Compliance & risk
New circulars, supervisory expectations, deadlines, and how to turn a regulator's wording into a control the business will actually follow.
What you are likely asking
- Is this guidance or a requirement?
- What is the deadline, and what evidence is expected?
- How do we map one control set across PDPO, HKMA and ISO?
You are the one who has to read the circular.
Written for you
Hong Kong regulatory
Pillar Two in Hong Kong: which groups must file, and when
AI governance
What the agent sandbox escape means for your AI governance
AI governance
Does Hong Kong have an AI law? What actually applies in 2026
AI governance
What the PCPD AI framework asks you to do, in practice
IT audit
ITGC explained for finance teams who have just been asked for evidence
Macau
Macau's personal data law: what it means for your operations
ISO standards
ISO/IEC 27701:2025 and the 2028 transition deadline
AI governance
The PCPD's guidance on agentic AI: what it asks you to control
AI governance
A practical AI use inventory: what to record and why
Hong Kong regulatory
SFC sets a July 2027 deadline for phishing-resistant authentication
Hong Kong regulatory
Cap. 653: what the code of practice asks designated operators to evidence
Hong Kong regulatory
Hong Kong data breach notifications rose 21% in 2025 — and the exposure is usually a supplier
Hong Kong regulatory
Cap. 653 is in force: are you a critical infrastructure operator?
Not sure which applies to you?
Tell us what triggered this and we will tell you whether we are the right firm.