Data Privacy & Information Governance
Information Governance Consultancy for Regulated Organisations
Put clear ownership, control and assurance around the information your organisation depends on.
IG-Smart helps regulated organisations design and operate information governance models that connect accountability, records lifecycle, policies, decision-making and assurance — so important information is managed deliberately rather than through fragmented local practice.
- Governance Operating Models
- Records Lifecycle
- Accountability & Decision Rights
- Policy Frameworks
- Assurance Reporting
When organisations engage us
When organisations engage us
Governance redesign
Existing arrangements have grown organically and ownership is unclear.
Regulatory or audit findings
Recurring weaknesses indicate a governance problem rather than an isolated control failure.
Organisational change
Merger, acquisition, restructuring, new technology or outsourcing has changed how information is owned or managed.
NHS / healthcare requirements
Information governance must align with sector-specific records, privacy, assurance and clinical governance expectations.
Growth into regulated markets
Informal practices no longer provide sufficient evidence or executive assurance.
Records remediation
Legacy information, inconsistent retention or uncontrolled repositories require structured intervention.
Board assurance requirement
Leadership needs a reliable picture of risk, remediation and residual exposure.
What we help solve
Information risk rarely comes from one missing policy
In most organisations, information-governance problems build up gradually. They commonly arise because:
- responsibilities are distributed but unclear;
- policies have accumulated without coherent ownership;
- retention decisions differ between teams and systems;
- committees receive activity reports instead of risk information;
- privacy, security, records and operational governance work in parallel;
- legacy information is retained without a defensible business or regulatory basis;
- important decisions are made but not consistently recorded;
- audit findings recur because governance causes are not addressed;
- ownership becomes unclear when systems, suppliers or business models change.
The underlying issue
The problem is usually not absence of documentation. It is absence of an effective governance system.
Adding documents to a system without clear ownership adds volume, not control.
What the engagement involves
Build governance that works in practice
- 01
Governance Operating Model
Define how information decisions are made, who owns them, who provides oversight and how issues escalate.
Typical areas
- Roles and accountability
- Decision rights
- Governance forums
- Committee structures
- Escalation routes
- Terms of reference
- Business ownership
- Assurance responsibilities
- 02
Records & Information Lifecycle
Establish proportionate governance from creation and use through retention, archival and defensible disposal.
Typical areas
- Retention architecture
- Records ownership
- Lifecycle controls
- Disposal governance
- Legal and regulatory holds
- Legacy information
- Structured and unstructured records
- Evidence of decisions
- 03
Policy & Control Framework
Replace fragmented documents with a coherent hierarchy of policies, standards, procedures and supporting controls.
Typical areas
- Policy architecture
- Document hierarchy
- Ownership
- Review cycles
- Approval routes
- Control mapping
- Exceptions
- Evidence expectations
- 04
Information Risk & Accountability
Make material information risks visible, owned and capable of escalation.
Typical areas
- Information-risk registers
- Accountable owners
- Issue escalation
- Risk acceptance
- Remediation
- Dependency mapping
- Supplier interfaces
- 05
Governance Committees & Reporting
Help governance forums spend less time receiving updates and more time making informed decisions.
Typical areas
- Committee design
- Agendas
- Management information
- KPIs and KRIs
- Decision logs
- Action tracking
- Executive reporting
- 06
Assurance & Continuous Improvement
Test whether governance arrangements are operating as intended and turn findings into measurable improvement.
Typical areas
- Governance reviews
- Maturity assessment
- Internal assurance
- Audit readiness
- Finding management
- Remediation oversight
- Board assurance
Definition
What is information governance?
Information governance is the system of accountability, decision-making, controls and assurance through which an organisation manages information throughout its lifecycle. It connects ownership, records management, privacy, security, retention, access, policy and oversight so information is managed consistently and important decisions can be evidenced.
Information governance is not the same as data protection
The disciplines overlap and depend on each other, but they are not interchangeable.
Focus of this page
Information Governance
- accountability
- records
- lifecycle
- decision rights
- policy
- assurance
The wider management and accountability environment around organisational information.
Data Protection
- lawful processing
- individual rights
- DPIAs
- transparency
- privacy accountability
Legal obligations relating to personal data. May sit within, alongside or intersect with information governance.
Cybersecurity
- confidentiality
- integrity
- availability
- technical and organisational security controls
Protects information and systems, but does not by itself establish ownership, lifecycle management or executive accountability.
Where they meet — for example retention of personal data, access control or incident handling — information governance provides the ownership and decision routes that let privacy and security controls work together.
Lifecycle
Govern information throughout its lifecycle
Retention is one stage. Governance applies at every stage, from the moment information is created or received.
- Ownership
- Policy
- Risk
- Privacy
- Security
- Assurance
- 01Create / Receive
- 02Classify
- 03Use & Share
- 04Store & Protect
- 05Retain
- 06Archive or Dispose
Operating model
Who owns information governance?
No single organisational model works universally. The right model depends on:
- sector
- regulatory environment
- organisational scale
- risk profile
- information types
- operating structure
- existing privacy, security and records functions
IG-Smart does not impose a fixed committee structure. We configure accountability around the organisation that exists — the example shown is one possible arrangement.
The objective is not more governance. It is clear governance.
- Board / Executive Oversight
- Information Governance Committee
- Specialist functions:
- Privacy
- Records
- Security
- Technology
- Clinical / Operational Governance
- Business Information Owners / System Owners
- Operational Teams
Regulatory and standards context
Which requirements can an information governance framework support?
