Governance
Who decides and who is accountable?
- roles
- decision rights
- committees
- escalation
- ownership
Independent Assurance & Board Reporting
Turn complex governance, risk and control information into evidence your Board can understand, challenge and act on.
IG-Smart helps regulated and high-consequence organisations assess governance effectiveness, strengthen accountability, prepare for audit or regulatory scrutiny and give Boards a clearer view of material risk, controls, remediation and residual exposure.
Our work connects assessment, evidence, independent challenge and reporting — so assurance supports decisions rather than becoming another layer of administration.
When organisations engage us
Committees receive reports, but material risks, control effectiveness and residual exposure remain difficult to see.
Evidence, ownership and control gaps need to be understood before formal review.
Remediation addresses symptoms without resolving the governance cause.
Leadership needs to understand how new requirements affect accountability, controls and evidence.
Existing arrangements no longer match organisational scale, complexity or risk.
Technology, operating-model, supplier or organisational change has altered the assurance position.
Management needs a view beyond self-assessment.
Governance and risk need to be assessed consistently across multiple businesses.
What we help solve
Most organisations already have plenty of governance material:
Yet leadership can still struggle to answer basic Board questions:
The underlying issue
The problem is often not lack of information. It is lack of a coherent assurance position.
A Board pack becomes more valuable when evidence, control effectiveness, unresolved findings and residual risk can be traced to clear ownership and decisions.
What the engagement involves
Help Boards understand material risk, controls, evidence, findings and residual exposure in a decision-ready format.
Assess how effectively accountability, controls, reporting and governance evidence operate and identify priority improvements.
Benchmark whether governance arrangements can withstand scrutiny, disruption, audit, regulatory pressure or supplier failure.
Define practical roles, decision rights, committees, escalation, assurance responsibilities and accountability.
Identify weak evidence, ownership gaps and control issues before formal audit or assurance activity exposes them.
Strengthen the evidence, accountability and control position required to respond credibly to regulatory scrutiny.
Turn complex governance, risk and assurance information into concise dashboards, scorecards, action trackers and decision-ready Board packs.
Give investors and portfolio leaders clearer visibility of governance, privacy, cyber, AI, supplier and resilience risk across portfolio companies.
Definition
Governance assurance is the structured use of assessment, evidence, monitoring and independent challenge to determine whether accountability, risk management, controls and oversight are operating as intended. It gives Boards and accountable executives a clearer basis for understanding material risks, evaluating remediation and making defensible decisions.
Who decides and who is accountable?
What could prevent the organisation achieving its objectives and what manages that exposure?
What evidence supports confidence in the position?
What does leadership need to understand and decide?
Strong governance connects all four.
Board line of sight
A Board should be able to follow the line from the risk being managed to the evidence supporting the assurance conclusion.
Assurance is strongest when management evidence, control effectiveness, independent challenge, findings and residual risk can be traced to the decision the Board is being asked to make.
Executive assurance
What exposures could materially affect objectives, obligations or critical services?
Who owns each material risk and control?
Which controls matter most to the position being assured?
What evidence shows those controls are operating as intended?
Where does confidence come from — and where are the gaps?
Which weaknesses remain unresolved?
Are actions progressing at the required pace?
What remains exposed and who has accepted it?
Decision-ready assurance tells the Board what the position means, not merely what activity occurred.
Reporting and assurance
Organises and communicates relevant information. May include:
Evaluates whether the information and underlying evidence support sufficient confidence in the position. May include:
The strongest Board packs bring reporting and assurance together without pretending they are interchangeable.
Assurance map
01
02
03
04
Board / Audit & Risk Committee
Organisational resilience
Organisational resilience is reflected in the ability to maintain effective decision-making, accountability and critical obligations during:
Resilience is not simply business continuity. It includes the governance capability to make accountable decisions when normal assumptions stop holding.
Governance maturity
Governance responds mainly when problems arise.
Key roles, policies and processes exist.
Governance arrangements are embedded in routine activity.
Evidence demonstrates whether controls and governance are functioning.
Governance changes as risks, regulation, technology and business models evolve.
Increasing maturity
The maturity model is used diagnostically, not as a universal scoring claim. Scores are only produced against an agreed assessment methodology.
Audit readiness
Recurring audit difficulty often results from:
Audit readiness should strengthen the underlying governance position rather than simply prepare documents for an auditor.
Regulatory assurance
Organisations may need to demonstrate:
Applicable requirements depend on sector, organisation and regulatory perimeter. IG-Smart does not apply one generic framework to every client.
