SFC Compliance Documentation Review for Hong Kong Licensed Corporations
SFC-licensed corporations face extensive documentation requirements under the SFO and Code of Conduct. Here's what documentation you need, common inspection findings, and how to review for completeness.
The Securities and Futures Commission conducts regular inspections of licensed corporations — and documentation is the first thing inspectors examine. Not trading records or client portfolios. Documentation. Your compliance manual, policies and procedures, KYC records, and internal controls framework tell the SFC whether your firm takes compliance seriously before they look at a single transaction.
Common SFC inspection findings consistently relate to documentation deficiencies: incomplete compliance manuals, outdated policies, insufficient KYC records, and inadequate record-keeping. These are preventable findings — if your documentation is reviewed systematically before the SFC reviews it for you.
SFC Licensing and Documentation Landscape
Regulated Activities (Types 1-12)
| Type | Activity | Documentation Intensity |
|---|---|---|
| Type 1 | Dealing in securities | High |
| Type 2 | Dealing in futures contracts | High |
| Type 3 | Leveraged foreign exchange trading | High |
| Type 4 | Advising on securities | Medium-High |
| Type 5 | Advising on futures contracts | Medium-High |
| Type 6 | Advising on corporate finance | High |
| Type 7 | Providing automated trading services | High |
| Type 8 | Securities margin financing | High |
| Type 9 | Asset management | High |
| Type 10 | Providing credit rating services | Medium |
| Type 11 | Dealing in OTC derivative products | High |
| Type 12 | Providing client clearing services | High |
Every licensed corporation, regardless of type, must maintain core compliance documentation. Additional documentation requirements apply based on the specific regulated activities conducted.
Required Compliance Documentation
1. Compliance Manual
The foundation document that sets out the firm's compliance framework.
Must address:
| Section | What to Include |
|---|---|
| Regulatory framework | Applicable laws, regulations, codes (SFO, Code of Conduct, subsidiary legislation) |
| Organisational structure | Compliance function structure, reporting lines, Responsible Officers |
| General compliance obligations | Licensing conditions, notification requirements, continuing obligations |
| Client-facing requirements | Know your client, suitability, client agreements, best execution |
| Market conduct | Market misconduct prevention, personal dealing, conflicts of interest |
| AML/CFT | Anti-money laundering programme, CDD requirements, suspicious transaction reporting |
| Record keeping | Retention requirements, formats, accessibility |
| Complaints handling | Procedures for receiving, investigating, and resolving complaints |
| Breach management | Internal reporting, escalation, regulatory notification |
Common inspection finding: Compliance manuals that haven't been updated to reflect current regulatory requirements. The SFC expects manuals to be reviewed and updated at least annually, and whenever significant regulatory changes occur.
2. Policies and Procedures
Separate, detailed policies for each major compliance area:
| Policy | Key Requirements |
|---|---|
| KYC/CDD Policy | Customer identification, verification, ongoing monitoring, enhanced due diligence for high-risk customers |
| AML/CFT Policy | Risk assessment, CDD procedures, transaction monitoring, suspicious transaction reporting, sanctions screening |
| Suitability Policy | Suitability assessment requirements, documentation of suitability analysis, product due diligence |
| Best Execution Policy | Execution factors, venue selection, monitoring, client disclosure |
| Conflicts of Interest Policy | Identification, management, disclosure of conflicts |
| Personal Dealing Policy | Pre-clearance, restricted lists, reporting requirements |
| Complaints Handling Policy | Receipt, acknowledgement, investigation, resolution, record-keeping |
| Business Continuity Plan | Risk assessment, recovery procedures, testing schedule |
| Information Barriers Policy | Chinese walls, restricted information handling, crossing procedures |
| Outsourcing Policy | Due diligence, oversight, regulatory notification requirements |
3. KYC and Client Documentation
The most inspected documentation category. SFC Circular on AML/CFT and the Guideline on AML/CFT set detailed requirements.
Per client, maintain:
| Document | Requirement |
|---|---|
| Client identification | Certified copies of identification documents |
| Verification records | Evidence of identity verification steps taken |
| Risk assessment | Customer risk rating with rationale |
| Source of funds/wealth | Documentation for high-risk and PEP customers |
| Suitability assessment | Risk tolerance, investment objectives, financial situation, knowledge and experience |
| Client agreement | Signed client agreement per SFC requirements |
| Account opening records | Complete account opening documentation |
| Ongoing monitoring records | Periodic review documentation, trigger event reviews |
4. Transaction and Trading Records
| Record | Retention Period |
|---|---|
| Transaction records | 7 years |
| Order records | 7 years |
| Client instructions | 7 years |
| Trade confirmations | 7 years |
| Account statements | 7 years |
| Telephone recordings (where applicable) | 6 months minimum |
5. Regulatory Correspondence and Notifications
| Document | When Required |
|---|---|
| SFC correspondence | Retain all incoming and outgoing correspondence with SFC |
| Licensing notifications | Changes to licensees, ROs, substantial shareholders |
| Breach notifications | Reports of regulatory breaches to SFC |
| Financial returns | Monthly/quarterly financial returns as required |
| Annual returns | Audited accounts and annual returns |
Common SFC Inspection Findings
Finding 1: Inadequate KYC/CDD Documentation
The single most common finding. Issues include: incomplete identification records, missing risk assessments, no documentation of ongoing monitoring, and failure to update client information when trigger events occur.
