Skip to main content
PTS Managed Services

PTS Managed Services · Hong Kong

The SFC licence navigator for small fund managers and advisers

Choose the regulated activities your firm holds or is applying for. The navigator shows what the SFC expects of a firm like yours, what that means for your technology and cybersecurity, and the proportionate way to get there — then turns your answers into a maturity self-assessment you can keep as a PDF or send to PTS.

Your licences (select all that apply)

Two switches change the answer more than any licence type: holding client assets raises the capital bar and brings the client asset rules in; any online client access brings the SFC's internet trading guidelines into scope.

Selected
Type 9
not holding client assets
Responsible officers
2 per activity
the same people can cover several licences
Minimum liquid capital
HK$100,000
paid-up: None prescribed
SFC IT instruments
9 apply, 4 to consider
see the IT and cyber rules tab
Roadmap controls
26
proportionate controls for this combination

What your combination means

Showing for Type 9

Every licensed corporation lives under the Code of Conduct, the Internal Control Guidelines and the SFC's cybersecurity circulars. Each regulated activity then adds its own obligations. Here is what your selection adds, and what it means for your technology.

Licences
Type 9
Asset management
Capital
HK$100,000 liquid
Types 4, 5, 6 and 9 with a condition not to hold client assets. Type 6 sponsor work needs HK$10,000,000 paid-up.
Internet trading guidelines
Benchmark only
Applied as the SFC's reference point for reasonable controls
Client asset rules
Not in scope
Custody sits with a bank, broker or fund custodian
Type 9 · Asset management

Managers of private funds, hedge funds and discretionary accounts. The core licence for a small fund manager.

What it adds: The Fund Manager Code of Conduct: risk management, custody arrangements, valuation, liquidity, conflicts, disclosure, record keeping and business continuity. HK$100,000 liquid capital without client assets.

For your IT: Where regulatory records live in the cloud (the EDSP circular), backup and continuity for the portfolio and investor data, and payment fraud controls around subscriptions and redemptions.

How PTS helps

PTS has operated in Hong Kong for over 25 years, holds ISO/IEC 27001 and ISO/IEC 20000 certifications, is independent of all vendors, and works with professional and financial services firms that face the same expectations as large institutions with a fraction of the headcount.

A proportionate starting point for Type 9

  • An independent IT and cybersecurity assessment mapped to the instruments that apply to your licences, with a prioritised roadmap and budget guidance
  • Remediation of the gaps, either through your existing provider or through PTS managed IT
  • Staff awareness training that produces a signed training record for your compliance pack
  • Penetration testing through PTS's external testing partner at a fixed price for a defined scope
  • Quarterly reporting to your IT Manager-In-Charge so supervision is evidenced, not assumed

Getting licensed

Showing for Type 9

The SFC tests the corporation and its people against a fit and proper standard: financial status, competence, ability to act honestly and fairly, and reputation. These are the practical requirements a clean application has to show.

Responsible officers
2 per activity
at least one an executive director, one in Hong Kong at all times
Paid-up capital
None prescribed
Types 4, 5, 6 and 9 with a condition not to hold client assets. Type 6 sponsor work needs HK$10,000,000 paid-up.
Liquid capital
HK$100,000
an FRR calculation, maintained every day
Timeline
15 weeks
SFC pledge once accepted; four to six months in practice
Fees
HK$4,740
per activity for the corporation; HK$2,950 per RO; HK$1,790 per representative

Responsible Officers

  • At least two ROs approved for each regulated activity; the same individuals can be approved for several
  • At least one an executive director, and at least one available in Hong Kong to supervise at all times
  • Type 9 ROs are expected to show experience exercising investment discretion, not only advisory or sales experience
  • ROs pass the local regulatory framework papers (HKSI Licensing Examination) unless exempt

RO experience routes

RouteEducationIndustry experienceManagement
1Relevant degree, or CFA, CIIA, CFP3 of last 6 years2 years
2HKDSE or HKCEE passes in Chinese or English and Maths5 of last 8 years2 years
3None8 of last 11 years2 years

Managers-In-Charge

Every licensed corporation names a manager for each of eight core functions: overall management oversight, key business line, operational control and review, risk management, finance and accounting, information technology, compliance, and AML/CFT. In a small firm the same individuals cover several. The MIC for overall management and for the key business line must be ROs. The IT MIC is the person the SFC will ask about everything on the IT and cyber rules tab.

