One platform, six stages, one loop back to reporting.
This is the architecture behind how a third party supplier digital mental health technology reaches a patient's hands in Wales; it's governed centrally, assured by specialist assurance teams, and enables the tracking of key usage data which is fed back into a central control centre. Hover any box for more detail, or press Start tour for a full narrated walk-through.
Control Centre
Scheme governance, reporting and operational oversight: the single place DHCW watches and steers the whole scheme from.
Control Centre
Scheme governance, reporting and operational oversight.
Portfolio / Scheme Reporting
Products, suppliers, impact and outcomes.
Activity & Audit Feed
Real-time activity, submissions and audit trail.
Provisioning / Configuration
Scheme settings, workflows, clinical pathways and rules.
Roles & Access
Scheme, organisation and supplier access.
Attribution & Usage Reporting
Usage, outcomes and supplier performance.
Operational Dashboards
Live operational view and insights.
Key Stakeholders
People and teams involved across the scheme. Each one owns the stage directly beneath it in the journey below. Follow the arrow down to see what they're responsible for.
Suppliers
Register, manage products, keep information up to date.
DHCW Assurance Teams + WIAG
Assess and approve suppliers and products.
Welsh Clinical & Systems Teams
Search, review and select assured products.
NHS Wales / Health Boards
Use assured devices in care settings.
Welsh Patients / Citizens
Safer, higher quality care through trusted digital tools.
DHCW – Scheme Owner / Control Centre
Oversee the scheme, monitor impact and drive improvement.
↕ each stakeholder owns the platform component below it. Hover or tap an arrow to see how
From supplier registration to patient impact
The six stages a product moves through, left to right, with each one coloured and column-aligned to the stakeholder above who owns it.
Supplier Onboarding & Product Submission
Suppliers register, create an account, maintain organisation details, add products and upload evidence.
Supplier Portal
- Register and login
- Manage organisation details
- Add and maintain products
- Upload evidence
- Track submission status
Supplier app onboarding / SDK enablement (optional)
Guidance and technical support for suppliers.
Assurance & Review
The assurance team triages submissions, reviews evidence, requests more information, and records decisions.
Assurance Hub
- Triage and allocate
- Assessor review
- QA / moderation
- Approve, reject or request more information
- Publish outcomes
Audit trail & workflow notifications
Automatic updates for suppliers and stakeholders, including WIAG.
Wales Informatics Assurance Group (WIAG)
Assurance hand-off for national informatics governance visibility.
Shared Services Partnership
Assurance hand-off for Welsh language translations.
Assured Product Catalogue
Approved products are published into a searchable catalogue used by approved clinical and system teams.
Catalogue Service
- Search and filter
- Product details and evidence
- Version history
- Status (e.g. approved, retired)
- API access (for systems and libraries)
Setup Configuration
Internal, none public facing.
Distribution & Patient Delivery
Approved products are made available to patients via app libraries, EHR recommendations and automated pathways.
Self-service App Libraries
- Local or board-specific library
- Curated by clinicians / library teams
- Patients browse approved apps
EHR Integrations
- Clinician recommends from inside the EHR
- Recommendation sent to patient
- Written back to the patient record
Pathways Auto-Distribution
- Rules-based automatic distribution
- Triggered by pathway, diagnosis, care setting or eligibility
- Right app, right patient, right time
Messaging Service
Delivers via:
Patient Use & Access
Patients receive the message or recommendation, open the link, browse where relevant, and access the app.
Patient Experience
- Receives recommendation
- Taps the link or browses the library
- Downloads / opens the app
- Begins using the technology
Self-service browsing
Patients can also browse the app library directly and select apps without a clinician recommendation.
Attribution, Usage Data
Accounts are linked to the original recommendation; usage data is collected and fed back for reporting and improvement.
Attribution Link Service
- Links app account to recommendation
- Creates attributed link / redirect
- Records click-through / redirect
Supplier App with Attribution SDK
- Supplier app has the SDK installed
- Account linked via attribution
- App generates usage events
Usage API
- Usage events pushed into API
- Standardised ingestion of usage & outcome events
Control Centre
Pulls this data back for scheme reporting, supplier performance, usage analytics and continuous improvement.
Data & Integration Layer
Data flows securely between all components, stage by stage, left to right.
Supplier Data
Suppliers, products, submissions.
