PTS Managed Services · Hong Kong
The SFC licence navigator for small fund managers and advisers
Choose the regulated activities your firm holds or is applying for. The navigator shows what the SFC expects of a firm like yours, what that means for your technology and cybersecurity, and the proportionate way to get there — then turns your answers into a maturity self-assessment you can keep as a PDF or send to PTS.
Two switches change the answer more than any licence type: holding client assets raises the capital bar and brings the client asset rules in; any online client access brings the SFC's internet trading guidelines into scope.
What your combination means
Showing for Type 9Every licensed corporation lives under the Code of Conduct, the Internal Control Guidelines and the SFC's cybersecurity circulars. Each regulated activity then adds its own obligations. Here is what your selection adds, and what it means for your technology.
Managers of private funds, hedge funds and discretionary accounts. The core licence for a small fund manager.
What it adds: The Fund Manager Code of Conduct: risk management, custody arrangements, valuation, liquidity, conflicts, disclosure, record keeping and business continuity. HK$100,000 liquid capital without client assets.
For your IT: Where regulatory records live in the cloud (the EDSP circular), backup and continuity for the portfolio and investor data, and payment fraud controls around subscriptions and redemptions.
PTS has operated in Hong Kong for over 25 years, holds ISO/IEC 27001 and ISO/IEC 20000 certifications, is independent of all vendors, and works with professional and financial services firms that face the same expectations as large institutions with a fraction of the headcount.
A proportionate starting point for Type 9
- An independent IT and cybersecurity assessment mapped to the instruments that apply to your licences, with a prioritised roadmap and budget guidance
- Remediation of the gaps, either through your existing provider or through PTS managed IT
- Staff awareness training that produces a signed training record for your compliance pack
- Penetration testing through PTS's external testing partner at a fixed price for a defined scope
- Quarterly reporting to your IT Manager-In-Charge so supervision is evidenced, not assumed
Getting licensed
Showing for Type 9The SFC tests the corporation and its people against a fit and proper standard: financial status, competence, ability to act honestly and fairly, and reputation. These are the practical requirements a clean application has to show.
Responsible Officers
- At least two ROs approved for each regulated activity; the same individuals can be approved for several
- At least one an executive director, and at least one available in Hong Kong to supervise at all times
- Type 9 ROs are expected to show experience exercising investment discretion, not only advisory or sales experience
- ROs pass the local regulatory framework papers (HKSI Licensing Examination) unless exempt
RO experience routes
| Route | Education | Industry experience | Management |
|---|---|---|---|
| 1 | Relevant degree, or CFA, CIIA, CFP | 3 of last 6 years | 2 years |
| 2 | HKDSE or HKCEE passes in Chinese or English and Maths | 5 of last 8 years | 2 years |
| 3 | None | 8 of last 11 years | 2 years |
Managers-In-Charge
Every licensed corporation names a manager for each of eight core functions: overall management oversight, key business line, operational control and review, risk management, finance and accounting, information technology, compliance, and AML/CFT. In a small firm the same individuals cover several. The MIC for overall management and for the key business line must be ROs. The IT MIC is the person the SFC will ask about everything on the IT and cyber rules tab.
Licensed representatives
Anyone else who performs the regulated activity (a trader, an analyst who makes investment decisions, an adviser who speaks to clients) needs a representative licence with its own competence and exam requirements. Back office and administration staff do not.
The application
What goes in
- SFC forms for the corporation, ROs and representatives, plus the supplementary questionnaires, through the WINGS portal
- Business plan: strategy, target clients, products, fee model, three year projections
- Organisation chart, MIC allocation, CVs and licensing history for each RO
- Compliance manual and description of the compliance function
- Proof of capital: bank statements and an FRR computation
- Office lease; the SFC approves business premises under section 130 of the SFO
- Incorporation documents, business registration, shareholder and director details
Where IT appears
- How systems, records and data will be kept and protected, and who the IT MIC is
- Where regulatory records will be stored: a firm keeping records only in the cloud has to deal with the EDSP circular before the licence is granted, because storage location is part of the premises approval
- Business continuity arrangements
This is the earliest point at which an IT provider can help. Getting the tenant, records and MIC arrangements right before submission avoids requisitions later.
