News

Hong Kong Rewrote Its Remote Onboarding Rules Around Deepfakes

Moca Network
September 10, 2026

The Hong Kong Monetary Authority issued a circular on 3 September 2026 that resets its expectations for how banks and stored value facility licensees on-board individual customers remotely. It supersedes guidance that had stood since 2019, and the reason it gives is stated plainly: artificial intelligence driven automation and sophisticated tactics, including the use of deepfake technology, have increased the potential for impersonation, online fraud and associated mule-account networks at much greater scale.

Key takeaways

  • The circular supersedes the HKMA circulars of 1 February 2019 (remote on-boarding of individual customers) and 24 May 2021 (remote on-boarding and iAM Smart).
  • Two circulars remain applicable and are to be read in conjunction with it: corporate remote on-boarding (24 September 2020) and the thematic review feedback on AML/CFT controls for remote on-boarding initiatives (3 June 2020).
  • Compliance is framed around two core principles: identity authentication and identity matching.
  • Remote on-boarding is described as an integral part of AML/CFT controls, subject to a continual programme of updates and recalibration rather than a one-time approval.
  • A tiered, risk-based approach is expected in product design, with features, functionality and transaction limits scaled dynamically to assessed risk and ongoing behaviour.
  • Institutions are told to conduct a comprehensive review of their remote on-boarding solutions and the systems and oversight around them, informed by fraud and scam intelligence shared by the HKMA and the Hong Kong Police Force.

The two core principles

The circular reduces a large operational subject to two questions an institution must be able to answer for every remotely on-boarded customer.

PrincipleWhat the HKMA expects
Identity authenticationWhere identity is obtained through electronic channels, take appropriate measures to ensure the reliability of the document, data or information obtained for verifying the customer’s identity, including utilising technology to ascertain the genuineness of the identity document.
Identity matchingUse appropriate technology to link the customer incontrovertibly to the identity provided.

The word doing the most work there is incontrovertibly. Supervisory drafting rarely reaches for an absolute, and the choice sets a high bar for the second half of the process. Establishing that a document is genuine is a document problem, and the market has spent a decade building tooling for it. Establishing that the person presenting it is the person it describes, over a video channel that a generative model can now populate convincingly, is a different problem, and it is the one the circular places under the strongest language.

What it replaces

Four circulars form the current picture. Two are withdrawn, two continue.

CircularDateStatus
Remote on-boarding of individual customers1 February 2019Superseded
Feedback from thematic reviews of AML/CFT control measures for remote on-boarding3 June 2020Continues to apply
Remote on-boarding of corporate customers24 September 2020Continues to apply
Remote on-boarding and iAM Smart24 May 2021Superseded
Remote on-boarding of individual customers3 September 2026In force

The 2019 circular was written when remote on-boarding was still being encouraged as an innovation, and the 2021 addition attached that encouragement to a specific national credential. The 2026 circular starts from the opposite premise. Remote on-boarding solutions, it says, have now become an integral part of the AML/CFT controls of Authorized Institutions and stored value facility licensees. There is no longer a channel to promote, only a control to keep working.

The threat model is named, not implied

Regulatory text usually gestures at emerging risk. This circular names it. Advancements in technology have driven changes in the money laundering and terrorist financing risk landscape, and the specific mechanisms cited are artificial intelligence driven automation, deepfake technology, impersonation, online fraud and the mule-account networks that sit downstream of all three. Scale is the operative word: the same tactics that once required a person now require a model.

The response the HKMA describes is not a new control requirement but an intelligence loop. The authority says it has been working closely with the industry and the Hong Kong Police Force to share the latest tactics and modus operandi, and that institutions are expected to use that intelligence on an ongoing basis to ensure their systems and processes can mitigate both existing and evolving risks. That places an obligation on the receiving end of the loop. Intelligence that arrives and does not change a threshold, a model or a decision rule has not been used.

Tiering moves from product design to control design

The second half of the circular is about proportionality. Institutions are expected to adopt a risk-based approach in the design of products and services, proportionate to the customer’s assessed risk profile. The worked example is a tiered account: features, functionality and transaction limits scaled dynamically and adjusted according to actual usage and ongoing customer behaviour.

Tiering has usually been treated as a growth decision, a way to let a customer start using a product before verification is complete. Here it is presented as part of the AML/CFT control itself, and paired with active senior management oversight. The practical consequence is that the limit structure has to be defensible on risk grounds rather than conversion grounds, and it has to move after on-boarding, not only at it.

What a review looks like in practice

The circular closes with an instruction rather than a suggestion: conduct a comprehensive review of remote on-boarding solutions, and of the systems and oversight that keep them effective, taking into account the latest intelligence about fraud and scam tactics. For most institutions that touches five things.

  • Document genuineness. Whether the current checks detect a synthetic or manipulated document rather than only a malformed one.
  • Liveness and injection resistance. Whether the capture path can distinguish a live presentation from an injected stream, which is where deepfake attacks land.
  • Matching evidence. What is retained to demonstrate the link between customer and identity, and whether it would satisfy the word incontrovertibly under examination.
  • Tier logic. Whether limits actually respond to observed behaviour, and who owns the threshold.
  • Intelligence intake. Whether shared tactics reach the team that can recalibrate, on a defined cadence.

A constructive signal for digital identity

Hong Kong has set an explicit expectation that an institution can tie a remote customer to a verified identity to a standard that leaves no room for doubt, in a market where the evidence presented over a camera is cheap to fabricate. The more important half of the circular is that this standard is not a one-time bar. Remote on-boarding controls cannot remain static; they must be continually reviewed and recalibrated as technologies and fraud tactics evolve.

