Skip to main content

Independent · UK · Regulated sectors

Independent Governance, Risk & Assurance for Regulated Organisations

Senior independent expertise to resolve governance and assurance gaps before they become barriers to regulation, procurement, audit or growth.

Outsourced DPO · UK GDPR · Information Governance · Cyber Assurance · AI Governance · DSPT · DTAC · Clinical Safety · Independent Assurance

Selected organisations and programmes supported by our practitioners

  • NHS England
  • AIG
  • Capgemini
  • UCL
  • The Co-operative Group
  • Glenmark Pharmaceuticals
  • UK-headquartered
  • Senior practitioner-led
  • Regulated-sector experience
Citation ISO Certification — ISO 27001:2022

ISO/IEC 27001:2022 certified
Information Security Management · Certificate No. 487582026

How it works

What happens next?

  1. Tell us what has triggered the requirement

    Share the requirement, deadline, RFP or concern.

  2. Establish the right scope

    We confirm the requirements, deliverables and commercial route.

  3. Receive a written proposal

    Approach, scope, fee and next steps, in writing.

Get started

Know the requirement.
Or start by defining it.

Our services

Find the service for your requirement

Our approach

One delivery architecture

  1. 01

    Assess

    Establish the real position.

  2. 02

    Build

    Design the governance, controls and evidence required.

  3. 03

    Manage

    Run or support the operating programme.

  4. 04

    Assure

    Test and demonstrate the position.

  5. 05

    Improve

    Close findings and keep evidence current.

Improve feeds the next Assess cycle, so evidence stays current.

Why IG-Smart

Independent judgement.
Senior practitioner-led.
Technology-independent.

  • Independent judgement

    Advice and assurance that can state clearly what remains unresolved.

  • Senior practitioner-led

    Experienced practitioners remain directly involved in substantive advisory and assurance work.

  • Technology-independent

    Recommendations follow evidence, requirements and risk rather than incentives to sell a third-party technology platform.

Evidence

Selected Client & Programme Experience

Assurance, governance and regulatory support for complex, regulated organisations.

Conceptual artwork showing the Palace of Westminster at sunset, representing the public-sector setting of the NHS COVID-19 contact tracing application governance case study.Featured engagement

Department of Health and Social Care

Governance leadership for the NHS COVID-19 contact tracing application

Legal & IG workstream leadership · Probity Cell programme management

Requirement
Leadership of the legal and Information Governance workstream, and programme management of the Probity Cell, so that governance could keep pace with delivery.
IG-Smart’s role
Legal and Information Governance workstream leadership
Outcome
Helped establish and maintain governance structures capable of supporting decision-making in an unusually fast-moving and high-consequence environment.
Read the case study: Governance leadership for the NHS COVID-19 contact tracing application

Glenmark Pharmaceuticals

Retained external DPO service for a global pharmaceutical company's EU and LATAM operations

Requirement
An external DPO service providing timely, context-aware advice and helping the organisation identify and address privacy concerns before they escalate.
IG-Smart’s role
External DPO service
Outcome
Glenmark received continuing external DPO capability across its EU and LATAM remit, with responsive support for privacy issues as they arose.
Read the case study: Retained external DPO service for a global pharmaceutical company's EU and LATAM operations

AIG

A nationwide data-governance audit of an insurer's offsite records-storage supplier

Requirement
An independent, nationwide audit of the supplier's data-protection and security arrangements.
IG-Smart’s role
GDPR and sector-regulation compliance review
Outcome
The audit identified areas for improvement and gave AIG a structured assessment of the supplier's information-governance, security and operational controls.
Read the case study: A nationwide data-governance audit of an insurer's offsite records-storage supplier

Deliverables

What you actually receive

Evidence, decisions and working governance — not generic consultancy slides.

  1. 01Current-state assessmentYour position against the applicable law, standard or framework.
  2. 02Prioritised remediationActions with owners, dependencies and sequencing.
  3. 03Working artefactsPolicies, registers, DPIAs and evidence packs — not generic templates.
  4. 04Decision-ready reportingWritten for boards, auditors, regulators and procurement reviewers.
  5. 05Residual-risk positionWhat is resolved, what remains and where risk is accepted.

Typical output structure

Independent Audit Report

  1. 01Scope and criteria
  2. 02Findings by severity
  3. 03Evidence references
  4. 04Management response

Supports: Assurance, audit response and executive decision-making

Illustrative output structure only — not client documents or evidence of any specific engagement. Content is tailored to each organisation.

Investment

Engagements & Investment

Transparent, proportionate and aligned to your requirement.

  • 01

    Defined-scope engagements

    Starting investment

    £7,500 + VAT

    Best fit

    Assessments, readiness exercises, independent reviews and defined deliverables.

    Submit a defined-scope requirement
  • 02

    Managed & retained services

    Starting investment

    £2,500 + VAT per month

    Best fit

    Ongoing DPO, governance, assurance and managed specialist support.

    Discuss managed support
  • 03

    Complex & enterprise programmes

    Starting investment

    £25,000 + VAT

    Best fit

    Multi-workstream, multi-country or transformation requirements.

    Discuss an enterprise programme

Scope, deliverables, assumptions and fees are agreed in writing before work begins. Published ranges are indicative, not a quotation.

Compare all engagement models & investment