Skip to main content

Independent · UK · Regulated sectors

Independent Governance, Risk & Assurance for Regulated Organisations

Senior independent expertise to resolve governance and assurance gaps before they become barriers to regulation, procurement, audit or growth.

Outsourced DPO · UK GDPR · Information Governance · Cyber Assurance · AI Governance · DSPT · DTAC · Clinical Safety · Independent Assurance

Selected organisations and programmes supported by our practitioners

  • NHS England
  • AIG
  • Capgemini
  • UCL
  • The Co-operative Group
  • Glenmark Pharmaceuticals
  • UK-headquartered
  • Senior practitioner-led
  • Regulated-sector experience
Citation ISO Certification — ISO 27001:2022

ISO/IEC 27001:2022 certified
Information Security Management · Certificate No. 487582026

How it works

What happens next?

  1. Tell us what has triggered the requirement

    Share the requirement, deadline, RFP or concern.

  2. Establish the right scope

    We confirm the requirements, deliverables and commercial route.

  3. Receive a written proposal

    Approach, scope, fee and next steps, in writing.

Get started

Know the requirement.
Or start by defining it.

Our services

Find the service for your requirement

Our approach

One delivery architecture

  1. 01

    Assess

    Establish the real position.

  2. 02

    Build

    Design the governance, controls and evidence required.

  3. 03

    Manage

    Run or support the operating programme.

  4. 04

    Assure

    Test and demonstrate the position.

  5. 05

    Improve

    Close findings and keep evidence current.

Improve feeds the next Assess cycle, so evidence stays current.

Why IG-Smart

Independent judgement.
Senior practitioner-led.
Technology-independent.

  • Independent judgement

    Advice and assurance that can state clearly what remains unresolved.

  • Senior practitioner-led

    Experienced practitioners remain directly involved in substantive advisory and assurance work.

  • Technology-independent

    Recommendations follow evidence, requirements and risk rather than incentives to sell a third-party technology platform.

Evidence

Selected Client & Programme Experience

Assurance, governance and regulatory support for complex, regulated organisations.

Conceptual artwork showing the Palace of Westminster at sunset, representing the public-sector setting of the NHS COVID-19 contact tracing application governance case study.Featured engagementContext image

Department of Health and Social Care

Governance leadership for the NHS COVID-19 contact tracing application

Legal & IG workstream leadership · Probity Cell programme management

Requirement
Leadership of the legal and Information Governance workstream, and programme management of the Probity Cell, so that governance could keep pace with delivery.
IG-Smart’s role
Legal and Information Governance workstream leadership
Outcome
Helped establish and maintain governance structures capable of supporting decision-making in an unusually fast-moving and high-consequence environment.
Read the case study: Governance leadership for the NHS COVID-19 contact tracing application
Pharmaceutical scientist using a microscope in a modern research laboratory.Context image

Glenmark Pharmaceuticals

Retained external DPO service for a global pharmaceutical company's EU and LATAM operations

Requirement
An external DPO service providing timely, context-aware advice and helping the organisation identify and address privacy concerns before they escalate.
IG-Smart’s role
External DPO service
Outcome
Glenmark received continuing external DPO capability across its EU and LATAM remit, with responsive support for privacy issues as they arose.
Read the case study: Retained external DPO service for a global pharmaceutical company's EU and LATAM operations
Conceptual artwork representing enterprise supplier data-governance assurance for the AIG case study.Context image

AIG

A nationwide data-governance audit of an insurer's offsite records-storage supplier

Requirement
An independent, nationwide audit of the supplier's data-protection and security arrangements.
IG-Smart’s role
GDPR and sector-regulation compliance review
Outcome
The audit identified areas for improvement and gave AIG a structured assessment of the supplier's information-governance, security and operational controls.
Read the case study: A nationwide data-governance audit of an insurer's offsite records-storage supplier

Deliverables

What you actually receive

Evidence, decisions and working governance — not generic consultancy slides.

