Digital Gnome
TECHNOLOGY ASSURANCE

Tell us who you are and we’ll cut the rest

One tool for the whole job, from a locked laptop to a signed policy. Answer two questions and we’ll show you only what fits, priced for your size.

1 · HOW MANY OF YOU?
2 · WHAT DO YOU DO? OPTIONAL
✓ NO CARD NEEDED ✓ FREE FOREVER FOR SMALL TEAMS ✓ BUILT IN WALES
Your business
LIVE PREVIEW
YOUR PLAN
WHAT YOU’D GET
← Back to news
STANDARDS 25 JUL 2026 · 3 MIN

DSPT: the two assertions that fail most often

Across the toolkits we help complete, the same two assertions trip people up. Fix training completion and leaver offboarding and most of the rest follows.

RHODRI EMRYS · ASSURANCE
SHARE LinkedIn X Email
STANDARDS cover image

The Data Security and Protection Toolkit looks large from the outside, and organisations often brace for a marathon. In practice the same two assertions cause most of the grief, and neither is technical. They are training completion and leaver offboarding: proving that your people have actually done their data-security training, and proving that when someone leaves, their access to everything goes with them.

Training fails not because it was not delivered but because it cannot be evidenced. ‘We covered it in a team meeting’ is not a record. What the toolkit wants is a name, a date, and completion for everyone in scope, including part-timers, the bank staff and the person who started last week. If you cannot produce that list on demand, the assertion is unmet however good the actual training was.

Leaver offboarding fails because it is nobody's single job. Someone leaves, HR knows, the rota knows, but the shared inbox, the clinical system, the building fob and the parent app each depend on a different person remembering. Weeks later an active login belongs to someone who no longer works there. That is the finding auditors reach for, because a live account with no owner is the classic route in.

Fix these two properly and the toolkit stops feeling like a wall. Keep a simple training register you update as people join, and a one-page leaver checklist that lists every system to switch off and who owns switching it off. Both are admin, not IT projects, and both turn a shaky assertion into one you can evidence in a minute.

WHAT TO DO
  • ✓Keep a training register: every person in scope, with a completion date.
  • ✓Write a one-page leaver checklist listing every system and account to disable.
  • ✓Assign a single owner to run the leaver checklist on someone's last day.
  • ✓Audit current accounts now and close any that belong to people who have left.