Pre-licensing IT set-up
- Design the Microsoft 365 tenant, device standard and record keeping to satisfy the EDSP circular and the application questions from day one
- Draft the proportionate IT and security policy, business continuity plan and provider agreement the application refers to
- Provide the IT section of the business plan and answer SFC requisitions on technology
- Set up the reporting the IT MIC will need once licensed
Ongoing obligations
Showing for Type 9Holding the licence is a continuous set of filings, notifications and standards. This is the rhythm for a firm with a 31 December year end.
Turning obligations into a calendar
- A quarterly IT report to the MIC that lines up with the annual return, the BRMQ and the audit
- Monthly patch, backup and access evidence so the BRMQ answers are true and provable
- Retention and audit logging set to the seven year record keeping standard
- Annual training and testing scheduled so CPT and the technical review land before year end
IT and cybersecurity rules
Showing for Type 9There is no single SFC IT rulebook. The expectations are spread across the codes and a series of circulars. Each instrument below is marked applies, consider or hidden, based on your selection. For a narrative walk-through of the cybersecurity instruments, see our guide to the SFC cybersecurity requirements for Hong Kong fund managers.
Outsourcing IT does not outsource responsibility. The SFC's cybersecurity review report says it plainly: firms can outsource the implementation of controls to third party providers, but senior management remains responsible for overall management and supervision. Every instrument below assumes the firm can show that supervision happened.
Applies to your firm
Code of Conduct for Persons Licensed by or Registered with the SFC
The general rulebook. General Principle 7 and paragraph 4.3 require internal controls, resources and operational capability that protect the firm and its clients. Paragraph 12.5 requires immediate reporting of material incidents, and 12.5(e) names cybersecurity incidents. Paragraph 5 (know your client and suitability) drives the advice records for Types 4 and 5.
Management, Supervision and Internal Control Guidelines
Management oversight, segregation of duties, information management, operational controls, record keeping and contingency planning, applied in proportion to the firm. The SFC's 2025 inspections flagged management review, segregation of duties, information management and audit trails as the most common weaknesses.
Fund Manager Code of Conduct
Applies to Type 9 firms managing funds and, in part, discretionary accounts. Organisation and resources, risk management, custody, valuation, liquidity and leverage, conflicts, disclosure, record keeping, business continuity and data security. The SFC's October 2024 circular on private fund management deficiencies (conflicts, valuation, risk disclosure) is the live inspection theme.
Circular on the Use of External Electronic Data Storage Providers (EDSP)
Applies whenever regulatory records (trade, client, accounting records, communications) are kept with a cloud or third party provider, which for a Microsoft 365 firm is always. Due diligence on the provider, an audit trail of who accessed or changed records, records reproducible at approved premises promptly and in full, and, where records are kept exclusively in the cloud, an SFC notice and undertaking from the provider plus two named Managers-In-Charge in Hong Kong with full access.
Circular on Management of Cybersecurity Risks Associated with Remote Office Arrangements
Strong VPN or equivalent secure remote access, strong passwords plus two-factor authentication, extra controls on privileged accounts, tiered access for corporate versus personal devices, secure video conferencing, staff awareness training and alerts, detection of unauthorised access and an incident reporting mechanism.
Circular and Report on Operational Resilience and Remote Working
The SFC's observations on hybrid working: business continuity plans that cover remote operation, dependence on third party providers, supervision of staff at home, and record keeping of communications on personal devices and messaging apps.
