Skip to main content

HealthTech Governance & Clinical Safety

Clinical Safety Consultancy

Clinical safety consultancy helps digital health organisations manage the risk that health IT could cause or contribute to patient harm — so product, deployment and change decisions are evidence-led, proportionate and defensible.

Independent clinical safety consultancy for digital health suppliers, NHS organisations and other health and care providers — from early design through deployment, operation and change.

View relevant evidence — View Relevant Evidence

When this service fits

When this service fits

  • You are developing or changing a health IT system

  • You are deploying digital technology into care pathways

  • You build software-as-a-medical-device or AI-enabled health technology

  • You are adapting an international product for the NHS and UK market

  • You are preparing for DTAC, procurement, pilot deployment or enterprise adoption

  • You are responding to clinical safety findings, incidents, audit actions or material system change

The service

Why does digital clinical safety matter?

Digital clinical safety assurance is the process through which health IT used by care professionals is assessed and governed so that associated clinical risks are identified, controlled and monitored. Clinical safety failures can arise from more than software defects. Risk may also result from poor workflow design, incomplete data, ambiguous alerts, unsafe configuration, weak integration, inadequate training, supplier dependencies or unmanaged change. Effective assurance must therefore connect technology, clinical practice and organisational governance. Typical stakeholders include Chief Clinical Officers, CMIOs, CCIOs, Clinical Safety Officers, Medical Directors, Product Leaders, General Counsel, DPOs, CISOs, Heads of Compliance, Procurement Leads and Board Sponsors.

Two related services

Which service fits?

Choose Clinical Safety Consultancy when you need help assessing gaps or developing and reviewing clinical safety evidence. Choose Clinical Safety Officer Services when you need a named CSO for an agreed project or ongoing arrangement. Where both are needed, we can scope them together.

The work · You are hereClinical Safety ConsultancyAssessing gaps, establishing or improving clinical risk management, facilitating hazard analysis and developing or reviewing agreed safety evidence.
The appointmentClinical Safety Officer ServicesA named CSO for an agreed scope: defined responsibilities, evidence review, change oversight and escalation, for a project or a continuing arrangement.Explore this service

DCB0129

Manufacturer responsibilities

Applies to organisations manufacturing health IT systems: clinical risk management across development, release, maintenance and change of the product.

DCB0160

Deployment and use responsibilities

Applies to health and care organisations deploying and using those systems: local configuration, workflows, training and operational change.

Supplier evidence does not automatically satisfy a deploying organisation’s obligations. Applicability depends on the product, intended use and deployment context; the current published standards remain the operative requirements while NHS England’s review continues.

What changes for your organisation

Outcomes the service is built to deliver

  • Clinical safety governance diagnostic

    A focused review of the product or deployment context, intended use, clinical pathways, current evidence, responsibilities and material safety risks.

  • Hazard identification and analysis

    Facilitated workshops and evidence review to identify credible clinical hazards, causes, controls, affected users and potential patient outcomes.

  • Clinical risk management planning

    A proportionate plan defining scope, methodology, roles, escalation, evidence requirements, review points and approval responsibilities.

  • Hazard log development and quality assurance

    Creation or review of a controlled hazard log that links hazards to causes, controls, owners, residual risk and verification evidence.

  • Clinical safety case and report support

    Structured evidence explaining why the system or deployment is acceptably safe for its intended use, including assumptions, limitations, unresolved issues and required actions.

  • Independent challenge and assurance

    Senior review of the quality, completeness and traceability of clinical safety evidence before release, procurement, deployment or significant change.

  • Ongoing governance and change control

    Support for safety monitoring, incident learning, periodic review, supplier coordination, decommissioning and material product or deployment changes.

What is the engagement approach?

Five steps to defensible safety evidence

Select a step to see what happens and what it produces.

  1. Define the safety context

    Confirm the intended purpose, users, patient population, clinical workflows, operating environment, boundaries, dependencies and applicable assurance obligations.

  2. Review current evidence

    Assess existing plans, hazard logs, safety cases, testing, incident information, supplier evidence and governance records for completeness and consistency.

  3. Identify and evaluate hazards

    Use structured clinical and technical input to identify hazards, estimate risk and test whether controls are effective and evidenced.

  4. Strengthen governance and artefacts

    Close priority gaps, clarify ownership, improve traceability and prepare decision-ready safety documentation.

  5. Assure and maintain

    Provide independent challenge, approval support where within scope, and a sustainable cadence for monitoring, change and continual improvement.

Final risk acceptance and formal approvals remain with appropriately authorised individuals in your organisation, including a suitably qualified Clinical Safety Officer where required. Delivered within IG-Smart’s wider Assess → Build → Manage → Assure → Improve approach.

What each stage produces

  1. Define the safety context

    Agreed safety context and scope.

  2. Review current evidence

    Evidence review and gap findings.

  3. Identify and evaluate hazards

    Hazard workshop outputs and decision log.

  4. Strengthen governance and artefacts

    Hazard log, clinical risk management plan and safety case support.

