Skip to main content
IG-Smart — Governance, Risk & Assurance

Independent Assurance & Board Reporting

Board-Ready Governance Assurance and Organisational Resilience

Turn complex governance, risk and control information into evidence your Board can understand, challenge and act on.

Talk to a Senior PractitionerStill defining the requirement
Submit a RequirementDefined scope, tender or RFP

IG-Smart helps regulated and high-consequence organisations assess governance effectiveness, strengthen accountability, prepare for audit or regulatory scrutiny and give Boards a clearer view of material risk, controls, remediation and residual exposure.

Our work connects assessment, evidence, independent challenge and reporting — so assurance supports decisions rather than becoming another layer of administration.

When organisations engage us

When organisations engage us

  • Board visibility is fragmented

    Committees receive reports, but material risks, control effectiveness and residual exposure remain difficult to see.

  • Audit or regulatory scrutiny is approaching

    Evidence, ownership and control gaps need to be understood before formal review.

  • Findings keep recurring

    Remediation addresses symptoms without resolving the governance cause.

  • Regulation is changing

    Leadership needs to understand how new requirements affect accountability, controls and evidence.

  • Growth has outpaced governance

    Existing arrangements no longer match organisational scale, complexity or risk.

  • A major transformation is underway

    Technology, operating-model, supplier or organisational change has altered the assurance position.

  • Independent challenge is required

    Management needs a view beyond self-assessment.

  • Investors need portfolio visibility

    Governance and risk need to be assessed consistently across multiple businesses.

What we help solve

More reporting does not automatically create more assurance

Most organisations already have plenty of governance material:

  • Risk registers
  • Compliance reports
  • Policies
  • Dashboards
  • Audit findings
  • Committee papers
  • Remediation trackers
  • Management attestations
  • Technical assessments

Yet leadership can still struggle to answer basic Board questions:

  • Which risks actually matter?
  • Who is accountable?
  • Which controls are material?
  • Are those controls operating effectively?
  • What evidence supports that conclusion?
  • Which findings remain unresolved?
  • Is remediation on track?
  • What residual risk remains?
  • Who has accepted that risk?
  • What does the Board need to decide?

The underlying issue

The problem is often not lack of information. It is lack of a coherent assurance position.

A Board pack becomes more valuable when evidence, control effectiveness, unresolved findings and residual risk can be traced to clear ownership and decisions.

What the engagement involves

Strengthen governance from assessment through Board assurance

Talk to a Senior Practitioner

Definition

What is governance assurance?

Governance assurance is the structured use of assessment, evidence, monitoring and independent challenge to determine whether accountability, risk management, controls and oversight are operating as intended. It gives Boards and accountable executives a clearer basis for understanding material risks, evaluating remediation and making defensible decisions.

Governance

Who decides and who is accountable?

  • roles
  • decision rights
  • committees
  • escalation
  • ownership

Risk & Control

What could prevent the organisation achieving its objectives and what manages that exposure?

  • risks
  • controls
  • owners
  • tolerance
  • treatment

Assurance

What evidence supports confidence in the position?

  • assessment
  • monitoring
  • testing
  • review
  • independent challenge

Board Reporting

What does leadership need to understand and decide?

  • material issues
  • trends
  • findings
  • remediation
  • residual risk
  • decisions

Strong governance connects all four.

Board line of sight

From organisational risk to Board decision

A Board should be able to follow the line from the risk being managed to the evidence supporting the assurance conclusion.

Assurance is strongest when management evidence, control effectiveness, independent challenge, findings and residual risk can be traced to the decision the Board is being asked to make.

Line of sight from strategic objective to Board decision
  1. 01Strategic objective
  2. 02Material risk
  3. 03Accountable owner
  4. 04Material controls
  5. 05Evidence / assurance
  6. 06Findings & remediation
  7. 07Residual risk
  8. 08Board decision / risk acceptance

Executive assurance

What should the Board be able to see?

  • Material risks

    What exposures could materially affect objectives, obligations or critical services?

  • Accountability

    Who owns each material risk and control?

  • Material controls

    Which controls matter most to the position being assured?

  • Control effectiveness

    What evidence shows those controls are operating as intended?

  • Assurance coverage

    Where does confidence come from — and where are the gaps?

  • Findings

    Which weaknesses remain unresolved?

  • Remediation

    Are actions progressing at the required pace?

  • Residual risk

    What remains exposed and who has accepted it?

Decision-ready assurance tells the Board what the position means, not merely what activity occurred.

Reporting and assurance

Board reporting and Board assurance are related — but not the same

Reporting

Organises and communicates relevant information. May include:

  • KPIs / KRIs
  • Risk movement
  • Incidents
  • Findings
  • Action status
  • Compliance activity

Assurance

Evaluates whether the information and underlying evidence support sufficient confidence in the position. May include:

  • Independent assessment
  • Control testing
  • Evidence review
  • Gap analysis
  • Challenge
  • Residual-risk evaluation

The strongest Board packs bring reporting and assurance together without pretending they are interchangeable.