Licensed representatives

Anyone else who performs the regulated activity (a trader, an analyst who makes investment decisions, an adviser who speaks to clients) needs a representative licence with its own competence and exam requirements. Back office and administration staff do not.

The application

What goes in

  • SFC forms for the corporation, ROs and representatives, plus the supplementary questionnaires, through the WINGS portal
  • Business plan: strategy, target clients, products, fee model, three year projections
  • Organisation chart, MIC allocation, CVs and licensing history for each RO
  • Compliance manual and description of the compliance function
  • Proof of capital: bank statements and an FRR computation
  • Office lease; the SFC approves business premises under section 130 of the SFO
  • Incorporation documents, business registration, shareholder and director details

Where IT appears

  • How systems, records and data will be kept and protected, and who the IT MIC is
  • Where regulatory records will be stored: a firm keeping records only in the cloud has to deal with the EDSP circular before the licence is granted, because storage location is part of the premises approval
  • Business continuity arrangements

This is the earliest point at which an IT provider can help. Getting the tenant, records and MIC arrangements right before submission avoids requisitions later.

How PTS helps

Pre-licensing IT set-up

  • Design the Microsoft 365 tenant, device standard and record keeping to satisfy the EDSP circular and the application questions from day one
  • Draft the proportionate IT and security policy, business continuity plan and provider agreement the application refers to
  • Provide the IT section of the business plan and answer SFC requisitions on technology
  • Set up the reporting the IT MIC will need once licensed

Ongoing obligations

Showing for Type 9

Holding the licence is a continuous set of filings, notifications and standards. This is the rhythm for a firm with a 31 December year end.

Annual return
1 month
after the licence anniversary, with the annual fee
Audited accounts
4 months
after year end, with the FRR audit, BRMQ and ADD
FRR returns
Half-yearly
firms with the no-client-assets condition
Notify changes
7 business days
directors, MICs, ROs, business nature, bank accounts, auditor
CPT
10 / 12 hours
per year for licensed individuals and ROs
Within 1 month of anniversary
Annual return and annual feeFiled through WINGS. Confirms particulars, MICs and that CPT was met. Late filing risks the licence.
Within 4 months of year end
Audited accounts, auditor's FRR report, BRMQ and ADDFor a December year end that is 30 April. The Business and Risk Management Questionnaire asks directly about IT, cybersecurity and business continuity.
Every 6 months
FRR financial returnLiquid capital must be maintained every day, not only at the filing date. Notify the SFC if it falls below 120% of the requirement.
Within 7 business days
Notify changesDirectors, shareholders, MICs, ROs leaving, business nature, bank accounts, auditor, complaints officer, emergency contact. Address changes need 7 business days' notice before the move.
By 31 December
Continuous professional trainingAt least 10 CPT hours per licensed individual, 12 for ROs including two on regulatory compliance. New entrants add 2 hours of ethics. Records kept for at least three years. Cybersecurity awareness training counts where relevant to the role.
Annually, around April
Asset and Wealth Management Activities SurveyPlus any thematic questionnaires the SFC circulates.
Immediately
Material incidents and breachesCyber incidents, system failures, breaches, liquid capital shortfalls and material complaints are reported to the SFC as soon as the firm becomes aware. See the Incidents tab.
Continuous
Standards of conductCode of Conduct, Fund Manager Code of Conduct, Internal Control Guidelines, AML/CFT Guideline, Keeping of Records Rules (most records seven years), PDPO. Licence displayed at the office. An RO supervising at all times.
How PTS helps

Turning obligations into a calendar

  • A quarterly IT report to the MIC that lines up with the annual return, the BRMQ and the audit
  • Monthly patch, backup and access evidence so the BRMQ answers are true and provable
  • Retention and audit logging set to the seven year record keeping standard
  • Annual training and testing scheduled so CPT and the technical review land before year end

IT and cybersecurity rules

Showing for Type 9

There is no single SFC IT rulebook. The expectations are spread across the codes and a series of circulars. Each instrument below is marked applies, consider or hidden, based on your selection. For a narrative walk-through of the cybersecurity instruments, see our guide to the SFC cybersecurity requirements for Hong Kong fund managers.

