Skip to main content
PTS Managed Services

PTS Managed Services · Hong Kong

The SFC licence navigator for small fund managers and advisers

Choose the regulated activities your firm holds or is applying for. The navigator shows what the SFC expects of a firm like yours, what that means for your technology and cybersecurity, and the proportionate way to get there — then turns your answers into a maturity self-assessment you can keep as a PDF or send to PTS.

Your licences (select all that apply)

Two switches change the answer more than any licence type: holding client assets raises the capital bar and brings the client asset rules in; any online client access brings the SFC's internet trading guidelines into scope.

Selected
Type 9
not holding client assets
Responsible officers
2 per activity
the same people can cover several licences
Minimum liquid capital
HK$100,000
paid-up: None prescribed
SFC IT instruments
10 apply, 3 to consider
see the IT and cyber rules tab
Roadmap controls
26
proportionate controls for this combination

What your combination means

Showing for Type 9

Every licensed corporation lives under the Code of Conduct, the Internal Control Guidelines and the SFC's cybersecurity circulars. Each regulated activity then adds its own obligations. Here is what your selection adds, and what it means for your technology.

Licences
Type 9
Asset management
Capital
HK$100,000 liquid
Types 4, 5, 6 and 9 with a condition not to hold client assets. Type 6 sponsor work needs HK$10,000,000 paid-up.
Internet trading guidelines
Benchmark only
Outside their scope, but the SFC's most detailed cyber checklist
Client asset rules
Not in scope
Custody sits with a bank, broker or fund custodian
Type 9 · Asset management

Managers of private funds, hedge funds and discretionary accounts. The core licence for a small fund manager.

What it adds: The Fund Manager Code of Conduct: risk management, custody arrangements, valuation, liquidity, conflicts, disclosure, record keeping and business continuity. HK$100,000 liquid capital without client assets.

For your IT: Where regulatory records live in the cloud (the EDSP circular), backup and continuity for the portfolio and investor data, and payment fraud controls around subscriptions and redemptions.

How PTS helps

PTS has operated in Hong Kong for over 25 years, holds ISO/IEC 27001 and ISO/IEC 20000 certifications, is independent of all vendors, and works with professional and financial services firms that face the same expectations as large institutions with a fraction of the headcount.

A proportionate starting point for Type 9

  • An independent IT and cybersecurity assessment mapped to the instruments that apply to your licences, with a prioritised roadmap and budget guidance
  • Remediation of the gaps, either through your existing provider or through PTS managed IT
  • Staff awareness training that produces a signed training record for your compliance pack
  • Penetration testing through PTS's external testing partner at a fixed price for a defined scope
  • Quarterly reporting to your IT Manager-In-Charge so supervision is evidenced, not assumed

Getting licensed

Showing for Type 9

The SFC tests the corporation and its people against a fit and proper standard: financial status, competence, ability to act honestly and fairly, and reputation. These are the practical requirements a clean application has to show.

Responsible officers
2 per activity
at least one an executive director, one in Hong Kong at all times
Paid-up capital
None prescribed
Types 4, 5, 6 and 9 with a condition not to hold client assets. Type 6 sponsor work needs HK$10,000,000 paid-up.
Liquid capital
HK$100,000
an FRR calculation, maintained every day
Timeline
15 weeks
SFC pledge once accepted; four to six months in practice
Fees
HK$4,740
per activity for the corporation; HK$2,950 per RO; HK$1,790 per representative

Responsible Officers

  • At least two ROs approved for each regulated activity; the same individuals can be approved for several
  • At least one an executive director, and at least one available in Hong Kong to supervise at all times
  • Type 9 ROs are expected to show experience exercising investment discretion, not only advisory or sales experience
  • ROs pass the local regulatory framework papers (HKSI Licensing Examination) unless exempt

RO experience routes

RouteEducationIndustry experienceManagement
1Relevant degree, or CFA, CIIA, CFP3 of last 6 years2 years
2HKDSE or HKCEE passes in Chinese or English and Maths5 of last 8 years2 years
3None8 of last 11 years2 years

Managers-In-Charge

Every licensed corporation names a manager for each of eight core functions: overall management oversight, key business line, operational control and review, risk management, finance and accounting, information technology, compliance, and AML/CFT. In a small firm the same individuals cover several. The MIC for overall management and for the key business line must be ROs. The IT MIC is the person the SFC will ask about everything on the IT and cyber rules tab.

Licensed representatives

Anyone else who performs the regulated activity (a trader, an analyst who makes investment decisions, an adviser who speaks to clients) needs a representative licence with its own competence and exam requirements. Back office and administration staff do not.

