The short answer

What the DCB standards actually require.

Two NHS information standards, published under section 250 of the Health and Social Care Act 2012. Which one applies depends on whether you build the system or deploy it.

DCB0129 / Manufacturers

If you build health IT

Applies to manufacturers and suppliers of health IT systems. You must run a proportionate clinical risk management process across the development lifecycle, appoint a named Clinical Safety Officer, and hold current clinical safety documentation.

  • Clinical Risk Management Plan
  • Hazard Log
  • Clinical Safety Case Report
  • Named, registered Clinical Safety Officer
DCB0160 / Deployers

If you deploy health IT

Applies to NHS trusts, primary care organisations, social care providers and other health and care organisations putting a system into live clinical use. Your supplier's compliance does not discharge your own duty.

  • Deployment-side hazard assessment
  • Local Clinical Risk Management Plan
  • Your own Clinical Safety Case Report
  • Named Clinical Safety Officer in your organisation
Fractional CSO

If you have no clinician

The bottleneck for most digital health companies. A Clinical Safety Officer must be a registered clinician trained in clinical risk management, and the role cannot be handed to a non-clinical quality manager.

  • Named CSO on a retained basis
  • Authors and signs the safety case
  • Stays engaged as the product changes
  • Proportionate to your stage
Fractional CSO

A named clinician, without a full-time hire.

A full-time Clinical Safety Officer is rarely proportionate for an early-stage company, and hiring one is slow. Retaining one is neither.

Accountable, not nominal

The CSO is personally accountable for the clinical safety of the system and signs the Clinical Safety Case Report. We take that seriously: we will not put a name to a safety case we do not believe in, and we say so early if the product needs to change before it can be signed.

Built into your release cycle

Clinical safety is not a document you write once. The Hazard Log is a living record, and material changes to a product need a safety review before release. We work to your development cadence rather than reopening the file annually.

Procurement-ready

The output is what NHS buyers ask for: a current, signed Clinical Safety Case Report, a defensible Hazard Log, and the clinical safety section of your DTAC submission completed and evidenced.

How the engagement runs

From no documentation to a signed safety case.

01 / Scope

Establish which standard applies

Whether you are a manufacturer under DCB0129, a deploying organisation under DCB0160, or both. We also establish early whether your product is, or is close to being, a regulated medical device, because that changes the wider obligation set considerably and is far cheaper to determine now than after a procurement has started.

02 / Hazard analysis

Work the clinical failure modes

A structured hazard identification workshop with your clinical and engineering leads. What can this system do to a patient when it works as designed, when it fails, when it is misused, and when it is integrated with something else. Each hazard gets causes, existing controls, a residual risk rating and an owner. This is the part that determines whether the safety case is credible.

03 / Documentation

Produce the full set

Clinical Risk Management Plan, Hazard Log and Clinical Safety Case Report, written to your actual product and process rather than adapted from a template. Where you already hold ISO 14971 risk management documentation, we build from that shared hazard analysis instead of duplicating it.

04 / Ongoing

Keep it live

Retained CSO cover: safety review of material changes before release, Hazard Log maintenance, incident and near-miss review, and support through NHS procurement questions and DTAC assessment. Clinical safety documentation that is eighteen months out of date fails scrutiny as surely as none at all.

At a glance

Clinical safety facts.

Key facts about DCB0129, DCB0160 and Clinical Safety Officers
DCB0129 full titleClinical Risk Management: its Application in the Manufacture of Health IT Systems.
DCB0160 full titleClinical Risk Management: its Application in the Deployment and Use of Health IT Systems.
Legal basisInformation standards published under section 250 of the Health and Social Care Act 2012.
Who DCB0129 bindsManufacturers and suppliers of health IT systems.
Who DCB0160 bindsHealth and care organisations deploying health IT into live clinical use.
Clinical Safety OfficerA suitably qualified and experienced clinician with current UK professional registration and clinical risk management training. Personally accountable; signs the safety case.
Core deliverablesClinical Risk Management Plan, Hazard Log, Clinical Safety Case Report.
Where it is asked forNHS procurement, DTAC clinical safety section, NHS trust information governance and onboarding.
Relationship to ISO 14971Overlapping method, not interchangeable. A regulated device deployed in NHS England typically needs both, built from one shared hazard analysis.
Current statusNHS England is running a national review of both standards, with attention to AI governance, complex system interactions and modern development practice. Obligations on IT suppliers have been tightening.
Common questions

Clinical safety, answered plainly.

What is DCB0129?

DCB0129 is the NHS information standard Clinical Risk Management: its Application in the Manufacture of Health IT Systems. It applies to manufacturers and suppliers of health IT, and requires a proportionate clinical risk management process across the development lifecycle, a named Clinical Safety Officer, and current clinical safety documentation. It is published under section 250 of the Health and Social Care Act 2012.

What is the difference between DCB0129 and DCB0160?

DCB0129 is the manufacturer's obligation; DCB0160 is the deployer's. A supplier building a health IT product complies with DCB0129. The NHS organisation implementing that product complies with DCB0160. Each produces its own Clinical Safety Case Report, and supplying a compliant product does not discharge the deploying organisation's duty – a point that catches out both sides regularly.

Who can be a Clinical Safety Officer?

A suitably qualified and experienced clinician holding current registration with a UK professional body – GMC, NMC, HCPC or equivalent – who has been trained in clinical risk management. The CSO is personally accountable for the clinical safety of the system and signs the Clinical Safety Case Report.

The role cannot be given to a non-clinical quality, regulatory or engineering manager, however capable. This is the single most common reason a company cannot produce a valid safety case.

What is a fractional Clinical Safety Officer?

A registered clinician acting as your named CSO on a retained, part-time basis rather than as a full-time employee. Most digital health companies have no clinician in-house with clinical risk management training, and a full-time CSO is not proportionate at early stage. A fractional CSO gives you a named, accountable clinician who authors and signs the documentation and stays engaged as the product changes.

What documents does compliance produce?

Three core documents. A Clinical Risk Management Plan setting out how clinical risk will be managed. A Hazard Log recording each hazard with causes, controls and residual risk rating. A Clinical Safety Case Report presenting the argument and evidence that the system is acceptably safe, signed by the CSO. The safety case report is the document NHS buyers and DTAC assessors ask to see.

Does DTAC require DCB0129?

Yes. The Digital Technology Assessment Criteria used across NHS procurement includes a clinical safety section asking suppliers to evidence DCB0129 compliance, including a named Clinical Safety Officer and a current Clinical Safety Case Report. Suppliers without that documentation typically stall at exactly this point in an NHS buying process.

How do DCB0129 and ISO 14971 relate?

ISO 14971 is the international standard for medical device risk management; DCB0129 is an England-specific NHS information standard for health IT clinical risk management. They overlap heavily in method but are not interchangeable. A product that is a regulated medical device and is deployed in NHS England will typically need both – built from one shared hazard analysis rather than two parallel exercises.

Are the DCB standards changing?

NHS England is running a national review of DCB0129 and DCB0160. The review has looked at gaps around artificial intelligence governance, complex system interactions and modern development practices, and the direction of travel has been toward firmer obligations on IT suppliers. If clinical safety sits on your roadmap, build the documentation to the current standards now – the underlying hazard analysis carries forward regardless of how the standards are reworded.

General information about NHS clinical risk management standards in England, not regulatory advice on a specific product. Requirements change – check the current position or take advice on your own circumstances.

Need a Clinical Safety Officer?

Tell us about your product and where you are in NHS procurement. We'll come back within one working day.

Request a quote