Act 2011
Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615)
Issued by Joint Financial Intelligence Unit
Effective: 1 Apr 2012
Last amended: 12 May 2026
Plain-English summary
The Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615) is the statutory regime that governs CDD requirements and record-keeping requirements in the various financial and professional sectors in Hong Kong. Under the strict enforcement regimes of the various sectoral regulators, the banks, securities dealers, insurance companies, and trust or company service providers have to undertake systematic client identification, identification of politically exposed persons (PEPs), transaction monitoring, and suspicious activity reporting to the JFIU. The consolidation of the financial institutions and the designated non-financial professions within one statutory framework makes Hong Kong compliant with the FATF regulations and combats financial crime.
Who it applies to
Banking · Insurance · Capital Markets · Crypto / VDA · DNFBPs (Lawyers, Accountants, Dealers)
Topics
AML / CFT / Sanctions
Obligations arising from this instrument
| Obligation | Timing | Regulator | Source | Detail |
|---|---|---|---|---|
| AML compliance programme and officer | Ongoing | JFIU | source | |
Anti-money laundering regime in Hong Kong as stipulated in the Anti-Money Laundering and Counter-Terrorist Financing Ordinance requires the adoption of risk-based compliance programs, which include Customer Due Diligence, transaction monitoring, and record keeping for a period of six years. Organizations are supposed to have a Compliance Officer and a Money Laundering Reporting Officer responsible for ensuring internal controls and filing Suspicious Transaction Reports to the Joint Financial Intelligence Unit, with penalties for not complying of HK$10 million and seven years' imprisonment. |
||||
| AML record retention | Retention period 5 years | JFIU | source | |
With respect to the timing of the AML document retention rule of Hong Kong, a rigid statutory period of at least five years should be set forth, wherein the trigger factor of the period depends solely on the category of the document to be stored [AMLO Cap 615 Hong Kong]. In terms of Customer Due Diligence (CDD) documents and account opening documents, the five-year period starts on the exact date when the business relationship is ended. Meanwhile, in the case of transaction documents, the five-year period commences on the date when the transaction is completed, no matter what status the account is having [AMLO Cap 615 Hong Kong]. In practice, the time periods may go beyond five years due to other regulatory mandates of different sectors (such as the Customs and Excise Department), as well as the Hong Kong Companies Ordinance, not to mention the indefinite period of those files linked to an ongoing JFIU investigation. |
||||
| Customer due diligence (KYC/CDD) | At onboarding + ongoing | JFIU | source | |
The CDD/KYC requirement in Hong Kong is a risk-based preventative statutory obligation which acts as a strict gatekeeper for financial crime [AMLO Cap 615 Hong Kong]. The requirement makes it a total responsibility of the institutions and compliance officers to identify the identity of customers before any business relation or transaction can be made, totally disallowing any anonymity or false accounts [AMLO Cap 615 Hong Kong]. This obligation is not a strict checklist but rather a requirement where the institutions will have to make a risk-based approach – conducting EDD on risky accounts as well as looking through corporate structures to expose any ultimate beneficial owners who hold over 25% stake. In summary, if the institution fails to meet these requirements, the legal mandate requires them to block the transaction and end the business relations while considering the necessity of filing a suspicious activity report. |
||||
| Suspicious transaction reporting | Deadline Event-based | JFIU | source | |
The temporal value of the HK’s obligation regarding suspicious transaction reporting requires that a report should be submitted "as soon as is reasonably practicable." Since this requirement is an immediate statutory obligation, there is no pre-established schedule or multi-day period of grace. Instead, regulators anticipate prompt internal notification of the MLRO and reporting directly to the JFIU. When the suspicion is generated before the execution of a transaction, the timeliness of reporting becomes vital since the company needs to freeze the transaction instantly in order to receive "Authorized Consent" from the JFIU, as handling of suspicious funds before submitting a report is the primary form of money laundering offense. Moreover, when a report is made, the typical five-seven-year cycle of data deletion is suspended and the records need to be kept forever until the case is closed by the law enforcement agency. |
||||
| No obligations match these filters. | ||||
Latest news
-
AUSTRAC Examines Western Union AML Controls and Transaction Monitoring
26 Sep 2026
Australia's financial intelligence unit has initiated a formal investigation into Western Union's anti-money laundering framework and compliance infrastructure. The regulatory examination focuses on the company's paymen…
-
RBI penalizes Ola Financial Services for KYC compliance failures
25 Sep 2026
The Reserve Bank of India imposed a monetary penalty of ₹3.10 lakh on Ola Financial Services Private Limited for non-compliance with KYC directions under the Payment and Settlement Systems Act, 2007. Following a statuto…