NHS organisations in England are systematically failing to comply with legislated digital safety standards potentially putting patients at risk, warned experts in an analysis published in the online journal BMJ Innovations.
The government's 10-Year Health Plan pushes rapid digital and AI expansion, the authors pointed out, warning that the NHS was being asked to scale AI, genomics, and robotics on top of a safety architecture that was already failing for existing, simpler technology.
In addition, they pointed out that most clinical safety officers (CSO) were clinicians who performed this role on top of their full-time job.
The researchers proposed a new model that incorporated Care Quality Commission (CQC) regulatory enforcement, National Quality Board defined quality standards, workforce professionalisation, and a hybrid framework combining centralised safety assessment with local risk management.
Without these changes, the digital transformation envisaged in the 10-Year Health Plan risked “propagating patient harm at unprecedented scale and speed”, they warned.
Widespread Non-Compliance
Despite statutory requirements under the Health and Social Care Act 2012 for digital
health technologies to undergo formal clinical risk assessment, the authors highlighted that recent evidence indicated only 17% of digital deployments in England’s NHS had evidence of documented safety assurance against these standards. Their original national cross-sectional study had also found that among the 14,848 digital health technologies in use across NHS trusts and integrated care boards (ICBs) in England, 70.1% lacked documented safety assurance.
For the new study, the researchers sought to identify drivers of low compliance to inform safety improvements. They analysed previously unpublished CSO workforce data, and performed a secondary analysis of their original survey of freedom of information responses received from NHS trusts and ICBs.
The “widespread non-compliance” the researchers identified with statutory digital clinical safety standards — which are not routinely monitored or enforced — was driven by four major, mutually reinforcing factors: poor understanding of the standards; immature governance infrastructure and oversight; ineffective assurance processes; and the perception of the CSO role not as a dedicated, professionalised post but as an ancillary responsibility absorbed into existing roles.
These themes did not operate in isolation, the researchers emphasised. No single component functions adequately, and the failure of each compounds the others, they said.
“While embedding safety within senior clinical leadership may provide strategic visibility, it also means the individuals responsible for safety oversight are those with the least available time to undertake it; reducing effective capacity and impairing the development of experiential expertise,” the authors said in a press release.
Professionalised CSO Workforce
The 10-Year Health Plan’s ambition to rapidly adopt frontier technologies demanded a highly skilled CSO workforce with dedicated time to undertake risk assessments of increasing complexity. It also needed the embedding of digital safety knowledge at undergraduate and postgraduate level, which the researchers suggested hadn’t happened.
The shift from hospital to community will also likely require expansion of digital services in primary care and other community settings — organisations that are likely to be smaller and less well-resourced than trusts and ICBs, with less access to specialist CSO capacity.
To tackle these issues, the researchers proposed a number of solutions, including formal regulation, for which they said the CQC was uniquely placed, and a “professionalised CSO workforce”, which would bring the NHS into line with other safety critical industries.
The paper's authors disclosed several competing interests. Co-author Keith Grimes is founder and owner of Curistica, a consultancy that provides clinical safety services to digital health organisations and NHS bodies, and co-author Youssof Oskrochi is Curistica's head of safety and data protection. Both acknowledged that the paper's subject — compliance with clinical safety standards — is directly relevant to Curistica's commercial activities. The authors reported no specific funding for the research.
Rob Hicks is a retired National Health Service doctor. A well-known TV and radio broadcaster, he has written several books and has regularly contributed to national newspapers, magazines, and online publications. He is based in the United Kingdom.
Facts Only
* NHS organisations in England are failing to comply with legislated digital safety standards.
* The Health and Social Care Act 2012 requires formal clinical risk assessments for digital health technologies.
* 70.1% of 14,848 digital health technologies in use across NHS trusts and integrated care boards (ICBs) lacked documented safety assurance.
* 17% of digital deployments in England's NHS had evidence of documented safety assurance.
* Clinical safety officers (CSOs) typically perform their duties alongside full-time clinical roles.
* The government's 10-Year Health Plan includes the expansion of AI, genomics, and robotics.
* Researchers propose a model involving Care Quality Commission (CQC) enforcement and National Quality Board standards.
* Proposed solutions include the professionalisation of the CSO workforce and undergraduate/postgraduate safety education.
* Co-authors Keith Grimes and Youssof Oskrochi are the owner and head of safety, respectively, of Curistica, a clinical safety consultancy.
* The research was published in the journal BMJ Innovations.
Executive Summary
The English NHS is facing a systemic failure in adhering to statutory digital safety standards, leaving a significant majority of digital health technologies without documented safety assurance. This gap exists despite legal requirements under the Health and Social Care Act 2012. The issue is driven by a combination of poor understanding of standards, immature governance, and a workforce model where Clinical Safety Officers (CSOs) manage safety as an ancillary responsibility to their full-time clinical duties, rather than as a dedicated professional role.
This systemic fragility coincides with the government's 10-Year Health Plan, which aims to rapidly integrate complex technologies like AI and robotics. Experts warn that scaling these advanced tools on a failing safety architecture could accelerate patient harm. To mitigate this, a transition toward a professionalised CSO workforce and the introduction of regulatory enforcement via the Care Quality Commission is proposed. While these measures aim to align the NHS with other safety-critical industries, the effectiveness of such a shift remains dependent on the successful implementation of new educational and regulatory frameworks.
Full Take
This analysis operates in ACADEMIC MODE. The study identifies a critical disconnect between statutory requirements and operational reality within the NHS.
1. METHODOLOGY CHECK: The research relies on a cross-sectional study of 14,848 technologies and secondary analysis of freedom of information responses and workforce data. A peer reviewer would likely question the reliability of FOI responses, as these can be subject to administrative error or inconsistent reporting across different trusts, potentially inflating the non-compliance figures.
2. CLAIMS vs EVIDENCE: The data strongly supports the claim of widespread non-compliance (70.1% lack of assurance). However, the leap from "lack of documentation" to "propagating patient harm at unprecedented scale" is a predictive projection rather than a documented result. The evidence shows a failure of *process*, not necessarily a catalog of *incidents*.
3. LITERATURE CONTEXT: This work extends the conversation on health informatics by moving from technical viability to regulatory governance. It challenges the assumption that clinical expertise automatically translates to digital safety expertise.
4. REAL-WORLD IMPLICATIONS: If the findings are accurate, the "digital transformation" of the NHS is being built on a foundation of administrative negligence. For this to matter, one must accept that documented assurance is a reliable proxy for actual patient safety.
5. BRIDGE QUESTIONS: To what extent does documented compliance actually correlate with a reduction in patient harm? Would a centralized safety assessment model reduce local agility and innovation in patient care?
The presence of competing interests—where authors own a consultancy providing the very services recommended—introduces a commercial incentive to highlight systemic failure. While this does not invalidate the data, it frames the solution in a way that benefits the authors' business model.
The content is clean; it presents data-driven warnings and proposed systemic shifts without utilizing coordinated influence tactics.
