Employing Third-Party Software: What Independent Providers Actually Need to Check

A vendor demo can make almost any system look ready. Slick dashboards, a confident sales lead, a case study from a trust three counties over. None of it tells you whether the product is safe to put in front of your clinicians and your patients.

That's what due diligence is for.

Below is the checklist we use with independent providers before any new clinical or care-related software goes near a live environment, what to ask for, who needs to sign it off, and the three red flags that should stop a procurement in its tracks.

The Due Diligence Checklist

1. Mandate Digital Technology Assessment Criteria (DTAC).

DTAC is the baseline for procurement, and it's just been refreshed. NHS England introduced an updated form in February 2026, with a hard cutoff on 6 April 2026, the previous version should no longer be in circulation. Independent providers delivering NHS care should insist on the standard NHS England DTAC form rather than accepting a vendor's own version of it. Providers delivering arms-length care should do likewise.

2. Demand the Clinical Safety Case.

Ask for the vendor's DCB0129 Clinical Safety Case and Hazard Log. This is the evidence that clinical risk was managed properly during development, and it's a statutory obligation for manufacturers of health IT systems under the Health and Social Care Act 2012. As the deploying organisation, you'll need it as the starting point for your own risk assessment, you can't complete DCB0160 without it. During checking, make sure that the hazards were investigated using standard methods.

3. Appoint your own Clinical Safety Officer (CSO).

You need a CSO to review the vendor's documentation and assess risk in the context of your own deployment‚ that's your DCB0160 obligation, and it sits with you, not the vendor. The CSO should be a registered senior clinician (GMC, NMC, GPhC, or HCPC). One detail worth knowing: the requirement for a specific NHS-mandated training course has recently been dropped from the DTAC framework, so don't let a vendor use its absence as a reason to wave through a weaker appointment‚ competence and registration still matter, the formal course just isn't the only route there anymore. If you don't have someone internally, this role can be outsourced to a consultant.

4. Check the Data Security and Protection Toolkit (DSPT).

Your organisation needs a current DSPT self-assessment. If you're a Category 2 supplier‚ with 50 or more staff, or turnover above £10 million‚ that now requires independent audit rather than self-declaration. "Standards Met" status is written into NHS Standard Contract Clause 21.2, so falling short isn't a paperwork gap, it's a contractual breach.

5. Verify Cyber Essentials Plus.

Cyber Essentials Plus has become the de facto requirement for NHS suppliers handling patient data or providing IT and digital services, driven by Procurement Policy Note 014. Strictly, the policy itself allows Cyber Essentials, Cyber Essentials Plus, or demonstrably equivalent controls‚ but NHS Supply Chain's own implementation pushes suppliers firmly toward Cyber Essentials Plus specifically, with a fallback security questionnaire for those who don't hold it. In practice, for an independent provider evaluating a vendor, Cyber Essentials Plus is the standard to ask for. Don't let ISO 27001 be offered as a straightforward substitute‚ it covers different ground.

6. Test with your own clinicians.

Insist on a pilot with your own clinical staff, using dummy or test data in a sandbox rather than live patient records. This is where you actually learn whether the system fits your workflow‚ particularly if you're running a private/NHS hybrid setting, which often behaves differently to a pure NHS deployment. This pilot is also where DCB0160 gets applied in practice: clinical risk management isn't a document you file once, it's something you test.

7. Confirm NHS interoperability.

Ask directly about integration with the NHS Spine and whether the vendor builds to Fast Healthcare Interoperability Resources (FHIR) standards. Independent providers are increasingly expected to integrate with NHS systems rather than sit apart from them, and the NHS Business Partners programme that used to help with this has been retired. That support gap means the burden of asking the right integration questions now sits with you.

8. Embed exit and performance clauses.

Get your legal team to build in explicit exit clauses, data extraction rights, and performance benchmarks tied to clinical outcomes‚ not just uptime. The Data (Use and Access) Act 2025 gives regulators direct enforcement powers over IT suppliers for the first time, which strengthens your hand at the contract stage. Make sure your contract is drafted to take advantage of that.

Three Red Flags

Missing or outdated DTAC form. Anything submitted on the pre-April 2026 version is a sign the vendor isn't keeping pace with its own compliance obligations.
No DCB0129 documentation. If a vendor can't produce a Safety Case and Hazard Log, that's not a gap to work around, it's a statutory obligation they haven't met, and a reason to walk away.
No independent DSPT audit, where one's required. If you're a Category 2 organisation and the vendor's DSPT submission hasn't been independently audited, they're non-compliant, and by extension so is your supply chain.

Your Governance Pathway

For an independent provider, sign-off on a new system should move through a clear sequence rather than sitting with one person's judgement:

1. Commercial/Procurement runs the RFP and negotiates the contract.
2. Your Clinical Safety Officer reviews DCB0129 and completes the DCB0160 risk assessment for your specific deployment.
3. Your Data Protection Officer signs off the DPIA and the DSPT submission.
4. Your Cyber Security Lead verifies Cyber Essentials Plus and the underlying technical security.
5. End-user clinicians test usability and workflow fit in your actual setting, not a generic demo environment.
6. Your Governance Committee reviews the evidence from each stage and gives formal approval.

Bottom Line

Due diligence isn't about ticking a form‚ it's about demanding the right documentation and getting the right people, particularly your CSO and DPO, to put their name to a formal sign-off. DTAC, DCB0129, DSPT, and Cyber Essentials Plus are the four pillars that should be non-negotiable. If a vendor can't produce all four without a fight, that tells you something worth knowing before you sign, not after.

Previous
Previous

HSSIB's Abolition: What It Actually Means for Independent Providers

Next
Next

Governance Bingo: The Words You'll Hear in Every MDT Meeting