The Securities and Futures Commission ("SFC") issued a circular on 20 Aug 2026 highlighting risks associated with simplified eDDA arrangements for licensed firms receiving client deposits and outlining required mitigation measures.
This article was generated using SAMS, an AI technology by Timothy Loh LLP.
On August 20, 2026, the Securities and Futures Commission ("SFC") issued circular SFO/IS/033/2026 to highlight risks associated with simplified Electronic Direct Debit Authorisation ("eDDA") arrangements adopted by licensed corporations, SFC-licensed virtual asset service providers, and associated entities (collectively, 'licensed firms'). eDDA is a Faster Payment System service enabling payers to pre-authorise direct debit payments from their own bank accounts by payees. While standard eDDA requires clients to initiate setup requests through their banks, simplified eDDA allows licensed firms to initiate requests on the basis of client pre-authorization and information. This arrangement facilitates fund transfers from clients' same-name bank accounts to trading accounts via mobile applications or websites.
Simplified eDDA Setup Process and Indemnity Obligations
The setup process typically involves a client providing pre-authorization and bank account details, including bank name, account number, owner's name, and identification document type and number, to the licensed firm via its trading platform. The firm submits this request to its bank (payee bank), which transmits it to the client's bank (payer bank) for verification. Depending on payer bank practices, client confirmation may be required; if not, the licensed firm may be required to confirm authorization was obtained and indemnify its bank against losses, liabilities, or third-party claims arising from eDDA processing or deposits.
Risk Profile: Impersonation and Financial Liability
Risks associated with simplified eDDA arrangements include impersonation and unauthorized access, where stolen personal and bank account information is used to initiate setup requests without the owner's knowledge. Additionally, firms face indemnity and financial risks from fraudulent or unauthorized eDDA setups, as well as disputes arising from erroneous requests containing inaccurate information submitted by the firm. Licensed firms are reminded of their obligations to maintain proper internal control procedures and adequate financial and operational capabilities to protect operations and clients from financial loss arising from fraud and other dishonest acts.
Pre-Implementation Risk Assessment
Before entering or continuing existing simplified eDDA arrangements, licensed firms should review indemnity terms provided to their banks, identify payer banks facilitating these arrangements, and determine if client confirmation is required. Firms must assess relevant risks, including erroneous, unauthorized, or fraudulent requests, and evaluate their operational capabilities and financial resources to address such risks. This risk assessment should be reviewed periodically or whenever material changes occur to the scale or risk profile of the arrangements. Firms should have a thorough understanding of related risk exposures and obligations, including reviewing service agreements, terms of business, and other contractual documents with their banks.
Verification of Authorization and Identity
Before processing new simplified eDDA setup requests, licensed firms must take reasonable steps to ascertain authorization. If payer banks require confirmation, firms should assess the robustness of the authentication process through enquiries with the payee or payer bank. If confirmation is not required, firms should verify account ownership by requiring a one-off small-value fund transfer and verifying the account holder's name against the deposit record. Identification information must be identical to firm records or verified via document submission where it differs. Firms must adhere to applicable limits on designated bank accounts and the bank account registration mechanism. Clients onboarded via 'online onboarding of clients using a designated bank account in Hong Kong' should not have initial deposits processed through simplified eDDA unless authorization is confirmed, and firms should not rely solely on client-provided deposit records for ownership ascertainment.
Ongoing Monitoring and Red Flag Indicators
Where verification measures cannot be satisfied or red flags are detected during ongoing monitoring, licensed firms should decline eDDA setup requests or withhold processing of deposit instructions. Red flags include repeated failures, frequent or large deposits without legitimate purpose, inconsistencies with financial profiles, new eDDA setups followed by wallet whitelisting, or suspicious deposits converted to virtual assets and withdrawn shortly thereafter. Firms must promptly investigate and assess whether transactions warrant reporting to authorities, such as the Joint Financial Intelligence Unit or Anti-Deception Coordination Centre of the Hong Kong Police Force ("HKPF"). Firms are also reminded of notification obligations to the SFC under paragraph 12.5 of the Code of Conduct and paragraph 16.7 of the VATP Guidelines.
Risk Mitigation and Alternative Arrangements
Licensed firms should consider implementing supplementary measures to mitigate risks, such as imposing limits on transaction amounts or frequency, introducing withholding periods after eDDA Deposits, or requiring step-up authentication based on client profiles and risk assessments. Where risks cannot be adequately mitigated, firms should use alternative deposit arrangements, such as standard eDDA, bank transfers, or other appropriate means. Firms should review and amend client agreements to ensure they remain appropriate in light of risk mitigating measures and promptly notify clients of any related changes.
Client Disclosure and Regulatory Compliance
Licensed firms must disclose eDDA settings, including transaction limits and expiry dates, obtain client consent, and remind clients to review settings with payer banks. Firms should also remind clients to regularly review registered bank accounts for eDDA Deposits, monitor transactions for irregularities, and contact the firm or banks immediately upon spotting suspicious activities, reporting to the HKPF as appropriate. The SFC recognizes the importance of safe use of these arrangements and continues to engage stakeholders. Licensed firms should continue to assess risks and implement mitigating measures. Queries should be directed to Ms Kiki Wong at 2231 1569. This circular is referenced as SFO/IS/033/2026. Firms are reminded of obligations under the Code of Conduct and VATP Guidelines, including paragraph 4.3 of the Code of Conduct, paragraph 11.10 of the VATP Guidelines, paragraph 12.5 of the Code of Conduct, and paragraph 16.7 of the VATP Guidelines, and should refer to Chapter 5 and Chapter 7 of the Guideline on Anti-Money Laundering and Counter-Financing of Terrorism.
View the full article:Source