Hong Kong has positioned itself as a leading global hub for virtual assets with a comprehensive regulatory framework that balances innovation with investor protection. The Virtual Asset Service Provider (VASP) licensing regime, introduced through amendments to the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (AMLO) and governed by the Securities and Futures Commission (SFC), establishes clear rules for operating virtual asset trading platforms (VATPs) and providing related services in Hong Kong.

This comprehensive guide explains everything you need to know about obtaining a VASP licence in Hong Kong, from the regulatory framework and dual licensing requirements to capital requirements, compliance infrastructure, and the application process. Whether you are a cryptocurrency exchange, a digital asset custodian, or a fintech firm exploring the virtual asset space, understanding Hong Kong's VASP regime is essential for lawful operation.

1. The Regulatory Framework: AMLO and SFO

Hong Kong's approach to regulating virtual assets is built on two key pieces of legislation: the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (AMLO) and the Securities and Futures Ordinance (SFO). This dual-track framework ensures that virtual asset activities are subject to both AML/CFT requirements and securities regulation where applicable.

AMLO Licensing Regime

Effective from 1 June 2023, the amended AMLO requires any person who operates a virtual asset exchange in Hong Kong, or actively markets such services to Hong Kong investors, to obtain a licence from the SFC. This applies regardless of whether the virtual assets traded constitute "securities" under the SFO. The AMLO regime covers the following activities:

  • Operating a virtual asset trading platform that facilitates buying, selling, or exchanging virtual assets
  • Providing custody services for virtual assets on behalf of clients
  • Facilitating the transfer or settlement of virtual asset transactions
  • Providing over-the-counter (OTC) trading services for virtual assets

SFO Licensing Requirements

Where virtual assets constitute "securities" or "futures contracts" under the SFO, the platform operator must also be licensed under the SFO for the relevant regulated activities. This creates a dual licensing requirement for platforms that trade both security tokens and non-security virtual assets. Platforms dealing exclusively in non-security virtual assets only need the AMLO VASP licence.

What Counts as a "Virtual Asset"?

Under AMLO, a "virtual asset" (VA) is defined as a cryptographically secured digital representation of value that is expressed as a unit of account or a store of economic value, functions as a medium of exchange, and can be transferred, stored, or traded electronically. This includes cryptocurrencies like Bitcoin and Ethereum, utility tokens, and stablecoins, but excludes digital representations of fiat currencies (CBDCs), financial assets already regulated under the SFO, and closed-loop limited-purpose items such as loyalty points or in-game tokens.

2. Who Needs a VASP Licence?

The VASP licensing requirement applies broadly to any entity that operates or plans to operate a centralised virtual asset trading platform in Hong Kong. The SFC takes a substance-over-form approach, meaning that the actual nature of your business activities determines whether licensing is required, not merely how you describe your services.

Entities That Need a VASP Licence

  • Centralised cryptocurrency exchanges operating in or from Hong Kong
  • Platforms that match buy and sell orders for virtual assets
  • Entities providing custody services as part of exchange operations
  • Firms actively marketing virtual asset trading services to Hong Kong residents
  • OTC desks that operate as exchanges by matching multiple parties

Entities That May Be Exempt

  • Decentralised exchanges (DEXs) that operate without a centralised operator — though the SFC has indicated it may address these in future guidance
  • Peer-to-peer trading platforms that do not custody client assets or match orders
  • Firms licensed under the SFO that only deal in virtual assets that are securities

3. The SFC's Approach to Virtual Asset Trading Platforms

The SFC has adopted a phased and principles-based approach to regulating VATPs. Initially, the SFC introduced an opt-in licensing framework in 2019 for platforms that traded at least one virtual asset constituting a security. From 1 June 2023, this was replaced by the mandatory AMLO licensing regime, which requires all centralised VATPs to be licensed.

Key Regulatory Principles

The SFC's regulatory approach is guided by several core principles that applicants must understand:

  • Same activity, same risks, same regulation: Virtual asset activities that pose similar risks to traditional financial activities are subject to comparable regulatory requirements
  • Investor protection first: The SFC places strong emphasis on protecting both retail and professional investors through robust custody, insurance, and disclosure requirements
  • Technology neutrality: Regulations focus on the economic substance of activities rather than the technology used to deliver them
  • Risk-based approach: Regulatory requirements are proportionate to the risks posed by the business activities

Retail vs Professional Investor Access

The SFC has adopted an evolving approach to investor access. Initially, only professional investors were permitted to trade on licensed VATPs. However, from June 2023, the SFC allowed licensed platforms to serve retail investors, subject to enhanced safeguards including:

  • Knowledge assessment: Platforms must assess whether retail investors have sufficient knowledge of virtual assets before allowing them to trade
  • Risk disclosure: Comprehensive risk disclosure statements must be provided to all retail clients
  • Exposure limits: Platforms should set reasonable exposure limits for retail investors based on their financial circumstances
  • Token admission criteria: Only virtual assets that meet the SFC's token admission criteria may be offered to retail investors, with stricter criteria for retail-accessible tokens
  • Suitability assessment: Platforms must ensure that the virtual assets and services offered are suitable for each retail client

4. Capital and Financial Requirements

The SFC imposes stringent capital requirements on VASP licensees to ensure they have adequate financial resources to operate safely and protect client assets. These requirements are significantly higher than traditional securities licensing due to the additional risks inherent in the virtual asset space.

