Saturday, November 12, 2022

Summary Review of SFC's Disciplinary Action against Swiss-Asia

On 8 November 2022, SFC fined Swiss-Asia Asset Management (HK) Limited $3 million for internal control failings and regulatory breaches in relation to the monitoring of trading activities in discretionary accounts and record keeping.

In mid-April 2015, a client signed an asset management mandate granting Swiss-Asia full discretionary power to manage the account, subject to certain management restrictions, e.g.
  • Swiss-Asia could sell covered call options on existing securities and option strategies which have defined risk.
  • It should not include any option strategies that involved uncapped risk or purchase options as a speculative strategy for the portfolio.

In late August 2016, the client complained to Swiss-Asia that its licensed representative conducted option trading in the account which was much riskier than agreed.

From May 2015 to August 2016, the licenced representative placed a total of 869 options trades in the account. Swiss-Asia only submitted to SFC in April 2017 that it had identified 225 of these options trades to be outside the management restrictions.

Swiss-Asia asserted that its responsible officers would randomly select five to seven portfolios on a monthly basis and conduct rough high-level reviews on them, which is considered inadequate by SFC. It did not maintain records of such random sample checks.

As a result of this case, Swiss-Asia has revised its internal control policies and procedures such that post-trade checks would be conducted on all accounts on a weekly basis. Any breaches in investment strategies or exceptions in the investment restrictions would be documented and escalated to executive management.

Swiss-Asia claimed that it operated with the support of the three lines of defence, i.e. (1) management supervision, (2) oversight by the legal and compliance team, and (3) audit by external auditors. SFC questions how legal and compliance as well as external auditors could perform their functions properly and effectively without records of the sample checks. I also question if legal and compliance (rather than risk management) would have the expertise in option strategies to identify breaches of investment mandate.

SFC highlights that the monitoring of trading activities are important for the detection and prevention of potential market misconduct (i.e. not just breaches of investment mandate). If this case involved also market misconduct, the penalty would be much higher.

SFC's Statement of Disciplinary Action is found here.

Wednesday, July 06, 2022

Proposed Amendments to SFO: Advertisements of Investment Products

In June 2022, SFC published a consultation paper on proposed amendments to the SFO. The proposal contains 2 enforcement-related amendments and the other one relating to the professional investor (PI) exemption (PI amendment) under section 103 of the SFO. I discuss the PI amendment in this article.

The PI amendment is triggered by the Pacific Sun case happened many years ago, summarized as follows:

  • SFC announced on 21 Mar 2013 that Pacific Sun Advisors Limited and its director Andrew Mantel were charged for issuing an advertisement on the corporate website promoting "Pacific Sun Greater China Equities Fund" (the Fund) without SFC's authorization. The defendants submitted that they intended to sell the Fund only to PIs and so the advertisements did not require SFC's authorization under the PI exemption. Surprisingly, the Magistrate accepted the defendants' argument and acquitted them.
  • SFC announced on 10 Jun 2014 that following its appeal, the Court of First Instance (CFI) issued a ruling in Jan 2014 clarifying that the advertisements in question did not fall within the PI exemption and ordered the case to be returned to the Magistrate for reconsideration. The CFI made it clear that the exemption only applies where the advertisement states on its face that the terms of the offer are limited to PIs. As a result, the defendants were convicted at the Magistrate.
  • SFC announced on 20 Mar 2015 that following the defendants' appeal, the Court of Final Appeal (CFA) overturned the ruling of the CFI in that the PI exemption applies even if the intention to sell the Fund only to PIs is not expressed in the advertisement, unless the Fund is subsequently sold to a retail investor. It follows that contravention of section 103 of the SFO can only be established well after the offer to the public has been issued.
SFC has definitely thought the CFA's ruling is not in line with the intention of the PI exemption. SFC expressed on 20 Mar 2015 that it will study the CFA's decision to determine whether there should be any proposal to amend section 103 of the SFO. However, SFC has not taken any action until Jun 2022.