The principle behind all of it

Outsourcing IT does not outsource responsibility. The SFC's cybersecurity review report says it plainly: firms can outsource the implementation of controls to third party providers, but senior management remains responsible for overall management and supervision. Every instrument below assumes the firm can show that supervision happened.

Applies to your firm

Code of Conductapplies

Code of Conduct for Persons Licensed by or Registered with the SFC

The general rulebook. General Principle 7 and paragraph 4.3 require internal controls, resources and operational capability that protect the firm and its clients. Paragraph 12.5 requires immediate reporting of material incidents, and 12.5(e) names cybersecurity incidents. Paragraph 5 (know your client and suitability) drives the advice records for Types 4 and 5.

ICGapplies

Management, Supervision and Internal Control Guidelines

Management oversight, segregation of duties, information management, operational controls, record keeping and contingency planning, applied in proportion to the firm. The SFC's 2025 inspections flagged management review, segregation of duties, information management and audit trails as the most common weaknesses.

FMCC · 5th editionapplies

Fund Manager Code of Conduct

Applies to Type 9 firms managing funds and, in part, discretionary accounts. Organisation and resources, risk management, custody, valuation, liquidity and leverage, conflicts, disclosure, record keeping, business continuity and data security. The SFC's October 2024 circular on private fund management deficiencies (conflicts, valuation, risk disclosure) is the live inspection theme.

19EC59 · Oct 2019 · FAQs Dec 2020applies

Circular on the Use of External Electronic Data Storage Providers (EDSP)

Applies whenever regulatory records (trade, client, accounting records, communications) are kept with a cloud or third party provider, which for a Microsoft 365 firm is always. Due diligence on the provider, an audit trail of who accessed or changed records, records reproducible at approved premises promptly and in full, and, where records are kept exclusively in the cloud, an SFC notice and undertaking from the provider plus two named Managers-In-Charge in Hong Kong with full access.

20EC37 · Apr 2020applies

Circular on Management of Cybersecurity Risks Associated with Remote Office Arrangements

Strong VPN or equivalent secure remote access, strong passwords plus two-factor authentication, extra controls on privileged accounts, tiered access for corporate versus personal devices, secure video conferencing, staff awareness training and alerts, detection of unauthorised access and an incident reporting mechanism.

21EC41 · Oct 2021applies

Circular and Report on Operational Resilience and Remote Working

The SFC's observations on hybrid working: business continuity plans that cover remote operation, dependence on third party providers, supervision of staff at home, and record keeping of communications on personal devices and messaging apps.

SFO/IS/004/2025 · 6 Feb 2025applies

Circular and Report on the Cybersecurity Review of Licensed Corporations

Eight material incidents reported between 2021 and 2024, including two ransomware attacks. Half of respondents ran end-of-life operating systems. Expectations with immediate effect: disable unnecessary ports and review access lists, an annual technical review including vulnerability scanning and penetration testing endorsed by management, security patches within one month of testing, encryption at rest and in transit, need-to-have access with restricted administrator accounts, audit logs retained and reviewed, policies for third party IT providers, and contingency plans that cover cyber scenarios. Firms with client accounts must monitor them for unauthorised access and move away from SMS one-time passwords.

AML/CFT Guidelineapplies

Guideline on Anti-Money Laundering and Counter-Financing of Terrorism

Client due diligence, source of wealth and funds, screening, transaction monitoring, record keeping and a named AML Manager-In-Charge. The KYC files are also the firm's most sensitive personal data, so the AML programme and the data protection controls have to be designed together.

