SFC and AFRC Sign MoU to Tighten Crypto Financial Reporting Oversight in Hong Kong
Hong Kong's two key financial gatekeepers have formalised a deeper working relationship that directly affects every SFC-licensed virtual asset service provider (VASP), authorised fund, and the accounting firms that audit them. On 28 September 2026, the Securities and Futures Commission (SFC) and the Accounting and Financial Reporting Council (AFRC) signed a new Memorandum of Understanding (MoU) that expands regulatory cooperation well beyond the listed-company audit oversight that defined their previous arrangement. For CFOs, finance directors, and audit partners serving the crypto sector, the practical implications are immediate.
What the New MoU Actually Covers
The 2021 MoU between the SFC and the then-named Financial Reporting Council was largely confined to the financial reporting and audit work of listed entities. The new agreement is substantially broader in two dimensions: the entities it covers, and the tools available to both regulators.
Entities now in scope
The MoU explicitly names four categories of regulated entity:
- SFC-licensed corporations (broker-dealers, asset managers, and similar regulated intermediaries)
- SFC-licensed virtual asset service providers
- SFC-authorised funds
- Registered open-ended fund companies (OEFCs)
In each case, the cooperation extends not just to the entity's own financial and compliance reporting, but also to the audit and assurance work performed by the external auditors of those entities. Auditors are, in other words, directly within the frame.
Regulatory tools established
The MoU creates a framework for four specific types of cross-regulator activity: information sharing, case referrals, mutual assistance, and coordinated inspections and investigations. That last category is the one most likely to affect day-to-day operations at audit firms and regulated entities alike. A joint inspection means both the SFC and the AFRC can review the same file, simultaneously, with their respective statutory powers in play.
Why This Matters for Crypto Financial Statements
The extension of the MoU to VASPs is not symbolic. Crypto financial statements prepared under IFRS (which Hong Kong mandates for many regulated entities) present genuinely complex judgements: the classification of digital assets under IAS 38 or IAS 2, impairment testing for intangible assets where no active market exists, and the fair value disclosures required under IFRS 13 for assets measured at fair value. Auditors signing off on those statements now face the prospect of AFRC reviewers working alongside SFC examiners, each bringing a different but complementary lens.
The IFRS crypto assets challenge in a joint oversight world
IFRS does not yet have a dedicated crypto-asset standard. Entities reporting under IFRS for crypto assets currently navigate a patchwork: IAS 38 for most tokens held as intangible assets, IAS 2 for holdings that meet the commodity-broker trader exception, and IFRS 9 for certain structured tokens that qualify as financial instruments. Each classification carries different measurement and disclosure requirements, and the choices made can materially affect reported net assets and profit or loss. Under a joint oversight framework, a classification decision that the SFC views as inconsistent with an entity's prudential position could simultaneously trigger an AFRC audit quality review. The two lines of enquiry, previously separate, are now formally linked.
Compliance reporting is also in scope
The MoU covers not only financial reporting but also compliance reporting. For SFC-licensed VASPs, compliance reporting includes the periodic financial returns submitted to the SFC under the licensing conditions established by the SFC's VASP regime. Errors or omissions in those returns can now be surfaced through the AFRC's audit oversight function as well, and vice versa. An auditor flagging a going-concern issue in the accounts, for example, could trigger a referral to the SFC's supervision team.
What the Regulators Said
The public statements from both chairpersons and chief executives are worth reading carefully, because they signal supervisory intent rather than just goodwill.
SFC's framing: market integrity and investor confidence
SFC Chairman Dr Kelvin Wong described the MoU as reinforcing a "shared commitment to reliable financial reporting and high-quality audits," and specifically referenced the breadth of Hong Kong's financial ecosystem. SFC CEO Julia Leung went further, noting that the arrangement "ensures our supervision evolves with market dynamics." In the context of a rapidly growing VASP-licensed population, that phrase is a clear signal that the SFC expects audit and reporting standards in the crypto sector to keep pace with those in traditional financial services.
AFRC's framing: earlier risk detection
AFRC CEO Janey Lai's statement is arguably the most operationally significant: enhanced cooperation and information sharing will "enable us to identify emerging risks earlier." For audit firms, earlier risk identification by the regulator typically translates into shorter intervention timelines. A firm whose client is flagged by the SFC can expect the AFRC to be in contact sooner than under the previous, more siloed arrangement.
Practical Implications for Accounting Firms and CFOs
Audit firms serving VASPs
Firms with audit engagements covering SFC-licensed VASPs should expect that their audit files, methodologies, and quality control procedures are now subject to coordinated inspection. Several practical steps are worth considering now:
- Review whether your firm's crypto asset valuation methodology is documented at a level of detail sufficient to withstand dual-regulator scrutiny. Fair value estimates for thinly traded tokens, in particular, need auditable price source hierarchies.
- Confirm that your audit engagement partner is aware of the expanded MoU scope. The risk profile of a VASP audit engagement has changed, and engagement acceptance and continuance assessments should reflect that.
- Check that your quality management systems (under HKQM 1, Hong Kong's equivalent of ISQM 1) are calibrated for the heightened inspection risk in this sub-sector.
