AI Governance & Responsible AI
Hong Kong has no blanket AI statute. It has voluntary PCPD guidance, HKMA and SFC expectations, one mandatory ordinance for critical infrastructure, and contract clauses doing most of the work.
AI system inventory
Every system in use, who owns it, what data it touches, which decisions it influences.
Risk and impact assessment
Per system, with an impact view for individuals and an organisational risk view for the board.
Use policy and employee rules
Acceptable use, approved tools, data input rules, human review, incident reporting.
ISO/IEC 42001 readiness
Controls, evidence, internal audit and management review mapped to the standard.
AI red teaming
Prompt injection, data leakage, guardrail bypass and agentic tool misuse.
Board briefing
Two hours on risk appetite, the pack a board should receive, and the questions to ask.
Frequently asked
Is AI governance required in Hong Kong?
Not by a single statute. PCPD guidance is voluntary, HKMA and SFC expectations are supervisory, and Cap. 653 is mandatory for designated critical-infrastructure operators. In practice the trigger is a client questionnaire or a board deadline.
Do we need ISO/IEC 42001 certification?
Only if a client, a group or a regulator asks for it. Many organisations do the governance work without pursuing certification.
Consultancy fee refund commitment
If your organisation is not recommended for certification at the first certification audit, we refund our consultancy fee in full.
Conditions: the agreed corrective actions are completed, the required records and evidence are provided, and the audit is conducted by an accredited certification body within three months of our readiness sign-off. The commitment covers our consultancy fee only, not the certification body's fees.
Request a quotation
Tell us which standard or service you need. If you are not sure, tell us what the client or regulator is asking for and we will work it out.