HKSI Licensing Examination Paper 1 (Regulation) — All Questions
63 questions
Under the AMLO and the SFC's AML/CFT Guideline, a licensed corporation opening an account for a new client must first:
- a.Obtain the SFC's written consent
- b.Wait 90 days before any transaction
- c.Report the prospective client to the police as a criminal suspect before opening any account or accepting funds
- d.Carry out customer due diligence to identify and verify the client and any beneficial owner✓
The Anti-Money Laundering and Counter-Terrorist Financing Ordinance requires customer due diligence (CDD): identifying and verifying the customer and beneficial owners and understanding the purpose of the relationship, on a risk-based approach, with enhanced due diligence for higher-risk clients such as politically exposed persons.
A licensed representative forms a suspicion that a client's transaction involves proceeds of crime. The representative must:
- a.Reverse the transaction without keeping a record
- b.File a suspicious transaction report with the Joint Financial Intelligence Unit (JFIU)✓
- c.Immediately warn the client of the concern and ask them to explain the source of the funds before doing anything else
- d.Report only at the year-end audit
Suspicious transactions must be reported to the Joint Financial Intelligence Unit (JFIU). Warning or 'tipping off' the client that a report has been or may be made is a criminal offence under the AMLO and OSCO.
Handling of clients' personal data by an intermediary is governed principally by:
- a.The Stamp Duty Ordinance
- b.The Listing Rules of the Stock Exchange, which set out how the personal data of investors must be collected and stored
- c.The Companies Ordinance
- d.The Personal Data (Privacy) Ordinance and its data protection principles✓
The Personal Data (Privacy) Ordinance (PDPO) and its six Data Protection Principles govern the collection, use, security and retention of clients' personal data, and are referenced in the business-operations topic of the Paper 1 syllabus.
Under the Management, Supervision and Internal Control Guidelines and General Principle 9, ultimate responsibility for a firm's proper controls and compliance rests with:
- a.The firm's senior management✓
- b.The external auditor
- c.The most junior compliance clerk
- d.The SFC's enforcement division
General Principle 9 (Responsibility of senior management) and the Internal Control Guidelines place ultimate responsibility for maintaining appropriate standards of conduct, controls and compliance on the firm's senior management.
Under AMLO Schedule 2, when a customer is a company, the intermediary must identify any beneficial owner, meaning generally an individual who:
- a.Is a director, regardless of shareholding
- b.Holds exactly 5% of the voting shares, this being the fixed statutory figure for identifying beneficial owners of every corporate customer under the Ordinance
- c.Ultimately owns or controls more than 25% of the company, or otherwise exercises control over it✓
- d.Owns any single share in the company
AMLO Schedule 2 defines a beneficial owner of a corporate customer to include an individual who ultimately owns or controls (directly or indirectly) more than 25% of the issued share capital or voting rights, or who otherwise exercises ultimate control over the company.
Under the AMLO, customer due diligence records and transaction records must generally be kept for at least:
- a.5 years after the end of the business relationship (or after a transaction is completed)✓
- b.Six months from account opening, after which the Ordinance requires them to be securely destroyed to protect customer privacy
- c.3 months
- d.1 year
AMLO Schedule 2 requires CDD records to be kept throughout the business relationship and for at least 5 years after it ends, and transaction records for at least 5 years after the transaction is completed.
The obligation to report a suspicious transaction to the Joint Financial Intelligence Unit (JFIU):
- a.Applies to any suspicious transaction regardless of amount — there is no minimum value threshold✓
- b.Arises only once several suspicious transactions by the same customer have together exceeded one million Hong Kong dollars in a single calendar month
- c.Applies only to transactions above HK$120,000
- d.Applies only to cash transactions
The duty to report suspicion of proceeds of crime or terrorist financing (under OSCO/DTROP/UNATMO) is triggered by suspicion itself, with no de minimis threshold — any suspicious transaction must be reported to the JFIU regardless of value.
After a suspicious transaction report has been filed, an employee who tells the customer that a report has been made:
- a.Has acted properly and transparently
- b.Has breached only an internal policy
- c.Commits the criminal offence of 'tipping off'✓
- d.Must simply note it in the file
Disclosing to a person that a suspicious transaction report has been or may be made, in a way likely to prejudice an investigation, is the criminal offence of 'tipping off' under OSCO/DTROP. Staff must not warn the customer.
