ISO Certification Consultancy
Gap analysis, documentation, training, internal audit and audit support — through to the certification audit and beyond.
Read more →Safe Harbour (Hong Kong) Consultants Limited is a Hong Kong consultancy for AI governance, ISO certification and IT audit. We make sure your information security management reaches the international standard, and we support you from documentation through to the certification audit. The audit is conducted and the certificate issued by an independent accredited certification body.
Client names and logos are published only with written consent.
Tenders list it as a requirement. Client due-diligence questionnaires ask for it. Bank and group partners expect it. It is not a nice-to-have — it is the gate that decides whether you reach the procurement shortlist.
If your organisation is not recommended for certification at the first certification audit, we refund our consultancy fee in full.
Conditions: the agreed corrective actions are completed, the required records and evidence are provided, and the audit is conducted by an accredited certification body within three months of our readiness sign-off. The commitment covers our consultancy fee only, not the certification body's fees.
Certification, audit and assurance services for organisations of every size in Hong Kong and Macau.
Gap analysis, documentation, training, internal audit and audit support — through to the certification audit and beyond.
Read more →IT general and application control review that stands up to your external auditor.
Read more →Independent internal audit and management review, with findings closed before the certification body arrives.
Read more →Manual penetration testing, red teaming, cloud configuration review and application security testing.
Read more →An AI inventory, risk and impact assessment, and a management system aligned to ISO/IEC 42001.
Read more →Internal auditor training, ISO awareness workshops and management briefings, in Cantonese, English or Putonghua.
Read more →Five stages. A named deliverable at each one, so you always know what you have and what comes next.
We review your operation and documentation against the standard and record the gaps.
We establish the framework, procedures and records the standard requires.
Awareness training and hands-on support so the system works day to day.
Internal audit and management review, with findings closed before the auditor arrives.
An accredited certification body audits and issues the certificate. We support you throughout.
Tell us which standard you are being asked for, and we will quote for it.
Requirements typically arrive from two directions at once — a client procurement questionnaire and board-level oversight. Organisations that respond promptly tend to have five things already documented.
How we work
Preparedness buys composure.
We publish our consultants' credentials, our method, and the source and date behind every regulatory position we take.
Every engagement is led by a qualified consultant whose name, role and experience are published.
Five stages, and a named deliverable at each one.
In Hong Kong, PCPD AI guidance is voluntary, while Cap. 653 has been mandatory since 1 January 2026. Every statement carries its date and source.
We are a readiness and advisory partner. We do not certify and we take no fee linked to a certification outcome.
Hong Kong and Macau regulatory updates, standard explainers and practical guides.
Hong Kong regulatory
AI governance
AI governance
Hong Kong regulatory
ISO certification confirms that your management system meets an internationally recognised standard. In Hong Kong it is most often required for tendering, client due diligence, licence conditions or supply chain approval.
Typically three to six months for a prepared organisation with one site, and six to twelve months where documentation or remediation needs significant work.
The certification fee is charged by the accredited certification body that audits you and issues the certificate. Our consultancy fee covers gap analysis, documentation, training, internal audit and audit support.
Yes. The standards apply to organisations of all sizes and the management system can be scaled to your operation. We will tell you honestly if a particular standard is not worth the cost for you.
A consultant helps you build and implement the management system. A certification body audits it independently and issues the certificate. The certification decision belongs to the certification body, and you are free to choose which one.
IT general controls cover access, program changes, program development and computer operations. External auditors rely on them to decide how much they can trust the systems producing your financial information.
One short email when a regulator moves, a standard changes or a deadline shifts — Hong Kong and Macau only.
Tell us which standard or service you need. If you are not sure, tell us what the client or regulator is asking for and we will work it out.