What is a digital banking license? Which business models are applicable
Hong Kong digital banks usuallyHong Kong Monetary Authority(HKMA)’s “Virtual Bank” regulatory framework,Conduct business as a licensed bank under the Banking Ordinance。Its core features are:Online-focused customer acquisition and service delivery、Risk management driven by technology and data、and in capital、governance、outsourcing、Meet the same or more prudent regulatory requirements as traditional banks in terms of cybersecurity and consumer protection。
Common applicable modes:
- Retail/SME Digital Banking (Deposits、loan、pay、Cards and wealth management, etc.)
- Scenario finance (e-commerce/platform ecology,Embedded Finance)
- Cross-border and multi-currency services (for international customers or cross-border trade)
- B2B2C distribution model based on API/open banking (need to focus on evaluating outsourcing and third-party risks)
If your product route is more "payment/remittance" or "money services" rather than complete banking services,You can also first evaluate whether you need other license/qualification combinations,Then decide whether to enter the digital banking license path。For relevant technical and compliance support, please refer to:Fintech Compliance Consulting、Cross-border payment solutions。
Regulatory concerns and entry barriers (expressed in terms of “verifiable evidence”)
《银行业条例》附表7“认可的最低准则”规定,在香港注册成立的银行须维持不少于3亿港元(或认可货币等值)的已缴股本;数字银行同样须符合持牌银行的最低准则。除法定最低额外,申请人还应按业务计划、风险和压力测试证明资本资源充足。
board governance、independence、Separation of responsibilities for key positions (CEO/CRO/CCO/MLRO/CIO, etc.)、Performance and accountability mechanisms need to form systems and evidence chains (meeting minutes、authorization matrix、Risk Appetite Statement, etc.)。
Cover credit、market、Liquidity、operate、Compliance、Models and third-party risks;Clarify RCSA、KRI、quota system、Problem rectification closed loop and internal audit plan。
Align AMLO、HKMA SPM and related guidelines:Customer Risk Assessment (CRA)、EDD、Transaction monitoring、List screening、suspicious transaction report、and digital identity/remote account opening control。
Identify key outsourcing clearly、Due diligence、Contract terms (audit rights/data residency/subcontracting controls/exit plans)、Continuous monitoring and concentration risk。
security baseline、Penetration testing and vulnerability management、Log retention and evidence collection、Keys and Encryption、Permissions and privileged account management,and personal data protection (PDPO) and cross-border transfer assessments。
We emphasize the principle of “verifiable evidence” in our coaching:Every regulatory statement should be traceable to institutional documents、System screenshot/configuration、Exercise records、Supplier Contract Terms、and auditable operational processes,Thereby improving interview defense and follow-upOn-site inspectionpass rate。
Implementation support related to data and privacy can be carried out simultaneously:Data security assessment、Personal information protection、Data privacy policy development。
List of core materials for application package (regulatory perspective)
1)Business and Products:target customer group、Product terms and pricing logic、Customer acquisition and marketing compliance (including misleading statement control)、Customer Complaints and Compensation Mechanism、Key indicators and customer handling plans in case of downtime/failure。
2) Governance and three lines of defense:Board Charter、committee setting、Authorization Matrix (DoA)、Compliance and risk independence、internal audit plan、Policy Framework。
3) Risk and Capital:Risk Appetite (RAS)、Limits and monitoring、stress test、Liquidity management、capital planning、and model methodology and verification mechanisms (such as using scorecards/machine learning)。
4)AML/CFT:Enterprise-level risk assessment、Customer due diligence (KYC/EDD)、Sanctions and PEP Strategy、Transaction monitoring rules and scenarios、Suspicious transaction handling process、Training and quality inspection mechanism。
5)IT and outsourcing:target architecture、List of critical systems、Change management、access control、Logging and monitoring、Vulnerability management、BCP/DR (including drills)、Key Outsourcing Due Diligence and Contract Points、Exit Plan。
6) Finance and Auditing:accounting policies、Audit and regulatory reporting capabilities、Data caliber and reconciliation mechanism、Description of fund uses and sources (including shareholder penetration and fund compliance)。

Implementation path:From 0 to being able to submit an application (including online preparation)
Clear license path、product boundaries、Target customer groups and regulatory risk points;Output gap list and roadmap (Governance/Capital/IT/AML/Outsourcing)。
Board of Directors and Key Position Responsibilities、three lines of defense、Policies and Procedures Library、Reporting mechanism and KRI system taking shape。
Core system and cloud architecture selection;Outsourced due diligence and solidification of contract terms;Security and BCP/DR solutions and drill plans。
Complete business plan、venture capital、AML/CFT、Complete application package for IT and outsourcing;Prepare to defend Q&A and evidence attachment。
