commvita
Connected care platform
EDITION EXPLAINER

Governance & Assurance Edition

Govern your organisation. The accountability record a board is inspected against — 116 modules on the Community base, sold to boards rather than clinicians, with no clinical workflow by design.

Live vs demonstrated: Live — real, API-backed platform logic (wired end-to-end today) Demonstrated — representative control surface with seeded data / illustrative UI mock-up

The Governance & Assurance Edition is commvita's answer to a question that has nothing to do with clinical software: can this organisation show that it is well run? It is bought by boards rather than by clinicians, it carries no clinical workflow by design, and it is the fastest of the three editions to put into service because nothing in it depends on clinical accreditation.

1Where this edition sits

commvita ships three editions and they are additive — each one contains the one beneath it. There is no fourth, and no “modules” tier to negotiate.

Population Platform The clinical record across every setting, population health and analytics + 161 modules · 416 in total Governance & Assurance Edition The accountability record an organisation is inspected against + 116 modules · 255 in total Community Edition The open platform base: identity, audit, data fabric, FDP parity 139 modules · £1 per instance Each edition contains the one beneath it. Governance & Assurance is sold to boards, not clinicians — it carries no clinical workflow.

Community Edition

139 modules · £1 per instance (optional support)

The open platform base — identity and RBAC, the audit framework, the data fabric, the integration engine, and everything the NHS Federated Data Platform does. Self-hosted, open standards, no Palantir contract.

Governance & Assurance

+116 modules · 255 in total

This document. The accountability record: board, risk, incident, information governance, AI governance, workforce competence and the statutory returns. Deliberately no clinical workflow.

Population Platform

+161 modules · 416 in total

The destination: the clinical record across primary care, social care, mental health, pharmacy, dentistry and community services, plus population health and analytics — and governance in full.

2What it is for

Most governance software is a filing cabinet with a workflow bolted on. The board papers live in one system, the risk register in a second, incidents in a third, policies in a fourth and training in a fifth — and the connections between them live in somebody's head, or in a spreadsheet, or nowhere. When an inspector asks how a particular incident changed a particular control, the answer is assembled by hand, from memory, under time pressure.

This edition is built on the opposite premise: the connections are the product. An event, a theme, a systemic issue, a risk and a board objective are one chain, and every step of it carries the evidence that justified the step.

Event An incident, a complaint, a near miss Theme A pattern across many events Systemic issue A confirmed cause, human-gated Risk On ONE register, three lenses Objective The board assurance framework Every promotion is a data transition that carries its evidence — never a re-keying And it runs backwards too. A risk drills down to the events that compose it, and the counts reconcile. De-escalation requires assurance and an abated signal — never a calendar date.

3The six questions

Strip away the frameworks and an inspection — CQC, HIW, HIS, RQIA, HIQA or an internal audit committee — comes down to a handful of questions. Each one has a module that answers it, and the module holds the evidence rather than a claim about the evidence.

THE QUESTION WHAT ANSWERS IT Are risks known and controlled? Board Assurance Framework /board-assurance-framework Is the organisation learning? Golden Thread · PSIRF · CAPA /golden-thread Are people competent and current? Appraisal · revalidation · CPD /appraisal Is data handled lawfully? IG Hub · ROPA · FOI clock /ig-hub Is AI used responsibly? AI Governance — ATRS, Art.22 /ai-governance Can you evidence any of it? Report Registry · audit chains /report-registry

4What is in it

Ten groups, 116 modules, on top of the 139-module Community base. This table is generated from the product's own edition definition, so it cannot drift from what actually ships.

GroupModulesWhat it evidences
Board assurance9That the board saw it, decided it, and signed it
Risk & compliance10That risk is identified, controlled and traceable to policy
Incident management14That harm is reported, investigated proportionately and learned from
Information governance & privacy12That personal data is held lawfully and requests are answered on time
Data & AI governance7That algorithms are registered, assessed and reviewable by a human
Training, CPD & workforce assurance12That the people doing the work are competent and currently registered
Governance intelligence7That the policy estate and the safety record are actually understood
Audit & evidence10That the claims above can be produced on demand
Statutory reporting & annual returns7That the publications an organisation is judged on are produced
Statutory readiness & operational command11That the organisation can run in a crisis and prove it planned to
Ambulance1
Analytics2
Clinical1
Operations1
US-ACO3
Workforce9
Total116on top of the 139-module Community base

5Evidence that cannot be quietly edited

A governance record is only worth what its integrity is worth. Board decisions, approval gates, policy sign-offs, information-governance access and the emergency loggist all write to append-only hash chains: each row stores the hash of the row before it, and the whole chain is re-verified by the server on every read.

