top of page

SFC Latest Circular Interpretation: Enhanced Account Opening Vetting and Client Lifecycle AML Monitoring Guidelines

The Hong Kong Securities and Futures Commission (SFC) requires Licensed Corporations (LCs) to implement enhanced safeguards against risks in remote onboarding, non-face-to-face verification, and forged identity documents. As financial technology and artificial intelligence proliferate, deepfake face-swapping and document forgery schemes have grown increasingly sophisticated. In response, the SFC has issued multiple SFC Account Opening Circulars and updated its SFC Account Opening Guidelines, enforcing strict control standards across remote onboarding AML screening and client lifecycle monitoring. Brokerage operations managers, Compliance Officers (COs), and Money Laundering Reporting Officers (MLROs) must establish robust end-to-end control frameworks that seamlessly bridge initial onboarding and ongoing surveillance.

I. Comparison of Verification Standards: Face-to-Face vs. Non-Face-to-Face / Remote Onboarding

Understanding regulatory nuances across face-to-face and remote onboarding helps Licensed Corporations design onboarding workflows that balance user experience with compliance security:

核實與控管維度 Verification & Control Dimension
面對面開戶 Face-to-Face Onboarding
非面對面 / 遠程開戶 Non-Face-to-Face / Remote Onboarding

Identity Document Verification

Licensed individuals or authorized representatives physically inspect original ID documents on-site, conducting   face-to-document and signature verification.

Must utilize recognized electronic identity verification technology (e.g., HK "iAM Smart"), digital certificates issued by recognized certification authorities, or certified true copies by designated professionals (e.g., lawyers, accountants).

Source of Funds & Bank Account Linking

Initial account funding can be transferred via a same-name or designated bank account.

Must be conducted via a same-name Hong Kong licensed bank account (transferring at least HKD 10,000 or equivalent), or an approved designated overseas bank account for initial fund remittance and reconciliation.

Biometrics & Anti-Fraud Detection

Licensed personnel perform physical, visual comparisons between the client and photo ID on-site.

Must deploy tamper-proof OCR document recognition and dynamic Liveness Detection to prevent AI deepfake face-swapping and static photo fraud.

AML / PEP / Sanctions Pre-Screening

Complete automated screening against blacklists, Sanctioned Persons (SAN), and Politically Exposed Persons (PEPs) prior to application submission.

Must execute real-time automated API screening against blacklists, Sanctioned Persons (SAN), and Politically   Exposed Persons (PEPs) before writing account data to systems, archiving screening logs.

High-Risk Client Approval Procedures

Escalate high-risk cases to the compliance department according to standard CDD procedures.

High-risk clients onboarding remotely (e.g., overseas PEPs) must undergo Enhanced Due Diligence (EDD) and secure   prior approval from senior management (ED or MLRO).

II. Lifecycle Ongoing Monitoring for PEPs and High-Risk Clients

Customer Due Diligence (CDD) extends well beyond the initial onboarding stage. Licensed Corporations must construct a dynamic monitoring mechanism spanning the client's complete lifecycle:

 

  • 1. Initial Risk Categorization & Dynamic Classification

Classify clients into high, medium, or low-risk tiers based on background, geographic location, product selection, and source of funds. Automatically flag Politically Exposed Persons (PEPs), clients from high-risk countries/jurisdictions, and complex trust structures as high-risk.

 

  • 2. Automated Transaction Monitoring & Exception Alerts

Deploy transaction monitoring systems to establish operational baselines covering transaction size, fund transfer frequencies, and investment preferences. Immediate exception alerts must trigger upon detecting large fund flows inconsistent with declared income, frequent cross-border transfers, or transactions lacking clear commercial purpose.

 

  • 3. Trigger Event Review Mechanisms

When material lifecycle events occur (e.g., career changes elevating a client to PEP status, corporate structure alterations, adverse media hits, or suspicious transaction alerts), the MLRO department must immediately initiate a review to re-evaluate client risk tiers.

