AIG
A nationwide data-governance audit of an insurer's offsite records-storage supplier
Strongest proof
Nationwide supplier audit
- Sector
- Financial Services
- Capability
- Information Governance · Cyber Governance & Assurance
- Geography
- United Kingdom
- Engagement model
- Defined-scope assurance
- Evidence
- Named client · Public evidence
At a glance
- Who
- AIG · Financial Services
- Why it mattered
- An insurer needed assurance that its offsite records-storage supplier protected client data across its UK facilities.
- IG-Smart's role
- Supplier data-governance audit
01The exposure
AIG is a global insurer. The engagement concerned a supplier storing its physical records offsite.
Outsourcing storage does not outsource accountability: the insurer remained responsible for its clients' data in the supplier's hands.
02The mandate
An independent, nationwide audit of the supplier's data-protection and security arrangements.
Commissioned scope
- GDPR and sector-regulation compliance review
- Physical and environmental security
- Access control, identity verification and audit trails
- Retention and disposal
- Incident response and disaster recovery
03Environment
Organisation context
Describes the client organisation — not the size of IG-Smart's work.
- Global insurer
Frameworks in scope
- UK GDPR
- Insurance-sector requirements
Scope boundary
- The audit assessed the supplier; remediation was the supplier's responsibility
04IG-Smart's approach
- 01
Compliance audit
Reviewed the supplier's alignment with GDPR and relevant sector requirements.
- 02
Physical security
Evaluated facility protection against unauthorised access and environmental risks.
- 03
Operational controls
Assessed access control, identity verification and audit trails.
- 04
Lifecycle and resilience
Reviewed retention and disposal policies and incident-response and recovery plans.
Engagement phases: Assess · Assure
05Engagement scale
What IG-Smart's work covered
- Nationwide audit of an offsite records-storage supplier
06What we delivered
- Supplier audit report and findings
- Improvement recommendations
07Outcome
Engagement result
The audit identified areas for improvement and gave AIG a structured assessment of the supplier's information-governance, security and operational controls.
08Client perspective
“At AIG, safeguarding our clients' data is not just a priority; it's our duty. We partnered with IG-Smart Ltd to conduct a nationwide audit of our offsite records storage supplier, and the results exceeded our expectations. Their unwavering commitment to data governance, risk management, and compliance mirrors our own, making them the perfect ally in our mission to protect our clients' interests. The audit not only identified areas of improvement but also showcased our dedication to transparency and integrity. Together with IG-Smart Ltd, we have reinforced our reputation as an insurance provider that goes above and beyond to safeguard our clients' data and ensure adherence to the highest industry standards.”
09What this demonstrates
Relevant to organisations that need independent supplier assurance where information-governance, physical-security and operational controls must withstand enterprise scrutiny.
10What buyers can verify
Public
- Named client
- Engagement scope
- Named executive quotation
- Deliverable types described
Further evidence can be discussed subject to confidentiality and client permissions.
Related services
Related evidence
Cyber Governance & Assurance
A FTSE 100 organisation
Security maturity and audit readiness for a FTSE 100 organisation
Global security policies didn't reflect UK practice ahead of a third-party security maturity assessment.
The client's CTO describes the work as focused, knowledgeable and timely.
Read the case studyRetail / Consumer, Cyber Governance & Assurance
The Co-operative Group
Routine penetration testing for a major national retailer and co-operative
A major national organisation needed consistent, routine testing that kept pace with its changing digital estate.
On the Group's preferred supplier list for more than two years.
Read the case study
Facing a comparable requirement?
This case reference is passed to the form so you don't need to re-enter it.
Submit a Requirement