Module 23 | Global Financial Crimes, Risk, and RegTech Library
Research verification date: 2026-08-09
Primary jurisdictions: Hong Kong, Taiwan, Japan and Mainland China context.
Important notice: Educational material only; not legal advice. It does not determine obligations in any jurisdiction or replace legal counsel, regulator engagement, institution-specific risk assessment, or a documented customer, transaction, product, or account decision.
Source Quality and Currency Note
Primary sources include Hong Kong legislation and HKMA/SFC/Companies Registry materials, Japan NPA/JAFIC/FSA sources, Taiwan law/FSC materials, and official Mainland China legal, data and supervisory sources. This is a jurisdictional education module, not legal advice. Applicability depends on entity, product, transaction, data, people, market, current rules and local legal interpretation.
How to Use This Module
Read this module in three passes if useful:
- Enterprise leader pass: executive thesis, decision map, Global Core / Local Edge model, maturity profile, failure cascade and executive discussion questions.
- Operator pass: workflows, decision rights, metrics, delivery dependencies, quality controls, jurisdictional configuration and execution checklists.
- Specialist pass: legal and supervisory architecture, technical terminology, reporting, data, evidence, test design, enforcement/supervisory cases and glossary.
Learning Objectives
- Compare the legal, supervisory, FIU, reporting, customer-due-diligence, data and payment contexts of Hong Kong, Taiwan, Japan and Mainland China.
- Design a regional operating model that distinguishes common control objects from local rules, language, authorities and data boundaries.
- Understand how financial-center activity, cross-border corporate structures, international payments and regional payment rails shape financial-crime risk.
- Assess virtual-asset, tokenization and emerging-payment obligations in the relevant local supervisory environments.
- Use official enforcement and supervisory materials as evidence for testing onboarding, CDD, monitoring, effectiveness and data controls.
- Develop a disciplined Mainland China context map without treating it as an extension of Hong Kong, Taiwan or a generic Asia policy.
Primary-Source Spine
The source strategy for this module is: Official legislation, regulators, FIUs, company registries, central/financial authorities, and supervisory/enforcement sources. Representative source anchors include S01: Hong Kong e-Legislation; S02: Hong Kong Monetary Authority; S03: Hong Kong Monetary Authority; S04: Hong Kong Companies Registry; S05: Securities and Futures Commission, Hong Kong; S06: National Police Agency / JAFIC, Japan; S07: Japan Financial Intelligence Center; S08: Japan Financial Services Agency. Material legal, supervisory, enforcement and operating claims are identified in the companion claim/evidence ledger. [S01][S02][S03]
Executive Thesis
Greater China and North Asia is not a common regulatory market. Hong Kong is an international financial center operating under its own legal and supervisory system, with a strong banking and capital-markets financial-crime architecture and a particular role in cross-border finance. Taiwan has its own AML/CFT legislation, financial supervisor, payment and virtual-asset developments, and market structure. Japan combines statutory preventive obligations, JAFIC financial intelligence, FSA supervisory guidance and an increasingly explicit focus on validation of effectiveness. Mainland China must be understood through its own anti-money-laundering, financial-supervision, cross-border foreign-exchange, data-security and personal-information legal environment. A regional operating model that treats them as a single “China policy” will be technically and legally weak.
The right starting point is a shared evidence and risk system with four separately owned execution models. Each must identify the local legal entity, supervisor, FIU or reporting route, customer and beneficial-ownership expectations, transaction-monitoring and suspicious-reporting path, sanctions and screening implications, virtual-asset or emerging-payment perimeter, data and transfer constraints, language, local escalation and regulator engagement. Common technology can help, but it must preserve distinct source systems, local legal rules, evidence provenance and date/version logic. [S01][S02][S06][S08][S11][S15][S16][S17]
For senior leaders, this regional module is especially important because the risk is not only non-compliance. Incorrect centralization can create a hidden loss of intelligence: local teams lose ability to see Chinese-language evidence, Hong Kong payment and corporate structures, Japanese effectiveness expectations, Taiwanese virtual-asset and fraud patterns, or Mainland China data and cross-border constraints. Conversely, ungoverned local autonomy produces fragmented customer intelligence and blind cross-border networks. The objective is a connected but legally configured control system.
Executive decision rule. Before accepting, changing, centralising, outsourcing, automating, restricting, reporting, or closing a material financial-crime control, require a clear statement of the applicable question, the in-scope population, the accountable owner, the decision evidence, the local legal configuration, the quality test and the residual-risk authority.
The Questions This Module Answers
- What are the distinct legal sources, supervisors, FIU/reporting mechanisms and customer obligations in each market?
- How should the group store and use Chinese-, Japanese- and English-language evidence while preserving source and meaning?
- Which regional corporate, payment, virtual-asset and trade structures need cross-border graph analysis rather than country-by-country files?
- What can be centralized, what must be configured, and what must stay within local data or accountability boundaries?
- How do local sanctions, export-control, foreign-exchange, privacy and data-security constraints change global case management?
- What supervisory evidence would demonstrate effectiveness rather than formal compliance in Hong Kong, Taiwan and Japan?
1. Executive Layer
The strategic stakes
Financial-crimes capability becomes strategically material when it affects what customers can be served, which products can be launched, how fast payments can move, whether a market can be entered, which relationships can be retained, what data can be used, and whether regulators or partners consider the institution trustworthy. The leadership task is to avoid two bad abstractions: viewing financial crime as an isolated compliance overhead, or treating every operational difficulty as a legal prohibition. The discipline is to identify the actual source of risk and then design an evidence-led decision path that is proportionate, timely, fair and sustainable.
Every executive should ask four linked questions. First, exposure: what customers, products, transactions, geographies, delivery channels, intermediaries, technologies and networks create the risk? Second, control: which preventive, detective, investigative, reporting, action and assurance mechanisms should respond? Third, proof: what data, documents, logs, reviewer rationale, quality results, model evidence and authority records prove the mechanism works? Fourth, adaptation: how will the institution detect that the risk, rule, product, data or capacity assumption has changed? The answer must be visible by legal entity and market, not merely at head office.
