commvita
Connected care platform
Governance & Risk

Incident to Board — the Golden Thread

One traceable chain from a frontline event to board assurance — Event → Theme → Systemic Issue → Risk → Objective (BAF) — where every promotion carries its evidence, every risk drills back to the events that made it, and de-escalation is earned by assurance and signal abatement, never the calendar.

Live vs demonstrated: Live — real, API-backed platform logic (wired end-to-end today) Demonstrated — representative control surface with seeded data / illustrative UI mock-up

The one chain — and its two spines

Operational, corporate and board (BAF) are not three registers — they are three lenses over ONE Risk source of truth. The chain promotes a frontline event up to a board objective, and a mitigation spine runs the other way, closing the loop with live data.

Event
Frontline incident
reported, de-identified
Theme
Recurring pattern
signal-confirmed
Systemic Issue
Root cause
cross-cutting
Risk
Principal risk
ONE source of truth
Objective (BAF)
Strategic objective
board-owned
Never a re-keying. Every promotion is a data transition that carries its evidence links forward — the Risk still points back to the Systemic Issue, Theme and constituent Events, so a risk score always reconciles with the exact set of events beneath it. The mitigation spine Risk → Control → Assurance runs alongside, and the loop closes: Assurance is fed by live event data, and an Action reduces the Risk. De-escalation or closure requires assurance plus signal abatement — not the passage of time.

Golden Thread

The traceable chain, end to end

Thread Explorer, Signal Engine and the Register & BAF Lens — bidirectional trace, human-confirmed theme promotion, and ONE risk list seen through Operational / Corporate / BAF toggles.

Where in commvita /golden-thread · reconciling drill-downs · just culture, de-identified.

Feeds into the thread

Where events are born

Incident Reporting (severity ≥ moderate → Auto-CAPA + Duty of Candour auto-trigger), Near-Miss, Complaints, FTSU and Mortality Review all promote evidence into the chain.

Where in commvita /incident-reporting · /near-miss · /complaints · /ftsu · /mortality-review.

Board assurance

Where the thread surfaces to the board

Risks ≥12 escalate from the Corporate Risk Register into the BAF; principal risks, strategic objectives and three-lines assurance flow to the board portal and the 5×5 governance visual boards.

Where in commvita /corporate-risk · /board-assurance-framework · /board-management · /governance-boards.

1 From a frontline event — captured once, promoted with evidence

The thread begins where the harm, near-miss or concern is reported. Nothing is re-typed on the way up; each step carries its evidence links forward under a §8 governance gate.

1

The event is reported — and acts immediately

An incident of severity ≥ moderate automatically raises an Auto-CAPA badge and link (PSIRF-aligned), and auto-triggers Duty of Candour (CQC Reg 20) into its 24-hour verbal / 10-day written SLA. The event is de-identified — patient initials and reporter role only.

/incident-reporting/capa/duty-of-candour · CQC Reg 20
2

Signals surface a candidate theme

The Signal Engine watches for patterns: a rule threshold, an SPC special-cause point, or triangulation across sources. Each candidate theme's trigger chips drill straight back to the evidence — the exact events behind it.

/golden-thread · Signal EngineSPC · rule · triangulation
3

A governance lead confirms — human-in-the-loop

A candidate is never auto-promoted. A governance-lead gate confirms candidate → theme, and the promotion carries its evidence links. From theme to systemic issue to risk, every edge records who, when, the §8 gate and the evidence carried.

human-confirm gate§8 promotion edge
4

It becomes a risk on ONE register

The systemic issue is promoted to a Risk — the single source of truth. It still drills down to its constituent events with reconciling counts: the risk's evidence count equals the drilled set. Controls link to /policy-to-process and /learn.

/golden-thread · Thread Explorer/corporate-risk
Golden Thread / Thread Explorer governance_lead
Bidirectional trace — one node lit up and down
Event ×7
Infusion-device rate error
de-identified · ≥ moderate
Theme
Smart-pump programming
signal-confirmed
Systemic Issue
Inconsistent pump library
cross-ward
Risk R-19
Medication-delivery harm
score 12 → drills to 7 events
Objective (BAF)
SO-2 Safe care
board-owned
Promotion edge — Systemic Issue → Risk R-19
who A. Idris (Governance Lead)when 18 Jun 2026 · 14:22§8 gate passedevidence 7 events · 2 CAPA · 1 DoC
Counts reconcile: R-19's evidence count (7) equals the drilled event set. One honest orphan event remains "not yet part of any theme".
Representative UI — illustrative

2 To the board — ONE risk, seen through the BAF lens

The same risk that started as an event is now a principal risk on the board's assurance framework. No parallel register: the Operational, Corporate and BAF views are toggles over the one record.

Escalate at ≥12 — into the BAF

A risk scoring ≥12 escalates from the Corporate Risk Register to the Board Assurance Framework, landing in the board acknowledgement queue against a strategic objective — inherent, residual and target scores intact.