Decision recorded prev_hash row_hash Approval granted prev_hash row_hash Policy signed off prev_hash row_hash Risk de-escalated prev_hash row_hash Verified on every read There is no update endpoint and no delete endpoint. Append-only is enforced by the absence of a route, not by a policy document. A broken chain raises a banner on the surface that reads it.

Sign-off is a named human accepting accountability. Approvals route through commvita Sign and are bound to the thing being signed, so a signature ceremony cannot be replayed to close a second item. A policy approval, a board pack, a safety case, a jurisdiction go-live and a professional revalidation recommendation each refuse to complete without one.

6Deadlines that are counted, not typed

A statutory duty counted in working days lands about a week later than the same number of calendar days. Software that types the deadline in produces breaches that are not breaches, and misses the ones that are.

A 20-day FOI duty, counted two ways Counted as CALENDAR days Deadline lands 20 days out — roughly a week EARLY → false breaches, chased work that is not late Counted as WORKING days — what the statute says Deadline lands about 28 days out, weekends and holidays excluded → the real duty Breach and at-risk are DERIVED from the deadline, never stored. A stored status drifts from the date beside it the moment either moves. The Report Registry declares, per return, whether its clock is statutory, a published national window, or a local convention.

7Governance intelligence

An organisation's policies and its free-text safety record are the two largest bodies of writing it owns, and the two least often read. Seven capabilities work over them.

Ask the corpus

Cited answers from your own policies

Every answer cites the document it came from. Retrieval is lexical, not semantic — commvita has no embedding provider, and the status endpoint says so, so nobody mistakes term matching for meaning. With no AI provider configured, the matching passages are returned verbatim rather than composed, because prose built from them without a model is invention.

Policy → flowchart

A long guideline becomes steps

Generated charts are bound to the source document version. Re-version the policy and the chart goes stale and stops claiming to be guidance — a sepsis flowchart drawn from a superseded policy is worse than none.

Safety thematic analysis

Patterns beyond the category someone ticked

Themes carry their record references, so a count reconciles with the set behind it. Where a model is used, the references it returns are validated against the real corpus so it cannot invent an incident.

Estate audit & merger

Duplication, ownership, conflicts

Both are advisory and read-only. commvita never rewrites a policy: which version survives a merger is an accountable human decision, and a test asserts the policy count is unchanged after a run.

8Beyond healthcare

Nothing in this edition requires the buyer to be a healthcare provider. The board, risk, policy, incident, information-governance, AI-governance and workforce-competence capabilities are the same shape in a housing association, a local authority, a charity or a professional body. The regulator, the inspection framework, the background-check scheme and the professional register are resolved per jurisdiction from a versioned, source-cited profile — and an unconfigured jurisdiction fails safe to a generic regulator rather than borrowing a neighbour's.

Why that matters commercially. It is the reason this edition has the shortest sales cycle of the three: no clinical accreditation to obtain, no clinical safety case to agree before go-live, and a far broader addressable market than a clinical system can reach.

9Every module in the edition

Generated from services/web/src/editions.ts. Routes are the real application routes.

Board assurance · 9 modules

Board Management — portal, papers, committees, actions/board-managementShipped
Board Assurance Framework (BAF)/board-assurance-frameworkShipped
Board Entity Governance/board-entity-governanceShipped
Register of Interests/register-of-interestsShipped
commvita Sign — e-signature & decision logging/esignShipped
Governance & Delivery Visual Boards — risk bubble map, maturity radar, delivery Gantt/governance-boardsShipped
commvita Financial Recovery & SIP — recovery plans, savings schemes, approval gates and delivery assurance/financial-recoveryShipped
Quality Impact Assessment — impact of service change on quality of care, evidence, mitigation and panel review/quality-impact-assessmentShipped
Quality Improvement & Evidence Programme — problem, baseline, PDSA, Lean and Agile tests, evidence, benefits and organisational learning/quality-improvementShipped

Risk & compliance · 10 modules

Corporate Risk Register/corporate-riskShipped
Golden Thread — incident → theme → risk → objective/golden-threadShipped
Policy-to-Process — policy as a gated process, authority matrix, N-of-M approvals, WORM audit/policy-to-processShipped
Policy management — authoring, versioning, version-aware attestation/policy-libraryShipped
Compliance Action Hub/compliance-hubShipped
Regulatory & Commissioner Engine/regulatory-engineShipped
Clinical Risk Management — DCB0129/0160 register & CSO sign-off/clinical-riskShipped
Hazard Log — DCB0129 hazard identification & control/hazard-logShipped
DCB0160 Workflow — change assessment for system modifications/dcb0160Shipped
Safety Case Report — DCB0129/0160 safety case compilation/safety-case-reportShipped