PDPOapplies

Personal Data (Privacy) Ordinance

Every client or investor KYC file is personal data. Data Protection Principle 4 requires practicable security safeguards. Breach notification to the Privacy Commissioner is currently voluntary, but the PCPD expects it as soon as practicable and the SFC expects the firm to have decided its position in advance.

Consider and document

Guidelines · Oct 2017consider

Guidelines for Reducing and Mitigating Hacking Risks Associated with Internet Trading

Twenty baseline controls: two-factor authentication for client login, encryption, one-month patching, daily offline backups, annual staff training, monitoring, and more. Mandatory for any firm whose clients can place orders or transact online. For every other firm the SFC treats them as the benchmark of what reasonable looks like, and the July 2026 Luk Fook enforcement case was built on them.

24EC55 · Nov 2024consider

Circular on the Use of Generative AI Language Models

Four core principles: senior management oversight, AI model risk management, cybersecurity and data protection, and third party risk management. Using AI to produce investment recommendations, advice or research is a high risk use case that needs human review and client disclosure, and may need notification to the SFC. Advisory licences are directly in scope.

26EC32 · 2 Jun 2026consider

Circular on Enhanced Cybersecurity Measures to Address AI-enabled Cyberattacks

Five areas: patching and vulnerability management with a route for urgent fixes; least privilege access, segmentation and maker-checker on high impact actions; detection, monitoring and threat intelligence; third party and supply chain governance; and incident response and recovery including tabletop exercises, backups and prompt SFC notification. Electronic trading firms and large brokers must implement all of it; every other licensed corporation must consider each area in proportion to its size and exposure, and be able to show that it did.

Market sounding guidelines · 2025consider

Guidelines for Market Soundings

Controls on the handling of confidential information when sounding out investors ahead of a placement: authorised personnel, information barriers, recording of communications, and a documented process. Corporate finance advisers are the disclosing side; fund managers that receive soundings are the recipient side and need their own handling controls.

What an SFC inspector asks a small firm

  • Who is the IT MIC and what do they actually review?
  • Where are regulatory records stored and who can produce them?
  • Show me the agreement with your IT provider and what it makes them responsible for
  • Show me MFA is on for everyone, and the last admin access review
  • When was the last backup restore test? The last patch report? The last staff training?
  • What would you do if your email were compromised tomorrow, and who would you tell?
Enforcement reference point

On 28 July 2026 the SFC fined Luk Fook Securities HK$2.1 million over a 2022 ransomware attack that exploited an unpatched vulnerability, citing network security, outdated systems, weak access control, insufficient remote access restriction, limited staff training and poor backup and continuity planning. No client lost money. Self-reporting and cooperation reduced the penalty.

How PTS helps

Mapping the rules to your environment

  • A gap analysis against every instrument marked above, written in plain language for the ROs and the IT MIC
  • A signed consideration note for the June 2026 and February 2025 circulars, so the firm can show it considered each area
  • Configuration of Microsoft 365, devices and backup to the standards the circulars describe
  • The evidence trail an inspector or investor asks for, produced as part of normal service rather than reconstructed afterwards

Your IT roadmap

Showing for Type 9

The proportionate set of controls for your selection, each with the SFC expectation it answers. Tick what is already in place — the ticks stay in this browser only, and they build your maturity self-assessment on the Your assessment tab.

Governance

Identity and access

Devices and remote working

Email and data

Detection and response

People and third parties

See your assessment

How PTS helps

Delivering the roadmap

  • Phase 1: independent assessment against this list, with a prioritised roadmap and budget guidance, typically three weeks for a small firm
  • Phase 2: remediation, through your current provider or PTS managed IT, and staff awareness training with a signed record
  • Phase 3: penetration testing through PTS's external testing partner at a fixed price, once the gaps are closed
  • Ongoing: the quarterly MIC report, patching, backup, monitoring and access reviews that keep the ticks true

Your assessment

Showing for Type 9

Your selections and roadmap ticks, turned into a maturity picture you can keep, print, or send to PTS for a costed remediation plan. Nothing here leaves your browser unless you choose to send it.

