Working and thinking globally.

ACPMIT.ASIA offers extensive range of IT security and IT consulting services to our clients based in Petaling Jaya, Malaysia

Working and thinking globally.

ACPMIT.ASIA offers extensive range of IT security and IT consulting services to our clients based in Petaling Jaya, Malaysia



End to End Cyber Security

 Our experience in IT auditing and security across multiple industries allows us to help our clients see their challenges from a new perspective. Our experts have over 20 years of experience in various fields of IT Security. 

IT Audit

 We provide audit services into IT systems of organizations with various business profiles. .

Program and Project Management

 We also handle program and project management tasks related to IT projects as well as strategic planning related to it. Our range of services on this field are: 

XBRL and Trustmark Services

 We are working with a team of internationally experienced specialists who are able to provide extensive support to any organization trying to manage its XBRL compliance and operational challenges. 

 We are an international Trustmark Operator based in Europe. As part of ASEAN Trustmark Alliance with our Malaysian office, ACPM helps trustful businesses with its Trustmark operation. We issue Trustmark seals to businesses with reliable online presence after auditing their services, which promotes online business trust. For more information on our Trustmark services, please get in contact with us here. 


 We provide a great variety of training programs in the different fields of IT security. From introductory training programs, management IT security training programs to in-depth defensive and offensive cyber-security training courses, we cover an extensive range of topics related to information technology. ACPM’s experts are ready to provide your team with IT training in our facilities or your own office, according to your requirements. We are also able to customize training programs for to your specific needs. For our current range of training courses, please get in contact with us here. .

Critical Anti-Fraud Program (‘CAP’) - Event Details

Governance, Risk and Compliance (GRC) for Critical Anti-Fraud Program




Event Agenda 

1400-1500 – Introduction   and Critical Anti-Fraud Program 

1515 –1700 – GRC Product   Demonstration and Product Functionalities:

· Governance

· Risk Management (ERM + ORM)

· Compliance

1700 – 1730 – Question   and Answer Session and Closing 


DATE & Venue


Friday - 16 August   2019

Sunway Nexis, Jalan PJU5/1, Kota Damansara, Petaling   Jaya

For Further information kindly download the brochure

For Further information kindly download the brochure

Governance,Risk&Compliance(GRC)/Critical Anti-Fraud Program

Event Date : 16th August 2019

 1. Critical Anti-Fraud Program (‘CAP’)

Left unchecked, fraud can spell disaster for an organization. By contrast, an organization with an effective critical anti-fraud program can reap many benefits. There is growing evidence that a broad cross section of stakeholders, including shareholders, regulators, law enforcement, lenders, insurance underwriters, analysts, and bond raters are willing to reward an organization that has a proven commitment to integrity and plan to address the S17A – corporate liability provision of the Malaysian Anti-Corruption Act that will be in force commencing1 June 2020.

Learn More



16th August 2019 : Event Agenda 

1400-1500 – Introduction and Critical Anti-Fraud Program 

1515 –1700 – GRC Product Demonstration and Product Functionalities:

· Governance

· Risk Management (ERM + ORM)

· Compliance

1700 – 1730 – Question and Answer Session and Closing  


Sunway Nexis, Jalan PJU5/1, Kota Damansara, Petaling   Jaya

Find out more



 The DOJ issued New April 2019 Guidance  (“Guidance”, or “2019 Guidance”) detailing how prosecutors will evaluate the effectiveness of corporate programs to prevent fraud and other misconduct, a key consideration in determining the penalties imposed against companies.  This is an update from the On February 8, 2017, the DOJ published Guidance entitled, “Evaluation of Corporate Compliance Programs”. 

 The 2019 Guidance contains 12 high-level topics (below) that are grouped to track the Three Core Questions about compliance program effectiveness contained in Section 9-28.800 of the Justice Manual and candidly are the key questions the board of directors should be asking.  After all it’s expected the the organization’s “governing authority shall be knowledgeable about the content and operation of the compliance and ethics program and shall exercise reasonable oversight” of it (See U.S.S.G. § 8B2.1(b)(2)(A)-(C)). 

