Mark Johnson
Governance, Risk & Compliance Director Senior Information Risk Owner (Siro) @The Access Group
Signup · Get unlimited contacts
WORK HISTORY
Governance, Risk & Compliance Director Senior Information Risk Owner (Siro) @The Access Group
Loughborough, GB
Leading governance, risk and compliance strategy across The Access Group\'s Health, Support & Care division, encompassing SaaS platforms serving NHS mental health and community health trusts, local government and technology-enabled care, and private care providers.As divisional Senior Information Risk Owner (SIRO), I hold accountability for information risk governance, data protection assurance and security oversight across the division\'s portfolio of health and social care technologies — supporting responsible innovation while maintaining the trust of the patients, service users and organisations we serve.My remit spans a complex, multi-framework regulatory environment including clinical safety (DCB0129/0160), medical device compliance (UK MDR, ISO 13485), information governance (DSPT, UK-GDPR), business continuity (ISO 22301), and quality and information security management (ISO 9001, ISO 27001). Current priorities include AI governance for healthcare applications, regulatory intelligence for M&A integration, and embedding proportionate risk management that enables — rather than constrains — product innovation and market growth.I lead a cross-functional GRC team comprising clinical directors, safety officers and compliance specialists, working collaboratively with product, engineering and commercial teams to ensure our technologies meet the highest standards of safety, compliance and clinical governance.
EDUCATION
Coventry University
BEng Hons, Manufacturing and Business Management
SKILLS
ABOUT MARK JOHNSON
An experienced and certified Data Protection & Compliance Officer with a demonstrated history of working with board-level roles in hi-tech Industry supporting Software Development & Technical Service for the Health Care markets.A certified Information Privacy Professional with GDPR practitioner and CIPP/E status working with large volume, personally identifiable, and highly sensitive health care data.Proven history in leading, delivering, and maintaining governance frameworks and management system certifications.
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.