Skip to main content
IG-Smart — Governance, Risk & Assurance

NHS & HealthTech Assurance

HealthTech Governance for Safer NHS and Regulated Adoption

Turn fragmented safety, privacy, security and procurement requirements into one defensible assurance position.

Talk to a Senior PractitionerStill defining the requirement
Submit a RequirementDefined scope, tender or RFP

IG-Smart helps digital-health suppliers and health and care organisations understand what applies, close assurance gaps and build the evidence needed for safer deployment, NHS procurement and continuing oversight.

From and digital clinical safety to , privacy, cyber security and procurement evidence, we connect the requirements instead of treating each as a separate compliance exercise.

HealthTech governance consultancy helps digital-health suppliers and healthcare organisations identify, manage and evidence the safety, privacy, cyber, clinical and procurement requirements that affect NHS adoption and use. IG-Smart connects requirements such as DTAC, , and relevant NHS assurance into a coherent evidence and governance programme.

When organisations engage us

When organisations engage us

  • Preparing to sell into the NHS

    The product is ready, but the assurance position is fragmented or incomplete.

  • DTAC evidence is incomplete

    Responses exist, but supporting evidence or controls need strengthening.

  • Clinical safety needs specialist support

    DCB0129, DCB0160, hazard management or CSO capability is required.

  • A procurement deadline is approaching

    Evidence needs prioritising without creating unsupported claims.

  • A technology is being deployed

    The care organisation must assess supplier evidence and local clinical risk.

  • The product has materially changed

    New functionality, integrations, AI or context may affect existing assurance.

  • The technology spans several frameworks

    Teams need one view of overlapping safety, privacy, cyber and procurement requirements.

  • A Board or buyer needs assurance

    Leadership needs to see what is complete, outstanding and accepted as residual risk.

What we help solve

One technology can trigger several assurance requirements

Organisations rarely struggle because documentation is missing. More often:

  • Responsibility for assurance is fragmented
  • DTAC evidence is assembled late in procurement
  • Supplier and deploying-organisation responsibilities become confused
  • Clinical safety is treated as a document rather than a lifecycle
  • Privacy, cyber, clinical safety and procurement teams work separately
  • The same evidence is recreated for every buyer
  • Product changes are not reflected in safety or assurance evidence
  • Supplier evidence is accepted without local deployment assessment
  • Boards cannot see what is complete, outstanding or accepted as risk
  • Evolving NHS requirements are difficult to track

The underlying issue

The problem is rarely one missing document. It is fragmented assurance across requirements that depend on each other.

A DTAC response, safety case or DSPT return has more value when it reflects a functioning governance system rather than a procurement deadline.

What the engagement involves

Build the evidence needed for safer adoption and procurement

Talk to a Senior Practitioner

HealthTech assurance map

What might a HealthTech product need to evidence?

DTAC
Digital Technology Assessment Criteria
DCB0129
Clinical risk management: manufacturers of health IT
DCB0160
Clinical risk management: deployment and use of health IT
DSPT
Data Security and Protection Toolkit
CAF
NCSC Cyber Assessment Framework
MHRA
Medicines and Healthcare products Regulatory Agency
NICE ESF
NICE Evidence Standards Framework

Digital health technology

Clinical Safety

DCB0129 / DCB0160 where applicable

Data Protection & IG

UK data-protection requirements, DPIAs, information governance

Cyber Security

Technical security, supplier assurance, relevant DSPT / NHS requirements

Interoperability

Standards, integration, data exchange and implementation dependencies

Usability & Accessibility

User needs, accessibility and safe practical use

Procurement & Buyer Evidence

DTAC responses, tender evidence, assurance packs and remediation

Medical-Device Regulation

Where intended purpose brings the product within applicable regulation

AI Governance

Where AI or algorithmic functionality adds governance, safety or regulatory considerations

Requirements depend on the product, intended purpose, organisation, deployment context and procurement route. Not every requirement applies to every technology.

Two assurance pathways

Are you supplying the technology — or deploying it?

Supplier and deploying-organisation obligations are related, but not interchangeable.

HealthTech supplier / manufacturer

Typical questions

  • What does the product do?
  • What evidence will NHS buyers expect?
  • Does DCB0129 apply?
  • What DTAC evidence exists?
  • Are privacy and cyber positions sufficiently evidenced?
  • Does medical-device regulation need separate specialist consideration?
  • Can procurement answers be substantiated?
  • How are product changes reflected in assurance evidence?
I supply HealthTech

NHS / health & care deploying organisation

Typical questions

  • What supplier evidence has been obtained?
  • Does DCB0160 apply?
  • What local hazards arise from deployment or configuration?
  • Has the DPIA / IG position been addressed?
  • Does the technology affect DSPT or cyber scope?
  • Are continuity and clinical workflow impacts understood?
  • Who accepts residual clinical risk?
  • What continuing monitoring is required?
I am deploying HealthTech

DTAC

What does DTAC assess?