Circular and Report on the Cybersecurity Review of Licensed Corporations
Eight material incidents reported between 2021 and 2024, including two ransomware attacks. Half of respondents ran end-of-life operating systems. Expectations with immediate effect: disable unnecessary ports and review access lists, an annual technical review including vulnerability scanning and penetration testing endorsed by management, security patches within one month of testing, encryption at rest and in transit, need-to-have access with restricted administrator accounts, audit logs retained and reviewed, policies for third party IT providers, and contingency plans that cover cyber scenarios. Firms with client accounts must monitor them for unauthorised access and move away from SMS one-time passwords.
Guideline on Anti-Money Laundering and Counter-Financing of Terrorism
Client due diligence, source of wealth and funds, screening, transaction monitoring, record keeping and a named AML Manager-In-Charge. The KYC files are also the firm's most sensitive personal data, so the AML programme and the data protection controls have to be designed together.
Personal Data (Privacy) Ordinance
Every client or investor KYC file is personal data. Data Protection Principle 4 requires practicable security safeguards. Breach notification to the Privacy Commissioner is currently voluntary, but the PCPD expects it as soon as practicable and the SFC expects the firm to have decided its position in advance.
Consider and document
Guidelines for Reducing and Mitigating Hacking Risks Associated with Internet Trading
Twenty baseline controls: two-factor authentication for client login, encryption, one-month patching, daily offline backups, annual staff training, monitoring, and more. Mandatory for any firm whose clients can place orders or transact online. For every other firm the SFC treats them as the benchmark of what reasonable looks like, and the July 2026 Luk Fook enforcement case was built on them.
Circular on the Use of Generative AI Language Models
Four core principles: senior management oversight, AI model risk management, cybersecurity and data protection, and third party risk management. Using AI to produce investment recommendations, advice or research is a high risk use case that needs human review and client disclosure, and may need notification to the SFC. Advisory licences are directly in scope.
Circular on Enhanced Cybersecurity Measures to Address AI-enabled Cyberattacks
Five areas: patching and vulnerability management with a route for urgent fixes; least privilege access, segmentation and maker-checker on high impact actions; detection, monitoring and threat intelligence; third party and supply chain governance; and incident response and recovery including tabletop exercises, backups and prompt SFC notification. Electronic trading firms and large brokers must implement all of it; every other licensed corporation must consider each area in proportion to its size and exposure, and be able to show that it did.
Guidelines for Market Soundings
Controls on the handling of confidential information when sounding out investors ahead of a placement: authorised personnel, information barriers, recording of communications, and a documented process. Corporate finance advisers are the disclosing side; fund managers that receive soundings are the recipient side and need their own handling controls.
What an SFC inspector asks a small firm
- Who is the IT MIC and what do they actually review?
- Where are regulatory records stored and who can produce them?
- Show me the agreement with your IT provider and what it makes them responsible for
- Show me MFA is on for everyone, and the last admin access review
- When was the last backup restore test? The last patch report? The last staff training?
- What would you do if your email were compromised tomorrow, and who would you tell?
On 28 July 2026 the SFC fined Luk Fook Securities HK$2.1 million over a 2022 ransomware attack that exploited an unpatched vulnerability, citing network security, outdated systems, weak access control, insufficient remote access restriction, limited staff training and poor backup and continuity planning. No client lost money. Self-reporting and cooperation reduced the penalty.
Mapping the rules to your environment
- A gap analysis against every instrument marked above, written in plain language for the ROs and the IT MIC
- A signed consideration note for the June 2026 and February 2025 circulars, so the firm can show it considered each area
- Configuration of Microsoft 365, devices and backup to the standards the circulars describe
- The evidence trail an inspector or investor asks for, produced as part of normal service rather than reconstructed afterwards
Your IT roadmap
Showing for Type 9The proportionate set of controls for your selection, each with the SFC expectation it answers. Tick what is already in place — the ticks stay in this browser only, and they build your maturity self-assessment on the Your assessment tab.
