top of page

Hong Kong Dealers in Precious Metals and Stones (DPMS) Frontline Staff Compliance Training and Audit

This article is designed for senior management, Compliance Officers (CO), Money Laundering Reporting Officers (MLRO) and Audit of Hong Kong Dealers in Precious Metals and Stones (DPMS). It offers an in-depth analysis of how DPMS can develop an anti-money laundering and counter-terrorist financing (AML/CFT) operational system under Anti-Money Laundering and Counter-Terrorist Financing Ordinance, Chapter 615 (AMLO) that can effectively respond to compliance inspections by the Hong Kong Customs and Excise Department (C&ED), focusing on the first line of defence (frontline training) and the third line of defence (audit).

I. Building the Defence Framework: Application of the Three Lines of Defence Model for Dealers in Precious Metals and Stones

Pursuant to the AML/CFT Guideline for Category B Registrants Engaged in Dealing in Precious Metals and Stones issued by C&ED and the Financial Action Task Force (FATF) 40 Recommendations, Category B registrants must establish a clear internal control framework.

 

AML Three Lines of Defence Framework for Dealers in Precious Metals and Stones

防線階層 Lines of Defense
核心執行人員 Key Personnel
法定合規職責 Compliance Duties
First Line of Defence (1st Line)

前線銷售、門市收銀員、客戶服務代表

Execute Customer Due Diligence (CDD), identify HKD 120,000 cash "structuring" and suspicious transaction red flag indicators.

Second Line of Defence (2nd Line)

合規主任 (CO)洗錢報告主任(MLRO)

Formulate internal AML/CFT policies, approve high-risk transactions, and submit Suspicious Transaction Reports (STR) to the Joint Financial Intelligence Unit (JFIU).

Third Line of Defence (3rd Line)

內部審計 (Internal Audit) / 第三方獨立顧問

Periodically and objectively assess the effectiveness of internal controls, conduct spot checks on frontline execution rates, and report systemic deficiencies directly to the board of directors.

II. First Line of Defence: Frontline Staff Compliance Training Practices

Frontline staff are the first gatekeepers in identifying money laundering risks. Without compliance awareness at the frontline, even the most comprehensive AML/CFT policies are rendered ineffective.

類別 Category
項目 Item
執行標準與詳細內容 Execution Standards & Details
I. Training Targets and Frequency

Applicable Targets

Store sales personnel, cashiers, customer service representatives, store managers and new employees.

New Employee Onboarding Training

Must be completed within 30 days of onboarding; before completing training, strictly prohibited from independently handling specified cash transactions.

Regular On-the-Job Training

At least once per year; content must be updated in accordance with the latest guidelines issued by C&ED.

Ad Hoc Remedial Training

Conducted immediately when any of the following occurs:

1. Legislative amendments

2. Changes to company AML/CFT policies

3. Compliance gaps identified by Internal Audit

II. Core Curriculum

Legal Foundation and Criminal Liability

Explain AMLO, the HKD 120,000specified cash transaction threshold and the criminal liability for tipping-off.

Linked Transactions and Anti-Structuring

Teach frontline personnel through real cases how to identify techniques such as "same customer structuring" or "syndicate batch ordering" used to evade scrutiny.

Suspicious Transaction Indicator Identification

Identify two major anomaly indicators:

  • Behavioural Anomalies: Price insensitivity, refusal to provide identification.
  • Financial Anomalies: Large quantities of soiled banknotes, third-party payments.

Internal Reporting Procedures

Familiarise with the procedure for completing an internal STR and submitting it to the MLRO within 2 hoursupon discovering anomalies.

Assessment Mechanism

A test must be conducted after training (passing score of 80%); those who fail must retake the test until they pass.

Record Retention

Attendance records, copies of training materials, certificates and test scores must be properly retained for at least 5 years.

III. Assessment and Record Management

Assessment Mechanism

A test must be conducted after training (passing score of 80%); those who fail must retake the test until they pass.

Record Retention

Attendance records, copies of training materials, certificates and test scores must be properly retained for at least 5 years.

III. Third Line of Defence: Audit and Independent Review Mechanism

Audit refers to the objective assessment of whether the design and execution of the company’s AML/CFT system remain continuously effective, preventing the system from becoming a mere formality.

