Section 279: an officer’s duty to support SFO compliance
Section 279 of Hong Kong’s Securities and Futures Ordinance requires every officer of a corporation to take all reasonable steps to ensure that the corporation complies with the Ordinance and its applicable rules.
More key points
- It is a personal compliance duty tied to the officer’s role and conduct; it does not mean every officer guarantees that no breach can ever occur.
On this page11 sections
- Who is an officer?
- What “all reasonable steps” means
- The duty is personal, but context matters
- Practical governance examples
- Translate the duty into supervision
- Respond when a warning appears
- Delegation and reliance
- How to analyze an exam fact pattern
- Evidence of reasonable oversight
- A practical oversight cycle
- Exam takeaway
Section 279 is a governance duty: it connects an officer’s own conduct to the corporation’s compliance with the Securities and Futures Ordinance. The statutory wording focuses on taking all reasonable steps. The exam distinction is between an active duty to support compliance and an absolute guarantee that the corporation will never breach a rule.
Who is an officer?
The SFO definition includes a director, manager, secretary, or other similar officer of the corporation. The person’s actual role and the statutory definition matter; a job title alone does not settle every question. A licensed corporation’s managers and responsible officers also have separate regulatory responsibilities under the licensing and conduct framework.
What “all reasonable steps” means
The provision expects an officer to act with reasonable diligence in the circumstances. Relevant steps may include understanding the business and its legal obligations, ensuring suitable controls and supervision exist, asking for reliable compliance reporting, responding to warning signs, and following up on identified breaches. What is reasonable depends on the officer’s responsibilities, authority, knowledge, and the risks involved.
The duty is personal, but context matters
An officer cannot treat compliance as someone else’s concern merely because a compliance department exists. At the same time, the section is not strict liability for every corporate breach: it asks whether the officer took all reasonable steps. A paper policy is not enough if management ignores exceptions, disables controls, or fails to address known problems.
Practical governance examples
- Ensure responsibilities for regulated activity are clear and appropriately staffed.
- Review exception reports and ask follow-up questions about unresolved issues.
- Escalate material control weaknesses and confirm corrective action is completed.
- Maintain records of decisions, training, supervision, and remediation.
- Reassess controls after business, technology, or regulatory changes.
Translate the duty into supervision
Reasonable steps are practical actions connected to the risks the corporation actually faces. An officer responsible for a business line should understand its regulated activities, confirm that responsibilities and approval limits are clear, and receive information capable of revealing non-compliance. The duty is not met merely by receiving a polished quarterly dashboard if that dashboard excludes unresolved breaches, complaints or control failures. A director with less day-to-day responsibility may rely more on delegated expertise, but should still respond when reporting raises a concern.
Respond when a warning appears
A warning changes what a reasonable response requires. If an officer learns that client orders were handled outside approved controls, sensible steps may include preserving records, stopping the affected process where appropriate, notifying compliance or senior management, assessing client impact, and tracking remediation. A vague instruction to “look into it” is weaker than assigning an owner, deadline and escalation route. Whether a specific action is reasonable depends on authority, urgency and available facts; the statutory question is about conduct, not hindsight alone.
Delegation and reliance
Compliance staff, auditors and business managers can perform specialist tasks, and an officer need not personally recalculate every trade or inspect every file. Reliance is stronger when the person is competent, the information is complete, the reporting line is independent enough for the purpose, and exceptions are followed through. Reliance becomes unsafe when the officer knows the report is incomplete, repeatedly sees the same issue, or has reason to doubt the control. Delegating a task allocates work; it does not automatically transfer the officer’s statutory responsibility.
How to analyze an exam fact pattern
Identify whether the person is an officer within the SFO definition, what compliance obligation the corporation faced, and what practical authority the officer had. Then compare the steps taken with the warning signals and the risk. A quiet period with tested controls may support periodic oversight; a known unresolved client-asset shortfall calls for prompt escalation and close follow-up. Avoid both extremes: the section is not automatic liability for every corporate breach, and it is not satisfied by a written policy that management ignores.
Evidence of reasonable oversight
Good governance records can show what information reached the officer, what questions were asked, what decisions were made and whether corrective action was verified. Useful evidence may include board or committee minutes, risk reports, breach logs, remediation records, training and delegated-authority documents. These records do not create a safe harbour by themselves: a detailed minute cannot cure an unreasonable decision. Their value is that they make the process and follow-through visible.
A practical oversight cycle
An officer can turn the reasonable-steps standard into a repeatable cycle: map the regulated activities and key rules; assign accountable owners; receive risk-based reporting; challenge exceptions; direct remediation; and verify closure. The cycle should adapt when products, staff, systems or regulation change. For example, a new order-routing system may require testing of access, supervision and record retention before launch. A later incident should feed back into the control design. This is not a statutory checklist that guarantees compliance, but it helps show active governance rather than passive reliance on policy documents.
Exam takeaway
Section 279 places a reasonable-steps obligation on every officer. It is not satisfied by delegating compliance and ignoring it, and it does not turn an officer into an insurer against all corporate misconduct. Focus on reasonable supervision, active response, and the officer’s actual role.
Common questions
Does section 279 make every officer automatically liable for a corporate breach?
No. It requires reasonable steps to secure compliance. The officer’s conduct, responsibilities, and response to risks are relevant.
Can an officer delegate compliance tasks?
Tasks can be assigned, but the statutory duty is not erased by delegation. Officers should maintain appropriate oversight and respond to problems.
Does section 279 apply only to licensed corporations?
The text applies to every officer of a corporation in relation to the corporation’s compliance with the SFO and its rules; other rules may also apply to licensed firms.
Does an officer have to prevent every breach?
No. Section 279 requires all reasonable steps to secure compliance; it is not a guarantee that no breach will occur.
Is a compliance officer’s report enough by itself?
Not necessarily. The officer should consider whether the reporting is suitable, follow up on material exceptions and respond to warning signs.
What should an officer do after discovering a control failure?
Take proportionate steps to contain risk, escalate through the proper channels, assess impact and verify remediation, consistent with the officer’s authority and applicable duties.