Skip to main content

Data Privacy & Information Governance

Managed Information Governance

Ongoing, senior-led information governance for organisations that need records, information risk and accountability managed consistently — not revisited only when an audit arrives.
Information governance operating model
  1. Information assets
  2. Ownership
  3. Lifecycle
  4. Controls
  5. Assurance
  6. Leadership
  • 18+ yearsSenior practitioner experience

  • Global audit deliveryInternational assurance and audit experience

  • Selected published client evidenceNHS England · UCL · AIG

  • ISO/IEC 27001:2022Certified information-security management

Ongoing information-governance capability, not a periodic clean-up — with defined-scope work available where the operating model or baseline first needs to be established.

Best suited to regulated, multi-entity, multi-site or public-sector-facing organisations that need information governance to operate consistently across teams, records and systems.

Senior-led and coordinated by a named service team, shown below.

When organisations engage us

Signals that it is time to act

  1. Information governance relies on one person or goodwill

  2. Records, retention and information-asset ownership are unclear

  3. Information risks are not reported to senior leadership

  4. Audit, contract or assurance requirements keep recurring

  5. Several business units handle information differently

  6. Incidents or near misses reveal gaps in control

What the service covers

Outcomes the service is built to deliver

IG framework and accountability
Defined roles, committees and reporting lines for information governance.
Information assets and risk
Oversight of information-asset registers, owners and information-risk management.
Records and retention governance
Governance of records management and retention so information is kept, and disposed of, deliberately.
Policy and procedure maintenance
Keeping IG policies and procedures current and consistently applied.
Incident and issue governance
Clear routes for information incidents, lessons learned and escalation.
Leadership reporting
Regular, evidenced reporting on information risk and progress.

How we deliver

Assess → Build → Manage → Assure → Improve

  1. Assess

    Baseline IG maturity, risks and evidence.

  2. Build

    Agree the IG model, priorities and reporting rhythm.

  3. Manage

    Run ongoing oversight, advice and issue governance.

  4. Assure

    Evidence control and progress for leadership and auditors.

  5. Improve

    Refresh priorities as the organisation and risks change.

Scope boundaries

Included, and separately scoped where required

Included in the core service

  • IG oversight and structured programme management
  • Senior advice and challenge
  • Risk-based prioritisation
  • Leadership and committee reporting

Separately scoped where required

  • Large-scale records remediation or migration
  • Operational administration at scale
  • Specialist cyber or legal deep dives
  • Major implementation programmes

Sample outputs

Example outputs you may receive

Illustrative examples of the reports, registers, dashboards and working records that may be provided, depending on scope.

Illustrative output

Information Governance Dashboard

Ongoing control visibility

A recurring view of ownership, retention and information-risk actions.

What it helps you see and do

  • Information assets and owners
  • Retention exceptions
  • Overdue reviews
  • Information-risk actions
  • Reporting trends

Likely format

  • Dashboard capture
  • IG-Smart branded PDF

Illustrative output

Information Asset & Ownership Register

Accountability

Every key information asset with an accountable owner and review date.

What it helps you see and do

  • Asset
  • Owner
  • Classification
  • Retention
  • Last review

Likely format

  • Spreadsheet / register

Illustrative output

Records & Retention Action Register

Control improvement

Where lifecycle control is incomplete, and what will close the gap.

What it helps you see and do

  • Business area
  • Schedule applied
  • Disposal evidenced
  • Action and owner

Likely format

  • Action tracker

Illustrative output

Board IG Assurance Summary

Executive oversight

A committee-ready view of information risk and progress.

What it helps you see and do

  • Information-risk position
  • Incidents
  • Policy currency
  • Escalations
  • Decisions required

Likely format

  • IG-Smart branded PDF
  • Board pack

Illustrative structure — not a client document. Exact outputs and formats depend on the agreed scope.

Relevant evidence

Relevant evidence

  • Named client · Healthcare / NHS

    NHS England

    Strategic data-privacy and data-sharing advisory

    National privacy-by-design framework · multiple national workstreams

    View the evidence: NHS England
  • Named client · Higher Education / Research

    UCL

    IG audit, improvement plan, training and physical-security audit

    Helped shape and focus the final DSPT submission

    View the evidence: UCL
  • Named client · Financial Services

    AIG

    Supplier data-governance audit

    Nationwide supplier audit

    View the evidence: AIG

Your IG-Smart team

Specialist expertise, coordinated around your requirement

Subject-matter expertise is paired with a clear client and programme contact from initial scoping through delivery.

Subject-matter expert

Michael Abtar

CEO and Founder

Governance, risk and assurance specialist with more than 18 years' experience spanning privacy, cyber resilience, AI governance, digital transformation, healthcare and complex regulated organisations.

Experience includes governance and assurance work involving more than 100 million consumer records.

View profile

Subject-matter expert

Shaista Peart

Senior Data Privacy & Information Governance Consultant

Privacy and information governance specialist advising organisations on data protection, DPO responsibilities and practical governance across healthcare and regulated environments.

View profile

Client & programme contact

Julia Andrade

Head of Client & Programme Success

A key point of contact from prospective-client scoping through programme and project delivery, coordinating practitioners, workstreams and client stakeholders.

View profile

Investment

Scoped to requirement

Delivered as a managed & retained service. Scope, deliverables, assumptions and fees are agreed in writing before work begins.

Talk to a Senior Practitioner How engagements & investment work

Fees reflect factors such as

  • Organisational scale and complexity
  • Number of entities and jurisdictions
  • Scope of retained responsibility
  • Existing maturity
  • Volume of remediation support
  • Required availability
  • Assurance and reporting requirements

Questions

Frequently asked questions

How does this differ from an IG assessment?

An assessment is a defined-scope review of where you stand. Managed Information Governance provides continuing oversight and support so improvements are sustained.

Does it cover data protection?

It covers the governance that data protection depends on. Where formal DPO oversight or a privacy programme is needed, it can be combined with those services with responsibilities kept distinct.

Can it support NHS assurance requirements?

Yes, it can support the governance behind NHS requirements. Where a DSPT submission needs dedicated readiness or assurance work, that is scoped as NHS DSPT Readiness & Assurance.