In May 2026, the Office of the Privacy Commissioner for Personal Data completed compliance checks on 60 Hong Kong organisations and found no contravention of the Personal Data (Privacy) Ordinance. That sounds like a clean bill of health. It is not. The same exercise found that 95% of those organisations already use AI daily, and roughly half are running three or more AI systems at once. Regulators are no longer asking whether you use AI. Buyers are no longer asking either. They are asking who audits it.
That question now has a formal answer, and it is turning up in procurement documents: ISO/IEC 42001.
What is ISO 42001?
ISO/IEC 42001 is the first international standard for an artificial intelligence management system, published in December 2023. It sets auditable requirements for how an organisation develops, supplies and uses AI, covering risk assessment, data governance, human oversight and continual improvement. Certification is granted by an accredited third-party body and lasts three years.
The word doing the work in that definition is management system. ISO 42001 does not certify a model. It does not score accuracy, benchmark a large language model, or approve a specific vendor product.
It certifies the organisational machinery around AI: who decides which systems get deployed, what evidence is kept, how outputs are reviewed, and what happens when something goes wrong.
According to ISO's own explanatory guidance, the standard is designed for any entity providing or using AI-based products and services, not only AI developers. That distinction matters for Hong Kong enterprises, most of which buy AI rather than build it.
Why is ISO 42001 appearing in enterprise RFPs in 2026?
ISO 42001 is entering RFPs because buyers need a portable way to verify AI trustworthiness without auditing every vendor themselves. Banks and asset managers have begun writing the standard directly into procurement language, alongside established security controls. The pattern mirrors what happened with SOC 2 a decade ago: an optional differentiator first, a contractual requirement soon after.
According to a FinTech Global analysis published on 18 August 2026, ISO 42001 is becoming the new baseline for AI vendor trust, with financial institutions embedding the criterion into RFP language rather than treating it as a nice-to-have.
Three forces are pushing this along at the same time.
--- Regulatory convergence. The EU AI Act sets a global reference point, and the NIST AI Risk Management Framework shapes US expectations. Neither is a certification, so procurement teams reach for one that is.
--- Vendor sprawl. If half your peers run three or more AI systems, your procurement team cannot audit each supplier individually. A recognised certificate compresses that work.
--- Board-level accountability. Directors are being asked to attest to AI oversight. A third-party audit is far easier to present than an internal policy document.
Early certificate holders include AWS, Microsoft and Anthropic. AWS announced in November 2024 that it had become the first major cloud provider to earn accredited ISO 42001 certification. When the platforms underneath your stack are certified, the question travels down the supply chain to you.
How does ISO 42001 differ from ISO 27001 and SOC 2?
ISO 27001 and SOC 2 certify information security: whether data is protected, access is controlled and incidents are handled. ISO 42001 certifies AI decision-making: whether the organisation knows what its AI systems do, who is accountable for outputs, how bias and drift are monitored, and how humans remain in the loop. Holding one does not deliver the other.
This is the single most common misunderstanding among Hong Kong enterprises that already hold ISO 27001.
A firm can encrypt every byte of customer data correctly and still deploy a credit-scoring model nobody can explain to a regulator. ISO 27001 has nothing to say about that. ISO 42001 does.
The practical relationship is layered rather than competitive. ISO 42001 uses the same Annex SL management-system structure as ISO 27001, so an organisation with a mature ISMS is starting from perhaps 40% of the required scaffolding rather than zero. The gap sits in AI-specific controls: impact assessment, data lineage for training and prompting, output review and lifecycle monitoring.
What does the PCPD's 2026 compliance check tell Hong Kong enterprises?
The PCPD's 2026 round, published on 19 May 2026, examined 60 organisations and found that 57 use AI in daily operations, 45 have done so for more than a year, and 29 run three or more AI systems. No PDPO contravention was identified. The finding to act on is not the clean result. It is the density of AI already embedded in Hong Kong operations.
Read those numbers as a procurement signal rather than a compliance verdict.
If 51% of the organisations examined operate three or more AI systems, the average Hong Kong enterprise is already managing a portfolio, not a pilot. Portfolios require governance structures. Pilots do not.
The PCPD has published supporting material for exactly this transition, including the Artificial Intelligence: Model Personal Data Protection Framework in 2024 and a checklist on employee use of generative AI in 2025. Neither is certifiable. Both map cleanly onto ISO 42001 clauses, which means work done for one is rarely wasted on the other.
For a fuller treatment of how PCPD expectations translate into day-to-day policy, see our earlier piece on AI governance for Hong Kong businesses.
What does ISO 42001 certification actually require?
Certification requires a documented AI management system, an AI system inventory, risk and impact assessments for each system, defined human oversight, supplier controls, internal audit, management review, and then a two-stage external audit by an accredited body. The certificate runs three years with surveillance audits in between. Most of the effort is evidence collection, not technology.