Your firm
Type 9
no client assets · no online client access
Controls in place
0 of 26
0% of the proportionate roadmap for this combination
Maturity
Not yet assessed
tick the roadmap to build your picture
Two minutes on the roadmap makes this useful

Go to the Your IT roadmap tab and tick the controls your firm already has. This tab then scores your maturity by area, lists the specific gaps, and pre-fills the request below — so the conversation with PTS starts from your actual position, not a blank page. You can also send it as-is and we will start from a discovery call.

Opens your browser's print dialog — choose "Save as PDF". The report includes your profile, scores and gap list, and nothing is sent to PTS.

Send your assessment to PTS — get a costed remediation plan

We reply within two business days with a practical view of your gaps, what closing them costs, and the order we would do it in. No obligation, no sales deck. Your selections and ticks above are attached automatically.

Costed remediation plan · No obligation · Goes to our inbox, not a database

Evidence pack

Showing for Type 9

What your firm should be able to hand to an SFC inspector or an investor's operational due diligence team, on the technology side, within a day.

Documents
17
for this combination
Two audiences
SFC and investors
inspections look for supervision; due diligence looks for the same plus testing
Golden rule
Produced, not reconstructed
evidence generated by normal operations is credible; evidence assembled after a request is not
DocumentWhat it showsRefresh
IT and information security policyRules for devices, access, email, data, remote working and acceptable use, with RO approvalAnnual
IT MIC appointment and quarterly reportsWho is accountable for IT to the SFC and evidence that they reviewed the provider's reportsQuarterly
IT provider agreement and service reportsResponsibilities, security obligations, audit rights, evidence of supervisionQuarterly reports
Systems and asset registerDevices, cloud services, systems, owners, data heldQuarterly
Regulatory records and EDSP registerWhich records live where, provider due diligence and certifications, notice or undertaking if relying on exclusive cloud storage, the two MIC namesAnnual and on change
Access register and review logWho has access to what, admin roles, review sign-offTwice yearly
Patch and vulnerability reportPatch status against the one month standard, end-of-life softwareMonthly
Backup and restore test recordBackup coverage and a successful restoreBackup daily; test annually
Incident response plan and incident logSteps, contacts, SFC and PCPD reporting flow, record of every incident and near missAnnual; log continuous
Business continuity and DR planScenarios, recovery objectives, alternative working, test resultsAnnual test
Cybersecurity assessment and roadmapIndependent findings mapped to SFC expectations, remediation statusAnnual
Penetration test reportExternal and Microsoft 365 testing, findings and closureAnnual or after major change
Training deck and signed training recordTopics mapped to SFC references, attendee signatures, date, CPT hoursAnnual
Third party register and due diligence filesEvery provider touching firm data, risk rating, evidence reviewedAnnual
Generative AI policyApproved tools, prohibited inputs, human review, high risk use cases and any SFC notificationAnnual
Data protection policy and PICSHow personal data is collected, secured, retained and deletedAnnual
Circular consideration notesSigned notes for 26EC32, the Feb 2025 circular and 24EC55 stating what was done or why not applicableOn each new circular
How PTS helps

Building and maintaining the pack

  • The policy set, incident plan, continuity plan and provider agreement drafted to your size
  • Registers and reports generated from the live environment every month and quarter
  • An assessment report, training record and penetration test report that slot straight into investor due diligence questionnaires
  • A single shared evidence folder, permissioned for the ROs, the IT MIC and your compliance adviser

Incidents and reporting

Showing for Type 9

What happens when something goes wrong, and who has to be told. This is the part most small firms have never rehearsed.

SFC
Immediately
Code of Conduct 12.5(e) on becoming aware of a material cyber incident
PCPD
As soon as practicable
voluntary today; the PCPD suggests within five days
Counterparties
Same day
administrator, custodian, brokers, so instructions are verified
Mitigation
Self-report
treated as a mitigating factor in enforcement
SFC

Code of Conduct paragraph 12.5

A licensed corporation must report to the SFC immediately on becoming aware of a material breach, a material failure of systems or controls, or a material cybersecurity incident. Material includes anything that affects clients, records, the ability to operate, or confidence in the firm. A compromised mailbox that handled client instructions is material. The ROs make the call and follow up with a written account and remediation plan.

