introduction: Why is the "BP+AML Manual" the watershed between the success and failure of licensed institutions?
In Hong Kong and cross-border financial business scenarios, Many applicants mistakenly believe that the key to obtaining a license is "complete materials", But real regulatory practice tells us: Business Plan, BP)andAML Internal Monitoring ManualIt is the core document for regulatory agencies to evaluate whether you are a "truly sustainable operation".Whether it is Hong Kong MSO, SFC related licenses, Insurance brokerage or moneylender business, Regulators are increasingly concerned about whether institutions have enforceable, traceable, Auditable governance system.
Simply put, BP is responsible for answering "What are you going to do?, how to make money, How to grow steadily", The AML Handbook answers "How do you identify and control illicit funding risks?".If the two are out of touch, Typical problems will arise: Radical business planning, Risk control mechanism is empty, Unclear boundaries of responsibilities, Formalizing the KYC process, Eventually leading to repeated patches, Delay in approval, They were even required to make rectifications during subsequent annual reviews and on-site inspections..

one, From a regulatory perspective: What problems do the BP and AML manuals solve respectively?

1. The regulatory implications of a business plan (BP)
Regulators don't just look at "business prospects", Look at the following points more:
- Is the business model legal and clear?: capital flow, Customer type, Whether the product structure is consistent with the scope of license application;
- Is the governance structure stable?: Board of Directors, Responsible person, Whether the compliance position has experience and responsibilities that match it;
- financial sustainability: revenue logic, cost structure, Are capital adequacy arrangements reasonable?;
- Risk identification ability: Whether to recognize cross-border payments, high risk jurisdictions, Potential risks such as agency channels.
2. Regulatory Implications of AML's Internal Control Manual
The AML manual is not an "institutional decoration", It's about institutional implementationFATF "Anti-Money Laundering", International Standards on Counter-Terrorism Financing and Counter-Proliferation Financing"General diagram of operation.Supervision usually focuses on:
- Whether to establish a risk-based approach framework;
- KYC, Customer Risk Rating, Is continuous due diligence a closed loop?;
- Whether the suspicious transaction monitoring and reporting process is enforceable;
- MLRO/Compliance Team Authority, Are reporting paths and record keeping clear?;
- staff training, System audit, Whether the independent review mechanism is implemented.
two, Core specifications for licensed financial BPs: Not writing "vision", Instead, write "verifiable capability"
1. The business boundary must correspond to the license scope one-to-one
The most common minefield for BP is "the business description is too broad".For example, applying for a certain type of payment or securities-related license, However, investment and financing matching beyond the authorized scope was written in BP., Asset management or disguised lending arrangements.This will be viewed by regulators as unclear boundaries or even potential violations..
suggestion: Use "Business Flow Chart + Transaction Chain" to present each link: Customer source, Account opening path, Funds in and out, Settlement channel, third party partners.Ensure every step has license basis and compliance instructions.
2. Revenue models must have "traceability assumptions"
Many BPs only write "Estimated revenue growth of 300% in three years", but did not explain the source of the growth.Regulation pays more attention to whether assumptions are verifiable:
- How is the unit price formed?
- What is the basis for customer conversion rate?
- Do channel costs match industry realities?
- Bad debt rate, Chargeback rate, How to calculate abnormal transaction rate?
If it is cross-border business, Exchange rate fluctuations should also be reflected, Jurisdiction changes, Bank cooperation policy adjustments and other stress tests.
3. Organizational structure and job competencies must be "matched between people and positions"
The supervisory committee will cross-check the organizational structure in BP and the resumes of personnel in the application materials..Typical questions include: Nominal Compliance Officer, Too many part-time jobs in key positions, The person in charge of the business does not have relevant license experience, etc..
high quality practices: Clearly list key positions (directors) in BP, RO, MLRO, Risk control, Operations) Responsibility Matrix, Approval authority and substitute mechanism, and consistent with actual employment or appointment arrangements.
4. Technology and operational systems must be able to support compliance enforcement
If you emphasize "technology-driven" in BP, The supervisory committee will ask: Is there a transaction monitoring rules engine? Do you support sanctions list screening? Are there log retention and audit trails?
therefore, BP should contain:
- System Architecture Overview (Core System, interface, permission management);
- Data governance policy (retention period, 加密, access control);
- Outsourcing management mechanism (supplier due diligence, SLA, Emergency switching).
three, Core Specifications of the AML Internal Control Manual: From "complete text" to "effective mechanism"
1. Adopt risk-based approach (RBA) for layered management
The manual should clearly indicate to the customer, area, product, Four types of risk factors in trading channels, and build a scoring model.Not all clients undergo the same depth of due diligence:
- low risk customers: Standard due diligence (CDD);
- high risk customers: Enhanced due diligence (EDD), Including verification of source of funds and wealth;
- Continuous monitoring: Set review frequency based on risk level.
2. KYC process must be "evidenceable"
Supervision is most afraid of "verbal compliance".KYC evidence standards should be clearly stated in the manual, Include proof of identity, Proof of address, Beneficial owner identification, Authorized signatory verification, Company structure penetration, etc., and stipulate:
- Criteria for rejecting account opening;
- Replacement time limit and upgrade path;
- Exit mechanism when due diligence cannot be completed.
3. The suspicious transaction monitoring (STR) process must have trigger thresholds and time limits
The phrase "report abnormalities after discovering them" is too general..The manual should be written clearly:
- Abnormal triggering scenarios (frequent small splits, Large transactions that do not match the business, Short-term multi-account cycle, etc.);
- Preliminary screening, Review, MLRO decision, Responsible person and time limit for reporting traces;
- Internal confidentiality and "tipping-off" requirements.
4. training, Testing and independent review are essential
An excellent AML system must include an annual training plan, Differentiated job assessment and independent review.Supervision is not just about "number of trainings", It is more about whether employees understand and can implement it after training.
It is recommended that at least every year:
- AML basic training for all employees;
- Practical drills on frontline and review positions;
- System effectiveness sampling testing and rectification tracking.
Four, High-frequency minefields in approval and annual review (Practical List)
Minefield 1: BP and AML manuals "fight" with each other
BP writes "for global high net worth and cross-border corporate clients", AML manual but no EDD mechanism for high-risk customers; BP emphasizes fast online account opening, The manual requires offline original verification.Such inconsistencies significantly reduce credibility.
Minefield 2: Copy the template, Lack of characteristics of this organization
Supervisors read a lot of templated documents, It's obvious at a glance that "no practical operational thinking".For example, inapplicable regulatory provisions appear in the manual, The job title is inconsistent with the actual company, etc., will be seen as weak in compliance governance.
Minefield 3: Just talk about the system, No evidence of execution
No record keeping regulations, No approval log, No exception handling ledger, Even if the system is well written, May also be judged to be "paper compliant" during inspection.
Minefield 4: Ignore the continuous update mechanism
regulatory policy, sanctions list, Market risks are constantly changing.If the manual is not updated for two or three years, It is easy to trigger rectification requirements during the annual review.A fixed update cycle and a "major event triggered update" mechanism should be set up.
five, How to build a "landable", Can be passed, Sustainable" documentation system?