CFOs and finance directors at licensed VASPs and funds
For the finance function at an SFC-licensed entity, the MoU raises the stakes around three specific areas:
- Financial statement quality: Disclosures around digital asset classifications, fair value hierarchies, and impairment assumptions need to be complete and defensible. A financial statement that satisfies the SFC's prudential review but leaves AFRC reviewers with unanswered questions about accounting policy choices creates unnecessary regulatory exposure.
- Compliance return accuracy: The periodic returns filed with the SFC must align with the audited accounts. Discrepancies, even where they reflect timing differences rather than errors, should be explained proactively and in writing.
- Auditor relationship: The quality of the external auditor and the rigour of their work programme now has direct regulatory consequences. Entities whose auditors are found to have deficiencies in their VASP audit work face the risk of both an AFRC sanction against the auditor and an SFC supervisory action against the entity itself.
Open-ended fund companies holding digital assets
Registered OEFCs that hold or are exposed to digital assets through their investment mandates are now explicitly covered. For those preparing crypto financial statements under IFRS, the interaction between fair value measurement requirements and the AFRC's audit oversight of their auditors creates a closed loop: the SFC monitors the fund's compliance, the AFRC monitors the auditor's work, and the two bodies now share information systematically. Fund administrators and their appointed auditors should review whether their digital asset valuation and disclosure processes are ready for that environment. The question of how the FASB's fair value model for crypto assets under ASC 350-60 and IFRS-based approaches compare is also worth understanding for any fund with cross-border reporting obligations, and our earlier coverage of how the SEC is reshaping crypto financial statements for advisers and funds sets out the US side of that picture.
The Broader Hong Kong Regulatory Context
The new MoU sits within a broader effort by Hong Kong authorities to position the city as a well-regulated digital asset hub. The SFC's VASP licensing regime has been operational since mid-2023, and the number of licensed and applicant entities has grown steadily. As that population scales, the regulatory infrastructure supporting financial reporting oversight needs to scale with it. This MoU is, in effect, the supervisory architecture catching up with the growth of the licensed sector.
It also signals that Hong Kong is not treating crypto financial reporting as a lower-priority subset of its broader capital markets oversight. Joint inspections, case referrals, and formal information-sharing protocols are the tools of a mature, integrated supervisory framework, not a light-touch approach. Firms that have been operating on the assumption that VASP audit quality would receive less scrutiny than listed-entity audit quality should update that assumption.
For accounting firms and CFOs thinking about digital asset accounting software and workflow, the MoU is also a reminder that the output of those systems, the financial statements and compliance returns, is now subject to a higher standard of regulatory scrutiny. Robust digital asset accounting software that produces audit-ready outputs with clear data lineage is no longer a nice-to-have. It is part of the compliance infrastructure. See also our analysis of FASB's proposed stablecoin cash-equivalent classification under US GAAP for context on how standard-setters in other jurisdictions are responding to similar pressures.
Frequently Asked Questions
Does this MoU apply to firms that have applied for but not yet received an SFC VASP licence?
The MoU as published covers SFC-licensed VASPs. Entities that are applicants but not yet licensed fall outside the formal scope described in the announcement. However, firms in the application process should still ensure their financial reporting and audit arrangements meet the standards they will be held to once licensed, given that the SFC reviews financial information as part of the licensing process itself.
How does this affect the choice of auditor for a licensed VASP or fund?
The AFRC now has a formal cooperative relationship with the SFC covering audit work on VASPs and authorised funds. An auditor with deficiencies in their crypto-asset audit methodology could trigger both AFRC disciplinary proceedings and SFC supervisory scrutiny of the licensed entity. The quality and crypto competence of the appointed auditor is therefore a material consideration for licensed firms, not just a procurement decision.
Which accounting standards apply to crypto assets for SFC-licensed entities in Hong Kong?
Most SFC-licensed entities prepare financial statements under Hong Kong Financial Reporting Standards (HKFRS), which are substantially converged with IFRS. There is no dedicated IFRS or HKFRS standard for crypto assets yet. Entities typically apply HKAS 38 (intangible assets) or HKAS 2 (inventories for broker-trader exceptions), with HKFRS 9 applying to tokens that qualify as financial instruments. HKFRS 13 governs fair value measurement and disclosure regardless of which primary standard applies.
What is a coordinated inspection under the new MoU, and what does it involve in practice?
The MoU establishes a framework for inspections and investigations conducted jointly by the SFC and the AFRC. In practice, a coordinated inspection could involve both regulators reviewing an entity's financial and compliance reporting and the audit firm's work papers at the same time, with findings shared between them. The exact procedures would be agreed between the two bodies on a case-by-case basis, but entities and their auditors should be prepared for the possibility of simultaneous scrutiny from both regulators.
Does the MoU create any new reporting obligations for licensed entities?
The MoU does not itself create new statutory reporting obligations. It is a cooperation framework between two regulators. The practical effect is that existing obligations, financial returns to the SFC, audited accounts, and compliance reports, are now subject to a more integrated supervisory process. Entities that are already meeting their existing obligations have the strongest starting position, but the quality and completeness of disclosures will matter more under a joint oversight regime than under the previous siloed one.
