Bridge Corporate Services
Home
PlatformNewsContact
Get Started
Nelson Sousa·June 21, 2026

CFT Compliance for Trust Companies: Understanding Terrorist Financing Obligations in Hong Kong

Understand CFT compliance obligations for Hong Kong trust companies under the AMLO. Learn sanctions screening, STR requirements, and how to build CFT controls.

CFT Compliance for Trust Companies: Understanding Terrorist Financing Obligations in Hong Kong

Last Reviewed: June 2025

CFT compliance for trust companies in Hong Kong is a mandatory legal obligation governed by the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (AMLO), Cap. 615. Every licensed Trust Company Service Provider (TCSP) must implement documented counter-terrorist financing controls, conduct ongoing risk assessments, and report suspicious activity to the Joint Financial Intelligence Unit (JFIU). Failure to comply exposes firms to licence revocation, criminal prosecution, and significant reputational damage.

This article explains exactly what CFT obligations mean in practice for Hong Kong trust companies, how they differ from AML requirements, and what operational frameworks are needed to remain fully compliant.


What Is CFT and Why Does It Apply to Trust Companies in Hong Kong?

Counter-Terrorist Financing (CFT) refers to the set of legal and procedural measures designed to detect, prevent, and disrupt the flow of funds to terrorist organisations or individuals. While Anti-Money Laundering (AML) focuses on proceeds of crime entering the financial system, CFT specifically targets funds — lawful or otherwise — that are directed toward financing terrorist acts.

Trust companies occupy a uniquely high-risk position in this framework. They hold assets, manage corporate structures, and act on behalf of clients across multiple jurisdictions including Singapore, London, the Cayman Islands, the British Virgin Islands, and Switzerland. This cross-border exposure means a Hong Kong TCSP can inadvertently become a conduit for terrorist financing if controls are inadequate.

The Financial Action Task Force (FATF), the global standard-setter for AML/CFT policy, has consistently identified trust and company service providers as a high-risk sector. Hong Kong's AMLO directly incorporates FATF Recommendations, making CFT compliance a statutory — not advisory — requirement for all licensed TCSPs.


The Legal Framework: AMLO and the Companies Registry

The primary legislative instrument governing CFT obligations for Hong Kong trust companies is the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615). Under Schedule 2 of the AMLO, TCSPs are classified as "designated non-financial businesses and professions" (DNFBPs) and are subject to enhanced compliance obligations.

The Companies Registry serves as the licensing and supervisory authority for TCSPs in Hong Kong. It has the power to inspect records, issue guidance notes, and take enforcement action against firms that fail to maintain adequate CFT controls.

According to Hong Kong's 2024 Mutual Evaluation Report prepared by FATF, Hong Kong was assessed as having a robust legal framework but identified ongoing risks in the TCSP sector relating to the misuse of corporate vehicles for terrorist financing. This assessment directly informs the supervisory approach the Companies Registry now takes toward licensed trust companies.


Core CFT Obligations Every Hong Kong Trust Company Must Meet

CFT compliance for trust companies is not a single checkbox — it is an integrated programme of controls. The following obligations are mandatory under the AMLO:

1. Customer Due Diligence (CDD) with a CFT Lens

All TCSPs must conduct CDD on every client before establishing a business relationship. From a CFT perspective, this means verifying not only the identity of clients and beneficial owners, but also screening them against United Nations sanctions lists, the Hong Kong Monetary Authority (HKMA) sanctions database, and other designated terrorist and proliferation financing lists.

Enhanced Due Diligence (EDD) is required where a client or transaction presents higher CFT risk — for example, clients connected to jurisdictions identified by FATF as having strategic deficiencies, or structures involving complex beneficial ownership chains typical in BVI or Cayman Islands entities.