The application

What goes in

  • SFC forms for the corporation, ROs and representatives, plus the supplementary questionnaires, through the WINGS portal
  • Business plan: strategy, target clients, products, fee model, three year projections
  • Organisation chart, MIC allocation, CVs and licensing history for each RO
  • Compliance manual and description of the compliance function
  • Proof of capital: bank statements and an FRR computation
  • Office lease; the SFC approves business premises under section 130 of the SFO
  • Incorporation documents, business registration, shareholder and director details

Where IT appears

  • How systems, records and data will be kept and protected, and who the IT MIC is
  • Where regulatory records will be stored: a firm keeping records only in the cloud has to deal with the EDSP circular before the licence is granted, because storage location is part of the premises approval
  • Business continuity arrangements

This is the earliest point at which an IT provider can help. Getting the tenant, records and MIC arrangements right before submission avoids requisitions later.

How PTS helps

Pre-licensing IT set-up

  • Design the Microsoft 365 tenant, device standard and record keeping to satisfy the EDSP circular and the application questions from day one
  • Draft the proportionate IT and security policy, business continuity plan and provider agreement the application refers to
  • Provide the IT section of the business plan and answer SFC requisitions on technology
  • Set up the reporting the IT MIC will need once licensed

Ongoing obligations

Showing for Type 9

Holding the licence is a continuous set of filings, notifications and standards. This is the rhythm for a firm with a 31 December year end.

Annual return
1 month
after the licence anniversary, with the annual fee
Audited accounts
4 months
after year end, with the FRR audit, BRMQ and ADD
FRR returns
Half-yearly
firms with the no-client-assets condition
Notify changes
7 business days
directors, MICs, ROs, business nature, bank accounts, auditor
CPT
10 / 12 hours
per year for licensed individuals and ROs
Within 1 month of anniversary
Annual return and annual feeFiled through WINGS. Confirms particulars, MICs and that CPT was met. Late filing risks the licence.
Within 4 months of year end
Audited accounts, auditor's FRR report, BRMQ and ADDFor a December year end that is 30 April. The Business and Risk Management Questionnaire asks directly about IT, cybersecurity and business continuity.
Every 6 months
FRR financial returnLiquid capital must be maintained every day, not only at the filing date. Notify the SFC if it falls below 120% of the requirement.
Within 7 business days
Notify changesDirectors, shareholders, MICs, ROs leaving, business nature, bank accounts, auditor, complaints officer, emergency contact. Address changes need 7 business days' notice before the move.
By 31 December
Continuous professional trainingAt least 10 CPT hours per licensed individual, 12 for ROs including two on regulatory compliance. New entrants add 2 hours of ethics. Records kept for at least three years. Cybersecurity awareness training counts where relevant to the role.
Annually, around April
Asset and Wealth Management Activities SurveyPlus any thematic questionnaires the SFC circulates.
Immediately
Material incidents and breachesCyber incidents, system failures, breaches, liquid capital shortfalls and material complaints are reported to the SFC as soon as the firm becomes aware. See the Incidents tab.
Continuous
Standards of conductCode of Conduct, Fund Manager Code of Conduct, Internal Control Guidelines, AML/CFT Guideline, Keeping of Records Rules (most records seven years), PDPO. Licence displayed at the office. An RO supervising at all times.

What does the BRMQ ask about technology?

The Business and Risk Management Questionnaire (BRMQ) is the SFC's annual return on how the firm is managed. Every licensed corporation files it with the audited accounts, within four months of the financial year end. The current form, issued under circular 24EC68, asks each firm directly about its technology, and the SFC reads the answers when deciding whom to inspect. The technology questions cover:

  • Whether IT is outsourced, to whom, and which function oversees the provider
  • Whether staff in the IT function receive training
  • How online banking credentials and tokens are protected
  • Whether there is a business continuity plan and whether it was drill-tested during the year
  • How and how often systems and data are backed up
  • Whether any system incident occurred: unplanned outage, hacking, ransomware, data loss or leakage
  • For fund managers: whether AI or machine learning is used in regulated activities, and where

Each answer is a representation to the regulator signed by senior management, so the evidence behind it should be on file before filing. The FAQ tab covers the BRMQ in more detail.

How PTS helps

Turning obligations into a calendar

  • A quarterly IT report to the MIC that lines up with the annual return, the BRMQ and the audit
  • Monthly patch, backup and access evidence so the BRMQ answers are true and provable
  • Retention and audit logging set to the seven year record keeping standard
  • Annual training and testing scheduled so CPT and the technical review land before year end

IT and cybersecurity rules

Showing for Type 9

There is no single SFC IT rulebook. The expectations are spread across the codes and a series of circulars. Each instrument below is marked applies, consider or hidden, based on your selection. For a narrative walk-through of the cybersecurity instruments, see our guide to the SFC cybersecurity requirements for Hong Kong fund managers. To check where your firm stands on the controls behind them, one question at a time, take the Security Controls Audit.

