NHS Mersey Internal Audit Agency www.miaa.co.uk
NHS MIAA Page Spacer

IM & T Assurance


Information Governance

Information governance is more than just an annual return!

Covering the areas of confidentiality, records management and security Information Governance (IG) is at the core of delivering high quality healthcare.  Having the right information, available, to the right individuals and the right time is critical to clinical and corporate decision making.At MIAA we have extensive experience, gleaned from working not just with our clients but with Connecting for Health and, previously, the NHS Information Authority, in assisting clients in delivering against the IG agenda.  We can provide input at a variety of levels from assurance regarding the appropriateness and validity of annual returns through to delivering major improvement projects.

A number of the key areas of where we have added value in supporting clients include:-

Assurance on the validity of returns

At the most basic level, we have provided assurance to Boards, Audit Committees and senior managers that the scores submitted by the organisation are valid and represent a reasonable picture of the position.  Generally, we undertake such work in liaison with the IG lead as draft submissions are being prepared.  This allows us to provide comments to the organisation prior to submission, ensuring that the final submission is accurate and can be substantiated with suitable evidence.

Collation of returns

Collation of evidence and defining scores for the submission of a toolkit return can be a labour intensive exercise, if done in a robust manner, and one which an organisation may struggle to resource given other pressures.  To assist our clients we have provided staff with extensive IG experience to project manage and deliver a draft IG submission, supported by appropriate evidence, for ratification and formal submission by the client.

Improvement roadmaps

There is more to IG improvement than merely raising the scores year-on-year. Real improvement is a more detailed exercise; it requires corporate buy-in and activities that go to more detailed levels that the IG toolkit requires.We have assisted a number of organisations in developing “real world” improvement plans which will delivery operational benefit to the organisation beyond the improvement in a toolkit return.  As part of this process, using our extensive library of policies, procedures and best practice, we are also able to provide the organisation with template solutions for local tailoring and adoption to address elements of the improvement plans.

Delivering improvement projects

For many organisations resources, whether in quantity or skill sets, to support improvement are scarce.  We have worked with many of our clients to deliver major improvement projects to support the business and, ultimately, to improve IG scores.

Examples of this work include:-Writing policies and procedures based on best practice but tailored to local need

  • Writing and implementing full information security management systems which have been certified to ISO 27001
  • Writing full business continuity plans
  • Undertaking full information security risk assessment
  • Delivering information security training

As with all of our services, assignments are tailored to meet your individual needs.  We would be happy to discuss your needs and to develop a solution to meet them.

For more information please contact us.


 


Internal Audit

Consultancy

Training & Development

Capital
Organisational Development

Foundation Trusts

Anti Fraud



Delivering IM & T Assurance





Tailoring a solution to meet your needs