A 1LoD report
HONG KONG
FORECAST 2026
Managing Financial Crime Risk Without Clear
Lines or Boundaries
Key Takeaways
!
Financial crime risk management frameworks are being stretched by sanctions complexity and regulatory divergence, as firms are increasingly required to exercise judgement rather than rely on rule‑based screening outcomes.
Sanctions compliance have become an exercise in judgement and ownership rather than screening precision, increasing accountability pressure on senior decision‑makers
!
Artificial intelligence (AI) is improving efficiency and pattern detection but is intensifying scrutiny around explainability, data quality and human‑in‑the‑loop decision making within established governance and review frameworks
!
Operating model effectiveness is determined more by escalation clarity and internal cultural alignment than formal separation between the 1st and 2nd lines.
Institutional engagement with digital assets remains cautious, driven more by client exposure than strategic intent, with continued uncertainty around the effectiveness and practical rationale of stablecoin and central bank‑led initiatives
!
!
Network analysis and third-party intelligence are becoming foundational as digital assets introduce new vectors for obfuscation and cross border risk.
Financial Crime Risk Management in an Era of Ambiguity and Accountability
Financial crime risk management frameworks are being recalibrated in response to sanctions volatility, increasingly globalised illicit activity and heightened regulatory expectations around judgement and accountability. Attention during the opening discussion at the Financial Crime Leaders’ Network in Hong Kong focused less on control expansion and more on how risk could be interpreted, owned and defended in an environment where legal clarity and operational certainty were no longer assured. The discussion reflected a shift away from static frameworks toward decision‑centric models that placed greater responsibility on experienced practitioners.
Sanctions risk dominated the debate, particularly the growing tension between global consistency and jurisdictional variances. The operating environment had moved decisively beyond deterministic outcomes, with compliance assessments “no longer black and white” and increasingly left to interpretation. Local regulatory expectations, shaped by domestic government sanctions regimes, were seen to conflict with group‑wide obligations driven by European or United States enforcement expectations. The result was not simply operational friction, but a sustained increase in judgement risk, often without proportional regulatory guidance.
Managing Financial Crime Risk Without Clear Lines or Boundaries ãã 3
This complexity was further amplified by opaque ownership structures, including layered shareholdings, minority control positions and repeated restructuring that obscured sanctioned exposure. Traditional name‑based screening was widely regarded as insufficient, with firms required to identify control, influence and economic benefit across increasingly opaque networks. This placed renewed emphasis on enhanced due diligence (EDD) and analytic capability, particularly in trade finance, where multiple stakeholders and fragmented data heightened exposure, but responsibility and accountability ultimately remained with the financial institution.
As sanctions interpretation became more nuanced, expectations of practitioners shifted accordingly. The emphasis moved away from volume‑driven alert processing toward analytical judgement supported by technology and deeper product‑specific expertise. One participant noted that “the type of investigator that we employ is very different,” reflecting the declining value of rule execution relative to behavioural interpretation and product understanding. In specialist domains such as trade finance, understanding the interaction between credit risk processes and financial crime controls, including documentation flows and data ownership outside financial crime teams, was essential to identifying abuse.
!
Within this broader shift, AI featured prominently in how banks were restructuring teams and rethinking financial crime risk management, but largely as an enabling layer rather than a decision engine. Measurable efficiency gains were reported in areas such as data aggregation, pattern recognition and narrative support. However, its use had also heightened regulatory and internal scrutiny. There was clear alignment that accountability could not be delegated to systems,
Traditional name‑based screening was widely regarded as insufficient, with firms required to identify control, influence and economic benefit across increasingly opaque networks.
with one participant stating that “you cannot hide behind AI.” Regulators were seen as increasingly focused on decision traceability, driving greater emphasis on internal scrutiny of AI‑supported decisions through model governance, 2nd line challenge and documented review rather than reliance on automated outputs alone.
Data quality emerged as the primary constraint on more advanced adoption, with fragmented, incomplete or poorly governed data undermining even sophisticated models. Several firms described early experimentation with behavioural analytics that focused on customer lifecycle changes rather than static thresholds but noted that such approaches required significant investment in data architecture and continuous data remediation programmes. Technology was therefore seen as amplifying both capability and exposure, rather than resolving structural weaknesses.
