Skip to main content
IG-Smart — Governance, Risk & Assurance

Data Privacy & Information Governance

Information Governance Consultancy for Regulated Organisations

Put clear ownership, control and assurance around the information your organisation depends on.

Talk to a Senior PractitionerStill defining the requirement
Submit a RequirementDefined scope, tender or RFP

IG-Smart helps regulated organisations design and operate information governance models that connect accountability, records lifecycle, policies, decision-making and assurance — so important information is managed deliberately rather than through fragmented local practice.

When organisations engage us

When organisations engage us

  • Governance redesign

    Existing arrangements have grown organically and ownership is unclear.

  • Regulatory or audit findings

    Recurring weaknesses indicate a governance problem rather than an isolated control failure.

  • Organisational change

    Merger, acquisition, restructuring, new technology or outsourcing has changed how information is owned or managed.

  • NHS / healthcare requirements

    Information governance must align with sector-specific records, privacy, assurance and clinical governance expectations.

  • Growth into regulated markets

    Informal practices no longer provide sufficient evidence or executive assurance.

  • Records remediation

    Legacy information, inconsistent retention or uncontrolled repositories require structured intervention.

  • Board assurance requirement

    Leadership needs a reliable picture of risk, remediation and residual exposure.

What we help solve

Information risk rarely comes from one missing policy

In most organisations, information-governance problems build up gradually. They commonly arise because:

  • responsibilities are distributed but unclear;
  • policies have accumulated without coherent ownership;
  • retention decisions differ between teams and systems;
  • committees receive activity reports instead of risk information;
  • privacy, security, records and operational governance work in parallel;
  • legacy information is retained without a defensible business or regulatory basis;
  • important decisions are made but not consistently recorded;
  • audit findings recur because governance causes are not addressed;
  • ownership becomes unclear when systems, suppliers or business models change.

The underlying issue

The problem is usually not absence of documentation. It is absence of an effective governance system.

Adding documents to a system without clear ownership adds volume, not control.

What the engagement involves

Build governance that works in practice

  1. 01

    Governance Operating Model

    Define how information decisions are made, who owns them, who provides oversight and how issues escalate.

    Typical areas

    • Roles and accountability
    • Decision rights
    • Governance forums
    • Committee structures
    • Escalation routes
    • Terms of reference
    • Business ownership
    • Assurance responsibilities
  2. 02

    Records & Information Lifecycle

    Establish proportionate governance from creation and use through retention, archival and defensible disposal.

    Typical areas

    • Retention architecture
    • Records ownership
    • Lifecycle controls
    • Disposal governance
    • Legal and regulatory holds
    • Legacy information
    • Structured and unstructured records
    • Evidence of decisions
  3. 03

    Policy & Control Framework

    Replace fragmented documents with a coherent hierarchy of policies, standards, procedures and supporting controls.

    Typical areas

    • Policy architecture
    • Document hierarchy
    • Ownership
    • Review cycles
    • Approval routes
    • Control mapping
    • Exceptions
    • Evidence expectations
  4. 04

    Information Risk & Accountability

    Make material information risks visible, owned and capable of escalation.

    Typical areas

    • Information-risk registers
    • Accountable owners
    • Issue escalation
    • Risk acceptance
    • Remediation
    • Dependency mapping
    • Supplier interfaces
  5. 05

    Governance Committees & Reporting

    Help governance forums spend less time receiving updates and more time making informed decisions.

    Typical areas

    • Committee design
    • Agendas
    • Management information
    • KPIs and KRIs
    • Decision logs
    • Action tracking
    • Executive reporting
  6. 06

    Assurance & Continuous Improvement

    Test whether governance arrangements are operating as intended and turn findings into measurable improvement.

    Typical areas

    • Governance reviews
    • Maturity assessment
    • Internal assurance
    • Audit readiness
    • Finding management
    • Remediation oversight
    • Board assurance

Definition

What is information governance?

Information governance is the system of accountability, decision-making, controls and assurance through which an organisation manages information throughout its lifecycle. It connects ownership, records management, privacy, security, retention, access, policy and oversight so information is managed consistently and important decisions can be evidenced.

Information governance is not the same as data protection

The disciplines overlap and depend on each other, but they are not interchangeable.

  • Focus of this page

    Information Governance

    • accountability
    • records
    • lifecycle
    • decision rights
    • policy
    • assurance

    The wider management and accountability environment around organisational information.

  • Data Protection

    • lawful processing
    • individual rights
    • DPIAs
    • transparency
    • privacy accountability

    Legal obligations relating to personal data. May sit within, alongside or intersect with information governance.

  • Cybersecurity

    • confidentiality
    • integrity
    • availability
    • technical and organisational security controls

    Protects information and systems, but does not by itself establish ownership, lifecycle management or executive accountability.

Where they meet — for example retention of personal data, access control or incident handling — information governance provides the ownership and decision routes that let privacy and security controls work together.

Lifecycle

Govern information throughout its lifecycle

Retention is one stage. Governance applies at every stage, from the moment information is created or received.

