Clinical Safety Standards DCB0129 and DCB0160 in the NHS

The NHS maintains safety standards for health information technology. Two standards specifically address clinical software and decision support systems: DCB0129 (Safety and Assurance Framework for Mobile Application) and DCB0160 (Clinical Risk Management). These standards exist to ensure that software used in clinical settings meets safety requirements.

DCB0129 applies to mobile applications and web applications used by healthcare professionals. It covers the safety of an application itself, the integrity of data it handles and the security of communications. An AI system that runs on a mobile device or accesses patient records through a web interface falls within DCB0129’s scope. The standard requires developers to perform clinical risk assessment, identify potential harms and mitigate them through design or governance controls. It requires testing of functionality and user interfaces. It requires documentation of changes and version control. It requires organisations using the application to maintain records of implementation and training.

DCB0160 is the overarching clinical risk management standard. It applies to any clinical software, not just mobile applications. DCB0160 requires systematic identification of hazards, assessment of their severity and likelihood, implementation of risk controls and ongoing monitoring. When an AI diagnostic tool is deployed in an NHS setting, DCB0160 governs how the risk it poses to patients should be managed. The standard requires risk assessment before deployment, documentation of mitigations and a process for monitoring safety in actual use.

Neither standard prohibits AI systems or algorithmic decision support. Instead, they require safety discipline around their deployment. A system cannot go into use without risk assessment. Potential failure modes must be identified. Consequences of failure must be considered. Controls must be designed to prevent or mitigate those failures. Clinicians using the system must be trained. Adverse events must be reported and investigated.

Many AI vendors and healthcare organisations have not yet aligned their processes with these standards. Some vendors do not understand these requirements and cannot provide evidence that their systems meet them. Some organisations deploy AI systems in the NHS without conducting DCB0129 or DCB0160 risk assessments. This creates both a safety gap and a compliance gap. An AI system in use in an NHS setting that does not meet DCB0129 or DCB0160 governance is being used outside regulatory requirements, whether anyone has formally stated that or not.

As a clinician, you should be aware of these standards and ask whether any AI systems you use have undergone proper risk assessment under DCB0129 or DCB0160. If your organisation has not documented this process, escalate the question to clinical governance or risk management. Do not assume that because a system is in use, it has been properly assessed. Many systems in use in NHS settings have not undergone formal risk assessment to DCB0129 or DCB0160.

If a vendor claims their system meets these standards, request evidence. Ask to see the risk assessment documentation, the identified hazards and the mitigations that were implemented. Review whether your organisation has contributed any additional mitigations or local governance controls. Understand what safety responsibilities lie with the vendor and what lie with your organisation.

The standards also require that systems be fit for purpose in the specific setting where they are deployed. A risk assessment conducted at a research hospital may not be adequate for deployment in a busy emergency department where workflow and patient demographics differ. Your organisation may need to conduct additional local risk assessment even if the vendor has performed risk assessment elsewhere.

Lesson concept diagram

Summary

DCB0129 and DCB0160 are NHS clinical safety standards that apply to healthcare software and decision support systems. They require risk assessment before deployment, identification of hazards and mitigation of risks. Many AI systems in use in NHS settings have not undergone formal risk assessment to these standards. Clinicians should ask whether systems they use have been properly assessed, and organisations should conduct local risk assessment to ensure the system is fit for purpose in their specific setting.