  5. Assure and maintain

    Assurance report and governance cadence.

What you receive

What clinical safety evidence can we help produce?

Clinical risk management plan · clinical safety case or report · hazard log and risk acceptance record · hazard workshop outputs and decision log · safety requirements and control traceability matrix · assessment or assurance report · roles, responsibilities and escalation matrix · governance cadence and committee terms of reference · change-impact and release safety assessment · incident, post-market or operational safety review · executive or board assurance summary · prioritised remediation roadmap and action tracker. Examples below are illustrative.

DTAC Readiness Dashboard · Pre-buyer reviewIllustrative data — not client data
Overall positionAmber — closing gaps
DTAC areas evidenced
3 / 5
▲ 1 this period
Open evidence gaps
6
▼ 3 vs last review
Responses challenged
18
▲ 12 resolved
Evidence owners assigned
9 / 10
▲ 2 this period

Evidence gaps by buyer impact

  • High1
  • Medium3
  • Low2

Evidence complete

68%

Overdue actions
2
Documents awaiting sign-off
3
Matters for escalation
1

Illustrative output

DTAC Readiness Dashboard

Readiness at a glance

A single view of readiness across the five DTAC areas, so gaps are closed before an NHS buyer reviews the form.

What it helps you see

  • Readiness across the five DTAC areas
  • Open evidence gaps by buyer impact
  • Readiness challenge progress
  • Evidence owners and sign-off status

Likely format

Dashboard / reporting view · Supporting registers and evidence records · Executive PDF summary where agreed

Clinical hazard logIllustrative data — not client data
Illustrative Clinical hazard log
HazardControlOwnerResidual risk
Hazard AControl specified and testedClinical leadAcceptable
Hazard BControl proposed, not evidencedProduct leadUnder review
Hazard CControl owned by deploying organisationDeployment leadTransferred

Illustrative output

Clinical hazard log

Hazard traceability

Hazards linked to causes, controls, owners, residual risk and verification evidence.

What it helps you see

  • Each hazard
  • Cause and control
  • Owner
  • Residual risk

Likely format

Control traceability matrixIllustrative data — not client data
Illustrative Control traceability matrix
RequirementHazardEvidenceStatus
Requirement AHazard ATest recordVerified
Requirement BHazard BPendingOpen
Requirement CHazard CSupplier evidenceUnder review

Illustrative output

Control traceability matrix

Safety requirements

Every safety requirement traced to a hazard and verification evidence.

What it helps you see

  • Safety requirement
  • Linked hazard
  • Verification evidence
  • Status

Likely format

Change-impact assessmentIllustrative data — not client data
Illustrative Change-impact assessment
ChangeImpactNew hazardsDecision
Change ANone—Proceed
Change BWorkflow altered1Conditions set
Change CNew intended use2Safety case update

Illustrative output

Change-impact assessment

Release safety

Whether a release or change alters the clinical risk profile.

What it helps you see

  • Change
  • Clinical risk impact
  • New hazards
  • Decision

Likely format

Illustrative structure — not a client document. Exact outputs and formats depend on the agreed scope.

Scope boundaries

What is included — and what remains with your organisation

What IG-Smart does

  • Facilitate clinical risk management
  • Draft or review clinical safety artefacts
  • Coordinate stakeholders across product, clinical and technical teams
  • Provide independent assurance

Not included unless expressly agreed

  • No guarantee of procurement acceptance, regulatory approval or a harm-free system
  • Statutory, regulatory, clinical and operational responsibilities (retained by you)
  • Final risk acceptance and formal approvals (retained by authorised individuals)
  • Legal advice
  • Medical-device conformity assessment
  • Product, penetration or accessibility testing
  • Your own clinical governance and incident-management responsibilities

Scope, deliverables and assumptions are agreed in writing before work begins.

Relevant evidence

Related NHS & HealthTech evidence

Selected published engagements demonstrating relevant governance, assurance and NHS/HealthTech capability. They are not presented as clinical safety engagements unless the underlying approved case evidence expressly states that.

  • Named client · Technology / SaaS / RegTech

    Clini-Hub

    Embedded governance and clinical-safety support since start-up

    NHS AI Toolkit, DSPT, DTAC and clinical-safety governance from start-up

    View the evidence: Clini-Hub
  • Named client · Technology / SaaS / RegTech

    accurx

    Retained DPO and NHS IG support

    Retained DPO services · privacy and NHS information-governance support during growth

    View the evidence: accurx
  • Named client · Life Sciences / Pharmaceutical

    UCL

    IG audit, improvement plan, training and physical-security audit

    Helped shape and focus the final DSPT submission

    View the evidence: UCL
  • Named client · Healthcare / NHS

    NHS England

    Strategic data-privacy and data-sharing advisory

    National privacy-by-design framework · multiple national workstreams

    View the evidence: NHS England

Your IG-Smart team

Specialist expertise, coordinated around your requirement

Subject-matter expertise is paired with a clear client and programme contact from initial scoping through delivery.