Requirement Amount (HK$) Notes
Minimum Paid-Up Capital $5,000,000 Must be fully paid before licence approval
Minimum Liquid Capital $5,000,000 Ongoing requirement; may be higher based on risk assessment
Application Fee $29,810 Non-refundable fee payable upon application
Annual Licence Fee $14,680 Payable annually to maintain the licence
Insurance / Compensation Varies Must cover client virtual assets held in custody

Insurance and Compensation Requirements

Licensed VATPs must maintain insurance or compensation arrangements to cover potential losses of client virtual assets due to hacking, theft, or other security incidents. The SFC expects coverage to protect a substantial portion of client virtual assets held in hot storage (e.g., 50%) and cold storage (e.g., 100%). The specific terms and amounts are assessed on a case-by-case basis during the licensing process.

5. Custody and Safeguarding of Client Assets

Custody of client virtual assets is one of the most critical aspects of the VASP licensing regime. The SFC requires licensed platforms to implement robust custody arrangements to protect client assets from loss, theft, and misappropriation.

Key Custody Requirements

  • Segregation of client assets: Client virtual assets must be held in segregated wallets, separate from the platform's proprietary assets
  • Cold storage mandate: The vast majority of client virtual assets (e.g., 98%) must be stored in cold wallets that are not connected to the internet
  • Multi-signature controls: Access to client asset wallets must require multiple authorised signatories
  • Seed phrase management: Private keys and seed phrases must be securely stored with appropriate backup and disaster recovery procedures
  • Third-party custody: If using third-party custodians, the VATP must ensure the custodian meets equivalent standards and conducts ongoing due diligence
  • Regular reconciliation: Daily reconciliation of client asset balances across all wallets and accounts

6. AML/CFT Compliance for Virtual Assets

Anti-money laundering and counter-terrorist financing compliance is a cornerstone of the VASP licensing regime. Licensed VATPs must implement comprehensive AML/CFT policies and procedures that meet both AMLO requirements and FATF Recommendations, including the "travel rule" for virtual asset transfers.

Core AML/CFT Obligations

  • Customer due diligence (CDD): Full identity verification for all clients before allowing trading, with enhanced due diligence for high-risk clients
  • Transaction monitoring: Automated systems to detect and flag suspicious transactions in real-time
  • Suspicious transaction reporting (STR): Mandatory reporting to the Joint Financial Intelligence Unit (JFIU) for any transactions suspected of involving money laundering or terrorist financing
  • Travel rule compliance: When transferring virtual assets on behalf of clients, VATPs must collect and transmit originator and beneficiary information in compliance with the FATF travel rule
  • Sanctions screening: Ongoing screening of clients and transactions against relevant sanctions lists
  • Record keeping: Maintaining all CDD records and transaction data for at least 6 years

Blockchain Analytics

The SFC expects licensed VATPs to employ blockchain analytics tools to trace the source and destination of virtual asset transactions, identify potentially tainted assets, and assess the risk profiles of counterparty wallets. This technology-driven approach is essential for effective AML/CFT compliance in the virtual asset ecosystem.

7. Compliance Infrastructure Requirements

The SFC requires VASP licensees to establish a comprehensive compliance infrastructure that covers governance, risk management, technology, and operational resilience. This infrastructure must be proportionate to the scale and complexity of the platform's business activities.

Governance and Personnel

  • At least two Responsible Officers (ROs) with relevant experience in virtual assets and financial services
  • A dedicated compliance officer with expertise in AML/CFT and securities regulation
  • An information security officer responsible for cybersecurity
  • Adequate staffing levels for operations, risk management, and compliance functions

Technology and Cybersecurity

  • Robust trading system with high availability, low latency, and disaster recovery capabilities
  • Comprehensive cybersecurity framework aligned with international standards (e.g., ISO 27001)
  • Regular penetration testing and vulnerability assessments by independent third parties
  • DDoS protection, intrusion detection, and incident response plans
  • Secure API management and access controls

Risk Management

  • Market manipulation surveillance systems
  • Conflict of interest management policies
  • Liquidity risk management framework
  • Operational risk assessment and mitigation
  • Business continuity and disaster recovery plans

8. The Application Process

The VASP licence application process involves multiple stages and requires extensive documentation. The SFC conducts a thorough assessment of every applicant's fitness and properness, business plan, systems and controls, and financial resources.

