Guide · Regulation

The role, explained: how the CSO became unmissable

The Clinical Safety Officer is not a best-practice suggestion. It sits inside national information standards issued under primary legislation, and every year since 2018 the net has tightened around any organisation that deploys software in a care setting.

Where the requirement comes from

Section 250 of the Health and Social Care Act 2012 gives NHS England the power to set information standards for health and adult social care in England. Under that power sit two clinical risk management standards: DCB0129, for organisations that manufacture health IT systems, and DCB0160, for organisations that deploy and use them.1 The duty attaching to them is to have regard to the standard: a real obligation to comply or publicly justify why not, not a box that can be left unticked.2

DCB0160 is the one that bites on the provider side. It applies to any organisation deploying, using, maintaining or decommissioning a health IT system: NHS trusts, ICBs, GP practices, and independent and private providers. The deploying organisation must run its own clinical risk assessment in its local context, maintain its own hazard log, and appoint its own Clinical Safety Officer.2

What the CSO actually owns

The CSO is the accountable clinician for clinical risk management across the system's entire lifecycle, from first deployment through every update to eventual decommissioning. In practice that means ownership of four artefacts and one power:

  • The Clinical Risk Management Plan: how safety will be managed, by whom, with what governance.
  • The Hazard Log: the living register of identified hazards, their assessed risk and the controls in place.
  • The Clinical Safety Case Report: the structured, evidence-backed argument that the system is safe for release, which the CSO signs.
  • Release and change sign-off: material changes cannot ship without CSO review.
  • The brake: the explicit authority to pause or stop a deployment when safety concerns arise.2

Who is allowed to hold the pen

NHS England defines the CSO as "a clinician with a current professional registration who has been trained in clinical risk management and is accountable for clinical safety."3 Registration means GMC, NMC, GPhC or HCPC. A practice manager, operations lead or IT manager can support the process but cannot be the accountable signatory; the role exists precisely so that a clinician, answerable to a professional regulator, owns the risk.

Training follows a recognised pathway: NHS England's Digital Clinical Safety programme runs Essentials, Intermediate and Practitioner levels (the Practitioner workshop being the qualification most employers expect), and CPD-certified equivalents now cover DCB0129, DCB0160 and DTAC v2 in a single course.4 CQC expects a GP practice's CSO to be trained to practitioner level.2

The compliance stack around it

Clinical safety never travels alone. A 2026 deployment conversation typically touches DTAC (which asks suppliers to name their CSO with evidence of registration and training, section C1.2), the DSPT for data security, UK GDPR, and, where software qualifies, MHRA medical device registration.3 The CSO is the connective tissue across all of it: the person who can answer clinical safety questions in procurement, at inspection and after incidents.

The Data (Use and Access) Act 2025 then raised the stakes for everyone: it creates mandatory IT standards across health and social care and extends enforcement powers beyond NHS bodies to IT suppliers and private providers directly.3 For independent providers (ADHD services, mental health clinics, digital-first practices), the era of treating clinical safety as an NHS-only concern is over. Meanwhile NHS England's formal review of both DCB standards, driven by EPR rollout and AI, signals the requirements are about to get more specific, not looser.3

Organisations that cannot demonstrate a suitably qualified CSO actively fulfilling these duties are, plainly, not compliant with DCB0160.

The deployer's checklist

  • Named CSO, currently registered clinician, practitioner-level trained
  • Clinical Risk Management Plan approved before go-live
  • Hazard Log open and maintained for every system in scope
  • Clinical Safety Case Report signed before deployment, and refreshed on change
  • Documented authority for the CSO to halt deployment
  • Incident pathway linking software failures to clinical review

Sources

  1. NHS England clinical risk management standards DCB0129 and DCB0160 (Amd 24/2018 and Amd 25/2018), issued under Section 250 of the Health and Social Care Act 2012.
  2. Clinical safety sector guidance, 2025–26: DCB0160 duties, clinician requirement, CQC expectation of practitioner-level training, authority to halt deployment.
  3. NHS England CSO definition; DTAC C1.2; Data (Use and Access) Act 2025 enforcement extension; NHS England review of the DCB standards.
  4. NHS England Digital Clinical Safety training pathway (Essentials / Intermediate / Practitioner); CPD-certified equivalents covering DCB0129, DCB0160 and DTAC v2.