The Hong Kong Monetary Authority (HKMA) has updated its guidance on remote customer onboarding and told every authorized institution (AI) and stored value facility (SVF) licensee in the territory to review how they verify individual customers online. The circular, issued on 3 September 2026 and signed by Executive Director (Enforcement and AML) Raymond Chan, supersedes the HKMA’s February 2019 guidance on remote onboarding of individual customers and its May 2021 circular on remote onboarding and iAM Smart.
Two earlier circulars remain in force and should be read alongside the new letter. The September 2020 guidance on “Remote onboarding of corporate customers” and the June 2020 “Feedback from thematic reviews of Anti-Money Laundering and Counter-Financing of Terrorism (AML/CFT) control measures for remote onboarding initiatives” both continue to be applicable. In particular, the HKMA points to artificial intelligence-driven automation and sophisticated tactics, including the use of deepfake technology, which have increased the potential for impersonation, online fraud and associated mule-account networks at much greater scale.
The two principles every remote onboarding flow must now satisfy
The circular sets out two core principles, ‘identity identification’ and ‘identity matching’ that remote onboarding solutions must remain effective and compliant with.
- Identity Authentication: The individual customer identity, obtained through the electronic channels by the AIs and SVF licensees, needs to ensure the reliability of the data, information, or document that is obtained for the purpose of verifying the identity of the customer.
- Identity Matching: AIs and SVF licensees should use appropriate technology to link the customer incontrovertibly to the identity provided.
In practice, the first principle, identity authentication, asks whether the identity evidence is real, and the second, identity matching, asks whether the person presenting it is the one it belongs to. A genuine document that is held by an impostor satisfies authentication but fails at matching, which is why the circular considers them as separate requirements rather than a single check.
Beyond the two core principles, AIs and SVF licensees are expected to adopt a risk-based approach in the design of their products and services, proportionate to the customer’s assessed ML/TF risk profile. For instance, a tiered approach, where account features, functionality and transaction limits are scaled dynamically and adjusted according to actual usage and ongoing customer behaviour, and says that combining this with remote onboarding solutions and active senior management oversight can significantly strengthen AML/CFT controls. The HKMA has been working with the industry and the Hong Kong Police Force to share the latest tactics and modus operandi, and firms are expected to use that intelligence to ensure their systems and processes mitigate both existing and evolving ML/TF risks on an ongoing basis.

















