Request evidence that matches the intended use
A certification, policy, or questionnaire can be useful, but only within its stated scope and date. Ask which product, hosting environment, organisational boundary, and period an artifact covers. Compare that scope with the pathway you intend to operate, including integrations, support access, subprocessors, and exports. [1][2]
Clinical safety and product evidence
- The intended purpose, users, care settings, and product boundaries
- Named ownership for clinical risk management and the current hazard record where applicable
- How measures, versions, licences, scoring rules, and limitations are governed
- How completion, scoring, review status, corrections, and exports are represented
- Release, incident, support, business-continuity, and change-notification processes
Ask the supplier to walk through both the normal pathway and credible failures using synthetic data. A demonstration should show who can see an unreviewed result, what happens when delivery fails, how corrected data is distinguished, and how a user can recover from an interrupted task.
The supplier evidence chain
A four-step chain for turning a supplier artifact into a deployment-specific assurance decision while preserving uncertainty.
- Request
Name the claim, artifact, scope, owner, and freshness required.
- Match
Compare the artifact boundary with the intended workflow and configuration.
- Verify
Inspect the artifact and test high-consequence behaviour with synthetic data.
- Resolve
Accept, remediate, contract for, or reject each remaining gap.
Privacy and security evidence
Document controller and processor roles for the proposed arrangement rather than assuming them from product labels. Request the processing terms, data-flow description, subprocessor list, retention and deletion behaviour, data-location information, access-control model, audit capabilities, vulnerability-management approach, and incident-notification process. The ICO states that controller-processor contracts must contain specified terms and that controllers remain responsible for choosing processors that provide sufficient guarantees. [3][2]
- Distinguish independently tested controls from supplier statements and customer-configured controls.
- Ask how privileged support access is authorised, time-limited, recorded, and reviewed.
- Request remediation status for material findings, not sensitive exploit detail.
- Confirm secure deletion and usable export procedures through contract language and a practical test.
Accessibility and interoperability evidence
Request an accessibility statement that names the tested product and standard, known limitations, testing method, assistive technologies, and remediation process. For integrations, request current interface documentation, authentication and authorisation details, versioning policy, error behaviour, rate limits, sandbox access, export formats, and responsibility for monitoring and reconciliation. [1]
Turn gaps into decisions
Classify each request as verified, partly verified, not verified, not applicable with rationale, or requiring a contractual commitment. Give every gap an owner, due date, consequence, and resolution route. A risk acceptance should identify the accountable decision-maker and compensating controls; it should not be hidden inside an overall supplier score. [1][2]
Sources and further reading
- Digital Technology Assessment Criteria (DTAC) guidance for buyers and suppliers (opens in a new tab)NHS England Digital. Updated 2026-05-20. Accessed 2026-07-13. Official NHS framework for evidence across clinical safety, data protection, security, interoperability, usability, and accessibility.
- The cloud security principles (opens in a new tab)UK National Cyber Security Centre. Accessed 2026-07-13. Official principles for evaluating cloud-service security and shared responsibilities.
- What needs to be included in the contract? (opens in a new tab)Information Commissioner's Office. Accessed 2026-07-13. Official UK guidance on mandatory controller-processor contract terms and assurance responsibilities.