DCB0129 and DCB0160 are two parts of the NHS clinical safety framework for digital health technologies. Both require a structured clinical risk management process rather than a one-off sign-off.
The distinction is about responsibility. DCB0129 applies to the manufacturer or supplier developing and maintaining the digital health technology. DCB0160 applies to the NHS organisation or care provider deploying the technology into its local care environment.
The two standards work together. The manufacturer's clinical safety documentation provides important evidence for the deploying organisation's own clinical risk assessment - neither one substitutes for the other.
DCB0129 is the NHS standard for clinical risk management in the manufacture of health IT systems. If your organisation develops or maintains software that NHS clinicians or patients rely on, DCB0129 provides the framework for managing the clinical risks associated with that product.
It requires a defined clinical risk management process for:
The key DCB0129 deliverables are a Clinical Risk Management Plan, a Hazard Log, and a Clinical Safety Case Report. Together, these provide evidence that clinical risks associated with the intended use of the technology have been systematically identified, assessed and managed.
DCB0160 is the NHS standard for clinical risk management when a digital health technology is deployed into a live care environment. It applies to the NHS organisation or care provider implementing and using the technology.
Deployment can introduce clinical risks that the manufacturer may not be able to identify in advance. These can arise from:
The deploying organisation therefore conducts its own clinical risk assessment and maintains its own clinical safety documentation for the local implementation. As a supplier, you are responsible for DCB0129 rather than DCB0160 - but you will normally be expected to support the deploying organisation by providing relevant clinical safety information, including your hazard log and clinical safety case.
| DCB0129 | DCB0160 | |
|---|---|---|
| Applies to | Manufacturer or supplier | NHS organisation or care provider deploying the technology |
| Typical owner | Digital health supplier or vendor | NHS Trust, ICB, GP practice or care provider |
| Primary focus | Clinical hazards associated with the product | Clinical hazards associated with local deployment and use |
| Key documentation | Clinical Risk Management Plan, Hazard Log and Clinical Safety Case | Local clinical risk assessment, Hazard Log and Clinical Safety Case |
| Named role | Clinical Safety Officer | Clinical Safety Officer |
| Responsibility | Demonstrate that product-related clinical risks are appropriately managed | Demonstrate that risks associated with local deployment and use are appropriately managed |
Both DCB0129 and DCB0160 require a named Clinical Safety Officer (CSO) - a suitably qualified and currently registered clinician with appropriate experience to undertake the role.
Under DCB0129, the manufacturer's CSO is responsible for overseeing the clinical risk management process and providing professional assurance of the clinical safety case. This includes supporting hazard identification and assessment, reviewing proposed controls and mitigations, maintaining the hazard log, reviewing the effectiveness of mitigations, providing clinical input into the safety case, and signing it off where appropriate.
Under DCB0160, the deploying organisation's CSO undertakes a similar role within the context of the local care environment.
Assessing whether a digital system could contribute to patient harm requires clinical judgement and an understanding of how technology interacts with real-world care - which is why the role is deliberately held by a registered clinician, not a compliance or QA function.
The hazard log is a living record of clinical hazards associated with the technology. It should capture, as appropriate: the identified hazard, its potential cause or contributing factors, the potential clinical consequence, the initial risk assessment, existing and proposed controls, the residual risk following mitigation, actions and responsible owners, and review status.
It should be maintained throughout the product lifecycle, and reviewed whenever there are significant changes to the technology, its intended use, or the clinical environment in which it is deployed.
The Clinical Risk Management Plan describes how clinical risk management will be undertaken for the product. It should set out the scope of the process, roles and responsibilities including the named CSO, how hazards will be identified and assessed, how risks will be controlled and mitigated, how clinical safety information will be documented, and how risks will be monitored and reviewed throughout the lifecycle.
The Clinical Safety Case Report provides the structured argument that the digital health technology is acceptably safe for its intended use. It brings together evidence from the clinical risk management process - including the hazard log and supporting evidence - to demonstrate that identified clinical risks have been appropriately managed. The CSO provides professional assurance and signs off the case where the evidence supports that conclusion.
DCB0129 focuses on the product: the manufacturer considers the clinical hazards that could arise from the technology itself and from its intended use. DCB0160 focuses on the implementation: the deploying organisation considers how those risks may change when the technology is introduced into a specific clinical environment.
A digital system may be designed for a particular clinical workflow, but during deployment the NHS organisation may identify additional risks arising from local processes, staffing arrangements, training, configuration, or how the technology is incorporated into existing care pathways. This is why both standards matter - a product can have a robust clinical safety case while the deploying organisation still needs to assess the risks of using that product in its own environment.
DCB0129 is the NHS clinical risk management standard for the manufacturer or supplier developing a digital health technology. DCB0160 is the equivalent standard for the NHS organisation or care provider deploying and using the technology. The supplier works to DCB0129; the deploying organisation works to DCB0160.
Yes. DCB0129 requires a named Clinical Safety Officer who is appropriately qualified and registered as a clinician, overseeing the clinical risk management process including the hazard log and clinical safety case.
The core documentation is a Clinical Risk Management Plan, a Hazard Log, and a Clinical Safety Case Report. Additional evidence may be required depending on the technology, its intended use, and the clinical risks identified.
DCB0160 is primarily the responsibility of the organisation deploying the technology. However, suppliers should expect to support their NHS customers with the information needed for the local clinical safety assessment - product information, intended use, known clinical hazards, the manufacturer's hazard log, clinical safety case documentation, mitigations and controls, and information about significant product changes.
Yes. Clinical safety is an ongoing process. The hazard log and clinical safety documentation should be reviewed whenever there are significant changes to the product, its intended use, identified risks, or the clinical environment in which it is deployed - a lifecycle activity, not a one-time approval.
No. The NHS organisation deploying the technology remains responsible for its own DCB0160 clinical risk management process. A supplier can provide evidence and support, but the deploying organisation must retain ownership of the clinical risks associated with its local implementation and use.
The two standards provide complementary assurance. DCB0129 addresses the clinical risks associated with developing and maintaining the technology; DCB0160 addresses the additional risks that can arise when that technology is introduced into a particular care environment. Together, they support a continuous approach to clinical risk management across the digital health technology lifecycle.
TrustPoint Digital Health provides independent clinical safety governance for AI and digital health products under DCB0129 and DCB0160. Get in touch to discuss your safety case.
TrustPoint provides independent clinical safety governance for digital health and clinical AI - DCB0129/DCB0160 safety cases, readiness reviews, and post-market surveillance.