Step 1: Pre-Application Preparation (2-4 Months)

  • Incorporate a Hong Kong company (if not already done)
  • Recruit qualified ROs and key personnel with virtual asset experience
  • Develop a detailed business plan covering target market, product offerings, and revenue model
  • Design and implement the trading platform with robust security features
  • Establish custody arrangements and insurance coverage
  • Develop comprehensive compliance policies (AML/CFT, KYC, token admission, custody)
  • Engage external auditors and legal counsel

Step 2: Application Submission

  • Submit the VASP licence application to the SFC
  • Provide all required supporting documentation
  • Pay the application fee
  • Submit individual applications for each RO and Licensed Representative

Step 3: SFC Assessment (6-12 Months)

  • The SFC reviews the application and conducts background checks on all key individuals
  • The SFC may conduct on-site inspections to assess the platform's operational readiness
  • External assessors may be engaged to evaluate the platform's cybersecurity and technology infrastructure
  • The SFC issues requisition letters requesting clarification or additional information
  • Multiple rounds of questions and responses are common

Step 4: Approval in Principle and Conditions

  • If satisfied, the SFC issues an Approval in Principle (AIP) with conditions
  • Conditions may include completing additional security assessments, finalising insurance, or modifying systems
  • The applicant must fulfil all AIP conditions before final licence issuance

Step 5: Final Licence Issuance

  • Upon fulfilment of all conditions, the SFC grants the VASP licence
  • The platform is listed on the SFC's public register
  • The platform may commence operations in accordance with its licence conditions

9. Comparison with Other Jurisdictions

Hong Kong's VASP licensing regime is one of the most comprehensive in Asia-Pacific. Here is how it compares with other key jurisdictions:

Aspect Hong Kong Singapore Dubai (VARA)
Regulator SFC MAS VARA
Legal Framework AMLO + SFO Payment Services Act Virtual Assets Regulatory Authority Law
Retail Access Yes (with safeguards) Restricted Yes (with safeguards)
Capital Requirement HK$5M+ S$250K base Varies by activity
Insurance Mandate Yes (hot + cold storage) Not mandatory Yes
Processing Time 6-12 months 6-12 months 3-6 months
Travel Rule Yes (FATF compliant) Yes Yes

Hong Kong's approach is notably rigorous in its custody and insurance requirements, reflecting the SFC's commitment to investor protection. While the application process may be longer than in some jurisdictions, the resulting licence carries significant credibility and opens access to one of the world's most important financial markets.

10. Timeline and Costs

The end-to-end process for obtaining a VASP licence in Hong Kong typically takes 9 to 18 months, depending on the complexity of the application and the applicant's state of readiness. Here is a breakdown of the typical timeline and associated costs:

Phase Duration Estimated Cost (HK$)
Pre-Application Preparation 2-4 months $500,000 - $2,000,000
Application Submission 2-4 weeks $29,810 (application fee)
SFC Review & Assessment 6-12 months $300,000 - $800,000 (professional fees)
External Assessments (cybersecurity, etc.) 1-2 months $200,000 - $500,000
AIP Conditions Fulfilment 1-3 months Varies

Total upfront costs, including company setup, technology infrastructure, personnel recruitment, professional fees, and capital requirements, can range from HK$10 million to HK$50 million or more, depending on the scale and complexity of the planned operations.

"Hong Kong's VASP licensing regime is rigorous but well-designed. It provides a clear pathway for legitimate virtual asset businesses to operate with regulatory certainty, while establishing robust safeguards to protect investors and maintain market integrity. For firms willing to invest in compliance, the Hong Kong VASP licence represents a premium credential in the global digital asset landscape."

Need Help with Your VASP Licence Application?

Our experienced consultants can guide you through every step of the VASP licensing process, from pre-application preparation to post-approval compliance.

Chat with Us on WhatsApp

香港已將自身定位為全球領先的虛擬資產中心,建立了一套平衡創新與投資者保障的綜合監管框架。虛擬資產服務提供者(VASP)發牌制度通過修訂《打擊洗錢及恐怖分子資金籌集條例》(AMLO)引入,由證券及期貨事務監察委員會(證監會)監管,為在香港營運虛擬資產交易平台(VATPs)及提供相關服務制定了清晰的規則。

本綜合指南將詳細解釋在香港取得VASP牌照所需了解的一切,包括監管框架和雙重發牌要求、資本要求、合規基礎設施及申請流程。無論您是加密貨幣交易所、數碼資產託管人,還是正在探索虛擬資產領域的金融科技公司,了解香港的VASP制度對於合法經營至關重要。

1. 監管框架:AMLO與SFO

香港對虛擬資產的監管建基於兩項核心立法:《打擊洗錢及恐怖分子資金籌集條例》(AMLO)和《證券及期貨條例》(SFO)。這一雙軌框架確保虛擬資產活動同時受到反洗錢/反恐融資要求和證券監管(如適用)的約束。

