WhatsApp contact icon for Nathan ISO Consulting
WhatsApp contact icon for Nathan ISO Consulting

Consultants in Dubai, Abu Dhabi & Saudi Arabia

Nathan ISO Consulting implements ISO 24143 information governance frameworks for government entities, financial institutions, healthcare providers and information-intensive organisations across the UAE, Saudi Arabia and the wider GCC.

Organisations across the Gulf now hold more information than at any point in their history, governed by more overlapping obligations than ever — data protection law, sector regulation, records retention requirements, freedom of information regimes, and increasingly the data quality expectations that artificial intelligence adoption exposes. ISO 24143 provides the framework that turns those scattered obligations into a coherent governance discipline rather than a set of disconnected policies owned by different departments.

What Is ISO 24143?

ISO 24143 addresses information governance — the overarching framework of accountability, policy, process and controls determining how an organisation manages information as an asset across its entire lifecycle, from creation through use, storage and sharing to eventual disposal.

It sits above and connects a set of disciplines organisations usually run separately: records management, data protection, information security, data quality, retention and disposal, and access management. The premise is that these overlap so substantially that managing them independently produces contradiction — a retention schedule requiring seven-year storage while a privacy policy commits to deletion on request, or a security classification scheme nobody applies because it was designed without reference to how information actually flows.

Governance componentWhat it addresses
Accountability and rolesWho owns information governance, who owns individual information assets, and how decisions are made and escalated
Policy frameworkA coherent set of policies covering classification, retention, access, quality, sharing and disposal without internal contradiction
Information asset registerWhat information the organisation holds, its value, sensitivity, ownership and lifecycle position
Classification and handlingSensitivity classification applied consistently, with handling rules staff can actually follow
Retention and disposalRetention schedules reflecting legal, regulatory and business requirements, with defensible disposal
Data qualityAccuracy, completeness and timeliness sufficient for the decisions the information supports
Access and sharingWho may access what, under what conditions, including sharing with external parties
Compliance integrationAlignment with data protection, security, sector regulation and records legislation obligations

Why the disciplines need connecting

The clearest illustration is retention. Data protection law requires personal data not be kept longer than necessary. Sector regulation frequently mandates minimum retention periods. Litigation and audit requirements demand preservation. Storage cost and security exposure argue for deletion. These pull in different directions, and an organisation without a governance framework resolves the tension differently in each department — or, more commonly, resolves it nowhere and keeps everything indefinitely, which is the worst outcome on every dimension except convenience.

ISO 24143 information governance consultants in Dubai

Why Information Governance Matters in the UAE and GCC

1. Overlapping regulatory obligations

The UAE Personal Data Protection Law, Saudi PDPL, DIFC and ADGM regimes, sector-specific requirements from health, financial and telecommunications regulators, and government records requirements each impose information obligations. Organisations subject to several simultaneously need a framework reconciling them rather than separate compliance projects producing contradictory rules.

2. Government digital transformation and records requirements

National digital agendas across the region have driven substantial digitisation of government and public sector records, alongside requirements for how those records are managed, retained and made accessible. Entities and their suppliers need governance frameworks that survive scrutiny.

3. AI and analytics readiness

Organisations adopting artificial intelligence and advanced analytics discover quickly that model output quality is bounded by data quality and that training data provenance carries legal implications. Information governance is the discipline that makes data genuinely usable for these purposes rather than technically available but practically unreliable.

4. Storage cost and security exposure

Information retained beyond need costs money to store and creates breach exposure with no offsetting benefit. Defensible disposal reduces both, but requires a retention framework robust enough that deletion decisions can be justified afterwards.

5. Merger, acquisition and due diligence readiness

Transactions expose information governance quickly. Organisations that cannot demonstrate what information they hold, under what obligations, and with what quality face both valuation and integration difficulties.

Nathan ISO Consulting’s Information Governance Services

Information governance maturity assessment

An honest evaluation of current practice across records management, retention, classification, quality and access — including where existing policies contradict each other.

