HKSI Paper 18: 60 Key Concepts and Study Guide (Version 1.0)

HKSI Paper 18, Regulation of Providing Depositary Services, covers the rules for safeguarding and overseeing the property of relevant collective investment schemes. It builds on the general regulatory knowledge assessed in Paper 1 and applies it to Type 13 depositaries, including licensed corporations and registered institutions.

Work through 60 concepts across the four public syllabus topics, with original examples and self-checks to help you apply each rule. Use the official Paper 18 study guide, currently version 1.0, alongside this article and confirm the version valid for your sitting.

40multiple-choice questions
60 minexamination time
70%pass mark

Exam format: HKSI examination overview . Latest published pass rate: 100.00% (Jul 2026) . A pass rate is a past result for a group of candidates, not your required score.

How to use these 60 concepts

  1. Work through the topics in the official order given here, since the syllabus is arranged so that earlier concepts (regulators, licensing, the Code of Conduct) underpin the later ones (Schedule 11, product codes, market misconduct). Tick each concept off only when you could explain it to a colleague in your own words.
  2. Read each concept alongside the current official source it comes from, such as the SFO and its subsidiary rules, the Code of Conduct and its Schedule 11, the Internal Control Guidelines, the UT Code, PRF Code, Code on REITs, OFC Code and the OTCD Reporting Rules. Check that you are studying against the current examinable study guide version before you begin.
  3. Use the four-stage study plan flexibly: shorten or lengthen each stage to fit your available weeks, but keep the sequence of reading, learning, practising questions and doing a final review, because recalling under exam-style conditions is what turns understanding into marks.

The practice examples are original and hypothetical unless explicitly identified as a published case. The concept count is a revision structure; it does not represent official question frequency or topic weighting.

Topic 1: General Regulatory Framework

The foundations every candidate needs: the key regulators and how they cooperate, the nature of Type 13 regulated activity and the depositary industry, licensing and registration, the Code of Conduct, open-ended fund companies, personal data, AML/CFT, corporate governance and SFC supervision and enforcement.

1. The SFC: objectives, guiding principles and statutory functions

The Securities and Futures Commission (SFC) is the statutory regulator of Hong Kong's securities and futures markets, established under the SFO. Its statutory objectives include maintaining a fair, efficient, competitive, transparent and orderly market, protecting the investing public, minimising crime and misconduct, reducing systemic risk, promoting public understanding of financial services, and assisting the Financial Secretary on financial stability. It exercises rule-making, supervisory and enforcement functions.

Example. A hypothetical depositary, GuardCo, mishandles fund units it safekeeps. The SFC can act on three fronts: issue or update rules, supervise GuardCo through inspections, and take disciplinary or enforcement action if breaches are found.

Watch out. Treating investor protection as the SFC's only objective. The SFC balances several objectives together; questions often test whether you know the full set rather than just one.

Self-check: can you list the SFC's statutory objectives without confusing investor protection with the whole set?

Answer: Yes - protection of the investing public is one of several objectives, alongside market integrity, transparency, public understanding, reducing crime and misconduct, reducing systemic risk and assisting the Financial Secretary.

2. The SFC's divisions and committees and what each does

The SFC organises its work into divisions with distinct mandates, such as corporate finance (listings, offers and takeovers), intermediaries (licensing, conduct and supervision of intermediaries including depositaries), enforcement (investigations and discipline), and supervision of markets. Committees, such as its advisory committee and the takeovers panels, support decision-making and specialist functions. Knowing which arm does what helps you predict who acts in a scenario.

Example. Assume GuardCo is registered as a Type 13 depositary. A conduct issue in its depositary business would primarily concern the intermediaries-side supervision, while a suspected market misconduct offence would be referred to the enforcement function.

Watch out. Attributing every SFC action to 'enforcement'. Routine supervision, licensing and rule-making are separate functions from enforcement investigations.

Self-check: which SFC arm would first supervise a registered depositary's ongoing conduct?

Answer: The intermediaries-supervision function, with enforcement engaged only if investigation reveals possible breaches requiring disciplinary or other action.

3. The HKMA, the MPFA and the Insurance Authority: their roles

The Hong Kong Monetary Authority (HKMA) promotes banking stability and is the front-line regulator of authorised institutions, including registered institutions carrying on SFC regulated activities. The Mandatory Provident Fund Schemes Authority (MPFA) regulates MPF retirement schemes, and the Insurance Authority (IA) regulates insurers and, in relevant respects, investment-linked products. Each has a distinct statutory mandate over its own sector.

Example. A hypothetical bank, SafeBank, is registered with the SFC to provide Type 13 depositary services. The HKMA oversees SafeBank's banking business day-to-day, while an MPF pooled fund it safekeeps falls under MPFA rules and an ILAS product under IA oversight.

Watch out. Assuming one regulator covers everything. A single bank depositary can face overlapping regimes from the HKMA, SFC, MPFA and IA simultaneously, each within its own mandate.

Self-check: who is the front-line supervisor of a bank's SFC regulated activities?

Answer: The HKMA, acting as front-line regulator for registered institutions, in cooperation with the SFC.

4. Regulatory cooperation where mandates overlap

Where a registered institution conducts regulated activities, the SFC and the HKMA share responsibilities: the HKMA handles day-to-day front-line supervision, while the SFC sets policy, rule-making and, where appropriate, takes direct action. The regulators exchange information and coordinate under their cooperation arrangements. Similar cooperation exists with the MPFA and the IA where products and mandates overlap.

Example. Hypothetically, the HKMA inspects SafeBank's depositary operations annually and flags a client-asset concern to the SFC. The SFC may then use its own supervisory or disciplinary powers, informed by the HKMA's findings, without duplicating the inspection.

Watch out. Thinking cooperation means either regulator stands down completely. Both retain their statutory powers; cooperation is about coordination, not exclusivity.

Self-check: in a scenario of overlapping supervision, what is the usual division of labour?

Answer: The HKMA performs day-to-day front-line supervision of registered institutions; the SFC sets regulatory policy and retains its own supervisory and enforcement powers.

5. Type 13 regulated activity: what a depositary actually does

Type 13 regulated activity under Schedule 5 of the SFO is 'providing depositary services for relevant CISs' - essentially safekeeping of relevant CIS property and related services, together with oversight of the scheme's operation in accordance with its scheme documents, such as holding assets, settling transactions, maintaining records and performing oversight duties. It was added to the regulated activity framework so that depositaries are subject to SFC regulation. Paper 18 examines the requirements attaching to this activity.

Example. Hypothetically, GuardCo holds units of an authorised fund for the fund, verifies the fund's valuation records and settles redemptions. Those safekeeping and oversight functions are the substance of its Type 13 business.

Watch out. Confusing the depositary with the fund manager. The manager invests the fund's assets; the depositary safekeeps them and performs independent oversight.

Self-check: is simply holding assets in a custody account enough to describe a depositary's role?

Answer: No - Type 13 depositary services also encompass related functions such as transaction settlement, record keeping and oversight duties, not mere asset holding.

6. Key participants, products and terminology in the depositary industry

The depositary industry involves participants such as funds and their managers, trustees, custodians, sub-custodians and delegates, and products including authorised collective investment schemes, open-ended fund companies, REITs and pooled retirement funds. Key terminology includes safekeeping, segregation, nominee arrangements, and delegation of functions. Precise use of these terms is essential because duties differ depending on the role a party plays.

Example. Hypothetically, GuardCo appoints SubCust Ltd in another jurisdiction to hold overseas shares. GuardCo remains responsible to the fund; SubCust acts as delegate. The fund, manager and investors are the other principal participants.