Prevention: Implement a KYC documentation checklist for each client type (individual, corporate, trust, PEP) and review completeness at account opening and during periodic reviews.
Finding 2: Outdated Compliance Manual
Compliance manuals that reference superseded regulations, outdated organisational structures, or discontinued processes. The SFC views an outdated compliance manual as evidence of a weak compliance culture.
Prevention: Schedule annual compliance manual reviews. Implement a regulatory change tracking process that triggers manual updates when relevant regulations change.
Finding 3: Insufficient Suitability Documentation
Recommendations made without documented suitability analysis, or suitability assessments that are generic rather than client-specific. The SFC requires documented evidence that suitability was assessed for each recommendation.
Prevention: Standardise suitability assessment documentation with specific fields for risk tolerance, investment horizon, financial situation, knowledge/experience, and the rationale linking the recommendation to the client's profile.
Finding 4: Weak AML/CFT Implementation
Policies exist on paper but aren't implemented in practice. Transaction monitoring gaps, late suspicious transaction reports, and incomplete sanctions screening are common findings.
Prevention: Review AML/CFT documentation against actual practices quarterly. Ensure transaction monitoring records demonstrate that alerts are investigated and resolved, not just generated.
Finding 5: Poor Record-Keeping Practices
Records that are incomplete, disorganised, or inaccessible. The SFC expects records to be readily retrievable during inspections — not reconstructed after the inspector requests them.
Prevention: Implement a record retention schedule with clear ownership. Test retrieval periodically — can you produce a specific client's complete KYC file within one business day?
Preparing for SFC Inspections
Pre-Inspection Documentation Review
| Priority | What to Review | Why |
|---|---|---|
| P1 | KYC files for a sample of clients (including high-risk) | Most commonly inspected; highest finding rate |
| P1 | Compliance manual currency | Inspectors check if the manual reflects current requirements |
| P1 | AML/CFT records (STR filings, transaction monitoring logs) | Focus area for all inspections |
| P2 | Suitability documentation for recent recommendations | Increasingly scrutinised |
| P2 | Complaints register and resolution records | Must demonstrate proper handling |
| P3 | Business continuity plan and testing records | Should be current and tested |
| P3 | Training records for licensed representatives | Must demonstrate ongoing compliance training |
Documentation Review Criteria
| Criterion | Weight | What to Check |
|---|---|---|
| Completeness | 3 | All required documents present for each category |
| Currency | 3 | Policies reflect current regulations and organisational structure |
| Consistency | 2 | Policies align with actual practices; no contradictions between documents |
| Specificity | 2 | Procedures are specific enough to follow, not generic boilerplate |
| Accessibility | 1 | Documents are organised, indexed, and retrievable within a reasonable timeframe |
Reviewing SFC Compliance Documentation
Using AI Review for SFC Documentation
AI review can systematically check SFC compliance documentation for:
- Completeness — are all required sections present in each policy?
- Currency — do references cite current regulations (not superseded versions)?
- Consistency — do related policies align (e.g., KYC policy and AML/CFT policy)?
- Plain language — are procedures clear enough for staff to follow?
- Structure — does each policy follow a consistent, professional format?
What AI review cannot do: Verify that documented procedures match actual practices, assess the adequacy of risk assessments, or determine whether specific KYC records meet the SFC's expectations for a particular client type. These require qualified compliance review.
Frequently Asked Questions
How often should we review our compliance documentation?
Full review: annually, timed before the SFC's typical inspection cycle. Targeted review: whenever a significant regulatory change occurs (new circular, amended code, guideline update). Ad hoc review: when organisational changes affect compliance procedures (new business lines, restructuring, key personnel changes).
What happens if the SFC finds documentation deficiencies?
Depending on severity: a management letter requesting remediation, compliance advice, a warning, or formal disciplinary action. Serious or repeated documentation failures can result in licence conditions, fines, or suspension. The SFC publishes enforcement actions — reputational impact is significant.
Should our compliance manual be one document or multiple?
Either approach is acceptable. Many firms use a master compliance manual with separate, detailed policy documents for each area (AML/CFT, KYC, suitability, etc.). The key is that the documentation is comprehensive, consistent, and accessible — not the format.
How long must we retain compliance records?
The SFO requires retention of transaction records for 7 years. The SFC's Code of Conduct and various guidelines specify retention periods for different record types. When in doubt, retain for 7 years — it's the safest standard that covers most requirements.
Do we need to document compliance training?
Yes. The SFC expects licensed representatives to receive regular compliance training, and for that training to be documented. Records should include: training date, topics covered, attendees, and assessment results (if applicable). The SFC's Guidelines on Competence specifically address ongoing training requirements.
Key Takeaways
- SFC inspections focus on documentation first. Your compliance manual, KYC files, and AML/CFT records are the primary inspection targets.
- The five most common findings are: inadequate KYC, outdated compliance manuals, insufficient suitability documentation, weak AML/CFT implementation, and poor record-keeping.
- Review documentation annually at minimum, and after every significant regulatory change.
- KYC documentation completeness is the single highest-risk area — implement per-client checklists.
- AI review checks completeness, currency, consistency, and structure — compliance adequacy requires qualified professional review.
- Prepare for inspections proactively — review before the SFC does, not after they send the inspection notice.
This article is for informational purposes only. SFC requirements are complex and evolve through circulars, codes, guidelines, and enforcement decisions. Consult a qualified compliance professional or legal adviser for guidance specific to your licensed corporation and regulated activities.