You send the request, so you own the authorisation
The wire moved again. One circular landed in the week just gone, and it is a substantive one: the SFC has looked at how client money arrives at internet brokers and virtual asset platforms, and decided the convenient version of that plumbing puts the firm, not the bank, on the hook.
Simplified eDDA: you initiate the debit, so you carry the authorisation
On 20 August the SFC issued Circular 26EC51 on the growing use of simplified eDDA arrangements for receiving client deposits. The distinction it turns on is small and easy to miss. Under a standard eDDA, your client sets up the direct debit through their own bank. Under a simplified eDDA, your firm does it — as payee, you submit the setup request to your own bank on the strength of the client’s pre-authorisation and the details they typed into your app: bank name, account number, account owner’s name, and the type and number of the identification document used to open that bank account.
Your bank passes the request to the client’s bank. And here is the part that matters: the payer bank may or may not ask the account owner to confirm it. Where it does not, the SFC’s position is that the firm which initiated the request bears primary responsibility for having obtained proper authorisation from the bank account owner. Your bank may separately require you to confirm you have it, and may require you to indemnify it against losses, liabilities and third-party claims arising from the setup or the deposits that follow.
So the two named risks are not abstract. One is impersonation and unauthorised access — somebody who has got into a client’s trading account, with stolen personal and bank details, setting up a debit the real account owner never knew about. The other is the indemnity: a fraudulent or simply erroneous request, and the claim lands on your balance sheet.
-
Who’s in scope: licensed corporations, SFC-licensed virtual asset service providers and associated entities that use simplified eDDA to receive client deposits — the circular names internet brokers and virtual asset trading platform operators as the typical users. If your clients fund their accounts only by ordinary bank transfer or standard eDDA, this one is a reading exercise, not a project.
-
What to do: two things, in order. First, assess: read the service agreements, terms of business and other contractual documents with your bank, and specifically the terms of any indemnity you have given or are about to give. Identify which payer banks your payee bank can facilitate, and find out which of them require owner confirmation. Judge whether your operational capability — and your financial resources to meet potential claims — match that exposure, and re-run the assessment periodically and whenever the scale or risk profile changes.
Second, before you process any new setup request, establish two facts. That the request is authorised by the account owner: either satisfy yourself the payer bank has a robust authentication process for confirming that (asking through your own bank, or the payer bank directly), or ask the client for a one-off small-value transfer from that very account and match the account holder’s name against the deposit record your bank gives you. And that the identification information submitted is verified: accept only details identical to your own client records — name, ID document type, ID number — or, where they differ, obtain the identification document purportedly used to open the bank account.
-
By when: the circular sets no deadline, which is not the same as no urgency. The trigger is transactional: the checks above apply before processing any new simplified eDDA setup request, and the risk assessment is expected before entering into or continuing with existing arrangements. In practice that means the next request through your app is already in scope.
Where those checks cannot reasonably be satisfied, or your ongoing monitoring throws a red flag, the expectation is to decline the setup and/or withhold the deposit instruction and anything that follows on that account until you have done the follow-up work. The red flags listed are worth pasting straight into your monitoring rules: repeated failed setup requests or deposits; frequent or large eDDA deposits in a short period with no apparent commercial rationale; deposits inconsistent with the client’s financial profile or historical pattern; a new eDDA setup followed by the whitelisting of a new virtual asset wallet address, or the reverse, particularly for an existing client; and deposits converted into virtual assets and withdrawn shortly afterwards.
Two smaller obligations ride along with it. Disclose the eDDA settings — any limits on amount or frequency, any expiry date — get the client’s consent to them, and remind clients to review their registered accounts and watch their own bank statements. And if you cannot mitigate the risk adequately, the circular is blunt about the alternative: use standard eDDA, bank transfers, or another appropriate method instead.
- TechnologyHKEX’s Post Release Test 2 on 22 August has now passed, so the schedule in 26EC44 has one session left: PRT 3 on Saturday 5 September, and it is optional. If PRT 2 threw anything at your SFTP connectivity, that is the last rehearsal before the backbone cutover in which to prove the fix.
- AMLThis week’s circular is the deposit-side twin of 26EC29, the May review of 12 securities brokers that found questionable and forged documents accepted at account opening. Same question, asked twice: do you actually verify that the person in front of you owns what they say they own, or do you accept the document they hand over?
- ConductThe account-takeover risk behind the new circular is the one 26EC35 addressed from the login end: phishing-resistant authentication and device binding, with large internet brokers expected to implement immediately and everyone else on a clock that runs to 8 July 2027. A stolen session is what makes an unauthorised eDDA setup possible in the first place.
- Type 1Exchange Participants: the licence holders insurance scheme for the 2026/2027 scheme year was set out in 26EC18, with Marsh reappointed as broker and administrator. The scheme documents come from Marsh separately — check yours rather than assuming the cover rolled over unchanged.
Borrowed comfort: the expert nobody assessed
No disciplinary outcome to report this week, so a supervisory finding from the Record that says the same thing as the One Thing in a different accent. On 30 January 2026 the SFC issued Circular 26EC4 on sponsor work. Amid a surge in listing applications, the SFC and the Stock Exchange had observed the quality of draft listing documents declining, and among the causes named: over-reliance on experts and third parties — legal advisers, accountants, valuers — to perform specific tasks without adequate assessment of their competency and resources, alongside Principals with no real capacity to supervise their transaction teams.
The teeth were unusually specific. The SFC said it generally regards any sponsor that has designated any Principal to simultaneously supervise or participate in six or more active listing engagements as lacking adequate or appropriate resources, absent very exceptional circumstances with valid justifications. The SFC and the Exchange had already issued a joint letter to 13 sponsors in December 2025; those firms and the ones with strained Principals were told to expect on-site thematic inspections. Where warranted, the SFC said it will restrict a sponsor’s business scope and the number of active listing engagements an individual may supervise or participate in, by imposing licence conditions — and in serious cases of misconduct, investigate or take disciplinary action against the sponsor, its Principals and the management accountable for the failures.
You may never do sponsor work. The control that would have caught it still applies: somebody, by name, has to have assessed whether the third party you are leaning on is actually competent to carry the weight you have put on them, and whether the person nominally supervising has the hours to do it. Substitute “the payer bank’s authentication process” for “the valuer” and you have this week’s circular. Delegating the work is allowed. Delegating the responsibility is not, and the SFC keeps saying so in whichever corner of the rulebook it happens to be standing.
One email to operations, one read of a bank indemnity. That is the whole of this week if you move on it now. See you next Monday.
Get next Monday’s briefing in your inbox.
Five minutes, every Monday, 7:30am HKT. Free, unsubscribe anytime.

