Hong Kong, Mainland China, Japan and North Asia
A global bank can write one financial-crime policy, but it cannot lawfully operate North Asia as if one policy were the law everywhere. Hong Kong, Mainland China, Japan and the Republic of Korea share many familiar AML/CFT building blocks: customer due diligence, beneficial-owner understanding, ongoing monitoring, suspicious-transaction reporting, sanctions controls, record keeping, governance and risk-based supervision. The legal source, competent authority, reporting route, data-sharing boundary and operational consequence can nevertheless differ materially from market to market.
The most useful mental model is therefore one group control framework sitting above several local legal planes. The group framework can define minimum standards for customer risk assessment, monitoring quality, case documentation, screening governance, model validation, training and assurance. Local legal addenda then determine who is legally obliged, what event creates a filing or restriction duty, which authority receives information, what confidentiality constraints apply, which sanctions measures have legal force, what records must be preserved and whether information may be transferred to another group entity.
This distinction matters because the same payment can touch more than one legal entity and more than one jurisdiction. A Hong Kong booking entity may serve a Mainland-related corporate group, receive a payment destined for Japan, use a regional monitoring service located elsewhere and generate a group-level alert visible to investigators in another country. The bank needs a joined operating model, but it must not collapse the legal questions into a single global answer.
The global standard is the starting point, not the final rulebook
The FATF Recommendations provide the common international architecture. As amended in June 2026, they continue to require countries to implement proportionate, risk-based measures for money laundering, terrorist financing and proliferation-financing risks, while recognising that countries have different legal, administrative and operational systems. That is exactly why a multinational bank should use FATF as the common language and local law as the legal implementation layer.
For an analyst or architect, this means a requirement such as “perform customer due diligence” is too vague to build. The requirement has to be decomposed. Which legal entity is onboarding the customer? Which local rule determines the identification and verification duties? What constitutes the beneficial owner for that customer type? Which information is mandatory before account activation and which can be completed under permitted delayed-verification conditions, if any? What triggers enhanced measures? What must be retained? Which data can be reused by another entity? The answers can vary even where the global control objective is identical.
A similar distinction applies to suspicious-transaction reporting. A group case-management platform can support investigation, but the legal decision to file is made under the applicable local framework and through the local reporting route. A single group case may therefore create separate local assessments rather than one universal “SAR submitted” status. The data model should record the jurisdiction, reporting entity, decision owner, decision time, filing channel, local reference and confidentiality restrictions separately.
Four operating environments, not one regional law
This chapter focuses on four concrete markets: Hong Kong, Mainland China, Japan and the Republic of Korea. “North Asia” should not be used as a shortcut that silently extends these rules to Macao, Taiwan or other markets. Those markets need their own legal inventory. The comparison below is an operating guide, not a substitute for local counsel.
| Market | Core AML/CFT operating anchors | FIU / reporting interface | Sanctions / restriction lens | Practical bank implication |
|---|---|---|---|---|
| Hong Kong | Anti-Money Laundering and Counter-Terrorist Financing framework and HKMA AML/CFT Guideline for authorised institutions | Joint Financial Intelligence Unit; STREAMS 2 is the current electronic STR platform from 2 February 2026 | Hong Kong gives effect to UN Security Council sanctions through local legislation including the United Nations Sanctions Ordinance | Separate statutory/local obligations from any broader US, EU or group-policy sanctions overlay |
| Mainland China | Revised Anti-Money Laundering Law effective 1 January 2025; PBOC and sector-regulator measures, including revised CDD and record-keeping rules effective 1 January 2026 | Local reporting obligations under the AML framework and PBOC-related rules | Applicable PRC legal measures and approved institutional policy must be mapped explicitly | Treat current PBOC measures and effective dates as versioned obligations; do not reuse obsolete thresholds or reporting logic |
| Japan | Act on Prevention of Transfer of Criminal Proceeds framework plus FSA AML/CFT/CPF Guidelines, revised March 2026 | Suspicious reporting under the APTCP framework, with JAFIC as Japan’s FIU | Foreign Exchange and Foreign Trade Act measures, including asset-freezing and other economic-sanctions controls | Keep AML suspicion and FEFTA sanctions decisioning connected operationally but legally distinct |
| Republic of Korea | Financial Transaction Reports Act and related AML/CFT legislation | Korea Financial Intelligence Unit receives STRs and other prescribed reports | Domestic CFT/proliferation-financing and sanctions-related requirements must be mapped through the applicable legal inventory | Build local CDD, STR and reporting requirements as explicit Korean obligations rather than a generic regional setting |
The table is deliberately high level. It shows why a bank needs a local obligation register behind the user interface. The case handler should not have to interpret the entire law while investigating a payment, but the system and procedure should be traceable to the approved legal requirement that justifies the action.
Hong Kong: risk-based banking with a distinct local reporting and sanctions framework
For Hong Kong authorised institutions, the HKMA AML/CFT Guideline is a central supervisory reference. It expects institutions to identify and assess money-laundering and terrorist-financing risk, apply risk-based customer due diligence, understand beneficial ownership, conduct ongoing monitoring and maintain controls proportionate to the institution’s risk profile. A bank should translate these expectations into onboarding, periodic review, event-driven review, transaction monitoring, escalation, training and assurance rather than treating the guideline as a compliance document read only by second line.
Hong Kong suspicious-transaction reporting is operationally important because the filing channel changed. The Hong Kong Police announced the launch of STREAMS 2 on 2 February 2026, replacing the previous platform with an updated cloud-based system for suspicious-transaction reporting and management. That change matters to delivery teams: user access, MLRO profiles, submission workflows, acknowledgement handling, contingency procedures and evidence retention all need to reflect the current platform. A procedure that still tells an analyst to use the old interface is not merely untidy documentation; it can create a real control failure.
Sanctions require equally careful wording. Hong Kong implements United Nations Security Council sanctions through local legislation, including the United Nations Sanctions Ordinance. The HKMA points institutions to the relevant Hong Kong government sources rather than maintaining a separate authoritative sanctions list of its own. A multinational bank may choose or be required by its group structure to screen against additional regimes, such as US or EU measures, but it should label those correctly. A US group policy restriction is not automatically “Hong Kong law” simply because a Hong Kong branch applies it.