Executive decision map
| Market | Primary operating emphasis | Global-model implication |
|---|---|---|
| Hong Kong | AMLO/HKMA/SFC risk-based AML/CFT, international financial-center flows, SCR evidence and financial intelligence interface. | Retain Hong Kong legal, language, payment, market and regulatory expertise; link it to global entity and transaction intelligence. |
| Japan | APTCP/JAFIC reporting and FSA effectiveness-oriented supervisory dialogue. | Build explicit effectiveness evidence, governance and local typology feedback into group controls. |
| Taiwan | Money Laundering Control Act, FSC expectations, virtual-asset rules and domestic payment/fraud context. | Configure customer, VASP, fraud/monitoring, report and language controls; verify local registration and scope. |
| Mainland China | Revised AML law, financial supervision, foreign-exchange/cross-border controls and data/privacy law. | Treat data-transfer, localization, product, payment, entity and authority questions as locally governed design constraints. |
The decision map is deliberately outcome-based. It prevents a program from announcing a new standard, a vendor deployment, a training campaign or a reduced backlog as a success without showing whether the actual decision quality, coverage and resilience improved. It also gives boards and transformation sponsors a more useful way to allocate capital: fund the evidence and operating capability that changes the decision, not simply the activity that surrounds it.
Read the cascade as a management diagnostic rather than an inevitability. A visible failure at the right side of the diagram—late reporting, unsafe customer action, a supervisory finding, or a costly remediation—usually began earlier with an unstated assumption about population, data, capacity, decision rights, or change control. The control response should move upstream until it identifies the first point at which evidence, ownership, or resilience was insufficient. That approach avoids treating rework, contractors, a larger backlog team, or a new dashboard as a substitute for fixing the decision path itself.
2. Operator Layer
The execution discipline
The operator layer turns legal and risk requirements into repeatable work. It begins with a controlled inventory, not a technology implementation. For each process, record the population, trigger, required evidence, key data, legal/policy basis, routing, reviewer authority, system, action, report, time standard, exception, quality test and feedback channel. If any of those elements are missing, the program is likely relying on individual memory or an undocumented work-around.
1. Establish four legal/regulatory maps
Create a separate map for Hong Kong, Taiwan, Japan and Mainland China: entity, product, law, supervisor, FIU/reporting route, sanctions and trade considerations, data laws, local systems, vendor, language, accountable executive and change owner.
2. Build multilingual evidence architecture
Retain source document, original script, reliable translation where used, translator/method, date, entity/person identifiers, reviewer and decision link. Do not flatten transliteration variants or translations into a single untraceable name field.
3. Manage cross-border corporate structures as graphs
Represent ownership, control, authority, directors, signatories, trade parties, payment parties, counterparties, jurisdictions, source evidence, dates and local legal labels. Distinguish Hong Kong, Taiwan, Japanese and Mainland China entities rather than relying on geographic shorthand.
4. Configure local monitoring and reporting
Use common data standards and scenario governance but ensure local patterns, payment rails, report requirements, language, escalation and authority interfaces are translated, tested and controlled.
5. Engineer data boundaries
For each data category and workflow, document local collection, permitted use, storage, user access, group visibility, transfer mechanism, aggregation/federation alternatives, legal review, evidence fallback and audit trail.
6. Test local effectiveness and regional connectivity
Run country QA and regulatory-readiness tests; then run cross-market analytics for linked entities, payments, trade, VASPs, device and fraud patterns. Reconcile the results with local legal and data limits.
Operating metrics that resist false assurance
Measure the entire decision path. Track demand and throughput, but pair them with aged risk, incomplete evidence, decision reversal, downstream escalation, report quality, customer-impact signal, QA error, model/data exceptions, vendor or system interruption, issue recurrence and time to root-cause closure. Require a management explanation for favorable metrics that move abruptly. A sharp improvement often reflects a useful control change, but it can also reveal data loss, a policy change, a case-type exclusion, a new vendor routing rule or an unrecorded suppression.
3. Specialist and Jurisdictional Layer
23.1 Hong Kong: financial-center execution
Hong Kong’s anti-money-laundering and counter-terrorist-financing architecture must be approached through its own law and supervisory system. The Anti-Money Laundering and Counter-Terrorist Financing Ordinance provides statutory context; HKMA’s guideline addresses authorized institutions; the SFC’s guideline provides an important capital-markets lens; and the Companies Registry’s Significant Controllers Register is relevant to corporate-transparency evidence. [S01][S02][S04][S05]
The operating implications are substantial. Hong Kong institutions frequently handle cross-border corporate groups, international payments, trade, private banking, fund structures, capital-markets activity, intermediaries and regional customers. A mature program needs strong entity resolution, multilingual name/transliteration controls, ownership/control graphing, purpose and source-of-wealth/source-of-funds analysis where risk requires, payment and trade visibility, connected screening, suspicious-transaction escalation and evidence that can be explained to the local supervisor. A registry result or a common English name is not a complete view of a complex cross-border relationship.
Enforcement and Supervisory Lens: Taiwan FSC Bank of Taiwan administrative penalty
Official record. The FSC announced a penalty relating to out-of-branch account opening, deposit/remittance transactions, ongoing CDD, account monitoring and employee conduct. [S15]
Operating lesson. Onboarding, payment activity, ongoing due diligence, monitoring and conduct must be viewed as an integrated control system.
Limit of inference. The announcement does not define a universal Taiwan threshold or a conclusion about all banks.
23.2 Hong Kong: corporate transparency, capital markets and emerging rails
The Significant Controllers Register supports a Hong Kong corporate-transparency regime but should be treated as one source layer. Its scope, access, verification and relationship to a firm’s own CDD have to be understood. An institution should preserve the customer declaration, registry information, independent evidence, source date, conflict, reviewer and decision. [S04]
Hong Kong’s financial-center environment also requires products to be classified precisely. A banking customer, licensed-corporation relationship, fund, family office, intermediary, payment participant, virtual-asset-related customer or trade party can sit in different supervisory and risk contexts. A global control platform should permit a shared ownership and transaction data model while routing local rules, licensing status, reportability, records, client-asset implications and escalation to Hong Kong specialists. It should not treat every cross-border connection as high risk, nor should it use a generic regional score to suppress a material Hong Kong risk signal.
Enforcement and Supervisory Lens: Japan FSA effectiveness-validation discussion paper
Official record. FSA finalized a discussion paper on issues and practices for dialogue on validation of AML/CFT framework effectiveness. [S09]
Operating lesson. A program must be able to validate whether controls produce their intended outcomes rather than simply demonstrating process adoption.
Limit of inference. A supervisory discussion paper is not itself a substitute for statutes, formal rules or entity-specific legal analysis.
