Why AI Governance Matters Right Now

As traditional cybersecurity defenses prove insufficient against Generative AI and Large Language Models (LLMs), risks surrounding algorithm transparency, Shadow AI, and third-party vendor dependencies are growing exponentially. Relying solely on information security (ISO 27001) is no longer enough to address key stakeholder concerns regarding digital trust and automated decision-making.

Key Hong Kong Regulatory Highlights
Key Hong Kong Regulatory Highlights:
PDPO Section 48B & DPP3:

Strict prohibitions against using customer channel data or interaction logs to fine-tune/train AI models without explicit, informed consent.

HKMA & SFC Directives:

Clear expectations for financial institutions to establish Board Accountability and concrete implementation timelines for AI governance.

Upcoming Local Legislation:

The Hong Kong SAR Government is actively preparing a dedicated statutory framework for AI data governance.

Key Takeaways

Key Takeaways

By watching this 54-minute recording, you will gain actionable insights on:
Shifting from Internal Security to External Trust:

Transitioning from traditional cybersecurity controls to a holistic Digital Trust strategy built across five core pillars: Security, Privacy, Transparency, Resilience, and Accountability.

Eliminating Compliance Silos:

Leveraging ISO's Harmonized Structure to integrate ISO 42001 (AIMS) into existing ISO 27001 (ISMS) and ISO 27701 (PIMS) management systems to prevent duplicate audits and optimize resource allocation.

Navigating Global Regulations:

Aligning internal processes with the EU AI Act, NIST AI RMF, Cyber Resilience Act (CRA), and DORA requirements for algorithm explainability and Human Oversight.

AI Risk Classification in Practice:

Applying the 4-level AI risk hierarchy (Unacceptable, High, Limited, Minimal) to manage AI asset inventories, responsibility mapping, and model output validation.

Ingo Unger DQS-Business Development Manager
Loading...
Featured Speakers

Ingo Unger

Head of Business Development Information Security & Cybersecurity, DQS Headquarters

Brings extensive global experience advising enterprise clients—including Porsche, Bosch, and Continental—on cybersecurity frameworks, ISO 27001, ISO 42001, TISAX, and the EU Cyber Resilience Act.

Recording Timestamps UI

Recording Timestamps

00:00 - 05:20

Opening & DQS Global Overview

Introduction to DQS and global certification capabilities.

05:21 - 06:18

Hong Kong Regulatory Updates

Key focus on PDPO compliance, HKMA/SFC mandates, and upcoming AI data legislation.

06:19 - 14:15

Defining Digital Trust

Exploring the 5 essential pillars (Security, Privacy, Transparency, Resilience, Accountability).

14:16 - 20:30

Global AI Regulatory Landscape

Impact of the EU AI Act, NIST, CRA, and DORA on enterprise AI deployment.

20:31 - 32:40

Integrating ISO Standards

How ISO 27001 (Security), ISO 27701 (Privacy), and ISO 42001 (AI Governance) work together.

32:41 - 44:10

Risk Classification & Human Oversight

Mitigating bias/hallucination risks and managing third-party AI vendors.

44:11 - 50:10

7-Step Implementation Roadmap

Practical steps from defining scope to internal audits.

50:11 - 53:58

Q&A & Local Support

Closing remarks and contact details for DQS Hong Kong.

 

 

 

Frequently Asked Questions (FAQ)

We already have ISO 27001 in place. Will adopting ISO 42001 add significant operational overhead?

No. ISO 42001 uses ISO’s Harmonized Structure, allowing seamless integration into your existing ISO 27001 ISMS. As Ingo demonstrates in the webinar, risk assessment models, vendor management processes, and internal audit mechanisms can be shared across frameworks to avoid redundancy.

 

Does ISO 42001 apply to our company if we do not develop AI models in-house but use third-party SaaS tools like ChatGPT?

Yes. ISO 42001 is designed for AI Developers, Providers, and Users. If your organization utilizes third-party AI tools in day-to-day operations, you still need to address Shadow AI, data leakage risks, vendor risk assessments, and output validation mechanisms. 

 

What is the primary difference between ISO 42001, ISO 27001, and ISO 27701?

ISO 27001 focuses on Information Security (CIA triad); ISO 27701 addresses Personal Information Management (PIMS); and ISO 42001 focuses specifically on AI-related risks, including algorithmic bias, model transparency, explainability, hallucination management, and human oversight. Together, they form a complete Digital Trust ecosystem. 

 

How does ISO 42001 certification help Hong Kong companies meet global regulations like the EU AI Act?

The controls within ISO 42001 closely mirror the requirements of the EU AI Act, NIST AI RMF, and other major frameworks. Achieving ISO 42001 certification demonstrates that your enterprise has established structured AI governance, helping you satisfy cross-border compliance demands and third-party vendor audits. 

 

What are the legal restrictions under Hong Kong’s PDPO when using customer data to fine-tune AI models?

Under the Hong Kong PDPO (specifically Section 48B and DPP3), organizations cannot use customer personal data or interaction logs to train or fine-tune AI models without obtaining explicit and voluntary consent from the data subjects. The webinar details practical steps to maintain compliance while leveraging AI. 

 

What are the key steps in the implementation roadmap for ISO 42001 certification?

The standard implementation process follows 7 steps: Defining Management System Scope, Conducting Risk Assessments, Establishing AI Policies, Implementing Control Measures, Performing Internal Audits, Conducting Management Reviews, and Undergoing Independent Third-Party Certification by DQS.