That distinction becomes practical when a customer asks why a transaction was stopped. The operational reason may be “group policy pending sanctions review,” while the legal consequence may later become “blocked under an applicable local prohibition,” “rejected under another jurisdiction’s rule,” or “released after false-positive resolution.” Conflating the labels makes customer communication, regulatory reporting and audit reconstruction harder.
Mainland China: current law, current measures and controlled information movement
Mainland China changed materially with the revised Anti-Money Laundering Law, adopted in November 2024 and effective from 1 January 2025. Banks should therefore be cautious about relying on training material, thresholds or procedures written under the previous legal version. Regulatory-change management is not a one-off policy exercise; it requires mapping the revised obligations into customer due diligence, monitoring, reporting, record keeping, governance and system controls.
The PBOC, together with other financial regulators, issued revised customer due-diligence, identity-material and transaction-record measures that take effect from 1 January 2026. For a bank, the important lesson is not to memorise a headline date. It is to version the obligations so that the system knows which requirements apply to which legal entity, customer type and process from which effective date. If a customer was onboarded in 2024 and reviewed in 2026, the bank may need to evidence both the historical basis and the current remediation or refresh requirements.
The PBOC also revised rules concerning large-value and suspicious transaction reporting, with changes effective from 1 December 2025. This is an area where stale global training can be particularly dangerous. A generic statement such as “every transfer above X must be reported” can become inaccurate when the local reporting framework changes. Requirements should point to the current rule, preserve the effective date and distinguish objective reporting duties, where applicable, from suspicion-based reporting and internal monitoring thresholds.
Data handling is another area where simplistic claims should be avoided. It is inaccurate to say that all financial-crime data must remain inside Mainland China or, at the other extreme, that a global AML purpose automatically permits unrestricted sharing. Chinese cybersecurity, data-security, personal-information and sector-specific requirements may affect cross-border transfer. The PBOC has also issued guidance addressing cross-border financial-sector data flows. The correct bank response is a data-transfer decision process: define the business and legal need, classify the data, minimise the fields, identify the lawful transfer mechanism, obtain required approvals or assessments, transmit securely, log the event and preserve evidence.
For investigators, this means a global case should not automatically pull every local document into a central data lake. A better architecture can support federated queries, masked or minimised data, local evidence stores, controlled extracts and permissioned escalation. The design objective is to give the decision maker enough information without turning “group financial-crime risk management” into a blanket exemption from local data rules.
Japan: connect APTCP, FSA expectations, JAFIC and FEFTA without mixing them
Japan’s operating model requires several connected but distinct control lines. The Act on Prevention of Transfer of Criminal Proceeds provides a core legal basis for customer verification, record keeping and suspicious-transaction reporting by specified business operators. JAFIC, within the National Police Agency, performs the FIU function. For financial institutions, the Financial Services Agency’s AML/CFT/CPF Guidelines provide important supervisory expectations, and the FSA revised those guidelines on 31 March 2026.
The revision date matters because it should trigger policy and control impact assessment. A mature bank does not wait for an examiner to ask whether the March 2026 guidance was considered. It records the publication, identifies affected requirements, maps impacted procedures and systems, decides whether changes are needed, tests them and closes the change with evidence.
Japan also illustrates why sanctions cannot be represented as one generic screening result. Economic-sanctions measures are implemented through the Foreign Exchange and Foreign Trade Act and related government actions. The AML suspicion decision under the APTCP framework and a FEFTA sanctions decision can arise from the same customer or transaction, but they are not the same legal test. A payment can be stopped because a sanctions restriction applies even when there is no separate money-laundering suspicion; conversely, suspicious activity may require escalation even when no sanctions match exists.
A case system should therefore use separate decision objects. One object captures identity resolution: is the screened party actually the listed or restricted party? A second captures legal applicability: which rule applies to the entity and transaction? A third captures the operational action: hold, reject, freeze, seek permission, release or escalate. The AML case can then record whether the facts create suspicion under the applicable framework. This separation reduces the common error of turning every sanctions alert into an AML case or every AML concern into a sanctions block.
Republic of Korea: KoFIU, CDD and suspicion-based reporting
The Republic of Korea provides a useful concrete regional comparator. The Korea Financial Intelligence Unit sits within the Financial Services Commission and acts as the institutional link between reporting entities and law-enforcement agencies. The Financial Transaction Reports Act provides the legal basis for core AML measures, including suspicious-transaction reporting, while related legislation addresses criminal proceeds and terrorist/proliferation financing.
KoFIU’s public guidance explains that financial institutions conduct customer due diligence and report suspicious transactions when there are reasonable grounds for suspicion. Korea also operates a currency-transaction reporting regime for cash transactions meeting the prescribed threshold. For a multinational bank, the important systems point is that STR and CTR are different report types with different logic. An objective cash-reporting requirement should not be implemented as if it were a suspicion score, and a suspicious transaction should not be suppressed merely because an objective reporting threshold was not reached.
Customer and beneficial-owner information should be stored in a way that supports local verification and ongoing monitoring while remaining usable for group risk management within lawful boundaries. The group can standardise data concepts such as legal name, identifier, beneficial owner, control relationship, occupation, industry, expected activity and risk rating. It should not assume that the evidence accepted, refresh cycle, reporting form or legal threshold is identical across all entities.
A practical control model: four layers
The safest architecture is a four-layer control model.
Layer 1 is the group minimum. It defines non-negotiable principles: risk-based customer understanding, no anonymous or fictitious relationships where prohibited, beneficial-owner analysis, sanctions screening, transaction monitoring, escalation, trained investigators, record integrity, quality assurance, auditability and senior accountability. This layer provides consistency and prevents local entities from falling below the bank’s approved baseline.
Layer 2 is the local legal overlay. It captures the rule that actually applies to the legal entity. It should include the source, article or regulatory reference where practical, effective date, customer or product scope, trigger, required action, reporting recipient, deadline, record-retention requirement, confidentiality rule and data-transfer constraint. This layer prevents the group minimum from becoming an accidental substitute for law.