Watch out. Using 'custodian', 'trustee' and 'depositary' interchangeably. These roles carry different legal duties under the different product codes, so exam scenarios expect you to distinguish them.

Self-check: if a delegate fails, who owes duties to the fund?

Answer: The depositary - appointing a delegate does not transfer the depositary's own responsibilities to the fund or its investors.

7. General SFC regulations applicable to RA13 depositaries

Type 13 depositaries operate under the SFO, applicable subsidiary legislation and SFC codes, including Schedule 11 of the Code of Conduct. Start by identifying whether the depositary is a licensed corporation or a registered institution: subsidiary rules have their own scopes, and a bank also comes under HKMA prudential supervision. Do not assume the Financial Resources Rules apply to registered banks in the same way as licensed corporations.

Example. Hypothetically, SafeBank becomes a registered depositary. It must satisfy capital, client-asset, record-keeping and audit requirements under SFC subsidiary legislation, and observe the Code of Conduct and Internal Control Guidelines in its RA13 business.

Watch out. Believing banking registration alone suffices. Registration with the SFC brings a full set of SFC requirements that apply in addition to banking rules.

Self-check: name the layers of rules a registered depositary must follow.

Answer: The SFO, its subsidiary legislation (capital, client assets, client money, records, accounts and audit) and SFC codes and guidelines such as the Code of Conduct, Schedule 11 and the Internal Control Guidelines.

8. Part IV of the SFO: regulating offers of investments

Part IV of the SFO restricts offers of investments to the public unless the investment is authorised by the SFC or an exemption applies. This is why collective investment schemes offered to the Hong Kong public must obtain SFC authorisation, with the depositary playing a defined role in the authorised structure. Understanding the authorisation gate explains why depositary duties differ between authorised and unauthorised products.

Example. Hypothetically, a fund manager wants to offer its fund to the Hong Kong public. It must seek SFC authorisation, appointing an eligible depositary; offering an unauthorised fund to the public would breach the Part IV restriction unless an exemption applies.

Watch out. Assuming every investment offer needs authorisation. Part IV contains exemptions; the restriction applies to offers to the public that are not exempt or authorised.

Self-check: what is the basic rule on public offers under Part IV?

Answer: Offers of investments to the public are restricted unless the investment is SFC-authorised or an exemption applies.

9. Public open-ended fund companies: nature and the special provisions in Part IVA of the SFO

An open-ended fund company (OFC) is a fund structured as a corporate entity with variable capital, governed by Part IVA of the SFO and the OFC Rules. A public OFC is one offered to the retail public and must be authorised by the SFC, whereas private OFCs operate in the private placement space. The OFC structure gives investors the fund benefits of open-ended pooling within a company form with limited liability.

Example. Hypothetically, a manager converts a unit trust into a public OFC. Investors buy shares in the company; redemptions are met by cancelling shares and reducing capital, so the company is 'open-ended' despite being a corporation.

Watch out. Treating an OFC as just another company limited by shares. Its variable capital, share-cancellation mechanics and the Part IVA regime make it a distinctive fund vehicle.

Self-check: what distinguishes a public OFC from a private OFC?

Answer: A public OFC is offered to the retail public and requires SFC authorisation; a private OFC is placed privately and does not carry that authorisation requirement.

10. The OFC Rules: forming a public OFC

The Securities and Futures (Open-ended Fund Companies) Rules set out the mechanics of forming an OFC, including incorporation requirements, the role of directors, the requirement for a custodian, and the documents and approvals needed. For a public OFC, SFC authorisation under the applicable code is also required. Formation rules ensure the vehicle is set up with proper governance and asset custody from the outset.

Example. Hypothetically, a sponsor incorporates an OFC intending a retail offering. It must put in place a board of directors, appoint an eligible custodian, and obtain SFC authorisation before offering shares to the public.

Watch out. Forgetting that incorporation alone is insufficient for a retail offer. A public OFC additionally needs SFC authorisation under the relevant code.

Self-check: what structural appointments must an OFC have at formation?

Answer: A board of directors responsible for governance and a custodian to hold the OFC's assets, with authorisation obtained if the OFC is public.

11. The OFC Rules: operating and governing an OFC

Beyond formation, the OFC Rules govern ongoing operations: directors' duties and stewardship, share issues and cancellations reflecting subscriptions and redemptions, capital maintenance mechanics, meetings and member rights, and winding up. The custodian safeguards assets while directors oversee management, often delegating investment management. Depositaries and custodians interacting with OFCs must understand this division of responsibilities.

Example. Hypothetically, an OFC receives redemption requests. The directors authorise share cancellation, the custodian confirms asset availability, and capital reduces accordingly - illustrating how operation rules link directors, capital and custody.

Watch out. Assuming the custodian manages the OFC. Custody and management are distinct: directors govern, an investment manager may invest, and the custodian safekeeps assets.

Self-check: who is responsible for an OFC's governance?

Answer: The board of directors, supported by any manager and investment manager they appoint, while the custodian is responsible for safekeeping the assets.

12. Licensing and registration for Type 13

A corporation generally needs the appropriate SFC licence to carry on Type 13 business; an authorised financial institution uses the SFC registration route. The activity concerns depositaries at the top of the custodial chain for relevant SFC-authorised schemes, subject to the statutory scope and exclusions. A custody-related job title alone does not decide whether the activity is Type 13.

Example. Hypothetically, SafeBank, already an authorised institution under the Banking Ordinance, applies to the SFC for registration to conduct Type 13 depositary services, and is entered on the SFC's register as a registered institution.

Watch out. Saying a bank must obtain an SFC 'licence' for RA13. Authorised institutions use the registration route; licensed corporations are the separate, non-bank route.

Self-check: how does an authorised institution become an SFC-regulated depositary?

Answer: By registering with the SFC as a registered institution to carry on the regulated activity, remaining subject to HKMA front-line supervision alongside SFC requirements.

13. Relevant individuals: fitness and propriety and the HKMA register

Individuals who perform regulated functions for a registered institution are 'relevant individuals'. They do not need a separate SFC individual licence or registration, but they must be fit and proper to perform those functions and must be entered in the HKMA's register of relevant individuals. The SFC and HKMA share oversight of relevant individuals' fitness and propriety.

Example. Hypothetically, Ms Chan supervises SafeBank's depositary operations. She is a relevant individual: no separate SFC individual licence is needed, but she must satisfy fitness and propriety requirements and appear on the HKMA register.

Watch out. Calling relevant individuals 'exempted persons' or 'excluded persons'. Those are different legal concepts; the correct category for individuals at registered institutions performing regulated functions is 'relevant individual'.

Self-check: does a relevant individual need an SFC individual licence?

Answer: No - a relevant individual needs no separate SFC licence, but must be fit and proper and be entered in the HKMA register.

14. The Fit and Proper Guidelines in practice

The Fit and Proper Guidelines set out how the SFC assesses whether firms and individuals meet the fit and proper requirement, considering matters such as financial status, integrity, reputation, competence and past regulatory or disciplinary history. Fitness and propriety is continuous, not a one-off test at application. Adverse findings can affect both institutions and the relevant individuals within them.

Example. Hypothetically, Ms Chan was previously disciplined for mishandling client assets at a former employer. When SafeBank registers its RA13 business, that history is relevant to her fitness and propriety, even though the conduct predates her current role.

Watch out. Treating fitness and propriety as purely financial solvency. The assessment spans honesty, reputation, competence and track record, and applies on an ongoing basis.

Self-check: when does the fit and proper requirement apply?

Answer: Continuously - at application and throughout the period of registration or licensing, covering financial status, integrity, reputation, competence and disciplinary history.

