Sitonce
Country: US
Show exams for United States Hong Kong
Sign in
Practice and exam technique

HKSI Paper 1 practice questions: Topic 6, operations and controls

Compiled by the Sitonce editorial team from the HKSI and SFC sources listed belowUpdated 8 min readFacts verified 5 September 2026
The short answer

Topic 6 covers internal controls, anti-money laundering, privacy and electronic trading, and we estimate about 10 of 60 questions. Its distractors reward candidates who can tell a preventive control from a detective one, and a risk rating from a prohibition.

Topic 6 is the operational topic, and it is the one that most resembles a job. Who checks whom. What you do when something looks wrong. What you are allowed to keep, and for how long. Candidates who have worked in a regulated firm find this topic easy. Candidates who have not tend to answer it with common sense, which is right about half the time.

What Topic 6 covers

Syllabus title
Business operations and practices
Second-level headings
6
Our estimate of questions
About 10 of 60
Main sources
Internal Control Guidelines, the anti-money laundering regime, the Personal Data (Privacy) Ordinance, the electronic trading requirements
Dominant distractor patterns
Partial compliance, risk direction reversed, waiver treated as effective
Difficulty
Moderate. Heavily scenario-led.

That question estimate is ours, scaled from the topic's six second-level syllabus headings. HKSI publishes no per-topic counts.

Six practice questions

Question 1 - internal controls

At a small licensed corporation, one settlements officer enters trades into the system, instructs the payment, and performs the daily reconciliation. Which control is missing?

  1. Segregation of duties
  2. An annual compliance training programme
  3. An external audit of the annual accounts
  4. A confidential whistleblowing channel
Answer: A. Segregation of duties separates execution from settlement, reconciliation and recording, so that no one person controls a transaction end to end. It is the control most often identified in enforcement action over unauthorised trading and misappropriation. Option B supports controls but does not create one, and a trained person acting alone still has full control of the transaction. Option C is detective and periodic rather than preventive and continuous, which is the distinction the question is testing. Option D surfaces problems after the fact and depends on somebody noticing.
Question 2 - privacy

A licensed corporation proposes to retain copies of client identity documents indefinitely, on the basis that storage is cheap and the documents might one day be useful. Which data protection principle does that engage most directly?

  1. DPP1, collection
  2. DPP2, accuracy and retention
  3. DPP4, security
  4. DPP6, access and correction
Answer: B. DPP2 covers both accuracy and retention, and personal data must not be kept longer than is necessary for the purpose for which it is used. Option A governs how and why data is collected, which is not the issue here since collection was legitimate. Option C is about protecting data against unauthorised access or loss, a different obligation the firm may well be meeting. Option D is the data subject's right of access and correction. Note the tension worth knowing: data retained to satisfy a legal record-keeping obligation is being retained for a purpose.
Question 3 - customer due diligence

A new corporate customer of a licensed corporation is owned through several layers of holding companies in different jurisdictions. What does the anti-money laundering regime require?

  1. Verifying the identity of the authorised signatories on the account is sufficient
  2. Identifying the beneficial owners and taking reasonable measures to verify their identity, on a risk-based approach
  3. Obtaining the certificate of incorporation of the immediate parent and no more
  4. No customer due diligence is required because the customer is a corporation rather than an individual
Answer: B. Customer due diligence requires the firm to look through the structure to the beneficial owners and take reasonable measures to verify who they are, with the depth of those measures driven by risk. Option A is partial compliance: identifying signatories is a real and necessary step that stops short of the beneficial ownership requirement. Option C stops at the first layer, which is precisely what a layered structure is designed to exploit. Option D denies the duty and gets the direction of risk backwards, since opaque corporate structures raise risk rather than remove it.
Question 4 - tipping off

Which of the following describes the offence of tipping off?

  1. Failing to make a report where a suspicion of money laundering arises
  2. Disclosing to the customer, or to anyone else, something likely to prejudice an investigation
  3. Making a report of suspicion that later turns out to be unfounded
  4. Accepting a cash deposit above a prescribed amount without additional approval
Answer: B. Tipping off is the disclosure of information likely to prejudice an investigation, and it applies to disclosure to the customer or to any other person. Option A is a separate offence and the two are routinely confused, which is why they sit together as options here. Option C describes something that attracts statutory protection rather than liability, since a report made in good faith is protected. Option D invents a cash threshold rule, and it is attractive because thresholds feel like the kind of thing anti-money laundering rules contain.
Question 5 - electronic trading

A licensed corporation offers selected clients direct market access, so that client orders reach the Exchange through the firm's system without manual handling. What is expected of the firm?