23.3 Japan: statutory perimeter, JAFIC and effectiveness
Japan’s preventive regime draws on the Act on Prevention of Transfer of Criminal Proceeds, the JAFIC financial-intelligence function and FSA supervisory work. The FSA’s AML/CFT guidelines and its 2025 discussion paper on validation of effectiveness are especially useful because they push the conversation beyond documentation. Institutions need to understand their risks, establish governance, apply CDD, monitor, report, train, test, and then validate whether the controls are producing the expected outcomes. [S06][S07][S08][S09]
Japanese operations should combine global control standards with local product, customer, payment, language, organization and supervisor context. Japanese-language evidence must remain available to the people who can assess it; translations should be traceable. Suspicious-transaction reference cases can help local scenario and typology design, but they are not a substitute for a firm-specific risk assessment. [S10] The specialist question is not whether a scenario detects an example; it is whether the complete data, risk-routing, investigative, reporting and feedback process is effective for the institution’s actual customer and payment population.
Enforcement and Supervisory Lens: Revised PRC Anti-Money Laundering Law announcement
Official record. The State Council announced that the revised AML law would take effect on 1 January 2025 and described risk-sensitive AML measures. [S16]
Operating lesson. Legal change in Mainland China should trigger an entity/product/data/workflow/evidence impact assessment rather than a global policy assertion.
Limit of inference. This module uses the official announcement for contextual orientation; implementation requires current local legal review.
23.4 Taiwan: AML/CFT, payment and virtual-asset perimeter
Taiwan’s Money Laundering Control Act and FSC regulatory materials frame the local financial-sector environment. The FSC model guidelines identify board-approved internal control and risk-management expectations for banks, while Taiwan’s revised VASP AML/CFT and registration regulations provide a clearer virtual-asset perimeter. [S11][S12][S13][S14] A group must not assume that an overseas VASP policy or a Hong Kong approach automatically meets Taiwanese legal and supervisory requirements.
The regional operating focus should include customer and entity evidence, local risk assessment, domestic and cross-border payment patterns, fraud/scam signals, ongoing CDD, account monitoring, reportability, VASP registration/status, wallet/counterparty risk where relevant, sanctions/property reporting context, and locally supportable investigation narratives. The FSC’s 2025 Bank of Taiwan enforcement announcement illustrates why account opening, remittance activity, ongoing CDD, account monitoring and employee conduct must be viewed as connected internal-control components. [S15]
23.5 Mainland China: AML, financial supervision, foreign exchange and data
Mainland China should be treated as a distinct legal and operating context. The State Council announced that the revised Anti-Money Laundering Law took effect on 1 January 2025 and described risk-sensitive AML measures. [S16] Financial institutions also need to understand the role of the relevant financial supervisory structure, including the NFRA for supervised financial activity within its remit, and foreign-exchange administration where cross-border payments and capital flows are involved. [S19][S20]
Data is a first-order design constraint, not an appendix. The Personal Information Protection Law and Data Security Law create a legal environment that must be assessed when customer, transaction, device, entity, case and investigative information is collected, used, stored, shared or transferred. [S17][S18] A global group should use a data-flow inventory that distinguishes raw data, derived risk scores, case notes, aggregate reporting, model features, screening hits, documentary evidence and regulatory/law-enforcement materials. Where raw data cannot be moved, it may need local access, federated analysis, structured risk conclusions, local investigations or lawful evidence packages. These are architecture and operating-model choices requiring local legal validation.
23.6 Regional cross-border structures and operating implications
The fact pattern that matters is rarely “China risk” or “Japan risk.” It is a linked relationship: a Hong Kong holding company with a Mainland China operating entity, Taiwanese payment recipient, Japanese investor, regional trade party, multiple name variants, different registries and different data permissions. The group should be able to represent that relationship as a time-bound graph while maintaining source and jurisdiction tags. It should be able to see the connected risk, but it should not assume a right to move every underlying record or a rule to act identically in every market.
The operational discipline is to create a shared case plan: facts; local legal entities; owners/controllers; payment and trade flows; source data; language/translation; reports; sanctions/trade/foreign-exchange considerations; data restrictions; local action; group risk decision; and post-action monitoring. This gives leaders a coherent regional view without collapsing legally distinct markets.
23.7 Four-market accountability model: one evidence vocabulary, four accountable executions
A regional risk appetite is useful only when it becomes a legal-entity decision system. The board or regional financial-crime committee should approve the common minimum standard, the escalation taxonomy, the material-risk thresholds for group visibility, the quality requirements for evidence, and the limits of delegated authority. It should then appoint an accountable executive and a local control owner for each Hong Kong, Taiwan, Japan and Mainland China operation. Their accountabilities should be documented against the legal entity, products, customer population, reporting path, systems, data environment, outsourced services and regulator relationship—not merely against a geographic label.
The practical artifact is a four-column control-accountability register. For every material obligation or control, it records: the local legal source and version; the local accountable owner; the group standard that applies; the configured policy/procedure; the system of record; the evidence retained; the local escalation and reporting route; the data-access constraint; the testing method; the next legal or product-change review; and the person who can halt a rollout. That register is more useful than an organisational chart because it exposes unowned seams. A global transaction-monitoring team may be responsible for platform operation while the local officer remains responsible for local decision quality; a central model team may set validation methods while a country team must validate local data, language, typology and outcome relevance.
This distinction also protects against a common management error: assuming central approval has discharged local accountability. It has not. Hong Kong’s statutory and supervisory environment, Taiwan’s FSC framework, Japan’s statutory/FSA/JAFIC context, and Mainland China’s legal and data environment each require local interpretation and evidence. [S01][S02][S06][S08][S11][S16] Conversely, local independence is not an excuse for an unobservable control. Regional governance should receive a defined set of evidence-led indicators: backlog age by disposition, CDD refresh exceptions, alert-to-case conversion, report-quality findings, screening-match closure quality, data-access exceptions, customer exits, local change events and open remediation commitments. Leaders can compare the quality of execution without pretending that identical raw rates prove identical risk.
