Sitonce
Country: US
Show exams for United States Hong Kong
Sign in

SFC Internal Controls: Staff Training and Practical Competence

Updated 5 min read
Key takeaway

The SFC Management, Supervision and Internal Control Guidelines expect a firm’s training programme to provide reasonable assurance that staff possess or acquire appropriate practical experience through structured and on-the-job training.

More key points
  • Training should fit the firm’s policies and procedures and applicable legal and regulatory requirements.
On this page17 sections
  1. The programme should build practical capability
  2. Training must match the firm's rules and obligations
  3. Management remains responsible for the control environment
  4. A practical training cycle
  5. Exam distinctions
  6. Training must fit the role
  7. Induction before access
  8. Ongoing training after rules change
  9. On-the-job learning and supervision
  10. Assess effectiveness
  11. Management accountability
  12. Example: updated phishing controls
  13. Exam application
  14. Proportionate training by firm size
  15. Training after an incident
  16. Keep evidence that training changed conduct
  17. Key takeaway

A compliance manual does not control a business if staff do not know how to apply it. The SFC Internal Control Guidelines connect staff capability with structured learning, practical experience, and training tied to the firm’s procedures.

The programme should build practical capability

The Guidelines describe a training programme that provides reasonable assurance staff possess or acquire appropriate and practical experience. It can include structured courses and on-the-job training. The relevant goal is not simply attendance or a completion certificate; staff need capability consistent with the work they perform.

Training must match the firm's rules and obligations

Training should be consistent with the firm’s policies, procedures, and legal and regulatory requirements. A person handling client assets, reviewing transactions, advising clients, or performing compliance monitoring needs instruction suited to those responsibilities. A generic induction alone may not address product-specific, operational, or regulatory risks.

Management remains responsible for the control environment

Training is one part of internal control. It does not transfer management’s responsibility for effective supervision, clear reporting lines, competent staffing, and monitoring. Firms should identify who needs training, what must be learned, how competence will be assessed, and when refreshers are needed after a material change.

A practical training cycle

  1. Map each role to the firm's policies, procedures, and regulatory duties.
  2. Provide structured instruction before staff perform controlled tasks.
  3. Use supervised on-the-job practice to build practical experience.
  4. Check understanding and ability to perform the work safely and accurately.
  5. Refresh training when responsibilities, products, procedures, or regulations change.
  6. Keep records that show who completed training and what the training covered.

Exam distinctions

  • Training should include practical experience, not only classroom teaching.
  • On-the-job learning should be consistent with firm procedures and legal duties.
  • Competency needs depend on assigned work and risk exposure.
  • Training does not replace supervision, segregation of duties, or review controls.

Training must fit the role

The Internal Control Guidelines expect training to provide reasonable assurance that staff possess or acquire appropriate practical experience through structured courses and on-the-job learning. A firm should map training to a person’s actual duties, authority and risks. A sales employee, trader, operations reviewer and manager have different needs; one generic annual presentation cannot demonstrate competence for every role.

Induction before access

Before a new employee handles client information or transactions, cover applicable conduct rules, client confidentiality, conflicts, escalation paths, system permissions, recordkeeping and the firm’s procedures. Role-specific examples help staff recognize issues in context. Access should be granted only after required training and approval, with restrictions maintained until the person is ready to perform the function.

Ongoing training after rules change

Regulatory requirements, products, systems and fraud patterns evolve. Compliance should identify changes that require targeted updates and deliver them before or alongside implementation. Keep versioned materials and attendance or completion evidence. A firm should also test understanding where a misunderstanding could cause client harm, rather than treating a click-through completion as proof of competence.

On-the-job learning and supervision

Practical experience can be gained through shadowing, supervised case work, review of sample files and progressively delegated authority. Supervisors should observe performance, give feedback and document sign-off. Training cannot replace supervision: a trained employee may still make errors, and a supervisor must monitor relevant work. Higher-risk responsibilities may require more frequent review or dual control.

Assess effectiveness

Use scenario questions, file reviews, error trends, complaint data, surveillance alerts and observed behavior to test whether training changed practice. If staff repeatedly miss the same issue, revise procedures and coaching rather than repeat the same slide deck. A training record should show the material, audience, date, assessment and follow-up for employees who did not demonstrate understanding.

Management accountability

Senior management remains responsible for establishing an effective control environment and ensuring staff are trained. A compliance team may design or deliver modules, but business managers must support staff time, explain expectations and address weak performance. If a breach reveals that employees did not understand a critical control, assess training, supervision and procedure design together.

Example: updated phishing controls

If the firm changes its client messaging policy to prohibit embedded transaction links, staff should know the approved communication channels, how to respond when a client reports a fake message, and which incident triggers escalation. A short practical exercise can test whether employees direct clients to the official app without sending another risky hyperlink. Training should match the control change, not just repeat general cyber advice.

Exam application

Explain that training is risk-based, role-specific and ongoing; it should combine structured learning with practical experience and supervision. Management owns adequacy even when delivery is delegated. Evidence of attendance is useful, but effectiveness depends on whether employees can apply current procedures in real cases.

Proportionate training by firm size

The SFC guidance is principles-based and recognizes that firms differ in size, business and complexity. A small firm may use a simpler programme, but must still provide practical, current instruction suited to its risks. A large firm may need role curricula, learning records, assessments and targeted sessions by business line. “Proportionate” means fit for purpose, not no training.

Training after an incident

When a complaint, near miss or surveillance alert reveals a knowledge gap, decide whether targeted retraining is needed and test the corrective change. Use anonymized case studies where appropriate, explain the correct escalation and review subsequent work for improvement. Training complements a system fix; it cannot compensate for a confusing procedure or inadequate staffing.

Keep evidence that training changed conduct

Training records should show course content, audience, assessment and remedial follow-up, but managers should also review whether employees apply the rule in live work. A low quiz score, repeat complaint or recurring exception should trigger more than a recorded attendance entry. The objective is reasonable practical competence, not completion statistics.

Keep this evidence available for supervisory review.

Key takeaway

The SFC Guidelines expect structured and on-the-job training that develops practical competence in line with the firm’s policies and regulatory obligations.

Common questions

Does the SFC guidance describe only formal classroom training?

No. It refers to structured courses and on-the-job training to build appropriate practical experience.

Does training eliminate the need for supervision?

No. Training is one element of internal control and does not replace management responsibility or ongoing supervision.