15. The Guidelines on Competence and on Continuous Professional Training

The Guidelines on Competence set the qualifications, experience and local regulatory knowledge expected of persons performing regulated functions, while the Guidelines on Continuous Professional Training (CPT) require ongoing training to maintain and update competence. For registered institutions, these expectations apply to relevant individuals performing regulated functions. Keeping training records is part of demonstrating compliance.

Example. Hypothetically, SafeBank requires its depositary staff performing regulated functions to complete a specified amount of CPT each year, including training on regulatory changes, and retains completion records as evidence.

Watch out. Assuming competence is proven once at appointment and never revisited. CPT obligations exist precisely because competence must be maintained over time.

Self-check: why do two separate guidelines govern competence?

Answer: One sets the baseline competence needed to perform regulated functions; the CPT Guidelines ensure that competence is maintained and updated through ongoing training.

16. The Code of Conduct: the nine general principles

The Code of Conduct opens with nine numbered general principles: GP1 honesty and fairness; GP2 diligence; GP3 capabilities; GP4 information about clients; GP5 information for clients; GP6 conflicts of interest; GP7 compliance; GP8 client assets; and GP9 responsibility of senior management. The principles frame the detailed code paragraphs that follow. Breaches can lead to disciplinary consequences through the licensing route.

Example. Hypothetically, an examiner scenario describes a depositary giving clients incomplete fee information. That implicates GP5 (information for clients) and potentially GP1 (honesty and fairness), alongside the detailed code provisions on disclosure.

Watch out. Mislabeling the general principles - for example, calling GP3 'diligence' (that is GP2) or treating GP5 as client identification (that is GP4, information about clients). Memorise the correct pairings.

Self-check: which GP covers each of honesty and fairness, diligence, capabilities, client assets and senior management responsibility?

Answer: GP1 honesty and fairness; GP2 diligence; GP3 capabilities; GP8 client assets; GP9 responsibility of senior management.

17. Client assets and client information duties under the general principles

GP8 requires intermediaries to ensure client assets are promptly and properly accounted for and adequately safeguarded - central to any depositary, whose core business is safekeeping. GP4 is 'information about clients': the firm should seek from clients information about their financial situation, investment experience and investment objectives relevant to the services provided. Protecting the personal data collected is a separate matter governed by the Personal Data (Privacy) Ordinance, not by GP4. These principles are elaborated by detailed code provisions and, for depositaries, by the client securities and client money rules studied in Topic 2.

Example. Hypothetically, SafeBank holds fund units for clients. It must segregate and properly record those assets (GP8), while the security of the personal data it collected on onboarding is governed by the Personal Data (Privacy) Ordinance, with breaches risking regulatory action under the applicable regime.

Watch out. Keep the duties distinct: GP4 concerns obtaining relevant information about clients, GP8 concerns client assets, and the Personal Data (Privacy) Ordinance governs personal-data handling. For a depositary, also identify the relevant CIS as the customer for the applicable due-diligence analysis.

Self-check: which general principle covers seeking information about clients, which covers the assets a depositary holds, and which law governs a leak of client onboarding data?

Answer: GP4 (information about clients) covers seeking client information; GP8 (client assets) covers safekeeping of the assets; a leak of onboarding data is a Personal Data (Privacy) Ordinance matter, not a GP4 breach.

18. Conflicts of interest and responsibility of senior management

GP6 requires intermediaries to identify conflicts of interest between themselves and clients, or between clients, and to manage them fairly - for depositaries, potential conflicts can arise between the fund and the depositary group's other businesses. GP9 places primary responsibility for a firm's conduct and compliance on its senior management, who must establish and maintain adequate controls and culture. Both principles shape daily depositary operations.

Example. Hypothetically, GuardCo's parent also manages a fund for which GuardCo is depositary. GuardCo must identify and manage this conflict (GP6), and its senior management must ensure oversight systems actually detect it (GP9).

Watch out. Thinking senior management can delegate accountability. GP9 makes senior management responsible for the firm's compliance framework even where day-to-day tasks are delegated.

Self-check: who bears primary responsibility for a registered institution's compliance?

Answer: Its senior management, under GP9 - delegation of tasks does not delegate accountability.

19. The six data protection principles under the Personal Data (Privacy) Ordinance

The Personal Data (Privacy) Ordinance is built on six data protection principles: (1) collection for a lawful, directly related purpose by lawful and fair means with prescribed information; (2) accuracy and limited retention - data must be accurate, up to date and not kept longer than necessary; (3) use limited to the original purpose unless prescribed consent or exemption applies; (4) security of data; (5) openness and transparency about data policies; and (6) access and correction rights for data subjects.

Example. Hypothetically, GuardCo keeps former clients' identity documents for years 'just in case'. DPP2 requires deletion when retention is no longer necessary, so indefinite retention breaches the principle.

Watch out. Confusing DPP3 (use limitation) with DPP5 (openness). DPP3 restricts how data is used; DPP5 concerns transparency about the firm's data policies and practices.

Self-check: which principle stops a depositary reusing onboarding data for unrelated marketing, and which limits how long data is kept?

Answer: DPP3 (use limitation) restricts reuse for a new purpose without the prescribed consent or exemption; DPP2 (accuracy and retention) limits retention to what is necessary.

20. Key anti-money laundering and counter-terrorist financing legislation in Hong Kong

The core AML/CFT framework includes the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (AMLO), which sets customer due diligence and record-keeping requirements, together with the Drug Trafficking (Recovery of Proceeds) Ordinance, the Organized and Serious Crimes Ordinance and the United Nations (Anti-Terrorism Measures) Ordinance, which underpin the offence of dealing with criminal proceeds and terrorist-property controls. SFC-issued AML guidelines apply to SFC-regulated firms, including depositaries.

Example. Hypothetically, GuardCo suspects a client's fund subscriptions derive from fraud proceeds. The OSCO framework criminalises dealing with proceeds of indictable offences, and SFC AML guidelines require GuardCo to report the suspicion promptly.

Watch out. Treating AML law as a single statute. Exam questions expect you to know which ordinance performs which function - CDD standards, proceeds offences and terrorist-financing controls sit in different instruments.

Self-check: which legislation primarily sets CDD and record-keeping requirements?

Answer: The AMLO, supported by the SFC's AML guidelines for SFC-regulated firms, while the proceeds-of-crime and terrorism ordinances supply the underlying offences.

21. Customer due diligence, including identification and reliance on third parties

Customer due diligence (CDD) requires a firm to identify and verify the customer and, where applicable, beneficial owners, understand the purpose and intended nature of the relationship, and conduct ongoing monitoring. CDD must generally be completed before establishing the relationship, with prescribed circumstances allowing deferred completion and risk-based management. Firms may, within limits, rely on third parties to perform parts of CDD, but responsibility for its adequacy remains with the relying firm.

Example. Hypothetically, GuardCo onboards a corporate client: it verifies the company's existence, identifies the natural persons with ultimate control as beneficial owners, and monitors later transactions - relying on another intermediary's CDD only if the statutory conditions are met.

Watch out. Thinking reliance on a third party outsources responsibility. The relying institution remains responsible for ensuring the CDD standards are actually met.

Self-check: if GuardCo relies on a third party's CDD, who answers for deficiencies?

Answer: GuardCo - reliance does not transfer responsibility; the firm must ensure the third party's CDD meets the required standards.

22. The risk-based approach: spotting ML/TF risks and reporting suspicious transactions

The risk-based approach (RBA) means allocating AML/CFT resources according to assessed risk: higher-risk customers, products, channels or geographies receive enhanced measures, while lower-risk situations may receive simplified measures where permitted. Firms must maintain risk-assessment processes, controls and staff training. When suspicion of money laundering or terrorist financing arises, a suspicious transaction report must be filed with the Joint Financial Intelligence Unit; tipping off the customer is prohibited.

