Provenance Data Risk Partners was founded by Navin Ahuja, a specialist in data control assurance for the Lloyd's and London Market insurance sector, with 16 years designing and auditing data control frameworks across the industry, from building frameworks from scratch to leading audits of divisional and functional CDOs at a Tier 1 bank, as well as design-assessing To Be data controls covering coverholder set-up and bordereaux mapping and ingestion for the Target Operating Model of a leading coverholder-driven carrier.
His experience exposed the same gap, firm after firm: most firms can't trust the data they rely upon for their most critical returns, because they are unaware of its provenance and lack confidence in the controls applied throughout the journey. In a regulatory climate where data carries more weight every year, they would struggle if an audit landed tomorrow.
We close that gap using the Provenance Method: a risk-based approach which produces auditable control design built around your specific data flows - not a governance framework that restricts itself to policy only.
An engagement results in a transparent, defensible basis for assessing the design and strength of the controls over your critical data as it flows throughout your organisation, facilitating conversations with regulators and auditors to satisfy their expectations of due care.
"The most dangerous position is not knowing your framework is inadequate. It is believing it is adequate - and finding out otherwise during a regulatory review."
A discovery call takes 30 minutes. It gives you an honest, independent assessment of where your framework stands and where the most material gaps are likely to lie.
What your auditor is looking for, and what to do before they arrive. The five questions auditors ask, the three places frameworks usually break, and a self-assessment to run before the audit begins.
A control framework that tells you what you already wanted to hear is not providing assurance.
It is providing reassurance - and reassurance is considerably less useful when something goes wrong.
Responsible for the quality and integrity of critical data, but working with frameworks that were built before the current regulatory environment. Provenance Data Risk Partners gives you a defensible, auditable foundation.
Facing regulatory reviews where the gap between a control that exists and a control that works becomes acutely visible. You need a residual risk position you can actually defend - not one that reflects optimism.
Whose outputs - capital models, regulatory returns, financial statements - are only as reliable as the data flowing into them. A framework built by Provenance Data Risk Partners gives you traceability from use case back to source.
Charged with providing independent assurance over data controls - but finding that the frameworks you are asked to assess were not built with auditability in mind. We design frameworks that give second and third line something real to work with.
Start with the Guide to a successful data audit. Then let's have an honest conversation.
No obligation. No sales pitch. Just clarity from someone who has built and audited data control frameworks to ensure that data can be relied upon with confidence.
Not ready for either? Subscribe to Data Risk Fortnightly instead.