Layer 3 is the product and channel overlay. A corporate trade-finance relationship, retail mobile account, correspondent relationship, securities service and virtual-asset exposure do not generate the same data or risk. The bank should adapt controls to the product without rewriting the legal rule. For example, trade finance may provide goods, vessel and shipping data that a simple credit transfer does not contain; an instant-payment rail may require decisions in seconds; a correspondent bank may have incomplete visibility of the underlying customer.
Layer 4 is the case-specific decision. This is where facts become an action. The investigator needs the applicable rule set, customer context, transaction evidence, screening or monitoring signal, relevant group intelligence and documented uncertainty. The decision should record not only “closed” or “escalated” but the reason, evidence, legal or policy basis and owner.
Customer due diligence across the region
The common purpose of CDD is to understand who the customer is, who ultimately owns or controls the relationship, why the service is needed and what activity is reasonably expected. The regional challenge is converting that common purpose into local evidence and local decisioning.
For individuals, identity data may include legal name, date of birth, nationality or residence, government-issued identifier and address information, depending on the jurisdiction and risk. For companies, the bank normally needs legal existence, registered details, directors or authorised persons, ownership and control, business activity and purpose. Higher-risk relationships may require stronger understanding of source of funds, source of wealth, counterparties, countries and expected transaction patterns.
A regional customer master should retain the original-script name where available, the verified local identifier, romanised or transliterated forms used by payment and screening systems, and the source of each value. East Asian names create practical matching challenges because the same person or entity may appear in Chinese characters, Japanese kanji or kana, Korean Hangul, romanised forms, abbreviations or legacy English names. The answer is not to lower the match threshold until noise disappears. It is to preserve multiple verified representations and use secondary identifiers such as date of birth, registration number, address and ownership context to resolve matches.
Beneficial ownership also needs a relationship model rather than a flat text field. Store the customer entity, owner or controller, ownership percentage where relevant, control basis, effective dates, evidence source and verification status. If the ownership changes, keep historical relationships. An investigation into a payment made six months ago may depend on who controlled the customer then, not who controls it today.
Event-driven review is especially important in cross-border groups. A sanctions designation, adverse regulatory event, ownership change, new high-risk geography, unexplained business-model change or material transaction pattern can make the original customer profile obsolete. The system should create a review trigger with a clear reason rather than silently changing the risk score and leaving no explanation.
Monitoring and screening: central capability, local decision
Large banks often centralise technology because duplicate platforms are expensive and inconsistent. Central technology can be sensible, but centralisation does not eliminate local accountability. The monitoring engine can process common data, the screening service can use shared lists and matching algorithms, and a regional operations centre can support investigation. The legal entity still needs confidence that the control covers its local obligations and that authorised decision makers can act within local deadlines.
Transaction monitoring should combine customer profile and transaction behaviour. Useful signals include unusual velocity, unexpected corridors, rapid movement of incoming funds, unexplained third parties, activity inconsistent with the business model, cash behaviour, trade anomalies, correspondent opacity and other typologies appropriate to the product. The same scenario may require different segmentation or thresholds across markets because the customer population, payment habits, cash usage and available data differ.
Screening should distinguish customer screening, payment screening and other forms of list or restriction control. Name matching alone is not a legal conclusion. The workflow needs match resolution, ownership or control analysis where required, jurisdictional applicability and a separate operational disposition. A Hong Kong entity applying a broader group sanctions policy should record whether the action is required by Hong Kong law, another applicable jurisdiction’s law, correspondent requirements or internal risk appetite.
Alert routing must preserve the legal entity. If one regional monitoring system creates an alert from transactions in Hong Kong and Japan, the case should know which booking entities and accounts contributed to the signal. That enables separate local reporting assessments where necessary and prevents one team from assuming that another entity’s filing discharged its own obligation.
From alert to local reporting decision
A robust investigation starts with the trigger but does not end there. The investigator should reconstruct the customer’s expected activity, relevant counterparties, payment timeline, account behaviour, ownership, geography, products and previous alerts. They should distinguish facts from hypotheses and document what evidence supports or weakens each explanation.
If suspicion remains, the reporting decision must follow the applicable local process. In Hong Kong, the institution’s workflow should route the matter to the appropriate reporting function and current JFIU submission process, including STREAMS 2 where applicable. In Mainland China, the bank should follow the current local suspicious-transaction reporting framework and approved reporting procedure. In Japan, the applicable APTCP process and institutional reporting route should be followed, with JAFIC performing the FIU role. In Korea, the reporting officer assesses reasonable grounds and, where the statutory test is met, reports to KoFIU.
The system should preserve confidentiality. A suspicious-transaction report is not ordinary customer-service information and should not be exposed to staff who do not need it. Customer communications should describe operational requirements without revealing protected reporting activity. Access logs, role-based permissions and export controls around case data are part of the financial-crime control, not merely cyber-security features.
Cross-border information sharing: purpose is not permission
Financial groups have a legitimate need to understand risks across entities. A mule network may use accounts in several markets; a sanctions-evasion structure may place related companies in different jurisdictions; a correspondent relationship may be managed globally. FATF standards recognise the value of group-wide programmes and information sharing, but the transfer still has to respect applicable privacy, secrecy and data rules.
The key design principle is purpose does not itself create legal permission. “We need the information for AML” is the beginning of the analysis, not the end. The bank should identify the requested data, purpose, receiving entity, location, sensitivity, legal basis, transfer mechanism, retention period and onward-sharing restriction. Where full transfer is not permitted or not necessary, the bank can consider minimisation, masking, pseudonymisation, local analysis with risk indicators shared centrally, federated search or controlled legal-escalation procedures.
Data lineage matters because the same attribute may be transformed several times. A Chinese legal name might be captured in local script, romanised by a channel, normalised by a screening engine, matched to a list entry and displayed to a case investigator. If the investigator sees only the normalised string, they may misinterpret the source. Good lineage preserves the original value, transformation, source system, time and confidence.
A regional data boundary also needs failure handling. What happens when the central system requests a document that cannot be exported? What happens when a remote investigator lacks permission to see a local government identifier? What happens if the group tool is unavailable but a local filing deadline continues to run? These are not edge cases. They should be explicit requirements with local fallback processes.
