IG-Smart helps digital-health suppliers and health and care organisations understand what applies, close assurance gaps and build the evidence needed for safer deployment, NHS procurement and continuing oversight.
From DTACThe Digital Technology Assessment Criteria — a common NHS approach for assessing digital-health technologies across clinical safety, data protection, technical security, interoperability, and usability and accessibility. and digital clinical safety to DSPTThe Data Security and Protection Toolkit — organisational assurance over data security and information governance. It does not substitute for product-specific assessment., privacy, cyber security and procurement evidence, we connect the requirements instead of treating each as a separate compliance exercise.
NHS Assurance
Digital Clinical Safety
DTAC Readiness
Governance & Evidence
Procurement Readiness
HealthTech governance consultancy helps digital-health suppliers and healthcare organisations identify, manage and evidence the safety, privacy, cyber, clinical and procurement requirements that affect NHS adoption and use. IG-Smart connects requirements such as DTAC, DCB0129The NHS standard for clinical risk management in the manufacture of health IT systems — it applies to suppliers and manufacturers., DCB0160The companion standard for clinical risk management by health and care organisations deploying and using health IT. Related to DCB0129, but not interchangeable. and relevant NHS assurance into a coherent evidence and governance programme.
When organisations engage us
When organisations engage us
Preparing to sell into the NHS
The product is ready, but the assurance position is fragmented or incomplete.
DTAC evidence is incomplete
Responses exist, but supporting evidence or controls need strengthening.
Clinical safety needs specialist support
DCB0129, DCB0160, hazard management or CSO capability is required.
A procurement deadline is approaching
Evidence needs prioritising without creating unsupported claims.
A technology is being deployed
The care organisation must assess supplier evidence and local clinical risk.
The product has materially changed
New functionality, integrations, AI or context may affect existing assurance.
The technology spans several frameworks
Teams need one view of overlapping safety, privacy, cyber and procurement requirements.
A Board or buyer needs assurance
Leadership needs to see what is complete, outstanding and accepted as residual risk.
What we help solve
One technology can trigger several assurance requirements
Organisations rarely struggle because documentation is missing. More often:
Responsibility for assurance is fragmented
DTAC evidence is assembled late in procurement
Supplier and deploying-organisation responsibilities become confused
Clinical safety is treated as a document rather than a lifecycle
Privacy, cyber, clinical safety and procurement teams work separately
The same evidence is recreated for every buyer
Product changes are not reflected in safety or assurance evidence
Supplier evidence is accepted without local deployment assessment
Boards cannot see what is complete, outstanding or accepted as risk
Evolving NHS requirements are difficult to track
The underlying issue
The problem is rarely one missing document. It is fragmented assurance across requirements that depend on each other.
A DTAC response, safety case or DSPT return has more value when it reflects a functioning governance system rather than a procurement deadline.
What the engagement involves
Build the evidence needed for safer adoption and procurement
01
NHS DTAC Readiness
Prepare evidence across the relevant DTAC domains and close gaps before NHS buyer scrutiny.
02
DTAC Gap Analysis
Assess existing evidence against DTAC expectations and convert gaps into a prioritised remediation plan.
03
Digital Health Compliance Consultancy
Coordinate privacy, clinical safety, cyber, governance and other relevant assurance requirements around the technology and its intended deployment.
04
NHS Procurement Readiness
Prepare buyer-ready evidence for NHS tenders, procurement reviews, due diligence and assurance questions.
05
Clinical Safety Consultancy
Strengthen the clinical-risk management processes, governance and evidence supporting safer digital-health development and deployment.
06
DCB0129 Assurance
Support manufacturers and suppliers with proportionate clinical-risk management and DCB0129 evidence.
07
DCB0160 Assurance
Support health and care organisations with clinical-risk governance when deploying and using health IT.
08
Clinical Safety Officer Services
Provide access to specialist Clinical Safety Officer capability for clinical-risk management, hazard review, safety evidence and governance.
Standards, integration, data exchange and implementation dependencies
Usability & Accessibility
User needs, accessibility and safe practical use
Procurement & Buyer Evidence
DTAC responses, tender evidence, assurance packs and remediation
Medical-Device Regulation
Where intended purpose brings the product within applicable regulation
AI Governance
Where AI or algorithmic functionality adds governance, safety or regulatory considerations
Requirements depend on the product, intended purpose, organisation, deployment context and procurement route. Not every requirement applies to every technology.
