Governance Beyond Regulation
Compliance alone is insufficient. Governance shapes patients, staff, and public trust — long before it satisfies a regulator.
"Ethics is not a checklist: compliance will never be enough."
IG: Beyond Compliance is a thought-leadership platform where I explore the intersection of information governance, AI ethics, digital transformation, accountability and public trust — with 40+ articles drawn from years of NHS practice.
It doesn't just explain governance. It examines how governance shapes the way power, innovation and trust operate — in practice.
For more background, updates and my latest thinking, visit Nahida Rahman on LinkedIn.

I started the newsletter because too much of what I read about information governance felt sanitised, regulatory, or dangerously optimistic about AI. I wanted a space for honest, practitioner-led thinking — for the questions we ask each other quietly, and rarely in public.
Every fortnight I publish an article that challenges readers to think beyond compliance and look squarely at the ethical, human and strategic implications of the decisions we make with data.
"Trust is built long before a breach occurs — and tested long after it is forgotten."
A distilled map of the ideas that run through every issue.
Compliance alone is insufficient. Governance shapes patients, staff, and public trust — long before it satisfies a regulator.
"Ethics is not a checklist: compliance will never be enough."
How do we enable LLMs, automation and digital transformation in healthcare without losing accountability, transparency and trust?
"AI governance is already failing — we're just not calling it failure yet."
Public confidence is earned through ethical data use and transparent decisions — and it can be dismantled by a single governance choice.
"Trust is built long before a breach occurs and tested long after it is forgotten."
Who actually has authority to accept or override risk in complex healthcare systems? Governance is a question of responsibility, not process.
"When governance says no, but power says yes — who owns the consequences?"
Policies meet real lives. Ethical fatigue, organisational culture, and the lived experience of governance professionals all matter here.
"Every data decision has a human consequence, even when that consequence is invisible."
DPIAs, FOI, cyber risk, data sharing, secondary use — balancing innovation with patient safety, drawn from 15+ years inside the NHS.
"The most significant governance risks are often not technical failures, but failures of accountability."
Information governance is not about saying no; it is about creating the conditions for safe and trusted innovation.
Good governance lives in the tension between opportunity and responsibility.
Behind every DPIA, risk register, and policy decision are people whose lives may ultimately be affected by the choices we make.
The newsletter is free. The comments — from CIOs, DPOs, clinicians, researchers and policy leads — are where the real thinking happens. I'd love your voice in there.
Prefer a private conversation about a specific challenge? nahida@igbeyondcompliance.com
You can also find more about my work and connect with me on Nahida Rahman | LinkedIn.

Author
Nahida Rahman