  • Clinical Safety Officer and health informatics specialist

    Himanshu Desai

    MSc, MBA, MRPharmS

    Specialist expertise in health informatics, prescribing and medication-management systems. Has completed the Digital Clinical Safety – Practitioner course, provided and accredited by NHS England and CPD.

    View profile
  • Service lead — clinical safety governance and multidisciplinary assurance

    Michael Abtar

    LLB (Hons), PG.Dip.Law, Cert. DPO

    Leads the service, drawing on his experience as Clinical Safety Officer at Royal Brompton & Harefield and coordinating clinical safety with information governance, privacy, cyber assurance and organisational accountability.

    View profile
  • Senior healthcare governance adviser; Chair, Independent Advisory Board

    Professor Dame Donna Kinnair DBE

    Senior strategic advice through an agreed escalation arrangement, where patient-safety, organisational or public-accountability concerns are significant.

    View profile
  • Client & programme contact

    Julia Andrade

    Coordinates scope, practitioners, delivery and stakeholder communication.

    View profile

Practitioner credentials

Himanshu Desai MSc, MBA, MRPharmS

Himanshu Desai has completed the Digital Clinical Safety – Practitioner course, provided and accredited by NHS England and CPD. His certificate of attendance is available on request.

Clinical safety training
Digital Clinical Safety – Practitioner
Provider
NHS England (accredited by NHS England and CPD)
Evidence
Certificate of attendance signed by the Clinical Director for Patient Safety; available upon request

Course completion is training, not a separate professional certification, and does not by itself satisfy every formal CSO appointment requirement or imply NHS endorsement of IG-Smart.

Request Clinical Safety Training Evidence

Senior escalation

Professor Dame Donna Kinnair DBE

For engagements involving significant patient-safety, organisational or public-accountability concerns, senior strategic advice from Professor Dame Donna Kinnair can be included through an agreed escalation arrangement. Her contribution provides healthcare leadership perspective and challenge alongside the appointed CSO and accountable client leaders.

Advisory involvement is agreed according to the engagement’s scope and availability, and is separate from her Independent Advisory Board role.

Buyer decisions

Questions before you engage

Do all digital health products require DCB0129 or DCB0160?

Not every digital solution requires the same level of formal clinical safety assurance. Applicability depends on the product, intended use, deployment context and potential effect on patient safety. An early applicability and scoping review is the safest starting point.

What qualifications should a Clinical Safety Officer have?

NHS guidance describes a Clinical Safety Officer as a suitably qualified clinician with current professional registration and relevant risk-management experience. The person should also be appropriately trained for the clinical safety role and able to exercise independent professional judgement.

Can you review clinical safety evidence prepared by another supplier or consultancy?

Yes. We can provide an independent quality and traceability review, identify material gaps and recommend proportionate remediation. The review does not transfer ownership of the underlying evidence or risk decisions.

Can you support AI-enabled or software-as-a-medical-device products?

Yes, subject to scope and specialist requirements. Clinical safety should be coordinated with AI governance, data protection, cyber security and medical-device responsibilities rather than treated as a standalone workstream.

When should clinical safety work begin?

At the start of product design, procurement or deployment. Early involvement makes hazards easier to control and reduces the risk of discovering fundamental safety issues immediately before release or go-live.

Are DCB0129 and DCB0160 changing?

NHS England began a national review of both standards in 2026. Organisations should continue working to the current published requirements while monitoring official updates and planning controlled transition when revised standards are issued.

Investment

Defined clinical safety projects from £7,500 + VAT.

Fees depend on clinical risk, system complexity, existing evidence and the support required. Scope, deliverables, responsibilities, available capacity and fees are agreed in writing before work begins. Onboarding, initial safety-case development and substantial remediation are quoted separately where required. Existing evidence is reviewed and reused wherever appropriate. Focused reviews and complex programmes are individually scoped.

What organisations should expect

  • Clearer clinical safety accountability across product, clinical, technical and executive teams
  • Earlier identification of hazards before procurement, release or deployment
  • More complete and traceable safety evidence for DCB0129, DCB0160 and DTAC-related scrutiny
  • Better informed risk acceptance and go-live decisions
  • Reduced rework caused by fragmented documentation or late clinical input
  • A reusable clinical safety capability that supports change, monitoring and incident learning
  • Greater confidence for boards, buyers, commissioners and clinical governance reviewers

Procurement or supplier-assurance review?

Visit our Trust Centre

Ready to move forward?

Build clinical safety into every critical decision.

Not sure which service applies? Find the Right Service

  • Still defining your requirement?

    Discuss Your Clinical Safety Project

    Discuss the requirement, risk, scope and the right engagement model with an experienced practitioner.

    Discuss Your Clinical Safety Project
  • Have a defined scope, tender or RFP?

    Request a Clinical Safety Proposal

    Share a defined requirement, RFP, tender, statement of work or existing scope for senior review.

    Request a Clinical Safety Proposal
  • Procurement or supplier assurance

    Prepare for Procurement Review

    Access company, security and assurance information for supplier review, with controlled evidence available on request.

    Open Trust Centre