When a client emails to change account particulars, or asks for a withdrawal to a third party, what verification does the SFC expect licensed corporations to do?
Answer
Under Circular 25EC32 (6 June 2025), licensed corporations cannot rely on an apparent signature match or on simply replying to an email. For changes to client particulars, verify identity and signatures (even if the signature looks genuine), independently check with the client using alternative registered contact information on at least a reasonable sample basis or when uncertain, and send acknowledgements to registered contacts not being changed. For email instructions, match the sender to official records and, where the request is suspicious or over a reasonable threshold, confirm via alternative registered contacts — never by replying to the same email. For third-party withdrawals / physical scrips, discourage third-party payments; allow them only in exceptional, legitimate cases with due diligence and management approval; before release, confirm directly with the client and verify the third party’s identity.
Scroll sideways for the full table
| Change of client particulars | Email instructions | Third-party deposits/payments & physical scrips | |
|---|---|---|---|
| Circular pin | 25EC32 (a); Appendix 2 item 1 | 25EC32 (b); Appendix 2 item 2 | 25EC32 (c); Appendix 2 item 3 |
| Core duty | Written authorisation; verify identity and signatures even if the signature looks genuine | Assume compromise risk; match the sender to official records | Policy that discourages third-party deposits and payments |
| Independent check | Alternative registered contacts; at least a reasonable sample or when uncertain | Suspicious or over a reasonable threshold: confirm via alternative registered contacts — do not reply to the email | Before release: confirm authenticity directly with the client; verify the third party’s identity against the written authorisation |
| Notifications / process | Acknowledgements to registered contacts not subject to change (when requested and when made); anomaly screening; maker-checker + audit-log review | Staff guidance and regular training on email scams / BEC | Exceptional and legitimate only; due diligence; management-approved policies and procedures |
Why the SFC issued Circular 25EC32
Circular 25EC32 (6 June 2025), Review of internal controls on client asset protection, shares the key findings of the SFC’s 2024 exercise on the client accounts of selected small to medium-sized securities brokers — on-site inspections of 12 brokers, conducted with an external consultant — together with red flags from reported asset misappropriation cases (Appendix 1) and the expected regulatory standards (Appendix 2).
The fraud pattern is consistent. Fraudsters impersonate clients: emails from forged or lookalike addresses (one case used contact@domainn.com against the genuine contact@domain.com) or from a hacked client email account; or counterfeit written instructions bearing forged signatures, sent by post, fax or email. The instructions typically first amend client particulars — phone numbers, email or correspondence addresses — to intercept statements of account, then move assets: significant transactions, transfers of securities to third-party accounts, physical scrips collected by third parties, or withdrawals to third-party or non-designated bank accounts opened purportedly in the client’s name but controlled by the fraudster.
The circular grounds these duties in the licensed corporation’s existing obligation to maintain internal controls protecting its operations and clients from theft, fraud and other dishonest acts (Code of Conduct, paragraph 4.3).
Lane A — change of client particulars
Handle amendment requests — correspondence address, email address, phone number, designated bank accounts, authorised representatives — with due care, supported by the client’s written authorisation. Verify the requestor’s identity and signature even if the instruction seemingly bears the client’s signature: signatures can be forged.
- Independent verification. Confirm directly with the client, at least on a reasonable sample basis or whenever there is uncertainty, using the client’s alternative registered contact information in the firm’s official records.
- Acknowledgements. When amendments are requested and when they are made, promptly notify the registered address, email or mobile phone that is not being changed.
- Anomaly screening. Check new contact details against the client database for common or similar patterns. Appendix 2’s examples: a new email address with an unusual username or domain (mahjong123@domain.com versus clientname@domain.com); a new bank account in a country outside the client’s usual residential or work location, even if in the client’s name; new correspondence addresses, email addresses or phone numbers identical to or closely resembling those of other clients.
- Process controls. Maker-checker controls for changes to the client database, and regular review of the system audit logs by designated staff independent of those making the changes.
Lane B — email instructions
Treat every emailed instruction — order placing, asset transfer or amendment of particulars — as carrying compromise risk: the client’s email account may have been hacked. Policies and procedures should address that risk.
- Verify the sender’s email address against the firm’s official records.
- For suspicious instructions, and requests involving amounts over a reasonable threshold, verify authenticity — for example, confirm with the client using alternative registered contact information. Never verify by replying to the same email.
- Give staff sufficient guidance and regular training on identifying email scams; the SFC’s business email compromise circular (22EC25) sets out the expected handling.
Lane C — third-party withdrawals and physical scrips
Third-party transactions carry higher misappropriation and money-laundering risk. The expected policy discourages third-party deposits and payments, accepting them only in exceptional and legitimate circumstances that are reasonably in line with the client’s profile and normal commercial practices, after proper due diligence and with management approval (see also Circular 19EC39).
Before client money or securities are released to a third party, or physical scrips are collected by a third party on the client’s behalf, the firm must confirm the request directly with the client — for example by calling the registered phone number — and verify the third party’s identity against the client’s written authorisation.
Practice boundaries
Three operational rules run through all three lanes:
- Never confirm through the inbound channel — not the email that carried the request, and not the new phone number or address contained in the request itself. In one Appendix 1 case, settlement staff “confirmed” a change of particulars by calling the new mobile number the fraudster had supplied.
- Maker-checker plus independent log review. No single person should both input and approve changes to the client database; audit logs should be generated and reviewed by staff independent of the change.
- Front office stays out of asset movements. Dealing staff and account executives should not handle non-trade matters — fund or stock deposits and withdrawals, changes of particulars — unless compensating controls apply, such as back-office settlement staff verifying relayed instructions directly with the client (Appendix 2, item 7).
Scope of this answer
Circular 25EC32 also covers the operation of bank accounts (authorised-signer arrangements; consider requiring two or more signers for bank payments) and dormant accounts (classify an account as dormant after a period without client-initiated activity, which should not exceed 24 months, and monitor it closely). Both are related lanes under the same circular but sit outside this question. This piece summarises verification expectations; it is not a guide to section 180 inspections.
Related
Discuss your SFC matter
If your firm has received a questionable change-of-particulars request or third-party withdrawal instruction, is reviewing its verification procedures under Circular 25EC32, or has discovered a possible misappropriation of client assets, contact Liva Law. At first contact, please give your name, a safe contact number and any deadline you face. Please do not send confidential documents until we have confirmed how they should be provided and whether we can act.
Call +852 3520 3333Email Liva LawMessage us on WhatsAppView all contact details
This article provides general information only and does not constitute legal advice. The appropriate approach depends on the facts and applicable requirements.