The three recognised stages of money laundering are:
- a.Collection, conversion and taxation
- b.Deposit, transfer and withdrawal
- c.Origination, distribution and settlement
- d.Placement, layering and integration✓
Money laundering is typically described in three stages: placement (introducing illicit funds into the financial system), layering (moving them through transactions to obscure their origin) and integration (returning them to the criminal as apparently legitimate wealth).
When a customer is identified as a politically exposed person (PEP), the AMLO requires the intermediary to:
- a.Treat the customer exactly like any ordinary retail client, since a person's political status has no bearing on money-laundering risk under the Ordinance
- b.Apply enhanced due diligence, obtain senior management approval to establish or continue the relationship, and establish the source of wealth and source of funds✓
- c.Refuse all business automatically
- d.Apply simplified due diligence
AMLO Schedule 2 requires enhanced due diligence for PEPs: obtaining senior management approval, taking reasonable measures to establish the source of wealth and funds, and conducting enhanced ongoing monitoring.
The AMLO framework is built on a 'risk-based approach', meaning an intermediary should:
- a.Assess risk only for professional investors
- b.Assess money-laundering risk once, at the very first meeting, and never revisit that assessment even as the customer's activity changes over the years
- c.Apply identical checks to every customer regardless of risk
- d.Direct more resources and scrutiny to higher-risk customers, products and situations✓
The risk-based approach in the AMLO and the SFC's AML/CFT Guideline requires firms to assess and mitigate risk proportionately, applying enhanced measures to higher-risk situations and keeping their risk assessments up to date.
Customer due diligence is not performed only at onboarding; the AMLO also requires:
- a.A single re-verification of the customer's identity precisely ten years after onboarding, with no transaction monitoring in the intervening period
- b.Continuous monitoring of the business relationship, including scrutiny of transactions to ensure they are consistent with what is known of the customer✓
- c.No further checks after onboarding
- d.Verification only when the account is closed
AMLO Schedule 2 requires ongoing monitoring of the business relationship, including reviewing transactions to ensure they are consistent with the firm's knowledge of the customer and their risk profile, and keeping CDD information current.
Sound AML controls require a firm to appoint a:
- a.Board-level committee whose sole function is to authorise, in advance, each and every individual customer transaction the firm processes during the day
- b.Full-time police liaison officer on staff
- c.Chief marketing officer to approve suspicious transaction reports
- d.Money Laundering Reporting Officer (MLRO) as the central point for receiving and evaluating internal suspicion reports✓
The SFC's AML/CFT Guideline expects firms to appoint a Money Laundering Reporting Officer (MLRO) and a Compliance Officer, giving them the authority and resources to receive internal reports, decide on external reporting to the JFIU, and oversee the AML programme.
Hong Kong's regime against terrorist financing (for example, the United Nations (Anti-Terrorism Measures) Ordinance) requires intermediaries to:
- a.Ignore sanctions lists
- b.Screen customers against terrorist and sanctions designations and freeze and report the funds of designated persons✓
- c.Screen only professional investors
- d.Report only after a year has passed
The United Nations (Anti-Terrorism Measures) Ordinance and related sanctions regimes require firms to screen against designated persons, refrain from dealing with their funds, freeze such funds, and report to the authorities.
Simplified due diligence may be appropriate under the AMLO where:
- a.The customer is a politically exposed person
- b.The customer refuses to provide any identification at all, since insisting on documents from reluctant customers is what simplified due diligence is designed to avoid
- c.The customer is lower-risk, such as certain regulated financial institutions or listed companies✓
- d.The transaction is anonymous and in cash
The AMLO permits simplified due diligence for defined lower-risk situations (for example, certain regulated financial institutions or listed companies subject to disclosure requirements), where the money-laundering risk is assessed to be low.
Onboarding a customer who is not physically present (non-face-to-face) is generally treated as:
- a.Prohibited entirely
- b.A higher-risk situation calling for additional measures to verify identity✓
- c.Lower risk requiring no checks
- d.Identical in risk to a face-to-face relationship, so the Ordinance requires no additional safeguards of any kind for remote customers
Non-face-to-face onboarding is treated as a higher-risk scenario under the SFC's AML/CFT Guideline, requiring additional identity-verification measures (such as certified documents or additional checks) to mitigate impersonation risk.
