Skip to main content

Case Studies & Evidence

Evidence for consequential decisions

Explore how IG-Smart helps organisations improve governance, privacy, cyber assurance and decision-making in regulated and high-consequence environments.

  • Named & anonymised evidence

    Real engagements with confidentiality protected

  • Client validation

    Published evidence and testimonials

  • Decision-ready outputs

    Practical, accountable and board-ready

  • Regulated & high-consequence environments

    Experience across complex regulated sectors

Evidence library

Matching case studies

6 matching case studies · 33 total

  • Technology / SaaS / RegTech, Named client

    Clini-Hub

    Embedded NHS standards governance for Clini-Hub, from start-up to scale

    Evidence available:

    • Named executive testimonial
    • Engagement scope stated
    • Deliverables described

    What IG-Smart did · AI Governance & Assurance

    IG-Smart has worked with Clini-Hub's leadership since its start-up stage, embedding information governance, clinical safety and AI governance aligned with the NHS AI Toolkit, DSPT, DTAC and DCB0129/DCB0160 standards as the company scaled.

    What this demonstrates

    Relevant to AI and digital-health suppliers that need DTAC, DSPT, clinical-safety and AI governance in place to sell to the NHS while they scale.

    “Their team’s depth of expertise and unwavering dedication has enabled Clini-Hub to achieve and maintain full compliance with all NHS standards applicable to us, including the AI Toolkit, DSPT, DTAC, and DCB standards.”
    Hugh Passmore, CEO, Clini-Hub

    Delivery:AssessBuildManageImprove

    Read the full case study: Clini-Hub
  • Technology / SaaS / RegTech, Named client

    Jigsaw Create

    ISO/IEC 27001 readiness and penetration testing for a RegTech start-up selling to enterprises

    Evidence available:

    • Named executive testimonial
    • Engagement scope stated
    • Deliverables described

    What IG-Smart did · Cyber Governance & Assurance

    IG-Smart provided ISO/IEC 27001 readiness and implementation support, penetration testing and security awareness training to Jigsaw Create. Certification was subsequently awarded through BSI's independent certification process.

    “IG-Smart took the time to truly understand our business before providing concise, pragmatic and expert-level advice... this approach sped up the whole process, saving us time and money.”
    Stephen Scanlan, MD, Jigsaw Create
    Read the full case study: Jigsaw Create
  • Technology / SaaS / RegTech, Named client

    accurx

    Retained DPO and NHS information-governance support for a HealthTech scale-up

    Evidence available:

    • Named executive testimonial
    • Engagement scope stated
    • Deliverables described

    What IG-Smart did · Data Privacy & DPO

    IG-Smart provided retained DPO services and NHS information-governance advice to accurx as its products and NHS presence developed.

    “Michael and his team have a deep knowledge of legislation and best practice on privacy and data protection. They work hard to understand the context we operate in and advise us appropriately. They deliver high quality DPO services.”
    Matt Honeyman, IG and Policy Lead, Operations, accurx
    Read the full case study: accurx
  • Technology / SaaS / RegTech, Anonymised engagement

    A FTSE 100 organisation

    Security maturity and audit readiness for a FTSE 100 organisation

    Evidence available:

    • Role-attributed testimonial
    • Engagement scope stated
    • Deliverables described

    What IG-Smart did · Cyber Governance & Assurance

    IG-Smart delivered a three-stage plan to adapt a FTSE 100 organisation's global information-security policies into UK-specific, audit-ready documentation ahead of a third-party security maturity assessment.

    What this demonstrates

    Relevant to complex enterprises that need global security and governance requirements translated into practical, audit-ready controls that reflect local operating reality.

    “IG Smart proposed a 3-stage plan... Focussed, knowledgeable and timely, IG Smart prioritised the deliverables required, conducted interviews with key stakeholders... and worked remotely to minimise disruption. Working to tight timescales, and also following up to ensure the policies and procedures met audit requirements, IG Smart worked professionally and competently throughout.”
    Chief Technology Officer, A FTSE 100 organisation
    Read the full case study: A FTSE 100 organisation
  • Retail & Consumer, Named client

    AIMIA Loyalty Solutions

    Global GDPR implementation and privacy-by-design for a loyalty-solutions business

    Evidence available:

    • Named executive testimonial
    • Engagement scope stated
    • Deliverables described

    What IG-Smart did · Data Privacy & DPO

    IG-Smart led an end-to-end global GDPR implementation programme for AIMIA Loyalty Solutions, supplying senior privacy, information-security and DPO-level specialists and embedding a privacy-by-design framework across international operations.

    What this demonstrates

    Relevant to multinational organisations that need senior privacy expertise to establish scalable GDPR and privacy-by-design governance across complex international operations.

