Directors & boards
Whether the board has approved what it needs to approve, whether the company can evidence it, and where personal exposure sits.
What you are likely asking
- What must the board formally approve this year?
- If a regulator asks, what can we produce?
- Where does personal liability start and stop?
- Is the cyber and AI risk on the risk register yet?
You approve the budget and carry the responsibility.
Written for you
Hong Kong regulatory
Pillar Two in Hong Kong: which groups must file, and when
AI governance
What the agent sandbox escape means for your AI governance
AI governance
Does Hong Kong have an AI law? What actually applies in 2026
Hong Kong regulatory
HKEX climate disclosure: the 2026 phase-in has started
AI governance
What the PCPD AI framework asks you to do, in practice
ISO standards
What affects the cost of ISO 27001 readiness in Hong Kong
AI governance
The PCPD's guidance on agentic AI: what it asks you to control
Hong Kong regulatory
Cap. 653: what the code of practice asks designated operators to evidence
Hong Kong regulatory
Hong Kong data breach notifications rose 21% in 2025 — and the exposure is usually a supplier
Hong Kong regulatory
Cap. 653 is in force: are you a critical infrastructure operator?
Hong Kong regulatory
Re-domiciling a company to Hong Kong: what the new regime involves
Not sure which applies to you?
Tell us what triggered this and we will tell you whether we are the right firm.