Example. Hypothetically, a client subscribes to fund units with layered transfers from unrelated third parties, inconsistent with its stated wealth. GuardCo's RBA flags this as high risk, it applies enhanced scrutiny and files an STR, without telling the client.

Watch out. Applying identical CDD to every client and calling it compliant. The RBA requires measures proportionate to assessed risk - uniform treatment is itself a deficiency.

Self-check: after filing an STR, what must staff never do?

Answer: Tip off the customer that a report has been or may be made - disclosure of that fact is prohibited.

23. Corporate governance: how senior management should direct and supervise a business

Good governance gives senior management clear responsibilities, effective oversight, independent control functions and reliable information about the business. Warning signs include unclear reporting lines, one person dominating decisions, unmonitored delegation and control staff who lack authority. Practise explaining how a control weakness could affect a fund and what management should do about it.

Example. Hypothetically, GuardCo's chief executive personally approves all exception dealings with no second line of review. Concentration of power, absent independent oversight and unclear reporting lines are classic governance deficiencies the SFC would criticise.

Watch out. Equating governance with paperwork. Board minutes and policies mean little if senior management does not genuinely supervise - effectiveness and independence of oversight are what count.

Self-check: name two governance strengths and two deficiencies you could spot in a scenario.

Answer: Strengths: clearly assigned responsibilities and an independent, empowered compliance function. Deficiencies: excessive concentration of decision-making in one person and weak or absent oversight of delegated functions.

24. How the SFC supervises the industry and exercises its enforcement powers

The SFC supervises intermediaries through routine and themed inspections, reviews of returns and information, and risk-based engagement, and can exercise investigative powers where concerns arise. Enforcement may lead to disciplinary sanctions through the licensing route or, for statutory contraventions, action as the law provides - civil and criminal routes have distinct elements and procedures and should not be conflated. Enforcement principles include acting fairly, proportionately and in the public interest.

Example. Hypothetically, an inspection reveals SafeBank kept incomplete client-asset records. The SFC may first require remediation through supervisory engagement, escalating to disciplinary action if the breach is serious or unremedied.

Watch out. Assuming every contravention is automatically a crime or that a code breach is itself a criminal offence. Civil, criminal and licensing-disciplinary routes are distinct, with different procedures and outcomes.

Self-check: what is the usual first step when supervision uncovers a record-keeping deficiency?

Answer: Supervisory engagement - typically requiring the firm to remediate - with escalation to disciplinary or enforcement action reserved for serious or unaddressed breaches.

Topic 2: RA13 Related Conduct Requirements

The ongoing conduct obligations that apply specifically to depositaries: notifications, capital, client securities and client money, record keeping, accounts and audit, Schedule 11 of the Code of Conduct and the Internal Control Guidelines.

25. Ongoing notification obligations for depositaries

A licensed or registered depositary has continuing notification duties. Identify the prescribed change, the relevant recipient and the applicable deadline rather than waiting for an annual filing. Some appointments require prior approval as well as notification; telling a regulator after the event does not automatically satisfy an approval requirement.

Example. Hypothetically, a depositary changes its office address. Staff identify and complete the required regulatory notifications within the applicable time instead of leaving the change for the next audit.

Watch out. Assuming notification duties apply only at the application stage. Ongoing notification is a continuing obligation, and missing a prescribed change can itself be a compliance failure.

Self-check: a depositary changes its registered office address. What should it do, and when?

Answer: Notify the SFC of the change within the time prescribed under the ongoing notification requirements, instead of waiting for a periodic filing.

26. Capital requirements under the Securities and Futures (Financial Resources) Rules

For a licensed corporation subject to the Financial Resources Rules, required capital must be maintained continuously. Monitor both the applicable paid-up share-capital requirement and required liquid capital. A shortfall calls for prompt action and the required notification; a registered bank follows its applicable prudential regime rather than simply adopting the same FRR test.

Example. Assume a depositary's required liquid capital is $5,000,000 and its current liquid capital falls to $4,500,000. The shortfall is $5,000,000 - $4,500,000 = $500,000, so it cannot simply wait for the next reporting date.

Watch out. Treating capital as an annual calculation. The requirement applies continuously, and a mid-month dip is still a shortfall against the assumed requirement.

Self-check: assume the requirement is $10,000,000 and capital is $9,200,000. What is the position?

Answer: There is a shortfall of $800,000 ($10,000,000 - $9,200,000); the firm must treat the FRR requirement as breached and notify and remedy it promptly.

27. Client securities: safekeeping under the Client Securities Rules

The Client Securities Rules are built on segregation and identification. Client securities must be held separately from the depositary's own assets and clearly identified as belonging to clients, with adequate records showing what is held and for whom.

Example. A depositary holds fund units for several CISs. It must keep those units distinguishable from its proprietary holdings and from each client's holdings, so any fund's assets can be identified at any time.

Watch out. Blending client securities with the firm's own holdings, even briefly, for convenience such as settling an internal position. Segregation is the core principle, not a housekeeping preference.

Self-check: may a depositary use securities held for one fund to cover a settlement obligation of another fund?

Answer: No. Client securities must remain segregated and identified; using one client's assets for another's obligation defeats the Client Securities Rules.

28. Client money: segregation under the Client Money Rules

For a Type 13 licensed corporation and its associated entity, the Client Money Rules apply to scheme money received or held in Hong Kong in the course of that activity. Segregate scheme money from the firm's operating money and apply the permitted account, payment and transfer arrangements. The specific scheme-money provisions and scheme documents matter; do not assume every custody arrangement uses an identical account structure.

Example. Assume subscription monies for a new fund arrive before units are issued. The depositary should place them in a designated client account and reconcile the balance, not park them in the firm's operating account.

Watch out. Depositing client money into the firm's own account 'just overnight'. Once commingled, the segregation and trust protections are compromised and the firm may breach the CMR.

Self-check: where must client money be kept, and what supporting practice keeps the account honest?

Answer: In segregated designated trust account(s) separate from firm money, supported by regular reconciliation of records and balances.

29. Record keeping requirements and retention under the Keep Records Rules

The Keep Records Rules require a depositary to make and keep business records that properly document its regulated activity, and to retain them for the prescribed retention period in a retrievable form. Good records underpin every other obligation, from client asset protection to audit.

Example. Assume a depositary processes custody instructions for a fund. It should retain the instruction records, confirmations and related correspondence so the full trail can be produced if the SFC or auditor asks.

Watch out. Deleting or archiving records too early, or keeping records that cannot be retrieved promptly. Retention runs for the prescribed period, and 'we can't find it' is not a defence.

Self-check: how long must records be kept, and in what condition?

Answer: For the prescribed retention period under the Keep Records Rules, in a form that remains complete and retrievable; check the rules rather than guessing a number.

30. Accounts and audit requirements under the Audit and Accounts Rules

A licensed corporation within the Audit and Accounts Rules must prepare and submit the prescribed audited accounts and other required reporting. Its management accounts do not replace these obligations. An independent audit provides assurance within its scope; it is not a guarantee that no error or misconduct exists. Identify the rules applicable to the entity and the reporting period.

Example. Hypothetically, a licensed depositary prepares monthly management accounts. It must still arrange the independent audit and regulatory submissions required by the Audit and Accounts Rules for its financial year.

Watch out. Believing well-kept internal accounts or management reports substitute for the audited accounts. The AAR specifically require independent audit and lodgement.

Self-check: what does the AAR add beyond ordinary internal bookkeeping?

Answer: Prescribed-form accounts audited by an independent auditor, lodged with the SFC within the prescribed time.

