Risk & Controls

Risk & Controls

Risk and control framework

Every identified risk maps to a named control, an accountable owner, a current status and traceable evidence — the same standard applied to traditional wholesale payment products.

New to the wording on this page? 8 terms explainedShow

AMLAnti-Money Laundering

The rules and checks banks must run to stop criminal money passing through them — screening names against watchlists, monitoring for suspicious patterns, and investigating anything unusual.

For example: An account that normally receives HK$50,000 a month suddenly receives fifty separate HK$49,000 payments in a week. That pattern triggers an alert, because breaking a large sum into smaller pieces is a classic way of hiding its origin.

KYCKnow Your Customer

Verifying who a customer actually is before letting them bank with you — checking identity, who really owns the company, and where their money comes from.

For example: Opening a corporate account requires passports of the directors, proof of who ultimately owns the company, and evidence of what the business actually does. It is why opening a business account takes weeks, not minutes.

Sanctions screening

Checking every payment's sender, receiver and purpose against government lists of banned people, companies and countries before the money moves.

For example: A payment to 'M. Ivanov' is automatically held because that name resembles someone on a sanctions list. A human then checks whether it is the same person or an innocent match — most are innocent, which is why the review step exists.

Legal finalitySettlement finality

The point at which the law says a transfer is permanent and cannot be unwound — including if one party later goes bankrupt. It is a legal question, decided country by country, and is not the same as software saying 'complete'.

For example: Your system shows a payment as settled at 10:00. At 11:00 the receiving company collapses and a court decides the 10:00 transfer can be clawed back into the bankruptcy pool. Technically it settled; legally it was not final.

Reconciliation

Checking that two separate records of the same thing actually agree — for example that the token ledger and the bank's main account system show the same balance. A mismatch is called a break.

For example: Like comparing your receipts against your bank statement at month end. If the statement says HK$4,000 and your receipts total HK$4,200, you have a break and must find the missing HK$200 before closing the books.

NPANew Product Approval

A bank's formal internal sign-off before launching anything genuinely new. Risk, legal, compliance, operations and technology all have to agree — not just the commercial team.

For example: Before the first client can use a tokenised deposit service, each function signs off in turn. Any one of them can block it. This is usually why bank products take far longer to launch than startup products.

RTO and RPORecovery Time Objective and Recovery Point Objective

Two disaster-planning targets. Recovery time is how fast a system must be back after an outage. Recovery point is how much data you can afford to lose — how far back the last usable backup may be.

For example: A recovery time of 15 minutes and a recovery point of zero means: after a total failure, the service must be running again within 15 minutes and must not lose a single transaction. That combination is expensive, which is exactly why it gets debated.

SLAService Level Agreement

A written promise about service performance — and, just as importantly, what counts as a failure.

For example: 'Any held payment will be reviewed within two hours during business days.' If it takes six hours, the bank has formally breached the agreement, which may carry financial consequences.

See every term used across this site

Total controls

23

High risk

8

Medium risk

12

Low risk

3