Governance: who owns what
First-line business teams own the customer relationship and the quality of information obtained during onboarding and servicing. Financial-crime operations perform screening, monitoring review and case work according to delegated responsibilities. Compliance sets or interprets policy, challenges control effectiveness, owns or oversees regulatory change and supports local reporting governance. Legal advises on statutory interpretation, sanctions applicability, secrecy and cross-border data issues where needed. Technology maintains the platforms, data flows, rules and access controls. Independent assurance tests whether the design and operation are effective.
Local MLRO or equivalent reporting roles cannot be replaced by a regional dashboard. Regional governance can compare alert volumes, backlogs, false-positive trends, filing outcomes, data defects and model performance, but it should preserve local decision rights. A useful committee pack shows where group standard and local implementation diverge, why the divergence exists, whether it is legally required or risk-approved, and when it will be reviewed.
Regulatory change needs a named owner. For each material update, record the source, publication date, effective date, impacted legal entities, affected controls, implementation actions, testing evidence and closure approval. The 2025–2026 changes in Mainland China and Japan demonstrate why this matters. A control that was correct in 2024 can become inaccurate even if the code has not changed.
Failure modes that look small but create large risk
One common failure is copying a rule from one market into another. A global procedure may use a familiar threshold, filing terminology or sanctions concept from the US or EU and present it as universal. The fix is obligation-level jurisdiction tagging and local approval.
Another failure is stale regulatory logic. The policy might cite the revised law, while the monitoring or reporting engine still contains old thresholds, old forms or old decision text. Change closure should therefore include technology and operational verification, not only document approval.
A third failure is central case closure without local assessment. Regional investigators may conclude that activity is explainable and close the case, but a local legal entity may have a different reporting test or additional evidence. The system needs local sign-off rules where required.
A fourth failure is over-sharing. Investigators often believe more data is always better. Unnecessary export of identity documents, government identifiers or sensitive case narratives can create privacy and secrecy risk without improving the decision. Data minimisation should be part of case design.
A fifth failure is sanctions labels that hide the legal basis. “Sanctioned” is not enough. The bank should know the regime, list or restriction, matched party, ownership/control analysis, nexus, effective date and required action. That is especially important where group policy is broader than local law.
Mini case: one payment, several legal questions
Consider a composite example. A Hong Kong incorporated trading company banks with a Hong Kong authorised institution. Its beneficial owner is resident in Mainland China. The company sends a large payment to a Japanese industrial supplier for specialised equipment. A Korean logistics intermediary appears in the invoice and payment narrative. The bank’s regional monitoring engine flags the transaction because the amount is substantially above the customer’s historic pattern, the beneficiary is new and a related company appeared in an earlier alert.
The first task is not to decide whether the transaction is criminal. It is to establish facts. The investigator checks the Hong Kong customer profile, expected trade activity, beneficial ownership, invoice, contract, payment message, previous counterparties and any available shipping information. The supplier name creates a weak sanctions fuzzy match, but date, address and registration data show that the beneficiary is not the listed entity. That screening alert can be closed with documented identity resolution.
The AML question remains. The customer previously described itself as a distributor of consumer electronics, while the invoice now refers to specialised industrial machinery. The explanation may be legitimate expansion, but it is a material profile mismatch. Relationship management obtains updated business information and contracts. The investigator checks whether the commercial purpose, pricing and counterparties are coherent and whether the customer’s expected activity should be refreshed.
The group intelligence team finds that another group entity has seen the Korean intermediary in unrelated higher-risk cases. That is useful intelligence, but it does not automatically prove suspicion and it does not automatically authorise unrestricted transfer of all underlying case documents. The bank uses its approved information-sharing process to provide the Hong Kong decision maker with the permitted risk indicators and, where necessary, seeks additional information through controlled channels.
If the Hong Kong entity determines that the facts create suspicion under its applicable framework, the filing decision follows the Hong Kong reporting process. That filing does not automatically satisfy any separate duty another legal entity might have if it also handled relevant activity. If the Japanese supplier’s bank independently identifies suspicious activity, its decision sits within Japan’s local framework. The group can coordinate facts and risk understanding while preserving each entity’s legal responsibility.
For a business analyst, this case generates concrete requirements: preserve original names and identifiers; link customer, beneficial owner, invoices, payments and counterparties; distinguish sanctions match resolution from AML suspicion; record local reporting entity and decision owner; restrict report visibility; support permitted group-intelligence sharing; capture event-driven KYC refresh; retain audit history; and prove which rule version was active when the decision was made.
What good looks like for delivery teams
A business analyst should be able to trace every local control to a source and every system field to a decision need. An architect should be able to show where data originates, where it is transformed, which entity owns it and where cross-border transfer occurs. A developer should know which rules are configurable by jurisdiction and effective date rather than hard-coded. A tester should be able to build scenarios that prove the local overlay changes the outcome correctly. Operations should have clear escalation paths when information is missing or conflicting. Compliance should be able to demonstrate that regulatory change reaches procedure, technology and training. Audit should be able to reconstruct the full decision without relying on staff memory.
The strongest regional model is therefore neither fully centralised nor fully duplicated. It centralises reusable capability where sensible—technology, data standards, list management, model governance, quality frameworks and common training—while keeping local legal interpretation, statutory decisioning and restricted data handling where required. The design goal is consistent control quality with jurisdiction-correct outcomes.
That is the core lesson of Hong Kong, Mainland China, Japan and North Asia: global consistency is valuable, but legal precision is non-negotiable. A bank succeeds when it can explain both at the same time.
Operational deep dive: data, investigations and local reporting
The regional operating model becomes difficult when common policy meets different languages, reporting routes, data rules and legal-entity responsibilities. The design goal is to let the bank connect risk across the region without losing the local basis for a decision.
Build the data model around decisions
A regional platform should start with the decisions the bank must defend: who is the customer, who owns or controls it, what activity is expected, whether a sanctions or other restriction applies, whether an alert can be closed, whether suspicion remains, which entity has a reporting duty and what information may be shared across the group.
Those decisions need linked customer, ownership, product, transaction, screening, monitoring, case and regulatory data. Each important value should retain provenance. A name copied from a payment message is not equivalent to a verified KYC name; a relationship-manager statement is not equivalent to an official registration record. The case should make that distinction visible.
