GlobalHong KongRegulation & Policy

Hong Kong SFC Updates Licensed Firms and Virtual Asset Providers on FATF High-Risk Jurisdictions

The Hong Kong Securities and Futures Commission has reminded licensed corporations, SFC-licensed virtual asset service providers and associated entities to update their AML/CFT controls following the June 2026 FATF Plenary.

The SFC circular covers three areas:

  • FATF’s high-risk jurisdictions subject to a call for action;
  • Changes to the list of jurisdictions under increased monitoring; and
  • Other regulatory developments agreed at the FATF Plenary held from 17 to 19 June 2026.

The update does not mean that every customer connected with a listed jurisdiction must be rejected. Firms are expected to distinguish between the different FATF classifications and apply measures proportionate to the actual risk.

FATF High-Risk Jurisdictions

FATF’s high-risk list continued to include:

  • Democratic People’s Republic of Korea;
  • Iran; and
  • Myanmar.

However, the required response is not identical for all three jurisdictions.

FATF continues to call for countermeasures against the DPRK and Iran. These may include limiting business relationships and financial transactions, reviewing correspondent relationships and restricting relationships with financial institutions or virtual asset service providers connected with those jurisdictions.

Myanmar remains subject to enhanced due diligence proportionate to the risks. FATF stated that it may consider countermeasures if Myanmar does not demonstrate further progress by October 2026.

For Hong Kong firms, customers and transactions connected with these jurisdictions require additional measures in line with the SFC’s AML/CFT requirements and the relevant FATF statement.

Changes to the Grey List

FATF added two jurisdictions to its list of jurisdictions under increased monitoring:

  • Bosnia and Herzegovina; and
  • Iraq.

It removed:

  • Algeria; and
  • Namibia.

Following these changes, the June 2026 grey list comprised:

  • Angola;
  • Bolivia;
  • Bosnia and Herzegovina;
  • Bulgaria;
  • Cameroon;
  • Côte d’Ivoire;
  • Democratic Republic of the Congo;
  • Haiti;
  • Iraq;
  • Kenya;
  • Kuwait;
  • Lao People’s Democratic Republic;
  • Lebanon;
  • Monaco;
  • Nepal;
  • Papua New Guinea;
  • South Sudan;
  • Syria;
  • Venezuela;
  • Vietnam;
  • Virgin Islands (UK); and
  • Yemen.

Grey-listed jurisdictions have identified strategic AML/CFT deficiencies but have committed to addressing them under FATF action plans.

FATF does not call for automatic enhanced due diligence or wholesale de-risking solely because a jurisdiction is on the grey list. The listing should instead be considered as part of the firm’s broader risk assessment.

How the Update Should Affect Customer Risk Ratings

Firms should update their country-risk data promptly and identify customers with material links to jurisdictions added to or removed from the lists.

A jurisdictional connection may arise through:

  • Residence or incorporation;
  • Beneficial ownership or control;
  • Principal business operations;
  • Source of funds or wealth;
  • Payment counterparties;
  • Financial institutions or VASPs used by the customer; or
  • Expected transaction destinations.

The FATF classification should not be the only factor determining the customer’s risk rating.

A customer connected with a grey-listed jurisdiction may remain acceptable where ownership is transparent, the business has a clear commercial purpose and transactions are consistent with the expected profile.

Risk may be higher where the country connection is combined with opaque ownership, unusual cross-border payments, weak supporting documents or exposure to sectors identified in the jurisdiction’s FATF action plan.

Removal from the grey list should also trigger a review rather than an automatic risk downgrade. Other factors—including sanctions, corruption, regulatory quality and the firm’s own experience—may continue to justify a higher rating.

When Enhanced Due Diligence Is Required

For jurisdictions subject to a FATF call for action, firms should apply the additional measures or countermeasures required by the relevant statement and Hong Kong regulations.

Enhanced measures may include:

  • Obtaining additional information about ownership and control;
  • Establishing source of funds or source of wealth;
  • Understanding the purpose of transactions;
  • Requiring senior management approval;
  • Increasing the frequency of customer reviews; and
  • Applying more intensive ongoing monitoring.

For grey-listed jurisdictions, EDD is not automatically mandatory solely because of the listing. It may nevertheless be appropriate where the overall customer or transaction risk is assessed as high.

The purpose of EDD is to address an identified risk—not simply to collect additional documents from every customer connected with a listed country.

Ongoing Monitoring and Event-Driven Reviews

Changes to FATF lists should be treated as risk events.

Firms should consider whether newly listed jurisdictions affect:

  • Existing customer risk ratings;
  • Review frequencies;
  • Expected transaction corridors;
  • Correspondent or counterparty relationships;
  • Transaction-monitoring scenarios; and
  • Previously accepted customer explanations.

Existing customers do not necessarily require an immediate full review. Firms may prioritise higher-risk relationships, customers with significant exposure to the newly listed jurisdictions and accounts already displaying unusual activity.

Where activity changes materially after onboarding, the firm should reassess the customer rather than waiting for the next scheduled review.

Implications for Virtual Asset Providers

SFC-licensed virtual asset service providers are subject to the same risk-based expectations.

Jurisdictional risk may appear through more than a customer’s nationality or registered address. Relevant information may include:

  • The location and regulatory status of another VASP;
  • Fiat funding and withdrawal accounts;
  • Wallet counterparties;
  • Exposure to services operating in higher-risk jurisdictions;
  • IP addresses and account-access information; and
  • The source and destination of virtual asset transfers.

A blockchain transaction does not always reveal the jurisdiction of the parties. VASPs should therefore combine on-chain analysis with customer information and data obtained from counterparties or Travel Rule processes.

Transactions involving high-risk wallets, unregulated offshore platforms or unexplained transfers through several services may require closer review, particularly where they also involve a listed jurisdiction.

The Compliance Significance

The SFC circular is a reminder that FATF list changes must be translated into operational controls.

Firms should update country-risk data, identify affected customers and determine whether risk ratings or monitoring need to change.

The correct response is not to treat every listed jurisdiction in the same way:

  • DPRK and Iran remain subject to countermeasures;
  • Myanmar requires enhanced due diligence proportionate to risk;
  • Grey-listed jurisdictions should inform the overall risk assessment but do not automatically require EDD or customer rejection.

The FATF lists are important risk indicators, but they do not replace customer-level analysis.

Main Sources

Hong Kong SFC — Circular to Licensed Corporations, SFC-Licensed Virtual Asset Service Providers and Associated Entities, 14 July 2026

https://apps.sfc.hk/edistributionWeb/gateway/EN/circular/aml/doc?refNo=26EC39

FATF — High-Risk and Other Monitored Jurisdictions, June 2026

https://www.fatf-gafi.org/en/countries/black-and-grey-lists.html

Adminrichie

AML Observatory Webmaster, responsible for the website's operations.

Related Articles

Leave a Reply

Back to top button