AMLO發牌制度

自2023年6月1日起生效的經修訂AMLO要求,任何在香港經營虛擬資產交易所或積極向香港投資者推銷此類服務的人士,均須向證監會取得牌照。無論所交易的虛擬資產是否構成SFO下的「證券」,均須遵守此規定。AMLO制度涵蓋以下活動:

  • 營運虛擬資產交易平台,方便買賣或交換虛擬資產
  • 為客戶提供虛擬資產託管服務
  • 為虛擬資產交易提供轉移或結算便利
  • 為虛擬資產提供場外交易(OTC)服務

SFO發牌要求

當虛擬資產構成SFO下的「證券」或「期貨合約」時,平台營運商亦必須根據SFO就相關受規管活動持牌。這為同時交易證券型代幣和非證券型虛擬資產的平台創造了雙重發牌要求。僅交易非證券型虛擬資產的平台只需取得AMLO VASP牌照。

何謂「虛擬資產」?

根據AMLO的定義,「虛擬資產」(VA)是指以密碼學方式保護的數碼價值表示,以記帳單位或經濟價值儲存形式表達,具有交換媒介功能,並可通過電子方式轉移、儲存或交易。這包括比特幣和以太幣等加密貨幣、功能型代幣和穩定幣,但不包括法定貨幣的數碼表示(央行數碼貨幣)、已受SFO規管的金融資產,以及忠誠度積分或遊戲代幣等封閉式有限用途項目。

2. 誰需要VASP牌照?

VASP發牌要求廣泛適用於任何在香港經營或計劃經營中心化虛擬資產交易平台的實體。證監會採取「實質重於形式」的方法,即決定是否需要持牌的是您業務活動的實際性質,而非僅僅是您對服務的描述。

需要VASP牌照的實體

  • 在香港或從香港營運的中心化加密貨幣交易所
  • 為虛擬資產撮合買賣訂單的平台
  • 作為交易所運作一部分提供託管服務的實體
  • 積極向香港居民推銷虛擬資產交易服務的公司
  • 以撮合多方方式運作的場外交易櫃台

可能獲豁免的實體

  • 在沒有中心化營運商的情況下運作的去中心化交易所(DEXs)——但證監會已表示可能在未來的指引中處理此類情況
  • 不託管客戶資產或撮合訂單的點對點交易平台
  • 僅交易構成證券的虛擬資產的SFO持牌公司

3. 證監會對虛擬資產交易平台的監管方針

證監會對VATPs採取了分階段、以原則為本的監管方式。最初,證監會於2019年推出自願參與的發牌框架,適用於至少交易一種構成證券的虛擬資產的平台。自2023年6月1日起,該框架被強制性的AMLO發牌制度所取代,要求所有中心化VATPs必須持牌。

核心監管原則

證監會的監管方式受到多項核心原則指導,申請人必須了解:

  • 相同活動、相同風險、相同監管:與傳統金融活動構成相似風險的虛擬資產活動,須受到相當的監管要求約束
  • 投資者保障優先:證監會十分重視通過穩健的託管、保險和披露要求保障散戶和專業投資者
  • 科技中立:監管聚焦於活動的經濟實質,而非用於提供服務的技術
  • 風險為本方法:監管要求與業務活動所帶來的風險成比例

散戶與專業投資者的準入

證監會在投資者準入方面採取了漸進式的方式。最初只允許專業投資者在持牌VATPs上進行交易。然而,自2023年6月起,證監會允許持牌平台為散戶投資者提供服務,但須遵守加強的保障措施,包括:

  • 知識評估:平台必須在允許散戶投資者交易前,評估其對虛擬資產是否具備足夠知識
  • 風險披露:必須向所有散戶客戶提供全面的風險披露聲明
  • 投資限額:平台應根據散戶投資者的財務狀況設定合理的投資限額
  • 代幣准入標準:只有符合證監會代幣准入標準的虛擬資產方可向散戶投資者發售,對散戶可參與的代幣有更嚴格的標準
  • 適合性評估:平台必須確保所提供的虛擬資產和服務適合每位散戶客戶

4. 資本及財務要求

證監會對VASP持牌人施加嚴格的資本要求,以確保其擁有充足的財務資源安全運營並保護客戶資產。由於虛擬資產領域固有的額外風險,這些要求明顯高於傳統證券發牌。

要求 金額(港幣) 備註
最低繳足股本 $5,000,000 須在牌照批准前全額繳付
最低速動資金 $5,000,000 持續要求;可能根據風險評估而更高
申請費 $29,810 申請時繳付的不可退還費用
年度牌照費 $14,680 每年繳付以維持牌照
保險/賠償安排 因情況而異 必須涵蓋託管中的客戶虛擬資產