Time is equally important. Ownership changes, customer profiles evolve, lists are updated and monitoring logic is recalibrated. Effective dates and history allow an auditor to reconstruct what the bank knew and which rule version applied when the transaction occurred.
Original script and entity resolution
North Asian names may appear in Chinese characters, Japanese kanji or kana, Korean Hangul, English names, abbreviations and several romanisation conventions. The customer record should preserve verified original-script names and alternate forms rather than forcing one Latin string to become the source of truth.
Screening can normalise strings for matching, but investigators need secondary identifiers such as date of birth, registration number, address, nationality or incorporation country to resolve candidates. The matching model should be tested with realistic regional patterns including reordered names, short names, punctuation, character conversion and transliteration differences.
CDD should create a behavioural baseline
CDD is most useful when it explains what the customer is expected to do. For a corporate customer, “general trading” may be too vague. A proportionate baseline can describe products, counterparties or counterparty types, currencies, corridors, expected volumes and the commercial reason for the relationship.
Beneficial ownership should be stored as relationships with effective dates, not a free-text note. If a Hong Kong company is owned by a Mainland parent and ultimately controlled by individuals elsewhere, the bank should retain the chain and evidence. A later investigation may depend on who controlled the customer at the time of the payment.
Material changes should create an event-driven review trigger with a reason: ownership change, new geography, new business line, unusual turnover, sanctions event or another significant risk signal. Silent changes to the risk score weaken auditability.
Payment data should tell a joined story
Evidence differs by product. An ISO 20022 payment may carry structured debtor, creditor, agent, address and remittance information; a domestic rail may provide local identifiers; trade finance can add invoices and shipping documents. The case platform should show what was actually available rather than imply that every transaction contains the same data.
Where identifiers exist, retain them end to end. Payment references, message identifiers, account references and timestamps help connect initiation, screening, settlement, return and investigation. A useful case timeline combines customer events and transaction events so that profile changes, new beneficiaries and previous alerts can be understood together.
Monitoring must be locally meaningful
A global typology can be valid while thresholds need local calibration. Customer mix, cash usage, domestic payment behaviour and available data differ across markets. Calibration should therefore use local populations and documented risk hypotheses rather than simply reducing alerts to fit operational capacity.
For advanced analytics, model governance should record training population, features, validation, limitations and drift. A model developed mainly on one market should not be assumed effective in another without evidence. Investigators also need explainability: why did the transaction look unusual, and which facts drove the alert?
Separate identity, legal applicability and action
Sanctions workflows are stronger when they answer three questions separately. First, is the screened subject actually the listed party? Second, if identity is confirmed, which restriction applies to the legal entity and transaction? Third, what action is required: hold, reject, freeze, seek permission, escalate or release?
This separation matters because Hong Kong implements UN Security Council sanctions through local law, Japan uses FEFTA for economic-sanctions measures, and a multinational group may screen against additional regimes. One matching engine can support all of them, but the legal consequence must remain explicit.
Local reporting is an entity-specific outcome
A regional case may support several local assessments. The filing object should therefore record the reporting entity, jurisdiction, decision owner, report type, decision and submission dates, local reference and access classification.
Hong Kong procedures should reflect the current JFIU environment including STREAMS 2. Mainland China procedures should use current local reporting rules and effective dates. Japan should preserve the APTCP reporting path with JAFIC’s FIU role while keeping FEFTA sanctions decisions distinct. Korea should keep suspicion-based STR logic separate from objective CTR logic.
Confidential reporting data needs stronger access controls than ordinary case notes. Role-based permissions, export controls and access logs are part of the financial-crime design because they help prevent inappropriate disclosure and preserve statutory confidentiality.
Group intelligence should be useful but controlled
A financial group needs to connect networks across entities, but “AML purpose” is not by itself permission to transfer every document. An information-sharing request should identify the purpose, requester, receiving entity, data categories and approved transfer route. Where full transfer is not necessary or permitted, the bank can share a risk indicator, masked fields, a controlled extract or use a federated query.
This is particularly important for Mainland-related data. The correct design is not “everything local” or “everything central.” It is a policy-controlled decision that reflects the data, entity, destination, purpose and current legal guidance.
Resilience and audit evidence
Central services create regional dependencies. Screening, list feeds, case management, analytics and FIU interfaces need fallback plans. Tests should simulate service outages, prove that queues are captured, confirm that no transactions or alerts are silently lost, and reconcile processing after recovery.
For any case, an auditor should be able to reconstruct the source data, rule or list version, investigation steps, decision, approver and local reporting or restriction outcome. For regulatory change, the evidence chain should link the authoritative publication to impact assessment, implementation, testing and closure.
A practical regional architecture therefore has three zones: a local evidence zone for authoritative and restricted records, a regional control layer for reusable screening, monitoring and workflow, and a group intelligence layer for approved risk signals and network connections. That pattern combines efficiency with jurisdiction-correct accountability.
Advanced practice: requirements, configuration and regulatory change
A regional programme becomes durable when legal expectations are translated into buildable, testable and version-controlled obligations. Publishing a policy addendum is not enough; the change must reach workflows, rules, data, procedures, training and assurance.
Create an obligation record
For each material rule, capture jurisdiction, legal entity, source, effective date, scope, trigger, required action, decision owner, reporting recipient, confidentiality condition and relevant data-sharing constraint. Also classify whether the item is law, supervisory guidance, group minimum or internal risk appetite. That prevents teams from presenting an internal restriction as if it were local statute.
Obligations should move through lifecycle states such as proposed, approved, effective and superseded. Historical versions should remain available so a past case can be reconstructed after a law or procedure changes.
Configure by legal entity and effective date
“Country” is too weak as the only control key. A bank may have multiple entities or licences in the same market. Configuration should therefore support legal entity, jurisdiction, product or channel, customer type, rule or list regime and effective date.
Generic workflow states are safer than hard-coded jurisdictional terminology. A technical state such as localReportingAssessmentRequired can route to the correct Hong Kong, Mainland, Japanese or Korean procedure based on the entity configuration. The user-facing decision remains local and precise.
