Trust & governance

Arrangements defined before any records change hands.

Public-sector engagements require clarity about who may access what, under what terms, and for how long. The sections below describe how we address that.

01

Confidentiality

Client information is treated as confidential and protected contractually. Confidentiality terms appropriate to each engagement — including separate confidentiality agreements where your organization requires them — are put in place before work begins.

02

Data minimization

We seek to limit the information collected and processed to what is necessary for the agreed scope. Where a review can be completed with extracts, summaries or defined data fields rather than full records, we propose the narrower option.

03

Access and processing

Access permissions, processing environments, authorized personnel and any automated processing arrangements are defined and documented before we receive client data.

04

Exception-based review

Our intended operating model is to work from structured analytical outputs and identified exceptions wherever feasible, minimizing routine human access to underlying financial records.

05

Secure transfer and storage

Transfer methods and storage arrangements appropriate to the sensitivity of the records are agreed upon and documented before an engagement begins.

06

Retention and deletion

Retention periods and data-return or deletion procedures are specified contractually, so it is clear at the outset what is kept, for how long and how it is disposed of.

07

Incident handling

Incident-notification obligations and response procedures are defined in the engagement documents, including who is notified and within what timeframe.

08

Client ownership

Clients retain ownership of their records and the data they provide. We act only within the permissions granted in the engagement documents.

The descriptions above set out our intended governance approach. The specific obligations for any engagement are those recorded in the signed engagement documents.

Review our governance approach with your team.

We are glad to walk through confidentiality, data-handling and retention expectations with your finance, legal or IT colleagues before any scope is agreed.