Welcome to the World of AML and CTF!

Hello there! Today, we are diving into a topic that makes auditors feel like financial detectives: Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF). While auditing is often about numbers, this chapter is about ethics, law, and protecting the public. Don't worry if this seems a bit "legalistic" at first—we will break it down into simple, everyday concepts to help you ace your HKICPA QP exams!

Why do we study this? As an auditor, you are a "gatekeeper" of the financial system. Criminals try to use legitimate businesses to hide their "dirty money." Your job is to make sure you (and your firm) don't accidentally help them.


1. What is Money Laundering (ML) and Terrorist Financing (TF)?

Let's start with the basics. Think of Money Laundering like literal laundry: you take something "dirty" (money from crime) and put it through a "wash" (business transactions) so it comes out "clean" (legal-looking cash).

The Three Stages of Money Laundering

Criminals usually follow a three-step process. You can remember this using the mnemonic P-L-I:

1. Placement: This is getting the "dirty money" into the financial system. Example: Depositing small amounts of illegal cash into a bank account.

2. Layering: This is moving the money around to hide its origin. Example: Transferring money between different companies or buying luxury goods and selling them. It’s like creating a complicated maze that’s hard to follow.

3. Integration: The "clean" money finally enters the economy. Example: The criminal buys a house using the money that now looks like legitimate business profit.

Terrorist Financing (TF)

While ML is about where the money came from, TF is about where the money is going. TF uses money (which can be legal or illegal) to fund terrorist acts. Even a very small amount of money can be dangerous here.

Quick Review: ML hides the source of dirty money. TF focuses on the purpose of the money.


In Hong Kong, auditors must follow specific laws. You don't need to be a lawyer, but you must know these three main ordinances:

1. DTROP (Drug Trafficking (Recovery of Proceeds) Ordinance)

2. OSCO (Organized and Serious Crimes Ordinance)

3. UNATMO (United Nations (Anti-Terrorism Measures) Ordinance)

Important Point: Under these laws, it is a criminal offense if you fail to report suspicious activity. If you know or "suspect" something is wrong and stay silent, you could face jail time or heavy fines!


3. Professional Guidelines: The HKICPA Approach

As a student of the HKICPA, you need to follow the Guidelines on AML and CTF for Professional Accountants. The core philosophy here is the Risk-Based Approach (RBA).

The Risk-Based Approach (RBA)

Instead of doing the same check for everyone, you focus your energy where the risk is highest. Think of it like airport security: everyone gets scanned, but someone traveling from a high-risk area with no luggage might get extra questioning.

Factors to consider:

- Country Risk: Is the client from a country known for corruption?

- Client Risk: Is the client a "Politically Exposed Person" (PEP)?

- Service Risk: Are you providing a service that is easily abused (like setting up offshore shell companies)?


4. Customer Due Diligence (CDD)

CDD is just a fancy way of saying "Get to know your client." You must verify who they are before you start working for them.

Types of CDD:

1. Standard CDD: Identifying the client and the "Beneficial Owner" (the person who actually owns/controls the company). You need to see documents like passports or business registrations.

2. Simplified CDD: Used for low-risk clients (e.g., a company listed on the HK Stock Exchange). Since they are already heavily regulated, you don't need to do as much digging.

3. Enhanced CDD (ECDD): Used for high-risk situations. This requires extra steps, like finding out where their total wealth came from (Source of Wealth).

Common Mistake to Avoid: Students often think you only check the person who signs the contract. Wrong! You must also identify the Beneficial Owner—the person "behind the curtain" who owns more than 25% of the shares or controls the company.


5. Reporting Suspicious Transactions

If you see something "fishy," you must act. This is the STR (Suspicious Transaction Report) process.

The Reporting Steps:

1. Identify Red Flags: Look for unusual patterns. Example: A client suddenly wants to pay you in cash or asks you to transfer money to a country they have no business in.

2. Report Internally: Most firms have a Money Laundering Reporting Officer (MLRO). You report your suspicions to them.

3. External Reporting: The MLRO decides if they should report it to the JFIU (Joint Financial Intelligence Unit) in Hong Kong.

The "Golden Rule": No Tipping Off!

This is the most important rule in this chapter. Once you have made a report (or if you are about to), you must NOT tell the client. If you tell the client "Hey, I'm reporting you for money laundering," that is called Tipping Off, and it is a criminal offense. It ruins the police investigation.

Analogy: Imagine you are a secret agent. If you tell the villain you are spying on them, you've blown your cover and the mission!


6. Record Keeping

Auditors love documentation! You must keep all AML-related records (identity documents, transaction records, etc.) for at least five years after the relationship with the client ends.

Key Takeaway: If it's not documented, it didn't happen. Always keep proof that you performed your CDD checks.


Summary and Quick Tips for the Exam

- ML Stages: Placement (In), Layering (Through), Integration (Out).

- CDD: Know the client and the Beneficial Owner.

- RBA: Spend more time on high-risk clients (like PEPs).

- Reporting: Report to the MLRO; never tip off the client.

- Retention: Keep records for 5 years.

Don't worry if you find the names of the Ordinances (OSCO, DTROP) hard to remember at first. Just focus on the principles: identify the risk, verify the identity, and report the suspicion without "tipping off" the client!