Separate sanctions data, matching and legal rules
Sanctions architecture should keep three layers distinct. The list-data layer contains designated subjects and source information. The matching layer identifies possible identity matches. The legal-rules layer determines whether a confirmed match creates a restriction for the relevant entity and transaction.
This makes group screening practical without hiding the legal basis. Hong Kong, Japan and additional group regimes can use a common matching service while retaining different legal outcomes. It also allows list updates, algorithm tuning and legal-rule changes to be governed independently.
Monitoring: shared typology, local calibration
A monitoring typology can be common while segmentation and calibration differ. Rapid pass-through activity, unexplained trade payments or mule behaviour may be relevant across markets, but thresholds and expected patterns should reflect local customers, products and data.
A calibration change needs a documented risk rationale and post-implementation review. Reducing alerts solely because the team lacks capacity is not sound calibration. Management should distinguish model noise, poor data, weak segmentation and genuine staffing constraints.
Cross-border data controls as a reusable service
A large bank can centralise cross-border policy decisions in a reusable service rather than embedding rules separately in every application. The service can evaluate source jurisdiction, data category, destination, purpose and approved sharing route, then return allow, deny or escalate.
Field-level treatment is useful. A regional analyst may be allowed to see a risk indicator and masked company identifier while a full identity document remains local. The transfer log should record requester, purpose, policy version, fields released and recipient.
Regulatory change from publication to production
A strong change process follows a traceable chain: detect the official publication; interpret it for the local entity; map affected obligations and controls; design remediation; build and test; deploy against the effective date; then perform post-implementation assurance.
Emergency sanctions changes need a faster controlled path because waiting for a normal release cycle may be unacceptable. Expedited deployment should still leave approvals, testing evidence and retrospective assurance.
Worked example: a rule change that touches policy, data and operations
Assume the local compliance team identifies a new or revised customer-due-diligence requirement with an effective date three months away. The first mistake would be to open a single ticket called “update KYC policy.” The real change surface is wider.
The legal interpretation should first identify which regulated entity and customer populations are affected, whether the change applies only to new relationships or also to existing customers, which information or evidence becomes mandatory, and whether transitional arrangements exist. Those conclusions belong in the obligation record with the authoritative source and effective date. Any uncertainty should be captured as an open legal question rather than converted prematurely into system logic.
The BA then maps the obligation to the current journey. If a new ownership attribute is required, the bank may need changes to onboarding forms, API contracts, customer-master fields, validation rules, document capture, relationship-manager procedures and downstream screening or monitoring. If the attribute is already collected but not verified, the requirement is different: the bank needs a verification rule, evidence type, exception path and audit trail rather than another input field.
Existing customers create a remediation question. The bank must decide which population requires refresh, how it will be prioritised, what deadline applies, what happens when customers do not respond and whether any product restrictions are permitted or required. A batch campaign may generate millions of tasks, so capacity, customer communication and exception management become part of the control design. The programme should distinguish legal deadlines from internal target dates so that operational pressure does not rewrite the obligation.
Technology should implement the change with an effective-date switch rather than overwriting the old rule before it becomes legally applicable. Pre-production testing can use future-dated configuration to prove the new journey. Historical cases should continue to show the rule that applied when the original decision was made. If the same customer is reviewed after the effective date, the new review should record the new rule version without rewriting the old evidence.
Testing needs positive, negative and boundary cases. A customer in scope should be prevented from completing onboarding if a mandatory item is absent, unless an approved exception applies. A customer outside scope should not be forced through unnecessary fields. A case initiated just before the effective date and completed just after it should follow the bank’s approved transition rule. A downstream screening feed should receive the new verified attribute where designed, and an unavailable dependency should route to a controlled exception rather than silently dropping the field.
Operations need clear procedures for missing or conflicting evidence. If the customer provides ownership information that differs from an external source, staff need a defined investigation and escalation path. If a high-risk relationship cannot be remediated before the deadline, the decision should be owned by the authorised function and recorded with the applicable policy or legal basis. Front-line staff should not invent workarounds to keep the customer journey moving.
Management information should track the remediation population, completion rate, ageing, high-risk exceptions, data defects and unresolved legal questions. A green programme status based only on code deployment is misleading if thousands of existing customers remain unreviewed or the new field is not reaching the screening platform.
Finally, post-implementation assurance should sample complete customer journeys from source evidence through the customer master and downstream controls. It should confirm that the old configuration is no longer used for new in-scope decisions, that historical evidence remains reconstructable, and that training and procedures match production behaviour. This is the point at which the bank can show that a regulatory publication became an operating control rather than merely a policy update.
The same method works for reporting-rule changes, sanctions measures and FIU platform changes. The affected systems differ, but the discipline is constant: source, interpret, map, implement, test, evidence and assure.
BA requirements that are specific enough to build
Useful requirements describe observable behaviour. Examples include:
- When a case contains transactions booked to multiple legal entities, preserve each entity and route separate local reporting assessments where configured.
- Retain original party data, normalised data, list source/version, match evidence, analyst decision and timestamp for screening reconstruction.
- Before restricted evidence is shown outside its approved data zone, evaluate the configured transfer policy and expose only the permitted fields.
- Give every rule, threshold and workflow template an effective-from date and historical version.
Test jurisdictional difference
Testing should prove that the same technical platform can reach different lawful outcomes when entity or jurisdiction changes.
For Hong Kong, test the current JFIU workflow and a case where broader group sanctions policy creates a hold without being mislabelled as Hong Kong statutory law. For Mainland China, test an effective-date change and a regional request for locally held sensitive evidence. For Japan, test a transaction that creates both an AML alert and a FEFTA sanctions candidate and confirm the decisions remain separate. For Korea, test an objective cash-reporting event and a separate suspicion-based case to prove CTR and STR logic are independent.
Across markets, also test multilingual names, ownership history, list rescreening, missing data, central service outages, report amendments and unauthorised access to protected filing information.
Management information and governance
Useful regional MI includes backlog age by risk, missing-data rates, sanctions resolution time, quality defects, late regulatory-change actions, list-update timeliness, failed data feeds, override volumes and unresolved model limitations. Filing rates should not be mechanically compared across jurisdictions because legal tests and customer populations differ.