2. Ongoing Monitoring and Transaction Screening

CFT obligations do not end at onboarding. TCSPs must continuously monitor client activity for patterns that suggest terrorist financing, including:

  • Unusual fund transfers to or from high-risk jurisdictions
  • Client instructions inconsistent with their stated business purpose
  • Transactions involving politically exposed persons (PEPs) with links to extremist networks
  • Rapid movement of funds through trust structures with no clear commercial rationale

3. Suspicious Transaction Reporting (STR)

When a TCSP has knowledge or reasonable grounds to suspect that funds are connected to terrorist financing, it is legally obligated to file a Suspicious Transaction Report (STR) with the Joint Financial Intelligence Unit (JFIU), which operates under the joint authority of Hong Kong Police and Customs and Excise Department. Filing an STR also triggers "tipping off" restrictions — the TCSP must not disclose the report to the client or any third party.

4. Record Keeping

All CDD records, transaction records, and STRs must be retained for a minimum of six years under Schedule 2 of the AMLO. These records must be readily accessible for inspection by the Companies Registry.

5. Staff Training on CFT Red Flags

The AMLO requires TCSPs to ensure all relevant employees receive regular training on CFT obligations, including how to identify terrorist financing red flags specific to trust structures. Training must be documented and demonstrable during supervisory inspections.


How CFT Differs from AML in a Trust Company Context

A common misconception among TCSP practitioners is that a robust AML programme automatically satisfies CFT requirements. This is incorrect.

CFT compliance addresses a fundamentally different risk typology. AML controls are designed to identify funds that derive from criminal activity entering the financial system. CFT controls must identify funds — including funds from entirely legitimate sources — that are being directed toward terrorist activity. This means the risk indicators differ substantially, and a TCSP's policies and procedures must address both risk types independently.

For example, a client who is a legitimate businessperson with verifiable income may pass all AML checks but still present a CFT risk if they have undisclosed connections to designated terrorist organisations. TCSPs must maintain separate screening workflows and risk assessment matrices that capture CFT-specific typologies.


Q&A: Common CFT Compliance Questions from Hong Kong TCSPs

Q: Does CFT compliance apply to TCSPs that only serve corporate clients, not individuals?

Yes. CFT obligations under the AMLO apply to all TCSP licensees regardless of their client profile. Corporate clients can be used as vehicles for terrorist financing, and TCSPs must screen beneficial owners, controllers, and connected parties across all client types.

Q: How often must a TCSP update its CFT risk assessment?

The AMLO requires TCSPs to conduct a firm-wide CFT risk assessment at least annually, and to update client-level risk assessments whenever there is a material change in circumstances, a trigger event, or a periodic review cycle. The Companies Registry expects documented evidence of these reviews during inspections.

Q: What is the penalty for failing to file an STR when terrorist financing is suspected?

Under section 25A of the Drug Trafficking (Recovery of Proceeds) Ordinance and equivalent provisions in the AMLO, failure to report a known or suspected terrorist financing transaction is a criminal offence in Hong Kong. Individuals can face imprisonment of up to three months and a fine of up to HKD 50,000, while firms face significant regulatory sanctions including licence suspension or revocation.


Building a CFT-Ready Compliance Infrastructure

CFT compliance for trust companies requires more than written policies. It demands an operational infrastructure capable of executing controls consistently across every client relationship, every transaction, and every jurisdiction served.

Effective CFT infrastructure for a Hong Kong TCSP includes:

  • A written CFT policy that is distinct from the AML policy and addresses terrorist financing typologies specific to trust services
  • Sanctions screening tools that search in real time against UN, OFAC, EU, and Hong Kong-specific designated lists
  • A risk-based client classification system that assigns CFT risk ratings and triggers appropriate monitoring levels
  • A documented escalation and STR workflow that ensures the Money Laundering Reporting Officer (MLRO) receives timely alerts and can file STRs within required timeframes
  • An audit trail for every compliance decision, CDD action, and monitoring output

Purpose-built compliance platforms significantly reduce the operational burden of maintaining this infrastructure. Bridge Services offers a purpose-built SaaS platform designed specifically for licensed TCSPs that automates sanctions screening, manages client risk profiles, and maintains auditable records aligned with AMLO requirements — removing the need for manual, error-prone processes.