Governance
Identity and access
Devices and remote working
Email and data
Detection and response
People and third parties
Delivering the roadmap
- Phase 1: independent assessment against this list, with a prioritised roadmap and budget guidance, typically three weeks for a small firm
- Phase 2: remediation, through your current provider or PTS managed IT, and staff awareness training with a signed record
- Phase 3: penetration testing through PTS's external testing partner at a fixed price, once the gaps are closed
- Ongoing: the quarterly MIC report, patching, backup, monitoring and access reviews that keep the ticks true
Your assessment
Showing for Type 9Your selections and roadmap ticks, turned into a maturity picture you can keep, print, or send to PTS for a costed remediation plan. Nothing here leaves your browser unless you choose to send it.
Go to the Your IT roadmap tab and tick the controls your firm already has. This tab then scores your maturity by area, lists the specific gaps, and pre-fills the request below — so the conversation with PTS starts from your actual position, not a blank page. You can also send it as-is and we will start from a discovery call.
Send your assessment to PTS — get a costed remediation plan
We reply within two business days with a practical view of your gaps, what closing them costs, and the order we would do it in. No obligation, no sales deck. Your selections and ticks above are attached automatically.
Evidence pack
Showing for Type 9What your firm should be able to hand to an SFC inspector or an investor's operational due diligence team, on the technology side, within a day.
| Document | What it shows | Refresh |
|---|---|---|
| IT and information security policy | Rules for devices, access, email, data, remote working and acceptable use, with RO approval | Annual |
| IT MIC appointment and quarterly reports | Who is accountable for IT to the SFC and evidence that they reviewed the provider's reports | Quarterly |
| IT provider agreement and service reports | Responsibilities, security obligations, audit rights, evidence of supervision | Quarterly reports |
| Systems and asset register | Devices, cloud services, systems, owners, data held | Quarterly |
| Regulatory records and EDSP register | Which records live where, provider due diligence and certifications, notice or undertaking if relying on exclusive cloud storage, the two MIC names | Annual and on change |
| Access register and review log | Who has access to what, admin roles, review sign-off | Twice yearly |
| Patch and vulnerability report | Patch status against the one month standard, end-of-life software | Monthly |
| Backup and restore test record | Backup coverage and a successful restore | Backup daily; test annually |
| Incident response plan and incident log | Steps, contacts, SFC and PCPD reporting flow, record of every incident and near miss | Annual; log continuous |
| Business continuity and DR plan | Scenarios, recovery objectives, alternative working, test results | Annual test |
| Cybersecurity assessment and roadmap | Independent findings mapped to SFC expectations, remediation status | Annual |
| Penetration test report | External and Microsoft 365 testing, findings and closure | Annual or after major change |
| Training deck and signed training record | Topics mapped to SFC references, attendee signatures, date, CPT hours | Annual |
| Third party register and due diligence files | Every provider touching firm data, risk rating, evidence reviewed | Annual |
| Generative AI policy | Approved tools, prohibited inputs, human review, high risk use cases and any SFC notification | Annual |
| Data protection policy and PICS | How personal data is collected, secured, retained and deleted | Annual |
| Circular consideration notes | Signed notes for 26EC32, the Feb 2025 circular and 24EC55 stating what was done or why not applicable | On each new circular |
Building and maintaining the pack
- The policy set, incident plan, continuity plan and provider agreement drafted to your size
- Registers and reports generated from the live environment every month and quarter
- An assessment report, training record and penetration test report that slot straight into investor due diligence questionnaires
- A single shared evidence folder, permissioned for the ROs, the IT MIC and your compliance adviser
Incidents and reporting
Showing for Type 9What happens when something goes wrong, and who has to be told. This is the part most small firms have never rehearsed.
Code of Conduct paragraph 12.5
A licensed corporation must report to the SFC immediately on becoming aware of a material breach, a material failure of systems or controls, or a material cybersecurity incident. Material includes anything that affects clients, records, the ability to operate, or confidence in the firm. A compromised mailbox that handled client instructions is material. The ROs make the call and follow up with a written account and remediation plan.
