SFC Type 9 licence: the IT & cybersecurity checklist for 2026
If your firm is applying for — or already holds — an SFC Type 9 licence to conduct asset management in Hong Kong, technology is no longer a back-office detail. The Securities and Futures Commission expects licensed corporations to run their IT and cybersecurity to a defined standard, and to be able to show it, both at the point of licensing and on an ongoing basis. This guide sets out, in plain terms, what that means in practice.
Why IT and cybersecurity sit at the centre of a Type 9 application
A Type 9 firm holds client mandates, moves instructions, and stores sensitive market and investor data. That makes it an attractive target and a regulated custodian of information at the same time. The SFC's fitness-and-properness assessment looks beyond the qualifications of the Responsible Officers to whether the firm has the systems and controls to operate soundly. Weak IT governance is a credible reason for questions during licensing — and a recurring theme in the regulator's thematic reviews of firms already in operation.
The checklist: eleven areas to have covered
The following maps to the control areas the SFC examines. Treat it as a readiness list — for each item, the question is not only "do we do this?" but "can we produce evidence?"
- Asset inventory. A current, complete list of every device, server and system in use — not a stale spreadsheet.
- End-of-life software. No unsupported operating systems or applications (a specific finding in the SFC's review). A tracked upgrade path before support ends.
- Patch management. Security updates applied promptly, verified, and evidenced — a defined SLA rather than "when someone gets to it".
- Access control and MFA. Multi-factor authentication enforced on email, remote access and all administrator accounts, with least-privilege access and periodic reviews.
- Remote access. Secure connectivity (VPN with session controls and IP allow-listing), not open RDP or unmanaged tools.
- Email security. SPF, DKIM and an enforced DMARC policy to stop your domain being spoofed — plus phishing-awareness training.
- Cloud (Microsoft 365) hardening. Conditional access, least-privilege admin, data-loss prevention and a backup of your tenant (Microsoft does not do this for you).
- Data protection and backup. Encrypted, tested backups with a documented, rehearsed recovery plan.
- Third-party / vendor risk. Due diligence and cybersecurity SLAs on your IT providers — with records you can show the regulator.
- Incident response. A written incident-response plan, named contacts, reporting thresholds, and at least an annual drill.
- Governance and oversight. Core IT policies, documentation, and senior-management visibility — reviewed, not written once and filed.
What "evidence" looks like
The single biggest gap we see in small firms is not the absence of controls but the absence of proof. A backup that has never been test-restored, MFA that is "mostly" on, a vendor with no signed SLA — each becomes a finding the moment someone asks. The firms that clear licensing and inspections smoothly are the ones that can hand over an asset inventory, a patch report, a restore test, a vendor due-diligence pack and an incident-response plan without a scramble.
How this connects to fundraising
The same evidence the SFC expects is what institutional allocators request during operational due diligence (ODD) before committing capital. Getting your IT house in order for the licence is therefore not a cost centre — it is preparation for your next raise. We cover that overlap in our guide to the IT questions allocators actually ask.