Seeding Your Advantage in 2026 AI Governance
Why AI Governance Matters Right Now
As traditional cybersecurity defenses prove insufficient against Generative AI and Large Language Models (LLMs), risks surrounding algorithm transparency, Shadow AI, and third-party vendor dependencies are growing exponentially. Relying solely on information security (ISO 27001) is no longer enough to address key stakeholder concerns regarding digital trust and automated decision-making.
Strict prohibitions against using customer channel data or interaction logs to fine-tune/train AI models without explicit, informed consent.
Clear expectations for financial institutions to establish Board Accountability and concrete implementation timelines for AI governance.
The Hong Kong SAR Government is actively preparing a dedicated statutory framework for AI data governance.
Key Takeaways
Transitioning from traditional cybersecurity controls to a holistic Digital Trust strategy built across five core pillars: Security, Privacy, Transparency, Resilience, and Accountability.
Leveraging ISO's Harmonized Structure to integrate ISO 42001 (AIMS) into existing ISO 27001 (ISMS) and ISO 27701 (PIMS) management systems to prevent duplicate audits and optimize resource allocation.
Aligning internal processes with the EU AI Act, NIST AI RMF, Cyber Resilience Act (CRA), and DORA requirements for algorithm explainability and Human Oversight.
Applying the 4-level AI risk hierarchy (Unacceptable, High, Limited, Minimal) to manage AI asset inventories, responsibility mapping, and model output validation.
Ingo Unger
Head of Business Development Information Security & Cybersecurity, DQS Headquarters
Brings extensive global experience advising enterprise clients—including Porsche, Bosch, and Continental—on cybersecurity frameworks, ISO 27001, ISO 42001, TISAX, and the EU Cyber Resilience Act.
Recording Timestamps
Opening & DQS Global Overview
Introduction to DQS and global certification capabilities.
Hong Kong Regulatory Updates
Key focus on PDPO compliance, HKMA/SFC mandates, and upcoming AI data legislation.
Defining Digital Trust
Exploring the 5 essential pillars (Security, Privacy, Transparency, Resilience, Accountability).
Global AI Regulatory Landscape
Impact of the EU AI Act, NIST, CRA, and DORA on enterprise AI deployment.
Integrating ISO Standards
How ISO 27001 (Security), ISO 27701 (Privacy), and ISO 42001 (AI Governance) work together.
Risk Classification & Human Oversight
Mitigating bias/hallucination risks and managing third-party AI vendors.
7-Step Implementation Roadmap
Practical steps from defining scope to internal audits.
Q&A & Local Support
Closing remarks and contact details for DQS Hong Kong.