Who else may need to know
- The fund administrator, custodian, prime broker or exchange, so they can hold or verify instructions
- Clients or investors whose data or instructions are affected
- Insurers, where cyber or professional indemnity cover exists
- Hong Kong Police for fraud or extortion
- Auditors, where records or financial controls are affected
The first 24 hours
- Contain: isolate the device, revoke sessions, reset credentials, block forwarding rules
- Preserve: keep logs and the affected mailbox; do not wipe before evidence is captured
- Assess: what data, which clients, which instructions could have been affected
- Notify: ROs decide on SFC and PCPD reporting; counterparties told to verify instructions
- Record: timeline, decisions, who was told and when
- Recover and learn: restore, close the gap, update the plan, brief staff
The tabletop exercise
The June 2026 circular expects regular testing of incident response through tabletop exercises and simulated attacks. For a small firm that is a one hour walk-through of a realistic scenario once a year: a compromised mailbox, a fraudulent redemption instruction, ransomware on a laptop, or the administrator's portal going down during a dealing day. The output is a short record of what worked, what did not and what changed.
The SFC has treated late reporting as an aggravating factor and self-reporting as a mitigating one. A firm that reports "we believe a mailbox was compromised and are investigating" is in a far better position than one that reports a confirmed loss three weeks later.
Before, during and after an incident
- A written incident response plan with the SFC and PCPD reporting flow and a contact sheet the ROs keep off the network
- An annual tabletop exercise facilitated by PTS, with the record the June 2026 circular expects
- Incident response support: containment, evidence preservation, recovery from backup and the technical account the SFC will ask for
- A post-incident review that closes the gap and updates the roadmap
Other licences
The full set of SFC regulated activities, and the non-SFC licences that firms of this kind sometimes hold. Select the ones you hold in the picker at the top to see what they add.
| Activity | Description | Who holds it | Relevance to a small manager |
|---|---|---|---|
| Type 1 | Dealing in securities | Brokers, fund distributors, placing agents; managers marketing their own funds | Common with Type 9 |
| Type 2 | Dealing in futures contracts | Futures brokers; managers executing listed derivatives | Paired with Type 5 |
| Type 3 | Leveraged foreign exchange trading | Margin FX dealers | Rare for fund managers |
| Type 4 | Advising on securities | Investment advisers, research, advisory mandates | Most common companion to Type 9 |
| Type 5 | Advising on futures contracts | Advisers on futures and listed derivatives | Paired with Type 2 or Type 9 |
| Type 6 | Advising on corporate finance | M&A advisers, IPO sponsors, boutique corporate finance | Occasionally with Type 9 |
| Type 7 | Providing automated trading services | Trading platforms and matching engines | Specialist |
| Type 8 | Securities margin financing | Margin lenders | Rare for fund managers |
| Type 9 | Asset management | Private funds, hedge funds, discretionary accounts | The core licence |
| Type 10 | Providing credit rating services | Credit rating agencies | Specialist |
| Type 11 | Dealing in or advising on OTC derivative products | OTC derivatives dealers and advisers | Regime being phased in |
| Type 12 | Providing client clearing services for OTC derivative transactions | Clearing members | Regime being phased in |
| Type 13 | Providing depositary services for relevant CIS | Trustees and custodians of SFC-authorised funds | In force since October 2024 |
Outside the SFC
Virtual assets
Managers running virtual asset strategies stay under Type 9 with additional SFC conditions and expectations (custody with licensed platforms, cold storage, multi-signature controls). Operating a trading platform needs the separate virtual asset trading platform licence, with the full internet trading and June 2026 circular obligations.
Trust or Company Service Provider
Licensed by the Companies Registry. Held by firms that administer structures or act as company secretary for clients. Brings its own AML and record keeping obligations.
Money Lenders Ordinance
Firms that lend, including private credit strategies that lend directly rather than through a fund vehicle, may need a money lender's licence from the Companies Registry.