Applicable requirements depend on the sector and the processing environment. Depending on the organisation, relevant references may include:
- UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025, where personal data is involved
- Freedom of Information and public-records obligations, where applicable
- Sector-specific records-management requirements
- NHS information-governance and records-management requirements for relevant health and care organisations
- ISO 15489-1:2016 records-management principles
- ISO/IEC 27001 information-security governance, where relevant
- Contractual, audit and procurement requirements
A governance framework supports an organisation in meeting these requirements; it does not by itself produce compliance with all of them. Scope is agreed for each engagement.
How we deliver
How IG-Smart approaches an information governance engagement
- 01
Assess
Establish the existing operating model, information lifecycle, ownership, policies, risks, governance forums and assurance position.
- 02
Build
Design proportionate governance structures, roles, controls, policy architecture, records arrangements and reporting.
- 03
Manage
Implement or support the operating rhythm — governance meetings, risk management, action tracking, reporting and lifecycle activity.
- 04
Assure
Test whether governance is operating as designed and provide clear evidence to executives, auditors, regulators or customers.
- 05
Improve
Close findings, strengthen maturity and adapt the governance model as risks, systems and requirements change.
Improvement feeds the next assessment cycle, keeping governance evidence current rather than rebuilding the position from scratch.
What you receive
What does an Information Governance engagement produce?
Depending on scope and organisational maturity, outputs may include:
- 01Information Governance current-state assessmentA documented view of the governance position, key dependencies, gaps and priority risks.
- 02Target operating modelDefined roles, accountability, decision rights, governance forums and escalation routes.
- 03Records and information lifecycle frameworkGovernance for creation, ownership, retention, archival and defensible disposal.
- 04Policy architectureA coherent hierarchy of policies, standards, procedures, owners and review cycles.
- 05Governance committee frameworkTerms of reference, decision routes, management information, reporting and action tracking.
- 06Prioritised remediation planFindings sequenced by risk, dependency, effort and accountable owner.
- 07Board / executive assurance reportingClear visibility of material information risk, progress, decisions and residual exposure.
Service boundaries
Information Governance, Managed Privacy and DPO support are connected — but different
Information Governance
Designs and operates the organisation-wide structures through which information is owned, controlled and assured.
Managed Privacy Programme
Provides operational capability for privacy controls, records of processing, DPIAs, rights handling and improvement activity.
Fractional / Outsourced DPO
Provides independent statutory or senior DPO oversight, challenge and assurance.
Explore Fractional & Outsourced DPO Services
These services can run together. Where they do, IG-Smart defines responsibilities at the outset so operational delivery, governance design and independent oversight stay distinct.
Relevant evidence
Selected information governance engagements
Published engagements involving national information governance advice, records and supplier assurance, and governance integration through organisational change.
Public Sector, Information Governance · Data Privacy & DPO
NHS England
National data-privacy and information-governance advisory for NHS England
A national health body needed privacy embedded in digital transformation, new care models and national publications.
Read the case studyFinancial Services, Information Governance · Cyber Governance & Assurance
AIG
A nationwide data-governance audit of an insurer's offsite records-storage supplier
An insurer needed assurance that its offsite records-storage supplier protected client data across its UK facilities.
AIG’s Head of Client Services EMEA: “the results exceeded our expectations… The audit not only identified areas of improvement…”
Read the case studyMedia / Entertainment, Data Privacy & DPO · Cyber Governance & Assurance
A US-based global music and entertainment group with an active acquisition strategy
Repeatable governance integration for acquisitions at a global entertainment group
A global entertainment group acquiring businesses frequently needed each new entity brought into one governance framework.
A retained governance partner since 2018.
Read the case study
Common engagement models
Assessment, programme or ongoing support?
Defined-scope assessment
A bounded review of governance, records, data sharing or a specific requirement, with prioritised findings and a written fee.
Suits
Organisations that need to establish their position or answer a specific assurance question.
Governance improvement programme
Phased design and implementation of ownership, policy, records and evidence arrangements across business units.
Suits
Fragmented governance, integration or remediation following an audit, incident or change.
Ongoing governance support
Retained senior support to maintain the governance framework, advise on new requirements and keep evidence current.
Suits
Organisations that need continuing senior capacity once the framework is in place.
Typical investment
Indicative investment
Information Governance assessment / programme
Starting investment: £7,500 + VAT
Typical investment: £10,000–£30,000+ + VAT
Model: Defined-scope engagement
Usually increases investment: Number of business units and record types; Maturity of existing policies and evidence; Remediation support required
Scope, deliverables, assumptions and fees are agreed in writing before work begins. What changes the fee is set out on the investment page; the exact fee is confirmed after scoping.
How engagements and investment workFAQ
Frequently asked questions
Regulatory and standards references reviewed September 2026. This page is reviewed every 6 months.
Related services
- Fractional & Outsourced DPO ServicesSenior independent data-protection leadership, retained DPO capability and operational privacy governance.
- HealthTech Governance & Clinical SafetyDTAC, DSPT, clinical safety, NHS procurement readiness and continuing assurance.
- Cyber Governance & AssuranceBoard-level cyber governance, resilience, supplier assurance, ISO readiness and technical assurance.
Discuss an information governance requirement
Need to strengthen the governance around your information?
Whether you need to assess the current position, redesign the operating model or implement continuing governance, start with the requirement.