Cross-cutting controls — applied at every stage
  • Ownership
  • Policy
  • Risk
  • Privacy
  • Security
  • Assurance
  1. 01Create / Receive
  2. 02Classify
  3. 03Use & Share
  4. 04Store & Protect
  5. 05Retain
  6. 06Archive or Dispose

Operating model

Who owns information governance?

No single organisational model works universally. The right model depends on:

  • sector
  • regulatory environment
  • organisational scale
  • risk profile
  • information types
  • operating structure
  • existing privacy, security and records functions

IG-Smart does not impose a fixed committee structure. We configure accountability around the organisation that exists — the example shown is one possible arrangement.

The objective is not more governance. It is clear governance.

Configurable example
  1. Board / Executive Oversight
  2. Information Governance Committee
  3. Specialist functions:
    • Privacy
    • Records
    • Security
    • Technology
    • Clinical / Operational Governance
  4. Business Information Owners / System Owners
  5. Operational Teams

Regulatory and standards context

Which requirements can an information governance framework support?

Applicable requirements depend on the sector and the processing environment. Depending on the organisation, relevant references may include:

  • UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025, where personal data is involved
  • Freedom of Information and public-records obligations, where applicable
  • Sector-specific records-management requirements
  • NHS information-governance and records-management requirements for relevant health and care organisations
  • ISO 15489-1:2016 records-management principles
  • ISO/IEC 27001 information-security governance, where relevant
  • Contractual, audit and procurement requirements

A governance framework supports an organisation in meeting these requirements; it does not by itself produce compliance with all of them. Scope is agreed for each engagement.

How we deliver

How IG-Smart approaches an information governance engagement

  1. 01

    Assess

    Establish the existing operating model, information lifecycle, ownership, policies, risks, governance forums and assurance position.

  2. 02

    Build

    Design proportionate governance structures, roles, controls, policy architecture, records arrangements and reporting.

  3. 03

    Manage

    Implement or support the operating rhythm — governance meetings, risk management, action tracking, reporting and lifecycle activity.

  4. 04

    Assure

    Test whether governance is operating as designed and provide clear evidence to executives, auditors, regulators or customers.

  5. 05

    Improve

    Close findings, strengthen maturity and adapt the governance model as risks, systems and requirements change.

Improvement feeds the next assessment cycle, keeping governance evidence current rather than rebuilding the position from scratch.

What you receive

What does an Information Governance engagement produce?

Depending on scope and organisational maturity, outputs may include:

  1. 01Information Governance current-state assessmentA documented view of the governance position, key dependencies, gaps and priority risks.
  2. 02Target operating modelDefined roles, accountability, decision rights, governance forums and escalation routes.
  3. 03Records and information lifecycle frameworkGovernance for creation, ownership, retention, archival and defensible disposal.
  4. 04Policy architectureA coherent hierarchy of policies, standards, procedures, owners and review cycles.
  5. 05Governance committee frameworkTerms of reference, decision routes, management information, reporting and action tracking.
  6. 06Prioritised remediation planFindings sequenced by risk, dependency, effort and accountable owner.
  7. 07Board / executive assurance reportingClear visibility of material information risk, progress, decisions and residual exposure.

Service boundaries

Information Governance, Managed Privacy and DPO support are connected — but different

These services can run together. Where they do, IG-Smart defines responsibilities at the outset so operational delivery, governance design and independent oversight stay distinct.

Relevant evidence

Selected information governance engagements

Published engagements involving national information governance advice, records and supplier assurance, and governance integration through organisational change.

Explore all case studies →Request Relevant Evidence →

Common engagement models

Assessment, programme or ongoing support?

  • Defined-scope assessment

    A bounded review of governance, records, data sharing or a specific requirement, with prioritised findings and a written fee.

    Suits

    Organisations that need to establish their position or answer a specific assurance question.

  • Governance improvement programme

    Phased design and implementation of ownership, policy, records and evidence arrangements across business units.

    Suits

    Fragmented governance, integration or remediation following an audit, incident or change.

  • Ongoing governance support

    Retained senior support to maintain the governance framework, advise on new requirements and keep evidence current.

    Suits

    Organisations that need continuing senior capacity once the framework is in place.

Typical investment

Indicative investment

  • Information Governance assessment / programme

    Starting investment: £7,500 + VAT

    Typical investment: £10,000–£30,000+ + VAT

    Model: Defined-scope engagement

    Usually increases investment: Number of business units and record types; Maturity of existing policies and evidence; Remediation support required

Scope, deliverables, assumptions and fees are agreed in writing before work begins. What changes the fee is set out on the investment page; the exact fee is confirmed after scoping.

How engagements and investment work

FAQ

Frequently asked questions

Regulatory and standards references reviewed September 2026. This page is reviewed every 6 months.

Discuss an information governance requirement

Need to strengthen the governance around your information?

Whether you need to assess the current position, redesign the operating model or implement continuing governance, start with the requirement.

Not sure what applies?Find the Right Service