Governance & policy
Whether your policies exist, match reality, and satisfy both group standards and local law.
Security Audit
An independent, evidence-based assessment of your security and compliance posture, measured against ISO/IEC 27001, China's MLPS 2.0 (等级保护), PIPL and your own internal policy. You get findings you can act on and evidence your group can rely on.
What we assess
Whether your policies exist, match reality, and satisfy both group standards and local law.
Access, network, endpoint, logging and configuration; reviewed against recognised baselines.
How personal and important data is collected, stored and moved, including cross-border transfer.
MLPS 2.0 grading, PIPL and Data Security Law obligations, and where gaps carry real exposure.
The vendors, cloud and integrators that quietly inherit your trust, and your liability.
Whether you could detect, contain and report an incident inside the windows the law allows.
Audit catalogue
From a rapid risk review to a standards-based internal audit, we define the scope, criteria and evidence required before fieldwork begins.
A broad review of governance, architecture, operations, resilience, access, data and third parties across your information system.
A focused review to identify material privacy exposure, including processing activities, notices, consent, vendors and cross-border transfers.
Readiness and gap assessment for MLPS 2.0 classification, required controls, evidence and remediation before formal evaluation.
ISMS implementation support, certification readiness and independent internal audits against ISO/IEC 27001:2022.
Targeted assessment of infrastructure, networks, cloud, identity, endpoints, configurations and other technical control areas.
What you receive
Every engagement ends with a report structured to ISO 19011, prioritised findings, the criteria each was measured against, and remediation you can hand straight to a team. No jargon wall, no filler.
We measure your posture against ISO/IEC 27001:2022, China's MLPS 2.0 (等级保护), the PIPL and Data Security Law, and your own group policies. Findings are reported to the ISO 19011 auditing standard.
A focused scoping audit typically runs one to three weeks depending on size, scope and access. A full ISMS assessment takes longer. We agree the scope and timeline with you before any fieldwork begins.
Yes. Reports are trilingual-ready (French, English, 中文) and map each local finding to the relevant group standard, so HQ, group auditors and your China team can all act on the same document.
We perform information-system audits, PIPL red-flag audits, MLPS compliance assessments, ISO/IEC 27001 implementation reviews and internal audits, and targeted technical audits covering infrastructure, networks, cloud, identity, endpoints and configurations.
It is a focused review designed to identify the most material privacy risks quickly. We examine processing activities, legal basis and consent, privacy notices, sensitive personal information, third parties, retention and cross-border transfers, then prioritise the issues requiring deeper work.
Yes. We can help determine the likely MLPS scope and classification, assess readiness against the applicable requirements, organise evidence and build a remediation plan. Formal classification, filing and testing remain subject to the relevant Chinese authorities and accredited bodies.
Yes. We support ISMS design and implementation, certification readiness and internal audit. Where we have supported implementation, responsibilities are separated so the internal audit remains objective and does not audit a consultant's own work.
The scope can cover infrastructure, network architecture and segmentation, cloud configuration, identity and access, endpoints, logging, backup, resilience and vulnerability management. We agree the systems, testing boundaries and safe methods before starting.
Tell us your size, sector and what's prompting the review, we'll propose a fit.
Contact APIS Consulting