Governance framework and accountability design

Ownership model, decision rights, escalation routes and the governance forum structure through which information decisions actually get made rather than deferred.

Information asset register

What information the organisation holds, where, who owns it, its sensitivity and value, and what obligations attach. This underpins everything else and frequently overlaps directly with the records of processing required under privacy law.

Classification scheme design

A sensitivity classification framework with handling rules staff can genuinely apply. Schemes with too many tiers or unclear boundaries get ignored, which is worse than having none, and we design for actual use rather than theoretical completeness.

Retention schedule development

Retention periods reconciling legal, regulatory, contractual and business requirements across each information category, with the reasoning documented so decisions are defensible later.

Defensible disposal procedures

Disposal processes with authorisation, execution and evidence, including handling of information held in backups, archives and third-party systems where deletion is technically more complex.

Data quality framework

Quality dimensions, measurement, ownership and remediation for the information assets where quality materially affects decisions or regulatory obligations.

Access and sharing governance

Access models, approval processes, third-party sharing arrangements and the controls ensuring information is available to those who need it without being available to those who do not.

Integration with existing certifications

Where ISO 27001, ISO 27701 or ISO 20000 are held, we build information governance as the connective layer above them rather than as a separate structure — which is how the framework is intended to work.

Training and capability development

Information governance awareness across the organisation, information asset owner training, and deeper capability for records and governance staff.

ISO 24143 records management review in Abu Dhabi

Our Implementation Process

  1. Consultation and fixed proposal. Discussion of your information landscape, regulatory obligations and objectives, followed by a fixed written quotation.

  2. Maturity assessment. Current practice reviewed across records, retention, classification, quality and access, with a written findings report.

  3. Scope definition. Which business units, information categories and systems the framework covers.

  4. Governance and accountability design. Ownership model, decision rights and governance forum structure.

  5. Information asset register build. Conducted with business function owners, not as a technology inventory exercise.

  6. Policy framework development. Coherent policy set covering classification, retention, access, quality, sharing and disposal.

  7. Retention schedule build. Category-by-category periods with documented legal and business reasoning.

  8. Classification and handling rollout. Scheme deployed with practical handling guidance and supporting tooling where appropriate.

  9. Disposal procedures. Defensible disposal with authorisation and evidence, including backups and third-party systems.

  10. Training rollout. Organisation-wide awareness plus asset owner and governance staff capability development.

  11. Assurance and review. Internal review arrangements, performance measures and the first governance review cycle facilitated by us.

Why Choose Nathan ISO Consulting

  • We resolve contradictions rather than adding policies. Most organisations already have retention, classification and privacy policies that conflict. Reconciling them is the actual work, and adding another policy on top makes things worse.

  • Asset register built with business owners. Information governance run purely from IT produces a systems inventory, not an information asset register. The distinction matters.

  • Classification designed for actual use. Schemes with too many tiers get ignored. We design something staff will genuinely apply and then measure whether they do.

  • Retention reasoning documented. Deletion decisions must be defensible afterwards. Recording the legal and business basis at the point of decision is what makes disposal defensible rather than risky.

  • Built above your existing certifications. Where ISO 27001 or ISO 27701 exist, information governance connects them rather than duplicating them.

  • Multi-jurisdiction obligation mapping. UAE PDPL, Saudi PDPL, DIFC, ADGM and sector regulation each impose information requirements. We reconcile them into one framework.

  • Practical disposal, including the hard parts. Backups, archives and third-party systems are where deletion commitments most often fail in practice.

  • One dedicated lead consultant throughout. Continuity from maturity assessment through framework embedding.

  • Capability transferred to your team. Asset owner and governance staff training so the framework operates without ongoing external dependence.

  • Fixed written pricing. Agreed upfront with no variation invoices.

Industries We Serve

  • Government and public sector entities. Records legislation, transparency obligations, citizen data and long-term archival requirements.

  • Banking and financial services. Regulatory retention, transaction records, customer data and audit trail obligations.