Assurance map

Where should assurance come from?

  1. 01

    Management evidence

    • control ownership
    • monitoring
    • attestations
    • metrics
  2. 02

    Risk / compliance / governance oversight

    • challenge
    • monitoring
    • review
    • policy oversight
  3. 03

    Independent assurance

    • internal audit
    • independent assessment
    • specialist testing
    • external review
  4. 04

    External evidence

    • certification
    • regulator feedback
    • customer assurance
    • supplier evidence

Board / Audit & Risk Committee

  1. Decision
  2. Remediation
  3. Risk acceptance
  4. Further assurance
The purpose is not to maximise assurance activity. It is to understand whether material risks have sufficient and proportionate assurance. Not every organisation needs every source.

Organisational resilience

Governance should withstand more than routine operations

Organisational resilience is reflected in the ability to maintain effective decision-making, accountability and critical obligations during:

  • Regulatory scrutiny
  • Incidents
  • Supplier failure
  • Cyber disruption
  • Executive turnover
  • Rapid growth
  • Acquisition / restructuring
  • Audit
  • Material control failure
  • Major regulatory change

Resilience is not simply business continuity. It includes the governance capability to make accountable decisions when normal assumptions stop holding.

  1. 01Understand
  2. 02Prepare
  3. 03Withstand
  4. 04Respond
  5. 05Recover
  6. 06Learn

Governance maturity

Governance maturity is visible in behaviour, not document volume

  1. 01

    Reactive

    Governance responds mainly when problems arise.

  2. 02

    Defined

    Key roles, policies and processes exist.

  3. 03

    Operating

    Governance arrangements are embedded in routine activity.

  4. 04

    Assured

    Evidence demonstrates whether controls and governance are functioning.

  5. 05

    Adaptive

    Governance changes as risks, regulation, technology and business models evolve.

Increasing maturity

The maturity model is used diagnostically, not as a universal scoring claim. Scores are only produced against an agreed assessment methodology.

Audit readiness

Audit readiness starts before the evidence request

Recurring audit difficulty often results from:

  • Unclear ownership
  • Evidence assembled too late
  • Controls documented differently from how they operate
  • Previous findings not fully closed
  • Inconsistent risk acceptance
  • Weak decision records
  • Remediation trackers without accountable owners
  • No clear evidence trail

Audit readiness should strengthen the underlying governance position rather than simply prepare documents for an auditor.

Regulatory assurance

Regulatory scrutiny tests evidence as well as intention

Organisations may need to demonstrate:

  • Accountable ownership
  • Appropriate governance structures
  • Control effectiveness
  • Evidence of monitoring
  • Documented decisions
  • Remediation
  • Escalation
  • Risk acceptance
  • Board oversight

Applicable requirements depend on sector, organisation and regulatory perimeter. IG-Smart does not apply one generic framework to every client.

Reference points

Current UK governance expectations

UK Corporate Governance Code 2024 and Provision 29

The UK Corporate Governance Code 2024 applies to companies listed in the FCA commercial companies category or closed-ended investment funds category. The Code applies for financial years beginning on or after 1 January 2025, with Provision 29 applying from 1 January 2026.

Provision 29 requires the Board to monitor the company's risk-management and internal-control framework and review its effectiveness at least annually. The Board's annual-report declaration relates to controls it determines to be material, including relevant financial, operational, reporting and compliance controls.

Read the full position
  • What constitutes a material control is company-specific. The FRC does not prescribe a universal list, and the degree of additional assurance required is a matter for the individual Board to determine.
  • Governance consultancy is distinct from statutory audit.

FRC: UK Corporate Governance Code (opens in a new tab)FRC: Corporate Governance Code Guidance (opens in a new tab)

Large private-company governance

Large private companies within scope of the Companies (Miscellaneous Reporting) Regulations 2018 must disclose their corporate-governance arrangements. The Wates Principles provide one recognised framework that eligible companies may use for that purpose; they are not universally applicable or mandatory as the only governance framework.

FRC: Wates Principles (opens in a new tab)

Good-governance guidance, statutory obligations and sector regulatory requirements are different things. Which apply depends on the organisation, its sector and its contractual and investor commitments.

Cross-domain assurance

Board assurance increasingly crosses traditional governance silos

The Board does not experience these risks as separate website service pages. Assurance should show how they interact at organisational level.

Specialist depth is available through Fractional & Outsourced DPO Services, Information Governance Consultancy, Cyber Governance & Assurance, AI Governance & Assurance and NHS & HealthTech Assurance.

  • Data Privacy
  • Information Governance
  • Cyber Security
  • AI Governance
  • HealthTech / Clinical Safety
  • Supplier Risk
  • Operational Resilience
  • Regulatory Compliance

Portfolio governance

Portfolio governance needs comparable evidence without forcing every company into the same model

The objective is a comparable assurance view while preserving the context of each portfolio company.

