ISO 31000 × COSO ERM Enterprise Risk Management Implementation — Listed Company Risk Governance
Can enterprise risk management be certified? No. ISO 31000 states it is not intended for certification, and COSO ERM is a framework. What listed companies need is a system the board understands and auditors can verify: a defined risk appetite, a sound assessment method and a steady rhythm of KRI monitoring. We apply ISO 31000 and COSO ERM 2017 to take you from a dynamic risk register to a KRI dashboard, addressing five disaster scenarios: fraud, ransomware extortion, supply chain disruption, reputational collapse and governance evaluation failure. Led by VP-level consultants with NTUST academic partnership, we help listed and manufacturing companies pass governance evaluations, customer due diligence and financing reviews.
ISO 42001 × EU AI Act AI Governance Certification Consulting — Three-Track Compliance
After amendment by Regulation (EU) 2026/1744, EU AI Act high-risk obligations moved to 2027-12-02 (Annex III) and 2028-08-02 (Annex I). The nearer deadline is 2026-12-02, when existing generative AI systems must apply machine-readable marking (Art. 111(4)); Art. 50 transparency duties already apply. We build certifiable ISO/IEC 42001 AI management systems aligned with Taiwan's AI Basic Act (in force 2026-01-14), addressing three disaster scenarios: algorithmic bias, EU AI Act fines (Art. 99: up to 7% of global annual turnover for prohibited practices, up to 3% for transparency and most other obligations), and liability for AI system failure. Led by VP-level consultants with NTUST academic partnership; 20+ clients, 99% passed on the first attempt.
ISO 56001 × TIPS Trade Secret Protection & Innovation Management Consulting
Trade secrets need no registration in Taiwan, but Article 2 of the Trade Secrets Act protects them only if they are not generally known, derive economic value from secrecy, and the owner has taken reasonable confidentiality measures. We build classification, access control and pre-departure audits under TIPS, and use ISO 56001:2024, the certifiable innovation management standard, to turn R&D into lasting value, addressing five disaster scenarios: technology leakage, failure of proof in trade secret litigation, cross-border IP infringement, trademark squatting and unauthorized use of AI training data. Delivered by VP-level consultants under strict NDA with NTUST academic support; 20+ clients, 99% passed on the first attempt.
ISO 27701 × GDPR Privacy Certification Consulting — Taiwan PDPA Compliance
No ISO 27001 yet? Since the second edition of ISO/IEC 27701 (October 2025), it is a standalone requirements standard, so a privacy information management system (PIMS) can be implemented and certified on its own. We deliver dual-track ISO 27701 and GDPR/Taiwan PDPA compliance and are a corporate member of the Taiwan Information Security Association (TWISA), addressing five disaster scenarios: GDPR fines of up to 4% of global annual turnover (Meta's €1.2B precedent), Taiwan PDPA Art. 48 penalties of up to NT$15M (further amended on 2025-11-11, effective date to be set by the Executive Yuan), cross-border transfer violations, missed 72-hour breach notifications, and AI processing without a DPIA. Led by VP-level consultants with NTUST academic support; 20+ clients, 99% passed on the first attempt. Holders of 2019-edition certificates should confirm transition deadlines with their certification body.
ISO 22301 Business Continuity Certification — BCP × DRP Architecture Consulting
RTO is how fast you must recover; RPO is how much data you can afford to lose. Both should be derived from a business impact analysis, not set in advance. ISO 22301 is the certifiable standard for business continuity management systems (BCMS). The current version is ISO 22301:2019 with Amendment 1:2024, which requires organizations to determine whether climate change is a relevant issue; a third edition is at committee draft stage with no publication date, so certification today is still against the 2019 version. We derive RTO and RPO from the BIA, build BCP and DRP, and plan annual exercises for five disaster scenarios: ransomware production halts, earthquake and typhoon supply disruption, geopolitical embargoes, critical component shortages and cloud service outages. Led by VP-level consultants with NTUST academic support; 20+ clients, 99% passed on the first attempt.
TISAX × ISO 21434 Automotive Cybersecurity Consulting — OEM Supply Chain
TISAX is not an ISO certificate but the automotive industry's information security assessment and exchange mechanism: an ENX-approved audit provider assesses you against the VDA ISA catalogue, and results are shared with customers on the ENX platform as labels valid for up to three years. VDA ISA2027 was published on 2026-07-01 and applies to assessments ordered from 2027-01-01; assessments ordered before then can still use ISA6. We integrate TISAX, ISO/SAE 21434 and UN R155 to help OEMs and Tier 1/2 suppliers complete the VDA ISA self-assessment, gap analysis, security control implementation and mock audits. We are consultants, not an issuing body.
EU Compliance Integration — CRA × NIS2 × EU AI Act
The CRA (Regulation (EU) 2024/2847) fully applies from 2027-12-11, but Art. 14 reporting has applied since 2026-09-11: actively exploited vulnerabilities and severe incidents must be reported via ENISA's single reporting platform with a 24-hour early warning and a 72-hour notification, including for products already on the EU market. EU digital laws recognize each other: meeting CRA Art. 12 counts as meeting the cybersecurity requirements of AI Act Art. 15, and DORA is lex specialis to NIS2. We use these links to plan a single compliance path, and are currently supporting 4 CRA clients.
Each day of delay compounds your organisation's compliance exposure. Schedule a complimentary framework assessment to identify gaps and establish a structured remediation plan.
Free Assessment