Insurance Authority and MPFA
Anyone selling insurance-linked products needs Insurance Authority registration; MPF intermediaries register with the MPFA. Unusual for a fund manager but common in wealth management groups.
When licences change
- Re-baseline the IT obligations whenever a licence is added, because Type 1 or any online client access changes the rules that apply
- Prepare the technology description and controls mapping the SFC asks for when a new regulated activity is added
- Adjust records, monitoring and backup to the new activity before the first client is onboarded
Questions small firms ask
Showing for Type 9Short answers for the questions that come up most. Some only appear for the licences you selected.
We are only two or three people. Does any of this really apply to us?
Yes. The SFC applies the same codes to every licensed corporation and scales its expectation by size and complexity, not by whether the rules apply. Its cybersecurity circulars are addressed to all licensed corporations. What changes for a small firm is depth: a short policy rather than a forty page one, a quarterly report from the provider rather than a security team.
Our IT is fully outsourced. Isn't the provider responsible?
The provider is responsible to you under its contract. You are responsible to the SFC. The SFC's review report says senior management remains responsible for overall management and supervision even when implementation is outsourced. Your IT Manager-In-Charge needs to be able to show that supervision happened, which is why PTS reports to the MIC quarterly in writing.
Do we need SFC approval to use Microsoft 365 or Google Workspace?
Not approval as such, but the EDSP circular applies. You need to have done due diligence on the provider, know where the data is held, keep retention and audit logs on, and decide whether you rely on exclusive cloud storage of regulatory records. If you do, you need the provider notice or undertaking arrangements and two named MICs in Hong Kong with full access.
Is MFA actually required?
The 2020 remote working circular expects two-factor authentication for staff logins, the February 2025 circular expects strong authentication and asks firms to move away from SMS one-time passwords, and the internet trading guidelines mandate it for client logins where clients transact online. A licensed corporation without MFA in 2026 would have no defence after an incident.
How quickly do we have to patch?
The February 2025 circular sets the standard at deployment within one month of completing testing for security patches, and expects end-of-life software to be removed. The June 2026 circular adds a route for urgent fixes outside the normal cycle.
Do we need a penetration test?
The February 2025 circular expects an annual technical review including vulnerability scanning and penetration testing, endorsed by management. For a small firm that means an external test of the internet-facing footprint and the Microsoft 365 tenant. If clients transact online, the portal and its APIs are tested too. PTS delivers testing through its external testing partner at a fixed price for a defined scope.
What do we have to do about AI?
Two things. Under the November 2024 circular, govern your own use: which tools, on which accounts, what must never be entered, and human review of anything that reaches a client. Advisory firms using AI for recommendations or research are in the high risk category. Under the June 2026 circular, consider the risk of AI-enabled attacks against you: deepfake voice and video, polished phishing and faster exploitation of vulnerabilities.
What counts as a reportable incident?
Under Code of Conduct 12.5 anything material: a compromised mailbox, ransomware, loss of a device with unencrypted data, a fraudulent payment, or a system failure that stops the firm operating. Report immediately on becoming aware, even before the facts are complete. Self-reporting is a mitigating factor in enforcement.
Does cybersecurity training count towards CPT?
It can, where the topic is relevant to the individual's role and the firm records it properly. ROs need 12 CPT hours a year including two on regulatory compliance; other licensed individuals need 10. PTS training sessions produce a signed record for the CPT log.
What is the IT Manager-In-Charge supposed to do?
Be the person the SFC holds accountable for IT. In practice: receive and read the provider's reports, sign off access reviews, own the incident plan, make sure the EDSP arrangements are in place, and be able to explain the firm's controls in an inspection. In a small firm this is usually a Responsible Officer, supported by the provider.
How long do we keep records?
Most records seven years under the Keeping of Records Rules, some two. Emails and messages containing orders, instructions or advice are records. Set Microsoft 365 retention to match and have a policy for personal messaging apps.
