Tel +852 5382 0328 info@safeharbour.hk WhatsApp 繁體中文
Safe Harbour Consultants · Hong Kong & Macau Get a Quote

A Hong Kong consultancy for AI governance, ISO certification and IT audit.

  • ISO 認證準備Certification
  • IT 審計與 ITGCIT audit
  • AI 治理與負責任 AIAI governance

Safe Harbour (Hong Kong) Consultants Limited is a Hong Kong consultancy for AI governance, ISO certification and IT audit. We make sure your information security management reaches the international standard, and we support you from documentation through to the certification audit. The audit is conducted and the certificate issued by an independent accredited certification body.

Standards and frameworks we work with
ISO/IEC 42001·ISO/IEC 27001·ISO/IEC 27701·ISO 22301·ISO 9001·ISO 14001·ISO 45001·ISO/IEC 20000-1·NIST AI RMF·EU AI Act

Client names and logos are published only with written consent.

Most requested standard

ISO/IEC 27001 is usually the precondition to a new client

Tenders list it as a requirement. Client due-diligence questionnaires ask for it. Bank and group partners expect it. It is not a nice-to-have — it is the gate that decides whether you reach the procurement shortlist.

  • Tender eligibilityMost enterprise buyers list it as a pass/fail condition before a demo is ever booked.
  • Shorter sales cycleA prepared evidence pack turns a two-week questionnaire into a one-day reply.
  • Partner due diligenceBanks and group partners expect it as part of third-party risk management.

Consultancy fee refund commitment

If your organisation is not recommended for certification at the first certification audit, we refund our consultancy fee in full.

Conditions: the agreed corrective actions are completed, the required records and evidence are provided, and the audit is conducted by an accredited certification body within three months of our readiness sign-off. The commitment covers our consultancy fee only, not the certification body's fees.

Our Services

All services →

Certification, audit and assurance services for organisations of every size in Hong Kong and Macau.

ISO Certification Consultancy

A tender requirement for ISO certification typically allows less preparation time than organisations expect.

Gap analysis, documentation, training, internal audit and audit support — through to the certification audit and beyond.

Read more →

IT Audit, ITGC & ITAC

ITGC evidence is frequently requested late in the audit cycle, when documentation is hardest to assemble.

IT general and application control review that stands up to your external auditor.

Read more →

Internal Audit

Non-conformities identified close to the certification audit leave limited time for corrective action.

Independent internal audit and management review, with findings closed before the certification body arrives.

Read more →

Penetration Testing

An automated scan and a penetration test report are different deliverables, and clients increasingly distinguish between them.

Manual penetration testing, red teaming, cloud configuration review and application security testing.

Read more →

AI Governance & Responsible AI

Requirements for AI governance typically arrive from two directions at once: client procurement and board oversight.

An AI inventory, risk and impact assessment, and a management system aligned to ISO/IEC 42001.

Read more →

Training

Whether staff can explain the management system to an auditor depends on how well they have been trained.

Internal auditor training, ISO awareness workshops and management briefings, in Cantonese, English or Putonghua.

Read more →
How we work

From gap analysis to certification audit

Five stages. A named deliverable at each one, so you always know what you have and what comes next.

  • 01

    Gap Analysis

    We review your operation and documentation against the standard and record the gaps.

  • 02

    Documentation

    We establish the framework, procedures and records the standard requires.

  • 03

    Implementation & Training

    Awareness training and hands-on support so the system works day to day.

  • 04

    Internal Audit

    Internal audit and management review, with findings closed before the auditor arrives.

  • 05

    Certification Audit

    An accredited certification body audits and issues the certificate. We support you throughout.

ISO Standards We Cover

All standards →

Tell us which standard you are being asked for, and we will quote for it.

ISO/IEC 27001
Information Security Management
Client due diligence questionnaires increasingly ask how third-party data is protected.
ISO/IEC 42001
AI Management System
AI governance requirements are increasingly appearing in commercial contracts.
ISO/IEC 27701
Privacy Information Management
Certificates issued against the 2019 edition expire on 31 October 2028.
ISO 22301
Business Continuity Management
Several regulators expect an independently reviewed business continuity position.
ISO/IEC 20000-1
IT Service Management
Service level commitments made in tenders are increasingly expected to be evidenced.
ISO 9001
Quality Management
The tender lists ISO 9001 as a mandatory qualification.
ISO 14001
Environmental Management
The main contractor wants environmental management evidence.
ISO 45001
Occupational Health & Safety
Site safety records carry increasing weight in tender assessment.
ISO 50001
Energy Management
Energy costs are rising, and procurement increasingly asks for verified consumption data.
AI governance

What AI governance evidence actually looks like

Requirements typically arrive from two directions at once — a client procurement questionnaire and board-level oversight. Organisations that respond promptly tend to have five things already documented.

Without documentation
Which AI do we use?Who owns it?Where did the data go?Is there a record?What did we do about the risky ones?
Documented and auditable
01AI inventory
02Risk and impact assessment
03Use policy and human review
04Audit records
05One-page board summary
0/ 5on file
Free AI governance self-assessment Talk to a consultant Ten questions. A gap list. No login.

How we work

Preparedness buys composure.

How we work

We publish our consultants' credentials, our method, and the source and date behind every regulatory position we take.

01

Named consultants, published credentials

Every engagement is led by a qualified consultant whose name, role and experience are published.

02

A published method

Five stages, and a named deliverable at each one.

03

Dated, sourced positions

In Hong Kong, PCPD AI guidance is voluntary, while Cap. 653 has been mandatory since 1 January 2026. Every statement carries its date and source.

04

A clear boundary

We are a readiness and advisory partner. We do not certify and we take no fee linked to a certification outcome.

Frequently Asked Questions

All questions →
1. What is ISO certification and how does it help a business?

ISO certification confirms that your management system meets an internationally recognised standard. In Hong Kong it is most often required for tendering, client due diligence, licence conditions or supply chain approval.

2. How long does the certification process take?

Typically three to six months for a prepared organisation with one site, and six to twelve months where documentation or remediation needs significant work.

3. What is the difference between the consultant fee and the certification fee?

The certification fee is charged by the accredited certification body that audits you and issues the certificate. Our consultancy fee covers gap analysis, documentation, training, internal audit and audit support.

4. Is ISO certification suitable for small and medium-sized companies?

Yes. The standards apply to organisations of all sizes and the management system can be scaled to your operation. We will tell you honestly if a particular standard is not worth the cost for you.

5. What is the difference between a consultant and a certification body?

A consultant helps you build and implement the management system. A certification body audits it independently and issues the certificate. The certification decision belongs to the certification body, and you are free to choose which one.

6. What is ITGC, and why is our auditor asking for it?

IT general controls cover access, program changes, program development and computer operations. External auditors rely on them to decide how much they can trust the systems producing your financial information.

The AI governance briefing

One short email when a regulator moves, a standard changes or a deadline shifts — Hong Kong and Macau only.

No more than one email a month. Unsubscribe in one click.

Request a quotation

Tell us which standard or service you need. If you are not sure, tell us what the client or regulator is asking for and we will work it out.

Tel:+852 5382 0328
Email:info@safeharbour.hk
WhatsApp:+852 5382 0328
Office hours:Monday to Friday, 9:00–18:00

We reply within one working day. Your details stay with our consultants.