/corporate-risk · escalate/board-assurance-framework

The BAF lens: objective → assurance → gaps

The lens reads objective → principal risk → controls → assurance by the three lines of defence → gaps in control → GAP IN ASSURANCE → actions with % complete. Every cell is expandable to its evidence; the risk row drills back to systemic issue → theme → events.

/golden-thread · Register & BAF Lens3 lines of defence

Live on the board portal

The board portal carries a live BAF risk summary, and the Governance Visual Boards plot the risk on a 5×5 map with a residual → target movement arrow — so a non-executive sees direction of travel, not just a number.

/board-management/governance-boards · 5×5 bubble map

De-escalation is earned, not scheduled

Closing or de-scoring a risk requires assurance plus signal abatement — the SPC signal returning to common-cause and the assurance gap closed — never the calendar. Evidence-based de-scoring (e.g. 12 → 6) only after both are met.

assurance + signal abatementSPC common-cause
Golden Thread / Register & BAF Lens board member
LensOperationalCorporateBAF ✓ ONE risk source of truth
Objective
SO-2 — Deliver consistently safe care
Principal risk
R-19 Medication-delivery harm · residual 12 → target 6
Controls
Standardised pump drug library · double-check protocol /policy-to-process · competency module /learn
Assurance · 3 lines
1st — ward audit2nd — Medicines Safety Cttee3rd — Internal Audit
Gaps in control
Legacy pumps on 2 wards not yet on the standard library
⚠ Gap in assurance
No independent (3rd-line) review of the new library since rollout — assurance not yet evidenced
Actions
Library rollout to remaining wards
72% complete · due 30 Sep 2026
Every cell expands to evidence; the R-19 row drills to systemic issue → theme → the 7 constituent events (count reconciles).
Representative UI — illustrative

3 The evidence never leaves the thread

Because the chain carries links rather than re-keying, the board risk and the frontline event are two ends of the same object. Here is where the event enters — and how the signal that promoted it stays visible.

Incident Reporting / Event INC-4471 care_coordinator
Infusion rate programmed in error
Ward B · reporter role: registered nurse · patient M.W.
severity: moderate
Auto-CAPA
Auto-CAPA pending · CAPA-AUTO-4471
Duty of Candour
auto-triggered · verbal SLA 24h
🧵Part of the Golden Thread — promoted into Theme "Smart-pump programming" → Systemic Issue → Risk R-19 (score 12).
Auto-Link CAPA Open Duty of Candour View in Thread
PSIRF-aligned: severity ≥ moderate auto-links CAPA and opens a Reg 20 Duty of Candour record. De-identified by design.
Representative UI — illustrative
Signal Engine — why this event mattered. The theme was not guessed. INC-4471 joined six sibling events that tripped the engine's triggers, and a governance lead confirmed the promotion. The trigger chips stay attached to the theme so anyone can drill from the board risk back to the raw signal.
rule ≥ 5 / 90dSPC special-causetriangulation ×3 sources

Where it lives in commvita

Event Theme Systemic Issue Risk Objective (BAF)
Step in the threadModuleRouteModel / APIStatus
Event captured · Auto-CAPA · DoC auto-triggerIncident Reporting/incident-reportinglinked_capa_ref · auto_triggered_from Live
Near-miss & complaints feedNear-Miss · Complaints/near-miss · /complaintsPSIRF · PHSO timescales Live
Speak-up & mortality signalsFTSU · Mortality Review/ftsu · /mortality-reviewGuardian cases · ME/LeDeR Live
Corrective actionCAPA Workflow/capaCAPA record · PSIRF Live
Duty of Candour (CQC Reg 20)Duty of Candour/duty-of-candourverbal 24h / written 10d SLA Live
Signal → Theme (SPC / rule / triangulation)Golden Thread · Signal Engine/golden-threadhuman-confirm gate · §19 worked example Demonstrated
Thread Explorer (bidirectional trace)Golden Thread/golden-threadpromotion edges (who/when/§8/evidence) Demonstrated
ONE Risk source of truthCorporate Risk Register/corporate-riskescalate ≥12 → BAF Live
Board Assurance FrameworkBAF · Register & BAF Lens/board-assurance-framework/baf/ · principal risks · 3-lines assurance Live
BAF summary on the board portalBoard Management/board-managementacknowledgement queue · portal API /board/ · reads live /baf/ Live
5×5 risk bubble map (residual → target)Governance Visual Boards/governance-boardslikelihood × impact · movement arrows Demonstrated
Controls (policy & competency)Policy-to-Process · commvita Learn/policy-to-process · /learnprocess steps · competency sign-off Live
© 2026 Commvita Digital Health Solutions Ltd. All rights reserved. NHS Board Assurance FrameworkPSIRFCQC Well-Led · Reg 20DCB0129 SPC / statistical process controlJust culture — de-identifiedNon-SaMD governance control surface