The principle behind all of it

Outsourcing IT does not outsource responsibility. The SFC's cybersecurity review report says it plainly: firms can outsource the implementation of controls to third party providers, but senior management remains responsible for overall management and supervision. Every instrument below assumes the firm can show that supervision happened.

Applies to your firm

Code of Conductapplies

Code of Conduct for Persons Licensed by or Registered with the SFC

The general rulebook. General Principle 3 and paragraph 4.3 require internal controls, resources and operational capability that protect the firm and its clients. Paragraph 12.5 requires immediate reporting of a material breach or a material failure of systems, and the SFC's cyber circulars apply it to material cybersecurity incidents. Paragraph 5 (know your client and suitability) drives the advice records for Types 4 and 5.

ICGapplies

Management, Supervision and Internal Control Guidelines

Management oversight, segregation of duties, information management, operational controls, record keeping and contingency planning, applied in proportion to the firm. The SFC's 2025 inspections flagged management review, segregation of duties, information management and audit trails as the most common weaknesses.

FMCC · 5th editionapplies

Fund Manager Code of Conduct

Applies to Type 9 firms managing funds and, in part, discretionary accounts. Organisation and resources, risk management, custody, valuation, liquidity and leverage, conflicts, disclosure, record keeping, business continuity and data security. The SFC's October 2024 circular on private fund management deficiencies (conflicts, valuation, risk disclosure) is the live inspection theme.

19EC59 · Oct 2019 · FAQs Dec 2020applies

Circular on the Use of External Electronic Data Storage Providers (EDSP)

Applies whenever regulatory records (trade, client, accounting records, communications) are kept with a cloud or third party provider, which for a Microsoft 365 firm is always. Due diligence on the provider, an audit trail of who accessed or changed records, records reproducible at approved premises promptly and in full, and, where records are kept exclusively in the cloud, an SFC notice and undertaking from the provider plus two named Managers-In-Charge in Hong Kong with full access.

20EC37 · Apr 2020applies

Circular on Management of Cybersecurity Risks Associated with Remote Office Arrangements

Strong VPN or equivalent secure remote access, strong passwords plus two-factor authentication, extra controls on privileged accounts, tiered access for corporate versus personal devices, secure video conferencing, staff awareness training and alerts, detection of unauthorised access and an incident reporting mechanism.

21EC41 · Oct 2021applies

Circular and Report on Operational Resilience and Remote Working

The SFC's observations on hybrid working: business continuity plans that cover remote operation, dependence on third party providers, supervision of staff at home, and record keeping of communications on personal devices and messaging apps.

SFO/IS/004/2025 · 6 Feb 2025applies

Circular and Report on the Cybersecurity Review of Licensed Corporations

Eight material incidents reported between 2021 and 2024, including two ransomware attacks. Half of respondents ran end-of-life operating systems. Expectations with immediate effect: disable unnecessary ports and review access lists, an annual technical review including vulnerability scanning and penetration testing endorsed by management, security patches within one month of testing, encryption at rest and in transit, need-to-have access with restricted administrator accounts, audit logs retained and reviewed, policies for third party IT providers, and contingency plans that cover cyber scenarios. Firms with client accounts must monitor them for unauthorised access, and firms are encouraged to stop using SMS one-time passwords or add compensating controls.

26EC32 · 2 Jun 2026applies

Circular on Enhanced Cybersecurity Measures to Address Evolving Risks Arising from AI-enabled Cyberattacks

Addressed to every licensed corporation, virtual asset platform and associated entity. Every firm is expected to keep its security controls robust and up to date, starting from an accurate inventory of its technology, and to consider five areas when reviewing its cybersecurity framework: patching and vulnerability management with a route for urgent fixes; least privilege access, segmentation and maker-checker on high impact actions; detection, monitoring and threat intelligence; third party and supply chain governance; and incident response and recovery including tabletop exercises, backups and prompt SFC notification. An appendix gives example controls. The SFC generally expects firms engaged in electronic trading (particularly large retail brokers), Type 13 depositaries and virtual asset platforms to adopt all of them; other firms should consider them in the light of the nature, scale and complexity of their operations and the risks they face.

AML/CFT Guidelineapplies

Guideline on Anti-Money Laundering and Counter-Financing of Terrorism

Client due diligence, source of wealth and funds, screening, transaction monitoring, record keeping and a named AML Manager-In-Charge. The KYC files are also the firm's most sensitive personal data, so the AML programme and the data protection controls have to be designed together.