 Three Core Questions

  1. Is the Corporation’s Compliance Program Well Designed?
  2. Is the Corporation’s Compliance Program Being Implemented Effectively?
  3. Does the Corporation’s Compliance Program Work in Practice?

The High-level Topics

  1. Risk Assessment
  2. Policies and Procedures
  3. Training and Communications
  4. Confidential Reporting Structure and Investigation Process
  5. Third Party Management
  6. Mergers and Acquisitions (M&A)
  7. Commitment by Senior and Middle Management
  8. Autonomy and Resources
  9. Incentives and Disciplinary Measures
  10. Continuous Improvement, Periodic Testing, and Review
  11. Investigation of Misconduct
  12. Analysis and Remediation of Any Underlying Misconduct

Under each of the above topics, the 2019 Guidance sets forth multiple sample questions that prosecutors are likely to ask during an investigation. A few examples are:

  • Risk Assessment: Risk Management ProcessWhat methodology has the company used to identify, analyze, and address the particular risks it faced?
  • Training and Communications: Risk Based Training What training have employees in relevant control functions received?
    • Has the company provided tailored training for high-risk and control employees that addressed the risks in the area where the misconduct occurred?
  • Confidential Reporting Structure and Investigation Process: Effectiveness of the Reporting MechanismDoes the company have an anonymous reporting mechanism, and, if not, why not?
    • How is the reporting mechanism publicized to the company’s employees?
    • Has it been used?
    • How has the company assessed the seriousness of the allegations it received
    • Has the compliance function had full access to reporting and investigative information?
  • Mergers and Acquisitions (M&A): Process Connecting Due Diligence to Implementation What has been the company’s process for tracking and remediating misconduct or misconduct risks identified during the due diligence process
    • What has been the company’s process for implementing compliance policies and procedures at new entities?
  • Commitment by Senior and Middle Management: Conduct at the Top How have senior leaders, through their words and actions, encouraged or discouraged compliance, including the type of misconduct involved in the investigation?
    • What concrete actions have they taken to demonstrate leadership in the company’s compliance and remediation efforts?
    • How have they modelled proper behavior to subordinates?
    • Have managers tolerated greater compliance risks in pursuit of new business or greater revenues?
    • Have managers encouraged employees to act unethically to achieve a business objective, or impeded compliance personnel from effectively implementing their duties?
  • Continuous Improvement, Periodic Testing, and Review: Internal AuditWhat is the process for determining where and how frequently internal audit will undertake an audit, and what is the rationale behind that process?
    • How are audits carried out?
    • What types of audits would have identified issues relevant to the misconduct
    • Did those audits occur and what were the findings?
    • What types of relevant audit findings and remediation progress have been reported to management and the board on a regular basis?
    • How have management and the board followed up?
    • How often does internal audit conduct assessments in high-risk areas?
  • Continuous Improvement, Periodic Testing, and Review: Properly Scoped Investigation by Qualified PersonnelHow has the company ensured that the investigations have been properly scoped, and were independent, objective, appropriately conducted, and properly documented?

Some Other Points of Focus

  • Compliance must adopt a risk-based approach (See Closing Thoughts below).
  • Compliance must have appropriate processes for the submission of complaints, and processes to protect whistleblowers.
  • The word “resource” appears 21 times in the Guidance, so I am certain that if your organization is not properly resourced that will more likely than not be a problem.
  • Compliance must have independent access to the Board and Audit Committee.
  • Compliance needs to be integrated with other functions like internal audit, and depending on structure, the legal function. 
  • Compliance must adopt strong third-party controls.

The 2019 Guidance seeks to understand how the organization approaches compliance and then what worked and what didn’t.  So, one might consider reading both the old and new Guidance to understand how the evaluation of an organization’s compliance programs has changed.

If you are going to have your organization’s compliance program evaluated and you should!




The new General Data Protection Regulation (GDPR) came in to force from 25 May 2018.