Investors may need visibility across:

  • Governance maturity
  • Cyber
  • Privacy
  • AI
  • Supplier risk
  • Regulatory exposure
  • Management actions
  • Residual risk

How we deliver

How IG-Smart approaches a governance assurance engagement

  1. 01

    Assess

    Establish the governance context, material risks, accountability, controls, evidence, assurance coverage, findings and decision needs.

  2. 02

    Build

    Define governance structures, control ownership, assurance methods, reporting, escalation and evidence requirements.

  3. 03

    Manage

    Support the governance rhythm — risk reviews, action tracking, assurance coordination, committee reporting and remediation oversight.

  4. 04

    Assure

    Independently assess whether governance arrangements, controls and evidence support the conclusions being reported to leadership.

  5. 05

    Improve

    Close findings, strengthen maturity, update evidence and adapt governance as risks, regulation and organisational priorities change.

Improvement feeds the next assessment cycle, keeping the assurance position current rather than recreating it for every audit, Board cycle or regulatory review.

What you receive

What does a governance assurance engagement produce?

Depending on the requirement and organisational maturity, outputs may include:

  1. 01Governance assurance current-state assessmentA documented view of material governance, control, evidence and assurance gaps.
  2. 02Risk and accountability mapClear ownership of material risks, controls, escalation and decision rights.
  3. 03Assurance mapVisibility of where confidence comes from, duplication exists and important assurance gaps remain.
  4. 04Prioritised remediation planActions sequenced by materiality, dependency, effort and accountable owner.
  5. 05Board / executive assurance packDecision-ready reporting on risks, control effectiveness, findings, remediation and residual exposure.
  6. 06Evidence packRelevant evidence structured for Board, audit, procurement or regulatory scrutiny.
  7. 07Risk-acceptance / decision recordA defensible record of significant residual-risk and governance decisions where required.
  8. 08Continuous-assurance planMonitoring, review triggers, ownership and governance cadence for maintaining the position.

Board reporting & assurance packs

Turn governance complexity into Board-ready assurance

IG-Smart does not simply format existing management information. The objective is to improve the quality of the assurance reaching decision-makers.

Board packs can include, where appropriate:

  • Executive summary
  • Material-risk position
  • Risk movement
  • Control-effectiveness view
  • Assurance status
  • Overdue findings
  • Remediation progress
  • Accepted residual risk
  • Decisions required
  • Trend indicators
  • Accountable owners

Scope

Independent assurance — with clear professional boundaries

IG-Smart can support

  • Independent governance assessment
  • Board assurance
  • Governance maturity
  • Governance operating models
  • Audit readiness
  • Regulatory assurance
  • Board reporting
  • Assurance mapping
  • Evidence review
  • Remediation oversight
  • Risk / control accountability
  • Portfolio governance
  • Continuous assurance

Not implied by default

  • Statutory external audit
  • Internal-audit outsourcing unless expressly contracted
  • Legal opinion
  • Regulator approval
  • Certification
  • Financial-statement audit opinion
  • Guaranteed audit outcomes
  • Guaranteed regulatory compliance
  • Transfer of Board or management accountability to IG-Smart

The nature and degree of independence required depends on the purpose of the engagement; IG-Smart's governance assurance should not be interpreted as a statutory audit or regulated audit opinion.

Where formal audit, legal, certification or specialist technical opinions are required, IG-Smart can work alongside the relevant independent professionals while maintaining clear role boundaries.

Relevant evidence

Selected assurance engagements relevant to boards

Published engagements that produced independent maturity, integration and assurance evidence for senior leadership.

Explore all case studies →Request Relevant Evidence →

Common engagement models

Independent review or phased assurance?

  • Independent assurance review

    A defined-scope, independent review of a governance area, control environment or board reporting, with findings the board can act on.

    Suits

    Boards and committees that need an objective view on a specific area or decision.

  • Phased assurance programme

    Assurance planned across several domains or periods, with consistent reporting and follow-up of agreed actions.

    Suits

    Organisations building an assurance map or responding to audit, regulatory or investor expectations.

Typical investment

Indicative investment

  • Independent Assurance / Board Reporting

    Starting investment: £10,000 + VAT

    Typical investment: £12,500–£35,000+ + VAT

    Model: Defined-scope engagement

Scope, deliverables, assumptions and fees are agreed in writing before work begins. What changes the fee is set out on the investment page; the exact fee is confirmed after scoping.

How engagements and investment work

FAQ

Frequently asked questions

Governance references reviewed September 2026. This page is reviewed every 6 months.

Discuss a governance assurance requirement

Need a clearer, more defensible view of your governance position?

Whether the requirement starts with Board assurance, audit readiness, governance maturity, regulatory scrutiny or reporting, begin with the position leadership needs to understand or demonstrate.