PDPOapplies

Personal Data (Privacy) Ordinance

Every client or investor KYC file is personal data. Data Protection Principle 4 requires practicable security safeguards. Breach notification to the Privacy Commissioner is currently voluntary, but the PCPD expects it as soon as practicable and the SFC expects the firm to have decided its position in advance.

Consider and document

Guidelines · Oct 2017consider

Guidelines for Reducing and Mitigating Hacking Risks Associated with Internet Trading

Twenty baseline controls: two-factor authentication for client login, encryption, one-month patching, daily offline backups, annual staff training, monitoring, and more. Mandatory for any firm whose clients can place orders or transact online. The July 2026 Luk Fook case applied them directly, because the broker ran an online trading platform. Other firms are outside their scope, but the guidelines remain the most detailed cyber checklist the SFC has published and a sensible benchmark.

24EC55 · Nov 2024consider

Circular on the Use of Generative AI Language Models

Four core principles: senior management oversight, AI model risk management, cybersecurity and data protection, and third party risk management. Using AI to produce investment recommendations, advice or research is a high risk use case that needs human review and client disclosure, and may need notification to the SFC. Advisory licences are directly in scope.

Market sounding guidelines · 2025consider

Guidelines for Market Soundings

Controls on the handling of confidential information when sounding out investors ahead of a placement: authorised personnel, information barriers, recording of communications, and a documented process. Corporate finance advisers are the disclosing side; fund managers that receive soundings are the recipient side and need their own handling controls.

What an SFC inspector asks a small firm

  • Who is the IT MIC and what do they actually review?
  • Where are regulatory records stored and who can produce them?
  • Show me the agreement with your IT provider and what it makes them responsible for
  • Show me MFA is on for everyone, and the last admin access review
  • When was the last backup restore test? The last patch report? The last staff training?
  • What would you do if your email were compromised tomorrow, and who would you tell?
Enforcement reference point

On 28 July 2026 the SFC reprimanded and fined Luk Fook Securities (HK) Limited HK$2.1 million after a September 2022 ransomware attack that came in through its remote access system and took almost three weeks to recover from. The SFC found a lack of firewall protection and adequate network monitoring, outdated operating systems and antivirus, weak control of user and privileged accounts, credentials kept in unencrypted files, weak control of remote access and external devices, no regular staff awareness training, and inadequate backup and continuity arrangements. Luk Fook, licensed for Types 1, 4 and 9, ran an online trading platform, so the internet trading guidelines applied to it directly. Nothing on that list is specific to trading platforms, though: most of it is the basic hygiene the February 2025 circular sets out for every licensed corporation. There was no evidence that clients lost money. The firm reported the attack to the SFC the same day, and in setting the penalty the SFC took into account its reviews and remediation, its co-operation and its clean record.

How PTS helps

Mapping the rules to your environment

  • A gap analysis against every instrument marked above, written in plain language for the ROs and the IT MIC
  • A signed consideration note for the June 2026 and February 2025 circulars, so the firm can show it considered each area
  • Configuration of Microsoft 365, devices and backup to the standards the circulars describe
  • The evidence trail an inspector or investor asks for, produced as part of normal service rather than reconstructed afterwards

Your IT roadmap

Showing for Type 9

The proportionate set of controls for your selection, each with the SFC expectation it answers. Tick what is already in place — the ticks stay in this browser only, and they build your maturity self-assessment on the Your assessment tab.

Governance

Identity and access

Devices and remote working

Email and data

Detection and response

People and third parties

See your assessment

How PTS helps

Delivering the roadmap

  • Phase 1: independent assessment against this list, with a prioritised roadmap and budget guidance, typically three weeks for a small firm
  • Phase 2: remediation, through your current provider or PTS managed IT, and staff awareness training with a signed record
  • Phase 3: penetration testing through PTS's external testing partner at a fixed price, once the gaps are closed
  • Ongoing: the quarterly MIC report, patching, backup, monitoring and access reviews that keep the ticks true

Your assessment

Showing for Type 9

Your selections and roadmap ticks, turned into a maturity picture you can keep, print, or send to PTS for a costed remediation plan. Nothing here leaves your browser unless you choose to send it.

Your firm
Type 9
no client assets · no online client access
Controls in place
0 of 26
0% of the proportionate roadmap for this combination
Maturity
Not yet assessed
tick the roadmap to build your picture
Two minutes on the roadmap makes this useful

Go to the Your IT roadmap tab and tick the controls your firm already has. This tab then scores your maturity by area, lists the specific gaps, and pre-fills the request below — so the conversation with PTS starts from your actual position, not a blank page. You can also send it as-is and we will start from a discovery call.