Regional governance should decide which controls are central, local or jointly owned. Local entities must retain visibility of defects in shared services that affect them. A regional platform can centralise capability; it cannot outsource the legal entity’s accountability.
The practical principle is simple: standardise the capability where the objective is common, and localise the consequence where the law is local.
Practice close: applying the North Asia operating model
A learner should finish this chapter able to inspect a regional control and ask whether the bank has preserved both consistency and legal precision.
Start with the legal entity. Which bank, branch or subsidiary owns the customer, transaction or reporting duty? Then identify the source of the obligation: local law, supervisory guidance, another jurisdiction with a relevant nexus, or group policy. Check the effective date, because a correct 2024 procedure may be stale after a 2025 or 2026 change.
Review the evidence. Can the investigator see verified names, original script, identifiers, ownership history, expected activity, payment references and the source of each important fact? Screening and AML suspicion should remain separate decisions. A false sanctions candidate does not close an AML concern, and an AML concern does not by itself create a sanctions prohibition.
Confirm the local reporting route and decision rights. Hong Kong procedures should reflect the current JFIU environment; Japan, Korea and Mainland China should route to their own approved local processes. A regional operations team should not silently discharge a local legal responsibility simply by closing the shared case.
Check cross-border data movement. If identity documents, case attachments or report-related information cross a boundary, the design should identify the purpose, data category, receiving entity and approved transfer route. Where a risk indicator or masked data is sufficient, the platform should not default to copying the whole file.
Compact BA and testing checklist
| Area | Evidence of a good design |
|---|---|
| Entity and jurisdiction | booking/reporting entity, local decision owner, effective rule version |
| CDD | original and alternate names, identifiers, ownership history, expected activity |
| Screening | list source/version, candidate evidence, identity resolution, legal applicability |
| Monitoring | scenario/model version, local calibration, triggering facts and explainability |
| Reporting | jurisdiction, report type, authorised role, decision/submission evidence |
| Data sharing | purpose, minimisation, policy decision, recipient and audit trail |
| Change | source, effective date, impacted controls, testing and closure |
| Resilience | outage fallback, queue capture, recovery and reconciliation |
A useful test pack should include: a Hong Kong reporting case using the current operating process; a group-policy sanctions hold that is not mislabelled as Hong Kong law; a Mainland effective-date change and controlled data-sharing request; a Japanese case with both AML and FEFTA paths; a Korean STR-versus-CTR comparison; multilingual name matching; historical ownership reconstruction; a central service outage; and an unauthorised attempt to view protected filing data.
The acceptance test is straightforward: the same technical platform must be capable of reaching different lawful outcomes when the legal entity or jurisdiction changes, and the audit trail must explain why. If the only regional configuration is a country flag, the design is probably too shallow.
Masterclass: one regional case, several local decisions
This fictional case combines recurring banking patterns for teaching. It is designed to show how a joined regional investigation can still produce separate legal outcomes.
Pacific Meridian Trading Limited is a Hong Kong company banking with the Hong Kong subsidiary of an international group. It historically imports electronic components from Mainland China and Japan. Six months ago a Mainland holding company acquired 70% of the customer, and a Korean logistics company became a regular intermediary.
A payment of JPY 480 million is initiated to a new Japanese manufacturer for precision industrial machinery. The payment is much larger than the customer’s historic activity and outside the product profile recorded at onboarding. The regional monitoring engine creates an alert for profile deviation, beneficiary novelty and amount. Screening also creates a fuzzy sanctions candidate on the Japanese supplier’s English name.
Resolve identity before debating legal consequence
The sanctions analyst compares the beneficiary’s Japanese legal name, registration number, address and bank details with the candidate record. The listed party has a similar English trading name but different local name, registration information and address. The analyst closes the candidate as a false identity match and records the original payment string, list version, secondary identifiers and reason.
That closure does not close the AML alert. Screening answered an identity question; the unusual customer behaviour still needs investigation.
Rebuild the customer story
The AML investigator reviews the updated ownership, expected activity, payment history and supporting documents. Turnover has increased sharply, two new Mainland counterparties now fund the account, and some incoming credits are followed quickly by payments to Japan and Korea.
The relationship manager obtains contracts, customer orders and board approval showing a genuine expansion into industrial machinery. The Japanese supplier appears commercially credible. One point remains difficult to explain: the Korean logistics company receives an additional consultancy fee even though shipping is already included in the supply contract. The customer initially provides only a short agreement with vague service wording.
Use group intelligence as evidence, not proof
The group intelligence layer shows that the Korean company has appeared in other higher-risk cases. The Hong Kong investigator requests information through the approved sharing process. Another group entity can share a controlled risk indicator but not its protected local reporting details.
That signal increases the need for explanation, but it does not prove criminality. The investigator asks for evidence of services, invoices and work product. The customer provides some additional material, but parts remain inconsistent with the fee level.
Preserve the Hong Kong reporting decision
The Hong Kong entity now considers the complete facts under its local reporting framework. If the authorised decision maker forms suspicion, the matter follows the bank’s current JFIU submission process, including STREAMS 2 where applicable. The case records the Hong Kong reporting entity, decision owner and filing reference under restricted access.
The customer-relationship decision remains separate. The bank may continue with enhanced monitoring, restrict a service, require more evidence or consider exit according to risk appetite and legal guidance. Filing does not mechanically require exit, and continued service does not mean the reporting concern disappeared.
Japan and Korea keep their own responsibilities
The Japanese beneficiary bank sees a different set of facts. If it identifies suspicious activity, its reporting decision follows Japan’s applicable framework. A Japan-specific sanctions concern is analysed under the relevant FEFTA measures rather than inheriting the Hong Kong bank’s legal conclusion.
If a Korean group entity services the Korean intermediary, its CDD and suspicious-reporting responsibilities remain within the Korean framework, including KoFIU reporting where applicable. Regional coordination can improve the evidence; it does not merge the statutory duties.
Data sharing must still be controlled
During the case, a regional analytics team asks for full identity and transaction records from the Mainland parent to enrich a network model. The AML purpose alone does not decide whether every field can be transferred.