That is a demanding position, and a correct one. It also carries a cost. Each institution is expected to reach the standard on its own, per customer, per on-boarding event, and to keep reaching it as the tactics change, which duplicates the same work across every regulated firm the customer approaches.

Where verifiable credentials fit

At AIR we see a direct role for verifiable credentials in supporting these objectives. Through AIR Identity, trusted issuers can issue reusable, user-held credentials, and institutions can verify proofs that those credentials are valid and come from an approved issuer.

AIR Identity adds a credential layer to existing remote on-boarding checks. It does not replace them: document and biometric controls continue to establish the customer’s identity, which is what the circular’s two core principles ask for.

Circular expectationWhat stays with existing controlsWhat a credential layer adds
Identity authenticationDocument genuineness checks on the identity evidence presentedCryptographic proof that an attestation came from an approved issuer and has not been altered
Identity matchingBiometric and liveness controls linking the person to the documentEvidence that the same holder was previously bound to the credential, carried forward for a relying party to evaluate
Continual recalibrationThreshold and model updates driven by shared fraud intelligenceIssuer status and revocation checked at the point of presentation rather than assumed from a stored record

The tiered approach the circular describes fits the same shape. Where account features and transaction limits are meant to move with assessed risk and observed behaviour, a credential that can be re-presented and re-checked gives a relying party something to raise a tier against, rather than re-running the full on-boarding flow.

Our read

We welcome the HKMA’s clear, risk-based approach to remote on-boarding, and its focus on stronger identity authentication, identity matching, and controls that evolve with emerging threats. The interesting design question it leaves open is whether assurance established once, to that standard, can be presented again to the next relying party in a form they can evaluate and a supervisor can examine, without every firm in the market rebuilding and re-storing the same evidence.

Frequently asked questions

What did the HKMA circular of 3 September 2026 change?

It replaces the HKMA's earlier remote on-boarding guidance for individual customers with a single updated statement of regulatory expectations. Remote on-boarding is now treated as an integral part of AML/CFT controls rather than an alternative channel, and institutions are told to keep those solutions under a continual programme of updates and recalibration against evolving money laundering and terrorist financing risk, including artificial intelligence driven automation and deepfake-enabled impersonation.

Which circulars does it supersede, and which remain in force?

It supersedes "Remote on-boarding of individual customers" of 1 February 2019 and "Remote on-boarding and iAM Smart" of 24 May 2021. Two circulars continue to apply and should be read alongside it: "Remote on-boarding of corporate customers" of 24 September 2020, and the 3 June 2020 feedback from thematic reviews of AML/CFT control measures for remote customer on-boarding initiatives.

What are the two core principles for remote on-boarding?

Identity authentication and identity matching. Under identity authentication, where a customer's identity is obtained through electronic channels the institution should take appropriate measures to ensure the reliability of the document, data or information used to verify it, including using technology to ascertain the genuineness of the identity document. Under identity matching, the institution should use appropriate technology to link the customer incontrovertibly to that identity.

What is the tiered approach the circular describes?

A risk-based design in which account features, functionality and transaction limits are scaled dynamically and adjusted according to actual usage and ongoing customer behaviour, proportionate to the customer's assessed ML/TF risk profile. The HKMA states that combining this with robust remote on-boarding solutions and active senior management oversight can significantly strengthen AML/CFT controls.

Who does the circular apply to?

It is addressed to the Chief Executive of all Authorized Institutions and Stored Value Facility licensees in Hong Kong. It was issued under references B10/1C, B1/15C and B10/21C by Raymond Chan, Executive Director (Enforcement and AML). Questions are directed to an institution's usual contact at the HKMA's AML and Financial Crime Risk Division.

Related reading

Source: Hong Kong Monetary Authority, “Remote on-boarding of individual customers”, circular to the Chief Executive of all Authorized Institutions and Stored Value Facility Licensees, refs B10/1C, B1/15C and B10/21C, 3 September 2026.

What we’re building at AIR

AIR is one integration suite for identity, money and loyalty. AIR Identity lets trusted issuers issue verifiable credentials and businesses verify them, so acquisition starts with users who already qualify, with minimal data custody. AIR Money embeds compliant global financial infrastructure, opening new markets without building new rails. AIR Loyalty gives brands a programmable, stable-value points engine that keeps users coming back.

Partner with us to grow your business.

AIR is built by Moca Network, the identity network of Animoca Brands.

Stay updated on AIR launches
Product updates, partner launches, and research across digital identity, fintech, and loyalty. Unsubscribe anytime.
By subscribing, you agree to our Privacy Policy and consent to receive updates.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
In this article
Blog

Read more articles

Lorem ipsum dolor sit amet, consectetur adipiscing elit.
View all
News
39.5 Million Accounts Leaked, Including the Identifier Koreans Cannot Change
Korea's Tving breach reached 39.54 million accounts, including connecting information, the identifier that links a person across every service they use.
News
Spain Ruled Stored Face Templates Unlawful, and the Defence Was Security
Spain's regulator ruled stored face templates are special category data and fined an identity provider €950,000. The provider says removing them weakens security.
News
Windows 11 Will Tell Apps How Old You Are, but Not When You Were Born
Microsoft documented a Windows 11 API that hands apps an age band instead of a birth date. Apple and Google already ship one. None of them verify the age.