保險與賠償要求

持牌VATPs必須維持保險或賠償安排,以涵蓋因黑客攻擊、盜竊或其他安全事件而造成的客戶虛擬資產潛在損失。證監會預期覆蓋範圍應保障存放於熱存儲的大部分客戶虛擬資產(如50%)和冷存儲(如100%)。具體條款和金額在發牌過程中按個案評估。

5. 客戶資產的託管與保障

客戶虛擬資產的託管是VASP發牌制度中最關鍵的環節之一。證監會要求持牌平台實施穩健的託管安排,以保護客戶資產免受損失、盜竊和挪用。

主要託管要求

  • 客戶資產分隔:客戶虛擬資產必須存放在獨立的錢包中,與平台的自有資產分開
  • 冷存儲規定:絕大部分客戶虛擬資產(如98%)必須存放在未連接互聯網的冷錢包中
  • 多重簽名控制:存取客戶資產錢包必須要求多名授權簽署人
  • 助記詞管理:私鑰和助記詞必須安全存放,並有適當的備份和災難恢復程序
  • 第三方託管:如使用第三方託管人,VATP必須確保託管人符合同等標準並持續進行盡職調查
  • 定期對帳:每日對所有錢包和帳戶中的客戶資產餘額進行對帳

6. 虛擬資產的反洗錢/反恐融資合規

反洗錢和反恐融資合規是VASP發牌制度的基石。持牌VATPs必須實施全面的反洗錢/反恐融資政策和程序,同時符合AMLO要求和FATF建議,包括虛擬資產轉移的「旅行規則」。

核心反洗錢/反恐融資義務

  • 客戶盡職調查(CDD):在允許交易前對所有客戶進行完整的身份驗證,對高風險客戶進行加強盡職調查
  • 交易監控:自動化系統實時偵測和標記可疑交易
  • 可疑交易報告(STR):對任何涉嫌洗錢或恐怖分子資金籌集的交易,必須向聯合財富情報組(JFIU)報告
  • 旅行規則合規:代客戶轉移虛擬資產時,VATPs必須按照FATF旅行規則收集和傳送匯款人和收款人資料
  • 制裁篩查:持續對照相關制裁名單篩查客戶和交易
  • 記錄保存:所有CDD記錄和交易資料至少保存6年

區塊鏈分析

證監會期望持牌VATPs採用區塊鏈分析工具,以追蹤虛擬資產交易的來源和目的地、識別可能受污染的資產,以及評估對手方錢包的風險概況。這種技術驅動的方法對於虛擬資產生態系統中有效的反洗錢/反恐融資合規至關重要。

7. 合規基礎設施要求

證監會要求VASP持牌人建立涵蓋管治、風險管理、技術和營運韌性的全面合規基礎設施。該基礎設施必須與平台業務活動的規模和複雜程度相稱。

管治和人員

  • 至少兩名具有虛擬資產和金融服務相關經驗的負責人員(ROs)
  • 一名專責的合規主任,具備反洗錢/反恐融資和證券監管專業知識
  • 一名負責網絡安全的資訊安全主任
  • 營運、風險管理和合規職能部門有足夠的人員配置

技術及網絡安全

  • 具備高可用性、低延遲和災難恢復能力的穩健交易系統
  • 符合國際標準(如ISO 27001)的全面網絡安全框架
  • 由獨立第三方定期進行滲透測試和漏洞評估
  • DDoS防護、入侵偵測和事件應對方案
  • 安全的API管理和存取控制

8. 申請流程

VASP牌照申請流程包括多個階段,需要大量文件。證監會對每位申請人的適當人選資格、業務計劃、系統和控制措施及財務資源進行全面評估。

步驟一:申請前準備(2-4個月)

  • 註冊香港公司(如尚未完成)
  • 招聘具有虛擬資產經驗的合格ROs及主要人員
  • 制定涵蓋目標市場、產品組合和收入模式的詳細業務計劃
  • 設計並實施具備穩健安全功能的交易平台
  • 建立託管安排和保險覆蓋
  • 制定全面的合規政策(反洗錢/反恐融資、KYC、代幣准入、託管)
  • 聘請外部審計師和法律顧問

步驟二:提交申請

  • 向證監會提交VASP牌照申請
  • 提供所有所需支持文件
  • 繳付申請費
  • 為每位RO和持牌代表提交個人申請

步驟三:證監會評估(6-12個月)

  • 證監會審查申請並對所有主要人員進行背景調查
  • 證監會可能進行現場檢查以評估平台的營運準備狀況
  • 可能聘請外部評估師評估平台的網絡安全和技術基礎設施
  • 證監會發出補充資料信函要求澄清或提供額外資料
  • 多輪問答往來屬常見情況

步驟四:原則上批准及條件

  • 如滿意申請,證監會發出附帶條件的原則上批准(AIP)
  • 條件可能包括完成額外的安全評估、落實保險或修改系統
  • 申請人必須在最終發牌前履行所有AIP條件

