The SFC licensed corporations s' conduct requirements for employees: Employee personal transaction and conflict of interest reporting from the perspective of internal control systems
According to the Code of Conduct for Licensees or Registered Persons of the Securities and Futures Commission (hereinafter referred to as the "Code of Conduct"), the SFC requires licensed institutions to establish sound internal control measures to properly manage employees' personal account transactions and conflicts of interest. Employees must report their personal trading accounts to their respective companies and obtain approval before engaging in any trading activities. The reporting and management of conflicts of interest vary in risk level depending on the type of license (such as Type 6 Corporate Finance, Type 9 Asset Management, and Type 10 Credit Rating). In some cases, only post-event notification is required, while in others, prior application and written consent are necessary. The following will explain in detail the relevant provisions of the Code of Conduct, the conflict management requirements for different license types, the personal transaction reporting mechanism, the internal control framework, and the importance of continuous compliance, and will provide practical guidance for board members and all financial practitioners by combining real enforcement cases.
The Core Control Framework of the Code of Conduct for Employee Conduct
The Code of Conduct stipulates that the SFC expects licensees to maintain market integrity and stability and protect client interests. Although the Code of Conduct is not a legal provision, the SFC will use it as an important reference guide when assessing whether a licensee or registrant meets the criteria for "suitable person." The control of employee conduct mainly revolves around two areas: personal account trading and conflict of interest management. The SFC expects licensees to separate their personal interests from those of their clients through robust internal control measures. The table below summarizes the requirements and practical operations of the Code of Conduct:
管控範疇 Scope of control | 《操守準則》核心原則 Core Principles of the Code o | 內部監控實務要求 Internal monitoring practice re |
|---|---|---|
Personal account trading | Employees must declare their personal trading accounts and apply for trading approval in advance according to company policy; trading with unauthorized accounts is prohibited. | Develop employee transaction policies; establish a transaction reporting system; conduct independent reviews of employee transactions; implement post-transaction spot checks and confirmation procedures; and obtain copies of employee account statements for verification after the reporting period ends. |
Conflict of interest | Identify actual or potential conflicts of interest; take reasonable steps to prevent conflicts, and provide specific disclosure to clients when conflicts cannot be avoided. | Require employees to declare external business interests and potential conflicts of interest; maintain a conflict of interest register; implement a "wall" policy before transactions; restrict employees from holding concurrent external positions; prohibit personal transactions in the same direction as client transactions. |
Internal monitoring | Organizations must establish a robust compliance culture and monitoring measures. | Senior management demonstrates a commitment to compliance; an independent compliance department is established; monitoring measures are reviewed regularly; and ongoing compliance training is provided. |
Disciplinary action | Violations of the Code of Conduct and internal policies may result in disciplinary action, including fines, license revocation, and even imprisonment. | Detailed enforcement cases and fines are listed below. |
Application Mode for High-Risk License Categories: Prior Application vs. Post-Application Notification
The Securities and Futures Commission (SFC) assesses conflict of interest risks differently for different license types. Below are some high-risk license categories and their corresponding practical handling models:
牌照級別 License Level | 涵蓋類別 Categories Covered | 核心業務 Core Business | 潛在利益衝突風險 Potential conflict of interest | 管控強度/申報模式 Control intensity/reporting mo |
|---|---|---|---|---|
Trading and Brokerage | Category 1 (Securities Trading)
Category 2 (Futures Contract Trading)
Category 3 (Leveraged Forex Trading)
Category 7 (Providing Automated Trading Services) | Executing buy and sell orders, providing trading channels, and margin financing. | Medium-to-high: May prioritize processing individual orders; conduct proprietary trading (front-running) using customers' unexecuted order information; use customer assets as collateral for personal financing. | Hybrid model: More flexible, low-risk positions can adopt a post-event notification and quarterly spot check system; however, for personnel involved in proprietary trading or handling customer order information, a strict "barrier" policy and pre-approval mechanism must be established. |
Corporate Finance and Sponsor | Category 6 (Providing advice on institutional financing)
