Hong Kong IA Fines FWD HK$19.5M for AML Failures

Hong kong flag motif inside a red circle with a white floral emblem overlapped by a blue shield with a white star and an orange fraud allegation badge | complycube

On 24 September 2026, the Hong Kong Insurance Authority (IA) announced a disciplinary action under Hong Kong’s Anti-Money Laundering and Counter-Terrorist Financing (AML/CTF) Ordinance. They fined FWD Life Insurance Company (Bermuda) Limited HK$19.5M (~$2.49M USD) after finding many issues with its AML controls. The Hong Kong IA found failures that involved third party payments, suspicious transaction monitoring, Politically Exposed Person (PEP) screening, and Customer Due Diligence (CDD).

This inspection covered various periods between April 2012 and September 2024. Though a penalty applies to one insurer, the findings lead to a much broader issue. Having weaknesses in payment verification, customer data, screening, and transaction monitoring can quickly become connected instead of isolated compliance failures.

How Hong Kong IA Learned About FWD’s AML Failures

They investigated and found four major areas of concern. However, these findings were significant when looked at together. Each and every control was responsible for answering different questions. Some answered who the customer was and where the money was from, and others answered if the activity matched the risks.

These problems came up when FWD was trying to verify third-party premium payments. Shortly after, it extended into transaction monitoring where suspicious cash activity was not properly reviewed. Separately, incomplete customer and beneficial-owner data impacted PEP screening, while some higher-risk relationships did not receive timely senior-management approval.

Hong kong ia fines fwd hk  5m for aml failures | complycube

This case is incredibly relevant for insurance compliance teams. It is rare that a control failure is confined to just one point in the whole customer journey. For example, if payer information is incomplete, it impacts the understanding of a transaction. Or if the beneficial owner’s information is missing, screening quality suffers. In some cases, if monitoring rules do not connect related payments, risky activity may not reach manual review.

Third-Party Payments Exposed a Verification Gap

The Hong Kong IA looked through 129 bank drafts worth up to HK$4.7M (~$599,000 USD), three of which had no supporting documentation. The remaining 126 policyholders submitted Premium Payment Declarations which stated that they had purchased the bank drafts themselves.

Instead, they found out during the investigation that 68 of the bank drafts had not been purchased by the policyholder, insured person, or settler named on the declaration form. Additionally, FWD did not have an effective threshold at which comprehensive verification of the payer’s identity became mandatory in practice.

Third-party payments can also carry additional money-laundering risk. This is because they introduce another person into the transaction process. The payer’s identity, relationship with the customer, and reason for funding the policy all become relevant in understanding if the activity is consistent with the expected customer profile. The FWD case shows why payment controls need to extend beyond collecting forms. High-value or unusual payments must trigger verification protocols proportionate to the risk presented.

Transaction Monitoring Missed HK$23.8M in Split Cash Payments

These payment issues became more relevant when the Hong Kong IA looked at how FWD monitored activity after a transaction entered the system. In 2022, FWD did not have any procedures that were designed to examine split cash premium payments.

When they conducted a review later at IA’s request, it found 306 policies involving $HK23.8M (~$3.03M USD), in split cash payments made by unidentified parties. A suspicious transaction report was subsequently filed with Hong Kong’s Joint Financial Intelligence Unit. The IA also found a completely separate system design flaw that prevented more than 100 transaction monitoring alerts from being generated.

Their findings point to a familiar challenge in automated AML monitoring. Individual payments look normal when assessed separately, but their risk is much clearer when a system links repeated payments, common funding sources, unusual transaction timing, or attempts to divide a larger amount into smaller transactions.

Having a transaction monitoring system is only part of the control. Firms also need to test if their scenarios, thresholds, and data flows find the behaviour that the system was designed to detect. In this case, the missed alerts show how a technical weakness is also a compliance weakness. Moreover, if the system does not create the alert, the compliance team may not get the chance to investigate any of the underlying behavior.

PEP Screening Added Another Layer of Risk

The Hong Kong IA also found gaps in how FWD collected and screened information on PEPs. The data gaps between 2012 and 2020 showed beneficial owners of trusts and legal-entity policyholders were not consistently screened for PEP status. This was not done during onboarding or on an ongoing basis. FWD failed to identify 58 customers or beneficial owners as PEPs.

Seven of those PEPs were foreign or non-Hong Kong. Since they were not identified, the required Enhanced Due Diligence (EDD) and senior-management approvals were not applied to those relationships. This highlights an important limitation of screening technology as it can only assess the identities provided to it.

