TABLE OF CONTENTS

    Financial compliance in Asia-Pacific (APAC) has moved from policy to proof in 2026. Regulators across the region, including Australia, Singapore, Hong Kong, Malaysia and China, expect evidence that financial services firms' ethics and conduct controls work in practice. Where they do not, those regulators are sending a message through enforcement actions.

    For compliance teams, the task of keeping up with regulators' focus areas can feel like being handed a jigsaw puzzle one piece at a time. A new rule on conflicts of interest can arrive in one market, while an enforcement action over personal trading lands in another, and a consultation on fit and proper checks arrives in yet another. Each one tends to land on a single aspect of employee conduct.

    The difficulty in keeping pace is that regulators do not look at these pieces in isolation. They want to know firms have a "complete picture" oversight perspective. It is therefore critical to ensure employees understand their obligations and are fit for their role responsibilities, from licensing and outside interests through to personal trading, access to material non-public information (MNPI), and the use of approved communications channels.

    Our article walks through the latest updates and enforcement actions across the APAC region, along with what is on the horizon for 2027. We also explore how compliance teams can more effectively pull the puzzle pieces together within their own compliance programmes.

    Key Highlights

    • The ASIC Corporate Plan 2026–27 puts a microscope on suspicious trading controls at institutional brokers.
    • APRA has released draft CPS 510, which would bring banks and insurers into its conflicts regime from 1 January 2028.
    • MAS continued to penalise AML/CFT lapses and wants a stronger stance from banks and insurers.
    • A Hong Kong asset manager paid HKD 2 million after staff placed more than 2,500 personal trades without approval.
    • Reference checks in Hong Kong now cross from banking into insurance, and CSRC figures show insider trading cases rose 22% in 2025.

    Australia

    ASIC Raises the Bar on Conflicts and Market Integrity

    The Australian Securities and Investments Commission (ASIC) reissued Regulatory Guide 181 in December 2025. Read more about the update in our article ASIC RG 181 Update: Raising the Stakes in Conflicts of Interest. ASIC provided guidance on its expectations of “adequate arrangements to manage conflicts”, including a four-step framework for managing employee conflicts of interest. ASIC Commissioner Kate O'Rourke described effective conflict management as "the cornerstone of trust in financial services".

    Sarah Court, who took over as ASIC Chair on 1 June 2026, had already put insider trading high on the list of ASIC's 2026 enforcement priorities during her time as Deputy Chair. The ASIC Corporate Plan 2026–27 goes a step further, with a review of suspicious trading controls at institutional brokers and work on AI-driven market manipulation risks.

    Employee conflicts of interest continue to see enforcement actions. In April 2026, ASIC banned a former financial adviser for 10 years and suspended the licence of the advice firm he directed.¹ He had accepted A$100,000 in conflicted remuneration without telling his clients, and ASIC found he did not meet fit and proper requirements. The firm's licence was cancelled a few months later.

    APRA Redrafts Its Governance Standard

     Meanwhile, the Australian Prudential Regulation Authority (APRA) released a revised draft of CPS 510 Governance in June 2026. If enacted, it will extend the conflicts rules for superannuation trustees to banks and insurers. The planned start date is 01 January 2028. Under CPS 510, each entity will need to identify and manage actual and potential conflicts, keep an up-to-date register and record in board minutes how each conflict was dealt with. Following industry feedback, guidance will cover perceived conflicts rather than the standard itself. 


    Singapore

    MAS Keeps the Focus on Controls in Practice

    The Monetary Authority of Singapore (MAS) has made it clear that an AML/CFT framework is only as good as its practical application by employees. In May 2026, it imposed a SGD 300,000 composition penalty on a licensed trust company that did not scrutinise unusual transactions or file its suspicious transaction reports promptly.² MAS also found that staff lacked a proper understanding of money laundering red flags. An independent reviewer must now check the firm's remediation work.

    Senior management accountability is also gaining attention. In September 2026, MAS opened a consultation on corporate governance requirements for banks and insurers. The regulator is proposing stricter tests of director independence. Licensed firms can submit their feedback before 09 December 2026.

    Hong Kong

    The SFC Is Targeting the Gap Between Policy and Practice

    In April 2026, the Securities and Futures Commission (SFC) fined a licensed asset manager HKD 2 million for failing to supervise staff personal trading, and suspended its former director and responsible officer for eight months.³ Staff made more than 2,500 personal trades without prior written approval, and on more than 200 occasions traded the same securities as the firm's funds on the same day. The firm did have a staff dealing policy in place, but nobody was checking whether staff followed it. See our article A Costly Oversight: Hong Kong SFC Action on Personal Trading for further details of this case.

