Skip to main content

Independent · UK · Regulated sectors

Independent Governance, Risk & Assurance for Regulated Organisations

Senior independent expertise to resolve governance and assurance gaps before they become barriers to regulation, procurement, audit or growth.

Outsourced DPO · UK GDPR · Information Governance · Cyber Assurance · AI Governance · DSPT · DTAC · Clinical Safety · Independent Assurance

Selected organisations and programmes supported by our practitioners

  • UK-headquartered
  • Senior practitioner-led
  • Regulated-sector experience
Citation ISO Certification — ISO 27001:2022

ISO/IEC 27001:2022 certified
Information Security Management · Certificate No. 487582026

Our services

Find the service for your requirement

Evidence

Selected Client & Programme Experience

Assurance, governance and regulatory support for complex, regulated organisations.

Featured engagement
NHS England

NHS · Information Governance · Privacy · Strategic Assurance

Requirement
Strategic data-privacy and data-sharing advice to senior data and IG leadership across several national programmes.
IG-Smart’s role
National data privacy by design and by default framework
Outcome
National privacy-by-design and information-governance mechanisms were developed and applied across significant NHS England workstreams, including support for New Models of Care, publications and the GP Challenge Fund.
Read the case study: NHS England
Glenmark Pharmaceuticals

Data Privacy & DPO

Requirement
An external DPO service providing timely, context-aware advice and helping the organisation identify and address privacy concerns before they escalate.
IG-Smart’s role
External DPO service
Outcome
Glenmark received continuing external DPO capability across its EU and LATAM remit, with responsive support for privacy issues as they arose.
Read the case study: Glenmark Pharmaceuticals
AIG

Governance, Risk & Supplier Assurance

Requirement
An independent, nationwide audit of the supplier's data-protection and security arrangements.
IG-Smart’s role
GDPR and sector-regulation compliance review
Outcome
The audit identified areas for improvement and gave AIG a structured assessment of the supplier's information-governance, security and operational controls.
Read the case study: AIG

Deliverables

What you actually receive

Evidence, decisions and working governance — not generic consultancy slides.

  1. 01Current-state assessmentYour position against the applicable law, standard or framework.
  2. 02Prioritised remediationActions with owners, dependencies and sequencing.
  3. 03Working artefactsPolicies, registers, DPIAs and evidence packs — not generic templates.
  4. 04Decision-ready reportingWritten for boards, auditors, regulators and procurement reviewers.
  5. 05Residual-risk positionWhat is resolved, what remains and where risk is accepted.

Typical output structure

Independent Audit Report

  1. 01Scope and criteria
  2. 02Findings by severity
  3. 03Evidence references
  4. 04Management response

Supports: Assurance, audit response and executive decision-making

Illustrative output structure only — not client documents or evidence of any specific engagement. Content is tailored to each organisation.

Why IG-Smart

Independent judgement.
Senior practitioner-led.
Technology-independent.

  • Independent judgement

    Advice and assurance that can state clearly what remains unresolved.

  • Senior practitioner-led

    Experienced practitioners remain directly involved in substantive advisory and assurance work.

  • Technology-independent

    Recommendations follow evidence, requirements and risk rather than incentives to sell a third-party technology platform.

Our approach

One delivery architecture

  1. 01

    Assess

    Establish the real position.

  2. 02

    Build

    Design the governance, controls and evidence required.

  3. 03

    Manage

    Run or support the operating programme.

  4. 04

    Assure

    Test and demonstrate the position.

  5. 05

    Improve

    Close findings and keep evidence current.

Improve feeds the next Assess cycle, so evidence stays current.

Investment

Engagements & Investment

Transparent, proportionate and aligned to your requirement.

  • 01

    Defined-scope engagements

    Starting investment

    £7,500 + VAT

    Best fit

    Assessments, readiness exercises, independent reviews and defined deliverables.

    Submit a defined-scope requirement
  • 02

    Managed & retained services

    Starting investment

    £2,500 + VAT per month

    Best fit

    Ongoing DPO, governance, assurance and managed specialist support.

    Discuss managed support
  • 03

    Complex & enterprise programmes

    Starting investment

    £25,000 + VAT

    Best fit

    Multi-workstream, multi-country or transformation requirements.

    Discuss an enterprise programme

Scope, deliverables, assumptions and fees are agreed in writing before work begins. Published ranges are indicative, not a quotation.

Compare all engagement models & investment

How it works

What happens next?

  1. 01

    Tell us what has triggered the requirement

    Share the requirement, deadline, RFP or concern.

  2. 02

    Establish the right scope

    We confirm the requirements, deliverables and commercial route.

  3. 03

    Receive a written proposal

    Approach, scope, fee and next steps, in writing.

Get started

Know the requirement.
Or start by defining it.