Data Privacy & Information Governance
Managed Information Governance
- Information assets
- Ownership
- Lifecycle
- Controls
- Assurance
- Leadership
18+ yearsSenior practitioner experience
Global audit deliveryInternational assurance and audit experience
Selected published client evidenceNHS England · UCL · AIG
ISO/IEC 27001:2022Certified information-security management
Ongoing information-governance capability, not a periodic clean-up — with defined-scope work available where the operating model or baseline first needs to be established.
Best suited to regulated, multi-entity, multi-site or public-sector-facing organisations that need information governance to operate consistently across teams, records and systems.
Senior-led by Michael Abtar, CEO and Founder · LLB (Hons), PG.Dip.Law, Cert. DPO
When organisations engage us
Signals that it is time to act
- Information governance relies on one person or goodwill
- Records, retention and information-asset ownership are unclear
- Information risks are not reported to senior leadership
- Audit, contract or assurance requirements keep recurring
- Several business units handle information differently
- Incidents or near misses reveal gaps in control
What the service covers
Outcomes the service is built to deliver
- IG framework and accountability
- Defined roles, committees and reporting lines for information governance.
- Information assets and risk
- Oversight of information-asset registers, owners and information-risk management.
- Records and retention governance
- Governance of records management and retention so information is kept, and disposed of, deliberately.
- Policy and procedure maintenance
- Keeping IG policies and procedures current and consistently applied.
- Incident and issue governance
- Clear routes for information incidents, lessons learned and escalation.
- Leadership reporting
- Regular, evidenced reporting on information risk and progress.
How we deliver
Assess → Build → Manage → Assure → Improve
Assess
Baseline IG maturity, risks and evidence.
Build
Agree the IG model, priorities and reporting rhythm.
Manage
Run ongoing oversight, advice and issue governance.
Assure
Evidence control and progress for leadership and auditors.
Improve
Refresh priorities as the organisation and risks change.
Scope boundaries
Included, and separately scoped where required
Included in the core service
- IG oversight and structured programme management
- Senior advice and challenge
- Risk-based prioritisation
- Leadership and committee reporting
Separately scoped where required
- Large-scale records remediation or migration
- Operational administration at scale
- Specialist cyber or legal deep dives
- Major implementation programmes
What you receive
Outputs you can picture before you engage
Illustrative structure — not a client document
Example content shown for illustration only.
Information asset ownership register
| Asset | Owner | Classification | Retention | Last review |
|---|---|---|---|---|
| Customer records | Customer Services Director | Confidential | Per approved retention schedule | Review date set |
| HR files | HR Director | Restricted | Per approved retention schedule | Review date set |
| Finance ledgers | Finance Director | Confidential | Current schedule applies | Review date set |
Relevant evidence
Relevant evidence
View the evidence: NHS EnglandNamed client · Healthcare / NHS
NHS England
Strategic data-privacy and data-sharing advisory
National privacy-by-design framework · multiple national workstreams
View the evidence: UCLNamed client · Higher Education / Research
UCL
IG audit, improvement plan, training and physical-security audit
Helped shape and focus the final DSPT submission
View the evidence: AIGNamed client · Financial Services
AIG
Supplier data-governance audit
Nationwide supplier audit

Service lead
Michael Abtar · CEO and Founder
LLB (Hons), PG.Dip.Law, Cert. DPO
Governance, risk and assurance specialist with more than 18 years' experience spanning privacy, cyber resilience, AI governance, digital transformation, healthcare and complex regulated organisations.
Experience includes governance and assurance work involving more than 100 million consumer records.
View profileInvestment
Scoped to requirement
Delivered as a managed & retained service. Scope, deliverables, assumptions and fees are agreed in writing before work begins.
Talk to a Senior Practitioner How engagements & investment work
Fees reflect factors such as
- Organisational scale and complexity
- Number of entities and jurisdictions
- Scope of retained responsibility
- Existing maturity
- Volume of remediation support
- Required availability
- Assurance and reporting requirements
Questions
Frequently asked questions
How does this differ from an IG assessment?
An assessment is a defined-scope review of where you stand. Managed Information Governance provides continuing oversight and support so improvements are sustained.
Does it cover data protection?
It covers the governance that data protection depends on. Where formal DPO oversight or a privacy programme is needed, it can be combined with those services with responsibilities kept distinct.
Can it support NHS assurance requirements?
Yes, it can support the governance behind NHS requirements. Where a DSPT submission needs dedicated readiness or assurance work, that is scoped as NHS DSPT Readiness & Assurance.
Next step