In the consultation paper, SFC proposes an amendment to section 103(3)(k) to restore the PI exemption to the original point in time when the advertising materials are issued. Therefore, following the proposed amendments, unauthorized advertisements of investment products which are intended to be sold only to PIs may only be issued to PIs who have been identified as such in advance by an intermediary through its know-your-client and related procedures, regardless of whether or not such an intention has been stated on the advertisements.

My views:
  • The CFA's ruling was weird. Even the CFA made it clear that the burden of establishing the PI exemption applies rests on the defendants, it didn't say expressing the intention to sell the Fund only to PIs was a must.
  • SFC's proposed amendments overshoot. It sounds impractical to require an intermediary to identify the PIs (esp. corporate and individual clients) in advance before issuing unauthorized advertisements of investment products.
  • My stance is close to the Magistrate's decision in 2014. Section 103 should be amended to require an intermediary to express prominently in the advertisements that the unauthorized product is intended to be sold only to PIs, otherwise the PI exemption won't apply. SFC can subsequently sample check if the intermediary has sold the product to retail investors.

Monday, January 10, 2022

Customer Supplied Systems

On 30 Dec 2021, SFC announced that it reprimanded and fined Grand International Futures Co., Limited (GIFCL) $8,000,000 and suspended the licence of GIFCL's responsible officer, Mr Liang Benyou for 8 months.

Liang has been accredited to GIFCL and approved to act as its responsible officer for RA2 and RA5 since 3 October 2017. Liang has been GIFCL's MIC of the OMO, OCR, Compliance and IT since 1 Sep 2017, and MIC of KBL since 4 Apr 2018. This is probably the first time a MIC of Compliance was sanctioned by SFC, though obviously Liang was not a full-time compliance professional.

Summary of Facts

  • SFC received a complaint against various LCs, including GIFCL, for allowing clients to place orders to their broker supplied systems (BSS) through a software called Xinguanjia (XGJ). XGJ was developed and/or provided by Hengxin Software Limited.
  • The complainant alleged that XGJ permitted the LCs' clients to create sub-accounts under their accounts maintained with the LCs, and the clients had solicited investors in Mainland China to trade through the sub-accounts via XGJ without having to open separate securities accounts with the LCs in Hong Kong.
  • Between Oct 2017 and Oct 2018 (Relevant Period), GIFCL has permitted 103 clients to use their designated customer supplied systems ("CSSs", including XGJ) for placing orders. From Dec 2017 to Oct 2018, the number of futures contracts transacted by GIFCL clients through orders placed via CSSs accounted for 93.92% to 99.25% of its monthly trading volume.

Failure to perform adequate due diligence on the CSSs and assess and manage the associated ML/TF and other risks

  • Before allowing its clients to connect their CSSs to its BSS, GIFCL would require its clients to: (a) complete an application form and risk disclosure statement; and (b) apply for authorisation from its BSS Supplier. But GIFCL did not perform any due diligence or testing on the CSSs used by its clients.
  • While GIFCL claimed that it relied on the BSS Supplier to conduct due diligence on the CSSs, the BSS Supplier stated that GIFCL had never instructed it to, and it did not, conduct any due diligence or test on the CSSs to examine their design and functions.
  • In the absence of proper control over the use of CSSs by its clients, GIFCL has exposed itself to the risks of improper conduct such as unlicensed activities, money laundering, nominee account arrangement and unauthorized access to client accounts.

Failure to conduct proper enquiries on client deposits which were incommensurate with the clients' financial profiles

  • SFC's review of the fund movements in sample client accounts showed that the amounts of deposits made into the accounts of four clients (Four Clients) were incommensurate with their financial profiles declared in their account opening documents, which were unusual and/or suspicious (Anomalies).
  • GIFCL claimed that it was aware of the Anomalies during the Relevant Period. As part of its monthly monitoring measure, it had contacted the top clients (including the Four Clients) via WeChat to understand the client situation (Monthly Monitoring).
  • However, the Monthly Monitoring was inadequate:
    • GIFCL did not document the policies and procedures governing the Monthly Monitoring.
    • The scope of the Monthly Monitoring was limited to top 10 clients with the highest number of transactions and top 10 clients with the highest amount of deposits.
    • GIFCL has not maintained any record of the Monthly Monitoring, including its enquiries allegedly made with the Four Clients and their responses to the enquiries.