 

  • 4. Execution of Periodic Review Cycles

    • High-Risk Clients (including PEPs): Conduct deep periodic reviews at least annually, re-verifying Source of Funds (SOF) and Source of Wealth (SOW), signed off by the MLRO or Executive Director (ED).

    • Medium-Risk Clients: Conduct periodic reviews every 2 to 3 years.

    • Low-Risk Clients: Review every 3 to 5 years, or upon the occurrence of a trigger event.

III. Core SFC Account Opening & AML Guidelines & Circulars

Licensed Corporations formulating onboarding and ongoing surveillance policies must strictly align with official SFC guidelines and circulars:

 

 

 

 

IV. Q&A: Practical Issues in Remote Onboarding and Client Lifecycle AML

Q1: What are the recognized identity verification pathways when onboarding overseas individual clients remotely via non-face-to-face methods?

A: According to SFC circulars, Licensed Corporations may adopt one of the following recognized routes:

 

  • Pathway 1 (Overseas Bank Account + Transfer): Verify identity via an approved designated overseas bank account (located in a FATF member state or equivalent jurisdiction), provided the client transfers an initial deposit of no less than HKD 10,000 (or foreign currency equivalent) from that same-name account.

 

  • Pathway 2 (Recognized Electronic Identity / Digital Certificate): Conduct online verification using officially recognized electronic identities (e.g., Hong Kong "iAM Smart") or recognized personal digital certificates issued within corresponding jurisdictions.

 

  • Pathway 3 (Professional Certification): Obtain certified true copies of original ID documents verified and signed by an acceptable professional (e.g., a HK practicing lawyer, CPA, or notary public).

 

Q2: How should Licensed Corporations satisfy regulatory mandates regarding AI Deepfake fraud prevention during remote onboarding?

A: LCs must deploy multi-layered anti-fraud controls within remote onboarding APPs or web platforms:

 

  • Interactive Liveness Detection: Mandate users to complete random prompts on camera (e.g., reading out random numbers, specific blinking/head turning commands) to prevent pre-recorded videos or static images from bypassing systems.

 

  • Micro-Expression & Lighting Analysis: Incorporate AI algorithms capable of analyzing skin texture, lighting changes, and subtle facial anomalies to detect deepfake synthesis artifacts in real time.

 

  • Device & Network Fingerprinting: Identify whether onboarding devices utilize emulators, VPN proxies, or frequent IP switching, triggering manual secondary reviews for high-risk profiles.

 

Q3: What immediate actions should the MLRO take if an existing client elevates to PEP status or is added to a high-risk list during their lifecycle?

A: Once system alerts or periodic reviews confirm a client has become a PEP, the LC must execute the following response steps:

 

  • Suspend High-Risk Functionalities: Restrict large fund withdrawals/deposits or high-risk product trading permissions pending risk re-assessment.

 

  • Initiate Enhanced Due Diligence (EDD): Request documentary evidence verifying the client's latest Source of Funds (SOF) and Source of Wealth (SOW).

 

  • Senior Management Approval: Escalate to the MLRO and Executive Director (ED) to re-determine whether to maintain the business relationship; if maintained, increase ongoing transaction monitoring and review frequency (at least annually).

​

  • File a Suspicious Transaction Report (STR): If asset origins remain questionable or unverified, the MLRO must promptly submit a Suspicious Transaction Report to the Joint Financial Intelligence Unit (JFIU) as legally required.

Conclusion

Constructing a compliant and effective onboarding and ongoing monitoring framework serves as a Licensed Corporation's primary defense against money laundering risks. ComplianceOne Consulting Limited (“ComplianceOne”) brings extensive experience in SFC onboarding process reviews, remote onboarding system compliance assessments, and AML/CFT framework setup, offering LCs end-to-end professional support. Our Ongoing Compliance Support Services, integrated with our proprietary RegTech solutions (such as the Screen-X AML/KYC Solutions (Screen-X) and eDon AML Transaction Monitoring System (eDon TM) ), provide robust technological and practical compliance safeguards.

bottom of page