An intermediary may rely on another qualified intermediary to carry out certain CDD measures, but:
- a.It thereby transfers all legal responsibility to that other party
- b.It may do so only where the other intermediary is located outside Hong Kong and is not itself subject to any anti-money-laundering supervision
- c.It may do so only where the customer is a PEP
- d.It remains ultimately responsible for CDD compliance and must be able to obtain the underlying information without delay✓
AMLO Schedule 2 permits reliance on specified intermediaries to perform CDD, but the relying firm remains ultimately responsible for compliance and must be able to obtain the CDD information from the third party without delay.
Where a customer presents higher money-laundering risk, enhanced due diligence typically includes:
- a.Reducing the frequency of monitoring
- b.Increasing the customer's trading limits automatically, to reward them for the additional documentation the firm has requested
- c.Waiving identity verification
- d.Establishing the source of the customer's funds and, for PEPs, the source of their wealth✓
Enhanced due diligence for higher-risk customers involves additional measures such as establishing the source of funds (and, for PEPs, source of wealth), obtaining senior management approval, and conducting closer ongoing monitoring.
A customer who repeatedly deposits amounts just below a reporting threshold to avoid scrutiny is exhibiting:
- a.'Structuring' (smurfing), a classic money-laundering red flag✓
- b.A permitted tax-planning technique
- c.Normal cash-flow management
- d.Best practice in personal finance, which intermediaries are encouraged under the AMLO to suggest to customers who wish to keep their affairs private
Structuring (or 'smurfing') — breaking a large sum into smaller transactions to evade reporting thresholds or scrutiny — is a recognised money-laundering red flag that should prompt review and, where suspicion arises, a report to the JFIU.
Which of the following is a money-laundering red flag when reviewing a corporate customer?
- a.A locally incorporated company that files its annual returns on time and operates a genuine office with employees engaged in a real business
- b.An opaque ownership structure with no apparent commercial rationale and unclear beneficial ownership✓
- c.A long trading history with audited accounts
- d.A well-known listed parent company
Complex or opaque ownership structures with no clear commercial purpose, and difficulty in identifying the beneficial owner, are recognised red flags that call for enhanced scrutiny under the risk-based approach.
Under the AMLO, verification of a customer's identity should generally be completed:
- a.At the sole discretion of the customer, who may decline verification indefinitely provided they continue to trade actively through the account
- b.Before establishing the business relationship, with limited exceptions permitting completion as soon as reasonably practicable afterwards✓
- c.Only after the first year of trading
- d.Never, if the customer is introduced by a friend
AMLO Schedule 2 requires identity verification to be completed before establishing a business relationship, subject to limited exceptions allowing verification to be completed as soon as reasonably practicable where necessary not to interrupt normal business and where ML/TF risks are effectively managed.
When identity documents are provided by a non-face-to-face customer, a common safeguard is to:
- a.Accept plain uncertified photocopies without question
- b.Ask the customer to certify their own copies as true, since a customer is always the person best placed to confirm the authenticity of their own documents
- c.Obtain documents certified by a suitable person (for example, a professional or another regulated intermediary)✓
- d.Rely on the customer's verbal description of the document
For non-face-to-face customers, the SFC's AML/CFT Guideline suggests additional safeguards such as obtaining copies of identity documents certified by a suitable certifier, to mitigate the higher impersonation risk.
After making a report to the JFIU, the firm should:
- a.Immediately return the funds to the customer and close the file, so that the firm cannot be accused of continuing to hold the proceeds of any crime
- b.Delete all records of the matter
- c.Retain records of the report and supporting information, and follow any consent or 'no consent' guidance before proceeding with the transaction✓
- d.Publicise the report
After reporting, a firm should keep records of the report and supporting material and, before proceeding with a transaction linked to suspected proceeds of crime, have regard to the consent regime, since dealing with such property can otherwise expose it to liability.
The Financial Action Task Force (FATF) is:
- a.A Hong Kong court
- b.A Hong Kong government department that personally licenses each securities dealer and directly prosecutes money-laundering cases in the local courts
- c.The international standard-setter whose recommendations shape Hong Kong's AML/CFT regime✓
- d.The clearing house for HKEX trades
The FATF is the inter-governmental body that sets international anti-money-laundering and counter-terrorist-financing standards (the FATF Recommendations), which Hong Kong implements through the AMLO and related guidance.