For firms seeking comprehensive support from inception through to ongoing operations, Bridge Services provides end-to-end TCSP company setup and licensing consulting alongside the technology infrastructure needed to operate compliantly from day one.


CFT Obligations Across Jurisdictions: The Convergence with Hong Kong Standards

TCSPs operating across multiple jurisdictions — including Singapore, the Cayman Islands, the British Virgin Islands, Switzerland, and London — face CFT frameworks that share common roots in FATF standards but differ in implementation detail.

Hong Kong's AMLO-based framework is broadly aligned with the Cayman Islands' Proceeds of Crime Law and the BVI's Anti-Money Laundering and Terrorist Financing Code of Practice. However, Hong Kong's framework is notable for the direct supervisory role of the Companies Registry, which conducts regular on-site and desk-based inspections. This contrasts with some other jurisdictions where supervisory intensity is lower.

For trust companies expanding into Hong Kong from Singapore, London, or the Cayman Islands, the CFT compliance framework will be familiar in structure but demanding in its documentation and inspection requirements. Expert guidance on Hong Kong TCSP regulations and AML/CFT requirements — as provided by specialists such as Bridge Services — ensures that firms adapt their existing compliance frameworks correctly rather than assuming equivalence.

For a broader overview of compliance obligations beyond CFT, the article on AML/CFT compliance for TCSP companies provides a comprehensive treatment of both regulatory pillars.


Quotable Insights on CFT Compliance

CFT compliance is not a subset of AML — it is a parallel obligation with distinct risk typologies, screening requirements, and reporting triggers. Trust companies that treat their AML programme as sufficient for CFT purposes are operating with a material compliance gap that supervisory inspections will expose.

The six-year record-keeping requirement under Hong Kong's AMLO is not merely administrative. It is the evidential foundation upon which every CDD decision, risk assessment, and STR submission can be reconstructed during a regulatory review. Without robust documentation infrastructure, even a firm with sound controls cannot demonstrate compliance.


Practical Steps to Strengthen CFT Compliance Today

If your trust company's CFT programme needs strengthening, prioritise the following actions:

  1. Commission a standalone CFT risk assessment separate from your AML risk assessment, addressing terrorist financing typologies specific to trust structures
  2. Review your sanctions screening coverage to confirm it includes UN, OFAC, EU, and HKMA-maintained lists, with real-time or near-real-time screening capability
  3. Audit your STR workflow to confirm escalation paths are clear, the MLRO is adequately resourced, and filing timelines are achievable
  4. Document staff CFT training for the past six years and schedule the next training cycle with updated content reflecting current FATF guidance
  5. Engage specialist TCSP compliance consultants to conduct a gap analysis against current Companies Registry expectations

Conclusion

CFT compliance for trust company service providers in Hong Kong is a demanding, non-negotiable regulatory obligation. It requires dedicated risk assessments, real-time sanctions screening, rigorous CDD, ongoing monitoring, timely STR filing, and documented staff training — all maintained to a standard that withstands Companies Registry inspection.

The firms that manage this best are those that invest in purpose-built compliance infrastructure and seek expert guidance that is specific to Hong Kong's AMLO framework. Bridge Services combines end-to-end TCSP licensing support with a purpose-built SaaS compliance platform and deep expertise in Hong Kong TCSP regulations, giving trust companies the operational foundation to meet every CFT obligation with confidence.

Bridge Corporate Services

Bridge Corporate Services Limited is incorporated in Hong Kong as a Limited Company under company number 2604159

Services

  • TCSP Company Setup
  • Compliance Advisory
  • Corporate Governance

Platform

  • Features
  • Request Demo

Contact

  • Unit 2807, 28/F Peninsula Tower, 535 Castle Peak Road, Lai Chi Kok, Hong Kong
  • Whatsapp

© 2026 Bridge Corporate Services Limited. All rights reserved.