The Hong Kong Monetary Authority (HKMA) issued the latest “Practice Guide on Cloud Adoption” (Practice Guide) on January 8th, 2026, setting out enhanced guidance to support Authorized Institutions (AIs) in adopting cloud technology securely and responsibly under the "Fintech 2030" strategy.
The latest HKMA Practice Guide illustrates supervisory principles and best practices to help AIs safely scale cloud use across hybrid/multi-cloud environments, as cloud initiatives now account for about 80% of reportable technology projects among banks in Hong Kong (including one-third to one-half involving critical systems).
The Practice Guide expands the number of cloud-related domains covered from four to eight, including governance, security, and resilience, to help AIs manage risks, strengthen operational resilience, and facilitate digital transformation. It also translates existing requirements from relevant Supervisory Policy Manual (SPM) modules into actionable, lifecycle-based guidance proportionate to workload criticality. The “dual-layered" approach binds high-level principles plus optional good practices drawn from HKMA supervision and global benchmarks, superseding the 2022 cloud circular.
Learn how Thales helps AIs comply with the Practice Guide across five domains.
Thales’ solutions can help Authorized Institutions (AIs) in Hong Kong to address the Practice Guide across five domains by simplifying compliance and automating security with visibility and control, reducing the burden on security and compliance teams.
HKMA Compliance Solutions
Protect applications and APIs at scale in the cloud, on-premises, or in a hybrid model. Our market leading product suite includes Web Application Firewall (WAF), protection against Distributed Denial of Service (DDoS) and malicious BOT attacks, security for APIs, and a secure Content Delivery Network (CDN).
Discover and classify sensitive data across hybrid IT and automatically protect it anywhere, whether at rest, in motion, or in use, using encryption tokenization and key management. Thales solutions also identify, evaluate, and prioritize potential risks for accurate risk assessment as well as identify anomalous behavior, and monitor activity to verify compliance, allowing organizations to prioritize where to spend their efforts.
Provide seamless, secure and trusted access to applications and digital services for customers, employees and partners. Our solutions limit the access of internal and external users based on their roles and context with granular access policies and Multi-Factor Authentication that help ensure that the right user is granted access to the right resource at the right time.
Application Security
Cloud Web Application Firewall
Data Security
Enterprise & Cloud Key Management
Application Security
Cloud Web Application Firewall
Data Security
Data Discovery & Classification
Identity & Access Management
Application Security
Data Security
Identity & Access Management