步驟五:最終發牌

  • 所有條件履行後,證監會頒發VASP牌照
  • 平台被列入證監會公眾登記冊
  • 平台可按照其牌照條件開展業務

9. 與其他司法管轄區的比較

香港的VASP發牌制度是亞太地區最全面的制度之一。以下是與其他主要司法管轄區的比較:

方面 香港 新加坡 杜拜(VARA)
監管機構 證監會 新加坡金管局 VARA
法律框架 AMLO + SFO 支付服務法 虛擬資產監管局法
散戶准入 是(附帶保障措施) 受限 是(附帶保障措施)
資本要求 港幣500萬以上 新幣25萬起 因活動而異
保險規定 是(熱存儲+冷存儲) 非強制
處理時間 6-12個月 6-12個月 3-6個月
旅行規則 是(符合FATF)

10. 時間表與成本

在香港取得VASP牌照的端到端過程通常需要9至18個月,具體取決於申請的複雜程度和申請人的準備狀態。以下是典型時間表和相關成本的細分:

階段 時長 預計成本(港幣)
申請前準備 2-4個月 $500,000 - $2,000,000
提交申請 2-4週 $29,810(申請費)
證監會審查及評估 6-12個月 $300,000 - $800,000(專業費用)
外部評估(網絡安全等) 1-2個月 $200,000 - $500,000
履行AIP條件 1-3個月 因情況而異

前期總成本,包括公司設立、技術基礎設施、人員招聘、專業費用和資本要求,根據計劃營運的規模和複雜程度,可能從港幣1,000萬至5,000萬或更多。

「香港的VASP發牌制度嚴格但設計完善。它為合法的虛擬資產業務提供了一條清晰的監管確定性路徑,同時建立了穩健的保障措施以保護投資者和維護市場誠信。對於願意投資合規的公司來說,香港VASP牌照代表着全球數碼資產領域的優質資歷。」

需要協助申請VASP牌照?

我們經驗豐富的顧問可以在VASP發牌流程的每一步為您提供指導,從申請前準備到獲批後的合規。

透過 WhatsApp 聯繫我們

香港已将自身定位为全球领先的虚拟资产中心,建立了一套平衡创新与投资者保障的综合监管框架。虚拟资产服务提供者(VASP)发牌制度通过修订《打击洗钱及恐怖分子资金筹集条例》(AMLO)引入,由证券及期货事务监察委员会(证监会)监管,为在香港运营虚拟资产交易平台(VATPs)及提供相关服务制定了清晰的规则。

本综合指南将详细解释在香港取得VASP牌照所需了解的一切,包括监管框架和双重发牌要求、资本要求、合规基础设施及申请流程。无论您是加密货币交易所、数码资产托管人,还是正在探索虚拟资产领域的金融科技公司,了解香港的VASP制度对于合法经营至关重要。

1. 监管框架:AMLO与SFO

香港对虚拟资产的监管建基于两项核心立法:《打击洗钱及恐怖分子资金筹集条例》(AMLO)和《证券及期货条例》(SFO)。这一双轨框架确保虚拟资产活动同时受到反洗钱/反恐融资要求和证券监管(如适用)的约束。

AMLO发牌制度

自2023年6月1日起生效的经修订AMLO要求,任何在香港经营虚拟资产交易所或积极向香港投资者推销此类服务的人士,均须向证监会取得牌照。无论所交易的虚拟资产是否构成SFO下的"证券",均须遵守此规定。AMLO制度涵盖以下活动:

  • 运营虚拟资产交易平台,方便买卖或交换虚拟资产
  • 为客户提供虚拟资产托管服务
  • 为虚拟资产交易提供转移或结算便利
  • 为虚拟资产提供场外交易(OTC)服务

SFO发牌要求

当虚拟资产构成SFO下的"证券"或"期货合约"时,平台运营商亦必须根据SFO就相关受规管活动持牌。这为同时交易证券型代币和非证券型虚拟资产的平台创造了双重发牌要求。仅交易非证券型虚拟资产的平台只需取得AMLO VASP牌照。

何谓"虚拟资产"?

根据AMLO的定义,"虚拟资产"(VA)是指以密码学方式保护的数码价值表示,以记账单位或经济价值储存形式表达,具有交换媒介功能,并可通过电子方式转移、储存或交易。这包括比特币和以太币等加密货币、功能型代币和稳定币,但不包括法定货币的数码表示(央行数码货币)、已受SFO规管的金融资产,以及忠诚度积分或游戏代币等封闭式有限用途项目。

2. 谁需要VASP牌照?