31. The Information Rules and associated entity rules where applicable

The Information Rules prescribe particulars and notification requirements for the persons within their scope. The Securities and Futures (Associated Entities - Notice) Rules deal with required notices about associated-entity relationships. An associated entity has a specific statutory meaning linked to receipt or holding of client assets; it does not mean every company in a financial group.

Example. Assume the SFC issues a notice asking a depositary for information about an associated entity in its group. The firm should respond through the applicable channel rather than treating the request as voluntary.

Watch out. Overlooking obligations that reach beyond the licensed entity itself. Group structure and associated entities can fall within the information-giving requirements where the rules apply.

Self-check: the SFC requests prescribed information about an associated entity. Is the depositary free to decline?

Answer: No. Where the Information Rules or associated entity rules apply, the firm must provide the required information as prescribed.

32. Schedule 11 of the Code of Conduct: why it matters to depositaries

Schedule 11 is the part of the Code of Conduct aimed at depositary and custody-type conduct. It sets out specific requirements on matters such as safekeeping and handling of client assets, complementing the statutory client asset rules with conduct-level expectations.

Example. Assume a depositary designs its custody procedures. Alongside the Client Securities Rules and Client Money Rules, it should map its procedures against Schedule 11's specific expectations for depositaries.

Watch out. Studying only the nine general principles and skipping Schedule 11. The syllabus singles Schedule 11 out for depositaries, so it needs its own attention.

Self-check: which part of the Code of Conduct specifically addresses depositary-relevant conduct requirements?

Answer: Schedule 11 to the Code of Conduct, which sits alongside the general principles and the statutory client asset rules.

33. Applying Schedule 11 to delegates and third parties engaged by depositaries

A depositary may engage delegates or third parties to perform activities relevant to its functions, but delegation does not transfer regulatory responsibility. The depositary must select delegates with due care, put proper arrangements in writing, and monitor their performance on an ongoing basis.

Example. Assume a depositary outsources its fund record-keeping to a service provider. It should assess the provider before appointment, document the arrangement, and review the provider's performance and controls afterwards.

Watch out. Thinking 'our delegate did it' shields the depositary. If a delegate mishandles client assets, the depositary remains answerable to the SFC for the function.

Self-check: a delegate mishandles fund assets. Who is accountable to the SFC?

Answer: The depositary remains responsible; it must have selected, documented and monitored the delegate properly under Schedule 11.

34. The Internal Control Guidelines: objectives and key areas of internal control

The Internal Control Guidelines (ICG) set out what the SFC expects a firm's internal control systems to achieve: safeguarding client assets, ensuring records are accurate, and ensuring compliance with regulatory requirements. They identify key areas of internal control, such as monitoring, risk management, segregation of duties, compliance and internal audit.

Example. Assume a depositary lets the same officer both approve custody transfers and update the records. Segregation of duties, an ICG key area, means these functions should be separated.

Watch out. Treating the ICG as vague background reading. The syllabus expects you to know the key areas of internal control and what each is meant to achieve.

Self-check: name the key areas of internal control identified under the ICG.

Answer: Areas such as monitoring, risk management, segregation of duties, compliance and internal audit, all directed at safeguarding assets and ensuring compliance.

35. Supervising the business: senior management duties under the ICG

Under the ICG, senior management bear overall responsibility for the business, including establishing and maintaining effective internal controls and a culture of compliance. They must allocate responsibilities clearly so accountability for each function is known.

Example. Assume a depositary's board approves a new custody outsourcing arrangement. Senior management should ensure controls, monitoring and clear allocation of who oversees the delegate are in place before it goes live.

Watch out. Assuming compliance failures are the compliance department's problem alone. The ICG place ultimate responsibility with senior management, who cannot delegate it away.

Self-check: who bears ultimate responsibility for a depositary's internal control system?

Answer: Senior management, who must direct the business, maintain effective controls and apportion responsibilities clearly under the ICG.

36. Bringing the conduct requirements together in day-to-day compliance

Topic 2's requirements work as one framework: notifications keep the SFC informed, capital rules keep the firm solvent, client asset rules protect clients, and records, audit, Schedule 11 and the ICG evidence and control it all. In practice, one business event can trigger several obligations at once.

Example. Assume a depositary launches depositary services for a new fund. It should check capital adequacy, client asset segregation, record keeping, any notifications, Schedule 11 duties and ICG controls as one integrated checklist.

Watch out. Studying each rule as an isolated silo and missing how they interact. Exam scenarios often describe one situation that engages several requirements simultaneously.

Self-check: a depositary appoints a new delegate. Which Topic 2 requirements interact here?

Answer: Schedule 11 selection and monitoring duties, ICG internal controls and segregation of duties, record keeping of the arrangement, and any applicable notification or information obligations.

Topic 3: RA13 Related Product Regulations

The product-specific codes a depositary must know: the SFC Handbook and the UT Code for authorised collective investment schemes, the OFC Code, the Code on REITs, the PRF Code and the over-the-counter derivative reporting regime.

37. The SFC Handbook for unit trusts, ILAS and unlisted structured investment products

The SFC Handbook brings together the codes governing three authorised product families: unit trusts and mutual funds (the UT Code, set out in Section II of the Handbook), investment-linked assurance schemes, and unlisted structured investment products. It sets authorisation criteria and ongoing conduct standards, including specific duties for depositaries and trustees of these products.

Example. Assume a bank acts as depositary for an authorised mutual fund and its parent insurer issues an ILAS policy investing into that fund. The Handbook's product-specific chapters tell the bank which duties apply to each role, so the compliance team maps obligations product by product rather than treating all authorised products alike.

Watch out. Treating the Handbook as one uniform rulebook. It consolidates separate product codes with different requirements, so a duty stated for unlisted structured investment products is not automatically a duty for unit trusts.

Self-check: which three product families does the SFC Handbook cover, and why must a depositary read the relevant chapter rather than the Handbook as a whole?

Answer: Authorised unit trusts and mutual funds, investment-linked assurance schemes, and unlisted structured investment products. Each chapter carries product-specific requirements, so the depositary must apply the chapter matching the product it serves.

38. Authorising a collective investment scheme: process and criteria

A CIS seeking public offering in Hong Kong must be authorised by the SFC under the Part IV offer regime. The SFC assesses whether the scheme, its operator, its depositary or trustee and its key documents meet the applicable code's criteria, covering fitness and propriety, disclosure quality, and investor protection arrangements.

Example. Assume a manager applies to authorise a new Asia bond fund. The SFC reviews the prospectus disclosures, the appointment of a qualifying depositary, valuation arrangements and the manager's fitness. Only after authorisation may the fund be offered to the Hong Kong public.

Watch out. Confusing SFC authorisation of a product with licensing of a firm. Authorisation approves the scheme for public offer; it does not license the manager or replace the depositary's own registration to conduct Type 13 regulated activity.

Self-check: what is the purpose of SFC authorisation of a CIS, and which parties' suitability does the SFC consider?

Answer: Authorisation permits public offering of the scheme in Hong Kong. The SFC considers the scheme's documents and the suitability of the operator, depositary or trustee and other key parties against the applicable code's criteria.

39. Depositary duties for authorised CISs under the UT Code

For authorised unit trusts and mutual funds, the depositary or trustee must safekeep scheme property, keep it segregated from its own assets, ensure dealings in scheme property are properly authorised, and perform oversight functions such as monitoring cash and supervising valuation. These duties exist to protect investors even when the manager runs the scheme day to day.

Example. Assume a fund manager instructs a transfer of fund shares to a counterparty. The depositary checks that the instruction is consistent with the trust deed and the UT Code before releasing the shares, and records the check. If the instruction looked unauthorised, the depositary should query it rather than process it.

