Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

Third-Party Payments in Securities Accounts: AML Controls and Red Flags

Updated 5 min read
Key takeaway

Third-party payments can obscure who owns or controls funds and may expose a securities intermediary to money laundering, fraud, and client-asset risks.

More key points
  • SFC guidance says third-party payments should be discouraged and accepted only under controlled approval and risk-based checks.
  • Firms identify the third party, understand the rationale, compare transfers with the customer profile, and escalate unresolved suspicion.
On this page12 sections
  1. Why the payer matters
  2. Discourage and control, do not normalize
  3. Identify the third party and connection
  4. Review the payment in context
  5. Incoming and outgoing transfers both matter
  6. A practical example
  7. Warning signs to recognize
  8. Keep the client experience clear
  9. Paper 1 takeaway
  10. Operational details that strengthen the control
  11. How to apply it in a real case
  12. Points to carry into practice

Third-party payments can obscure who owns or controls funds and may expose a securities intermediary to money laundering, fraud, and client-asset risks. SFC guidance says third-party payments should be discouraged and accepted only under controlled approval and risk-based checks. Firms identify the third party, understand the rationale, compare transfers with the customer profile, and escalate unresolved suspicion.

Why the payer matters

A client account is expected to reflect the client’s legitimate activity. When a different person or entity sends money, the firm needs to understand the relationship and reason. An unrelated third party may be helping with a legitimate family or corporate arrangement, but the payment can also conceal ownership, move criminal proceeds, or enable fraud. The SFC has highlighted third-party transfers as a risk area for licensed corporations and associated entities.

Discourage and control, do not normalize

SFC guidance says third-party payments should be discouraged and accepted only after approvals from designated senior staff. This is not an instruction to reject every payment from someone other than the customer. It means the firm should have a controlled exception process, risk-sensitive measures, and documented rationale. A salesperson should not promise acceptance before compliance review.

Identify the third party and connection

The firm should take reasonable steps to identify the third-party source and understand how the payer relates to the customer. Obtain relevant supporting documents, such as corporate authorization, trust documentation, family relationship evidence, or business agreements, depending on the circumstances. Verify the account or remitter details where possible. A customer’s statement alone may not be enough when the amount, route, or relationship presents higher risk.

Review the payment in context

Look at whether the payment is frequent or large, whether the customer or payer is cross-border, whether the transfer route is unusual, and whether the payment fits the customer’s known wealth and account purpose. Third-party funds may be inconsistent with the customer’s profile even when the payer’s name is familiar. Ask what legitimate activity explains the transfer and whether the evidence supports that explanation.

Incoming and outgoing transfers both matter

Risk can arise when an unrelated person pays into an account, and when a customer requests that proceeds be sent to a third party. Outgoing requests can create asset-theft and impersonation risk as well as AML risk. Confirm authority, beneficiary ownership, and reason under the firm’s payment controls. For unusual instructions, independently verify using contact information already held on file, not details included in the new instruction alone.

A practical example

A retail client sells securities and asks the broker to remit settlement proceeds to a newly named overseas company. Staff should not process the request merely because the client gave the instruction. They document the beneficiary, relationship, rationale, source of account funds, and requested route, then obtain required approval. If the information does not resolve suspicion, the MLRO considers an STR and staff avoid tipping off.

Warning signs to recognize

Potential red flags include repeated transfers between unrelated parties, funds quickly entering and leaving without a clear investment rationale, third-party cheques or deposits, unconventional payment methods, a sudden change in beneficiary, and cross-border activity inconsistent with the customer’s profile. A red flag is not proof. It is a reason to pause, gather facts, and apply the firm’s risk-based procedure.

Keep the client experience clear

Explain that the firm needs to verify the payment instruction under its controls and give a neutral description of the documents required. Do not accuse the customer or reveal a suspicious-transaction report. If the payment is rejected or delayed, tell the client what can be shared and who can answer further questions. Keep a record of the customer explanation and the firm’s decision.

Paper 1 takeaway

Third-party money must be understood, not waved through. Identify payer and beneficiary, establish rationale, apply approval and enhanced review proportionate to risk, and escalate suspicion.

Operational details that strengthen the control

Written approvals should be specific to the transaction and not operate as a blanket permission for all future payments from the same third party. Record the amount, currency, date, payer or beneficiary, account, relationship to the client, supporting evidence, approving person, and any conditions. If the payment pattern changes in size or destination, revisit the approval rather than relying on the earlier record. Reconciliation can reveal funds that arrived from an unexpected account or were sent to a name different from the instruction. Operations staff should use exception reports to identify mismatched names and repeated round-dollar or rapid in-and-out movements, then refer the facts to compliance.

How to apply it in a real case

A common operational error is to treat a third-party transfer as an ordinary client withdrawal after receiving AML approval. Before funds move, confirm the client’s valid authority, beneficiary details, account name, and any standing authority requirements. A payment request that changes the beneficiary after approval should be treated as a new instruction and independently verified. After completion, reconcile the payment to the approved amount and destination. This separation keeps the AML rationale from substituting for client-asset protection and payment authorization.

Where the source is a company within the client’s group, verify the corporate relationship and authority rather than treating common branding as proof. An intra-group label does not by itself explain the commercial purpose.

A change to beneficiary bank details should receive independent verification even if the customer has previously used third-party payments. Fraudsters often exploit routine exceptions after learning the firm’s process.

Keep payment approval separate from the person who benefits from the transfer. Independent review reduces the chance that commercial pressure overrides client-asset and AML safeguards.

Points to carry into practice

  • Check current SFC rules, guidance and firm procedures for the exact requirement.
  • Record the facts, escalate uncertainty and protect client interests.

Common questions

Are all third-party payments prohibited?

The SFC says they should be discouraged and only accepted under designated approval and appropriate controls; firm policy may be stricter.

What if the customer says the payer is a relative?

Verify the relationship and purpose as appropriate; assess the payment in context rather than relying on an unsupported label.

Are outgoing third-party payments a risk too?

Yes. They raise AML, authority, and client-asset concerns and need independent verification.

Does a red flag mean an STR must always be filed?

It triggers review. The MLRO assesses whether the statutory suspicion threshold is met.