3rd Party Product & Compliance Data
App details, evidence docs.
Assurance Decisions
Assessments, outcomes, status and audit.
Welsh Catalogue Data
Approved products, versions and metadata.
Distribution / Recommendation Events
EHR, pathways, messaging events.
Attribution Data
Links, click-throughs, supplier app accounts.
Product Usage Data
Usage events, outcomes.
Reporting & Analytics Data
Scheme reporting, insights and KPIs.
Infrastructure & Compliance
A secure, resilient foundation for Wales, underneath everything above it.
Secure
Security by design.
Scalable
Grows with demand.
Resilient
High availability.
Cloud
Flexible deployment.
NHS Wales standards
Aligned to national standards.
Data residency
Data held in the UK.
Auditability
Full traceability.
Accessibility
Inclusive and usable for all.
MH Apps Framework
The full standards and criteria used to assess a third-party digital health technology before it is published to the catalogue, reproduced here from the MH Apps Framework Publishable Document. Every category below is collapsed by default; open a category, then a sub-standard, to see its criteria.
→Glossary of Terms, Abbreviations and Acronyms
The following is a first-pass glossary of the standards, abbreviations and acronyms referenced within the MH Apps Framework assessment criteria. It should be reviewed and expanded as the framework develops.
→1Scene Setters
Establishes the core context for the product before the detailed standards are applied: its purpose, intended users, and functional characteristics, for example the type of information, guidance, monitoring, decision support, algorithms, treatment or administrative features it provides. These criteria are not scored; instead, the answers determine which of the standards and criteria that follow are relevant to the specific product being assessed.
→1a. App Identity
| Code | Criteria | Facing |
|---|---|---|
| 1a - Q1 | Is the app health focused? | Assessor-facing |
| 1a - Q2 | Has the app been developed for NHS Wales or developed independently by a Third Party? | Assessor-facing |
| 1a - Q3 | Does the app collect data? | Assessor-facing |
| 1a - Q4 | What Permissions does the app request? | Assessor-facing |
| 1a - Q5 | Which operating systems or platforms does the health app support? | Supplier-facing |
| 1a - Q6 | What is the name of the health app? | Supplier-facing |
| 1a - Q7 | In which languages is the health app available? | Supplier-facing |
| 1a - Q8 | Provide instructions for access to the health app for assessment. | Supplier-facing |
| 1a - Q9 | What type of data is collected? | Assessor-facing |
| 1a - Q10 | Are users required to sign up / register to use the service? | Assessor-facing |
| 1a - Q11 | Is data collected through cookies? | Assessor-facing |
| 1a - Q12 | What type of cookies are used? | Assessor-facing |
| 1a - Q13 | Is the Data (cookie and/or none cookie) Collected: | Assessor-facing |
| 1a - Q14 | How is none cookie data collected? | Assessor-facing |
| 1a - Q15 | What other apps is the App connected to? | Assessor-facing |
| 1a - Q16 | What devices is the App connected to? | Assessor-facing |
| 1a - Q17 | Can the user prevent cookie data being collected and still use the App? | Assessor-facing |
| 1a - Q18 | Does the disabling of cookies impact the use of the App in any way? | Assessor-facing |
| 1a - Q19 | Can/is data shared? (excluding cookies) | Assessor-facing |
| 1a - Q20 | Can data be shared through the direct manual intervention of the user? Y/N {i.e. by sending data via email etc} Reference DS05 Answer options for choices. | Assessor-facing |
| 1a - Q21 | How is the user able to manually share their data? | Assessor-facing |
| 1a - Q22 | Is data ONLY shareable through direct manual intervention? (excluding cookies) Yes if the only data transfers that occur are through the direct user interactions identified. | Assessor-facing |
| 1a - Q23 | Can the user control any automatic data sharing, through setting individual sharing preferences in the app? (excluding cookies) | Assessor-facing |
| 1a - Q24 | Where/With who can the user share data automatically through setting sharing preferences in the app? | Assessor-facing |
| 1a - Q25 | Is any data (excluding cookie data) shared automatically as soon as the App is accessed – based only on agreement to relevant T&C's or Privacy Policy? | Assessor-facing |
