Governance / Data privacy

Handle information with a defined purpose.

Our approach is to discuss what information an engagement needs, who should access it and how it should be transferred or returned. Clients should identify sensitive information and applicable handling requirements during scoping.

Our approach

Make the principle useful.

01 / Focus area

Purpose and necessity

Identify who is responsible and how expectations will be communicated within the agreed engagement.

02 / Focus area

Access responsibility

Discuss the information, decisions or approvals needed to put this into practice.

03 / Focus area

Agreed transfer methods

Consider the people and dependencies affected, including any specialist requirements.

04 / Focus area

Return and retention instructions

Agree how the activity or decision will be reviewed and how concerns can be raised.

An approach, not an unsupported assurance.

Our approach is to discuss what information an engagement needs, who should access it and how it should be transferred or returned. Clients should identify sensitive information and applicable handling requirements during scoping.

These principles describe how requirements should be discussed and responsibilities made clear. They are not a claim of certification, independently audited controls or a guarantee of compliance. If your organisation needs formal policies or evidence as part of procurement, request the relevant documentation before agreeing an engagement.

A useful requirement is specific enough to guide action. Describe the expectation, identify who owns it and record how it will be applied within the engagement. Where a client has a policy or a specialist requirement, bring that into the conversation early.

Questions to bring into the conversation.

Agree the scope, the people who can authorise decisions and the practical information needed to begin. Explain any important deadlines, access restrictions or dependencies on other providers. If an assumption is uncertain, make it visible so it can be resolved before it affects delivery.

  • What specific activity or outcome does the requirement concern?
  • Who owns the information, premises or systems involved?
  • Which decisions need approval, and who can provide it?
  • What documents, access arrangements or specialist advice are needed?
  • How will completion, exceptions and follow-up be discussed?

Requirements involving law, regulation or professional obligations may need qualified advice. Agree that need separately. Avoid treating a general statement of intent as evidence that a specific legal or technical requirement has been satisfied.

Keep the result reviewable.

Use the agreed scope as the basis for reviewing the work. Discuss what has been completed, what information is being handed over and who takes responsibility for any continuing activity. If further work is useful, describe it as a new or revised requirement.

Concerns can be raised through the group’s contact details. Give enough context to identify the engagement and issue, while avoiding unnecessary disclosure of sensitive information. The next step should establish who needs to consider the concern and what information they require.

Start a service conversation ↗