23.8 Hong Kong: CDD, ownership and investigative evidence in an international financial centre
Hong Kong customer due diligence should be designed around a proposition rather than a checklist. The question is whether the firm can explain, with contemporaneous evidence, who the customer is, who owns or controls it, who can act for it, why the relationship and product make sense, and whether observed activity remains coherent with that proposition. AMLO, the HKMA guideline for authorized institutions and SFC guidance for licensed corporations form the formal local context; the exact obligations and application must be reviewed for the entity and activity. [S01][S02][S05]
For a cross-border corporate relationship, the analyst should preserve a chronological evidence pack: incorporation and registry extracts; the customer’s own declarations; constitutional documents and signing authority; significant-controller or other ownership evidence where relevant; independent corporate sources; relationship purpose; expected geography, counterparties, volumes and products; source-of-funds or source-of-wealth evidence when risk warrants it; screening results; adverse-information review; and the rationale for confidence, conflict resolution and approval. The Significant Controllers Register is a useful evidence layer, but it cannot replace the institution’s own assessment of identity, control, authority and economic purpose. [S04] The control should distinguish legal ownership from de facto control, decision authority, beneficiary, nominee/intermediary roles and the ability to direct payments.
Monitoring needs the same relationship hypothesis. A financial-centre transaction does not become suspicious simply because it crosses a border, involves an investment vehicle or has a short description. Review should look for mismatch: payments that are inconsistent with customer purpose, unexplained third-party flows, circularity, sudden activity after dormancy, documentary gaps, unusual changes in ownership/control, high-risk customer behaviour, trade/payment inconsistency, rapid dispersal, or a linked alert in another market. The case record should say what changed, what source was examined, what alternative explanation was assessed, what local escalation occurred, and whether the relationship profile was updated. That makes the decision reproducible and makes the regional graph more reliable than a string of generic alert notes.
23.9 Hong Kong: capital markets, intermediaries, virtual-asset exposure and product launch gates
A Hong Kong operating model must classify the regulated relationship before it selects controls. Banking, securities and futures, fund administration, private wealth, payment services, corporate services and virtual-asset-adjacent activity can have very different actors, custody chains, client-money pathways, intermediaries, record sources and supervisory expectations. HKMA and SFC materials should therefore be treated as targeted supervisory inputs, not as a single generic policy library. [S02][S03][S05] The product owner, local compliance lead and financial-crime owner should document the exact legal entity and activity, the applicable local rules and guidance, expected client types, countries, intermediaries, transactions, custody/payment flows, screening population, reporting route and data sources before launch.
An effective launch gate asks six evidence questions. First, can the firm identify the customer, beneficial owner, controllers, authorised persons and material intermediaries? Second, can it understand the economic purpose and expected activity for the specific product? Third, can the operational data identify the relevant payer, payee, securities account, wallet or custodian in time for screening and review? Fourth, can an analyst retrieve original-language and third-party documents and show their provenance? Fifth, is there a clear escalation route for suspicious activity, sanctions concerns, market-abuse indicators, fraud, complaints and operational incidents? Sixth, can the firm stop, limit or exit the activity if an external provider, client or data feed fails?
The commercial temptation is to treat high-net-worth, institutional or professionally intermediated business as self-evidently well understood. That is an assumption, not evidence. A specialist review should challenge whether reputation substitutes for ownership proof, whether a fund or nominee masks the operating party, whether a rapid change in signatory or payment instruction is captured, and whether the monitoring design sees the product-specific transaction lifecycle. The resulting product risk assessment should be a living input to monitoring, periodic review, training and thematic testing—not a launch artifact filed and forgotten.
23.10 Taiwan: bank controls, VASP perimeter and integrated fraud/AML decisioning
Taiwan’s Money Laundering Control Act, FSC bank model guidelines and the FSC virtual-asset AML/CFT and registration regulations give a primary-source base for local design. [S11][S12][S13][S14] The correct operational response is neither to assume that every virtual-asset customer is unacceptable nor to treat a registration status as a complete risk answer. Before servicing a VASP, exchange, wallet provider, broker, payment intermediary or customer with material virtual-asset activity, the local team should determine the activity’s legal and regulatory status, registration and ownership evidence where applicable, customer and counterparty geography, wallet/custody model, fiat flows, transaction data available, sanctions and illicit-finance exposure, reporting triggers, product restrictions, and the residual risk that a local accountable officer is prepared to accept.
The 2025 FSC enforcement announcement involving Bank of Taiwan is an especially practical reminder that control stages interact: account opening, deposit/remittance activity, ongoing due diligence, account monitoring and employee conduct were all within the published deficiencies. [S15] A sound Taiwan framework therefore joins customer risk, payment/fraud signals, AML monitoring, investigation, operations and employee controls. A scam-related incoming transfer, a new device or contact channel, an abrupt change in beneficiary behaviour, a pass-through account, or a customer seeking rapid movement from fiat to a virtual-asset service may require parallel fraud and AML handling. Parallel does not mean duplicate cases. The firm should define a single fact record, time-stamped evidence, distinct decision owners, rules for legitimate information sharing, clear customer-protection actions, and an auditable explanation for reporting, restriction, release or exit.
Validation is crucial. The team should sample accounts from the highest-risk products and customer cohorts, reconstruct the end-to-end journey, and ask whether onboarding facts reached monitoring; whether staff saw relevant remittance and device/fraud context; whether investigators used the correct local language and escalation route; whether CDD was refreshed after material behavioural change; and whether employee incentives or override practices weakened the control. A lower alert rate is not automatically an outcome improvement. It may reflect an uncalibrated scenario, missing field, hidden operational workaround or suppressed reporting culture.
23.11 Japan: effectiveness validation, suspicious reporting and local feedback loops
Japan’s Act on Prevention of Transfer of Criminal Proceeds establishes a preventive legal context, JAFIC provides a financial-intelligence function, and the FSA’s AML/CFT materials frame supervisory expectations for financial institutions. [S06][S07][S08] The FSA’s 2025 finalized discussion paper on validation of effectiveness makes a valuable management point: effectiveness cannot be inferred solely from policies, training attendance, alert volume or an untested model. [S09] A firm needs a hypothesis for what each control is intended to prevent, detect, investigate or report; a measurement method; a meaningful population; an independent challenge; and a documented decision on whether to adjust the control.
For example, a Japanese customer-onboarding control can be validated through a stratified sample of accepted, restricted and rejected relationships. Testers can ask whether required identity and purpose information was actually verified; whether beneficial-owner and control analysis was commensurate with risk; whether Japanese-language documents and translations remained accessible; whether high-risk escalations contained adequate reasoning; and whether subsequent transaction behaviour contradicted the initial profile. A monitoring control can be validated by reconstructing known suspicious cases, testing reasonable challenge cases that did not alert, analysing data lineage and watch-list coverage, and examining whether alert triage conveyed sufficiently complete facts to the investigator. The objective is not to engineer the maximum number of alerts; it is to demonstrate appropriate detection and decision quality for the firm’s risk.