  • Healthcare providers and payers. Medical records retention, patient data sensitivity, and clinical research data governance.

  • Legal and professional services. Client files, privilege, matter retention and conflict management.

  • Insurance. Policy and claims records with long retention tails and complex access requirements.

  • Energy and utilities. Technical documentation, asset records and regulatory reporting with decades-long retention needs.

  • Education and research. Student records, research data management and publication data requirements.

  • Real estate and construction. Project documentation, as-built records and warranty period retention.

  • Telecommunications. Subscriber data, traffic records and regulatory retention obligations.

Locations We Serve

Dubai

Information governance consultants across Dubai — Business Bay, Deira, Jebel Ali and Dubai South — plus Dubai Internet City, Dubai Healthcare City, Dubai Silicon Oasis, DMCC, JAFZA, DAFZA and DIFC.

Abu Dhabi and Al Ain

Abu Dhabi city, Mussafah, ICAD, KEZAD, Masdar City, Abu Dhabi Global Market, Hub71 and Al Ain — including government entities, healthcare organisations and ADNOC group companies.

Sharjah and the Northern Emirates

Sharjah city, Sharjah Publishing City, Hamriyah Free Zone and SAIF Zone; Ajman and Ajman Free Zone; Ras Al Khaimah and RAKEZ; Umm Al Quwain Free Trade Zone; Fujairah and Fujairah Free Zone.

Saudi Arabia

Riyadh, Jeddah, Dammam, Al Khobar, Dhahran, Mecca, Medina and Tabuk — including government entities, financial institutions and organisations working through Saudi PDPL and sector records obligations.

Qatar, Kuwait, Oman and Bahrain

Qatar — Doha, Lusail, Qatar Free Zones and the Qatar Financial Centre. Kuwait — Kuwait City and Shuwaikh. Oman — Muscat, Knowledge Oasis and Salalah. Bahrain — Manama, Seef and Bahrain Bay.

ISO 24143 information governance framework in Saudi Arabia

What Determines the Cost?

Our consultancy fee is quoted as a fixed sum in writing before engagement, driven by the number of business units and information categories in scope, the volume and age of existing records requiring assessment, the number of regulatory regimes applying, whether existing policies require reconciliation or development from scratch, and whether the framework is built above existing ISO 27001 or ISO 27701 systems.

Where certification against a management system standard is also required, we advise on which certifiable standard delivers it — commonly ISO 27001 for information security or ISO 27701 for privacy — and structure the information governance framework so it supports both rather than running as a separate exercise.

Get Started with Information Governance

For ISO 24143 information governance framework implementation in Dubai, Abu Dhabi, Sharjah, Saudi Arabia, Qatar, Kuwait, Oman or Bahrain, call +971 50 258 5024, email info@nathanisoconsulting.com, or visit our contact page for a maturity assessment and a fixed written proposal.

Frequently Asked Questions About Information Governance

Information security protects information from unauthorised access, disclosure, alteration and destruction. Information governance is broader — it determines what information the organisation should hold at all, for how long, at what quality, who may access it, and when it should be disposed of. Security is one component within governance rather than a synonym for it.

ISO 27001 certifies an information security management system. ISO 24143 provides the governance framework that sits above it, connecting security with records management, retention, data quality and privacy. Organisations holding ISO 27001 typically find the governance framework resolves questions the ISMS raises but does not answer, such as how long information should be retained.

ISO 27701 addresses personal data specifically. ISO 24143 covers all organisational information, personal and otherwise. The information asset register and retention schedule serve both, and organisations implementing both find substantial overlap — the records of processing required for privacy compliance is essentially a subset of the information asset register.

ISO 24143 is oriented toward providing a governance framework and concepts rather than functioning as a certification scheme in the way ISO 9001 or ISO 27001 do. Where you need a certificate, the appropriate route is usually ISO 27001 or ISO 27701, with the information governance framework supporting and connecting them. We will tell you clearly at the outset what can and cannot be certified rather than implying otherwise.