IV. Key Compliance Points

Training Records Are Compliance Evidence:

During C&ED inspections, employee training records or test records are the first items reviewed. No records means deemed not executed.

Audit Frequency Should Match Risk:

Category B registrants are recommended to conduct an independent AML/CFT audit every two years. If the business volume is extremely large or if C&ED has previously issued improvement recommendations, the audit should be conducted annually.

V. Frequently Asked Questions (Q&A)

Q1: Must Category B registrants establish a standalone "internal audit department"? Is it lawful to engage a third-party consultancy firm to handle this?

A: It is not required to establish a dedicated internal audit department; engaging a third-party consultancy firm is entirely lawful and common practice. According to C&ED guidelines and FATF standards, the key requirements are the independence and professional competence of the review. A third-party consultancy firm with professional AML/CFT audit experience and no direct conflict of interest with the business units under review can produce an independent review report that is recognised by C&ED or other authorities.

Q2: Can a newly onboarded employee, during the 30-day transition period before completing AML/CFT training, handle specified cash transactions (HKD 120,000 or above)?

A: Absolutely not. Before completing onboarding training, new employees are strictly prohibited from independently handling any specified cash transaction reaching or exceeding HKD 120,000. If such transactions arise during the transition period, they must be supervised and co-signed throughout by a trained senior employee or store manager; otherwise, this constitutes an internal control deficiency.

Q3: If a frontline employee identifies unusual customer behaviour and submits an internal report to the MLRO, can the employee tell the customer "we are conducting a compliance review"?

A: Strictly prohibited — such action constitutes the criminal offence of tipping-off!

  • Under AMLO, any person who discloses to another that a report has been made to the MLRO or JFIU, or that a suspicious transaction investigation is underway, commits an offence.

  • Correct frontline practice: Standard Front-Line Procedure: Maintain a professional attitude and strictly refrain from disclosing any review or investigation details to the client. Internal reports must be submitted to the MLRO within two hours.

Q4: How often should a Category B registrant conduct an independent AML/CFT audit?

A: The frequency should be determined based on the company’s risk assessment results.

    The general guidelines are as follows:

  • Normal Frequency: An independent AML/CFT audit is recommended every two years.

  • High-Risk / Special Circumstances: If the company has an extremely large business volume, is involved in high-risk jurisdictions/customers, introduces new business models, or has previously received compliance improvement recommendations from C&ED, the frequency must be increased to annually.

Q5: How long must training records and audit reports be retained according to C&ED regulations? Are electronic records acceptable?

A: They must be properly retained for at least 5 years.

  • All compliance records must be retained for at least 5 years.

  • Electronic Retention: Fully acceptable, provided that records can be retrieved and printed immediately during C&ED spot checks.

VI. Professional Services ComplianceOne Provides for DPMS

ComplianceOne Consultants Limited ("ComplianceOne") has successfully assisted numerous jewellers and precious metals investment companies in completing DPMS registration, including both Category A and Category B applications. We provide the following one-stop services:

  • Eligibility Assessment: Identify your company’s business model and recommend the most suitable registration category

  • Application Preparation: Assist in organising business registration documents, completing application forms and submitting them to C&ED.

  • AML System Development (Category B): Draft customer due diligence policies, establish ongoing monitoring and suspicious transaction reporting mechanisms

  • Staff Training: Provide AML compliance training for management and staff

  • Independent Audit (Category B): Conduct periodic independent reviews of the AML system

  • Annual Renewal: Assist with Category B Registration renewal applications

  • Automated Screening System: Provide compliant screening and AML/customer management systems

 

Note: ComplianceOne is a licensed Trust or Company Service Provider (TCSP Licence No.: TC007463), with extensive experience in handling various financial and non-financial compliance matters.

Conclusion

With C&ED stepping up enforcement, AML compliance for DPMS is critical to safeguarding business resilience and market reputation. A truly effective compliance system relies on well-trained front-line staff and regular, independent internal audits. ComplianceOne offers deep industry expertise to help gold and jewelry merchants implement 'risk-based' regulatory requirements. We help you stay inspection-ready for the , enabling long-term, sustainable business growth.

bottom of page