Failure to maintain effective ongoing monitoring system to detect and assess suspicious trading patterns in client accounts
  • SFC’s review of the transactions in sample client accounts showed that there were 100,989 self-matched trades (i.e. the client’s order matched with his/her own order in the opposite direction) (Matched Trades) in nine client accounts during the Relevant Period. But GIFCL was not aware of the Matched Trades at the material time.
  • During the Relevant Period, GIFCL relied on its dealing department to monitor client trading activities. However, it did not provide its staff with any guidelines or procedures for such monitoring.

As a result, SFC remarked that LCs should assess the risks of any new products and services (especially those that may lead to misuse of technological developments or facilitate anonymity in ML/TF schemes) before they are introduced and ensure appropriate additional measures and controls are implemented to mitigate and manage the associated ML/TF risks. Approving the use of CSSs by clients is indeed a new challenge to LCs.

In addition, as SFC said, the LCs' clients had solicited investors in Mainland China to trade through the sub-accounts via XGJ without having to open separate securities accounts with the LCs in Hong Kong. This may even facilitate the breach PRC's regulations which restrict cross-border online brokers.

Wednesday, September 01, 2021

Provision of False Client Documents and Information

On 30 Aug 2021, SFC announced that it suspended Mr Cheung Man Chit, a former licensed representative of Emperor Securities Limited and Emperor Futures Limited (collectively, Emperor), for two years. The facts are summarized below.


Submission of false client documents and information to Emperor

  • Cheung received two sets of client agreements from Client L and H in around Aug 2013 for the opening of Client L's accounts at Emperor, but submitted to Emperor the one received from H. Further, he falsely certified and claimed to have witnessed Client L's signing of the submitted client agreement.
  • In around Jan 2014, Cheung received three payment forms authorising fund transfer from Client L to H, one from Client L and two from H. He submitted to Emperor the two payment forms received from H and not signed by Client L, one of which resulted in the $300,000 Transfer which Client L alleged was not authorised by her.
  • He handled and submitted to Emperor six other account documents of Client L which were not signed by her between Nov 2013 and Jun 2014.
  • Cheung provided his own addresses, and an email address he created, to state as the residential addresses and email address of another client (Client Y) in her client agreement and a change of particulars form which he submitted to Emperor.

Transfer of funds for clients

  • Between Jun 2014 and Jan 2017, the accounts of Client Y and another client (Client C) at Emperor recorded transfers totalling around $3.2 million to/from Cheung's bank account or the bank account of a company solely owned by him (Company U) on 15 occasions. Ten of the 15 transfers were made pursuant to third party deposit/payment request forms (Third Party Forms) of the clients signed by Cheung as the handling account executive.
  • Cheung admitted that he helped the clients transfer money to/from the Mainland using his and Company U's bank accounts, and claimed that he did not receive any benefit for transferring money for the clients. He accepted that the money transferred from the Emperor accounts of the clients had been mingled with the money in his and Company U's bank accounts.
  • To secure Emperor's approval of the third party fund transfer requests of the clients and get around the need to provide supporting documents required under the firms' then policy, he falsely stated in the clients' Third Party Forms that they were directors of Company U, he and Client C were business partners, and the reason for payment was capital recovery by Company U.
Using a client's password to place trade orders in her online trading account
  • Client C opened an option account at Emperor in May 2014. Based on the records of internet service providers, 84 orders were placed in her option account via internet from IP addresses subscribed by Cheung or situated at the offices of Emperor and his new employers between Jun 2014 and Aug 2017.
  • Cheung stated that he placed orders for Client C via internet as a friend and did not receive any personal benefit from her. Client C only paid commission to Emperor for the trades.
Failure to inform SFC and Emperor of directorship / proprietorship
  • Cheung has been the sole proprietor of Company U and the director of another company since their incorporation in around 2010 and January 2018.
  • He did not report to SFC his directorship and proprietorship of the two companies in his licence application and throughout the period when he was licensed with SFC.
  • Cheung did not notify Emperor of his proprietorship of Company U during his accreditation with the firms pursuant to their internal policy.