Others

Who else may need to know

  • The fund administrator, custodian, prime broker or exchange, so they can hold or verify instructions
  • Clients or investors whose data or instructions are affected
  • Insurers, where cyber or professional indemnity cover exists
  • Hong Kong Police for fraud or extortion
  • Auditors, where records or financial controls are affected
Sequence

The first 24 hours

  • Contain: isolate the device, revoke sessions, reset credentials, block forwarding rules
  • Preserve: keep logs and the affected mailbox; do not wipe before evidence is captured
  • Assess: what data, which clients, which instructions could have been affected
  • Notify: ROs decide on SFC and PCPD reporting; counterparties told to verify instructions
  • Record: timeline, decisions, who was told and when
  • Recover and learn: restore, close the gap, update the plan, brief staff
Rehearse

The tabletop exercise

The June 2026 circular expects regular testing of incident response through tabletop exercises and simulated attacks. For a small firm that is a one hour walk-through of a realistic scenario once a year: a compromised mailbox, a fraudulent redemption instruction, ransomware on a laptop, or the administrator's portal going down during a dealing day. The output is a short record of what worked, what did not and what changed.

Do not wait for certainty

The SFC has treated late reporting as an aggravating factor and self-reporting as a mitigating one. A firm that reports "we believe a mailbox was compromised and are investigating" is in a far better position than one that reports a confirmed loss three weeks later.

How PTS helps

Before, during and after an incident

  • A written incident response plan with the SFC and PCPD reporting flow and a contact sheet the ROs keep off the network
  • An annual tabletop exercise facilitated by PTS, with the record the June 2026 circular expects
  • Incident response support: containment, evidence preservation, recovery from backup and the technical account the SFC will ask for
  • A post-incident review that closes the gap and updates the roadmap

Other licences

The full set of SFC regulated activities, and the non-SFC licences that firms of this kind sometimes hold. Select the ones you hold in the picker at the top to see what they add.

ActivityDescriptionWho holds itRelevance to a small manager
Type 1Dealing in securitiesBrokers, fund distributors, placing agents; managers marketing their own fundsCommon with Type 9
Type 2Dealing in futures contractsFutures brokers; managers executing listed derivativesPaired with Type 5
Type 3Leveraged foreign exchange tradingMargin FX dealersRare for fund managers
Type 4Advising on securitiesInvestment advisers, research, advisory mandatesMost common companion to Type 9
Type 5Advising on futures contractsAdvisers on futures and listed derivativesPaired with Type 2 or Type 9
Type 6Advising on corporate financeM&A advisers, IPO sponsors, boutique corporate financeOccasionally with Type 9
Type 7Providing automated trading servicesTrading platforms and matching enginesSpecialist
Type 8Securities margin financingMargin lendersRare for fund managers
Type 9Asset managementPrivate funds, hedge funds, discretionary accountsThe core licence
Type 10Providing credit rating servicesCredit rating agenciesSpecialist
Type 11Dealing in or advising on OTC derivative productsOTC derivatives dealers and advisersRegime being phased in
Type 12Providing client clearing services for OTC derivative transactionsClearing membersRegime being phased in
Type 13Providing depositary services for relevant CISTrustees and custodians of SFC-authorised fundsIn force since October 2024

Outside the SFC

Virtual assets

Managers running virtual asset strategies stay under Type 9 with additional SFC conditions and expectations (custody with licensed platforms, cold storage, multi-signature controls). Operating a trading platform needs the separate virtual asset trading platform licence, with the full internet trading and June 2026 circular obligations.

Trust or Company Service Provider

Licensed by the Companies Registry. Held by firms that administer structures or act as company secretary for clients. Brings its own AML and record keeping obligations.

