Skip to content
TB
TeamBenchResources

SFC Compliance Documentation Review for Hong Kong Licensed Corporations

SFC-licensed corporations face extensive documentation requirements under the SFO and Code of Conduct. Here's what documentation you need, common inspection findings, and how to review for completeness.

TeamBench· Content Quality PlatformFebruary 9, 202610 min read

The Securities and Futures Commission conducts regular inspections of licensed corporations — and documentation is the first thing inspectors examine. Not trading records or client portfolios. Documentation. Your compliance manual, policies and procedures, KYC records, and internal controls framework tell the SFC whether your firm takes compliance seriously before they look at a single transaction.

Common SFC inspection findings consistently relate to documentation deficiencies: incomplete compliance manuals, outdated policies, insufficient KYC records, and inadequate record-keeping. These are preventable findings — if your documentation is reviewed systematically before the SFC reviews it for you.

SFC Licensing and Documentation Landscape

Regulated Activities (Types 1-12)

TypeActivityDocumentation Intensity
Type 1Dealing in securitiesHigh
Type 2Dealing in futures contractsHigh
Type 3Leveraged foreign exchange tradingHigh
Type 4Advising on securitiesMedium-High
Type 5Advising on futures contractsMedium-High
Type 6Advising on corporate financeHigh
Type 7Providing automated trading servicesHigh
Type 8Securities margin financingHigh
Type 9Asset managementHigh
Type 10Providing credit rating servicesMedium
Type 11Dealing in OTC derivative productsHigh
Type 12Providing client clearing servicesHigh

Every licensed corporation, regardless of type, must maintain core compliance documentation. Additional documentation requirements apply based on the specific regulated activities conducted.

Required Compliance Documentation

1. Compliance Manual

The foundation document that sets out the firm's compliance framework.

Must address:

SectionWhat to Include
Regulatory frameworkApplicable laws, regulations, codes (SFO, Code of Conduct, subsidiary legislation)
Organisational structureCompliance function structure, reporting lines, Responsible Officers
General compliance obligationsLicensing conditions, notification requirements, continuing obligations
Client-facing requirementsKnow your client, suitability, client agreements, best execution
Market conductMarket misconduct prevention, personal dealing, conflicts of interest
AML/CFTAnti-money laundering programme, CDD requirements, suspicious transaction reporting
Record keepingRetention requirements, formats, accessibility
Complaints handlingProcedures for receiving, investigating, and resolving complaints
Breach managementInternal reporting, escalation, regulatory notification

Common inspection finding: Compliance manuals that haven't been updated to reflect current regulatory requirements. The SFC expects manuals to be reviewed and updated at least annually, and whenever significant regulatory changes occur.

2. Policies and Procedures

Separate, detailed policies for each major compliance area:

PolicyKey Requirements
KYC/CDD PolicyCustomer identification, verification, ongoing monitoring, enhanced due diligence for high-risk customers
AML/CFT PolicyRisk assessment, CDD procedures, transaction monitoring, suspicious transaction reporting, sanctions screening
Suitability PolicySuitability assessment requirements, documentation of suitability analysis, product due diligence
Best Execution PolicyExecution factors, venue selection, monitoring, client disclosure
Conflicts of Interest PolicyIdentification, management, disclosure of conflicts
Personal Dealing PolicyPre-clearance, restricted lists, reporting requirements
Complaints Handling PolicyReceipt, acknowledgement, investigation, resolution, record-keeping
Business Continuity PlanRisk assessment, recovery procedures, testing schedule
Information Barriers PolicyChinese walls, restricted information handling, crossing procedures
Outsourcing PolicyDue diligence, oversight, regulatory notification requirements

3. KYC and Client Documentation

The most inspected documentation category. SFC Circular on AML/CFT and the Guideline on AML/CFT set detailed requirements.

Per client, maintain:

DocumentRequirement
Client identificationCertified copies of identification documents
Verification recordsEvidence of identity verification steps taken
Risk assessmentCustomer risk rating with rationale
Source of funds/wealthDocumentation for high-risk and PEP customers
Suitability assessmentRisk tolerance, investment objectives, financial situation, knowledge and experience
Client agreementSigned client agreement per SFC requirements
Account opening recordsComplete account opening documentation
Ongoing monitoring recordsPeriodic review documentation, trigger event reviews

4. Transaction and Trading Records

RecordRetention Period
Transaction records7 years
Order records7 years
Client instructions7 years
Trade confirmations7 years
Account statements7 years
Telephone recordings (where applicable)6 months minimum

5. Regulatory Correspondence and Notifications

DocumentWhen Required
SFC correspondenceRetain all incoming and outgoing correspondence with SFC
Licensing notificationsChanges to licensees, ROs, substantial shareholders
Breach notificationsReports of regulatory breaches to SFC
Financial returnsMonthly/quarterly financial returns as required
Annual returnsAudited accounts and annual returns

Common SFC Inspection Findings

Finding 1: Inadequate KYC/CDD Documentation

The single most common finding. Issues include: incomplete identification records, missing risk assessments, no documentation of ongoing monitoring, and failure to update client information when trigger events occur.

Prevention: Implement a KYC documentation checklist for each client type (individual, corporate, trust, PEP) and review completeness at account opening and during periodic reviews.

Finding 2: Outdated Compliance Manual

Compliance manuals that reference superseded regulations, outdated organisational structures, or discontinued processes. The SFC views an outdated compliance manual as evidence of a weak compliance culture.