Opens your browser's print dialog — choose "Save as PDF". The report includes your profile, scores and gap list, and nothing is sent to PTS.

Send your assessment to PTS — get a costed remediation plan

We reply within two business days with a practical view of your gaps, what closing them costs, and the order we would do it in. No obligation, no sales deck. Your selections and ticks above are attached automatically.

Costed remediation plan · No obligation · Goes to our inbox, not a database

Evidence pack

Showing for Type 9

What your firm should be able to hand to an SFC inspector or an investor's operational due diligence team, on the technology side, within a day.

Documents
17
for this combination
Two audiences
SFC and investors
inspections look for supervision; due diligence looks for the same plus testing
Golden rule
Produced, not reconstructed
evidence generated by normal operations is credible; evidence assembled after a request is not
DocumentWhat it showsRefresh
IT and information security policyRules for devices, access, email, data, remote working and acceptable use, with RO approvalAnnual
IT MIC appointment and quarterly reportsWho is accountable for IT to the SFC and evidence that they reviewed the provider's reportsQuarterly
IT provider agreement and service reportsResponsibilities, security obligations, audit rights, evidence of supervisionQuarterly reports
Systems and asset registerDevices, cloud services, systems, owners, data heldQuarterly
Regulatory records and EDSP registerWhich records live where, provider due diligence and certifications, notice or undertaking if relying on exclusive cloud storage, the two MIC namesAnnual and on change
Access register and review logWho has access to what, admin roles, review sign-offTwice yearly
Patch and vulnerability reportPatch status against the one month standard, end-of-life softwareMonthly
Backup and restore test recordBackup coverage and a successful restoreBackup daily; test annually
Incident response plan and incident logSteps, contacts, SFC and PCPD reporting flow, record of every incident and near missAnnual; log continuous
Business continuity and DR planScenarios, recovery objectives, alternative working, test resultsAnnual test
Cybersecurity assessment and roadmapIndependent findings mapped to SFC expectations, remediation statusAnnual
Penetration test reportExternal and Microsoft 365 testing, findings and closureAnnual or after major change
Training deck and signed training recordTopics mapped to SFC references, attendee signatures, date, CPT hoursAnnual
Third party register and due diligence filesEvery provider touching firm data, risk rating, evidence reviewedAnnual
Generative AI policyApproved tools, prohibited inputs, human review, high risk use cases and any SFC notificationAnnual
Data protection policy and PICSHow personal data is collected, secured, retained and deletedAnnual
Circular consideration notesSigned notes for 26EC32, the Feb 2025 circular and 24EC55 stating what was done or why not applicableOn each new circular
How PTS helps

Building and maintaining the pack

  • The policy set, incident plan, continuity plan and provider agreement drafted to your size
  • Registers and reports generated from the live environment every month and quarter
  • An assessment report, training record and penetration test report that slot straight into investor due diligence questionnaires
  • A single shared evidence folder, permissioned for the ROs, the IT MIC and your compliance adviser

Incidents and reporting

Showing for Type 9

What happens when something goes wrong, and who has to be told. This is the part most small firms have never rehearsed.

SFC
Immediately
Code of Conduct 12.5, which the SFC's cyber circulars apply to material cyber incidents
PCPD
As soon as practicable
voluntary today; the PCPD suggests within five days
Counterparties
Same day
administrator, custodian, brokers, so instructions are verified
Mitigation
Self-report
treated as a mitigating factor in enforcement
SFC

Code of Conduct paragraph 12.5

A licensed corporation must report to the SFC immediately on a material breach of the rules, or a suspected one, and under 12.5(e) on a material failure, error or defect in its trading, accounting, clearing or settlement systems. The paragraph does not name cyber incidents, but the SFC's June 2026 circular applies it to material cybersecurity incidents and attacks, and its July 2026 circular to hacking incidents at internet brokers. In practice, treat as material anything that affects clients, records, the ability to operate or confidence in the firm; a compromised mailbox that handled client instructions qualifies. The ROs make the call and follow up with a written account and remediation plan.

Others

Who else may need to know

  • The fund administrator, custodian, prime broker or exchange, so they can hold or verify instructions
  • Clients or investors whose data or instructions are affected
  • Insurers, where cyber or professional indemnity cover exists
  • Hong Kong Police for fraud or extortion
  • Auditors, where records or financial controls are affected
Sequence

The first 24 hours

  • Contain: isolate the device, revoke sessions, reset credentials, block forwarding rules
  • Preserve: keep logs and the affected mailbox; do not wipe before evidence is captured
  • Assess: what data, which clients, which instructions could have been affected
  • Notify: ROs decide on SFC and PCPD reporting; counterparties told to verify instructions
  • Record: timeline, decisions, who was told and when
  • Recover and learn: restore, close the gap, update the plan, brief staff
Rehearse

The tabletop exercise

The June 2026 circular expects regular testing of incident handling and contingency plans through tabletop exercises, simulated attacks or other appropriate means. For a small firm that is a one hour walk-through of a realistic scenario once a year: a compromised mailbox, a fraudulent redemption instruction, ransomware on a laptop, or the administrator's portal going down during a dealing day. The output is a short record of what worked, what did not and what changed.