Reference points
The UK Corporate Governance Code 2024 applies to companies listed in the FCA commercial companies category or closed-ended investment funds category. The Code applies for financial years beginning on or after 1 January 2025, with Provision 29 applying from 1 January 2026.
Provision 29 requires the Board to monitor the company's risk-management and internal-control framework and review its effectiveness at least annually. The Board's annual-report declaration relates to controls it determines to be material, including relevant financial, operational, reporting and compliance controls.
FRC: UK Corporate Governance Code (opens in a new tab)FRC: Corporate Governance Code Guidance (opens in a new tab)
Large private companies within scope of the Companies (Miscellaneous Reporting) Regulations 2018 must disclose their corporate-governance arrangements. The Wates Principles provide one recognised framework that eligible companies may use for that purpose; they are not universally applicable or mandatory as the only governance framework.
Good-governance guidance, statutory obligations and sector regulatory requirements are different things. Which apply depends on the organisation, its sector and its contractual and investor commitments.
Cross-domain assurance
The Board does not experience these risks as separate website service pages. Assurance should show how they interact at organisational level.
Specialist depth is available through Fractional & Outsourced DPO Services, Information Governance Consultancy, Cyber Governance & Assurance, AI Governance & Assurance and NHS & HealthTech Assurance.
Portfolio governance
The objective is a comparable assurance view while preserving the context of each portfolio company.
Investors may need visibility across:
How we deliver
Establish the governance context, material risks, accountability, controls, evidence, assurance coverage, findings and decision needs.
Define governance structures, control ownership, assurance methods, reporting, escalation and evidence requirements.
Support the governance rhythm — risk reviews, action tracking, assurance coordination, committee reporting and remediation oversight.
Independently assess whether governance arrangements, controls and evidence support the conclusions being reported to leadership.
Close findings, strengthen maturity, update evidence and adapt governance as risks, regulation and organisational priorities change.
Improvement feeds the next assessment cycle, keeping the assurance position current rather than recreating it for every audit, Board cycle or regulatory review.
What you receive
Depending on the requirement and organisational maturity, outputs may include:
Board reporting & assurance packs
IG-Smart does not simply format existing management information. The objective is to improve the quality of the assurance reaching decision-makers.
Board packs can include, where appropriate:
Scope
The nature and degree of independence required depends on the purpose of the engagement; IG-Smart's governance assurance should not be interpreted as a statutory audit or regulated audit opinion.
Where formal audit, legal, certification or specialist technical opinions are required, IG-Smart can work alongside the relevant independent professionals while maintaining clear role boundaries.
Relevant evidence
Published engagements that produced independent maturity, integration and assurance evidence for senior leadership.
Cyber Governance & Assurance
A FTSE 100 organisation
Global security policies didn't reflect UK practice ahead of a third-party security maturity assessment.
The client's CTO describes the work as focused, knowledgeable and timely.
Read the case studyMedia / Entertainment, Data Privacy & DPO · Cyber Governance & Assurance
A US-based global music and entertainment group with an active acquisition strategy
A global entertainment group acquiring businesses frequently needed each new entity brought into one governance framework.
A retained governance partner since 2018.
Read the case studyFinancial Services, Information Governance · Cyber Governance & Assurance
AIG
An insurer needed assurance that its offsite records-storage supplier protected client data across its UK facilities.
AIG’s Head of Client Services EMEA: “the results exceeded our expectations… The audit not only identified areas of improvement…”
Read the case studyCommon engagement models
A defined-scope, independent review of a governance area, control environment or board reporting, with findings the board can act on.
Suits
Boards and committees that need an objective view on a specific area or decision.
Assurance planned across several domains or periods, with consistent reporting and follow-up of agreed actions.
Suits
Organisations building an assurance map or responding to audit, regulatory or investor expectations.
Typical investment
Starting investment: £10,000 + VAT
Typical investment: £12,500–£35,000+ + VAT
Model: Defined-scope engagement
Scope, deliverables, assumptions and fees are agreed in writing before work begins. What changes the fee is set out on the investment page; the exact fee is confirmed after scoping.
How engagements and investment workFAQ
Governance references reviewed September 2026. This page is reviewed every 6 months.
Discuss a governance assurance requirement
Whether the requirement starts with Board assurance, audit readiness, governance maturity, regulatory scrutiny or reporting, begin with the position leadership needs to understand or demonstrate.