JAFIC and FSA suspicious-transaction reference materials can support a structured typology-feedback loop. [S07][S10] Local teams should translate relevant behaviours into data features, scenario hypotheses, investigation prompts and training examples, then test them against their own customer and product base. They should preserve why a reference case was deemed relevant or not relevant, how the scenario was configured, how false positives and false negatives were assessed, and what evidence supports a change. This avoids copying an example mechanically while still using public supervisory information as a living source of operational learning.
23.12 Japan: governance, correspondent connectivity and culturally reliable escalation
The Japanese execution model should not be designed as a language wrapper around a global queue. Local ownership must include the ability to challenge data quality, operational service levels, translations, risk scoring, case narratives, local-report decisions and business pressure. The local accountable officer needs access to evidence sufficient to make a genuine decision, while central specialists need enough structured information to identify linked regional risk. That balance can be achieved through a common case schema with local source attachments, controlled translations, confidence fields, decision timestamps and a strict rule that material uncertainty is visible rather than silently normalized.
For correspondent, institutional and cross-border payment relationships, the review needs to differentiate the customer’s role from the transaction’s role. A bank, broker, payment institution or corporate treasury relationship may be legitimate and complex. The control question is whether the firm understands the respondent, its ownership/control, products, customer base where relevant, countries, expected corridors, nested or downstream activity where relevant, screening/reporting responsibilities, notable adverse information, and the circumstances in which it will seek further evidence or restrict activity. Global corridor analytics may identify an anomaly; a Japan-based specialist should be able to inspect the original payment and customer context, assess alternative explanations and record the decision in a way that preserves local evidence.
Escalation culture is a control design matter. A policy that says “raise concerns” is weak if staff do not know how to do so, whether they can bypass a commercial owner, what facts must be preserved, when a report decision is urgent, and how they will be protected from improper influence. The assurance program should use confidential staff interviews, case-file review, override/exception analysis, aging and rework metrics, and retrospective review of material customer decisions to test whether escalation is operating in practice. This is a direct application of effectiveness thinking: governance is proven through decisions and outcomes, not merely through meeting minutes.
23.13 Mainland China: locally governed AML implementation and legal-change discipline
The revised PRC Anti-Money Laundering Law, announced by the State Council as taking effect on 1 January 2025, is a trigger for an organised legal-change program. [S16] A group should not respond with a generic global policy addendum. It should create a locally owned implementation register that maps the affected legal entities, products, customer segments, existing controls, policies, data fields, record-retention arrangements, employee guidance, outsourcing contracts, regulatory interactions and test evidence. For each identified change or interpretation, the register should assign a local legal source, local legal analysis, control owner, technology owner, target date, dependency, validation population and closure evidence.
The operating map should separately identify financial supervision and foreign-exchange/cross-border matters. The NFRA’s public information establishes its role in the current financial supervisory structure, while SAFE is a primary authority resource for foreign-exchange administration. [S19][S20] This does not permit a group to make a broad assertion that every international transaction is prohibited, reportable or suspicious. It does require the group to know which entity is conducting the activity, what product and payment route are involved, which local function owns the foreign-exchange and customer evidence, how exceptions are escalated, and how AML, fraud, sanctions/trade and foreign-exchange questions are sequenced. A regional investigation without local regulatory context risks creating both false confidence and inappropriate action.
Local implementation also requires a practical data-and-evidence design. Customer identifiers, transaction records, communications, biometrics/device data, model features, risk scores, case notes and investigation documents may not all have the same legal character, permitted access path, retention requirement or cross-border transfer route. PIPL and the Data Security Law provide primary legal context, but application is fact-sensitive and must be locally reviewed. [S17][S18] The design response is a data-use register: purpose; category; origin; legal entity; system; local user group; group user group; storage; transfer/access mechanism; vendor involvement; retention; security classification; approval; and evidence of ongoing review. A global portal that merely disables a download button is not necessarily a lawful or controlled data architecture.
23.14 Mainland China: data boundaries, investigations and resilient group intelligence
A well-designed regional program distinguishes visibility from possession. The central team may need to know that a locally investigated relationship has a high-risk ownership conflict, unusual payments, an unresolved adverse-information issue or a local report decision. It may not need every underlying personal document, raw transaction field or investigation communication. The local team may retain the source material, while a structured regional record carries the case identifier, legal entity, risk event, date, typology, decision state, confidence, restrictions, linked-entity hash or approved identifier, and a description of what additional evidence can be requested through a lawful process.
This architecture should be tested under pressure. Run tabletop exercises in which a Hong Kong branch asks for a Mainland China customer document, a regional model team proposes using local case notes for training data, a global sanctions team receives a possible match, a regulator or law-enforcement authority requests information, or a vendor support engineer needs production access. For each, test the actual path: who classifies the request, what source material is available, whether a local legal/data review is required, how access is granted or declined, how the decision is logged, how the group is informed, and what happens if the deadline is urgent. The result should be a repeatable decision playbook, not an informal chat escalation.
Resilience matters as much as normal-state compliance. If cross-border access is delayed, the local operation should still be able to perform CDD, investigate, make a local report decision and preserve evidence. If a local system is unavailable, the group should know which manual procedures apply, who can approve them, how data will later reconcile, and how inadvertent over-sharing will be prevented. If a global model cannot use local raw data, it should either use locally validated features, federated or aggregated evaluation, or maintain a transparent boundary that describes what risk it cannot assess. A model’s elegant regional performance chart is not a substitute for knowing what the model cannot see.
23.15 Cross-border payments, trade and foreign-exchange: sequencing rather than label-driven review
Regional cases often combine several control domains. A Hong Kong customer may initiate a payment linked to a Mainland China operating entity, a Japanese contractual counterparty and a Taiwanese beneficiary. The appropriate investigation order is not dictated by a country label. First establish the legal entities, customer role, ownership/control, authority, purpose and transaction facts. Then identify the relevant payment, trade, sanctions, fraud, foreign-exchange, privacy/data and reporting questions for each local operation. Finally determine which local function must decide, what evidence can be shared, and what group restriction or monitoring action is appropriate.