Rigid debates about 1st or 2nd line ownership were widely rejected in favour of a focus on escalation clarity, independence safeguards and organisational culture. One participant remarked that “the whole lines of defence concept, it gets in the way,” capturing frustration with frameworks that prioritised structure over outcome. Hybrid operating models were increasingly common, combining business‑proximate triage with more independent investigative oversight. What mattered, participants agreed, was not where decisions sat but whether authority, challenge and accountability were clearly defined.
Engagement with regulators in Hong Kong was viewed as comparatively constructive, particularly in relation to technology adoption. Early dialogue, sandbox participation and directional guidance were seen as enabling experimentation without prescriptive constraint. Regulatory maturity was seen as enabling experimentation, but only where firms could evidence defensible governance and decision logic. Documentation, auditability and personal accountability were therefore viewed as foundational, not supplementary, to future innovation.
The discussion suggested that financial crime risk management was entering a phase defined less by control expansion and more by judgement resilience, as technology accelerated detection while concentrating responsibility and narrowing tolerance for ambiguity. Firms that could integrate advanced analytics with disciplined governance, experienced practitioners and transparent escalation were likely to be better positioned as regulatory expectations continued to tighten.
“This meeting is very engaging with good quality participants.”
HENRY YU, CHIEF AML OFFICER, MANULIFE
Digital Assets: Cautious Engagement within an Unsettled Risk Landscape
The second debate examined how institutions were approaching digital assets against a backdrop of regulatory fragmentation, client‑driven exposure and financial crime risk. The prevailing sentiment was one of measured caution. Digital assets adoption was commonly characterised as “at a very nascent stage,” with most institutions adopting a deliberate wait‑and‑watch posture while monitoring regulatory developments and peer activity.
While legal uncertainty remained a primary inhibitor to broader engagement, institutions also faced increasing indirect exposure driven by client activity. Participants highlighted the absence of consistent classification, licensing standards and cross‑border enforceability as significant barriers to institutional participation. While some global institutions had begun to test products such as stablecoins, exchange‑traded funds or custody solutions, these initiatives were seen as requiring scale, capital and risk tolerance that were not universally available. Regional and mid‑sized institutions described a preference for observing outcomes before committing resources, particularly given the difficulty of exiting once systems and controls were embedded.
Client demand nevertheless emerged as a persistent pressure point, with exposure to digital assets increasingly indirect and driven by clients’ activity rather than institutional product strategy. One participant stated that “it is very much client driven,” underscoring that digital assets could not be excluded from internal financial crime risk assessments simply because institutions chose not to offer dedicated products. This dynamic required firms to enhance client due diligence (CDD) into unfamiliar territory, often without clear regulatory benchmarks.
Digital assets were also seen to blur established risk boundaries. Participants described conducting enhanced assessments of third parties’ governance, know‑your‑customer, standards and sanctions screening, often extending correspondent banking concepts into the digital sphere. This expansion of scope increased both operational burden and residual risk, particularly where counterparties operated in lightly regulated or offshore environments. Sanctions circumvention was identified as a key concern, especially where stablecoins were used to bypass traditional payment rails in jurisdictions with limited access to reserve currencies.
Tokenisation of real‑world assets generated cautious interest but no clear near‑term consensus. Participants acknowledged potential efficiency and liquidity benefits but stressed that financial crime exposure could not be considered in isolation. Cyber-security risk was repeatedly cited as a limiting factor, particularly in relation to wallet custody, key management and incident response. Responsibility for cyber-risk was often distributed across technology, compliance and operational teams, complicating escalation and accountability in the event of breach.
Regulatory capability was viewed as uneven but improving. Hong Kong regulators were generally regarded as proactive, particularly in developing licensing regimes and engaging industry participants. However, several participants questioned the commercial logic underpinning certain initiatives, with one noting that “I do not see the business case” for specific local stablecoin proposals. This scepticism reflected broader uncertainty about how regulatory ambition would translate into sustainable market activity.
The discussion concluded that digital assets regulations were likely to converge, rather than diverge, from traditional financial crime risk frameworks over time. Participants emphasised that underlying risk principles remained consistent, with one describing the challenge as “the same concept, same principle,” applied to new structures and faster settlement mechanisms. Meaningful engagement, however, was seen as dependent on clearer legal definitions, demonstrable cyber-resilience and the ability to trace risk across complex networks. Until these conditions mature, most institutions appeared committed to cautious exposure management rather than proactive expansion.