A basic internal-control principle for a securities firm is segregation of duties, meaning:
- a.The dealing, settlement and audit of each transaction should all be performed by the same senior employee, so that accountability rests clearly with one identifiable individual
- b.One person should control a transaction from start to finish for efficiency
- c.Only directors may perform any operational task
- d.Incompatible functions (such as dealing, settlement and record-keeping) should be handled by different people to reduce fraud and error✓
Segregation of duties — separating incompatible functions such as dealing, settlement, custody and record-keeping — is a core internal control under the SFC's Management, Supervision and Internal Control Guidelines, reducing the risk of undetected fraud or error.
The SFC's Management, Supervision and Internal Control Guidelines address controls over areas such as:
- a.Exclusively the personal share portfolios of the firm's clients, and nothing about the firm's own management, supervision or operational systems
- b.Only the firm's tax affairs
- c.Management and supervision, segregation of client assets, risk management, operational controls, compliance and staff dealing✓
- d.Only the firm's marketing
The Management, Supervision and Internal Control Guidelines cover the whole control environment — management structure and supervision, segregation and safeguarding of client assets, risk management, operational and financial controls, compliance and staff dealing.
An effective compliance function within a licensed corporation should be:
- a.Staffed by the very dealing desk it is meant to monitor
- b.Adequately resourced and sufficiently independent to monitor and report on the firm's regulatory compliance✓
- c.Made directly subordinate to the head of sales, and required to obtain that person's approval before reporting any breach of the rules to senior management
- d.Abolished once the firm becomes profitable
The Internal Control Guidelines expect an adequately resourced and sufficiently independent compliance function that can monitor adherence to regulatory requirements and report directly to senior management, free from undue influence by the business lines it oversees.
Under the Securities and Futures (Keeping of Records) Rules, a licensed corporation must keep records that sufficiently explain its transactions and financial position for at least:
- a.3 months
- b.7 years✓
- c.30 days after each trade, after which the firm may lawfully discard them to reduce its data-storage costs
- d.1 year
The Securities and Futures (Keeping of Records) Rules require records that explain the firm's transactions and financial position to be kept for at least 7 years, supporting audit, supervision and reconstruction of the firm's dealings.
The Securities and Futures (Financial Resources) Rules (FRR) require a licensed corporation to:
- a.Keep exactly the same fixed amount of capital as every other firm in the market, irrespective of the type or scale of regulated activity it carries on
- b.Hold no minimum capital at all
- c.Invest all of its capital in client securities
- d.Maintain paid-up share capital and liquid capital at or above the prescribed minimum for its regulated activities, and report any shortfall to the SFC✓
The Financial Resources Rules require a licensed corporation to maintain minimum paid-up share capital and required liquid capital appropriate to its regulated activities, file financial returns, and notify the SFC of any shortfall.
If a licensed corporation's liquid capital falls below its required minimum, it must:
- a.Wait until the annual audit to disclose it
- b.Continue trading normally and simply add a footnote about the shortfall to next year's audited financial statements when they are eventually filed
- c.Notify the SFC immediately and cease business as required until the position is restored✓
- d.Borrow client money to cover the gap
Under the FRR, a firm that fails, or is likely to fail, to maintain required liquid capital must notify the SFC immediately and generally must not carry on regulated business until the shortfall is remedied. Client money may never be used to plug the gap.
A licensed corporation must generally submit to the SFC:
- a.Only a marketing brochure
- b.Audited accounts and the required financial returns within the prescribed periods✓
- c.A single set of unaudited figures prepared once, at the moment it is first licensed, and nothing further for the remaining life of the business
- d.No financial information at all
Licensed corporations must file audited financial statements and periodic financial returns (for example monthly or as prescribed) with the SFC within the required timeframes, enabling ongoing prudential supervision.
Sound operational controls expect a licensed corporation to maintain:
- a.Business continuity and contingency arrangements so that critical functions can continue after a disruption✓
- b.A policy of ceasing all client business permanently the first time any system outage or disruption occurs, however brief or minor
- c.No contingency plans, to save cost
- d.Plans that rely entirely on a single member of staff
The Internal Control Guidelines expect firms to have business continuity and contingency planning so that critical operations, client access and records can be maintained or promptly restored following disruptions.