Do not wait for certainty

The SFC has treated late reporting as an aggravating factor and self-reporting as a mitigating one. A firm that reports "we believe a mailbox was compromised and are investigating" is in a far better position than one that reports a confirmed loss three weeks later.

How PTS helps

Before, during and after an incident

  • A written incident response plan with the SFC and PCPD reporting flow and a contact sheet the ROs keep off the network
  • An annual tabletop exercise facilitated by PTS, with a written record of the testing the June 2026 circular expects
  • Incident response support: containment, evidence preservation, recovery from backup and the technical account the SFC will ask for
  • A post-incident review that closes the gap and updates the roadmap

Other licences

The full set of SFC regulated activities, and the non-SFC licences that firms of this kind sometimes hold. Select the ones you hold in the picker at the top to see what they add.

ActivityDescriptionWho holds itRelevance to a small manager
Type 1Dealing in securitiesBrokers, fund distributors, placing agents; managers marketing their own fundsCommon with Type 9
Type 2Dealing in futures contractsFutures brokers; managers executing listed derivativesPaired with Type 5
Type 3Leveraged foreign exchange tradingMargin FX dealersRare for fund managers
Type 4Advising on securitiesInvestment advisers, research, advisory mandatesMost common companion to Type 9
Type 5Advising on futures contractsAdvisers on futures and listed derivativesPaired with Type 2 or Type 9
Type 6Advising on corporate financeM&A advisers, IPO sponsors, boutique corporate financeOccasionally with Type 9
Type 7Providing automated trading servicesTrading platforms and matching enginesSpecialist
Type 8Securities margin financingMargin lendersRare for fund managers
Type 9Asset managementPrivate funds, hedge funds, discretionary accountsThe core licence
Type 10Providing credit rating servicesCredit rating agenciesSpecialist
Type 11Dealing in or advising on OTC derivative productsOTC derivatives dealers and advisersRegime being phased in
Type 12Providing client clearing services for OTC derivative transactionsClearing membersRegime being phased in
Type 13Providing depositary services for relevant CISTrustees and custodians of SFC-authorised fundsIn force since October 2024

Outside the SFC

Virtual assets

Managers running virtual asset strategies stay under Type 9 with additional SFC conditions and expectations (custody with licensed platforms, cold storage, multi-signature controls). Operating a trading platform needs the separate virtual asset trading platform licence, with the full internet trading, June 2026 and July 2026 circular obligations.

Trust or Company Service Provider

Licensed by the Companies Registry. Held by firms that administer structures or act as company secretary for clients. Brings its own AML and record keeping obligations.

Money Lenders Ordinance

Firms that lend, including private credit strategies that lend directly rather than through a fund vehicle, may need a money lender's licence from the Companies Registry.

Insurance Authority and MPFA

Anyone selling insurance-linked products needs Insurance Authority registration; MPF intermediaries register with the MPFA. Unusual for a fund manager but common in wealth management groups.

How PTS helps

When licences change

  • Re-baseline the IT obligations whenever a licence is added, because Type 1 or any online client access changes the rules that apply
  • Prepare the technology description and controls mapping the SFC asks for when a new regulated activity is added
  • Adjust records, monitoring and backup to the new activity before the first client is onboarded

Questions small firms ask

Showing for Type 9

Short answers for the questions that come up most. Some only appear for the licences you selected.

We are only two or three people. Does any of this really apply to us?

Yes. The SFC applies the same codes to every licensed corporation and scales its expectation by size and complexity, not by whether the rules apply. Its February 2025 and June 2026 cybersecurity circulars are addressed to every licensed corporation. What changes for a small firm is depth: a short policy rather than a forty page one, a quarterly report from the provider rather than a security team.

Our IT is fully outsourced. Isn't the provider responsible?

The provider is responsible to you under its contract. You are responsible to the SFC. The SFC's review report says senior management remains responsible for overall management and supervision even when implementation is outsourced. Your IT Manager-In-Charge needs to be able to show that supervision happened, which is why PTS reports to the MIC quarterly in writing.

Do we need SFC approval to use Microsoft 365 or Google Workspace?