VASP发牌要求广泛适用于任何在香港经营或计划经营中心化虚拟资产交易平台的实体。证监会采取"实质重于形式"的方法,即决定是否需要持牌的是您业务活动的实际性质,而非仅仅是您对服务的描述。

需要VASP牌照的实体

  • 在香港或从香港运营的中心化加密货币交易所
  • 为虚拟资产撮合买卖订单的平台
  • 作为交易所运作一部分提供托管服务的实体
  • 积极向香港居民推销虚拟资产交易服务的公司
  • 以撮合多方方式运作的场外交易柜台

可能获豁免的实体

  • 在没有中心化运营商的情况下运作的去中心化交易所(DEXs)——但证监会已表示可能在未来的指引中处理此类情况
  • 不托管客户资产或撮合订单的点对点交易平台
  • 仅交易构成证券的虚拟资产的SFO持牌公司

3. 证监会对虚拟资产交易平台的监管方针

证监会对VATPs采取了分阶段、以原则为本的监管方式。最初,证监会于2019年推出自愿参与的发牌框架,适用于至少交易一种构成证券的虚拟资产的平台。自2023年6月1日起,该框架被强制性的AMLO发牌制度所取代,要求所有中心化VATPs必须持牌。

核心监管原则

  • 相同活动、相同风险、相同监管:与传统金融活动构成相似风险的虚拟资产活动,须受到相当的监管要求约束
  • 投资者保障优先:证监会十分重视通过稳健的托管、保险和披露要求保障散户和专业投资者
  • 科技中立:监管聚焦于活动的经济实质,而非用于提供服务的技术
  • 风险为本方法:监管要求与业务活动所带来的风险成比例

散户与专业投资者的准入

证监会在投资者准入方面采取了渐进式的方式。最初只允许专业投资者在持牌VATPs上进行交易。然而,自2023年6月起,证监会允许持牌平台为散户投资者提供服务,但须遵守加强的保障措施,包括:

  • 知识评估:平台必须在允许散户投资者交易前,评估其对虚拟资产是否具备足够知识
  • 风险披露:必须向所有散户客户提供全面的风险披露声明
  • 投资限额:平台应根据散户投资者的财务状况设定合理的投资限额
  • 代币准入标准:只有符合证监会代币准入标准的虚拟资产方可向散户投资者发售,对散户可参与的代币有更严格的标准
  • 适合性评估:平台必须确保所提供的虚拟资产和服务适合每位散户客户

4. 资本及财务要求

证监会对VASP持牌人施加严格的资本要求,以确保其拥有充足的财务资源安全运营并保护客户资产。由于虚拟资产领域固有的额外风险,这些要求明显高于传统证券发牌。

要求 金额(港币) 备注
最低缴足股本 $5,000,000 须在牌照批准前全额缴付
最低速动资金 $5,000,000 持续要求;可能根据风险评估而更高
申请费 $29,810 申请时缴付的不可退还费用
年度牌照费 $14,680 每年缴付以维持牌照
保险/赔偿安排 因情况而异 必须涵盖托管中的客户虚拟资产

保险与赔偿要求

持牌VATPs必须维持保险或赔偿安排,以涵盖因黑客攻击、盗窃或其他安全事件而造成的客户虚拟资产潜在损失。证监会预期覆盖范围应保障存放于热存储的大部分客户虚拟资产(如50%)和冷存储(如100%)。具体条款和金额在发牌过程中按个案评估。

5. 客户资产的托管与保障

客户虚拟资产的托管是VASP发牌制度中最关键的环节之一。证监会要求持牌平台实施稳健的托管安排,以保护客户资产免受损失、盗窃和挪用。

主要托管要求

  • 客户资产分隔:客户虚拟资产必须存放在独立的钱包中,与平台的自有资产分开
  • 冷存储规定:绝大部分客户虚拟资产(如98%)必须存放在未连接互联网的冷钱包中
  • 多重签名控制:存取客户资产钱包必须要求多名授权签署人
  • 助记词管理:私钥和助记词必须安全存放,并有适当的备份和灾难恢复程序
  • 第三方托管:如使用第三方托管人,VATP必须确保托管人符合同等标准并持续进行尽职调查
  • 定期对账:每日对所有钱包和账户中的客户资产余额进行对账

6. 虚拟资产的反洗钱/反恐融资合规

反洗钱和反恐融资合规是VASP发牌制度的基石。持牌VATPs必须实施全面的反洗钱/反恐融资政策和程序,同时符合AMLO要求和FATF建议,包括虚拟资产转移的"旅行规则"。

核心反洗钱/反恐融资义务

  • 客户尽职调查(CDD):在允许交易前对所有客户进行完整的身份验证,对高风险客户进行加强尽职调查
  • 交易监控:自动化系统实时侦测和标记可疑交易
  • 可疑交易报告(STR):对任何涉嫌洗钱或恐怖分子资金筹集的交易,必须向联合财富情报组(JFIU)报告
  • 旅行规则合规:代客户转移虚拟资产时,VATPs必须按照FATF旅行规则收集和传送汇款人和收款人资料
  • 制裁筛查:持续对照相关制裁名单筛查客户和交易
  • 记录保存:所有CDD记录和交易资料至少保存6年