Incident management · 14 modules

Incident Reporting (PSIRF · LFPSE)/incident-reportingShipped
Root Cause Analysis/rcaShipped
CAPA workflow/capaShipped
Near-Miss Tracking/near-missShipped
Complaints Management/complaintsShipped
Duty of Candour/duty-of-candourShipped
Freedom to Speak Up/ftsuShipped
Mortality Review — MBRRACE · LeDeR · SHMI/mortality-reviewShipped
LEARN Reporting — national patient-safety event submission/learn-reportingShipped
CQC Notifications — statutory notification register/cqc-notificationsShipped
RIDDOR Reporting — HSE statutory reporting/riddorShipped
Safety Walkrounds — board-to-ward assurance visits/safety-walkroundsShipped
Patient Feedback (FFT) — responses, themes, CQC evidence pack/patient-feedbackShipped
Patient & Family Escalation (Rapid Review) — 24/7 worsening-condition escalation/rapid-reviewShipped

Information governance & privacy · 12 modules

IG Hub — DSPT, DPIA, breach, DSAR/ig-hubShipped
Confidential-Information Governance Spine/ig-spineShipped
Legitimate Relationship Log/legitimate-access-logShipped
Data Sharing Partnership Agreements/dspa-managerShipped
IG Training Compliance/ig-training-complianceShipped
Supplier IG Assurance/supplier-ig-assuranceShipped
FOI workflow — request, statutory clock, exemptions, review/ig-recordsShipped
Records management — retention & disposal schedules/ig-recordsShipped
Information Asset Register + Art.30 ROPA/ig-recordsShipped
Patient Data Control — Art.30 data flows, ABAC policy, National Data Opt-Out/ig-data-controlShipped
Shared Care Opt-Out Registry — FHIR Consent, emergency override governance/shcr-opt-outShipped
Federated Governance — cross-org data sharing agreements & steward registry/federated-governanceShipped

Data & AI governance · 7 modules

AI Governance — ATRS register, AIA, bias, Art.22 overrides/ai-governanceShipped
AI Integration Hub — governed provider config & audit/ai-integration-hubShipped
Data Transparency Register/data-transparencyShipped
Data lineage — source & transformation tracking/ig-recordsShipped
Microsoft Purview integration (optional, removable)/ig-recordsShipped
Clinical Studies — research IG, DSA register, re-identification risk, extract ledger/clinical-studiesShipped
Federated Cohort Discovery — GDPR Art.89, k≥5 suppression/cohort-discoveryShipped

Training, CPD & workforce assurance · 12 modules

commvita Learn — learning management & course catalogue/learnShipped
Mandatory Training compliance — statutory & role-based/mandatory-trainingShipped
CPD record & Training Passport — hours, evidence, export/learnShipped
Accreditations register — NMC · GMC · HCPC, expiry & manager verification/learnShipped
Competency frameworks & supervisor sign-off/learnShipped
Appraisal & professional revalidation — signature-backed sign-off, Well-Led evidence/appraisalShipped
eAssessment — scored knowledge checks with attempt history/learnShipped
commvita Learn Mobile — offline learning delivery/mobile-learnShipped
Staff Portal — personal governance (training, interests, approvals, signatures)/staff-portalShipped
Staff Hierarchy Builder — accountability & clinical supervision/hierarchy-builderShipped
IG training compliance — DSPT Criterion 7/ig-training-complianceShipped
Staff Wellbeing — PERMA+, staff survey, psychological safety (figures are seeded)/staff-wellbeingShipped

Governance intelligence · 7 modules

Ask the corpus — cited answers from your own policies and SOPs/governance-intelligenceShipped
Policy → interactive flowchart — version-bound, approved by a named person/governance-intelligenceShipped
Safety thematic analysis — patterns across the free-text safety record/governance-intelligenceShipped
PFD (Regulation 28) register — coroner concerns, statutory 56-day clock/governance-intelligenceShipped
Policy estate audit — duplication, overdue review, missing ownership/governance-intelligenceShipped
Merger harmonisation — conflicts and gaps between two estates/governance-intelligenceShipped
Process Quality Baseline — cycle time, handoffs, rework and coded-vs-free-text, measured over time/process-qualityShipped