SFC guidance on the security of internet trading expects firms to:
- a.Email each client their full login password in clear text every morning, so that customers who have forgotten their credentials can always trade without delay
- b.Treat cyber risk as purely an IT matter of no regulatory concern
- c.Implement controls such as two-factor authentication and monitoring to protect clients' internet-trading accounts✓
- d.Store client passwords in plain text for convenience
The SFC's guidelines on the management of cybersecurity risks and reducing internet-trading hacking risks expect controls such as two-factor authentication for client logins, monitoring, encryption and prompt incident response.
Under the Personal Data (Privacy) Ordinance, personal data collected from a client should be:
- a.Collected without limit and kept forever
- b.Collected for a lawful purpose, used only for that or a directly related purpose (absent consent), kept accurate and no longer than necessary, and adequately secured✓
- c.Published openly to demonstrate the firm's transparency
- d.Sold to any interested third party
The PDPO's Data Protection Principles require personal data to be collected for a lawful purpose, used only for that or a directly related purpose (unless the individual consents), kept accurate and no longer than necessary, adequately protected, and handled transparently, with a right of access and correction.
Before using a client's personal data for direct marketing, the PDPO generally requires the firm to:
- a.Inform the client and obtain the client's consent (or non-objection), and to cease such use on the client's request✓
- b.Obtain the SFC's approval
- c.Do nothing, as consent is always implied
- d.Sell the client's contact details to as many marketing partners as possible first, and only afterwards ask the client whether they might have preferred to opt out
The PDPO's direct-marketing provisions require a data user to notify the individual and obtain consent (or indication of no objection) before using personal data in direct marketing, and to cease using the data for that purpose if the individual so requests.
If a firm suffers a loss of clients' personal data, good practice and PDPO guidance is to:
- a.Conceal the breach indefinitely
- b.Take no action unless and until a client happens to notice the loss independently and personally lodges a formal written complaint about it
- c.Blame the clients for the loss
- d.Contain the breach, assess its impact, notify affected persons and the Privacy Commissioner as appropriate, and remediate✓
PDPO guidance on data breach handling recommends containing the breach, assessing the risk of harm, notifying affected data subjects and the Privacy Commissioner where appropriate, and taking remedial and preventive steps.
Client securities received by a firm should be:
- a.Held in safe custody and segregated from the firm's own assets, in accordance with the Client Securities Rules✓
- b.Registered in the dealer's own personal name
- c.Lent out to other clients of the firm at interest whenever the firm judges that doing so would be commercially advantageous, without any client authority
- d.Sold to fund the firm's operations
The Securities and Futures (Client Securities) Rules require client securities to be properly safeguarded and segregated from the firm's own assets, held in a designated client account or registered appropriately, and not dealt with except with the client's authority.
To detect errors and misappropriation, a firm should regularly:
- a.Reconcile client money and client securities records against bank and custodian statements✓
- b.Rely solely on the dealer's memory
- c.Compare this year's total client balances against last year's total, and treat any difference of less than one hundred per cent as requiring no further investigation
- d.Avoid checking client balances
Regular reconciliation of internal records of client money and client securities against external bank and custodian statements is a key control for detecting errors, shortfalls or misappropriation of client assets.
A firm's controls over employee dealing typically require staff to:
- a.Route their personal trades through client accounts, mixing them with client orders so that individual staff transactions are harder for compliance to identify
- b.Never disclose their personal trades to the firm
- c.Deal through monitored accounts and, where required, obtain pre-clearance, so the firm can detect front running or insider dealing✓
- d.Trade anonymously through overseas brokers
The Internal Control Guidelines and Code of Conduct expect firms to monitor employees' personal dealing — requiring dealing through identifiable accounts and pre-clearance where appropriate — so conflicts such as front running or insider dealing can be detected.
From an operations and internal-control perspective, client complaints should be:
- a.Handled informally with no records kept
- b.Logged, investigated, escalated where needed, and analysed for systemic issues✓
- c.Forwarded unread to the SFC
- d.Deleted from the firm's systems as soon as they are received, so that the existence of complaints cannot later be used against the firm by a regulator
Effective controls require complaints to be recorded, investigated and escalated, with root-cause analysis to identify systemic weaknesses. Proper complaint records also evidence the firm's handling to the SFC.
Showing 40 of 63