Money Lenders Ordinance

Firms that lend, including private credit strategies that lend directly rather than through a fund vehicle, may need a money lender's licence from the Companies Registry.

Insurance Authority and MPFA

Anyone selling insurance-linked products needs Insurance Authority registration; MPF intermediaries register with the MPFA. Unusual for a fund manager but common in wealth management groups.

How PTS helps

When licences change

  • Re-baseline the IT obligations whenever a licence is added, because Type 1 or any online client access changes the rules that apply
  • Prepare the technology description and controls mapping the SFC asks for when a new regulated activity is added
  • Adjust records, monitoring and backup to the new activity before the first client is onboarded

Questions small firms ask

Showing for Type 9

Short answers for the questions that come up most. Some only appear for the licences you selected.

We are only two or three people. Does any of this really apply to us?

Yes. The SFC applies the same codes to every licensed corporation and scales its expectation by size and complexity, not by whether the rules apply. Its cybersecurity circulars are addressed to all licensed corporations. What changes for a small firm is depth: a short policy rather than a forty page one, a quarterly report from the provider rather than a security team.

Our IT is fully outsourced. Isn't the provider responsible?

The provider is responsible to you under its contract. You are responsible to the SFC. The SFC's review report says senior management remains responsible for overall management and supervision even when implementation is outsourced. Your IT Manager-In-Charge needs to be able to show that supervision happened, which is why PTS reports to the MIC quarterly in writing.

Do we need SFC approval to use Microsoft 365 or Google Workspace?

Not approval as such, but the EDSP circular applies. You need to have done due diligence on the provider, know where the data is held, keep retention and audit logs on, and decide whether you rely on exclusive cloud storage of regulatory records. If you do, you need the provider notice or undertaking arrangements and two named MICs in Hong Kong with full access.

Is MFA actually required?

The 2020 remote working circular expects two-factor authentication for staff logins, the February 2025 circular expects strong authentication and asks firms to move away from SMS one-time passwords, and the internet trading guidelines mandate it for client logins where clients transact online. A licensed corporation without MFA in 2026 would have no defence after an incident.

How quickly do we have to patch?

The February 2025 circular sets the standard at deployment within one month of completing testing for security patches, and expects end-of-life software to be removed. The June 2026 circular adds a route for urgent fixes outside the normal cycle.

Do we need a penetration test?

The February 2025 circular expects an annual technical review including vulnerability scanning and penetration testing, endorsed by management. For a small firm that means an external test of the internet-facing footprint and the Microsoft 365 tenant. If clients transact online, the portal and its APIs are tested too. PTS delivers testing through its external testing partner at a fixed price for a defined scope.

What do we have to do about AI?

Two things. Under the November 2024 circular, govern your own use: which tools, on which accounts, what must never be entered, and human review of anything that reaches a client. Advisory firms using AI for recommendations or research are in the high risk category. Under the June 2026 circular, consider the risk of AI-enabled attacks against you: deepfake voice and video, polished phishing and faster exploitation of vulnerabilities.

What counts as a reportable incident?

Under Code of Conduct 12.5 anything material: a compromised mailbox, ransomware, loss of a device with unencrypted data, a fraudulent payment, or a system failure that stops the firm operating. Report immediately on becoming aware, even before the facts are complete. Self-reporting is a mitigating factor in enforcement.

Does cybersecurity training count towards CPT?

It can, where the topic is relevant to the individual's role and the firm records it properly. ROs need 12 CPT hours a year including two on regulatory compliance; other licensed individuals need 10. PTS training sessions produce a signed record for the CPT log.

What is the IT Manager-In-Charge supposed to do?

Be the person the SFC holds accountable for IT. In practice: receive and read the provider's reports, sign off access reviews, own the incident plan, make sure the EDSP arrangements are in place, and be able to explain the firm's controls in an inspection. In a small firm this is usually a Responsible Officer, supported by the provider.

How long do we keep records?

Most records seven years under the Keeping of Records Rules, some two. Emails and messages containing orders, instructions or advice are records. Set Microsoft 365 retention to match and have a policy for personal messaging apps.

