Information is a critical asset, and organisations increasingly make decisions on the strength of it. That only works when it is managed with controls that keep it accurate, secure and compliant.
Foundations
Information governance
We provide health checks and as-is assessments, and build information governance strategies and frameworks that people can actually follow.
Data
Data management
Enterprise content services, master data management, data architecture, data quality and metadata management. We have built strategies, roadmaps, business cases and multi-year delivery plans around the DMBOK data management framework for public sector clients.
Compliance
Regulatory compliance
Transparency of information and protection of privacy pull in different directions, and finding the balance takes experience. We review your position, recommend, and work with you to implement and transition the changes.
We work across GDPR and UK data protection · DORA · PCI DSS · FCA requirements · NIS2 · ISO 27001 · BS 10008 · NIST
A recent example. A full compliance health check and assurance review for a local government client, followed by alignment of business processes and systems, sponsored by the Chief Information Officer.
Further reading
Regulators, guidance and case law
Information governance moves with the regulator. These are the primary sources we work from, and the ones we recommend clients keep an eye on rather than relying on summaries.
- Information Commissioner’s Office — guidance for organisations on UK GDPR, freedom of information and direct marketing
- ICO enforcement action — fines, reprimands and enforcement notices — the clearest guide to what the regulator cares about
- UK GDPR guidance and resources — the ICO’s working guidance on the UK data protection regime
- Data protection self-assessment — ICO checklists for assessing your own compliance position
