Skip to main content
IG-Smart — Governance, Risk & Assurance

Michael Abtar

Founder & Chief Executive Officer

Governance, risk and assurance for organisations where the consequences matter.

  • Governance, Risk & Assurance
  • Privacy
  • Cyber
  • AI Governance
  • Digital Transformation
Speak to IG-Smart

Overview

Michael Abtar is the Founder and Chief Executive Officer of IG-Smart.

A legally trained governance, privacy and assurance specialist, Michael has spent more than 18 years helping organisations navigate complex questions at the intersection of technology, regulation, data, cybersecurity, organisational risk and executive accountability.

His work has included major national technology programmes, multinational organisations, large-scale consumer data environments, healthcare and HealthTech organisations, regulated businesses and organisations undergoing significant digital transformation.

Michael's approach is grounded in a simple principle: governance should do more than demonstrate compliance. It should enable better decisions, stronger accountability and more resilient organisations.

Areas of Expertise

Michael's work spans:

  • Governance, risk and assurance
  • Data protection and privacy
  • Information governance
  • Managed DPO and Privacy Office services
  • Cyber governance and resilience
  • AI governance and assurance
  • Digital transformation governance
  • Regulatory compliance
  • International data governance
  • Third-party and supplier assurance
  • Board reporting and executive assurance
  • Healthcare and HealthTech governance
  • Organisational risk and control frameworks

Selected Experience

NHS national COVID-19 Contact Tracing App

Michael led Legal and Information Governance workstreams supporting the development of the NHS national COVID-19 Contact Tracing App.

The programme required governance and data-protection considerations to be addressed within a highly complex, fast-moving and nationally significant technology environment.

Large-scale GDPR transformation

Michael led the GDPR compliance implementation programme for the UK's largest consumer loyalty database, involving more than 100 million consumer records.

The engagement required privacy requirements to be translated into practical governance across a major data ecosystem.

International Data Protection Officer leadership

Michael has served as Data Protection Officer and senior privacy adviser for multinational organisations, providing strategic guidance across complex organisational and regulatory environments.

NHS governance leadership

His previous leadership roles include Chair of NHS London's Information Governance Forum and Freedom of Information Forum.

Working at the intersection of disciplines

Many of the risks organisations face today cannot be managed within a single professional discipline.

A new technology programme may simultaneously create questions involving:

Privacy. Cybersecurity. AI. Third-party risk. Regulatory compliance. Clinical safety. Data governance. Board accountability.

Michael's role frequently involves bringing these disciplines together and helping leadership teams understand the complete governance picture.

That multidisciplinary perspective underpins IG-Smart's wider methodology:

Assess → Build → Manage → Assure → Improve

Board and Executive Advisory

Michael regularly works with senior leaders who need to convert complex technical or regulatory information into decisions that can be understood and governed at executive or board level.

His work can include:

  • Governance framework design
  • Board and executive risk reporting
  • Regulatory readiness
  • Accountability frameworks
  • Risk appetite and escalation
  • Technology governance
  • Executive assurance
  • Independent challenge
  • Remediation programme oversight
  • Governance following significant incidents or organisational change

The objective is not simply to produce another report.

It is to give leadership teams a defensible basis for action.

Privacy and Information Governance

Michael's background in law, information governance and organisational risk informs IG-Smart's approach to privacy.

Rather than treating privacy as an isolated legal requirement, the firm considers how data protection interacts with technology, security, suppliers, operations, AI, customer trust and executive accountability.

Michael's work in this area includes:

  • DPO leadership
  • Privacy governance
  • Complex DPIAs
  • International data transfers
  • Data governance
  • Privacy risk
  • Accountability frameworks
  • Regulatory response
  • Privacy transformation programmes
  • Privacy by design

Cyber Governance and Resilience

Cybersecurity is increasingly a board and governance issue rather than solely a technical one.

Michael works alongside IG-Smart's cybersecurity specialists to help organisations establish the governance structures needed to understand, manage and demonstrate control over cyber risk.

This can include:

  • Cyber governance
  • Executive cyber assurance
  • Incident governance
  • Cyber risk reporting
  • Supplier assurance
  • Control-framework alignment
  • Security accountability
  • Cyber tabletop exercises
  • Continuous assurance

AI Governance and Assurance

As organisations adopt AI, many are discovering that technical capability is developing faster than organisational governance.

Michael supports organisations in establishing responsible and defensible approaches to AI governance, including:

  • AI governance frameworks
  • Roles and accountability
  • AI risk assessment
  • AI inventory and classification
  • Human oversight
  • Data governance
  • Supplier and model risk
  • Policy development
  • Regulatory readiness
  • AI assurance

Healthcare and HealthTech

Michael has extensive experience working within healthcare governance and digital health environments.

IG-Smart's health capability brings privacy, cyber, clinical safety, information governance and regulatory assurance together so that organisations can address requirements such as NHS DSPT, DTAC, DCB0129 and DCB0160 as part of a coherent governance model rather than isolated compliance exercises.

Leadership Philosophy

Good governance should make organisations more capable, not more bureaucratic.

Michael's focus is on helping organisations create governance that can withstand regulatory scrutiny while still enabling innovation, growth and effective decision-making.

Work with Michael

Michael typically supports:

  • Boards and executive teams
  • General Counsel and legal teams
  • DPOs and privacy leaders
  • CISOs and security teams
  • CIOs and technology leaders
  • Healthcare organisations
  • HealthTech companies
  • AI and technology businesses
  • Organisations undergoing regulatory or digital transformation

Relevant Services

Related Evidence & Insights

Need independent governance or assurance?

Talk to IG-Smart about your governance, risk or assurance requirements.