Provide additional explanations and adjustments in response to inquiries;“Operation proof” (commissioning record) of key controls、Exercise minutes)。
Online list、KYC and transaction monitoring threshold calibration、Operation and customer service SOP、Internal audit first year planning and compliance routine monitoring。
If you plan to introduce mature systems or white label capabilities,Technical deliverables can be designed simultaneously with regulatory materials,Avoid “system first”、Refactoring costs caused by "compliance and post-compliance"。Relevant delivery capabilities can be referred to:Payment system integration、KYC identity verification system、eDon TM Transaction Monitoring System。
AML/CFT and Sanctions:“Explainable Compliance” in Digital Scenarios
The difficulty with AML/CFT in digital banks is usually not “whether there is a system”,But lies in:The customer journey is highly online、Identity verification and device/behavior signals are complex、and the superimposed risks of sanctions and fraud brought about by cross-border transactions and multiple currencies.。
Key controls we generally recommend:
- Customer Risk Assessment (CRA) Interpretable:Rule + model parallelism,The source of the variable needs to be explained、weight logic、Manual review and appeal mechanism。
- Remote account opening hierarchical control:Different risk levels correspond to different amounts、Function and trigger review points (such as abnormal address/occupation/fund source)。
- Sanctions and List Screening:Cover customers、beneficial owner、Counterparties and ultimate beneficiaries;Clarify fuzzy matching strategy and disposition SLA。
- Scenario-based transaction monitoring:around products (transfers、Card、Loan disbursement and repayment、Merchant acquiring, etc.) Create scenarios;Adjust parameters regularly、Backtesting and false positive management。
- STR closed loop and audit trail:From alarm - investigation - upgrade - report - archiving, the entire process leaves traces,Support regulatory spot checks and internal audit reviews。
If involvedCross-border customersand group structure,It is also recommended to evaluate simultaneouslytax information exchangeand disclosure obligations:CRS tax consulting、Cross-border tax consulting。
Cost and Budget Reference
香港数字银行按《银行业条例》下的银行牌照路径申请。截至2026年9月3日核验,该条例附表2“费用”列明银行牌照费及续牌费均为750,000港元。
上述金额是法定牌照费,不包括附表7“认可的最低准则”规定的最低已缴股本,也不包括核心银行系统、network security、管理层及控制职能人员、office space、audit、法律与专业顾问等申请和运营成本。项目预算应分别列示:法定牌照费、资本资源、申请准备与系统上线成本,以及获批后的持续监管和运营成本。
The service fees are subject to applicable jurisdiction、Business scope、Main structure、Data complexity and delivery schedule assessment;Involving government fees,The latest fees announced by the corresponding regulatory agency shall prevail.。
Frequently Asked Questions (FAQ)
In the context of Hong Kong,Digital banks generally fall within the HKMA’s virtual banking regulatory framework,Ultimately carry out business as a licensed bank under the Banking Ordinance。Market representations may vary,But the core of supervision lies in “technology-based delivery model + equal prudential supervision”。
High-frequency inquiries focus on:Penetration of shareholders and funding sources、Board governance and independence of key positions、Controllability of outsourcing and cloud (audit rights/exit plan/subcontracting management)、Interpretability and enforceability of AML/CFT、Cybersecurity and operational resilience (including drills and incident response)。
Can use outsourcing and mature systems,However, outsourcing governance needs to be included as a core chapter in application materials and implementation control.:Due diligence、Contract terms、Continuous monitoring、Concentration risk and exit plans must be implementable and auditable。
应先按实际产品和资金流判断牌照路径。如果业务不接受存款而主要提供兑换或汇款,应评估相应货币服务或支付监管要求;申请数字银行则属于《银行业条例》下的银行牌照路径,不能把MSO牌照视为数字银行牌照的前置条件或替代品。You can refer to it first香港金管局数字银行监管说明。
usually include:Gap Assessment and Roadmap、Complete governance and compliance package、AML/CFT framework and key processes、Outsourcing and Cloud Governance Documents、Data and security assessment recommendations、Application materials coordination and inquiry response support,and compliance acceptance checklist before going online.。
If you want to plan an integrated path of "license + system + compliance operation" at the same time,Can be referenced:Virtual Banking Solutions、Fintech Compliance Consulting。
Executable preparation for digital banking license application
Digital banking license applications usually examine both shareholders and funding sources、Management、business model、capital、client funds、risk governance、Technological resilience and exit planning。Completing the system or registering a company does not equate to meeting the conditions for a banking license。
- Clear deposits and loans、pay、Card、Forex、Permissible boundaries for wealth management and client funds。
- Prepare shareholders and controllers、Source of funds、management suitability、Three-year business and financial plan。
- Establish credit、Liquidity、capital、AML/CFT、consumer protection、Data and Cyber Security Framework。
- Provide stress testing、Disaster recovery、outsourcing、incident response、Evidence of recovery and orderly exit。
Official verification:金管局《授权指引》第9章:数字银行授权、第8章:Application procedureand申请文件清单附件2。能否获批及审查所需时间由金管局按申请材料和实际情况决定,不能承诺固定结果或周期。