The investigation plan should record both facts and boundaries. It should include a time line; invoice, contract or trade-document provenance where relevant; payer/payee/account/wallet identifiers; intermediaries; shipment or service narrative; ownership and control changes; screening results; exchange or payment-route facts; customer explanations; source language; translation method; data location; local legal questions; pending information; and decisions. A missing field should remain visibly missing rather than being replaced with a generic “cleared” status. The case manager should also distinguish an unresolved question from a confirmed adverse fact. That is particularly important where local teams cannot immediately share source documents.
Quality assurance should review cases that crossed boundaries: whether the initial fact map was accurate; whether a foreign-exchange, sanctions, trade, fraud or AML issue was routed to the correct local owner; whether group escalation occurred at the right time; whether data sharing followed the documented path; whether local reporting or customer action was independently considered; and whether the final relationship profile reflects the result. This creates a learning loop. Recurrent documentary mismatches may signal a product or onboarding weakness; recurrent data delays may signal an architecture or agreement gap; recurrent regional false matches may signal an entity-resolution problem rather than a customer-risk trend.
23.16 Technology, vendors and model governance across scripts and data boundaries
Shared technology can improve consistency, but a vendor contract or a central deployment does not make a control transferable by default. The regional design should inventory every screening, monitoring, investigation, identity, translation, graph, document-processing, workflow, storage and model component. For each component record the legal entity using it; raw and derived data categories; hosting and support locations; sub-processors; model or rule version; languages/scripts supported; local configuration; quality measures; change-control route; incident route; audit rights; service-level commitments; exit plan; and local legal/data approval. The same inventory should identify manual workarounds, because they are frequently where unapproved data movement and untested decision rules emerge.
Name matching deserves specialist governance. Chinese names can appear in Chinese characters, multiple romanisation systems, reordered forms, abbreviations and corporate aliases; Japanese names may appear in kanji, kana and romanized forms. A match engine should retain the original string, script, source, date, matching method, score, applied normalisation and reviewer decision. It should be tested for local precision and recall using an approved, lawful test population. Transliteration should improve retrieval, not collapse distinct identities into a false certainty. A business user must be able to understand why a potential match appeared and how the conclusion was reached.
Models and rules should be locally challengeable. A scenario built from aggregated regional data may miss local payment types, vocabulary, customer practices or fraud signals. A machine-learning model may learn a proxy for missing data or customer segment rather than financial-crime risk. Governance should therefore require a local data-representativeness assessment, drift monitoring, explainability appropriate to the decision, human-review standards, false-negative investigation where feasible, and a suspension or rollback mechanism. Japan’s effectiveness conversation and the Taiwan enforcement signal both reinforce the broader lesson: operational evidence—not technology branding—demonstrates a sound AML/CFT framework. [S09][S15]
23.17 Assurance, enforcement learning and the ninety-day regional reset
A credible assurance program works from both local obligations and operational outcomes. Its annual plan should include entity/product coverage; four local legal-source refreshes; CDD and ownership-quality samples; screening and transaction-monitoring effectiveness tests; suspicious-report decision quality; virtual-asset and payment/fraud cases where relevant; data-access and transfer-control testing; vendor/model controls; conduct and override testing; local regulatory commitments; and cross-border case reviews. Testing teams should be sufficiently independent to challenge commercial and operations leaders, yet include language and market expertise so that they do not misread the evidence they are sampling.
Enforcement and supervisory materials are useful when translated into a testable lesson rather than treated as news. The Taiwan FSC announcement should trigger an integrated review of account opening, remittance, ongoing CDD, monitoring and conduct, not a superficial “Bank of Taiwan” watch-list entry. [S15] The FSA effectiveness-validation material should trigger a review of whether control metrics have causal meaning and whether management receives evidence of outcomes. [S09] The revised PRC AML-law announcement should trigger a local legal-change and impact-assessment record, not an assumption that a regional policy already covers it. [S16] Each lesson should be assigned to an owner, scoped to affected entities/products, tested against a defined population, and closed only when evidence is reviewed by the accountable officer.
In the first ninety days, leaders should: (1) complete the four-market legal/entity/data/accountability maps; (2) inventory all cross-border data and vendor flows; (3) select and reconstruct a sample of high-risk connected cases; (4) validate source-language, translation and name-variant controls; (5) test one monitoring and one CDD outcome in each market; (6) identify gaps in VASP/payment/fraud handling; (7) establish a regional evidence and exception dashboard; and (8) agree the escalation route for urgent cross-border cases. The target is not uniformity. It is visible, locally lawful, evidence-led control performance across an interconnected region.
4. Cross-Border Operating Model
The appropriate regional architecture is “connected evidence, separate execution.” Global systems should retain a common person/entity/transaction/case model, source-provenance rules, name-variant architecture, quality standards, versioning, model governance and executive escalation. Hong Kong, Taiwan, Japan and Mainland China should each retain a local legal and operational configuration. The regional center should support cross-border graphing, typology development, technology, testing, specialist communities, cases with multiple markets and management information. It should not erase local legal, data, reporting, language or supervisor boundaries.
The most important technical implementation choice is evidence traceability. A name or ownership match across scripts and transliterations should preserve the original claim, source, method and confidence. A data restriction should preserve why the global system sees a risk conclusion but not raw data. A local report should preserve its local legal source even when a regional case manager sees the linked facts. That is what makes a genuinely global capability defensible.
5. Practical Frameworks and Assurance
Framework 01: The System Proof Test
Use the following ten questions before declaring a capability effective. This is a library operating framework, not a regulatory checklist.
- Is the applicable legal, regulatory, supervisory and policy question explicitly classified?
- Is the in-scope population known, reconciled and versioned?
- Is the required customer, entity, transaction, data or evidence object complete enough for the decision?
- Is the accountable owner clear, including the local legal-entity owner where relevant?
- Does the workflow distinguish prevention, detection, investigation, reporting, action and assurance?
- Are there measurable quality, timeliness, coverage and customer-impact guardrails?
- Can a reviewer reconstruct the rule, source, data, reasoning, override, action and report?
- Can the system absorb a surge, data failure, vendor failure, legal change or material risk event?
- Has independent challenge tested real decisions and not only written procedures?
- Does the learning loop make a controlled change, retain the evidence and test whether it worked?
