Health-sector digital assurance
For organisations that build, buy, or run digital health and AI. Two competencies sit at the core, information security and information governance, and clinical safety, plus cross-sector AI governance that applies in health and beyond. We help suppliers get ready for the NHS, and give buyers independent assurance when a decision has to stand up to scrutiny.
Not sure where you sit? See for suppliers or for buyers. All prices exclude VAT.
Information Security & IG
DSPT Support & Completion
A defensible DSPT submission through gap assessment, CAF-aware advisory and quality assurance.
ISO/IEC 27001 Implementation Advisory and QA
A certification-ready ISMS on an advisory-and-QA basis, owned and populated by your team under our direction.
Virtual Data Protection Officer (DPO)
An outsourced, independent Data Protection Officer for organisations that need the role but have no qualified person in-house.
NHS Data Security & Risk Assurance Review
A board-level, independent opinion on whether an organisation is genuinely safe to access NHS data.
ISO/IEC 27001 Control Reality Assessment
An independent check of whether documented ISO 27001 controls are meaningful in practice.
GDPR Risk Defensibility Assessment
An independent view of whether your data protection risk is defensible in practice, not just on paper.
Pre-Procurement & Pre-Data Access Risk Assessment
A fast, independent risk opinion before you procure a system or grant a supplier access to data.
Clinical Safety
Clinical Safety Officer (DCB0129 / DCB0160) as a Service
Your named Clinical Safety Officer under DCB0129/0160, held by a registered clinician.
DTAC Readiness
A completed, buyer-ready DTAC submission for NHS procurement, with the clinical safety domain produced by us.
Clinical Risk & DCB0129 Supplier Assurance
An independent, clinically-informed check of a supplier clinical risk management file before you deploy.
AI Governance
AI Management System Implementation (ISO/IEC 42001)
An ISO/IEC 42001 AI management system, integrated with your ISO 27001 controls.
AI & Emerging Technology Governance Assessment
An independent assessment of whether your AI deployment risk is acceptable and defensible.
