Skip to content

Governance and assurance

Code: GOV — governance and assurance.

Scope

This finding concerns the controls around digital capability: specification, procurement, configuration, local adoption, clinical safety assessment, monitoring, change, incident learning and preservation of safety barriers across organisational boundaries. It asks not only whether a feature exists, but whether the end-to-end work system is demonstrably safe in representative use.

What recurs in the current series

  • Responsibility crosses supplier and organisational boundaries. Rachelle Ross (representative case) concerns a national screening status feed, GP systems and local manual entry; no single component description captures the whole control.
  • Presentation and workflow controls are coupled. Stephen Rhodes (representative case) concerns laboratory reporting, GP review workload and filing behaviour rather than an isolated screen property.
  • The used representation may not expose an available audit capability. Alexander Braund (representative case) shows why assurance must test printed and exported views as well as the live audit trail.
  • Safety functions can be locally optional or vulnerable during replacement. Paula Doreen Hughes concerns duplicate-prescribing controls and the preservation of local safety nets as systems change.
  • Migration needs reconciliation of every open clinical action. Margaret Spencer concerns follow-up prematurely closed during migration to Lorenzo, without an assured process to expose omitted surveillance. The report placed the system change among wider administrative, training and clinical failures.
  • National safety knowledge can diverge in local configurations. Brian Bicat concerns inconsistent paraffin-emollient fire-risk warnings across prescribing systems that appeared to be updated by individual CCGs. The digital warning was one element of a wider communication and product-safety issue, not an isolated causal explanation.
  • Access governance determines provenance in actual use. Joan Lunt concerns delayed individual access for agency staff and recording through proxy or generic identities; a nominal authentication policy did not preserve accountable authorship in the deployed workflow.
  • A proposed control may introduce another hazard. In Christopher Collinson, a respondent rejected a generic confirmation alert because of alert-fatigue risk; this supports evaluation of the complete workflow rather than counting features.
  • A digital access model can remove established prescribing safeguards. Karl Willis concerns online self-certification and a patient choice that prevented GP notification after amitriptyline had been stopped. The online supply formed part of the circumstances of death, but the report does not establish interface design as the sole cause.
  • Respondents can dispute the need for system change. In Theo Tuikubulau, NHS England responses said both triage systems would reach the highest category when the full presentation was elicited and considered no change necessary. That counter-position must remain visible beside the coroner's concern.
  • Passive flags and actionable worklists are not equivalent. In John Singleton, respondent evidence preferred actionable reports to a passive record flag for non-collection of medication.

The recurring governance issue is control of the deployed configuration and workflow, including interfaces and organisational responsibilities, rather than abstract assurance of a product in isolation.

Variation and limits

  • GOV is deliberately broad and is assigned to many reports because PFDs request preventive action. It is less discriminating than a specific mechanism code and should be read with VIS, LOOP, INT, PROV, RES or ALERT.
  • Requested action does not prove that a proposed technical remedy is effective or proportionate.
  • Respondent plans describe intended or later states; they do not rewrite the incident-state finding and should not be presented as completed remediation without verification.
  • Historical findings do not establish current product behaviour, and this series cannot compare the safety of suppliers or organisations.

The current review counts demonstrate recurrence of GOV coding in the focused legal-publication series, not prevalence of deficient governance in healthcare.

Defence implications — analytical translation

The following are review-derived implications for DPHC and Programme CORTISONE:

  • specify safety properties as testable end-to-end requirements, including interface, workflow, ownership and degraded-mode behaviour;
  • maintain traceability from hazard to requirement, configuration, assurance evidence, operational monitor and change decision;
  • regression-test proven safety barriers during migration and configuration change;
  • assure representative roles, locations, volumes, access states and cross-boundary workflows rather than a demonstration path alone; and
  • monitor safety outcomes and control performance after deployment, with explicit ownership across Defence, NHS and supplier boundaries.

These implications are analytical translation, not coronial findings about Defence. See the DPHC and Programme CORTISONE analysis.

Evidence basis: included-case dataset, coding framework, and current review counts.