A realistic sequence for a 200 to 500-person Hong Kong enterprise looks like this.
--- Scope definition. Decide which business units and which AI systems sit inside the certificate. Narrow scope certifies faster and costs less, but a scope that excludes your customer-facing AI will not satisfy a buyer's RFP.
--- AI inventory. List every AI system in use, including the ones procurement never approved. This step routinely surfaces twice as many tools as leadership expected.
--- Impact assessment. For each system, document who it affects, what data it touches, and what a wrong output costs.
--- Control implementation. Human oversight points, output review, escalation paths, supplier due diligence.
--- Internal audit and management review. Evidence that the system operates, not merely that it was written down.
--- Stage 1 and Stage 2 external audit. Documentation review, then operational verification.
Budget and timeline vary widely with scope and existing ISO maturity, so treat any single published figure with suspicion. The reliable planning assumption is that the internal effort dominates the audit fee, and that evidence gathering is the long pole.
Should you certify, or only require it from vendors?
Certify when you sell AI-enabled services, operate in a regulated sector, or face RFPs that ask for it. Require it from vendors when you consume AI rather than supply it, and your exposure sits in third-party systems. Most Hong Kong mid-market enterprises land in the second category first, and move into the first only when a major client asks.
A four-question test resolves this quickly.
--- Does anyone ask? If ISO 42001 has appeared in a live RFP or a client due-diligence questionnaire, the business case is already written for you.
--- Do you supply or consume? Suppliers of AI-enabled services carry the certification burden. Consumers push it to their vendors.
--- What is the regulatory floor? Financial services, healthcare and anything touching credit or employment decisions face the shortest runway.
--- What is already in place? An organisation with ISO 27001 and a functioning risk committee is closer than one starting from a blank page.
If the answer is that you should be requiring it rather than holding it, the practical next step is to fold the question into vendor scoring. Our four-question framework for evaluating enterprise AI vendors covers how to weight it without disqualifying strong suppliers who are mid-implementation.
How does this play out in a Hong Kong financial services firm?
A 300-person Hong Kong asset manager receives a client due-diligence questionnaire asking whether its AI systems are certified. It holds ISO 27001. It has no AI inventory. Three business units have separately deployed generative AI tools. The gap is not technical capability. It is the absence of a single accountable owner and a documented record of what each system does.
The realistic path for that firm runs in three moves.
First, an inventory. Every AI system, every business owner, every data source. This is usually a two to four week exercise and it is uncomfortable, because it makes shadow deployments visible.
Second, a scoping decision. Certifying the whole organisation is slower than certifying the client-facing investment research and reporting functions that the questionnaire actually concerns.
Third, a gap assessment against ISO 42001 clauses, reusing ISO 27001 evidence wherever the control is shared. Governance, competence, documentation and internal audit largely transfer. Impact assessment and AI lifecycle monitoring do not.
The firm answers the questionnaire honestly in the meantime: implementation underway, target date stated. In 2026, a credible plan with a date still scores. In 2027, it increasingly will not.
What goes wrong when organisations attempt this without guidance?
The three recurring failures are scoping the certificate too broadly, treating it as a documentation exercise rather than an operating change, and starting the audit before the AI inventory is complete. Each one converts a six-month programme into an eighteen-month one, and each is visible early enough to avoid.
--- Over-scoping. Leadership asks for organisation-wide certification because it sounds stronger. The audit then depends on the least mature business unit.
--- Paper compliance. Policies are written, nobody operates them, and the Stage 2 audit finds no evidence of management review or internal audit actually happening.
--- Incomplete inventory. A tool discovered during the audit is a finding. The same tool discovered three months earlier is a task.
--- No owner. AI governance assigned to a committee with no named accountable executive stalls at the first contested decision.
--- Ignoring suppliers. Your certificate covers your management of third-party AI. If you cannot evidence supplier due diligence, the scope collapses.
The strategic takeaway
ISO 42001 is not a technology decision. It is the moment AI governance stops being a policy document and becomes an audited business capability that buyers can verify without trusting you.
For most Hong Kong enterprises the correct first move is not to book an auditor. It is to build the AI inventory, name an accountable owner, and decide whether the standard is something you will hold or something you will demand. That decision is cheap to make now and expensive to postpone.
Twenty-eight years of Hong Kong enterprise technology cycles teach one consistent lesson: the standards that feel optional in year one become the price of entry by year three. We understand AI. We understand you. With UD by your side, AI never feels cold.
Reviewed by the UD enterprise AI team.
Where to start
Now that you have the framework, the next step is establishing where your organisation actually stands. We'll walk you through every step, from AI readiness assessment and system inventory to governance design, vendor scoring and audit preparation, backed by 28 years of Hong Kong enterprise experience.