The accountability record an inspection asks for.
Information governance, clinical governance, organisational governance, quality, financial recovery, regulatory and research oversight — as one chain rather than eight registers.
One chain from an event to a board objective
Every promotion along this chain carries its evidence links. A risk drills back down to the events that compose it and the counts reconcile — which is the difference between a governance system and a set of spreadsheets that agree by coincidence.
De-escalation requires assurance and an abated signal, never a date.
Eight areas, one record
Information governance
- Information asset register
- Records of processing activities
- Records management and retention
- Retention and disposal with legal hold
- Information sharing agreements
- Data protection impact assessments
- Data sharing agreements
- Subject access requests
- Freedom of information and environmental information requests
- Consent management
- Privacy management
- Data breach management
- Compliance monitoring
- Audit management
Clinical governance
- Clinical risk management
- Safety cases
- DCB0129 hazard log
- DCB0160 deployment safety
- Incident management and patient safety response
- Assurance reviews
- Duty of candour
- Mortality review
Organisational governance
- Committees and terms of reference
- Board and committee papers
- Corporate and operational risk registers
- Actions and decisions
- Escalation ladders
- Register of interests
- Board assurance framework
Quality improvement
- Quality impact assessment
- Benefits tracking
- Outcomes tracking
- Improvement cycles
- Process quality baselines
- Clinical audit
… continued
Financial recovery
- Savings targets
- Scheme creation
- Scheme approval with a quality gate
- Benefits realisation
- Risk tracking
- Executive reporting
Regulatory management
- Compliance obligations
- Evidence libraries
- Audits and mock inspection
- Accreditation
- Regulatory reporting
- Report registry with computed deadlines
Research governance
- Ethics approval
- Research datasets
- Access requests
- Research monitoring
- Extract ledger
- Genomic research oversight
Genomics governance
- Genomic consent
- Genetic testing governance
- Data access controls
- Research permissions
- Precision medicine governance
- Familial information handling
- Clinical review processes
An operating model, not a folder of policies
Statutory clocks are computed, never typed.
Working days and calendar days are not interchangeable
A freedom-of-information duty counts working days. Adding twenty calendar days instead understates the deadline by about a week and manufactures false breaches. commvita computes the deadline on the correct basis per duty and derives breach and at-risk from it rather than storing a status that can go stale.
A saving is not a saving until the benefit is evidenced
The quality impact assessment is a gate enforced in software, not a form.
The governance a genomic service actually needs
A genomic result is family information. The governance has to handle a person who never consented, was never a patient, and may not want to know.
- Genomic consent
- Genetic testing governance
- Data access controls
- Research permissions
- Precision medicine governance
- Familial information handling
- Clinical review processes
Governance for a register that is not yet persisted
The genomics governance surfaces described here are built. The underlying genomic registers are, for three of the record types, held in process memory and do not survive a restart. Governance over a register that cannot retain a record is incomplete by definition, and the persistence work comes before any live use.