The Digital Technology Assessment Criteria provide a common approach for assessing digital-health technologies across five areas:

  • 01

    Clinical Safety

  • 02

    Data Protection

  • 03

    Technical Assurance

  • 04

    Interoperability

  • 05

    Usability & Accessibility

DTAC is an assessment framework, not an accreditation badge. Completing a response does not remove the need to determine which underlying legal, clinical, security or organisational requirements apply.

Digital clinical safety

Clinical safety runs through the technology lifecycle

  1. 01Supplier / developer

    DCB0129

    Clinical risk management in the manufacture and development of health IT systems. Relevant evidence may include:

    • Clinical risk-management process
    • Clinical Safety Officer involvement
    • Clinical risk-management plan
    • Hazard identification and hazard log
    • Risk controls
    • Clinical safety case
    • Change and post-deployment considerations
  2. 02

    Handover / assurance evidence

  3. 03Deploying NHS / care organisation

    DCB0160

    Clinical risk management when health and care organisations deploy and use health IT systems. Relevant areas may include:

    • Review of supplier safety evidence
    • Local deployment hazards
    • Configuration and workflow
    • Risk controls and hazard management
    • Clinical safety case
    • Operational ownership
    • Ongoing monitoring and change

Supplier clinical-safety evidence does not automatically discharge the deploying organisation's own clinical-risk responsibilities.

Organisational assurance

Where does DSPT fit?

The Data Security and Protection Toolkit is organisational assurance. It does not substitute for product-specific DTAC or clinical-safety work.

The -aligned DSPT integrates cyber-security and information-governance outcomes for relevant health and care organisations. Not every HealthTech supplier is assessed through the same process as an NHS trust.

The DSPT continues to evolve, including expectations on resilience, essential-function scoping and recovery. The relevant model depends on organisation type and current NHS requirements.

Data Security and Protection Toolkit (opens in a new tab)

CAF-aligned outcome areas

  1. AManaging risk
  2. BProtecting against cyber attacks and data breaches
  3. CDetecting cyber-security events
  4. DMinimising the impact of incidents
  5. EUsing and sharing information appropriately
Discuss a DSPT requirement

NHS procurement readiness

Evidence should be ready before the tender arrives

NHS and health-sector buyers may require evidence across several disciplines during procurement or onboarding.

The objective is not polished answers that cannot be evidenced. It is to make the underlying assurance position procurement-ready.

A buyer-ready pack may draw from

  • Product description and intended purpose
  • DTAC
  • Clinical-safety evidence
  • Privacy / DPIA information
  • Cyber-security evidence
  • Interoperability
  • Accessibility and usability
  • Supplier governance
  • Business continuity
  • Subprocessors and supply chain
  • Medical-device status, where relevant
  • AI governance, where applicable
  • Remediation plans and outstanding risks

Regulatory intersections

Where other frameworks may also apply

Does medical-device regulation also apply?

Some software and AI used in health and care may qualify as medical devices, depending on intended purpose and classification rules. Where relevant, medical-device regulation sits alongside — not in place of — NHS assurance such as DTAC or clinical safety. Definitive classification requires appropriate specialist expertise.

MHRA: software and AI as a medical device (opens in a new tab)

Clinical and economic evidence may matter too

NICE's Evidence Standards Framework for digital health technologies may be relevant to developers, evaluators and commissioners assessing effectiveness and value. Meeting it does not mean NICE endorsement or regulatory approval.

NICE Evidence Standards Framework (opens in a new tab)

AI can add another assurance layer

AI-enabled HealthTech may raise further questions around:

  • Intended purpose
  • Clinical safety
  • Data protection
  • Cyber security
  • Human oversight
  • Performance and monitoring
  • Bias and fairness
  • Model or supplier changes
  • Medical-device status
  • AI regulatory obligations

AI governance should integrate with clinical safety rather than run as a separate policy exercise. See AI Governance & Assurance.

Operating model

HealthTech assurance requires joined-up ownership

The objective is not another committee. It is ensuring each requirement has an accountable owner and that material risks converge into one decision-making process.

Example only — not a mandatory NHS structure
  1. Board / Executive Sponsor
  2. Product / Programme Governance
  3. Specialist input:
    • Clinical Safety
    • Privacy / DPO
    • Cyber Security
    • Information Governance
    • Technical / Architecture
    • Procurement / Commercial
  4. Product Owner / Supplier / Implementation Team
  5. Evidence input:
    • Evidence
    • Decisions
    • Risks
    • Remediation
    • Change
  6. ↺ Executive / Buyer Assurance

How we deliver

How IG-Smart approaches a HealthTech assurance engagement

  1. 01

    Assess

    Identify the technology, intended use, deployment context, applicable assurance requirements, existing evidence, accountable owners and material gaps.

