Skip to content
Start a conversation
A data governance lead and a compliance officer reviewing access controls together at a desk
Service

Data Governance & Compliance

A regulator will not ask whether you have a data policy. They assume you do. They will ask you to prove that what the policy says is what actually happens, and that is where most organisations struggle. We build the evidence so you can answer on the day.

Book a discovery call

Saying you check something is not the same as being able to show the check happening.

A data quality and control dashboard: rule pass rates against target, open exceptions by age, access by role and subject access request timeliness

What they actually ask for

Across the reviews we have supported, the questions come down to a much shorter list than a long policy document prepares you for.

Where did this number come from?

They will pick a figure from a return you submitted and ask you to trace it back to the original system. If you have proper tracing, that takes minutes. If you have a diagram someone drew, it takes weeks.

Who could have changed it?

Not who has access now, but who had access back in March when the report was produced. Almost nobody can answer this, and it is the gap we find most often.

How would you know if it broke?

They accept that systems fail. What they want to know is whether a wrong figure would be caught before you submitted it, and how.

Show me the last time this went wrong

Saying nothing has ever gone wrong is not the strong answer it sounds like. It suggests you either do not detect problems or do not record them. A good incident log builds confidence.

What we build instead of more paperwork

Automatic tracing of every number

Generated from the code itself, so it stays correct as things change. Anything a person has to remember to update will be out of date within a few months.

A record of who had access, and when

We take a regular snapshot of permissions and keep it. Cheap to start doing today, close to impossible to recreate for a date that has already passed.

Checks on the numbers you report externally

We focus on the figures that leave the organisation and check them for the kinds of errors that produce a believable but wrong answer, which are the dangerous ones.

A real incident log

Every issue recorded, including small ones. It shows a reviewer that you notice problems and deal with them, which is what they are actually assessing.

A named owner for each area

An actual person with an actual stand-in, not a team name or a responsibility three people assume someone else is covering.

Retention and sensitivity built in

Enforced by the system itself, so it happens whether or not anyone remembers the policy exists.

Make the right way the easy way

On one project, definitions were supposed to be recorded in a separate system with its own login that engineers never opened. Only about a third ever got recorded. Reminding people had not worked and was never going to.

  • We moved the definition into the code the engineers already worked in
  • If a definition was missing, the change simply would not go through
  • Within two weeks it was effectively complete, with no training and no chasing
A compliance lead reviewing controls against a wall of data screens

The awkward questions, rehearsed early

We would rather find the gap ourselves, with you, than have a reviewer find it in front of your board.

Common questions

We have just had a difficult review. What should we do?

The instinct is to write more documentation, and that is almost always the wrong move, because the documents were never the problem. It is far more effective to make a small number of things provable automatically.

Which regulations or frameworks do you cover?

Whichever ones apply to you. The underlying work is much the same in each case, because they all ultimately ask you to demonstrate what happens rather than describe it.

Can you cover all of our data?

We would advise against trying, at least at first. Attempting everything at once is the most common reason these programmes stall. Three areas done properly is worth far more than forty done on paper.

The controls this covers

Named frameworks and named controls, so you can check this against your own obligations.

A working conversation at a desk

Access, encryption and anonymisation

Role-based access as standard, with encryption and anonymisation where the data warrants it.

GDPR, HIPAA, CCPA and ISO 27001

We work to whichever apply to you. The underlying engineering is largely the same, because all of them ask you to demonstrate rather than assert.

Data catalogues

One view of what data the organisation holds, generated from the systems rather than compiled by hand.

Live compliance reporting

Dashboards and audit trails showing current status, rather than a report assembled the week before a review.

Financial services

Regulatory reporting and fraud prevention, where being able to trace a figure is the whole requirement.

Manufacturing

Securing supply chain data that moves between organisations.

Ready to turn complexity into your next advantage?

Take one figure from your last submission and try to trace it back to source. If that takes more than an afternoon, you already know where to start.

Book a discovery call