Framework 02: Outcome Dashboard
| Outcome | Leading / lagging indicators | Evidence source |
|---|---|---|
| Decision quality | Accuracy, completeness, timeliness, consistency, explained overrides | QA, independent testing, case review and regulatory challenge |
| Coverage | Population, product, channel, data and legal-entity inclusion | Coverage map, reconciliations, negative testing and change control |
| Customer / counterparty outcome | Friction, hold/release timing, complaints, remediation and fairness | Journey evidence, service data, root-cause analysis and governance |
| Resilience | Surge capacity, data dependency, vendor concentration, recovery and key-person exposure | Scenario test, service review, continuity exercise and exit plan |
| Learning | Issue recurrence, typology feedback, model/process change and post-implementation result | Root-cause log, risk acceptance, validation and BAU monitoring |
The dashboard should be read as a pattern, not a scorecard contest. A sharp reduction in alert volume may be good, bad, or meaningless depending on the covered population, detection precision, missed-risk testing, quality, account/action outcomes and source data. A backlog decline may signal stronger process design, or it may result from relaxed review, unrecorded exceptions, data loss or customer exits. The governance record should require the owner to explain the causal story and the independent challenger to test it.
Framework 03: Decision-Rights Map
| Role | Minimum decision rights and evidence |
|---|---|
| Global owner | Common standard, data/evidence grammar, control taxonomy, model/vendor/QA framework, thematic risk and escalation. |
| Local entity owner | Local legal translation, reportability, data access, customer action, supervisory engagement, local source and procedure. |
| Independent challenge | Second-line challenge, quality, validation/audit, issue severity, evidence review and residual-risk escalation. |
| Executive forum | Risk appetite, funding, material exceptions, product/growth conditions, remediation closure and authority engagement. |
6. What Good Looks Like / What Failure Looks Like
What mature, defensible, sustainable capability looks like
- Mature / defensible: Four separate legal/regulatory execution maps under a shared regional evidence, risk and governance framework.
- Mature / defensible: Multilingual source, translation and transliteration controls that preserve provenance and do not overwrite ambiguity.
- Mature / defensible: A country-configured VASP, payment, CDD, monitoring, report and data framework with transparent local ownership.
- Mature / defensible: Cross-border corporate and payment graphing that distinguishes Hong Kong, Taiwan, Japan and Mainland China entities and source claims.
- Mature / defensible: Data architecture that supports lawful local access, federated analysis and structured group intelligence where raw transfers are constrained.
What weak, misleading, fragile, or non-defensible implementation looks like
- Fragile / non-defensible: A “China/APAC” policy that treats Hong Kong, Taiwan, Japan and Mainland China as one regulatory environment.
- Fragile / non-defensible: A global customer record that erases original-language evidence, source, translation, transliteration or uncertainty.
- Fragile / non-defensible: A Hong Kong or Taiwan registry result used as total proof of ownership, control, authority or customer purpose.
- Fragile / non-defensible: A Japan program that measures policy adoption but cannot validate effectiveness of its risk assessment, monitoring, reporting and governance.
- Fragile / non-defensible: A Mainland China data design that assumes cross-border data transfer is an IT setting rather than a legal and operating decision.
7. Common Misconceptions and Contrarian Insights
“Greater China is one legal regime.”
Hong Kong, Taiwan and Mainland China have distinct legal, supervisory, data, registry, payment and enforcement contexts.
“Japanese AML/CFT is purely rules-based.”
FSA materials highlight validation of effectiveness and supervisory dialogue, not just document compliance.
“VASP policy can be copied from one market to another.”
VASP definitions, registration, customer, transaction, reporting and supervisory frameworks are local and changeable.
“A translation is just a convenience.”
Translation and transliteration can alter identity resolution, evidence, screening, investigation and report quality; provenance matters.
“Data localization only affects storage.”
It can affect access, processing, sharing, investigation, model development, evidence preservation and incident response.
8. Executive Discussion Questions
- Can we show four distinct legal-entity, supervisor, FIU/reporting, data and escalation maps for Hong Kong, Taiwan, Japan and Mainland China?
- How does the group preserve Chinese- and Japanese-language source evidence and verify the meaning of material translations?
- Which cross-border corporate/payment patterns are currently invisible because files are organized by country rather than graph relationship?
- What local VASP, tokenization, payment or fraud developments trigger a product and control impact assessment?
- What does the Japan effectiveness-validation lens reveal about our current metrics and independent testing?
- Can the regional platform distinguish a Hong Kong legal entity from a Mainland China, Taiwan or Japanese connected party without data loss?
- Which data categories can move, which need local access, and how do we retain a global risk picture where raw data cannot move?
- Does our entity-resolution system preserve name variants, identifiers, source language, translation method and confidence?
- How are sanctions, trade and foreign-exchange considerations sequenced in a case that spans Hong Kong and Mainland China?
- What evidence supports ongoing CDD and monitoring in Taiwan as customer behavior and fraud typologies shift?
- Can local teams stop a regional rollout when the legal/data/evidence configuration is not ready?
- What regional thematic review follows a significant local enforcement or supervisory observation?
9. Practitioner and Specialist Checklists
Executive checklist
- Can we name the legal / policy question, accountable executive, local legal entity and decision authority?
- Can we see current evidence on coverage, quality, timeliness, customer impact, resilience and residual risk?
- Can we distinguish regulatory requirement, supervisory expectation, operating recommendation and untested assumption?
- Can we condition growth, product scope, outsourcing, data use or customer action when a guardrail is breached?
- Can we prove that a completed remediation is operating in BAU rather than merely deployed?
Operator checklist
- Map each decision to an in-scope population, trigger, data/evidence, procedure, system, owner, escalation, action and record.
- Reconcile source, case, report, action and quality data; do not allow unresolved data loss to become a business-as-usual assumption.
- Version rule, process, model, vendor, translation and report changes; retain test evidence and rollback/contingency decisions.
- Route complex, ambiguous, high-risk, cross-border, language or legal issues to named specialists with documented outcomes.
- Run recurring QA and root-cause analysis that reaches upstream policy, data, product, training and technology causes.
Specialist validation checklist
- Verify the applicable legal source, current effective date, scope, entity, product and authority before applying a control conclusion.
- Preserve primary source, locator, original language where relevant, translation/version, collection date, confidence and decision use.
- Test negative cases, population coverage, false positives, false negatives, overrides, edge conditions, timing and evidence reproducibility.
- Separate legal requirement, supervisory expectation, market practice and library operating inference in analysis and documentation.
- Record local variations, data restrictions, report interfaces, translation debt, legal advice and residual-risk decisions explicitly.