Watch out. Thinking the depositary merely stores documents. Safekeeping, segregation, transaction verification and oversight are active duties; passive custody without monitoring can breach the UT Code.

Self-check: name the core functions a UT Code depositary performs for an authorised CIS.

Answer: Safekeeping and segregation of scheme property, verifying that dealings in scheme property are properly authorised, monitoring cash flows, and oversight duties including supervising valuation and acting in investors' interests.

40. Investment and borrowing restrictions for authorised CISs

The UT Code restricts what an authorised CIS may invest in and how much it may borrow, using concentration limits, eligible asset classes and borrowing caps to control risk. The depositary's oversight role includes monitoring whether the scheme stays within these restrictions and escalating breaches.

Example. Assume, purely hypothetically, a code limit of 10% of net asset value in any single issuer. A fund's holding in one issuer drifts to 11% of NAV after market moves. The depositary's monitoring flags the breach of the assumed limit, the manager rebalances, and the depositary documents the follow-up.

Watch out. Memorising numbers from memory without checking the current code text, or assuming the depositary sets the limits. The code sets the restrictions; the depositary monitors compliance with them.

Self-check: why do authorised CISs face investment and borrowing restrictions, and what is the depositary's role in relation to them?

Answer: The restrictions limit concentration and leverage risk to protect investors. The depositary does not set them but monitors the scheme's positions and borrowing against the code's requirements and escalates apparent breaches.

41. Ongoing authorisation requirements for authorised CISs

Authorisation is not a one-off event. The UT Code imposes ongoing requirements, including notifying the SFC of material changes, seeking approval for changes to key documents, meeting reporting and disclosure standards, and maintaining the conditions on which authorisation was granted. Failure to keep pace can jeopardise the authorisation.

Example. Assume an authorised fund wants to change its investment objective from equities to a balanced mandate. The manager must seek the necessary SFC approval and update the offering documents before marketing the new objective; the depositary should confirm the change is approved before acting on amended instructions.

Watch out. Assuming authorisation lasts forever once granted. Material changes generally need notification or approval, and ongoing obligations continue throughout the scheme's life.

Self-check: what kinds of ongoing obligations attach to an authorised CIS after authorisation?

Answer: Notifying or obtaining approval for material changes, keeping offering documents accurate, meeting periodic reporting and disclosure requirements, and continuing to satisfy the authorisation criteria on an ongoing basis.

42. The OFC Code: scope, purpose and who it protects

The Code on Open-Ended Fund Companies applies to OFCs, which are collective investment schemes structured as companies rather than unit trusts. The OFC Code sets authorisation and operational standards for OFCs, including the mandatory appointment of a custodian to safeguard scheme property, and its central purpose is investor protection.

Example. Assume a manager converts an authorised unit trust into a public OFC. The scheme keeps the same investment strategy but now has a corporate structure with a board, so the OFC Code's requirements, including custodian arrangements, apply alongside the SFO's Part IVA provisions.

Watch out. Mixing up the OFC Code with the OFC Rules. The SFO's Part IVA and the OFC Rules provide the legal framework for forming and operating OFCs, while the OFC Code sets the SFC's authorisation and conduct standards for them.

Self-check: what structure does an OFC take, what code governs its SFC authorisation standards, and who benefits from those standards?

Answer: An OFC is a corporate-form collective investment scheme. The OFC Code governs the SFC's authorisation and operational standards, and the standards primarily protect the OFC's investors.

43. Rights and obligations under the OFC Code

An OFC has separate shareholders, directors, an investment manager and a custodian. Shareholders exercise rights under the framework and constitutive documents; directors oversee the company; the investment manager manages its investments; and the custodian safeguards scheme property. A public OFC also has the applicable depositary oversight requirements. Distinguish public and private OFCs when applying the rules.

Example. Assume shareholders of a public OFC are unhappy with the board's performance. Under the OFC framework they may exercise their voting rights at a general meeting, while the depositary independently monitors the safekeeping of scheme assets regardless of the outcome of that vote.

Watch out. Assuming the depositary and the manager are interchangeable. The manager invests the assets; the depositary safekeeps them and provides independent oversight, and the OFC Code imposes distinct obligations on each.

Self-check: which parties hold rights and which owe obligations under the OFC framework, and how do the roles differ?

Answer: Shareholders hold rights such as voting; directors, the manager and the depositary owe obligations. The manager manages investments, the depositary safekeeps assets and oversees, and directors are responsible for the OFC's governance.

44. The Code on REITs: REIT structure and depositary responsibilities

A REIT authorised under the Code on REITs is a collective investment scheme that invests primarily in income-producing real estate, held through a trust structure with a manager and a trustee. The trustee performs depositary-type functions: safekeeping of the REIT's assets, oversight of the manager and monitoring compliance with the code, including restrictions on the REIT's activities and borrowing.

Example. Assume a REIT's manager proposes to acquire an office building and to increase borrowings to fund it. The trustee reviews whether the acquisition and the resulting leverage stay within the Code on REITs' requirements before the transaction proceeds, and documents its oversight.

Watch out. Treating a REIT like an ordinary listed company. A REIT is a trust-based CIS with a trustee, and property valuations and leverage are subject to code requirements, so company-law thinking alone misses the depositary's oversight duties.

Self-check: what does a REIT invest in, what structure holds it, and what does the trustee do under the Code on REITs?

Answer: A REIT invests primarily in income-producing real estate held through a trust. The trustee safekeeps the assets, oversees the manager and monitors compliance with the code, including activity and borrowing restrictions.

45. Pooled retirement funds and the PRF Code

Pooled retirement funds are collective investment vehicles used within the retirement scheme framework, and the PRF Code sets the standards applied to them, covering authorisation-type requirements, investment restrictions, valuation and the roles of the trustee or custodian and the investment manager. The depositary or custodian's duties mirror the investor-protection logic of the other product codes.

Example. Assume a retirement scheme trustee selects a pooled fund for scheme members. The PRF Code's requirements on asset segregation and valuation mean the fund's custodian must safekeep the pooled assets separately and ensure prices used for member accounts are properly determined.

Watch out. Assuming the PRF Code is identical to the UT Code. It is a separate code for the retirement-savings context, so requirements should be checked against the PRF Code itself rather than borrowed from the UT Code.

Self-check: what are pooled retirement funds, which code sets standards for them, and what role does the custodian play?

Answer: They are pooled vehicles used in the retirement scheme framework. The PRF Code sets their standards, and the custodian safekeeps the pooled assets, keeps them segregated and supports proper valuation for members' accounts.

46. The OTCD Reporting Rules: what depositaries must report

Hong Kong's OTC derivatives reporting and record-keeping rules require specified persons to report in-scope transactions to the SFC through a specified repository and retain the required records. A depositary must assess its own entity status, role in the transaction and any exemption. Merely safekeeping a fund's assets does not automatically make the depositary the reporting counterparty for every trade.

Example. Hypothetically, an entity acting as a depositary is also a specified person entering into an in-scope interest-rate swap. It captures the required information and arranges the applicable reporting and record keeping, rather than assuming the fund's reporting arrangements discharge its own obligations.

Watch out. Assuming reporting is only for dealers and trading desks. The obligation attaches to specified persons entering into or carrying out covered transactions, so a depositary must check its own status and transactions, not just its clients'.

Self-check: what three things must a reporting entity get right under the OTCD Reporting Rules?

Answer: Whether the transaction is a specified OTC derivative transaction within scope, whether it is a specified person obliged to report, and reporting the prescribed data to the SFC through a specified repository within the prescribed time.

47. Exemptions from over-the-counter derivative reporting

The OTCD Reporting Rules provide exemptions for defined categories of transactions, so not every OTC derivative transaction must be reported. A depositary should identify whether a transaction falls within an exemption before deciding its reporting position, and should document the basis for treating a transaction as exempt.