When a policy involves a trust or legal entity, the relevant risk may sit behind the named customer. Trustees, settlers, shareholders, controllers, and beneficial owners may all need to form part of the compliance picture. That is also the reason that ongoing monitoring is important because PEP status is not static.

Someone who presents no political exposure at the time of onboarding can acquire it later. This means the customer risk profile can change without the customer opening a new account or buying another product. You can learn more here: What is a Politically Exposed Person?

Senior Management Became Part of the Control Failure

The Hong Kong IA findings did not stop with technology and customer data. It also extended to senior-management oversight. FWD failed to get approval from senior management before establishing business relationships with 19 high-risk policyholders during 2022. The regulator’s findings placed responsibility beyond the compliance function itself. This is where risk-based compliance moves from finding risk to acting on it.

A firm can find a high-risk customer, but that achieves very little unless it changes the onboarding or monitoring process. A higher-risk result may need to trigger EDD, source-of-funds checks, a manual review, or senior-management approval before the relationship proceeds.

Information always needs to lead somewhere. A suspicious payment must trigger investigation. A PEP match should trigger enhanced checks. A high-risk classification should trigger the right approvals. If those steps operate as separate manual processes, the possibility of delay or missed escalation increases.

Hong Kong IA’s Wider AML Enforcement Push

The FWD penalty is easier to understand as part of a wider enforcement pattern across Hong Kong. In 2024, the IA also fined AIA International Ltd. HK$23M (~$2.93M USD) after an AML inspection that found issues involving PEP screening and suspicious transaction monitoring. Similarly, three licensed broker firms were later fined a combined HK$429,000 (~$54,700 USD) for AML deficiencies that included PEP screening and third-party arrangements.

The Hong Kong IA 2024-2025 Annual Report recorded eight on-site insurer inspections, 85 concluded investigation cases, and 50 disciplinary actions. Hong Kong’s next Financial Action Task Force (FATF) mutual evaluation is due in the second half of 2029, placing continued attention on AML supervision and enforcement. The direction is important for insurers and intermediaries.

Regulators will not be checking if an AML policy contains the right wording. Enforcement increasingly examines whether the operational controls under policies actually work. They assess whether the correct people are screened, if payment information is verified, and whether transaction patterns generate alerts. They look at if higher-risk relationships are actually escalated.

FWD said it cooperated with the Hong Kong IA and that remediation was substantially complete. The insurer also confirmed that a review of customers onboarded during the relevant period found no cases in which customers who should have been rejected were incorrectly onboarded.

What Insurers Can Take from Hong Kong IA’s FWD Case

The significance of the HK$19.5M fine extends beyond FWD. For insurance companies, brokers, and other regulated financial businesses, the case shows how AML weaknesses can build up when controls responsible for different parts of the customer journey do not share the same information. Three lessons stand out:

  • Verify the person behind the payment: Find and assess third-party payers where high-value or unusual transactions are involved.
  • Test whether monitoring works in practice: Regularly confirm that transaction monitoring rules detect risk patterns and generate the right alerts.
  • Connect customer data to ongoing risk: Ensure PEP status, ownership data, transaction behaviour, and risk scores continuously inform due diligence and escalation.

The FWD and Hong Kong IA case ultimately shows that AML effectiveness is not determined by the number of controls a firm has. It depends on whether those controls exchange the right information, identify changing risk, and trigger action at the right time.

Fortify your fraud prevention and identity verification solutions with complycube | complycube

Find out more AML news in ComplyCube’s Trust Edition newsletter. We explore the latest in developments across identity verification and AML globally. 

Table of Contents

More posts

Person raises a smartphone for a selfie as part of an identity check with a verification card showing a photo and a green checkmark nearby | complycube

Biometric Verification API: A Buyer’s Guide

Learn how to choose the best biometric verification API for your company. Choose one that balances face matching, liveness, fraud prevention, compliance, privacy, integration, and cost for both Compliance and Engineering teams....
Icon of person in the middle surrounded by reg tech logos including complycube complyadvantage persona seon nice actimize and sumsub | complycube

Top 6 AML KYC Solutions for Unified Compliance in 2026

An AML/KYC comparison matrix helps firms choose vendors that best support their sector, customer, and country-specific risk-based workflows. Compare the market-leading regulatory SaaS platform against current regulatory mandates....
Three g2 fall 2026 report badges in our blog header | complycube

G2 Fall 2026 Shows ComplyCube Winning Where It Matters

ComplyCube’s G2 Fall 2026 results highlight growing strength across regional verification, enterprise relationships, and compliance, with 12 #1 rankings, 28 #2 positions, and strong results across key categories....