How Licensed Corporations File the SFC Business and Risk Management Questionnaire (BRMQ)? 5 Common Pitfalls and Compliance Filing Guide
The Business and Risk Management Questionnaire (BRMQ) is a core questionnaire used by the Hong Kong Securities and Futures Commission (SFC) to evaluate the risk rating of Licensed Corporations (LCs), and must be submitted via the SFC WINGS platform within 4 months after the end of each financial year. Through the BRMQ, the SFC systematically collects operational data, client asset scale, cybersecurity measures, and internal control frameworks from Licensed Corporations. For Managers-In-Charge (MICs), Chief Operating Officers (COOs), and Chief Financial Officers (CFOs) of Licensed Corporations, successfully completing the SFC BRMQ questionnaire is not only a statutory annual compliance obligation, but also a crucial indicator demonstrating the institution's robust governance standards. Understanding common SFC BRMQ common pitfalls and implementing a precise Licensed Corporation BRMQ filing workflow can effectively mitigate the risk of regulatory on-site inspections or inquiries.
I. 5 Common Pitfalls and Traps in BRMQ Filing for Licensed Corporations
Many Licensed Corporations fall into the following five compliance traps during BRMQ preparation due to insufficient cross-departmental communication or misinterpretation of question definitions:
-
1. Misclassification of Client Assets and Custody Structure Reporting Errors
One of the most common pitfalls is confusing "Client Money" with "House Money," or failing to accurately report the proportion of assets custodied with Authorized Institutions (AIs) versus compliant custodians. If the Licensed Corporation deals with Virtual Assets (VA) or tokenized products, failing to precisely report private key custody arrangements or cold/hot wallet asset allocation ratios will easily trigger regulatory alerts.
-
2. Discrepancies Between Reported Cybersecurity/IT Infrastructure and Actual Operations
The BRMQ contains extensive detailed questions regarding cybersecurity defenses, Multi-Factor Authentication (MFA), data encryption, and Business Continuity Plans (BCP). Some institutions adopt idealized policy terms during filing while overlooking operational realities, such as unfulfilled remote access privilege controls or penetration testing frequencies falling short of requirements, creating a disconnect between reported data and on-site inspection findings.
-
3. Inaccurate Anti-Money Laundering (AML/CFT) and High-Risk Client Statistics
The BRMQ requires Licensed Corporations to disclose numbers of Politically Exposed Persons (PEPs) and clients from high-risk countries/regions, as well as the number of suspicious transaction alerts triggered and reports filed with the Joint Financial Intelligence Unit (JFIU) during the year. Licensed Corporations lacking automated transaction monitoring systems that rely solely on manual estimates often produce statistical omissions or inconsistencies.
-
4. Omissions in Outsourcing Services and MIC Responsibility Matrix Reporting
If a Licensed Corporation outsources critical functions (such as IT system maintenance, AML screening tools, or cloud storage) to third-party service providers, these must be fully disclosed in the BRMQ. A common error is failing to include material outsourcing agreements or presenting an MIC (Manager-In-Charge) responsibility division that contradicts the latest organizational chart submitted to the SFC.
-
5. Significant Contradictions Between BRMQ Data and Financial Returns (FRR) or Audited Reports
Data within the BRMQ regarding total client assets, Assets Under Management (AUM), trading volume, and revenue structure must strictly reconcile with the monthly Financial Resources Rules (FRR) returns and audited annual financial statements submitted to the SFC for the corresponding period. Data discrepancies are the primary trigger for in-depth SFC investigations.
II. 3-Step Standard Process for Compliant BRMQ Filing for Licensed Corporations
To ensure reporting accuracy and compliance, Licensed Corporations should establish a standardized BRMQ preparation mechanism:
-
Step 1: Cross-Departmental Data Collection and Pre-Filing Reconciliation
Led by the Compliance Department, collaborate with Accounting/Finance (CFO/MIC in charge), Operations (COO), and IT departments to cross-check data across all BRMQ sections, ensuring data sources are authoritative and traceable.
-
Step 2: Compliance Gap Diagnosis and Historical Data Comparison
Compare current-year data against the previous year's BRMQ filing records. If business data (such as AUM, client headcount, or trading volume) exhibits significant abnormal fluctuations, prepare reasonable commercial explanations and supporting documentation prior to submission.
-
Step 3: MIC & Board Review and Authorized Submission via WINGS
The BRMQ must be signed and verified by designated Managers-In-Charge (typically the MIC of Compliance or MIC of Overall Management Oversight (MIC of OMO)) and an Executive Director (ED), before final electronic submission via the WINGS platform within 4 months following the financial year-end.
III. Q&A: BRMQ Filing Inquiries and Regulatory Accountability
Q1: What are the serious consequences if reported data contradicts FRR returns or audited financial reports?
A: If discrepancies arise between BRMQ data and FRR returns or audited financial reports, the SFC typically initiates the following regulatory actions:
-
Issuance of Requests for Information (RFI): Requiring the Licensed Corporation to submit detailed written explanations and a Reconciliation Statement regarding the data variances within a short timeframe.
-
Elevation of the Licensed Corporation's Regulatory Risk Rating: Data inconsistencies directly erode the SFC's trust in the firm's internal controls and financial management capabilities, potentially placing the Licensed Corporation on a priority monitoring list.
-
Triggering Unannounced On-Site Inspections: If doubts cannot be resolved through written clarification, the SFC inspection team will directly enter the Licensed Corporation's premises to examine underlying accounts and system logs.
-
Statutory Disciplinary Action and Criminal Liability: Under Section 384 of the Securities and Futures Ordinance (SFO), any person who knowingly or recklessly provides false or misleading information in a material particular to the SFC commits an offense. The Licensed Corporation, Responsible Officers (ROs), and relevant MICs may face fines or criminal prosecution.
Q2: Is a Licensed Corporation still required to submit the BRMQ if it had no active operations (Dormant Status) during the financial year?
A: Yes. As long as a corporation holds an SFC license, even if it conducted no Regulated Activities (RAs) or held no client assets during that financial year, it must still submit the BRMQ within the statutory deadline, accurately checking the non-operational options to complete a zero-filing process.
Q3: If data errors are discovered after submitting the BRMQ, can an application for rectification be made?
A: Yes. If a Licensed Corporation identifies material data errors post-submission, it should immediately contact its assigned SFC Case Officer, explain the cause of the error, and submit a rectified questionnaire along with an explanatory cover letter via the WINGS platform. Proactive rectification demonstrates compliance good faith far better than awaiting discovery during regulatory audits.
Conclusion
The Business and Risk Management Questionnaire (BRMQ) serves as a vital window through which Licensed Corporations demonstrate their compliance health. ComplianceOne Consulting Limited (“ComplianceOne”) brings extensive experience in BRMQ review, data reconciliation, and WINGS filing advisory, assisting Licensed Corporations in identifying reporting pitfalls and ensuring flawless annual compliance submissions. This support is fully integrated into our Ongoing Compliance Support Services.