1. Make a business and risk map first, Write the file again
Don't apply the template first.The customer journey should be sorted out first, Funding path, high risk touchpoints, Then infer the BP and AML control points.
2. Use the "three-tier document structure" to improve execution
- first floor: Policy level documents(BP, AML policy, governance principles);
- second floor: program level files(Open an account, Due diligence, monitor, reporting process);
- third floor: record level file(form, Ledger, Approval records, training records).
3. Do a good job in "regulatory Q&A rehearsal"
Will supervise questions that may be asked (authenticity of customer origin, High risk customer handling, Transaction monitoring threshold basis, System capabilities, etc.) formulate a response caliber in advance, and consistent with the documentation, Avoid "one set of files", A set of calibers".
4. Introducing an external professional review mechanism
For first-time applicants or institutions expanding across licenses, The value of external compliance advisors is: Upgrade documents from "enterprise perspective" to "regulatory perspective".This is why more and more companies choose to have a team familiar with Hong Kong practices for full case hosting and ongoing maintenance..
in this regard, 88MSO and its professional team have been serving MSO for a long time, SFC, Insurance brokerage, moneylender and other multi-track projects, Ability to submit application documents, Internal systems are aligned with subsequent annual review requirements, Reduce the hidden costs of "rework after review".
six, Practical template framework reference (can be directly used for internal project approval)
BP suggested directory
- Company background and ownership structure
- Description of license scope and business boundaries
- Target market and customer stratification strategy
- Product and service flow chart
- Risk control and compliance governance structure
- Financial Forecasting and Stress Testing
- IT systems and data security mechanisms
- Milestone and KPI management
AML Handbook Suggested Table of Contents
- Policy objectives and scope of application
- Risk assessment model and customer classification
- CDD/EDD/KYC standards and processes
- Transaction monitoring, Early warning and STR process
- Sanctions screening and list management
- Record keeping and internal reporting mechanisms
- training, Audit and independent review
- System update and board supervision
Conclusion: The nature of compliance documents, It is a "verifiable expression" of business capabilities.
Write internal control manual for licensed financial BP and AML, not paperwork, It's a timely review of the company's strategy, governance, Systematic physical examination of risk control and execution.Really high quality files, Able to satisfy three things at the same time: Supervision is understandable, The team can do it, Check and get evidence.
If the business goal is long-term operation rather than "short-term license acquisition", It is recommended to establish an integrated mechanism of "application documents - system implementation - annual review and maintenance" as soon as possible.This will not only improve the efficiency of approval, It can also be expanded in the future., Bank cooperation, Continue to benefit from cross-border capital arrangements.Compliance is not a cost center, It is the underlying competitiveness of financial institutions through the cycle..