks | 3 | Addresses single premium, early surrender, beneficiary changes, third-party payments |
| CDD completeness | 3 | Customer identification and verification records complete |
| Ongoing monitoring | 2 | Evidence of ongoing monitoring appropriate to risk level |
| Training records | 1 | AML/CFT training for all relevant staff documented |
Frequently Asked Questions
How has regulation changed since the IA took over from self-regulatory bodies?
The IA's standards are generally higher than the previous self-regulatory regime. Documentation expectations are more specific, inspections are more rigorous, and enforcement is more active. Intermediaries accustomed to the previous regime need to upgrade their documentation to meet IA expectations.
Do insurance intermediaries need the same level of AML/CFT documentation as banks?
The core AML/CFT requirements apply, but the risk profile differs. Insurance intermediaries should focus on insurance-specific ML/TF risks rather than simply adopting banking-style AML/CFT procedures. The IA expects risk-based, proportionate AML/CFT programmes.
How often does the IA inspect intermediaries?
The frequency is risk-based. Larger intermediaries and those with higher-risk profiles are inspected more frequently. All intermediaries should be prepared for inspection at any time. The IA also conducts thematic reviews targeting specific areas across the industry.
Can AI review help with insurance compliance documentation?
AI review can check FNA documentation for completeness and client-specificity, verify that all required disclosure elements are present, check AML/CFT policies for insurance-specific risk coverage, and assess documentation consistency. Regulatory adequacy and product suitability assessment require qualified insurance compliance professionals.
Key Takeaways
- The IA's direct regulation has raised documentation standards significantly compared to the previous self-regulatory regime.
- FNA documentation must be client-specific — generic or pre-filled forms are the most common inspection finding.
- Disclosure documentation (commission, capacity, material interest) must be provided and documented at the required time.
- Insurance-specific AML/CFT must address unique risks: single premium policies, early surrender, beneficiary changes.
- CPD records must be complete for all licensed individuals — missing records are a straightforward compliance failure.
- AI review checks completeness, client-specificity, and consistency — regulatory adequacy requires qualified compliance professionals.
This article is for informational purposes only. Insurance regulatory requirements in Hong Kong are complex and evolve through IA guidelines, circulars, and codes. Consult a qualified insurance compliance professional for guidance specific to your entity type and licensed activities.