My comments on this case:
  • In terms of variety, severity and duration of Cheung's misconducts, licence suspension of two years seems too lenient.
  • Emperor's account opening, trading and settlement procedures had been abused by Cheung. The relevant internal controls and monitoring should be strengthened.

Wednesday, August 04, 2021

Various Regulatory Breaches of UBS

A large-cap investment bank is supposed to have a more robust compliance mechanism than mid-cap/small-cap ones, but it is not immune from regulatory breaches.

On 3 Aug 2021, SFC announced it reprimanded and fined UBS AG and UBS Securities Asia Limited (UBSSAL) (collectively, UBS) $9.8 million and $1.75 million respectively over various regulatory breaches.


Disclosure of financial interests in research reports

  • Between May 2004 and May 2018, UBS failed to make proper disclosure of its financial interests in some Hong Kong listed issuers covered in its research reports in breach of para. 16.5(a) of the Code of Conduct.
  • The failure was caused by (i) multiple data feed logic errors in relation to a legacy data source used by UBS for tracking its shareholding positions; and (ii) UBS’s lack of proper systems and controls to test the accuracy of, and detect the logic errors in, the data feeds.
  • Based on UBS's review, the failure affected 80 (6.43%) research reports issued by UBSSAL and 125 (14.59%) research reports issued by UBS AG during sample periods between Sep 2017 and May 2018.

Compliance with the Client Securities Rules ("CSR") and Contract Notes Rules ("CNR")

  • Between Nov 2012 and Feb 2019, UBS AG failed to diligently supervise its client advisors and implement sufficient controls to ensure that only professional investor ("PI") clients were subscribed to the securities pooled lending ("SPL") service. As a result, 2,263 non-PI clients were subscribed to the SPL service, out of which 91 clients entered into 913 SPL transactions with UBS AG.
  • As UBS AG had wrongly assumed that these clients were PIs, it failed to obtain valid standing authorities from and issue contract notes to them in respect of the SPL transactions, in breach of sections 4 and 7 of the CSR and section 5 of the CNR.


Compliance with the telephone recording requirement

  • Between Aug 2017 and Jun 2019, UBS AG had failed to record client order instructions received through the telephone in breach of paragraph 3.9 of the Code of Conduct:
    • Between Aug 2017 and Dec 2017, the order instructions placed through 8 overflow lines for 2,006 transactions executed for 364 clients were not recorded. This was caused by an omission in the voice recording setting during the migration of UBS AG’s telephone system to a new system. Due to the wrong assumption held by the project team responsible for the migration that overflow lines of UBS AG’s wealth management department would be automatically recorded after migrating to the new telephone system, it failed to enable the recording function of such phone lines during and after the migration.
    • Between Nov 2018 and Jan 2019, the order instructions placed. through a telephone line for 20 transactions executed for 5 clients were not recorded. This was caused by an omission to re-activate the voice recording function when the telephone line was transferred from a former client adviser to a newly joined client adviser.
    • Between 13 and 17 Jun 2019, the order instructions placed through 26 telephone lines for 96 transactions executed for 51 clients were not recorded. This was caused by human error in the course of transitioning UBS AG's telephony system from Skype for Business soft phones to Cisco desk phone which led to a break in the voice recording system.


Assessment of clients' derivatives knowledge

  • Prior to 2018, UBS AG required its staff to obtain trading evidence (such as bank statements) from clients who declared that they had conducted five or more derivative trades in the past 3 years. UBS AG discontinued this practice in 2018 due to its misinterpretation of another FAQ issued by SFC.
  • As a result, between 2 Jan 2018 and 17 Jun 2020, UBS AG failed to follow applicable regulatory guidelines relating to the assessment of clients' derivative knowledge by failing to obtain trading evidence from 858 clients who declared that they had conducted 5 or more derivative trades in the past 3 years, in breach of paragraph 5.1A of the Code of Conduct. Out of these 858 clients, 380 of them have subsequently traded derivative products with UBS AG.


