UCL
Information-governance audit and DSPT readiness for a leading research university
Strongest proof
Helped shape and focus the final DSPT submission
- Sector
- Higher Education / Research · Healthcare / NHS
- Capability
- Information Governance · NHS & HealthTech
- Geography
- United Kingdom
- Engagement model
- Defined-scope assurance
- Evidence
- Named client · Public evidence
At a glance
- Who
- UCL · Higher Education / Research · Healthcare / NHS
- Why it mattered
- A research-intensive school handling sensitive health data needed to understand its readiness for the NHS Data Security and Protection Toolkit.
- IG-Smart's role
- IG audit, improvement plan, training and physical-security audit
01The exposure
UCL is a leading UK research university. The engagement focused on its School of Life and Medical Sciences, which handles sensitive research and health data.
Access to NHS data for research depends on demonstrating appropriate information governance through the Data Security and Protection Toolkit.
02The mandate
An independent audit of existing IG policies and SOPs, and a clear, prioritised improvement plan aligned with evolving DSPT requirements.
Commissioned scope
- Audit and gap analysis of IG policies and SOPs
- Prioritised improvement plan
- Follow-on: training for the SIRO and Head of Information Governance
- Follow-on: physical-security audit referenced to ISO/IEC 27001
03Environment
Organisation context
Describes the client organisation — not the size of IG-Smart's work.
- Leading UK research university
Frameworks in scope
- NHS Data Security and Protection Toolkit
- ISO/IEC 27001
Scope boundary
- The DSPT submission itself remained the institution's responsibility
04IG-Smart's approach
- 01
Audit and gap analysis
Reviewed current IG policies and SOPs against DSPT expectations and identified where practice needed to change.
- 02
Prioritised improvement plan
Set out where to focus resources ahead of the DSPT submission.
- 03
Leadership training
Retained to train the Senior Information Risk Owner and Head of Information Governance.
- 04
Physical-security audit
Conducted a physical-security audit referenced to ISO/IEC 27001 controls.
05Engagement scale
What IG-Smart's work covered
- School of Life and Medical Sciences
- IG audit, improvement plan, SIRO training, physical-security audit
06What we delivered
- IG audit report
- Gap analysis against DSPT expectations
- Prioritised improvement plan
- SIRO and Head of IG training
- Physical-security audit report
07Outcome
Client-reported result
The client's Head of Information Governance reports that the audit report clearly indicated areas to prioritise and helped shape and focus the final DSPT submission.
Professional assessment
IG-Smart was retained for further training and a physical-security audit following the initial engagement.
08Client perspective
“We first came across, and were impressed with, IG Smart’s work with one of our partner organisations. This gave us the confidence to choose IG Smart to perform an internal audit and assess our readiness for the DSP Toolkit. IG Smart were able to work with us and produce a report that clearly indicated areas to prioritise. The report provided insight that helped shape and focus our final DSP Toolkit submission.”
09What this demonstrates
Relevant to research, healthcare and other regulated organisations that need an independent assessment of information-governance readiness, clear remediation priorities and evidence capable of supporting an NHS DSPT submission.
10What buyers can verify
Public
- Named client
- Engagement scope
- Named executive quotation
- Deliverable types described
Further evidence can be discussed subject to confidentiality and client permissions.
Related services
Related evidence
Find the Right ServiceFacing a comparable requirement?
This case reference is passed to the form so you don't need to re-enter it.
Submit a Requirement