  2. 02

    Build

    Develop the governance, safety, privacy, cyber, procurement and evidence components needed to address the agreed scope.

  3. 03

    Manage

    Coordinate assurance activity, evidence ownership, risks, actions, governance cadence and changes across relevant disciplines.

  4. 04

    Assure

    Review whether requirements and controls are sufficiently evidenced and whether outstanding risks are clear to decision-makers and buyers.

  5. 05

    Improve

    Close findings, update evidence and adapt the assurance position as the technology, deployment and NHS requirements change.

Improvement feeds the next assessment cycle, keeping HealthTech evidence current rather than rebuilding it for every procurement exercise.

What you receive

What does a HealthTech Governance & Clinical Safety engagement produce?

Depending on product, role, deployment and scope, outputs may include:

  1. 01Applicable-requirements mapA documented view of the assurance requirements relevant to the technology and context.
  2. 02Current-state / gap assessmentClear findings across applicable governance, clinical-safety, privacy, cyber and procurement requirements.
  3. 03Prioritised remediation planActions sequenced by materiality, dependency, procurement impact, effort and owner.
  4. 04Clinical-safety evidenceHazard-management and safety artefacts where DCB0129/DCB0160 support is within scope.
  5. 05DTAC evidence packStructured evidence and responses mapped to relevant DTAC criteria.
  6. 06Governance and decision recordsAccountability, approvals, risk decisions and accepted residual risk.
  7. 07Procurement / buyer assurance packDefensible evidence organised for tender, due diligence or NHS buyer scrutiny.
  8. 08Continuing-assurance planDefined review triggers for product, regulatory, supplier and deployment change.

Scope

Integrated assurance — with clear professional boundaries

IG-Smart can support

  • HealthTech governance
  • DTAC readiness and gap analysis
  • Digital clinical-safety consultancy
  • DCB0129 / DCB0160 assurance support
  • CSO services, where appropriately scoped
  • Privacy and information-governance assurance
  • NHS procurement readiness
  • Cyber governance coordination
  • Evidence development
  • Remediation oversight
  • Continuing assurance

Not implied by default

  • NHS approval or endorsement
  • Accredited certification
  • Medical-device regulatory approval
  • DTAC “certification”
  • Guaranteed procurement success
  • Legal opinions outside professional scope
  • Full penetration testing unless commissioned
  • Software-development responsibility
  • Guaranteed compliance

Where the requirement needs specialist medical-device, legal, clinical or technical expertise beyond the agreed IG-Smart scope, the appropriate delivery model is identified during scoping and responsibilities are made explicit in the proposal.

Relevant evidence

Selected NHS and health-sector engagements

Published engagements involving national NHS information governance advice, DSPT readiness and health and care data governance.

Explore all case studies →Request Relevant Evidence →

Common engagement models

Readiness, assessment or ongoing support?

  • Readiness and assessment

    Defined-scope DSPT or DTAC readiness work: gap assessment, evidence review and a prioritised plan. IG-Smart does not award NHS approval or DTAC certification.

    Suits

    Suppliers and care organisations preparing for NHS procurement or annual assurance.

  • Clinical-safety support

    Support with DCB0129 or DCB0160 clinical-risk management and evidence, scoped to the product or deployment.

    Suits

    Manufacturers and deploying organisations that need proportionate clinical-safety evidence.

  • Governance support and independent assurance

    Ongoing governance support or an independent review of the assurance position across DSPT, DTAC, clinical safety and data protection.

    Suits

    Organisations that need continuing senior support or an independent view before a key decision.

Typical investment

Indicative investment

  • DSPT / NHS assurance

    Starting investment: £7,500 + VAT

    Typical investment: £10,000–£25,000+ + VAT

    Model: Defined-scope engagement

  • DTAC readiness / assurance

    Starting investment: £7,500 + VAT

    Typical investment: £7,500–£10,000 + VAT

    Depending on scope and existing evidence

    Model: Defined-scope engagement

Scope, deliverables, assumptions and fees are agreed in writing before work begins. What changes the fee is set out on the investment page; the exact fee is confirmed after scoping.

How engagements and investment work

FAQ

Frequently asked questions

NHS and regulatory references reviewed September 2026. This page is reviewed every 3 months.

Discuss a HealthTech assurance requirement

Need to make your HealthTech assurance position clearer and more defensible?

Whether the requirement starts with DTAC, clinical safety, NHS procurement, deployment assurance or several overlapping frameworks, begin with the evidence and decisions you need to demonstrate.