    A month earlier, the SFC banned a former licensed representative of an asset manager for life and fined him HKD 17.43 million.⁴ He had arranged for a managed fund to lend HKD 22.5 million to a company under his control without ever declaring the conflict. The SFC described his conduct as "wilful and dishonest".

    Inside information is another critical piece of the full compliance puzzle. Under the SFC's Guidelines for Market Soundings, mishandling inside information can work against a person's fit and proper standing. Looking ahead, the SFC published its Strategic Action Plan in September 2026. The regulator is committing to enhancing its supervision and enforcement activity through the use of technology, including AI programs.


    See our full, on-demand webinar on Market Sounding Compliance for more detail.

    The HKMA Extends Reference Checking Across Sectors

     The Hong Kong Monetary Authority (HKMA) has also widened its efforts to stop "rolling bad apples", the term used for staff who move between firms after instances of misconduct. Under a joint circular issued with the Insurance Authority in May 2026, insurers and banks acting as licensed insurance agencies have had to check references for individual long-term insurance intermediaries since 1 July 2026, going back seven years. The regulators refer to this first cross-sector stage as Phase 3A.⁵

    Malaysia

    Conduct and Financial Crime Controls Under Scrutiny

    The Securities Commission Malaysia (SC) continues its firm stance on insider trading and the misuse of MNPI. Bank Negara Malaysia (BNM) has also sharpened its focus in this area. In August 2026, BNM and the Labuan Financial Services Authority announced an enforcement action to the tune of MYR 10 million compound against an investment bank. The investigation found the firm failed to promptly report 53 suspicious transactions and fell short on customer due diligence.⁶

    Separately, BNM put forward rules to make insurers and takaful operators responsible for mis-selling by the intermediaries who sell their products.

     

    China

    CSRC Enforcement Data Shows a Sharper Focus

     

    The China Securities Regulatory Commission (CSRC) reported in April 2026 that insider trading cases rose by 22.5% in 2025, to 218 of the 701 cases it investigated.⁷ Market manipulation cases went up by close to a fifth, and fines and confiscations came to CNY 15.47 billion over the year.

    Beijing's wider policy goals haven't shifted either. Speaking at the Financial Street Forum in October 2025, People's Bank of China Governor Pan Gongsheng named macro-prudential regulation as a five-year priority.⁸ He pointed to broader coverage and firmer checks on systemic risk.

    India

     The Securities and Exchange Board of India (SEBI) broadened the definition of unpublished price sensitive information (UPSI) when it amended its Prohibition of Insider Trading Regulations in 2025. Listed companies and intermediaries may want to check that their UPSI registers and trading window controls have kept pace with the change.

    Indonesia

    The OJK Tightens Bank Governance and Related-Party Controls

     Indonesia's Financial Services Authority (OJK) Circular Letter No. 14/SEOJK.03/2025 is still the main governance reference for banks. It contains 16 self-assessment factors, including anti-bribery and anti-fraud programmes. The regulator also expects banks to deal with related parties on terms no better than they would offer anyone else, and to closely monitor insider lending, staff affiliations, and gifts.


    What to Watch in 2027

    Several of the pieces covered above have dates attached, so it helps to plan around them now rather than later.

    • Hong Kong, end of 2026. The HKMA and the Insurance Authority will review cross-sector reference checking, and their findings will shape Phase 3B, the next stage of the arrangement, which could extend reference checking to more roles.⁵
    • Singapore, from December 2026. MAS's governance consultation closes on 9 December 2026, so final requirements on director independence could follow during 2027.
    • Australia, to June 2027. ASIC's 2026–27 projects, including the review of suspicious trading controls at institutional brokers, run until the end of the financial year.
    • Australia, through 2027. With CPS 510 expected to start on 1 January 2028, banks and insurers will likely spend much of 2027 building their conflicts registers and controls.

     

    Seeing the Full Picture of Employee Conduct

    The above cases showed pieces of a larger puzzle. The Australian adviser took undisclosed payments, misstated them in client documents and was found not to satisfy fit and proper requirements. The Hong Kong representative steered a fund's lending towards a company he controlled. The SFC’s lifetime ban of an asset manager for unapproved trades, same-day dealing alongside client funds, and broken holding periods revealed the information existed in the firm's records.