  They are a significant upgrade to the existing Data Protection regulations that have been in place since 1998. The upgrade is required to meet the new developments in data use over the past 20 years. Simple examples are the use of cookies that track internet viewing habits or supermarket loyalty cards that record purchases.


The aim of data use by businesses is to target advertising more efficiently. However, data users have not always explained how this works or allowed individuals to opt out. There is also a secondary market for this data where details are bought and sold without

the knowledge of the individual. So the

new regulations set more explicit duties for organisations that use personal data and that includes just about everyone.


This guide sets out the scope of the new GDPR regime and explains the practical steps that should be taken to ensure compliance.

Who is affected? 

All organisations are affected if they  collect personal data.

Personal data is any record that identifies an individual through name, address, or other contact details. This is a wide definition and shows why everyone needs to have an awareness of GDPR and how it affects their organisation.


The impact of GDPR will depend on the nature of the personal data held and why the organisation holds it. There are legal grounds for holding data and businesses that are already compliant with existing data protection law will have a head start in meeting the new rules.


Any organisation active in direct marketing should already follow data protection law. However, the new rules are more demanding so a number of organisations will have to consider data protection for the first time. For example, there are specific rules for records of children and vulnerable people so the education and health sectors are a particular focus.

The Regulator 

The Information Commissioner’s Office (ICO) was set up in 1984.

It upholds information rights in the public interest, promoting openness by public bodies and data privacy for individuals

in response to concerns about direct marketing. It has evolved over time and has acquired the ability to issue large fines. Several companies have been under scrutiny for large scale data breaches, including T-mobile and Superdrug. Its remit covers all marketing channels including mail, telephone and email. There are two legally distinct areas of activity; Data Protection and the Privacy and Electronic

Communications Regulations.


Enforcement and fines

GDPR has raised the existing ceiling for fines to €20,000,000 or 4% of worldwide turnover, whichever is

greater. Fines have been levied on Google at €50million (£44m) for a privacy violation,issued by the French data protection authority in January 2019.

Fines can be levied where:

•An organisation is actively misusing the data and, as the bar on compliance is being raised, previous practice cannot be relied upon 

•There is a failure to maintain adequate controls against misuse or data loss. Data can be lost through hacking of websites or theft of IT equipment and a fine will follow if adequate precautions have not been taken

•If individual rights are not protected and that individual complains to the ICO.


Every organisation needs to understand their responsibilities under GDPR and then take steps to make sure they are

compliant by 25 May 2018 and beyond. We recommend addressing these six, simple, key issues:


GDPR - What should be done to ensure GDPR compliance?

1. Get an understanding on GDPR

Get an understanding on GDPR, tailored to your industry so that you understand what matters for your organisation. This is particularly important if you are working with children or vulnerable adults

2. Map the personal data held by your organisation

Understand what personal data your organisation uses, where it came from and why it is held.

This includes electronic databases

and hard copy filing


Ensure you have appropriate consent processes that give individuals control of their data. This includes asking for consent, how that consent is recorded and what happens if consent is not given

4. Legal Basis

Consent is not the only legal basis for data processing. Make sure you understand the use of legitimate interests as a basis for lawful processing

5.Individual rights

Understand the strengthened individual rights and the ability of your organisation to meet them. This includes knowing where data is held, the deletion of data no longer needed and how you might pass data on to third parties when needed

6.Data Protection Management

Review your existing data protection regime and determine what needs to improve to meet GDPR; for example the ability to detect, report and investigate a personal data breach. The regime should satisfy both the letter and spirit of the law.



Let us help

 •We can provide a tailored briefing session for your organisation that will enable an action plan to be prepared

•We can support you in the implementation of your GDPR regime

•GDPR regime in place? We can audit your processes to ensure they are fully compliant

•We can help with maintenance and audit of your GDPR systems.

How do I know if I’m doing a good job?