    “IG Smart quickly enabled AIMIA to reach GDPR readiness and implementation of the ‘privacy by design’ framework in a highly efficient and time-effective manner.”
    Richard Peake, President & COO, AIMIA Loyalty Solutions – Asia Pacific
    Read the full case study: AIMIA Loyalty Solutions
  • Technology / SaaS / RegTech, Named client

    Capgemini

    Certified Data Protection Officer training for senior consultants at a global consultancy

    Evidence available:

    • Named executive testimonial
    • Engagement scope stated
    • Deliverables described

    What IG-Smart did · Data Privacy & DPO

    IG-Smart delivered an intensive PECB Certified Data Protection Officer training programme for senior Capgemini consultants in Sweden, combining legislative depth with the practical realities of the DPO role.

    What this demonstrates

    Relevant to organisations that need senior practitioner-led privacy capability building where professional knowledge must translate into recognised certification and practical DPO competence.

    “I would like to thank Michael Abtar – CEO IG-Smart for a well-conducted and insightful course.”
    Tor-Ståle Hansen, Global CISO, Capgemini
    Read the full case study: Capgemini

Client voices

Client voices behind the evidence

IG Smart have provided us with quality subject matter experts surrounding GDPR and Privacy risk-based analysis and remediation; supplying qualified senior information security and experienced DPO and specialists.

Dan WestGlobal CIO, AIMIA ILS

Integrated privacy and information-security expertise

View the evidence — AIMIA ILS case study

What the evidence helps clients decide

Decision-ready outputs

The outlines show how IG-Smart structures typical outputs. They are not client documents.

  • Prioritise remediation

    Independent audit report · Supplier, IG or security audit

    An independent view of how controls operate in practice, with rated findings and recommendations.

    Used by:
    Risk, compliance and procurement leads; supplier owners
    Supports:
    Supplier assurance, remediation and contract decisions
    View typical structure

    Representative IG-Smart structure — client information not shown

    1. 01Scope and method
    2. 02Findings by control area
    3. 03Risk rating and rationale
    4. 04Prioritised recommendations
    5. 05Residual risk and owner
  • Plan and evidence improvement

    Prioritised improvement plan · Readiness for DSPT, ISO/IEC 27001 or audit

    A sequenced plan that turns gaps into owned, evidenced actions.

    Used by:
    Programme owners, SIROs, IG and security leads
    Supports:
    Resourcing, sequencing and readiness decisions
    View typical structure

    Representative IG-Smart structure — client information not shown

    1. 01Current-state gaps
    2. 02Priority and dependency
    3. 03Owner and timescale
    4. 04Evidence required
    5. 05Progress tracking
  • Maintain accountability

    Retained DPO advisory record · Outsourced or fractional DPO service

    A running record of matters raised, advice given and the decisions taken.

    Used by:
    Legal, compliance and data-protection leads
    Supports:
    Accountability, consistent advice and regulator-ready records
    View typical structure

    Representative IG-Smart structure — client information not shown

    1. 01Matter raised
    2. 02Applicable requirement
    3. 03Advice and options
    4. 04Decision owner
    5. 05Follow-up
  • Understand residual risk

    Board assurance summary · Board, committee or executive reporting

    An executive-level view of material findings, residual risk and decisions requiring accountable-owner attention.

    Used by:
    Boards, Audit Committees, accountable executives
    Supports:
    Risk acceptance, remediation prioritisation and assurance decisions
    View typical structure

    Representative IG-Smart structure — client information not shown

    1. 01Assurance question
    2. 02Evidence reviewed
    3. 03Assurance opinion basis
    4. 04Exceptions and risk acceptance
    5. 05Decisions requested

Differentiation

Why organisations appoint IG-Smart

Each reason links to published cases that show it in practice.

  1. Senior practitioner-led

    Engagements are led by experienced practitioners with direct involvement in substantive advisory and assurance work, supported proportionately where appropriate.

  2. Independent challenge

    Advice and assurance driven by evidence, requirements and risk rather than incentives to sell a technology platform.

  3. Practical, decision-ready outputs

    Work designed to support accountable owners, procurement teams, executives and boards.

    Evidenced by
  4. Experience in regulated and high-consequence environments

    Evidence supported through the published portfolio.

  5. Retained capability where continuity matters

    Evidence from managed and long-term client relationships.

Confidentiality & controlled disclosure

Evidence without compromising client confidentiality

Some of IG-Smart's most sensitive engagements involve regulatory, operational, security, commercial or patient-safety information that cannot responsibly be published in full. Where necessary, examples are anonymised or withheld from public listing.

Additional evidence may sometimes be available, subject to:

  • Confidentiality
  • Client permissions
  • Appropriateness for the buyer
  • Procurement stage
  • IG-Smart approval

Need evidence relevant to your requirement?

Tell us the sector, service or procurement requirement you are assessing.