Disclosure of product risk

  • UBS AG had failed to disclose to its clients the "stop loss event" feature of a structured note issued by an issuer (Notes) before trade execution. The failure affected 15 client accounts involving the sale of 12 Notes between Oct 2017 and Feb 2020 for a total notional amount of about US$12 million.
  • UBS AG's disclosure failure was caused by an omission of the stop loss event feature in the additional product sheet prepared by UBS AG's Structured Product Sales Team in Singapore (SP Team). The SP Team member who prepared the additional product sheet was not aware of the stop loss event feature. When another SP Team member reviewed the draft additional product sheet, he noted that the stop loss event feature was not included but he did not raise any issues as he considered the stop loss event feature to be insignificant as compared to the issuer default risk. UBS AG discovered the failure when handling a client complaint in Apr 2020.


Other investment banks may take this comprehensive case as a good reference when reviewing their own internal controls.

Wednesday, June 30, 2021

Operation of House and Client Bank Accounts

On 28 Jun 2021, SFC issued a circular about operation of bank accounts.  This 7-page circular is quite clumsy and repetitive.  Its essentials can be summarized as follows:

  • Authorised signers for effecting payments out of a LC's client bank accounts should only be RO, MIC or his / her delegate.
  • Authorised signers for effecting payments out of a LC's house bank accounts should be:
    • RO, MIC or his delegate; or
    • Any other person, provided that such person can only effect payments jointly with RO, MIC or his delegate.
The "delegate" should be accountable to the RO or MIC, e.g. staff of the LC, staff of the LC's group companies, or a payment processing agent.

SFC issued this circular because it has noted cases of LC's unsatisfactory practices.  For example, a LC's house or client bank accounts were operated solely by a shareholder, a director or a nominee of a shareholder or director, and these were not RO, MIC or their delegates.  The authorised signers were not subject to appropriate oversight in relation to the operation of the LC's bank accounts and were not accountable to any RO or MIC.

SFC requires LC to critically review their existing policies and procedures to ensure full compliance with this circular.  To account for the time of making necessary changes, SFC leniently allows LC to implement the expected standards by 3 Jan 2022.  I wish no LC collapse during the transitional period due to lax operational controls over bank accounts.

Tuesday, June 29, 2021

Suspected Ramp and Dump Scams

This year SFC has put substantial efforts to combat ramp and dump scams involving market manipulation of Hong Kong listed shares.  Today it issued a circular to remind intermediaries of their existing obligations under para. 12.5(f) of the Code of Conduct to report suspected market misconduct suspected of their clients to SFC timely manner.

Most importantly, this circular provides a non-exhaustive illustrative list of red flags may indicate a potential ramp and dump scam:

  • Clients whose transaction amounts are generally incommensurate with their reported profiles. For example, a client, who is unemployed with no significant previous trading experience and has limited reported assets, conducts a large volume of trading in a stock in a short period of time;
  • Clients who regularly acquire shares through bought and sold notes or on a free-of-payment basis or who receive large third-party deposits in their accounts;
  • Clients who bought shares on a delayed settlement basis, following which the share price rose substantially during the delayed settlement period, and then gave instructions before the payment date to sell these shares;
  • Clients who bought shares in a particular stock towards the end of the trading day in a way that had the effect of substantially raising the closing price on a number of days, particularly when the company is a thinly-traded, small-cap stock with a highly concentrated shareholding and it has experienced a sustained price increase which cannot be explained by any corporate or sector-specific news;
  • Clients who sold a large volume of shares in a particular company shortly before a collapse of the share price which cannot be explained by any corporate or sector specific news.  It would be particularly suspicious if clients seek to receive the funds immediately following the selling instruction and before the completion of the normal T+2 settlement period;
  • A group of clients, some of whom are identified from the trading behavior set out above, traded in the same stock in the same direction, at more or less the same price or at the same time, and exhibit any of the following characteristics:
    • they have authorised the same third party to operate their accounts;
    • they have effected fund transfers amongst themselves;
    • they opened accounts on or around the same day, were served by the same account executive or referred to the intermediary by the same person at account opening; or
    • they share the same personal particulars such as telephone numbers or email addresses.
In my compliance practice, I had witnessed most of the above red flags and taken necessary actions against those suspicious clients.  This circular is in fact a summary of good industry practices.