Cross-border and control
Nine points to settle before signing a cross-border services contract
The clauses that cause trouble later are the ones that seemed obvious to both sides and were never written down — scope, change control, governing law, tax, IP, data, liability, exit and stamp duty.
Read the article →Getting ready for a PDPO data-handling review
A walk through Hong Kong's six Data Protection Principles from a review perspective: what to inventory, what to fix first, and which provisions carry penalties that people forget.
Read the article →Scoping a first internal audit in a mid-market group
Risk-based process selection, testing design and operation separately, writing findings with owners and dates, and making follow-up part of the scope from day one.
Read the article →Regulatory and technology outlook
Hong Kong’s evolving regulatory landscape: 2026 outlook
BEPS 2.0 Pillar Two top-up tax filings, the Significant Controllers Register, the stablecoin licensing regime and the PDPO obligations that show up every week — with a monitoring routine that takes an afternoon a quarter.
Read the article →AI adoption in APAC: navigating hype, risk and real value
Where AI actually pays, where the business case collapses, the five questions to settle before a pilot, and the data protection obligations to answer before launch rather than after.
Read the article →Third-party risk management in an interconnected economy
Tiering suppliers, the due diligence that earns its cost, the contract clauses that matter, and why the fourth party is usually the layer nobody can describe.
Read the article →What we write about
Our articles cover the questions clients actually raise with us: cross-border contracting and trade documentation, Hong Kong regulatory compliance including the Personal Data (Privacy) Ordinance, internal audit and control in mid-market groups, and the practical side of technology change. If there is a topic you would like us to cover, tell us.