Sitonce
Country: US
Show exams for United States Hong Kong
Sign in
The syllabus, topic by topic

Topic 6 of HKSI Paper 1: business operations and practices

Compiled by the Sitonce editorial team from the HKSI and SFC sources listed belowUpdated 6 min readFacts verified 5 September 2026
The short answer

Topic 6 covers how a licensed firm must be run: the Management, Supervision and Internal Control Guidelines, anti-money laundering, electronic trading and alternative liquidity pools, and the Personal Data (Privacy) Ordinance. Six syllabus headings, about 10 of 60 questions on our estimated blueprint, and almost all of it list-shaped.

Syllabus topic
6 of 9 - Business operations and practices
Second-level headings
6
Estimated questions
About 10 of 60 (our estimate, not published)
Main sources
SFC Internal Control Guidelines, anti-money laundering legislation, the Personal Data (Privacy) Ordinance
Character
Operational and list-based rather than conceptual

Here is my one strong opinion about Paper 1. Topic 6 is where candidates lose marks they did not need to lose. Not because it is hard, but because it looks like admin, gets left to the last weekend, and is then revised at the speed of skimming. The material is almost entirely memorisable lists with clean boundaries, which is the easiest kind of question to answer and the easiest kind to get wrong when you half-know it.

Six headings. Two of them carry most of the weight.

What does Topic 6 cover?

Syllabus headingWhat it asks of you
Management, Supervision and Internal Control GuidelinesThe eight control areas, and who is responsible for them
Anti-money laundering and counter-terrorist financingCustomer due diligence, the risk-based approach, suspicious transaction reporting, tipping off
Electronic trading and alternative liquidity poolsResponsibility for systems, direct market access controls, dark pool disclosure
Personal Data (Privacy) OrdinanceThe six data protection principles, and direct marketing consent
Compliance and governanceThe compliance function, its independence, and reporting lines
Other operational mattersBusiness continuity, outsourcing, staff dealing and record retention
About the question count

HKSI does not publish a per-topic split. Our figure is a judgement about where the emphasis falls, and it is the split our own question bank is built to. It is a study-time guide, not a fact about the paper.

Who is responsible when controls fail?

Senior management. That is the organising idea of the whole topic, and it comes straight from the Code of Conduct principle placing primary responsibility for standards and procedures at the top of the firm. Controls can be delegated. Responsibility cannot.

The Management, Supervision and Internal Control Guidelines then set out what a sound control environment looks like: management and supervision, segregation of duties, personnel and training, information management, compliance, audit, operational controls, and risk management. Segregation of duties is the most examined of the eight. The person who executes a trade should not also be the person who settles it, reconciles it and records it, because that combination is how a single employee hides a loss for two years. Our internal control guidelines explainer walks through all eight.

How much anti-money laundering do you need?

More than most people revise. The regime imposes statutory customer due diligence and record-keeping duties on financial institutions, and licensed corporations are inside it. The approach is risk-based: assess the risk presented by the customer, the product, the delivery channel and the jurisdiction, then calibrate the diligence to that assessment. Simplified where the risk is demonstrably low. Enhanced where it is high.

Then the reporting duty, which is the part questions love. A person who knows or suspects that property represents the proceeds of an indictable offence, or is terrorist property, must report to the Joint Financial Intelligence Unit. Suspicion is enough. Proof is not required, and waiting for proof is itself a breach. At the same time, telling the customer anything likely to prejudice an investigation is the separate criminal offence of tipping off. Report, and say nothing. The full detail is in our anti-money laundering guide.

Data privacy: the six principles

The Personal Data (Privacy) Ordinance runs on six data protection principles covering collection, accuracy and retention, use, security, openness, and access and correction. They are short. They are numbered. They are the single most predictable thing in Topic 6, and a candidate who can recite all six in order has bought themselves an easy mark. The one that bites in a securities firm is the use principle: data collected to open an account cannot be repurposed for direct marketing without consent.

Electronic trading, in one paragraph

A firm using or providing an electronic trading system stays fully responsible for the orders that leave it. Outsourcing the technology does not outsource the obligation. The system must be adequately tested, sufficient in capacity, reliable, secure and backed by contingency arrangements. Where clients get direct market access, the firm needs pre-trade controls over what those clients can send and the ability to intervene. Alternative liquidity pools bring extra duties: tell clients their orders may be routed there, maintain a user register, and restrict who may participate.

A worked question

Topic 6 example

A dealer notices that a client's transactions have no apparent economic purpose and suspects the funds are criminal proceeds. The client asks why settlement is being delayed. What must the firm do?

  1. Report to the Joint Financial Intelligence Unit and explain the report to the client
  2. Report to the Joint Financial Intelligence Unit and not disclose the report to the client
  3. Gather proof of the underlying offence before reporting anything
  4. Report to the SFC, which will decide whether a disclosure is required
Answer: B. The duty is triggered by knowledge or suspicion, so waiting for proof is a breach in itself. Disclosing anything likely to prejudice an investigation is tipping off, a separate criminal offence. The report goes to the Joint Financial Intelligence Unit, not to the SFC.

How to revise Topic 6 without wasting a week

  1. Write out the six data protection principles from memory. Repeat until you can do it in under a minute.
  2. Learn the customer due diligence steps as a sequence, then learn the one rule about timing: due diligence comes before the relationship starts.
  3. Fix the report-and-do-not-tell pairing so firmly that a stem cannot shake it.
  4. Skim the eight internal control areas and memorise segregation of duties properly.
  5. Read the electronic trading material once and move on.

The concession, and it is worth saying: our estimated split may understate this topic. Anti-money laundering has grown in regulatory importance faster than the syllabus headings suggest, and if the examiners weight anything above its heading count, this is a plausible candidate. We do not know, because HKSI does not tell anyone. Sit a full mock and see what you actually get.

Common questions

What does Topic 6 of HKSI Paper 1 cover?

How a licensed firm must be run: the Management, Supervision and Internal Control Guidelines, anti-money laundering and counter-terrorist financing, electronic trading and alternative liquidity pools, the Personal Data (Privacy) Ordinance, compliance and governance, and other operational matters.

How many questions come from Topic 6?

HKSI does not publish a per-topic breakdown. Our estimate puts Topic 6 at about 10 of 60 questions, and our question bank is built to that split. That is our estimate for allocating study time, not a published figure.

Who is responsible for internal controls in a licensed corporation?

Senior management bears primary responsibility. The Code of Conduct places it there and the Internal Control Guidelines build on it. Day-to-day tasks can be delegated to a compliance function, but responsibility for the control environment cannot be delegated away.

Is Topic 6 hard?

Not conceptually. It is list-heavy and operational, which makes it easy to answer if you have memorised the lists and easy to fumble if you have only read them. Most marks lost here are lost to shallow revision rather than genuine difficulty.

Where do the six data protection principles come from?

They sit in a schedule to the Personal Data (Privacy) Ordinance and cover collection, accuracy and retention, use, security, openness, and access and correction. Every data user in Hong Kong is bound by them, including licensed corporations.