Skip to main content

Independent · UK · Regulated sectors

Independent Governance, Risk & Assurance for Regulated Organisations

Senior-led governance, risk and assurance to address critical gaps, strengthen accountability and produce defensible evidence for procurement, audit, regulatory scrutiny and board decisions.

  • Outsourced DPO
  • UK GDPR
  • Cyber Assurance
  • AI Governance
  • NHS DSPT
  • Clinical Safety
Talk to a Senior Practitioner For requirements you’re still defining.
Submit a RequirementFor defined scopes, tenders and RFPs.
Find the Right Service A short guide to the right service.

Selected organisations and programmes supported by our practitioners

  • NHS England
  • Royal Brompton & Harefield NHS Foundation Trust
  • AIG
  • Capgemini
  • National Institute for Health and Care Research
  • UCL
  • Crown Office and Procurator Fiscal Service
  • The Co-operative Group
  • Glenmark Pharmaceuticals
  • Nectar
  • AIMIA
  • Iconex
Citation ISO Certification — ISO 27001:2022

ISO/IEC 27001:2022 certified
Certificate No. 487582026

Award-winningM&A Today Global Awards 2026 · GDPR Consultancy of the Year 2020 & 2021View recognition

Conceptual artwork showing the Palace of Westminster at sunset, representing the public-sector setting of the NHS COVID-19 contact tracing application governance case study.Selected programme experience

Department of Health and Social Care

IG-Smart led the legal and information-governance workstream and managed the Probity Cell, helping maintain accountable decision-making during rapid programme delivery.

How it works

What happens next?

  1. Tell us what has triggered the requirement

    Share the requirement, deadline, RFP or concern.

  2. Establish the right scope

    We confirm the requirements, deliverables and commercial route.

  3. Receive a written proposal

    Approach, scope, fee and next steps, in writing.

Get started

Know the requirement.
Or start by defining it.

Our services

Specialist advisory and assurance services

Integrated expertise across privacy, information governance, cyber, AI, health and supplier assurance.

Our approach

One delivery architecture

  1. 01

    Assess

    Establish the real position.

  2. 02

    Build

    Design the governance, controls and evidence required.

  3. 03

    Manage

    Run or support the operating programme.

  4. 04

    Assure

    Test and demonstrate the position.

  5. 05

    Improve

    Close findings and keep evidence current.

Improve feeds the next Assess cycle, so evidence stays current.

Why IG-Smart

Independent judgement.
Senior practitioner-led.
Technology-independent.

  • Independent judgement

    Advice and assurance that can state clearly what remains unresolved.

  • Senior practitioner-led

    Experienced practitioners remain directly involved in substantive advisory and assurance work.

  • Technology-independent

    Recommendations follow evidence, requirements and risk rather than incentives to sell a third-party technology platform.

Meet our senior practitioners

Meet the wider team

Evidence

Selected Client & Programme Experience

Assurance, governance and regulatory support for complex, regulated organisations.

Glenmark Pharmaceuticals logoData Privacy & DPO

Glenmark Pharmaceuticals

Retained external DPO service for a global pharmaceutical company

Requirement
An external DPO service providing timely, context-aware advice and helping the organisation identify and address privacy concerns before they escalate.
IG-Smart’s role
External DPO service
Outcome
Glenmark received continuing external DPO capability under a global remit, with responsive support for privacy issues as they arose.
Read the case study: Retained external DPO service for a global pharmaceutical company
AIG logoGovernance, Risk & Supplier Assurance

AIG

A nationwide data-governance audit of an insurer's offsite records-storage supplier

Requirement
An independent, nationwide audit of the supplier's data-protection and security arrangements.
IG-Smart’s role
GDPR and sector-regulation compliance review
Outcome
The audit identified areas for improvement and gave AIG a structured assessment of the supplier's information-governance, security and operational controls.
Read the case study: A nationwide data-governance audit of an insurer's offsite records-storage supplier

Deliverables

What you actually receive

Evidence, decisions and working governance — not generic consultancy slides.

