commvitaConnected care platform
Editions › Governance & Assurance
Governance & Assurance edition

The accountability record an inspection asks for.

Information governance, clinical governance, organisational governance, quality, financial recovery, regulatory and research oversight — as one chain rather than eight registers.

The thread

One chain from an event to a board objective

Every promotion along this chain carries its evidence links. A risk drills back down to the events that compose it and the counts reconcile — which is the difference between a governance system and a set of spreadsheets that agree by coincidence.

The governance golden threadEvent to theme to systemic issue to risk to board objective, each promotion carrying its evidence, with a return path from a risk back to its events.Every promotion carries its evidence links. Nothing is re-keyed.Eventan incident, a near miss,a complaint, a concernThemea pattern across events,confirmed by a personSystemic issuea cause, not arecurrenceRiskscored, owned, onthe registerObjectiveboard assuranceframeworkA risk drills back down to the events that compose it, and the counts reconcile. De-escalation needs assurance and an abated signal — never a date.

De-escalation requires assurance and an abated signal, never a date.

Capability

Eight areas, one record

Information governance

  • Information asset register
  • Records of processing activities
  • Records management and retention
  • Retention and disposal with legal hold
  • Information sharing agreements
  • Data protection impact assessments
  • Data sharing agreements
  • Subject access requests
  • Freedom of information and environmental information requests
  • Consent management
  • Privacy management
  • Data breach management
  • Compliance monitoring
  • Audit management

Clinical governance

  • Clinical risk management
  • Safety cases
  • DCB0129 hazard log
  • DCB0160 deployment safety
  • Incident management and patient safety response
  • Assurance reviews
  • Duty of candour
  • Mortality review

Organisational governance

  • Committees and terms of reference
  • Board and committee papers
  • Corporate and operational risk registers
  • Actions and decisions
  • Escalation ladders
  • Register of interests
  • Board assurance framework

Quality improvement

  • Quality impact assessment
  • Benefits tracking
  • Outcomes tracking
  • Improvement cycles
  • Process quality baselines
  • Clinical audit
Capability

… continued

Financial recovery

  • Savings targets
  • Scheme creation
  • Scheme approval with a quality gate
  • Benefits realisation
  • Risk tracking
  • Executive reporting

Regulatory management

  • Compliance obligations
  • Evidence libraries
  • Audits and mock inspection
  • Accreditation
  • Regulatory reporting
  • Report registry with computed deadlines

Research governance

  • Ethics approval
  • Research datasets
  • Access requests
  • Research monitoring
  • Extract ledger
  • Genomic research oversight

Genomics governance

  • Genomic consent
  • Genetic testing governance
  • Data access controls
  • Research permissions
  • Precision medicine governance
  • Familial information handling
  • Clinical review processes
Information governance

An operating model, not a folder of policies

The information governance operating modelThree columns — know what you hold, control how it is used, prove it on demand — over a note that statutory clocks are computed rather than typed.Know what you holdInformation asset registerRecords of processingData flows and lineageRetention schedulesControl how it is usedLawful basis per purposeConsent and opt-outsAccess control and scopeSharing agreementsProve it, on demandTamper-evident auditSubject access and FOI clocksBreach managementEvidence packsStatutory clocks are computed, never typedA working-day duty counts working days. A calendar duty counts calendar days. Getting that wrong understates a deadline by about a week.Information governance as an operating model, not a folder of policies.

Statutory clocks are computed, never typed.

Working days and calendar days are not interchangeable

A freedom-of-information duty counts working days. Adding twenty calendar days instead understates the deadline by about a week and manufactures false breaches. commvita computes the deadline on the correct basis per duty and derives breach and at-risk from it rather than storing a status that can go stale.

Financial recovery

A saving is not a saving until the benefit is evidenced

The financial recovery programme lifecycleSix stages from target set through scheme drafted, quality impact assessment, approval and delivery to benefit realised, with the assessment as a hard gate.Target setScheme draftedQIA completedApprovedIn deliveryBenefit realisedA saving is not a saving until the benefit is evidenced.A quality impact assessment is a gate, not a formA scheme that has not been assessed for its effect on quality, safety, access and equity cannot be approved. The refusal is enforced in the software, not left to a policy.

The quality impact assessment is a gate enforced in software, not a form.

Genomics governance

The governance a genomic service actually needs

A genomic result is family information. The governance has to handle a person who never consented, was never a patient, and may not want to know.

  • Genomic consent
  • Genetic testing governance
  • Data access controls
  • Research permissions
  • Precision medicine governance
  • Familial information handling
  • Clinical review processes

Governance for a register that is not yet persisted

The genomics governance surfaces described here are built. The underlying genomic registers are, for three of the record types, held in process memory and do not survive a restart. Governance over a register that cannot retain a record is incomplete by definition, and the persistence work comes before any live use.