Governance & Integrity
The standards that make HKISG programmes repeatable, reviewable, and completely accountable.
Our Governance Model
To ensure impartial decision-making, HKISG is structured as a membership-funded professional body with clear segregation of duties:
- The Executive Board: Oversees strategic direction, financial stewardship, and legal compliance. They have no operational say in rating outcomes.
- The Programme Council: Maintains and updates the assessment methodology, manages the review queue, and ensures testing standards for Trust Reviews and IT Awards.
- The Editorial Council: Governs all public-facing content including security bulletins, directory listings, and the handling of factual corrections.
Independence & Objectivity
Our core promise is that trust cannot be purchased. We enforce this through strict rules:
- Membership fees, review fees, and event sponsorships fund our operating capacity only. They do not determine, guarantee, or influence any assessment outcomes.
- Assessors must declare all potential conflicts of interest (past employment, financial stakes, vendor relationships) before accepting an assignment.
- Any conflicted assessor is strictly recused from scoring, panel deliberation, and publication approval.
- Published rating pages clearly state their scope, the exact date of review, the expiry date, and any material limitations of the audit.
Public Accountability
Transparency is not just a marketing term; it is our operational reality. Every year, HKISG commits to publishing:
- An Annual Programme Report: Detailing aggregate rating trends, major security challenges identified in Hong Kong, and financial stewardship summaries.
- A Methodology Change Log: Documenting how and why our scoring rubrics evolve over time to meet new threats.
- A Public Register: A searchable, timestamped index of all active Trust Reviews to prevent vendors from selectively quoting expired scores.
- A Corrections Log: For substantive errors in publications or ratings, maintaining a clear trail of what was fixed and when.
Complaints and Appeals Process
We recognize that complex IT environments can be misunderstood. If an organisation disputes an assessment outcome:
- They may request factual corrections or formally appeal a rating process within 30 calendar days of receiving the private draft report.
- Appeals must be submitted in writing, detailing the specific methodology clauses allegedly misapplied, along with supporting evidence.
- A secondary review panel—comprising senior assessors who did not participate in the original assessment—will evaluate the appeal.
- The secondary panel's decision is final and will be published if the rating goes live.
Frequently asked questions
- How long do appeals take?
- Appeals must be submitted within 30 calendar days of receiving the private draft report. Secondary panel review typically completes within 20 business days, depending on evidence complexity. Outcomes are documented if the rating goes public.
- Can sponsors influence ratings?
- No. Sponsorships fund programme capacity only. Sponsors are disclosed; conflicted assessors recuse. See Policies & Standards and the independence rules on this page.
- Where are corrections published?
- Substantive corrections to ratings or publications appear in the public corrections log referenced in our annual programme report. Factual fixes do not silently upgrade scores — they create dated revision notes.