  1. Effective controls over what clients can send, including pre-trade risk limits and the ability to intervene in client order flow
  2. A written waiver from each client accepting responsibility for all orders sent
  3. Approval of each order by the Exchange before it is accepted
  4. No particular controls, because the client rather than the firm enters the orders
Answer: A. The firm is the participant and remains responsible for the orders that pass through its system, so it must control what clients can send and be able to intervene. Option B is the waiver-treated-as-effective pattern: a regulatory obligation cannot be contracted away to a client, however willing the client is. Option C misunderstands the market: the Exchange matches orders, it does not pre-approve them. Option D pushes responsibility to the client, which is the whole error that direct market access requirements exist to correct.
Question 6 - outsourcing

A licensed corporation outsources part of its back-office processing to a third-party service provider under a detailed contract that makes the provider liable for errors. What is the regulatory position?

  1. Responsibility for the outsourced function transfers to the provider under the contract
  2. The firm remains responsible for the outsourced function and must exercise appropriate oversight of the provider
  3. The SFC must approve any outsourcing arrangement before it takes effect
  4. Outsourcing of back-office functions by a licensed corporation is not permitted
Answer: B. Outsourcing moves the work, not the obligation. The firm remains answerable for the function and must have due diligence, oversight and contingency arrangements around the provider. Option A treats a private contract as effective against a regulator, which it is not. Option C invents a consent requirement, and inventing a plausible approval step is a standard distractor design. Option D over-corrects, turning a management obligation into a prohibition, and would be obviously unworkable in practice.

What the wrong options were testing

PatternWhere it appearedThe defence
Detective control offered for a preventive oneQuestion 1Ask whether the control stops the problem or finds it afterwards
Wrong principle pickedQuestion 2Learn the data protection principles by their one-line job, not their number
Partial complianceQuestion 3A necessary step is not automatically a sufficient one
Neighbouring offenceQuestion 4Tipping off and failure to report are separate. Know both
Waiver treated as effectiveQuestions 5 and 6Nothing a client signs discharges a regulatory duty
Invented approval stepQuestion 6Ask who the approval would protect. If the answer is nobody, it is invented
Over-correctionQuestion 6Regulation usually manages an activity rather than banning it

How to revise Topic 6

Three lists, and they are short.

  1. The data protection principles, one line each. Six lines. Most privacy questions on this paper are answered by knowing which principle owns which job.
  2. The anti-money laundering sequence: identify and verify the customer, identify beneficial owners, understand the purpose of the relationship, apply ongoing monitoring, escalate suspicion internally, and say nothing to the customer. Learn it as a sequence, because the questions are almost always "what happens next".
  3. The control vocabulary: preventive against detective, and first line against second line. A surprising number of Topic 6 distractors are controls that exist and do a different job.

Then practice the risk-direction reflex. Higher risk means more diligence, not refusal. Lower risk means simplified measures, not none. Candidates who get that backwards lose several marks across the topic, and it is one idea.

The two duties that pull against each other

You must report a suspicion internally, and you must not say anything to the customer that could prejudice an investigation. Questions are frequently built on the tension between them, and the resolution is always the same: report up, stay silent sideways.

The opinion: this is the topic where practical experience helps most and reading helps least. If you have never worked in a regulated firm, do the questions before you do the reading. The scenarios will teach you what the guidelines are actually about far faster than the guidelines will.

The concession: parts of this topic move quickly. Anti-money laundering guidance is revised regularly and electronic trading expectations have evolved as the market has. Anything you learn here should be checked against the current SFC material before you rely on it professionally, and that includes what you read from us.

Common questions

How many Paper 1 questions cover anti-money laundering?

HKSI does not publish a breakdown. Anti-money laundering sits inside the operations topic, which our estimate puts at around six questions of 60, and it typically carries the largest share of them because the material lends itself to situational questions.

What is tipping off?

Disclosing to a customer, or to anyone else, something likely to prejudice an investigation into money laundering or related conduct. It is separate from the offence of failing to report a suspicion, and the two are frequently offered as alternative options in the same question.

What should staff do when they suspect money laundering?

Report internally to the firm's money laundering reporting officer, who considers whether to make a disclosure to the authorities, and say nothing to the customer. The reporting duty arises when the suspicion is formed rather than when a pattern is confirmed.

Does outsourcing transfer regulatory responsibility to the service provider?

No. A licensed corporation remains responsible for outsourced functions and must carry out due diligence on the provider, maintain oversight, and have contingency arrangements. A contract making the provider liable for errors is a commercial matter and does not affect the firm's regulatory position.

Which data protection principle covers how long data may be kept?

DPP2, which covers accuracy and retention. Personal data must be accurate and must not be kept longer than is necessary for the purpose. Data retained to satisfy a legal record-keeping obligation is being kept for a purpose, which resolves the apparent conflict with the record-keeping rules.