    Much like a jigsaw puzzle, looking at a few pieces in isolation may provide hints. For example, access to MNPI, a personal trade and a message on an unmonitored channel may each seem minor. However, putting the pieces of employee conduct together reveals the full picture.

    MCO (MyComplianceOffice) gives financial firms a complete compliance solution that brings the puzzle pieces together. When licensing records, outside interests, MNPI access, trading activity and communications sit side by side, compliance teams can identify patterns that a single view of each activity may miss.



    Putting the Pieces Together in Your Financial Compliance Programme

    With so many updates landing in different markets, it helps to step back and ask a few practical questions about your own programme before the next examination comes around.

    • Can you see all the pieces for each employee? Licensing and registrations, outside business activities, personal trading, access to MNPI and communications often sit in separate systems, or in spreadsheets. When they are kept apart, a red flag in one area can easily go unnoticed in another.
    • Are policies followed day to day? The Hong Kong asset manager and the Singapore trust company both showed a gap between what their policies required and what staff were actually doing.
    • Could you produce the full record quickly? If an examiner asked for every disclosure, conflict and personal trade linked to one employee, how long would it take to pull together, and would it hold up to scrutiny?


    How firms operationalise regulatory expectations will be a key decider of their risk profile in 2027 and beyond. A puzzle is only finished when every piece is in place. In compliance, that means having one complete record of who disclosed what, who traded when, and what the firm did about employee conflicts of interest in between.

    MCO’s complete compliance solution brings everything together in one place, with a full audit trail behind every decision.

    MCO's Know Your Employee (KYE) suite helps firms:

    • track licensing and registrations to support fit and proper assessments
    • pre-clear personal trades, apply holding periods and restricted lists, and reconcile broker data
    • capture outside business activities and close personal relationships, and manage the conflicts they create
    • manage insider lists and access to MNPI
    • monitor electronic communications across channels for conduct risk.

    With all of these controls working together, compliance teams can see the whole picture of each employee's conduct and act on red flags early.

     

    Consider your firm’s need for a comprehensive, automated compliance solution with full audit trails to build a more responsive, risk-informed compliance framework across all aspects of employee conduct and conflict-of-interest management.

    To find out how the pieces fit, learn more about MCO's compliance solutions.

     

    References

    Regulatory Sources and Enforcement Actions

    1. ASIC, 26-073MR ASIC bans former financial adviser for 10 years and suspends Group's AFS licence (10 April 2026)
    2. MAS, MAS imposes $300,000 composition penalty for AML/CFT breaches  (25 May 2026)
    3. SFC, SFC sanctions firm and its former responsible officer over staff trading activities  (9 April 2026)
    4. SFC, SFC life ban and fines of $17.43 million for misconduct  (24 March 2026)
    5. HKMA and Insurance Authority, Joint circular on cross-sector reference checking arrangement between the banking and insurance sectors (13 May 2026)
    6. BNM, Joint Enforcement Action against Investment Bank  (14 August 2026)
    7. CSRC, 2025 enforcement overview (in Chinese) (17 April 2026)
    8. PBOC, China's Macroprudential Management System: Development Practice and Future Evolution, keynote speech by Governor Pan Gongsheng at the Annual Conference of Financial Street Forum 2025 (27 October 2025)

    MCO Resources

    FAQs

    Here’s your opportunity to clarify your clients’ questions.

    Regulators across the region want firms to show that their ethics and conduct controls work in practice. Through 2027, APRA's governance reforms, MAS's board proposals and Hong Kong's reference checking review are likely to keep that focus firmly in place.

    Most firms start with clear policies on personal trading, outside business activities, gifts and conflicts of interest, supported by regular attestations and training. The harder part is checking that staff actually follow those policies. In practice, that usually means pre-clearing trades, monitoring communications and keeping records that can be handed to a regulator when asked.

    Compliance teams generally look for software that brings employee disclosures, personal trading, licensing records and communications monitoring into one system. MCO's Know Your Employee suite is built for this, giving firms a single record of each employee's conduct with a full audit trail.

    Useful tools include personal trade pre-clearance, registers for outside business activities and gifts, insider list management and communications surveillance. MCO (MyComplianceOffice) combines these in one platform, so a conflict flagged in one area can be checked against everything else the firm knows about that employee.