(Including sponsors, placement agents, and underwriters) | Initial Public Offering Sponsorship, Compliance Advisory, Placement, Underwriting | Extremely high risk: Continuous exposure to material, non-public, price-sensitive information; sponsors must maintain independence and are strictly prohibited from trading related securities during the appointment period; placement and underwriting may involve the transfer of benefits to the issuer. | Prior application is paramount: all personal transactions must obtain prior written approval from the compliance department and strictly adhere to cooling-off periods and segregation regulations; members of the sponsor team are generally prohibited from holding or trading related securities. |
Asset Management | Category 9 (Providing asset management) | Discretionary account management and fund portfolio management | Extremely high: The manager may invest client funds in related funds or collect commissions; may prioritize personal portfolios or use client funds to inflate the value of personal holdings. | Prior application is the primary requirement: all personal transactions must be pre-approved by the compliance department; a fair prioritization and execution rule of "clients first, employees second" is enforced; high-risk positions (such as fund managers) are subject to quarterly independent reviews. |
Credit rating | Category 10 (Providing credit rating services) | Provide credit ratings for issuers | Very High: If rating analysts hold securities of the rated agency, their independence and objectivity will be severely affected; the rating agency's own commercial relationship with the issuer (such as fee collection) may constitute a conflict. | The dual-track hybrid model implements a strict "wall" separation policy for daily rating work, prohibiting analysts from holding securities of the rated entities; non-core personnel (such as administrative and IT staff) can adopt a post-event periodic reporting system; rating agencies must establish an independent compliance department to monitor conflict situations. |
Consulting and Research | Category 4 (Providing advice on securities) Category 5 (Advising on futures contracts) | Writing research reports and providing investment advice | Moderate: Analysts' personal shareholdings may affect the objectivity of their research opinions; the research department may be biased due to pressure from other business units within the company (such as investment banking). | Hybrid model: Primarily relies on compliance spot checks and conflict of interest disclosure systems; research reports must be reviewed by the compliance department before publication to confirm the absence of undisclosed individual shareholdings or related-party transactions. |
Practical Notes: The SFC's circular points out that many asset management companies have failed to properly manage conflicts of interest, with some companies prioritizing their own or related entities' interests over those of their clients. Management must take all reasonable steps in accordance with the Code of Conduct to identify, prevent, and monitor all actual or potential conflicts of interest. For industry categories with higher conflict risk, internal controls must be designed more rigorously, and obtaining prior approval from the compliance department is standard practice; for categories with lower conflict risk, post-event reporting can be adopted, but must be accompanied by an effective random audit and verification mechanism.
Employee Personal Transaction Reporting System and Internal Control Requirements
Section 12.2 of the SFC's Code of Conduct explicitly stipulates that licensed institutions must formulate written policies to regulate employees' securities transactions for personal gain and require employees to report and disclose such transactions. Specific practical requirements are as follows:
管控範疇 Scope of control | 內部監控實務要求 Internal monitoring practice re |
|---|---|
Personal account declaration | Employees must report all their securities trading accounts to the company; upon new employment and annually. |
Transaction pre-approval | Most companies have policies requiring employees to obtain compliance approval before trading; personal trading is prohibited for securities on restricted lists. |
Account concealment is prohibited | Employees are prohibited from conducting transactions in accounts registered under other people's names (such as family members) to circumvent reporting requirements. |
Minimum holding period | Most companies have policies that set a minimum holding period (e.g., 30 days) for individual transactions to prevent short-term speculation and the acquisition of undisclosed profits. |
Transaction records are kept on file. | The company should require employees to provide transaction statements for their accounts, which should then be independently reviewed by the compliance department. |
The SFC’senforcement actions demonstrate that this is not just a policy on paper:
-
Case 1 (Concealing Personal Accounts): In 2025, the Securities and Futures Commission (SFC) imposed a seven-month market ban on a former licensed representative, Mr. Zheng, for reasons including concealing his mother's securities trading account and conducting over 260 personal transactions in that account without reporting them to the company. The representative also failed to disclose his personal securities trading account to the company, raising questions about his reliability and competence. This clearly demonstrates that simply maintaining written policies is insufficient; institutions must proactively implement and monitor them.
