Skip to main content

Case Studies & Evidence

Evidence for consequential decisions

Explore how IG-Smart helps organisations improve governance, privacy, cyber assurance and decision-making in regulated and high-consequence environments.

  • Named & anonymised evidence

    Real engagements with confidentiality protected

  • Client validation

    Published evidence and testimonials

  • Decision-ready outputs

    Practical, accountable and board-ready

  • Regulated & high-consequence environments

    Experience across complex regulated sectors

Evidence library

Matching case studies

3 matching case studies · 33 total

  • NHS, Health & HealthTech, Named client

    UCL

    Information-governance audit and DSPT readiness for a leading research university

    Evidence available:

    • Named executive testimonial
    • Engagement scope stated
    • Deliverables described

    What IG-Smart did · Information Governance

    IG-Smart audited information-governance policies and procedures in UCL's School of Life and Medical Sciences, produced a prioritised improvement plan for DSPT readiness, and was retained for leadership training and an ISO/IEC 27001-referenced physical-security audit.

    What this demonstrates

    Relevant to research, healthcare and other regulated organisations that need an independent assessment of information-governance readiness, clear remediation priorities and evidence capable of supporting an NHS DSPT submission.

    “The report provided insight that helped shape and focus our final DSP Toolkit submission.”
    Trevor Peacock, Head of Information Governance, UCL
    Read the full case study: UCL
  • NHS, Health & HealthTech, Named client

    National Institute for Health and Care Research (NIHR)

    Information governance framework for national patient-data sharing across the UK's original Biomedical Research Centres

    Evidence available:

    • Engagement scope stated
    • Deliverables described

    What IG-Smart did · Information Governance

    IG-Smart developed the information governance framework that enabled the National Institute for Health Research's Health Informatics Collaborative to share complex, voluminous patient datasets for research across the UK's five original national Biomedical Research Centres — Oxford, Cambridge, Guy's, King's and UCLH.

    What this demonstrates

    Relevant to research consortia, NHS and academic partnerships, trusted research environments and data platforms that need lawful, trusted data-sharing frameworks.

    Delivery:AssessBuildAssure

    Read the full case study: National Institute for Health and Care Research (NIHR)
  • NHS, Health & HealthTech, Named client

    Liverpool John Moores University

    NHS Data Security and Protection Toolkit compliance for a university school of nursing and allied health

    Evidence available:

    • Named executive testimonial
    • Engagement scope stated
    • Deliverables described

    What IG-Smart did · Information Governance

    IG-Smart delivered NHS Information Governance consultancy that enabled Liverpool John Moores University's School of Nursing and Allied Health to achieve full compliance with the NHS Data Security and Protection Toolkit, and is commissioned by the University each year to help maintain compliance with NHS-mandated Information Governance practice.

    What this demonstrates

    Relevant to universities, research groups and other non-NHS organisations that need DSPT compliance to access or process NHS patient data.

    “From the get-go we were confident you could support the work we do in the University and improve our information governance processes when faced with new challenges.”
    Lorraine Shaw, Head for Nursing, School of Nursing and Allied Health, Liverpool John Moores University

    Delivery:AssessBuildAssureManage

    Read the full case study: Liverpool John Moores University

Client voices

Client voices behind the evidence

IG Smart have provided us with quality subject matter experts surrounding GDPR and Privacy risk-based analysis and remediation; supplying qualified senior information security and experienced DPO and specialists.

Dan WestGlobal CIO, AIMIA ILS

Integrated privacy and information-security expertise

View the evidence — AIMIA ILS case study

What the evidence helps clients decide

Decision-ready outputs

The outlines show how IG-Smart structures typical outputs. They are not client documents.

  • Prioritise remediation

    Independent audit report · Supplier, IG or security audit

    An independent view of how controls operate in practice, with rated findings and recommendations.

    Used by:
    Risk, compliance and procurement leads; supplier owners
    Supports:
    Supplier assurance, remediation and contract decisions
    View typical structure

    Representative IG-Smart structure — client information not shown

    1. 01Scope and method
    2. 02Findings by control area
    3. 03Risk rating and rationale
    4. 04Prioritised recommendations
    5. 05Residual risk and owner
  • Plan and evidence improvement

    Prioritised improvement plan · Readiness for DSPT, ISO/IEC 27001 or audit

    A sequenced plan that turns gaps into owned, evidenced actions.

    Used by:
    Programme owners, SIROs, IG and security leads
    Supports:
    Resourcing, sequencing and readiness decisions
    View typical structure

    Representative IG-Smart structure — client information not shown

    1. 01Current-state gaps
    2. 02Priority and dependency
    3. 03Owner and timescale
    4. 04Evidence required
    5. 05Progress tracking
  • Maintain accountability

    Retained DPO advisory record · Outsourced or fractional DPO service

    A running record of matters raised, advice given and the decisions taken.

    Used by:
    Legal, compliance and data-protection leads
    Supports:
    Accountability, consistent advice and regulator-ready records
    View typical structure

    Representative IG-Smart structure — client information not shown

    1. 01Matter raised
    2. 02Applicable requirement
    3. 03Advice and options
    4. 04Decision owner
    5. 05Follow-up
  • Understand residual risk

    Board assurance summary · Board, committee or executive reporting

    An executive-level view of material findings, residual risk and decisions requiring accountable-owner attention.

    Used by:
    Boards, Audit Committees, accountable executives
    Supports:
    Risk acceptance, remediation prioritisation and assurance decisions
    View typical structure

    Representative IG-Smart structure — client information not shown

    1. 01Assurance question
    2. 02Evidence reviewed
    3. 03Assurance opinion basis
    4. 04Exceptions and risk acceptance
    5. 05Decisions requested

Differentiation

Why organisations appoint IG-Smart

Each reason links to published cases that show it in practice.

  1. Senior practitioner-led

    Engagements are led by experienced practitioners with direct involvement in substantive advisory and assurance work, supported proportionately where appropriate.

  2. Independent challenge

    Advice and assurance driven by evidence, requirements and risk rather than incentives to sell a technology platform.

  3. Practical, decision-ready outputs

    Work designed to support accountable owners, procurement teams, executives and boards.

    Evidenced by
  4. Experience in regulated and high-consequence environments

    Evidence supported through the published portfolio.

  5. Retained capability where continuity matters

    Evidence from managed and long-term client relationships.

Confidentiality & controlled disclosure

Evidence without compromising client confidentiality

Some of IG-Smart's most sensitive engagements involve regulatory, operational, security, commercial or patient-safety information that cannot responsibly be published in full. Where necessary, examples are anonymised or withheld from public listing.

Additional evidence may sometimes be available, subject to:

  • Confidentiality
  • Client permissions
  • Appropriateness for the buyer
  • Procurement stage
  • IG-Smart approval

Need evidence relevant to your requirement?

Tell us the sector, service or procurement requirement you are assessing.