us

206.206.118.103

Back
News

HKMA Tightens Remote Onboarding Rules Over Deepfake Fraud Risk

HKMA Tightens Remote Onboarding Rules Over Deepfake Fraud Risk
Shufti Shufti SEPTEMBER 14, 2026 1 minute read

The Hong Kong Monetary Authority (HKMA)  has updated its guidance on remote customer onboarding and told every authorized institution (AI) and stored value facility (SVF) licensee in the territory to review how they verify individual customers online. The circular, issued on 3 September 2026 and signed by Executive Director (Enforcement and AML) Raymond Chan, supersedes the HKMA’s February 2019 guidance on remote onboarding of individual customers and its May 2021 circular on remote onboarding and iAM Smart.

Two earlier circulars remain in force and should be read alongside the new letter. The September 2020 guidance on “Remote onboarding of corporate customers” and the June 2020 “Feedback from thematic reviews of Anti-Money Laundering and Counter-Financing of Terrorism (AML/CFT) control measures for remote onboarding initiatives” both continue to be applicable. In particular, the HKMA points to artificial intelligence-driven automation and sophisticated tactics, including the use of deepfake technology, which have increased the potential for impersonation, online fraud and associated mule-account networks at much greater scale.

The two principles every remote onboarding flow must now satisfy

The circular sets out two core principles, ‘identity identification’ and ‘identity matching’ that remote onboarding solutions must remain effective and compliant with. 

  1. Identity Authentication: The individual customer identity, obtained through the electronic channels by the AIs and SVF  licensees, needs to ensure the reliability of the data, information, or document that is obtained for the purpose of verifying the identity of the customer. 
  2. Identity Matching: AIs and SVF licensees should use appropriate technology to link the customer incontrovertibly to the identity provided.

In practice, the first principle, identity authentication, asks whether the identity evidence is real, and the second, identity matching, asks whether the person presenting it is the one it belongs to. A genuine document that is held by an impostor satisfies authentication but fails at matching, which is why the circular considers them as separate requirements rather than a single check. 

Beyond the two core principles, AIs and SVF licensees are expected to adopt a risk-based approach in the design of their products and services, proportionate to the customer’s assessed ML/TF risk profile. For instance, a tiered approach, where account features, functionality and transaction limits are scaled dynamically and adjusted according to actual usage and ongoing customer behaviour, and says that combining this with remote onboarding solutions and active senior management oversight can significantly strengthen AML/CFT controls. The HKMA has been working with the industry and the Hong Kong Police Force to share the latest tactics and modus operandi, and firms are expected to use that intelligence to ensure their systems and processes mitigate both existing and evolving ML/TF risks on an ongoing basis.

Disclaimer: The information provided here is for general informational purposes only and should not be treated as legal, regulatory, or business advice. Shufti Pro Limited accepts no liability for decisions or actions taken in reliance on this information.

Share you link

See Shufti in Action

ID verification, KYC, KYB, AML screening and Transaction Monitoring in one platform, across 240+ countries and 10,000+ document types.

    “Industry Partnerships That Create Real Value”

    Join Shufti’s partnership network to expand your connections, collaborate with industry leaders, and unlock new opportunities.

    Pitch a piece and get a verified byline in the Media room.

    Partnership Inquiries?
    Email us at [email protected]

    iBeta Level 1 — ISO 30107-3 Compliant iBeta Level 2 — ISO 30107-3 Compliant iBeta Level 3 — ISO 30107-3 Compliant PCI DSS SOC 2 Type 2 GDPR GDPR Fundamentals — Quality Guild ISO 27001:2022 KJM Age Verification CCPA / CPRA Cyber Essentials Cyber Essentials Plus
    Copyright © 2026 Shufti. All rights reserved.