Two assurance pathways
Are you supplying the technology — or deploying it?
Supplier and deploying-organisation obligations are related, but not interchangeable.
HealthTech supplier / manufacturer
Typical questions
What does the product do?
What evidence will NHS buyers expect?
Does DCB0129 apply?
What DTAC evidence exists?
Are privacy and cyber positions sufficiently evidenced?
Does medical-device regulation need separate specialist consideration?
Can procurement answers be substantiated?
How are product changes reflected in assurance evidence?
The Digital Technology Assessment Criteria provide a common approach for assessing digital-health technologies across five areas:
01
Clinical Safety
02
Data Protection
03
Technical Assurance
04
Interoperability
05
Usability & Accessibility
DTAC is an assessment framework, not an accreditation badge. Completing a response does not remove the need to determine which underlying legal, clinical, security or organisational requirements apply.
The Data Security and Protection Toolkit is organisational assurance. It does not substitute for product-specific DTAC or clinical-safety work.
The CAFThe NCSC Cyber Assessment Framework — a structured set of cyber-security and resilience outcomes used to assess organisations.-aligned DSPT integrates cyber-security and information-governance outcomes for relevant health and care organisations. Not every HealthTech supplier is assessed through the same process as an NHS trust.
The DSPT continues to evolve, including expectations on resilience, essential-function scoping and recovery. The relevant model depends on organisation type and current NHS requirements.
Some software and AI used in health and care may qualify as medical devices, depending on intended purpose and classification rules. Where relevant, medical-device regulation sits alongside — not in place of — NHS assurance such as DTAC or clinical safety. Definitive classification requires appropriate specialist expertise.
NICE's Evidence Standards Framework for digital health technologies may be relevant to developers, evaluators and commissioners assessing effectiveness and value. Meeting it does not mean NICE endorsement or regulatory approval.
AI-enabled HealthTech may raise further questions around:
Intended purpose
Clinical safety
Data protection
Cyber security
Human oversight
Performance and monitoring
Bias and fairness
Model or supplier changes
Medical-device status
AI regulatory obligations
AI governance should integrate with clinical safety rather than run as a separate policy exercise. See AI Governance & Assurance.
Operating model
HealthTech assurance requires joined-up ownership
The objective is not another committee. It is ensuring each requirement has an accountable owner and that material risks converge into one decision-making process.
Example only — not a mandatory NHS structure
Board / Executive Sponsor
Product / Programme Governance
Specialist input:
Clinical Safety
Privacy / DPO
Cyber Security
Information Governance
Technical / Architecture
Procurement / Commercial
Product Owner / Supplier / Implementation Team
Evidence input:
Evidence
Decisions
Risks
Remediation
Change
↺ Executive / Buyer Assurance
How we deliver
How IG-Smart approaches a HealthTech assurance engagement
01
Assess
Identify the technology, intended use, deployment context, applicable assurance requirements, existing evidence, accountable owners and material gaps.
02
Build
Develop the governance, safety, privacy, cyber, procurement and evidence components needed to address the agreed scope.
03
Manage
Coordinate assurance activity, evidence ownership, risks, actions, governance cadence and changes across relevant disciplines.
04
Assure
Review whether requirements and controls are sufficiently evidenced and whether outstanding risks are clear to decision-makers and buyers.
05
Improve
Close findings, update evidence and adapt the assurance position as the technology, deployment and NHS requirements change.
Improvement feeds the next assessment cycle, keeping HealthTech evidence current rather than rebuilding it for every procurement exercise.
What you receive
What does a HealthTech Governance & Clinical Safety engagement produce?
Depending on product, role, deployment and scope, outputs may include:
01Applicable-requirements mapA documented view of the assurance requirements relevant to the technology and context.
02Current-state / gap assessmentClear findings across applicable governance, clinical-safety, privacy, cyber and procurement requirements.
03Prioritised remediation planActions sequenced by materiality, dependency, procurement impact, effort and owner.
04Clinical-safety evidenceHazard-management and safety artefacts where DCB0129/DCB0160 support is within scope.
05DTAC evidence packStructured evidence and responses mapped to relevant DTAC criteria.
06Governance and decision recordsAccountability, approvals, risk decisions and accepted residual risk.
07Procurement / buyer assurance packDefensible evidence organised for tender, due diligence or NHS buyer scrutiny.