  1. Current-state assessmentYour position against the applicable law, standard or framework.
  2. Prioritised remediationActions with owners, dependencies and sequencing.
  3. Working artefactsPolicies, registers, DPIAs and evidence packs — not generic templates.
  4. Decision-ready reportingWritten for boards, auditors, regulators and procurement reviewers.
  5. Residual-risk positionWhat is resolved, what remains and where risk is accepted.

Illustrative outputs

See what good governance looks like in practice

Illustrative examples of the assessments, action plans, dashboards and executive reporting clients may receive — designed to turn evidence into clear decisions and measurable progress.

  • Real-world structure
  • Evidence-led insight
  • Actionable and decision-ready
  • Applied across all services

Illustrative output

Assurance & Readiness Assessment

Current position

A clear, evidence-based view of your current position against relevant standards, regulations and good practice.

What it helps you see and do

  • Overall readiness rating
  • Assessment by domain
  • Material and critical gaps
  • Evidence coverage
  • Key findings and recommendations
  • Next steps

Typical use cases

  • ISO 27001 readiness
  • DSPT and DTAC
  • UK GDPR compliance
  • AI governance
  • Supplier assurance
  • Regulatory preparation

Likely format

  • IG-Smart branded PDF
  • Evidence pack

Illustrative output

Prioritised Improvement Plan

Remediation & action

The gaps that matter, turned into sequenced actions with owners, dates and dependencies.

What it helps you see and do

  • Priority actions
  • Accountable owners
  • Due dates and dependencies
  • Progress against plan

Typical use cases

  • Post-assessment remediation
  • Audit response
  • Certification preparation

Likely format

  • Action tracker
  • IG-Smart branded PDF

Illustrative output

Governance & Assurance Dashboard

Ongoing oversight

A recurring view of risks, actions and evidence, so you can see whether governance is improving.

What it helps you see and do

  • Open and closed actions
  • Risks by severity
  • Evidence completion
  • Overdue items and exceptions
  • Trend over time

Typical use cases

  • Managed services
  • Retained advisory
  • Committee reporting

Likely format

  • Dashboard capture
  • IG-Smart branded PDF

Illustrative output

Board Assurance Summary

Executive decision support

A concise, evidenced view for leadership: where you stand, what remains, and what must be decided.

What it helps you see and do

  • Overall assurance position
  • Top risks
  • Residual risk
  • Progress against plan
  • Decisions required

Typical use cases

  • Board and committee meetings
  • Audit committee
  • Management review

Likely format

  • IG-Smart branded PDF
  • Board pack

Illustrative structure — not a client document. Exact outputs and formats depend on the agreed scope.

Ways to work with us

Choose the support that fits your requirement

A focused project, continuing senior support or a coordinated enterprise programme.

Compare engagement options
  • One-off

    Defined Project

    A focused requirement with agreed deliverables.

    From
    £7,500 + VAT

    Your proposal defines the deliverables, responsibilities and completion criteria.

    Typical requirements

    • Assessment
    • Readiness review
    • Independent review
    • Defined improvement work
    Scope a defined project
  • Ongoing

    Ongoing Senior Support

    Continuing specialist advice or managed delivery.

    Retained advisory from
    £2,500 + VAT per month
    Senior advice, oversight and agreed reviews.
    Managed services from
    £5,000 + VAT per month
    Ongoing delivery of an agreed governance or assurance capability.

    Typical requirements

    • DPO & privacy
    • Governance
    • Supplier assurance
    • AI governance
    • Cyber leadership
    Discuss ongoing support
  • Enterprise

    Enterprise Programme

    Coordinated delivery across complex requirements.

    From
    £25,000 + VAT

    Your proposal defines the workstreams, governance, dependencies and reporting.

    Typical requirements

    • Multiple workstreams
    • Multiple jurisdictions
    • Transformation
    • Board-critical assurance
    Discuss an enterprise programme
  • Not sure where to start?

    Use the short Assurance Pathfinder to identify a suitable next step.

    Find the Right Service
    1. Tell us what triggered the requirement.
    2. See a suggested service route.
    3. Discuss or submit your requirement.

Starting fees are indicative. Fees for individual services are confirmed after scoping. Scope, deliverables, assumptions and fees are agreed in writing before work begins.