Skip to main content
IG-Smart — Governance, Risk & Assurance

Independent · UK · Regulated sectors

Independent Governance, Risk & Assurance for Regulated Organisations

Senior independent expertise to resolve governance and assurance gaps before they become barriers to regulation, procurement, audit or growth.

Outsourced DPO · UK GDPR · Information Governance · Cyber Assurance · AI Governance · DSPT · DTAC · Clinical Safety · Independent Assurance

Not sure what applies?Find the Right Service

Selected organisations and programmes supported by our practitioners

  • UK-headquartered, supporting regulated organisations in the UK and internationally
  • Senior practitioner-led
  • Regulated-sector experience
Citation ISO Certification — ISO 27001:2022

ISO/IEC 27001:2022 certified
Information Security Management · Certificate No. 487582026

Why organisations engage us

When governance becomes business-critical

Choose what has triggered the requirement and the Assurance Pathfinder will suggest the right route.

Capabilities

Find the service for your requirement

Deliverables

What you actually receive

Evidence, decisions and working governance — not generic consultancy slides.

  1. 01Current-state assessmentA documented assessment against the applicable law, standard, contractual requirement or framework.
  2. 02Prioritised remediationA practical remediation plan with owners, effort, dependencies and sequencing.
  3. 03Working artefactsPolicies, registers, DPIAs, governance documents, evidence packs and other agreed deliverables — not generic templates.
  4. 04Decision-ready reportingReporting written for boards, auditors, regulators, customers and procurement reviewers.
  5. 05Residual-risk positionA clear statement of what has been resolved, what remains outstanding and where risk has been accepted.

Evidence

Selected Client & Programme Experience

Selected organisations and programmes where IG-Smart expertise has supported governance, privacy, cyber, assurance or regulated transformation.

Selected experience includes: NHS & health (NHS England) · Pharmaceutical & life sciences (Glenmark Pharmaceuticals) · Technology & consulting (Capgemini) · Insurance & financial services (AIG) · Higher education & research (UCL) · Retail & consumer enterprise (The Co-operative Group)

  • Glenmark Pharmaceuticals

    Data Privacy & DPO

    Requirement
    An external DPO service providing timely, context-aware advice and helping the organisation identify and address privacy concerns before they escalate.
    IG-Smart’s role
    • External DPO service
    • Advisory support to legal and compliance teams
    Delivered / outcome
    Glenmark received continuing external DPO capability across its EU and LATAM remit, with responsive support for privacy issues as they arose.
    Client perspective
    “Knowledgeable and responsive… IG help us to navigate an otherwise tricky area of compliance.”

    Oliver Bourne, Vice President, Legal and Compliance – EU and LATAM, Glenmark Global Pharmaceuticals

    Read the case study
  • UCL

    Information Governance & NHS Assurance

    Requirement
    An independent audit of existing IG policies and SOPs, and a clear, prioritised improvement plan aligned with evolving DSPT requirements.
    IG-Smart’s role
    • Audit and gap analysis of IG policies and SOPs
    • Prioritised improvement plan
    Delivered / outcome
    The client's Head of Information Governance reports that the audit report clearly indicated areas to prioritise and helped shape and focus the final DSPT submission.
    Client perspective
    “The report provided insight that helped shape and focus our final DSP Toolkit submission.”

    Trevor Peacock, Head of Information Governance, UCL

    Read the case study
  • AIG

    Governance, Risk & Supplier Assurance

    Requirement
    An independent, nationwide audit of the supplier's data-protection and security arrangements.
    IG-Smart’s role
    • GDPR and sector-regulation compliance review
    • Physical and environmental security
    Delivered / outcome
    The audit identified areas for improvement and gave AIG a structured assessment of the supplier's information-governance, security and operational controls.
    Client perspective
    “The audit not only identified areas of improvement but also showcased our dedication to transparency and integrity.”

    Kojo Kwarteng, Head of Client Services EMEA, AIG

    Read the case study

Our position

Why IG-Smart

  • Independent challenge

    Advice and assurance that can state clearly what remains unresolved.

  • Senior practitioner-led delivery

    Engagements are led by experienced practitioners with direct involvement in substantive advisory and assurance work, supported proportionately where appropriate.

  • Technology-independent advice

    Recommendations are driven by evidence, applicable requirements and risk rather than incentives to sell a particular third-party technology platform.

  • Defensible evidence
  • Residual-risk visibility
  • Senior accountability

How we deliver

One delivery architecture, from first assessment to continuous improvement

  1. 01

    Assess

    Establish the real position against the applicable law, standard or framework.

  2. 02

    Build

    Design the governance, controls, documentation and evidence that will withstand scrutiny.

  3. 03

    Manage

    Run the programme day to day, or support the team that does.

  4. 04

    Assure

    Test, report and demonstrate the position to boards, regulators and customers.

  5. 05

    Improve

    Close findings, raise maturity and keep evidence current between cycles.

Improvement feeds the next assessment cycle, so governance and evidence remain current rather than being rebuilt for every audit.

Commercial clarity

Engagements & Investment

We publish indicative investment levels so organisations can establish commercial fit before committing time to a conversation. Final fees depend on scope, complexity, regulatory requirements, existing maturity, evidence available and delivery timescale.

Scope, deliverables, assumptions and fees are agreed in writing before work begins.

View typical investment and engagement models

Procurement route

What happens next?

  1. 01

    Tell us what has triggered the requirement

    Share the requirement, deadline, RFP or current concern.

  2. 02

    Establish the right scope

    We clarify the applicable requirements, assumptions, deliverables and commercial route.

  3. 03

    Receive a written proposal

    You receive the agreed delivery approach, scope, fee and next steps.