Example. Assume a depositary enters into a transaction that appears to fall within a defined exemption category in the Rules. Its compliance team records the exemption relied on, the analysis supporting it, and reviews the position if the transaction is amended, since a restructured trade may lose the exemption.

Watch out. Assuming an exemption is automatic or permanent. Exemptions apply to defined categories and depend on the transaction's facts, so any amendment or novation should trigger a fresh exemption analysis.

Self-check: how should a depositary handle a transaction it believes is exempt from OTC derivative reporting?

Answer: Confirm the transaction fits a defined exemption category in the Rules on its actual facts, document the analysis, report if the exemption does not apply, and re-assess if the transaction is later amended or restructured.

Topic 4: Misconduct

The market misconduct provisions of the SFO: the two civil and criminal routes and their safeguards, the Market Misconduct Tribunal, each of the six types of market misconduct, the consequences that follow, private civil actions and why the SFC enforces.

48. The two routes: MMT proceedings versus criminal prosecution

The SFO deals with market misconduct through two distinct routes. The civil route is a hearing before the Market Misconduct Tribunal (MMT), decided on the civil standard of proof and resulting in civil orders. The criminal route is a prosecution in the criminal courts, decided on the criminal standard and potentially resulting in conviction, imprisonment and fines.

Example. The SFC investigates a suspected insider deal. It could apply to the MMT for a civil finding, or refer the matter for possible criminal prosecution, depending on the evidence and circumstances.

Watch out. Assuming both routes automatically apply to the same person for the same conduct. The SFO contains safeguards (see the next concept) that prevent this double exposure.

Self-check: Which body hears civil market misconduct cases, and on what standard of proof?

Answer: The Market Misconduct Tribunal, on the civil standard (balance of probabilities).

49. Double-jeopardy safeguards under sections 283 and 307 of the SFO

Because the same conduct could theoretically attract both civil and criminal proceedings, the SFO builds in double-jeopardy safeguards. Section 283 protects a person who has been the subject of MMT findings from criminal prosecution for the same conduct, while section 307 operates where criminal proceedings have been brought, restricting the MMT route.

Example. The MMT finds Ms Chan engaged in insider dealing. Under the section 283 safeguard, she cannot then be criminally prosecuted for that same conduct.

Watch out. Saying a person can face both MMT proceedings and criminal prosecution for the same market misconduct. The sections 283 and 307 safeguards exist precisely to prevent that.

Self-check: What is the purpose of SFO sections 283 and 307?

Answer: To safeguard against a person facing both civil MMT proceedings and criminal prosecution for the same conduct.

50. The Market Misconduct Tribunal: its role and procedures

The MMT is an independent civil tribunal that hears applications from the SFC alleging market misconduct. It applies civil procedures and the civil standard of proof, decides whether market misconduct has occurred, and if so imposes civil orders (covered later in this topic). It is not a criminal court and cannot imprison anyone.

Example. The SFC applies to the MMT alleging false trading. The Tribunal reviews the evidence, makes a finding on the balance of probabilities, and issues appropriate civil orders.

Watch out. Describing the MMT as a criminal court, or assuming it can sentence offenders to imprisonment. Imprisonment only follows a criminal conviction in the courts.

Self-check: Can the MMT imprison a person it finds has engaged in market misconduct?

Answer: No. The MMT is a civil tribunal; only a criminal court conviction can result in imprisonment.

51. SFC investigation powers in market misconduct cases

The SFC investigates suspected market misconduct using powers such as requiring the production of records and information and questioning persons. After investigating, the SFC may apply to the MMT for civil proceedings; decisions on criminal prosecution rest with the Secretary for Justice, to whom matters may be referred.

Example. The SFC notices unusual pre-announcement trading in a listed fund's units, obtains trading records and interview responses, then applies to the MMT based on its findings.

Watch out. Saying the SFC itself conducts criminal prosecutions. It investigates and applies to the MMT; criminal prosecution is a separate decision and process.

Self-check: Who decides whether a market misconduct case proceeds to criminal prosecution?

Answer: The Secretary for Justice; the SFC investigates and may refer matters for prosecution.

52. Insider dealing: elements and the applicable standard of proof

Insider dealing broadly involves a person connected with a corporation dealing (or procuring someone else to deal) in its listed securities while holding inside information about it, or certain related conduct. Inside information is specific, not generally known, and would likely materially affect price if known. Before the MMT the case is proved on the civil standard; in a criminal prosecution, on the criminal standard.

Example. A depositary employee learns, through work, that a listed CIS is about to announce a merger, and buys units before the announcement.

Watch out. Claiming the civil route has no mental-state or element requirements at all. The applicable elements and the standard of proof differ between the MMT and criminal routes, and both must be satisfied as applicable.

Self-check: What standard of proof applies to insider dealing alleged before the MMT?

Answer: The civil standard, on the balance of probabilities.

53. False trading: creating a false or misleading appearance with intention or recklessness

False trading covers doing anything with the intention that, or being reckless as to whether, it creates or is likely to create a false or misleading appearance of active trading in, or with respect to the market for or price of, securities. The SFO also contains statutory deeming provisions (for example for wash sales and matched orders) and defences, so not every case requires proof of an intent to move the price.

Example. A trader repeatedly buys and sells units between accounts he controls, with no real change of beneficial ownership, to make the fund's units look actively traded.

Watch out. Demanding proof of intent to move the price in every false trading case. The provisions focus on the false or misleading appearance, with intention or recklessness as applicable, plus statutory deeming and defences.

Self-check: What appearance must conduct create for false trading, and with what mental state?

Answer: A false or misleading appearance of active trading or of the market or price, involving intention or recklessness as applicable.

54. Price rigging: artificial devices and the ownership elements

Price rigging is its own category of market misconduct, not merely a narrower version of false trading. One limb involves wash sales - transactions with no change in beneficial ownership - that maintain, increase, reduce, stabilise or cause fluctuations in the price of securities, where the person must prove their purposes were innocent; the other limb involves fictitious or artificial transactions or devices carried out with the intention that, or recklessness as to whether, they have that effect. Check both limbs and their elements against the provision.

Example. A person uses an arrangement of linked orders as an artificial device to hold up the price of a listed security, intending others to trade on the strength of that price.

Watch out. Labelling price rigging as simply identical to false trading. It has distinct elements, including the artificial-device element and the beneficial-ownership element.

Self-check: Name two features that distinguish price rigging from false trading.

Answer: Its own artificial-device element and its own beneficial-ownership element.

55. Disclosure of information about prohibited transactions

This category concerns representing or stating that the price of securities is likely to be affected by prohibited manipulative dealing, with conditions in the provision about participation in, or benefit from, that dealing. It does not simply mean disclosing any forced sale, any confidential order, or a fictitious transaction.

Example. A person who participated in manipulative dealing tells market contacts that a security's price is likely to be affected by that prohibited dealing, encouraging them to trade accordingly.

Watch out. Assuming that disclosing any forced sale or confidential order falls within this category. The provision is tied to price being affected by prohibited manipulative dealing, with participation or benefit conditions.

Self-check: What must disclosed information concern for this category of misconduct?

Answer: That the price of securities is likely to be affected by prohibited manipulative dealing, with the applicable participation or benefit conditions met.

56. Disclosure of false or misleading information inducing transactions

This category covers disclosing, circulating or disseminating information likely to induce other people to trade in securities, or likely to affect their price, where the information is false or misleading as to a material fact or through the omission of a material fact. The mental element differs by route: in the civil route the person need only know, be reckless or be negligent as to whether the information is false or misleading, while the criminal offence requires knowledge or recklessness. Publishing a fabricated takeover rumour is a classic example of this category.

