Hong Kong has been a FATF member since 1991 and joined the Asia/Pacific Group on Money Laundering (APG) in 1997 — a long enough regulatory track record that Hong Kong became the first FATF member in Asia-Pacific to receive an overall "compliant" assessment.
What is the Hong Kong Monetary Authority, and what does it actually do?
The HKMA is Hong Kong's central banking institution, established on 1 April 1993 through the consolidation of the Office of the Exchange Fund and the Office of the Commissioner of Banking. Its four core functions: supporting Hong Kong's status as an international financial centre and developing financial infrastructure, maintaining currency stability under the Linked Exchange Rate System, managing the Exchange Fund, and promoting financial system stability and banking integrity — AML/CTF supervision sits within that last function specifically.
What's the underlying legal framework?
The Anti-Money Laundering and Counter-Terrorist Financing Ordinance (AMLO) covers customer due diligence and record-keeping obligations, while the Banking Ordinance (BO) requires banks to maintain adequate internal control systems more broadly. Together they give Hong Kong both a dedicated AML statute and a general prudential requirement that AML controls have to sit within.
What does the HKMA actually supervise day to day?
Authorised Institutions' money-laundering/terrorism-financing risk assessment and compliance specifically, alongside providing guidance so institutions can direct compliance resources efficiently rather than spreading them evenly regardless of actual risk. The HKMA also represents Hong Kong in international standard-setting bodies — FATF, APG, and Basel Committee Expert Groups — feeding global standards back into domestic supervision.
What does the risk-based approach require of an individual institution?
Systems sized to the institution's own business — its nature, size, and complexity, not a one-size-fits-all template. In practice that means: compliance management arrangements with a designated Compliance Officer and Money Laundering Reporting Officer, employee screening procedures, an independent audit function, and ongoing staff training. The risk-based approach itself requires institutions to first identify, assess, and genuinely understand their own ML/TF risk before implementing controls proportionate to it — sequencing that matters, since proportionate controls built on a weak risk assessment tend to be proportionate to the wrong thing.