A record of what information the organisation holds — by category rather than by individual document — including its owner, sensitivity, value, location, retention requirement and applicable obligations. It differs from a systems inventory in that it describes the information itself rather than the technology storing it, which is why it must be built with business owners rather than from IT records.

By reconciling legal minimums, regulatory requirements, contractual obligations, litigation and audit needs, and genuine business utility for each information category — then documenting the reasoning. The documentation matters as much as the period, because it is what makes a disposal decision defensible if questioned years later.

Disposal conducted under a documented policy, with proper authorisation, consistent execution and retained evidence — so that if the absence of a record is later questioned, you can demonstrate it was destroyed under a legitimate schedule rather than selectively or in response to a specific dispute. Ad hoc deletion, however well intentioned, is not defensible.

Fewer than most organisations initially want. Schemes with five or six tiers and ambiguous boundaries get applied inconsistently or ignored entirely, which is worse than a simple scheme applied properly. Three or four clearly distinguished levels with practical handling rules is what works in most organisations we implement for.

This is where deletion commitments most commonly fail. Options include backup rotation policies that age out deleted data within a defined window, documented technical limitations communicated transparently, and where necessary, targeted deletion capability. What matters is that your privacy and retention commitments reflect what you can actually achieve rather than what sounds reassuring.

Substantially. Model output quality is bounded by input data quality, and training data provenance carries legal implications around rights, consent and licensing. Organisations attempting AI adoption without governance discover their data is technically available but practically unreliable and legally uncertain, which stalls initiatives after significant investment.

It spans legal, compliance, IT, records management and business functions, so ownership needs authority across all of them — typically a governance, compliance or chief data role reporting to executive level. Ownership placed purely in IT produces a technology-focused programme that never addresses the business decisions the framework exists to resolve.

Records management is a core discipline within information governance, concerned with capturing, maintaining and disposing of records as evidence of activity. Information governance extends beyond records to all information assets and adds the accountability, quality and value dimensions.

This is usually the hardest part, and the honest answer is that comprehensive control of legacy unstructured data is rarely achievable. Practical approaches include applying governance rigorously to newly created information, targeting remediation at the highest-risk repositories, and applying container-level retention rather than attempting document-level classification retrospectively.

Not necessarily to establish the framework, which is primarily a policy, accountability and process exercise. Technology becomes relevant for enforcement at scale — classification tooling, retention automation, discovery capability. We advise on proportionate tooling rather than assuming a purchase is required.

Directly. The information asset register overlaps with records of processing, retention schedules address the storage limitation principle, classification supports the security of processing obligation, and disposal procedures support deletion rights. Organisations implementing both find each substantially reduces the effort required for the other.

It remains within your governance scope where you determine its purposes. Contractual arrangements need to support your retention, deletion, access and quality requirements, and the framework should identify where third-party arrangements do not currently allow you to meet your own commitments — which is a common and consequential finding.

Through indicators such as classification application rates, retention schedule coverage across information categories, disposal executed against schedule, data quality measures for critical assets, access review completion, and the volume of information held beyond its retention period. The last of these is often the most revealing.

Four to nine months for a mid-sized organisation depending on scope, existing maturity and the number of regulatory regimes applying. Building the information asset register with business owners is usually the longest activity, since it requires time from people who have other responsibilities.

Yes. Organisation-wide awareness, information asset owner training, and deeper capability development for records and governance staff are included in our implementation programmes and available standalone.

By reviewing the asset register when new systems or business activities are introduced, updating retention schedules when legal or regulatory requirements change, monitoring classification application, executing disposal on schedule rather than deferring it, and holding governance review at a defined cadence. Frameworks that are established and then left static tend to become inaccurate within about eighteen months.

CONTACT
Reach out to us for any inquiries, collaborations,
or just to say hello!

Contact information for Nathan ISO Consulting

CLIENTELE
Our Valuable Client

WHEN NUMBERS MATTER
Empowering Insights into our Business Performance