区块链分析

证监会期望持牌VATPs采用区块链分析工具,以追踪虚拟资产交易的来源和目的地、识别可能受污染的资产,以及评估对手方钱包的风险概况。这种技术驱动的方法对于虚拟资产生态系统中有效的反洗钱/反恐融资合规至关重要。

7. 合规基础设施要求

证监会要求VASP持牌人建立涵盖管治、风险管理、技术和运营韧性的全面合规基础设施。该基础设施必须与平台业务活动的规模和复杂程度相称。

管治和人员

  • 至少两名具有虚拟资产和金融服务相关经验的负责人员(ROs)
  • 一名专责的合规主任,具备反洗钱/反恐融资和证券监管专业知识
  • 一名负责网络安全的信息安全主任
  • 运营、风险管理和合规职能部门有足够的人员配置

技术及网络安全

  • 具备高可用性、低延迟和灾难恢复能力的稳健交易系统
  • 符合国际标准(如ISO 27001)的全面网络安全框架
  • 由独立第三方定期进行渗透测试和漏洞评估
  • DDoS防护、入侵侦测和事件应对方案
  • 安全的API管理和存取控制

8. 申请流程

VASP牌照申请流程包括多个阶段,需要大量文件。证监会对每位申请人的适当人选资格、业务计划、系统和控制措施及财务资源进行全面评估。

步骤一:申请前准备(2-4个月)

  • 注册香港公司(如尚未完成)
  • 招聘具有虚拟资产经验的合格ROs及主要人员
  • 制定涵盖目标市场、产品组合和收入模式的详细业务计划
  • 设计并实施具备稳健安全功能的交易平台
  • 建立托管安排和保险覆盖
  • 制定全面的合规政策(反洗钱/反恐融资、KYC、代币准入、托管)
  • 聘请外部审计师和法律顾问

步骤二:提交申请

  • 向证监会提交VASP牌照申请
  • 提供所有所需支持文件
  • 缴付申请费
  • 为每位RO和持牌代表提交个人申请

步骤三:证监会评估(6-12个月)

  • 证监会审查申请并对所有主要人员进行背景调查
  • 证监会可能进行现场检查以评估平台的运营准备状况
  • 可能聘请外部评估师评估平台的网络安全和技术基础设施
  • 证监会发出补充资料信函要求澄清或提供额外资料
  • 多轮问答往来属常见情况

步骤四:原则上批准及条件

  • 如满意申请,证监会发出附带条件的原则上批准(AIP)
  • 条件可能包括完成额外的安全评估、落实保险或修改系统
  • 申请人必须在最终发牌前履行所有AIP条件

步骤五:最终发牌

  • 所有条件履行后,证监会颁发VASP牌照
  • 平台被列入证监会公众登记册
  • 平台可按照其牌照条件开展业务

9. 与其他司法管辖区的比较

香港的VASP发牌制度是亚太地区最全面的制度之一。以下是与其他主要司法管辖区的比较:

方面 香港 新加坡 迪拜(VARA)
监管机构 证监会 新加坡金管局 VARA
法律框架 AMLO + SFO 支付服务法 虚拟资产监管局法
散户准入 是(附带保障措施) 受限 是(附带保障措施)
资本要求 港币500万以上 新币25万起 因活动而异
保险规定 是(热存储+冷存储) 非强制
处理时间 6-12个月 6-12个月 3-6个月
旅行规则 是(符合FATF)

10. 时间表与成本

在香港取得VASP牌照的端到端过程通常需要9至18个月,具体取决于申请的复杂程度和申请人的准备状态。以下是典型时间表和相关成本的细分:

阶段 时长 预计成本(港币)
申请前准备 2-4个月 $500,000 - $2,000,000
提交申请 2-4周 $29,810(申请费)
证监会审查及评估 6-12个月 $300,000 - $800,000(专业费用)
外部评估(网络安全等) 1-2个月 $200,000 - $500,000
履行AIP条件 1-3个月 因情况而异

前期总成本,包括公司设立、技术基础设施、人员招聘、专业费用和资本要求,根据计划运营的规模和复杂程度,可能从港币1,000万至5,000万或更多。

"香港的VASP发牌制度严格但设计完善。它为合法的虚拟资产业务提供了一条清晰的监管确定性路径,同时建立了稳健的保障措施以保护投资者和维护市场诚信。对于愿意投资合规的公司来说,香港VASP牌照代表着全球数码资产领域的优质资历。"

需要协助申请VASP牌照?

我们经验丰富的顾问可以在VASP发牌流程的每一步为您提供指导,从申请前准备到获批后的合规。

通过 WhatsApp 联系我们