Navin Ahuja, Founder

Provenance Data Risk Partners was founded by Navin Ahuja, a specialist in data control assurance for the Lloyd's and London Market insurance sector with experience across data, risk management and audit.

With 16 years designing and auditing data control frameworks across the industry:

Building frameworks from scratch for leading London Insurance Market carriers
Leading audits of divisional and functional CDOs at a Tier 1 bank
Assessing design effectiveness of To Be data controls covering coverholder set-up and bordereaux mapping and ingestion for the Target Operating Model of a leading coverholder-driven carrier

His experience exposed the same challenge: many firms are unable to articulate clearly and precisely why the controls they have in place over their most critical data, that used to support regulatory returns and to drive core processes, are adequate.

In a regulatory climate where data carries more weight every year, they would struggle if an audit landed tomorrow.

We close that gap using the Provenance Method: a risk-based approach which produces auditable control design built around your specific data flows - not a governance framework that restricts itself to policy only.

An engagement results in a transparent, defensible basis for assessing the design and strength of the controls over your critical data as it flows throughout your organisation, facilitating conversations with regulators and auditors to satisfy their expectations of due care.

"The most dangerous position is not knowing your framework is inadequate. It is believing it is adequate - and finding out otherwise during a regulatory review."

A discovery call takes 30 minutes. It gives you an honest, independent assessment of where your framework stands and where the most material gaps are likely to lie.

Three steps, starting with the data, not the policy.

01
Map Your Data Flows
We trace the data that matters back from its use, a regulatory return, a capital calculation, a bordereaux, to its source.
02
Assess The Risks
We identify where the risk actually sits within that flow, and where the current framework catches it, if it catches it at all.
03
Define Controls
We design or redesign controls at the point they can catch something, not at the point they are easiest to evidence.
Outcome
A transparent, auditable basis for trusting your data, so conversations with regulators and auditors can be conducted from evidence of strong control design.

Two ways to work together, depending on what you need.

Provenance Method Coaching

I come to you and coach your team directly in the Provenance Method, covering Data Flow Mapping, Risk Identification & Assessment, and Control Design, so the capability stays in-house.

Independent Controls Review

An independent assessment of whether the controls over an end-to-end data flow, for example IFRS 17 calculations, are adequately designed to mitigate the risk within appetite.

Free Guide
How to Survive a Data Audit

What your auditor is looking for, and what to do before they arrive. The five questions auditors ask, the three places frameworks usually break, and a self-assessment to run before the audit begins.

Your details will not be shared with third parties.

A control framework that tells you what you already wanted to hear is not providing assurance.
It is providing reassurance - and reassurance is considerably less useful when something goes wrong.

For the people responsible when something goes wrong.

Chief Data Officers

Responsible for the quality and integrity of critical data, but working with frameworks that were built before the current regulatory environment. Provenance Data Risk Partners gives you a defensible, auditable foundation.

Risk and Compliance Directors

Facing regulatory reviews where the gap between a control that exists and a control that works becomes acutely visible. You need a residual risk position you can actually defend - not one that reflects optimism.

Heads of Actuarial and Finance

Whose outputs - capital models, regulatory returns, financial statements - are only as reliable as the data flowing into them. A framework built by Provenance Data Risk Partners gives you traceability from use case back to source.

Internal Audit and Second Line

Charged with providing independent assurance over data controls - but finding that the frameworks you are asked to assess were not built with auditability in mind. We design frameworks that give second and third line something real to work with.

Is Your Data And The Controls Over It Fit For Purpose?

Start with the Guide to a successful data audit. Then let's have an honest conversation.

No obligation. No sales pitch. Just clarity from someone who has built and audited data control frameworks to ensure that data can be relied upon with confidence.

Subscribe to Data Risk Fortnightly