  1. 01Current-state assessmentYour position against the applicable law, standard or framework.
  2. 02Prioritised remediationActions with owners, dependencies and sequencing.
  3. 03Working artefactsPolicies, registers, DPIAs and evidence packs — not generic templates.
  4. 04Decision-ready reportingWritten for boards, auditors, regulators and procurement reviewers.
  5. 05Residual-risk positionWhat is resolved, what remains and where risk is accepted.

Illustrative outputs

See what good governance looks like in practice

Illustrative examples of the assessments, action plans, dashboards and executive reporting clients may receive — designed to turn evidence into clear decisions and measurable progress.

  • Real-world structure
  • Evidence-led insight
  • Actionable and decision-ready
  • Applied across all services

Illustrative output

Assurance & Readiness Assessment

Current position

A clear, evidence-based view of your current position against relevant standards, regulations and good practice.

What it helps you see and do

  • Overall readiness rating
  • Assessment by domain
  • Material and critical gaps
  • Evidence coverage
  • Key findings and recommendations
  • Next steps

Typical use cases

  • ISO 27001 readiness
  • DSPT and DTAC
  • UK GDPR compliance
  • AI governance
  • Supplier assurance
  • Regulatory preparation

Likely format

  • IG-Smart branded PDF
  • Evidence pack

Illustrative output

Prioritised Improvement Plan

Remediation & action

The gaps that matter, turned into sequenced actions with owners, dates and dependencies.

What it helps you see and do

  • Priority actions
  • Accountable owners
  • Due dates and dependencies
  • Progress against plan

Typical use cases

  • Post-assessment remediation
  • Audit response
  • Certification preparation

Likely format

  • Action tracker
  • IG-Smart branded PDF

Illustrative output

Governance & Assurance Dashboard

Ongoing oversight

A recurring view of risks, actions and evidence, so you can see whether governance is improving.

What it helps you see and do

  • Open and closed actions
  • Risks by severity
  • Evidence completion
  • Overdue items and exceptions
  • Trend over time

Typical use cases

  • Managed services
  • Retained advisory
  • Committee reporting

Likely format

  • Dashboard capture
  • IG-Smart branded PDF

Illustrative output

Board Assurance Summary

Executive decision support

A concise, evidenced view for leadership: where you stand, what remains, and what must be decided.

What it helps you see and do

  • Overall assurance position
  • Top risks
  • Residual risk
  • Progress against plan
  • Decisions required

Typical use cases

  • Board and committee meetings
  • Audit committee
  • Management review

Likely format

  • IG-Smart branded PDF
  • Board pack

Illustrative structure — not a client document. Exact outputs and formats depend on the agreed scope.

Ways to work with us

Choose the level of support you need

Start with a defined project, add ongoing senior capability, or commission a complex enterprise programme. Scope, deliverables, assumptions and fees are agreed with you before work begins.

  • One-off

    Defined Project

    One clear outcome. One agreed scope.

    From
    £7,500 + VAT

    Choose this when you need

    • Assessment
    • Readiness
    • Independent review
    • Defined remediation
    Scope a defined project
  • Ongoing

    Ongoing Senior Support

    Senior capability without permanent senior headcount.

    Retained advisory from
    £2,500 + VAT/month
    Managed services from
    £5,000 + VAT/month
    What’s the difference?

    Retained advisory provides continuing access to senior advice, oversight and agreed review/reporting activity.

    Managed services include ongoing delivery or operation of an agreed governance, assurance or specialist capability.

    Choose this when you need

    • DPO & privacy
    • Governance
    • Supplier assurance
    • AI governance
    • Cyber leadership
    Discuss ongoing support
  • Enterprise

    Enterprise Programme

    Complex requirements. Coordinated delivery.

    From
    £25,000 + VAT

    Choose this when you need

    • Multiple workstreams
    • Multiple jurisdictions
    • Transformation
    • Board-critical assurance
    Discuss an enterprise programme

Not sure which applies? Tell us what has triggered the requirement and we'll help you find the right route.

Find the Right Service
Compare all engagement options & investment

Scope, deliverables, assumptions and fees are agreed in writing before work begins. Published ranges are indicative, not a quotation.