| 1a - Q26 | Where/with who is data automatically shared, on the basis of end user agreement to the developer's Privacy Policy and/or T&C's? | Assessor-facing |
| 1a - Q27 | What data is automatically shared with the developer? | Assessor-facing |
| 1a - Q28 | What data is automatically shared with clinicians/HCPs? | Assessor-facing |
| 1a - Q29 | What data is automatically shared with other users? | Assessor-facing |
| 1a - Q30 | What data is automatically shared with third parties? | Assessor-facing |
| 1a - Q31 | What data is automatically shared with other devices? | Assessor-facing |
| 1a - Q32 | Does the app allow users to access their own NHS personal health records e.g. patient access? | Assessor-facing |
| 1a - Q33 | Does the App appear to access and/or process NHS Patient Information? | Assessor-facing |
| 1a - Q34 | Does the App allow access through NHS Login? | Assessor-facing |
→1b. Information & Guidance
| Code | Criteria | Facing |
|---|---|---|
| 1b - Q1 | Does the App provide information, resources or activities to the public, patients or clinicians, either about a specific condition or general health and lifestyle? | Assessor-facing |
| 1b - Q2 | Is the app designed to provide information or guidance? | Assessor-facing |
| 1b - Q3 | Does the app provide information that is personalised to an end user's specific circumstances? | Assessor-facing |
| 1b - Q4 | Does the app provide environmental data not specific to the patient? | Assessor-facing |
| 1b - Q5 | Does the app provide users with information regarding where they are able to find local or suitable support services? | Assessor-facing |
→1c. Clinical Decision Support & Diagnostics
| Code | Criteria | Facing |
|---|---|---|
| 1c - Q1 | Is the data the app collects automatically assessed for the purposes of evaluating risk or providing diagnostic support? | Assessor-facing |
| 1c - Q2 | Does the app diagnose a specific condition? | Assessor-facing |
| 1c - Q3 | Does the app provide an assessment of the risk to an individual - based on data input or collected by the app - of: | Assessor-facing |
| 1c - Q4 | Does the app provide an assessment of the risk to a health care professional - based on data input or collected by the app - of: | Assessor-facing |
| 1c - Q5 | Does the app provide the option for further assessment or analysis by a healthcare professional? | Assessor-facing |
| 1c - Q6 | Is the app a Symptom Checker? | Assessor-facing |
| 1c - Q7 | Does the app indicate likelihood of a match for the listed conditions? | Assessor-facing |
| 1c - Q8 | Can users filter results to display by highest risk / likelihood / severity? | Assessor-facing |
| 1c - Q9 | Does the app provide treatment recommendations for the listed conditions? | Assessor-facing |
| 1c - Q10 | Does the app only signpost the user to suitable care or recommend seeking further advice? (eg. Go to A&E, book an appointment with your GP, call 111) Y/N | Assessor-facing |
→1d. Algorithms & AI
| Code | Criteria | Facing |
|---|---|---|
| 1d - Q1 | Does the app contain algorithms? | Assessor-facing |
| 1d - Q2 | How does the app use the algorithm? | Assessor-facing |
| 1d - Q3 | Does the app appear to use AI? | Assessor-facing |
| 1d - Q4 | What AI technique is used in the app? | Assessor-facing |
| 1d - Q5 | Is the AI monitored/ maintained? | Assessor-facing |
→1e. Monitoring
| Code | Criteria | Facing |
|---|---|---|
| 1e - Q1 | Does the app allow the monitoring of key health information? | Assessor-facing |
| 1e - Q2 | Does the app involve the recording of relevant data over time for the user to access and review (with no 'intelligent' manipulation of that data by the app)? | Assessor-facing |
| 1e - Q3 | Does the app involve the automated assessment or interpretation of relevant data to deliver alerts, insights, reminders or adjustments regarding the management of a specific condition? | Assessor-facing |
| 1e - Q4 | Is the app? | Assessor-facing |
| 1e - Q5 | Is the output of the app's monitoring intended to affect the treatment of an individual? | Assessor-facing |
| 1e - Q6 | Does the app allow others (i.e. not the user) to monitor or view the health data captured? | Assessor-facing |
| 1e - Q7 | Does the app automatically measure and/or record data about a user's specified condition, and transmit the data to a professional, carer or third party organisation, without any input from the user? | Assessor-facing |
| 1e - Q8 | Does the app generate any alarms or alerts from the data recorded by the app or a connected device? | Assessor-facing |
