HKSI Paper 1 practice questions: Topic 6, operations and controls
Topic 6 covers internal controls, anti-money laundering, privacy and electronic trading, and we estimate about 10 of 60 questions. Its distractors reward candidates who can tell a preventive control from a detective one, and a risk rating from a prohibition.
Topic 6 is the operational topic, and it is the one that most resembles a job. Who checks whom. What you do when something looks wrong. What you are allowed to keep, and for how long. Candidates who have worked in a regulated firm find this topic easy. Candidates who have not tend to answer it with common sense, which is right about half the time.
What Topic 6 covers
- Syllabus title
- Business operations and practices
- Second-level headings
- 6
- Our estimate of questions
- About 10 of 60
- Main sources
- Internal Control Guidelines, the anti-money laundering regime, the Personal Data (Privacy) Ordinance, the electronic trading requirements
- Dominant distractor patterns
- Partial compliance, risk direction reversed, waiver treated as effective
- Difficulty
- Moderate. Heavily scenario-led.
That question estimate is ours, scaled from the topic's six second-level syllabus headings. HKSI publishes no per-topic counts.
Six practice questions
At a small licensed corporation, one settlements officer enters trades into the system, instructs the payment, and performs the daily reconciliation. Which control is missing?
- Segregation of duties
- An annual compliance training programme
- An external audit of the annual accounts
- A confidential whistleblowing channel
A licensed corporation proposes to retain copies of client identity documents indefinitely, on the basis that storage is cheap and the documents might one day be useful. Which data protection principle does that engage most directly?
- DPP1, collection
- DPP2, accuracy and retention
- DPP4, security
- DPP6, access and correction
A new corporate customer of a licensed corporation is owned through several layers of holding companies in different jurisdictions. What does the anti-money laundering regime require?
- Verifying the identity of the authorised signatories on the account is sufficient
- Identifying the beneficial owners and taking reasonable measures to verify their identity, on a risk-based approach
- Obtaining the certificate of incorporation of the immediate parent and no more
- No customer due diligence is required because the customer is a corporation rather than an individual
Which of the following describes the offence of tipping off?
- Failing to make a report where a suspicion of money laundering arises
- Disclosing to the customer, or to anyone else, something likely to prejudice an investigation
- Making a report of suspicion that later turns out to be unfounded
- Accepting a cash deposit above a prescribed amount without additional approval
A licensed corporation offers selected clients direct market access, so that client orders reach the Exchange through the firm's system without manual handling. What is expected of the firm?
- Effective controls over what clients can send, including pre-trade risk limits and the ability to intervene in client order flow
- A written waiver from each client accepting responsibility for all orders sent
- Approval of each order by the Exchange before it is accepted
- No particular controls, because the client rather than the firm enters the orders
A licensed corporation outsources part of its back-office processing to a third-party service provider under a detailed contract that makes the provider liable for errors. What is the regulatory position?
- Responsibility for the outsourced function transfers to the provider under the contract
- The firm remains responsible for the outsourced function and must exercise appropriate oversight of the provider
- The SFC must approve any outsourcing arrangement before it takes effect
- Outsourcing of back-office functions by a licensed corporation is not permitted
What the wrong options were testing
| Pattern | Where it appeared | The defence |
|---|---|---|
| Detective control offered for a preventive one | Question 1 | Ask whether the control stops the problem or finds it afterwards |
| Wrong principle picked | Question 2 | Learn the data protection principles by their one-line job, not their number |
| Partial compliance | Question 3 | A necessary step is not automatically a sufficient one |
| Neighbouring offence | Question 4 | Tipping off and failure to report are separate. Know both |
| Waiver treated as effective | Questions 5 and 6 | Nothing a client signs discharges a regulatory duty |
| Invented approval step | Question 6 | Ask who the approval would protect. If the answer is nobody, it is invented |
| Over-correction | Question 6 | Regulation usually manages an activity rather than banning it |
How to revise Topic 6
Three lists, and they are short.
- The data protection principles, one line each. Six lines. Most privacy questions on this paper are answered by knowing which principle owns which job.
- The anti-money laundering sequence: identify and verify the customer, identify beneficial owners, understand the purpose of the relationship, apply ongoing monitoring, escalate suspicion internally, and say nothing to the customer. Learn it as a sequence, because the questions are almost always "what happens next".
- The control vocabulary: preventive against detective, and first line against second line. A surprising number of Topic 6 distractors are controls that exist and do a different job.
Then practice the risk-direction reflex. Higher risk means more diligence, not refusal. Lower risk means simplified measures, not none. Candidates who get that backwards lose several marks across the topic, and it is one idea.
You must report a suspicion internally, and you must not say anything to the customer that could prejudice an investigation. Questions are frequently built on the tension between them, and the resolution is always the same: report up, stay silent sideways.
The opinion: this is the topic where practical experience helps most and reading helps least. If you have never worked in a regulated firm, do the questions before you do the reading. The scenarios will teach you what the guidelines are actually about far faster than the guidelines will.
The concession: parts of this topic move quickly. Anti-money laundering guidance is revised regularly and electronic trading expectations have evolved as the market has. Anything you learn here should be checked against the current SFC material before you rely on it professionally, and that includes what you read from us.
Common questions
How many Paper 1 questions cover anti-money laundering?
HKSI does not publish a breakdown. Anti-money laundering sits inside the operations topic, which our estimate puts at around six questions of 60, and it typically carries the largest share of them because the material lends itself to situational questions.
What is tipping off?
Disclosing to a customer, or to anyone else, something likely to prejudice an investigation into money laundering or related conduct. It is separate from the offence of failing to report a suspicion, and the two are frequently offered as alternative options in the same question.
What should staff do when they suspect money laundering?
Report internally to the firm's money laundering reporting officer, who considers whether to make a disclosure to the authorities, and say nothing to the customer. The reporting duty arises when the suspicion is formed rather than when a pattern is confirmed.
Does outsourcing transfer regulatory responsibility to the service provider?
No. A licensed corporation remains responsible for outsourced functions and must carry out due diligence on the provider, maintain oversight, and have contingency arrangements. A contract making the provider liable for errors is a commercial matter and does not affect the firm's regulatory position.
Which data protection principle covers how long data may be kept?
DPP2, which covers accuracy and retention. Personal data must be accurate and must not be kept longer than is necessary for the purpose. Data retained to satisfy a legal record-keeping obligation is being kept for a purpose, which resolves the apparent conflict with the record-keeping rules.