What will an SFC inspection ask for on IT?

The IT MIC and their reports, the provider agreement, where records are stored, MFA status, admin access and reviews, patching evidence, backup and restore tests, the incident plan, training records and the BCP. The Evidence pack tab is that list.

Is a separate backup of Microsoft 365 necessary if Microsoft already has copies?

Microsoft protects its platform, not your data against deletion, ransomware or a compromised administrator. The June 2026 circular expects regular backups as part of recovery, and the review report lists backup resilience as an area needing improvement. A separate backup with an annual restore test is the proportionate answer.

What happens if we do nothing?

Most likely nothing until something happens. Then the firm faces the SFC's question of whether controls were adequate, with the July 2026 Luk Fook decision as the reference point: a HK$2.1 million fine for control failures even without client loss. Investor due diligence is the nearer term cost: allocators walk away from firms that cannot evidence the basics.

How PTS helps

Ask us the one that is not here

  • A thirty minute conversation with a PTS consultant about your licences, your environment and where to start
  • No obligation and no sales deck; the answer is usually a short list of what to fix first

Glossary and sources

ADD
Accounting Disclosure Document, filed with the audited accounts.
BRMQ
Business and Risk Management Questionnaire, filed annually with the audited accounts.
CPT
Continuous Professional Training required of licensed individuals each calendar year.
EDSP
External Electronic Data Storage Provider: any cloud or third party that holds the firm's regulatory records.
FMCC
Fund Manager Code of Conduct.
FRR
Securities and Futures (Financial Resources) Rules.
ICG
Management, Supervision and Internal Control Guidelines.
MIC
Manager-In-Charge of a core function.
PCPD
Office of the Privacy Commissioner for Personal Data.
PDPO
Personal Data (Privacy) Ordinance.
RO
Responsible Officer.
SFO
Securities and Futures Ordinance (Cap. 571).
WINGS
The SFC's online portal for licensing applications, filings and notifications.

Sources

  1. SFC, Circular 26EC32, Enhanced cybersecurity measures to address evolving risks arising from AI-enabled cyberattacks, 2 June 2026. apps.sfc.hk
  2. SFC, Circular SFO/IS/004/2025, Cybersecurity review of licensed corporations, 6 February 2025. apps.sfc.hk
  3. SFC, Report on the 2023/24 thematic cybersecurity review of licensed corporations, February 2025. sfc.hk
  4. SFC, Circular 24EC55, Use of generative AI language models, November 2024. apps.sfc.hk
  5. SFC, Circular 19EC59, Use of external electronic data storage, 31 October 2019, and FAQs, December 2020.
  6. SFC, Circular 20EC37, Management of cybersecurity risks associated with remote office arrangements, 29 April 2020.
  7. SFC, Circular 21EC41, Operational resilience and remote working, October 2021. apps.sfc.hk
  8. SFC, Guidelines for Reducing and Mitigating Hacking Risks Associated with Internet Trading, October 2017.
  9. SFC enforcement, Luk Fook Securities (HK) Limited, HK$2.1 million, 28 July 2026. Gibson Dunn summary
  10. SFC, Ongoing obligations for licensed intermediaries. sfc.hk
  11. SFC, Fund Manager Code of Conduct, fifth edition. sfc.hk
  12. SFC, Guidelines on Continuous Professional Training, January 2022.
  13. Charltons, Applying to the SFC for a Type 9 (asset management) licence. charltonslaw.com
  14. Timothy Loh LLP, SFC License Type 9 FAQs. timothyloh.com
  15. Waystone Compliance, 2026 SFC compliance readiness checklist. compliance.waystone.com
  16. PTS, SFC cybersecurity requirements for Hong Kong fund managers.

This navigator is a technology and controls reference prepared by PTS Managed Services Limited. It is not legal or regulatory advice. Fees, capital thresholds and filing deadlines change; confirm them against the SFC's current publications or your compliance adviser. References current at 26 August 2026.

Call Request a proposal