Not approval as such, but the EDSP circular applies. You need to have done due diligence on the provider, know where the data is held, keep retention and audit logs on, and decide whether you rely on exclusive cloud storage of regulatory records. If you do, you need the provider notice or undertaking arrangements and two named MICs in Hong Kong with full access.

Is MFA actually required?

The 2020 remote working circular expects two-factor authentication for staff logins, the February 2025 circular expects strong authentication and encourages firms to stop using SMS one-time passwords, and the internet trading guidelines mandate it for client logins where clients transact online. For internet brokers the July 2026 circular goes further: client login should be phishing-resistant by 8 July 2027, using passkeys or bound devices rather than SMS or email one-time passwords. A licensed corporation without MFA in 2026 would have no defence after an incident.

How quickly do we have to patch?

The February 2025 circular sets the standard at deployment within one month of completing testing for security patches, and expects end-of-life software to be removed. The June 2026 circular adds a route for urgent fixes outside the normal cycle.

Do we need a penetration test?

The February 2025 circular expects an annual technical review including vulnerability scanning and penetration testing, endorsed by management. For a small firm that means an external test of the internet-facing footprint and the Microsoft 365 tenant. If clients transact online, the portal and its APIs are tested too. PTS delivers testing through its external testing partner at a fixed price for a defined scope.

What do we have to do about AI?

Two things. Under the November 2024 circular, govern your own use: which tools, on which accounts, what must never be entered, and human review of anything that reaches a client. Advisory firms using AI for recommendations or research are in the high risk category. Under the June 2026 circular, assess how prepared you are for AI-enabled attacks against you: deepfake voice and video, polished phishing and faster exploitation of vulnerabilities.

What counts as a reportable incident?

Code of Conduct 12.5 requires immediate reporting of a material breach or a material failure of systems, and the SFC's cyber circulars apply it to material cybersecurity incidents. Incidents likely to be material include a compromised mailbox, ransomware, loss of a device with unencrypted data, a fraudulent payment, or a system failure that stops the firm operating. Report immediately on becoming aware, even before the facts are complete. Self-reporting is a mitigating factor in enforcement.

Does cybersecurity training count towards CPT?

It can, where the topic is relevant to the individual's role and the firm records it properly. ROs need 12 CPT hours a year including two on regulatory compliance; other licensed individuals need 10. PTS training sessions produce a signed record for the CPT log.

What is the IT Manager-In-Charge supposed to do?

Be the person the SFC holds accountable for IT. In practice: receive and read the provider's reports, sign off access reviews, own the incident plan, make sure the EDSP arrangements are in place, and be able to explain the firm's controls in an inspection. In a small firm this is usually a Responsible Officer, supported by the provider.

How long do we keep records?

Most records seven years under the Keeping of Records Rules, some two. Emails and messages containing orders, instructions or advice are records. Set Microsoft 365 retention to match and have a policy for personal messaging apps.

What is the BRMQ and what does it ask about our IT?

The Business and Risk Management Questionnaire is the SFC's annual return on how a licensed corporation is run. Every licensed corporation files it through WINGS with the audited accounts, within four months of the financial year end, so 30 April for a December year end. The current form comes from circular 24EC68 and has a section for every firm plus sections by business line. Its technology questions ask whether IT is outsourced and to whom, who oversees the provider, whether IT staff are trained, how online banking credentials and tokens are protected, whether there is a business continuity plan and whether it was drill-tested this year, how and how often systems and data are backed up, and whether any system incident occurred: an unplanned outage, hacking, ransomware, data loss or leakage. Firms offering internet trading answer a further block on two-factor authentication, monitoring and client notifications.

Who signs the BRMQ and what happens if a technology answer is wrong?

Senior management signs the BRMQ, and the SFC uses it to decide which firms to inspect and what to ask. An answer that says backups are taken and the continuity plan was tested is a representation to the regulator, so the evidence behind it needs to exist on the day of filing: backup reports, a restore test record, the drill report, the provider agreement and the MIC's supervision notes. PTS's quarterly IT report to the Manager-In-Charge is written so that each BRMQ technology question can be answered from it, with the evidence attached.

Does the BRMQ ask fund managers about AI?

Yes. Since the December 2024 edition of the form, the asset management section asks whether the firm uses AI or machine learning in its regulated activities, traditional or generative, third-party or in-house, in which functions and at which stages of the investment process. A truthful answer needs an inventory of the AI tools staff actually use, which is also the first thing the November 2024 generative AI circular expects. Firms that answer no while staff use ChatGPT or Copilot on work accounts are the ones an inspection catches out.

What will an SFC inspection ask for on IT?

The IT MIC and their reports, the provider agreement, where records are stored, MFA status, admin access and reviews, patching evidence, backup and restore tests, the incident plan, training records and the BCP. The Evidence pack tab is that list.