Example. A person spreads a fabricated rumour that a listed company is about to receive a takeover offer, hoping investors will buy and push up the price.

Watch out. Classifying a fabricated rumour as stock market manipulation. That category requires transactions; rumour-based conduct belongs here, under false or misleading information inducing transactions.

Self-check: Into which category does publishing a fabricated takeover rumour fall?

Answer: Disclosure of false or misleading information inducing transactions.

57. Stock market manipulation: transaction and intent elements

Stock market manipulation involves two or more transactions in securities that have, or are likely to have, the effect of raising, depressing, maintaining or stabilising their price, carried out with the intent to induce other people to trade, or to refrain from trading, as applicable. The transaction element is essential; words alone are not enough.

Example. Two traders agree a matched series of purchases and sales between themselves to create the appearance of demand, intending other investors to follow and buy.

Watch out. Treating rumour-mongering as stock market manipulation. Without two or more transactions affecting price plus the relevant intent, the conduct belongs in another category.

Self-check: What transaction element does stock market manipulation require?

Answer: Two or more transactions in securities affecting, or likely to affect, the price, with the relevant intent.

58. Section 257 orders: disqualification, cold-shoulder, disgorgement and costs

If the MMT finds market misconduct, it may make orders under section 257 of the SFO, including disqualification from being a director or officer of listed and unlisted companies, a cold-shoulder order restricting dealings in the Hong Kong financial market, a cease-and-desist order, disgorgement of profit gained or loss avoided, costs, and possible disciplinary referral or recommendation.

Example. After an MMT finding of false trading, the Tribunal orders the person to disgorge the profit made, issues a cold-shoulder order restricting his market dealings, and refers the matter for disciplinary consideration.

Watch out. Adding a free-standing fine to the section 257 order list, or describing a cold-shoulder order as merely a ban on opening accounts. It restricts dealings in the Hong Kong financial market, and no free-standing fine sits in this category.

Self-check: What is a cold-shoulder order, and can the MMT impose a free-standing fine for market misconduct?

Answer: A restriction on dealings in the Hong Kong financial market; no, section 257 orders do not include a free-standing fine.

59. Consequences compared: criminal penalties, and the separate Part XIVA disclosure fine

A criminal conviction for market misconduct, obtained in the criminal courts to the criminal standard, can bring imprisonment and fines. Separately, the Part XIVA regime on disclosure of inside information by listed corporations is its own civil regime and can carry its own civil fine, so a civil fine is possible there even though section 257 MMT orders for the six misconduct categories include no free-standing fine.

Example. A listed corporation fails in its Part XIVA duty to disclose inside information as soon as reasonably practicable; that separate regime can result in its own civil fine.

Watch out. Generalising that 'the MMT can never fine' across all regimes. That is true for section 257 market misconduct orders, but Part XIVA is a separate regime with its own civil fine.

Self-check: Which regime can impose its own civil fine for inside-information disclosure failures?

Answer: The separate Part XIVA disclosure regime; this is distinct from section 257 MMT orders.

60. Private civil actions, licensing discipline and why the SFC takes enforcement action

The SFO gives persons affected by market misconduct a separate route: private civil actions for compensation, decided between the parties. Distinct again is licensing discipline, where the SFC acts against intermediaries; individuals performing regulated functions at registered institutions are relevant individuals, who need no separate SFC licence but must be fit and proper and entered in the HKMA register. The SFC enforces to protect market integrity, safeguard investors and deter misconduct.

Example. Investors who bought units at inflated prices because of false trading sue the wrongdoer for compensation, while the SFC separately takes disciplinary action against the intermediary involved.

Watch out. Mixing up the three routes. Private compensation actions, MMT/criminal proceedings for misconduct, and licensing discipline have different purposes, elements and procedures.

Self-check: Do individuals performing regulated functions at a registered institution need a separate SFC individual licence?

Answer: No; they are relevant individuals, must be fit and proper, and are entered in the HKMA register.

Turn your revision into a study plan

Adjust the pace to your starting knowledge and examination date. These are suggested revision stages, not an official preparation timetable.

StageWhat to do
Stage 1: Orient yourselfRead the current Paper 18 syllabus and this outline end to end, collect the official texts you will need (the SFO and subsidiary rules, the Code of Conduct with Schedule 11, the ICG, the UT Code, PRF Code, Code on REITs, OFC Code and OTCD Reporting Rules), and confirm you are studying the current examinable study guide version. Note which concepts feel familiar from Paper 1 and which are new depositary territory.
Stage 2: Learn the conceptsWork through the 60 concepts topic by topic in syllabus order, reading each concept together with its source text. Write a one-line summary and two or three exam-style keywords for each concept in your own notes. Give the larger Topic 1 more sessions than the smaller Topic 3, in proportion to its breadth.
Stage 3: Practise and self-testConvert your notes into quick flashcards and answer multiple-choice practice questions under timed conditions (roughly 90 seconds per question, matching the real 40 questions in 60 minutes). For every wrong answer, return to the source text and re-read the underlying concept before moving on. Pay special attention to distinctions, such as the different misconduct categories, elements and routes, because these suit MCQ testing.
Stage 4: Final reviewIn the last stretch before the exam, re-test yourself on every concept title without notes, then drill your weakest topics. Re-read Schedule 11, the section 257 order types and the six misconduct categories one final time. Sit at least one full 40-question mock in one sitting, then rest well before exam day.

Questions candidates ask

What is the format of HKSI Paper 18?

Paper 18 consists of 40 multiple-choice questions to be answered in 60 minutes, and the pass mark is 70%. That means you have about 90 seconds per question and can afford roughly 12 wrong answers and still pass, so steady accuracy across all four topics matters more than perfection in any single one.

Do I need to have studied Paper 1 first?

The syllabus states that candidates should recap and demonstrate understanding of the general regulatory framework acquired and assessed in LE Paper 1, then apply it to depositary work. So yes, the general framework (regulators, the SFO, licensing, the Code of Conduct) is assumed knowledge, and Paper 18 focuses on how those requirements, plus additional codes and guidelines, apply to the Type 13 regulated activity.

How should I divide my time between the four topics?

Follow the syllabus's own breadth rather than guesswork. Topic 1 covers eight sub-areas from regulators to enforcement and warrants the largest share of your sessions; Topics 2 and 3 are narrower but detail-heavy, with many specific requirements to memorise; Topic 4 is compact but conceptually demanding, requiring you to distinguish six misconduct categories and different legal routes. Adjust to your own strengths as you practise.

Which study documents should I use alongside this guide?

Use the official primary texts referenced in the syllabus: the SFO and its subsidiary rules (the FRR, CSR, CMR, KRR and AAR), the Code of Conduct including Schedule 11, the Management, Supervision and Internal Control Guidelines, the SFC Handbook, the UT Code, PRF Code, Code on REITs and OFC Code, and the OTCD Reporting Rules. Always check you have the current examinable study guide version for Paper 18 before you start revising.

How many weeks should I allow to prepare?

There is no fixed rule, and required study hours vary with your background. A practical approach is to map this outline onto the time you genuinely have: if you can study several sessions a week, you can complete the four stages over a handful of weeks; if your time is scarce, stretch the plan out but keep the sequence of learning, practising and reviewing intact. Finish with at least one timed mock so the 60-minute format feels familiar.

Official sources and further reading

These independent revision notes explain the public syllabus through original examples. They do not reproduce the official study guide or examination questions. Use the official study guide valid for your examination date for the full examinable detail. HKSIDataBase is an independent provider and is not endorsed by the HKSI Institute.

Browse all 17 paper guides