What will an SFC inspection ask for on IT?
The IT MIC and their reports, the provider agreement, where records are stored, MFA status, admin access and reviews, patching evidence, backup and restore tests, the incident plan, training records and the BCP. The Evidence pack tab is that list.
Is a separate backup of Microsoft 365 necessary if Microsoft already has copies?
Microsoft protects its platform, not your data against deletion, ransomware or a compromised administrator. The June 2026 circular expects regular backups as part of recovery, and the review report lists backup resilience as an area needing improvement. A separate backup with an annual restore test is the proportionate answer.
What happens if we do nothing?
Most likely nothing until something happens. Then the firm faces the SFC's question of whether controls were adequate, with the July 2026 Luk Fook decision as the reference point: a HK$2.1 million fine for control failures even without client loss. Investor due diligence is the nearer term cost: allocators walk away from firms that cannot evidence the basics.
Ask us the one that is not here
- A thirty minute conversation with a PTS consultant about your licences, your environment and where to start
- No obligation and no sales deck; the answer is usually a short list of what to fix first
Glossary and sources
- ADD
- Accounting Disclosure Document, filed with the audited accounts.
- BRMQ
- Business and Risk Management Questionnaire, filed annually with the audited accounts.
- CPT
- Continuous Professional Training required of licensed individuals each calendar year.
- EDSP
- External Electronic Data Storage Provider: any cloud or third party that holds the firm's regulatory records.
- FMCC
- Fund Manager Code of Conduct.
- FRR
- Securities and Futures (Financial Resources) Rules.
- ICG
- Management, Supervision and Internal Control Guidelines.
- MIC
- Manager-In-Charge of a core function.
- PCPD
- Office of the Privacy Commissioner for Personal Data.
- PDPO
- Personal Data (Privacy) Ordinance.
- RO
- Responsible Officer.
- SFO
- Securities and Futures Ordinance (Cap. 571).
- WINGS
- The SFC's online portal for licensing applications, filings and notifications.
Sources
- SFC, Circular 26EC32, Enhanced cybersecurity measures to address evolving risks arising from AI-enabled cyberattacks, 2 June 2026. apps.sfc.hk
- SFC, Circular SFO/IS/004/2025, Cybersecurity review of licensed corporations, 6 February 2025. apps.sfc.hk
- SFC, Report on the 2023/24 thematic cybersecurity review of licensed corporations, February 2025. sfc.hk
- SFC, Circular 24EC55, Use of generative AI language models, November 2024. apps.sfc.hk
- SFC, Circular 19EC59, Use of external electronic data storage, 31 October 2019, and FAQs, December 2020.
- SFC, Circular 20EC37, Management of cybersecurity risks associated with remote office arrangements, 29 April 2020.
- SFC, Circular 21EC41, Operational resilience and remote working, October 2021. apps.sfc.hk
- SFC, Guidelines for Reducing and Mitigating Hacking Risks Associated with Internet Trading, October 2017.
- SFC enforcement, Luk Fook Securities (HK) Limited, HK$2.1 million, 28 July 2026. Gibson Dunn summary
- SFC, Ongoing obligations for licensed intermediaries. sfc.hk
- SFC, Fund Manager Code of Conduct, fifth edition. sfc.hk
- SFC, Guidelines on Continuous Professional Training, January 2022.
- Charltons, Applying to the SFC for a Type 9 (asset management) licence. charltonslaw.com
- Timothy Loh LLP, SFC License Type 9 FAQs. timothyloh.com
- Waystone Compliance, 2026 SFC compliance readiness checklist. compliance.waystone.com
- PTS, SFC cybersecurity requirements for Hong Kong fund managers.
This navigator is a technology and controls reference prepared by PTS Managed Services Limited. It is not legal or regulatory advice. Fees, capital thresholds and filing deadlines change; confirm them against the SFC's current publications or your compliance adviser. References current at 26 August 2026.