Since July 2026, Hong Kong government bureaux and departments have had to assess whether proposed new computer systems can incorporate suitable integrity and security controls when applying for funding. The Independent Commission Against Corruption (ICAC) will provide assistance with the assessments.
The ICAC formally published the Computer System Integrity and Security Standard on 2 September for government bureaux and departments. Reports describe it as setting out 12 core control measures aimed at strengthening system security, process controls and monitoring of irregularities.
Reported measures include user authentication, clearly defined access rights, data encryption, mandatory conflict-of-interest declarations for important processes, supervisory approval, access logs, anomaly detection and automatic alerts. The reports differ slightly over whether the 12 items are controls, risks or functions.
The ICAC said the standard was developed partly in response to weaknesses identified in past corruption investigations and prevention reviews. These included accounts being used by impersonators to log in, data leaks, missed conflict-of-interest declarations and failures to stop non-compliant conduct promptly.
The standard also reportedly supports embedding government and departmental rules into work processes, including anti-bribery reminders, conduct-training questions and links to relevant resources. One report said possible features included a secure online complaints channel and safeguards for complainants’ identities.
The ICAC and officials said incorporating integrity controls at the design stage could reduce opportunities for misconduct and lower future investigation, system-repair and reputational-crisis risks. These are projected policy benefits, rather than verified results established by the available reports.
It remains unclear whether the self-assessments require approval, whether failing to meet the standard could affect a funding application, or whether the standard applies to upgrades to existing systems.
More than 65 bureaux and departments and about 120 representatives reportedly attended the 2 September launch. A seminar afterwards featured case-sharing, workflow improvements and demonstrations involving artificial intelligence, data science and integrity controls.