| 1e - Q9 | Are the alarms generated by user-defined filtering rules? | Assessor-facing |
→1f. Treatment & Prevention
| Code | Criteria | Facing |
|---|---|---|
| 1f - Q1 | Is the App used in combination with a drug molecule? | Assessor-facing |
| 1f - Q2 | Is the app intended to be (or does the developer claim it can be) used for the prevention of disease? | Assessor-facing |
| 1f - Q3 | Is the app intended to (or does the developer claim it can be used to) compensate an injury or handicap? | Assessor-facing |
| 1f - Q4 | Does the app contain a clinical calculator? | Assessor-facing |
| 1f - Q5 | What type of clinical calculator does the app contain? | Assessor-facing |
| 1f - Q6 | Does the app support healthcare professionals' decisions about treatments? | Assessor-facing |
| 1f - Q7 | How does the app prevent disease? | Assessor-facing |
| 1f - Q8 | Does the app provide treatment of a condition? | Assessor-facing |
| 1f - Q9 | What treatment does the app provide? | Assessor-facing |
| 1f - Q10 | Does the app guide the treatment of a condition? | Assessor-facing |
| 1f - Q11 | How does the app guide the treatment of the condition? | Assessor-facing |
| 1f - Q12 | Who does the App provide the treatment guidance to? | Assessor-facing |
| 1f - Q13 | Is the treatment provided independently of a healthcare professional? | Assessor-facing |
| 1f - Q14 | What type of intervention/ treatment does the app provide? | Assessor-facing |
| 1f - Q15 | Does the app follow the path of a procedure/treatment without making any decisions? | Assessor-facing |
| 1f - Q16 | Does a healthcare professional make the final decision regarding treatment based on advice and/or options displayed? | Assessor-facing |
| 1f - Q17 | Does the app automate the treatment pathway for an individual patient? | Assessor-facing |
| 1f - Q18 | Is the app intended to be (or does the developer claim it can be) used as a physical intervention to reduce the symptoms or severity of a disease, injury or handicap? | Assessor-facing |
→1g. Online Consultations
| Code | Criteria | Facing |
|---|---|---|
| 1g - Q1 | Can the app be used for patients to have online consultations, conversations, or related Health Care services with a healthcare professional? | Assessor-facing |
| 1g - Q2 | Does the App allow healthcare professionals to provide clinical advice, as opposed to the App providing advice itself? | Assessor-facing |
| 1g - Q3 | If the app allows healthcare professionals to provide clinical advice, as opposed to the app providing the advice itself, how does it do this? | Assessor-facing |
| 1g - Q4 | Is this through video consultation? | Assessor-facing |
→1h. Administrative & Pharmacy Services
| Code | Criteria | Facing |
|---|---|---|
| 1h - Q1 | Is this an administrative app which does not directly impact patient care? | Assessor-facing |
| 1h - Q2 | What administrative functions does the app provide? | Assessor-facing |
| 1h - Q3 | Is the app used to facilitate communication between healthcare professionals other than for consultation or the delivery of advice? | Assessor-facing |
| 1h - Q4 | Does the app allow users to book appointments with a healthcare professional? | Assessor-facing |
| 1h - Q5 | Does the app allow users to order and request prescriptions? | Assessor-facing |
| 1h - Q6 | Does the App constitute a Pharmacy Service? | Assessor-facing |
→1i. Notifications
| Code | Criteria | Facing |
|---|---|---|
| 1i - Q1 | Does the app send push notifications? | Assessor-facing |
| 1i - Q2 | Does the app send email notifications? | Assessor-facing |
→1j. External Devices & Integration
| Code | Criteria | Facing |
|---|---|---|
| 1j - Q1 | Is the app a companion of the device, as opposed to having been designed to connect with a third party manufacturer's device? | Assessor-facing |
| 1j - Q2 | Is the app's main functionality dependent on the user having one of the devices to connect with the app? | Assessor-facing |
| 1j - Q3 | Do any of the features or functions of the app appear to allow it to be used to control a medical device? | Assessor-facing |
| 1j - Q4 | What is the third party device the app connects to? | Assessor-facing |
| 1j - Q5 | Is the third party device a medical device? | Assessor-facing |
→1k. Forums & Communication
| Code | Criteria | Facing |
|---|---|---|