Audit & evidence · 10 modules

Clinical Audit/clinical-auditShipped
Regulatory Assessment (CQC SAF / multi-jurisdiction)/regulatory-assessmentShipped
Assurance Dashboard — deployment rings/assuranceShipped
HIMSS Maturity Cockpit/himss-assessmentShipped
Cyber Assessment (Cyber Essentials · ISO 27001)/cyber-assessmentShipped
Data Security Architecture/security-architectureShipped
Real-Time Security Console — SOC, Art.9 monitoring, GDPR Art.33 ICO countdown/security-consoleShipped
DTAC Compliance — the NHS supplier gate/dtacShipped
ShCR Maturity Scorecard/shcr-maturityShipped
PRSB Compliance Dashboard — Core Information Standard completeness/prsb-complianceShipped

Statutory reporting & annual returns · 7 modules

Quality & Performance Report (DCEOE) — the monthly board report; ND carries its reason/quality-performance-reportShipped
Automated QPR Reporting — IAPT QPR (NHS Digital DS v2.0), CQC/NICE KPI pack, PCN/ARRS utilisation/qpr-reportingShipped
OPEL submission — the daily NHS England operational pressures return/opel-submissionShipped
Quality Account — the statutory annual quality publication/quality-accountShipped
Annual Plan Hub — SMART outcomes, quarterly milestones, live RAG/annual-plansShipped
Net Zero & Sustainability — Scope 1/2/3 and the CNZAP annual return/net-zeroShipped
AI Transformation Advisor — executive decision support, human-in-the-loop/ai-transformation-advisorShipped

Statutory readiness & operational command · 11 modules

EPRR Hub — Civil Contingencies Act 2004, business continuity, on-call, WORM loggist/eprrShipped
Major Incident — METHANE, JESIP joint decision, CSCATTT, Gold/Silver/Bronze, casualty tracking/major-incidentShipped
On-Call Manager — OPEL assessment, escalation, duty log, handover/oncall-managerShipped
Safe Staffing / CHPPD — NQB safe staffing, professional judgement, board return/safe-staffingShipped
Bank & Agency Cascade — bank-first cascade, agency control, WTD compliance/bank-agencyShipped
Shift Priority Board — shift-aware priority actions & handover/shift-priorityShipped
Handover Clock — 15-minute handover standard, breach & delay reasons/handover-clockShipped
Jurisdiction Profile — versioned, sourced, signed-off jurisdictional variance/jurisdiction-profileShipped
Firearms Certificate Management — evidence-grade decision log (per-jurisdiction regime)/firearms-certificationShipped
21st Century Cures Act — ONC information blocking (US)/cures-actShipped
EHDS Compliance — EU Reg. 2024/2987/ehdsShipped

Ambulance · 1 modules

HEMS Coordination/hemsShipped

Analytics · 2 modules

Benchmarking/benchmarkingShipped
ICS Finance/ics-financeShipped

Clinical · 1 modules

Community Nursing Activity (KF25/KF26)/community-nursing-activityShipped

Operations · 1 modules

Elective Experience Standards/elective-experience-standardsShipped

US-ACO · 3 modules

CMS Conditions of Participation/cms-copShipped
CMS Interoperability/cms-interoperabilityShipped
No Surprises Act/no-surprises-actShipped

Workforce · 9 modules

Dynamic Scheduling/dynamic-schedulingShipped
ESR Integration/esr-integrationShipped
HR & Finance/hr-financeShipped
Job Planning & PA Management/job-planningShipped
NHS Pension & Job Planning/nhs-pensionShipped
Rostering/rosteringShipped
Staff Directory/staff-directoryShipped
Staff Org Management/staff-org-managementShipped
Workforce Heatmaps & Skill-Mix/workforce-visualsShipped

10The honest edges

This edition needs the Community platform base underneath it. It is a standalone commercial product, not a stepping stone — it shares no modules with Community or Population — but it runs on the Community foundation of identity, RBAC, audit and data fabric.

Some figures on some surfaces are seeded. Where that is true the module says so rather than the document: the Staff Wellbeing dashboard, for example, is a designed control surface whose figures are illustrative until its data is wired. The Quality & Performance Report goes further and refuses to invent: an indicator it cannot compute is returned as unavailable with the reason and the module that would have to be wired, so the report doubles as the platform's own gap register.

Assurance is derived from coverage. A domain more than a third unavailable cannot report full assurance. That is enforced in the code rather than left to the narrative, and it means the product will sometimes tell a board something less comfortable than a competitor would.

Non-SaMD. Nothing in this edition diagnoses, treats, or makes a clinical decision. The clinical-safety modules (DCB0129/0160 hazard log, clinical risk, safety case) are the governance record of clinical safety work, not a clinical device.

Generated from services/web/src/editions.ts · 116 modules in 16 groupsNon-SaMD · governance and assurance surfaces only
© 2026 Commvita Digital Health Solutions Ltd. All rights reserved.