Prevention: Schedule annual compliance manual reviews. Implement a regulatory change tracking process that triggers manual updates when relevant regulations change.

Finding 3: Insufficient Suitability Documentation

Recommendations made without documented suitability analysis, or suitability assessments that are generic rather than client-specific. The SFC requires documented evidence that suitability was assessed for each recommendation.

Prevention: Standardise suitability assessment documentation with specific fields for risk tolerance, investment horizon, financial situation, knowledge/experience, and the rationale linking the recommendation to the client's profile.

Finding 4: Weak AML/CFT Implementation

Policies exist on paper but aren't implemented in practice. Transaction monitoring gaps, late suspicious transaction reports, and incomplete sanctions screening are common findings.

Prevention: Review AML/CFT documentation against actual practices quarterly. Ensure transaction monitoring records demonstrate that alerts are investigated and resolved, not just generated.

Finding 5: Poor Record-Keeping Practices

Records that are incomplete, disorganised, or inaccessible. The SFC expects records to be readily retrievable during inspections — not reconstructed after the inspector requests them.

Prevention: Implement a record retention schedule with clear ownership. Test retrieval periodically — can you produce a specific client's complete KYC file within one business day?

Preparing for SFC Inspections

Pre-Inspection Documentation Review

PriorityWhat to ReviewWhy
P1KYC files for a sample of clients (including high-risk)Most commonly inspected; highest finding rate
P1Compliance manual currencyInspectors check if the manual reflects current requirements
P1AML/CFT records (STR filings, transaction monitoring logs)Focus area for all inspections
P2Suitability documentation for recent recommendationsIncreasingly scrutinised
P2Complaints register and resolution recordsMust demonstrate proper handling
P3Business continuity plan and testing recordsShould be current and tested
P3Training records for licensed representativesMust demonstrate ongoing compliance training

Documentation Review Criteria

CriterionWeightWhat to Check
Completeness3All required documents present for each category
Currency3Policies reflect current regulations and organisational structure
Consistency2Policies align with actual practices; no contradictions between documents
Specificity2Procedures are specific enough to follow, not generic boilerplate
Accessibility1Documents are organised, indexed, and retrievable within a reasonable timeframe

Reviewing SFC Compliance Documentation

Using AI Review for SFC Documentation

AI review can systematically check SFC compliance documentation for:

  • Completeness — are all required sections present in each policy?
  • Currency — do references cite current regulations (not superseded versions)?
  • Consistency — do related policies align (e.g., KYC policy and AML/CFT policy)?
  • Plain language — are procedures clear enough for staff to follow?
  • Structure — does each policy follow a consistent, professional format?

What AI review cannot do: Verify that documented procedures match actual practices, assess the adequacy of risk assessments, or determine whether specific KYC records meet the SFC's expectations for a particular client type. These require qualified compliance review.

Frequently Asked Questions

How often should we review our compliance documentation?

Full review: annually, timed before the SFC's typical inspection cycle. Targeted review: whenever a significant regulatory change occurs (new circular, amended code, guideline update). Ad hoc review: when organisational changes affect compliance procedures (new business lines, restructuring, key personnel changes).

What happens if the SFC finds documentation deficiencies?

Depending on severity: a management letter requesting remediation, compliance advice, a warning, or formal disciplinary action. Serious or repeated documentation failures can result in licence conditions, fines, or suspension. The SFC publishes enforcement actions — reputational impact is significant.

Should our compliance manual be one document or multiple?

Either approach is acceptable. Many firms use a master compliance manual with separate, detailed policy documents for each area (AML/CFT, KYC, suitability, etc.). The key is that the documentation is comprehensive, consistent, and accessible — not the format.

How long must we retain compliance records?

The SFO requires retention of transaction records for 7 years. The SFC's Code of Conduct and various guidelines specify retention periods for different record types. When in doubt, retain for 7 years — it's the safest standard that covers most requirements.

Do we need to document compliance training?

Yes. The SFC expects licensed representatives to receive regular compliance training, and for that training to be documented. Records should include: training date, topics covered, attendees, and assessment results (if applicable). The SFC's Guidelines on Competence specifically address ongoing training requirements.

Key Takeaways

  • SFC inspections focus on documentation first. Your compliance manual, KYC files, and AML/CFT records are the primary inspection targets.
  • The five most common findings are: inadequate KYC, outdated compliance manuals, insufficient suitability documentation, weak AML/CFT implementation, and poor record-keeping.
  • Review documentation annually at minimum, and after every significant regulatory change.
  • KYC documentation completeness is the single highest-risk area — implement per-client checklists.
  • AI review checks completeness, currency, consistency, and structure — compliance adequacy requires qualified professional review.
  • Prepare for inspections proactively — review before the SFC does, not after they send the inspection notice.

This article is for informational purposes only. SFC requirements are complex and evolve through circulars, codes, guidelines, and enforcement decisions. Consult a qualified compliance professional or legal adviser for guidance specific to your licensed corporation and regulated activities.

sfc-compliancehong-kong-compliancelicensed-corporationsfc-code-of-conductregulatory-documentationsfc-inspection

Need consistent content quality across your team?

TeamBench lets you create custom AI reviewers that score content against your specific criteria. Submit content, get instant scored feedback, and improve with one click.

  • Create custom AI reviewers for your brand
  • Score content against your specific criteria
  • Instant feedback, one-click improvement
  • Free to start — no credit card required