Technology, operations and governance, handled as one system.

A licensed firm is a set of promises to a regulator, kept every day by people and software. I work on the software, the daily practice, and the documents that describe both.

The manual is fine. Year two is the problem.

The usual route to a licence works. Engage a compliance consultant, adopt their manual, appoint the responsible officers and Managers-In-Charge, buy a CRM and a document store. Most firms are built this way, and the manual is usually a good one.

The trouble starts in year two. The manual now describes a firm that no longer quite exists. The staff dealing policy names a broker the firm stopped using. The technology policy promises patch timelines nobody tracks. The annual questionnaire gets answered from memory. An inspection measures the gap between the document and the practice, and the gap only grows. Most of my time goes on closing it: systems that produce their own evidence, policies rewritten to match, and one named person accountable for both.

If you are preparing a Type 4 or Type 9 application, start with the systems the questionnaire will ask about. The manual is the easier part.

An office facade, a grid of lit windows Hong Kong from above at night A lighthouse and its causeway at dusk

Three disciplines, one operating model

  1. Technology

    Architecture, build and vendor decisions, made by someone who runs the stack inside a licensed firm. Modern tooling, AI included, with the access controls, logging and change discipline an inspection expects.

  2. Operations

    Onboarding, KYC and professional investor assessment, the CRM, hand-offs to the fund administrator, reporting. Built so the daily work leaves its own audit trail.

  3. Governance

    Technology policy, AI oversight, cybersecurity review, business continuity, the Manager-In-Charge duties and the annual questionnaire. Written to match what the firm does, since that is what gets tested.

Sustainability, as data and disclosure.

Climate and ESG obligations have moved out of the marketing deck and into the compliance file. Fund managers answer for climate risk under the Fund Manager Code of Conduct, listed companies report against ISSB-aligned HKEX rules, and a fund that calls itself ESG has to show why. The questions are operational now: where the data comes from, who signs it off, and whether the firm can show its working.

  • ESG data pipelines and scoring methods an auditor can follow.
  • Climate-risk processes and disclosures for SFC-licensed managers.
  • Reporting to HKEX and ISSB requirements, with the evidence trail attached.
  • A read of the ESG claims in fund documents against what the process can actually support.

Four formats, one order.

Usually in this order, though each stands on its own.

  1. Diagnostic

    One to two weeks

    Interviews, a look at the systems in use, and the policies read against practice. You get a short written assessment and a ranked list of what to fix first.

  2. Roadmap

    Two to four weeks

    Sequenced initiatives with owners, costs and regulatory dependencies, so the board can approve a plan and a budget in one sitting.

  3. Build and embed

    Retainer or interim leadership

    I build, or I sit alongside your team while they do. Where a firm needs the seat itself, I take it on a fractional basis: CTO or COO for a few days a month, named and accountable, with the Manager-In-Charge designation where the licence calls for one. Licensed firms and growth companies alike.

  4. Workshop

    Half or full day

    For boards and management teams that need to make one decision well: a vendor, a platform, an AI policy, licence readiness.

The rules the work answers to.

This is not a law firm or a compliance consultancy. I build the systems and the working practice that let those functions hold up under questioning, inside these frameworks.

  • SFC Code of Conduct and the Fund Manager Code of Conduct, including its climate-related risk requirements
  • Management, Supervision and Internal Control Guidelines
  • The Manager-In-Charge regime
  • SFC cybersecurity guidelines and thematic reviews
  • The Anti-Money Laundering and Counter-Terrorist Financing Ordinance and the SFC guideline
  • The Personal Data (Privacy) Ordinance
  • HKEX climate disclosure requirements and the ISSB standards behind them
  • ISO 27001 and SOC 2, as references for control design

Five kinds of client.

  • SFC-licensed boutiques of five to thirty people, and managers preparing a Type 4 or Type 9 application.
  • Trust and company service providers holding a TCSP licence, and the fiduciary businesses around them.
  • Single family offices setting up an investment function, with or without the tax concession.
  • Fintech and payments companies holding, or applying for, a stored value facility or money service operator licence.
  • Growth companies preparing for an institutional investor’s due diligence or a listing.

Start with a conversation.

Two or three sentences about the firm and the problem is enough. I read every message and reply myself. If it is a fit, the first step is a two-week diagnostic and a written assessment. If it is not, I will say so and suggest who to ask instead.

Write to Sean Connect on LinkedIn