10. Module Glossary
| Term | Definition |
|---|---|
| AMLO | Hong Kong’s Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615). |
| APTCP | Japan’s Act on Prevention of Transfer of Criminal Proceeds. |
| JAFIC | Japan Financial Intelligence Center. |
| SCR | Hong Kong Significant Controllers Register. |
| Transliteration | Rendering a name from one script into another; a control-relevant source and match attribute, not a single definitive identity field. |
| VASP | Virtual asset service provider; legal definition and registration/AML scope vary by jurisdiction. |
| PIPL | People’s Republic of China Personal Information Protection Law. |
| Federated analysis | A design pattern in which analytic logic operates across distributed/local data without necessarily centralizing all raw records. |
11. MLA 9 Works Cited
[S01] Hong Kong. Anti-Money Laundering and Counter-Terrorist Financing Ordinance. Cap. 615, https://www.elegislation.gov.hk/hk/cap615. Accessed 9 Aug. 2026.
[S02] Hong Kong Monetary Authority. Guideline on Anti-Money Laundering and Counter-Financing of Terrorism (For Authorized Institutions). 25 May 2023, https://brdr.hkma.gov.hk/eng/doc-ldg/docId/20230525-4-EN. Accessed 9 Aug. 2026.
[S03] Hong Kong Monetary Authority. Ordinances and Statutory Guidelines. updated 28 Nov. 2025, https://www.hkma.gov.hk/eng/key-functions/banking/anti-money-laundering-and-counter-financing-of-terrorism/ordinances-statutory-guidelines/. Accessed 9 Aug. 2026.
[S04] Companies Registry. Significant Controllers Register: Overview. Government of the Hong Kong Special Administrative Region, https://www.cr.gov.hk/en/legislation/scr/overview.htm. Accessed 9 Aug. 2026.
[S05] Securities and Futures Commission. Guideline on Anti-Money Laundering and Counter-Financing of Terrorism (For Licensed Corporations and Associated Entities). https://apps.sfc.hk/edistributionWeb/api/consultation/openFile?lang=EN&refNo=23CP1&fileName=AML_Guideline_Eng.pdf. Accessed 9 Aug. 2026.
[S06] Japan. Act on Prevention of Transfer of Criminal Proceeds. National Public Safety Commission, https://www.npa.go.jp/sosikihanzai/jafic/laws/law.html. Accessed 9 Aug. 2026.
[S07] Japan Financial Intelligence Center. Outline of JAFIC. National Police Agency, https://www.npa.go.jp/sosikihanzai/jafic/english/about_jafic.html. Accessed 9 Aug. 2026.
[S08] Financial Services Agency. Guidelines for Anti-Money Laundering and Combating the Financing of Terrorism. https://www.fsa.go.jp/en/refer/amlcft/amlcft_guidelines.html. Accessed 9 Aug. 2026.
[S09] Financial Services Agency. Publication of the Finalized Discussion Paper on Issues and Practices for Dialogue on Validation of Effectiveness of AML/CFT Frameworks. 31 Mar. 2025, https://www.fsa.go.jp/en/news/2025/20250331/20250331.html. Accessed 9 Aug. 2026.
[S10] Financial Services Agency. Reference Cases on Suspicious Transactions. updated 4 Feb. 2026, https://www.fsa.go.jp/en/laws_regulations/str.html. Accessed 9 Aug. 2026.
[S11] Taiwan. Money Laundering Control Act. Laws and Regulations Database of the Republic of China, https://law.moj.gov.tw/ENG/LawClass/LawAll.aspx?pcode=G0340131. Accessed 9 Aug. 2026.
[S12] Financial Supervisory Commission. Model Guidelines for Banks’ Anti-Money Laundering and Countering the Financing of Terrorism Policies and Procedures. https://www.fsc.gov.tw/fckdowndoc?file=%2F%E9%8A%80%E8%A1%8C%E9%98%B2%E5%88%B6%E6%B4%97%E9%8C%A2%E5%8F%8A%E6%89%93%E6%93%8A%E8%B3%87%E6%81%90%E6%B3%A8%E6%84%8F%E4%BA%8B%E9%A0%85%E7%AF%84%E6%9C%AC-EN%28clear%29.pdf&flag=doc. Accessed 9 Aug. 2026.
[S13] Financial Supervisory Commission. Regulations Governing Anti-Money Laundering and Countering the Financing of Terrorism for Enterprises or Persons Providing Virtual Asset Services. 26 Nov. 2024, https://law.fsc.gov.tw/EngLawContent.aspx?id=2733&lan=E. Accessed 9 Aug. 2026.
[S14] Financial Supervisory Commission. Regulations Governing Anti-Money Laundering Registration of Enterprises or Persons Providing Virtual Asset Services. 26 Nov. 2024, https://law.fsc.gov.tw/EngLawContent.aspx?id=2734&lan=E. Accessed 9 Aug. 2026.
[S15] Financial Supervisory Commission. FSC Imposes Administrative Penalty on Bank of Taiwan for Deficiencies Involving Account Opening, Deposit/Remittance Transactions, Ongoing Customer Due Diligence and Account Monitoring. 11 Mar. 2025, https://www.fsc.gov.tw/en/home.jsp?dataserno=202506020001&dtable=News&id=54&mcustomize=multimessage_view.jsp&parentpath=0%2C2. Accessed 9 Aug. 2026.
[S16] State Council of the People’s Republic of China. China Revises Anti-Money Laundering Law. 9 Nov. 2024, https://english.www.gov.cn/news/202411/09/content_WS672ef1efc6d0868f4e8ecc4b.html. Accessed 9 Aug. 2026.
[S17] National People’s Congress. Personal Information Protection Law of the People’s Republic of China. https://www.npc.gov.cn/englishnpc/c23934/202112/1f5b8e1dd7f44476b0d9a0d70868e2bf.shtml. Accessed 9 Aug. 2026.
[S18] National People’s Congress. Data Security Law of the People’s Republic of China. https://www.npc.gov.cn/englishnpc/c23934/202109/2d44d6a0c3584be88980a8ccd6e7a6f6.shtml. Accessed 9 Aug. 2026.
[S19] State Administration of Foreign Exchange. State Administration of Foreign Exchange. https://www.safe.gov.cn/en/. Accessed 9 Aug. 2026.
[S20] National Financial Regulatory Administration. About the NFRA. https://www.nfra.gov.cn/en/view/pages/. Accessed 9 Aug. 2026.