Common Conflict of Interest Scenarios and Compliance Prevention Measures
利益衝突情境 Conflict of interest scenarios | 潛在風險 Potential risks | 合規防治措施 Compliance prevention measures |
|---|---|---|
Front-running | Using customer order information to establish a position and obtain illicit profits. | Employees are strictly prohibited from conducting transactions in their personal capacity or in the name of their associates before a customer order is executed; an electronic monitoring system will be established to detect suspicious transaction patterns. |
Related Party Transactions and Priority Treatment | Investing client funds in related entities (such as funds under the group) or prioritizing transaction orders that are favorable to oneself. | Customer relations staff are required to disclose all related-party transactions in writing; the "price/time priority" principle must be followed when executing transactions; and any significant conflicts of interest must be specifically disclosed, including the interests of counterparties, asset managers, and related companies. |
Receiving Undisclosed gifts or rebates | This affects the objectivity of judgment and causes harm to the interests of clients. | Clear reporting thresholds are set and enforced (e.g., gifts exceeding a specified amount must be reported); employees who violate these regulations will be held personally liable. |
Concurrently holding external positions | Time and attention were diverted, and business secrets were leaked. | The board of directors must approve all external salaried positions and directorships in advance. |
Construction of Internal Control Framework and ComplianceOne's Professional Services
A robust internal control framework is fundamental to managing employee conduct risks. ComplianceOne Consultanting Limited (“ComplianceOne”) offers an “Internal Control Review” service specifically designed to assist licensed corporations in reviewing their internal systems and controls, policies, procedures, and operational practices to address specific regulatory concerns. This includes: conducting walkthrough tests on key processes and controls to assess the design effectiveness of internal control procedures; performing sample tests on key controls to assess the operational effectiveness of relevant internal control procedures and measures; and providing practical recommendations to strengthen your company’s internal control framework.
Furthermore, ComplianceOne’s “Ongoing Compliance Support Service” provides customized solutions based on the nature of an organization’s business and risk profile. Services cover reviewing and evaluating clients’ policies, internal control measures, manuals, procedures, and documents; reviewing marketing materials and client communications before their release or delivery to clients; handling licensing matters for responsible personnel and representatives, including conducting competency assessments; and providing customized compliance training for senior management and employees.
Meanwhile, ComplianceOne’s eDon AML Transaction Monitoring System (eDon TM) is an integrated solution for anti-money laundering and transaction monitoring. This system, through automated processes and machine learning technology, can efficiently identify abnormal transactions and suspicious money laundering activities. It supports both on-premises and cloud environments and offers nearly 50 preset transaction monitoring rules. Financial institutions can flexibly adjust rules, parameters, and even customize rules according to their business needs. The system also integrates the "Screen-X AML/CRM Solutions " function, continuously monitoring customer data and global sanctions list databases to achieve end-to-end transaction monitoring and comprehensively improve compliance efficiency.
Frequently Asked Questions (Q&A)
Q1:How should Type 6 license holders manage conflicts of interest in their work as sponsors?
A: The independence requirements for sponsors are extremely stringent. Members of the sponsor's team and their affiliated entities are typically prohibited from trading the relevant securities during the appointment period. This falls under the category of situations requiring strict adherence to "pre-approval," and any violation could result in serious regulatory consequences.
Q2: What issues must asset managers pay attention to when managing conflicts?
A: Type 9 licensed corporations (asset management) must comply with the following requirements:
-
Separation of Responsibilities: The trading activities of employees responsible for investment decisions should be strictly limited, and trading records must be independently reviewed.
-
Segregation of Information: Ensure that trading instructions on behalf of the fund take precedence over any individual trading instructions.
-
Fee Disclosure: If the fund invests in investment projects initiated by the manager itself or its affiliates, it must provide clients with full and clear written disclosure.
Q3:How should employees handle personal transaction reporting for "family accounts"?
A: According to SFC enforcement cases, even if transactions are conducted in the name of a family member, if the employee has a beneficial interest in or control over the account, they are still obligated to report it to the company. Concealing a family member's account is considered intentional deception and can result in severe regulatory penalties.
Q4: How does ComplianceOne assist clients in establishing effective employee conduct monitoring systems?
A:ComplianceOne provides the following professional support:
-
Policy Review: Review and assess whether the current Employee Trading Policy and Conflict of Interest Policy comply with the SFC’s requirements
-
Gap Analysis: Identify deficiencies in the design and operation of current internal control procedures through walkthrough testing and sample testing, and provide optimization suggestions.
-
System Development: Assist in the development of internal documents such as compliance manuals and anti-money laundering policies.
Continuing Compliance: Provide customized ongoing compliance support, including compliance training and regulatory communication and coordination.
Conclusion
In recent years, the Securities and Futures Commission (SFC) has continuously strengthened its enforcement efforts regarding internal controls and employee conduct of licensed institutions. Management must ensure that institutions have established comprehensive Employee Trading Policies and Conflict of Interest Disclosure Systems, and conduct regular internal reviews and compliance audits. ComplianceOne's Internal Control Review and Continuous Compliance Services can assist institutions in establishing and maintaining these key systems. Directors and all employees should remember that adhering to the Code of Conduct is not only a regulatory responsibility, but also a fundamental commitment to maintaining market integrity and protecting client assets.
