Sector · Financial Services & Insurance
Governance and supplier assurance for financial services and insurance
Financial-services firms rely on suppliers, platforms and outsourced services that handle customer data on their behalf. We help insurers and financial-services businesses evidence how that data is governed, and build data protection into new platforms from the start.
Lead evidence
AIG
Supplier data-governance audit
Nationwide supplier audit
2 published cases in this sector
What is at stake
What makes governance difficult here
- Data held by third parties
- Records and customer data held by suppliers remain the firm's responsibility. Assurance needs to come from evidence, not contract wording alone.
- New platforms, built correctly
- New products and digital platforms are easier to govern when data protection is designed in rather than added before launch.
- Security and resilience scrutiny
- Boards, customers and partners expect security and resilience to be tested and reported clearly.
Where IG-Smart helps
The services that matter in this sector
- Cyber Governance & Supplier AssuranceFor independent supplier audits and cyber assurance where customer data sits with third parties.
- Information Governance ConsultancyFor records, retention and data-governance controls that hold up to audit.
- Fractional & Outsourced DPO ServicesFor firms that need DPO capability and data protection by design while the business is being built.
Common requirements
Requirements and frameworks buyers commonly encounter
Depending on the type of firm, its activities and regulatory perimeter, relevant requirements and supervisory expectations may include operational resilience, outsourcing and third-party risk management requirements set by the FCA and/or PRA. Other requirements may also apply:
- UK GDPR and the Data Protection Act 2018
- FCA and/or PRA operational resilience, outsourcing and third-party risk management requirements, for firms in scope
- ISO/IEC 27001, where buyers or partners require it
For firms in scope, these can include matters such as:
- Important business services
- Impact tolerances
- Mapping and testing
- Third-party dependencies
- Outsourcing governance
- Due diligence
- Ongoing oversight
- Business continuity and exit planning
Relevant evidence
Published work in this sector
How clients engage
Ways organisations in this sector work with us
Defined engagements
Assessment, audit, readiness, remediation, assurance and defined programmes.
Managed & retained capability
Ongoing specialist governance and assurance where continuity matters.
Procurement & trust
