Insights
Hong Kong and Macau regulatory updates, standard explainers and practical guides — written for the questions our clients actually ask.
Or read for your role
Directors & boardsSmall and medium businessesListed companiesTrustees, family offices & corporate servicesCompliance & riskIT & information security
Hong Kong regulatory
Pillar Two in Hong Kong: which groups must file, and when
AI governance
What the agent sandbox escape means for your AI governance
AI governance
Does Hong Kong have an AI law? What actually applies in 2026
Hong Kong regulatory
HKEX climate disclosure: the 2026 phase-in has started
AI governance
What the PCPD AI framework asks you to do, in practice
IT audit
ITGC explained for finance teams who have just been asked for evidence
ISO standards
What affects the cost of ISO 27001 readiness in Hong Kong
Macau
Macau's personal data law: what it means for your operations
ISO standards
ISO/IEC 27701:2025 and the 2028 transition deadline
AI governance
The PCPD's guidance on agentic AI: what it asks you to control
AI governance
ISO 42001 or ISO 27001 — which comes first?
AI governance
A practical AI use inventory: what to record and why
Hong Kong regulatory
SFC sets a July 2027 deadline for phishing-resistant authentication
Hong Kong regulatory
Cap. 653: what the code of practice asks designated operators to evidence
Hong Kong regulatory
Hong Kong data breach notifications rose 21% in 2025 — and the exposure is usually a supplier
Hong Kong regulatory
Cap. 653 is in force: are you a critical infrastructure operator?
Hong Kong regulatory
Re-domiciling a company to Hong Kong: what the new regime involves
Regulatory updates, when something actually changes
A short email when a circular is issued or a deadline moves.