Is a separate backup of Microsoft 365 necessary if Microsoft already has copies?

Microsoft protects its platform, not your data against deletion, ransomware or a compromised administrator. The June 2026 circular expects regular backups as part of recovery, and the review report lists backup resilience as an area needing improvement. A separate backup with an annual restore test is the proportionate answer.

What happens if we do nothing?

Most likely nothing until something happens. Then the firm faces the SFC's question of whether controls were adequate, with the July 2026 Luk Fook case as the reference point: a reprimand and a HK$2.1 million fine for basic control failures exposed by a ransomware attack, although there was no evidence that clients lost money. Investor due diligence is the nearer term cost: allocators walk away from firms that cannot evidence the basics.

How PTS helps

Ask us the one that is not here

  • A thirty minute conversation with a PTS consultant about your licences, your environment and where to start
  • No obligation and no sales deck; the answer is usually a short list of what to fix first

Glossary and sources

ADD
Accounting Disclosure Document, filed with the audited accounts.
BRMQ
Business and Risk Management Questionnaire, filed annually with the audited accounts.
CPT
Continuous Professional Training required of licensed individuals each calendar year.
EDSP
External Electronic Data Storage Provider: any cloud or third party that holds the firm's regulatory records.
FMCC
Fund Manager Code of Conduct.
FRR
Securities and Futures (Financial Resources) Rules.
ICG
Management, Supervision and Internal Control Guidelines.
MIC
Manager-In-Charge of a core function.
PCPD
Office of the Privacy Commissioner for Personal Data.
PDPO
Personal Data (Privacy) Ordinance.
RO
Responsible Officer.
SFO
Securities and Futures Ordinance (Cap. 571).
WINGS
The SFC's online portal for licensing applications, filings and notifications.

Sources

  1. SFC, Circular 26EC32, Enhanced cybersecurity measures to address evolving risks arising from AI-enabled cyberattacks, 2 June 2026, and its Appendix of example controls. apps.sfc.hk · Appendix (PDF)
  2. SFC, Circular 26EC35, Implementing robust authentication methods to reduce and mitigate hacking risks from phishing attacks and adequate monitoring and surveillance measures to identify suspicious activities, 9 July 2026. apps.sfc.hk
  3. SFC, Circular SFO/IS/004/2025, Cybersecurity review of licensed corporations, 6 February 2025. apps.sfc.hk
  4. SFC, Report on the 2023/24 thematic cybersecurity review of licensed corporations, February 2025. sfc.hk
  5. SFC, Circular 24EC55, Use of generative AI language models, November 2024. apps.sfc.hk
  6. SFC, Circular 19EC59, Use of external electronic data storage, 31 October 2019, and FAQs, December 2020.
  7. SFC, Circular 20EC37, Management of cybersecurity risks associated with remote office arrangements, 29 April 2020.
  8. SFC, Circular 21EC41, Operational resilience and remote working, October 2021. apps.sfc.hk
  9. SFC, Guidelines for Reducing and Mitigating Hacking Risks Associated with Internet Trading, October 2017.
  10. SFC, News release 26PR118, SFC reprimands and fines Luk Fook Securities (HK) Limited $2.1 million for inadequate cybersecurity control to fend off cyberattack, 28 July 2026, and the Statement of Disciplinary Action. apps.sfc.hk · Statement of Disciplinary Action (PDF)
  11. SFC, Business and Risk Management Questionnaire (BRMQ): form and guidance. sfc.hk
  12. SFC, Circular 24EC68, Revised Business and Risk Management Questionnaire, 27 December 2024, Annex 1a (licensed corporation form). apps.sfc.hk
  13. SFC, Ongoing obligations for licensed intermediaries. sfc.hk
  14. SFC, Code of Conduct for Persons Licensed by or Registered with the Securities and Futures Commission, including paragraph 12.5 (notifications to the SFC). sfc.hk
  15. SFC, Fund Manager Code of Conduct, fifth edition. sfc.hk
  16. SFC, Guidelines on Continuous Professional Training, January 2022.
  17. Charltons, Applying to the SFC for a Type 9 (asset management) licence. charltonslaw.com
  18. Timothy Loh LLP, SFC License Type 9 FAQs. timothyloh.com
  19. Waystone Compliance, 2026 SFC compliance readiness checklist. compliance.waystone.com
  20. PTS, SFC cybersecurity requirements for Hong Kong fund managers.

This navigator is a technology and controls reference prepared by PTS Managed Services Limited. It is not legal or regulatory advice. Fees, capital thresholds and filing deadlines change; confirm them against the SFC's current publications or your compliance adviser. References current at 23 September 2026.

Call Request a proposal