08Continuing-assurance planDefined review triggers for product, regulatory, supplier and deployment change.
Scope
Integrated assurance — with clear professional boundaries
IG-Smart can support
HealthTech governance
DTAC readiness and gap analysis
Digital clinical-safety consultancy
DCB0129 / DCB0160 assurance support
CSO services, where appropriately scoped
Privacy and information-governance assurance
NHS procurement readiness
Cyber governance coordination
Evidence development
Remediation oversight
Continuing assurance
Not implied by default
NHS approval or endorsement
Accredited certification
Medical-device regulatory approval
DTAC “certification”
Guaranteed procurement success
Legal opinions outside professional scope
Full penetration testing unless commissioned
Software-development responsibility
Guaranteed compliance
Where the requirement needs specialist medical-device, legal, clinical or technical expertise beyond the agreed IG-Smart scope, the appropriate delivery model is identified during scoping and responsibilities are made explicit in the proposal.
Relevant evidence
Selected NHS and health-sector engagements
Published engagements involving national NHS information governance advice, DSPT readiness and health and care data governance.
Defined-scope DSPT or DTAC readiness work: gap assessment, evidence review and a prioritised plan. IG-Smart does not award NHS approval or DTAC certification.
Suits
Suppliers and care organisations preparing for NHS procurement or annual assurance.
Clinical-safety support
Support with DCB0129 or DCB0160 clinical-risk management and evidence, scoped to the product or deployment.
Suits
Manufacturers and deploying organisations that need proportionate clinical-safety evidence.
Governance support and independent assurance
Ongoing governance support or an independent review of the assurance position across DSPT, DTAC, clinical safety and data protection.
Suits
Organisations that need continuing senior support or an independent view before a key decision.
Typical investment
Indicative investment
DSPT / NHS assurance
Starting investment: £7,500 + VAT
Typical investment: £10,000–£25,000+ + VAT
Model: Defined-scope engagement
DTAC readiness / assurance
Starting investment: £7,500 + VAT
Typical investment: £7,500–£10,000 + VAT
Depending on scope and existing evidence
Model: Defined-scope engagement
Scope, deliverables, assumptions and fees are agreed in writing before work begins. What changes the fee is set out on the investment page; the exact fee is confirmed after scoping.
The accountability, decision-making, controls and evidence through which a digital-health supplier or care organisation manages the safety, privacy, security, interoperability and procurement requirements that apply to a technology — and keeps them current as it changes.
The Digital Technology Assessment Criteria: a common NHS approach for assessing digital-health technologies across clinical safety, data protection, technical security, interoperability, and usability and accessibility.
Not universally. Whether DTAC is expected depends on the technology, the buyer, the procurement route and current NHS guidance. Many NHS buyers use it, so suppliers selling into the NHS should expect to evidence it.
DCB0129 covers clinical risk management in the manufacture of health IT systems. DCB0160 covers clinical risk management by health and care organisations deploying and using them. They are related but not interchangeable.
Organisations within scope of DCB0129 or DCB0160 need a suitably qualified and experienced clinician acting as Clinical Safety Officer to oversee clinical-risk management. Specific requirements are set by the standards.
No. Supplier evidence is an important input, but the deploying organisation must still assess local deployment, configuration and workflow hazards and own its residual clinical risk.
DSPT is organisational assurance over data security and information governance. DTAC assesses a specific technology. One does not substitute for the other, though evidence may overlap.
No. DTAC is an assessment framework, not an accreditation, certification or NHS endorsement.
Yes. IG-Smart can assess existing evidence, identify gaps, help build the underlying evidence and review responses so they can be substantiated.
Yes. Where in scope, IG-Smart helps organise defensible evidence for tenders, due diligence and assurance questionnaires — without creating claims the underlying position cannot support.
Material changes — new functionality, integrations, AI or deployment context — may affect clinical-safety, privacy, security and DTAC evidence. Defined review triggers keep the assurance position current.
Yes. IG-Smart integrates AI governance with clinical safety, data protection and HealthTech assurance. Medical-device classification and specialist technical AI testing may require separate expertise.
NHS and regulatory references reviewed September 2026. This page is reviewed every 3 months.
Need to make your HealthTech assurance position clearer and more defensible?
Whether the requirement starts with DTAC, clinical safety, NHS procurement, deployment assurance or several overlapping frameworks, begin with the evidence and decisions you need to demonstrate.