Insights
Governance guidance, reviewed and dated
Each guide names its author and reviewer, lists its sources and shows when it was last reviewed.
UK
Do You Need a Data Protection Officer?
When UK GDPR requires a Data Protection Officer, when a voluntary appointment makes sense, and how to choose between an internal, fractional or outsourced DPO.
UK
DSPT, DTAC, DCB0129 and DCB0160: How NHS HealthTech Governance Fits Together
What each NHS assurance requirement covers, who owns it, how they overlap, and how a digital health supplier can build one evidence base that satisfies all four.
UK
What Does an Independent Cyber Security Audit Actually Cover?
What a governance-led cyber security audit examines, how it differs from penetration testing and certification audits, and what boards and buyers should expect to receive.