 •You have looked into what GDPR is and what it entails. You have assessed how compliant your organisation is and what steps you need to take

•You have assigned someone to take responsibility for data protection compliance

•You have implemented processes and procedures to ensure that you are GDPR compliant

•You have communicated what GDPR is to staff and have ensured that they understand and are following correct processes and procedures. It’s everyone’s job to get this right and protect the data.

Find out more

MBRS Training

Course Introduction

Suruhanjaya   Syarikat Malaysia (“SSM”) has   introduced a submission   platform based on the eXtensible Business Reporting Language (“XBRL”) format   in 2018. 

This submission platform, known   as   the Malaysian Business   Reporting System (“MBRS”) which allows for the annual   submission of :

1.Financial Statements (“FS”) and Key Financial Indicators (“KFI”);

2.Annual   Return (“AR”); and 

3.Exemption Applications (“EA”) which are related to the FS and AR applications. 

The guiding principles behind MBRS are based on the financial and non-financial scope of   Companies Act 2016.

The MBRS Portal (“mPortal”) is available at and prior registration with SSM is required.

Participants can download MBRS Preparation Tool (“mTool”) during the training. 

Course Objectives

This 1-day   course provides participants with an understanding of XBRL and MBRS for the   purpose of compliance with the requirements contained in the Companies Act   2016. Participants will learn about the submission requirements and how to optimise the use of   the preparation tool (“mTool”)   to   ensure smooth filing of Annual   Returns, Financial   Statements and Exemption Applications.

Training Methodology

Trainer-facilitated course supported   with presentation slides and Q&A session.


Laptop is   not compulsory for this event.   

Course Content

1.What is XBRL   and how does it work?

2.Introduction   to Malaysian Business Reporting System

3.Components   of MBRS: Taxonomy, mTool, mPortal and Reports

4.Compulsory   digital signature registration

5.Submission   workflow for FS,   KFI, AR   and EA. 

6.Install and   getting started with the preparation tool 

7.Introduction to SSM Taxonomy   (“SSMxT”) 

8.Sample   preparation and   submission of MBRS Annual Returns 

Course Learning Outcome

By attending   this course, participants will be able to :

1. Explain MBRS submission requirements

2.Get started with mTool 

3. Prepare and submit MBRS Annual Returns

4.Understand   the context of MBRS  Financial Statements

Who Should Attend

Company   Secretaries, Directors, Accountants, Auditors, Finance Professionals,   Business Owners and those  Officers and Managers who will be impacted by MBRS.


Baker Tilly MH Consulting Sdn Bhd is a direct member of XBRL International Inc. XBRL International Inc is the international organisation which develops and maintains the XBRL standard and related specifications.

The professionals of Baker Tilly have been involved in the MBRS journey with SSM since 2015 through MBRS planning and implementation.

We have the right mix of team with in-depth knowledge in XBRL, Public Key Infrastructure, Companies Act 2016 and financial reporting. Baker Tilly MH Consulting Sdn Bhd is accredited by the Malaysian Communications and Multimedia Commission under the Digital Signature Act 1997 and Digital Signature Regulations 1998.

Find out more

About Us



ACPM was founded and is headquartered in Budapest, Hungary. We have partners and  representative offices in various locations around the world to provide top-quality service to our global clients.

Reach out to one of our offices to start a discussion.

Find out more

Our Blog


Want to keep up with ACPM Events and News. 

Visit our blog for more information

Find out more



Find out more about the team at ACPMIT.ASIA Consultants and our Consulting Services

Find out more



Lim Huck Hai

Managing Director


T: +6012 620 9868


Douglas Brown

Executive Director



Anuarul Hakim Ab halim

 Head of Business Development 


Contact Us

Drop us a line!

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

ACPMIT.Asia (Moore Stephens Advisory Sdn Bhd - 1128087-T)

Sunway Nexis C-10-07, 1 Jalan PJU5/1, Kota Damansara, PETALING JAYA, Selangor 47810, Malaysia

+603-61450889 +6012-620 9868



9:00 am – 6:00 pm


9:00 am – 6:00 pm


9:00 am – 6:00 pm


9:00 am – 6:00 pm


9:00 am – 6:00 pm