The bank’s approved data policy evaluates the source, data categories, destination and purpose. It permits selected ownership attributes and risk indicators, masks some identifiers and keeps other documents in the local evidence zone. The analytics team can still connect the network without receiving an unnecessary copy of the complete customer file.
What the case means for delivery teams
For a BA, the case creates clear requirements: preserve original names and identifiers; retain ownership history; link customers, counterparties and payments; separate sanctions match resolution from AML suspicion; record local reporting entity and decision owner; restrict filing data; support controlled group intelligence; capture event-driven KYC refresh; and retain the rule version used at decision time.
For testers, the scenario should prove that a false sanctions match can close while an AML alert remains open, that protected filing data is invisible to unauthorised regional users, that permitted group indicators retain lineage, and that each local entity can reach its own reporting outcome.
For management, repeat use of the same intermediary should become a network insight, not just more isolated alerts. If matching on Japanese names creates repeated false positives, that is a calibration and data-quality issue. If investigators repeatedly cannot obtain usable ownership information, that is a control-data issue. Mature programmes turn case outcomes into control improvement.
The central lesson is that one regional risk story can be investigated collaboratively without turning it into one universal legal decision.
References and further reading
These sources were used to verify the jurisdictional framework in this chapter. They are deliberately weighted toward official laws, regulators, FIUs and international standard setters. Local legal advice and the bank’s approved jurisdiction-specific policy remain necessary for transaction-level decisions.
Global standard
- Financial Action Task Force (FATF), The FATF Recommendations, as amended June 2026. https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html
- FATF, Risk-Based Approach Guidance for the Banking Sector. https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Guidance-rba-banking-sector.html
- Basel Committee on Banking Supervision, Sound management of risks related to money laundering and financing of terrorism. https://www.bis.org/bcbs/publ/d505.htm
Hong Kong
- Hong Kong Monetary Authority (HKMA), Guideline on Anti-Money Laundering and Counter-Financing of Terrorism (For Authorized Institutions), revised guideline effective 1 June 2023. https://www.hkma.gov.hk/media/eng/doc/key-information/guidelines-and-circular/guideline/Guideline_on_AML-CFT_%28for_AIs%29_eng_May%202023.pdf
- HKMA, Ordinances and Statutory Guidelines. https://www.hkma.gov.hk/eng/key-functions/banking/anti-money-laundering-and-counter-financing-of-terrorism/ordinances-statutory-guidelines/
- Joint Financial Intelligence Unit (Hong Kong Police Force and Customs and Excise Department), Announcement of the launch of STREAMS 2 on 2026-02-02, January 2026 announcement; launch 2 February 2026. https://www.jfiu.gov.hk/en/
- HKMA, Sanctions-related Notices and Updates. https://www.hkma.gov.hk/eng/key-functions/banking/anti-money-laundering-and-counter-financing-of-terrorism/sanctions-related-notices-updates/
- Commerce, Industry and Tourism Branch, Hong Kong, United Nations Security Council Sanctions. https://www.cedb.gov.hk/citb/en/policies/united-nations-security-council-sanctions.html
Mainland China
- National People’s Congress, Revised Anti-Money Laundering Law, adopted 8 November 2024 and effective 1 January 2025. https://www.npc.gov.cn/npc/c2/kgfb/202411/t20241108_440949.html
- National People’s Congress, Anti-Money Laundering Law official text (PDF). https://wb.flk.npc.gov.cn/flfg/PDF/b7f4c63443a044798dad5aff10fc3cf2.pdf
- People’s Bank of China (PBOC), Measures on Customer Due Diligence, Customer Identity Materials and Transaction Records, effective 1 January 2026. https://www.pbc.gov.cn/tiaofasi/144941/144957/5916164/index.html
- PBOC, Revised Anti-Money Laundering Law, official Chinese text, adopted 8 November 2024; effective 1 January 2025. https://www.pbc.gov.cn/tiaofasi/144941/144951/5548765/index.html
- PBOC, Decision Amending and Repealing Certain Rules, Order [2025] No. 10, signed 30 September 2025; reporting and supervisory amendments effective 1 December 2025 (official Chinese text). https://www.pbc.gov.cn/tiaofasi/144941/144957/5863650/index.html
- PBOC, Compliance Guidelines on Promoting and Regulating Cross-border Data Flow in the Financial Sector, official English announcement dated 17 April 2025. https://www.pbc.gov.cn/en/3688110/3688172/5552468/2025092319411582026/index.html
- State Council of the People’s Republic of China, Regulations on facilitating and regulating cross-border data flows, 2024. https://english.www.gov.cn/news/202403/24/content_WS66000bb5c6d0868f4e8e55f3.html
Japan
- Financial Services Agency (Japan), Guidelines for Anti-Money Laundering and Combating the Financing of Terrorism, revised 31 March 2026. https://www.fsa.go.jp/en/news/2026/20260331/01.pdf
- Financial Services Agency, Revision of Guidelines for Anti-Money Laundering and Combating the Financing of Terrorism, 31 March 2026. https://www.fsa.go.jp/en/news/2026/20260331/20260331.html
- Japan Financial Intelligence Center (JAFIC), National Police Agency, About JAFIC (official Japanese page). https://www.npa.go.jp/sosikihanzai/jafic/jafic/about.htm
- Ministry of Finance, Japan, Economic Sanctions and Permission Procedures (official Japanese page). https://www.mof.go.jp/policy/international_policy/gaitame_kawase/gaitame/economic_sanctions/index.htm
Republic of Korea
- Korea Financial Intelligence Unit (KoFIU), AML/CFT Framework. https://www.kofiu.go.kr/eng/regime/framework.do
- KoFIU, Customer Due Diligence. https://www.kofiu.go.kr/eng/policy/amls05.do
- KoFIU, Suspicious Transaction Report. https://www.kofiu.go.kr/eng/policy/amls03.do
- KoFIU, Currency Transaction Report. https://www.kofiu.go.kr/eng/policy/amls04.do
The official sources should be checked again whenever a bank implements a new rule, changes a reporting workflow or makes a transaction-specific legal decision. Sanctions designations, FIU channels and data-transfer rules can change faster than educational material, so the chapter teaches a version-controlled operating model rather than a static list of thresholds.
<!-- source-review: 2026-09-22 -->