| 1k - Q1 | Are there opportunities to link with other users (buddying, forums or group education)? | Assessor-facing |
| 1k - Q2 | Does the App allow two-way communication between citizens, patients or healthcare professionals? | Assessor-facing |
| 1k - Q3 | Does the app provide an internally hosted forum or online community for their users? | Assessor-facing |
| 1k - Q4 | Does the app link to a third-party service to host a forum or online community for their users? | Assessor-facing |
→1l. Goal Setting & Customisation
| Code | Criteria | Facing |
|---|---|---|
| 1l - Q1 | Can the app presentation be customised by the user? | Assessor-facing |
| 1l - Q2 | Does the app respond to preferences in the device? | Assessor-facing |
| 1l - Q3 | Does the app provide gamification or goal setting features for the user? | Assessor-facing |
| 1l - Q4 | Does the app set goals for the user? | Assessor-facing |
| 1l - Q5 | Does the app allow the user to set goals for themselves? | Assessor-facing |
→1m. Business Model & Commercials
| Code | Criteria | Facing |
|---|---|---|
| 1m - Q1 | Is the App totally free? | Assessor-facing |
| 1m - Q2 | How is the app funded? | Assessor-facing |
| 1m - Q3 | Does the app contain adverts? | Assessor-facing |
→1n. Claimed Benefits
| Code | Criteria | Facing |
|---|---|---|
| 1n - Q1 | What are the claimed or implied benefits of the app? | Assessor-facing |
→2Data & Privacy
Considers how the product collects, uses, stores, shares and protects personal and sensitive data, and how transparently this is communicated to users through its privacy policy and related documentation, including alignment with relevant data protection legislation and developer-facing assurance questions.
→2a. Privacy Policy
| Code | Criteria | Facing |
|---|---|---|
| 2a - Q1 | Can you provide a copy or link to your product's transparency information? | Supplier-facing |
| 2a - Q2 | Document uploadProduct transparency information i.e DPIA or privacy notice/policy | Supplier-facing |
| 2a - Q3 | Can you provide the relevant product terms and conditions regarding use of user data, end user licence agreement or equivalent? | Supplier-facing |
| 2a - Q4 | If this does not apply to your product, state this and explain why. | Supplier-facing |
| 2a - Q5 | Document uploadProduct terms and conditions regarding use of user data, end user licence agreement or equivalent. | Supplier-facing |
| 2a - Q6 | Is there a Privacy Policy clearly available via the App/Web App/Website? | Assessor-facing |
| 2a - Q7 | Is there a Privacy Summary published anywhere by the developer? | Assessor-facing |
| 2a - Q8 | Is the Privacy Policy made immediately available when the user first opens the app? | Assessor-facing |
| 2a - Q9 | Is the policy made available when the user is signing up to use the services? | Assessor-facing |
| 2a - Q10 | Is it published within the app? | Assessor-facing |
| 2a - Q11 | Is it available externally via the app? | Assessor-facing |
| 2a - Q12 | Is it available via the relevant app store? | Assessor-facing |
| 2a - Q13 | What data does the Privacy Policy state the developer collects? (What the Developer says they collect) | Assessor-facing |
| 2a - Q14 | Is the policy accurate, with regards to the data the developer intends to collect? | Assessor-facing |
| 2a - Q15 | Does the app state that data collected by the app is stored locally, unless the user manually exports the data? | Assessor-facing |
| 2a - Q16 | Does the app state that the developer's liability ends at the point of the manual export of data? | Assessor-facing |
| 2a - Q17 | How does the developer obtain consent for the processing of user data? | Assessor-facing |
| 2a - Q18 | Does the Privacy Policy Provide the name and contact details of their Data Protection Officer (DPO), or similar individual representative for the company? | Assessor-facing |
| 2a - Q19 | Provide the details of the DPO: | Assessor-facing |
| 2a - Q20 | Does the developer fully inform the user of how they will collect data about them? Eg. Directly from the user or through third party sources | Assessor-facing |
| 2a - Q21 | Does the developer provide users with details on all the purposes of processing user data? | Assessor-facing |
| 2a - Q22 | What is automatically shared data used for? | Assessor-facing |
| 2a - Q23 | Does the developer appear to intend to share or process the user data collected by the app for any purposes that have not been made clear to the user, or for any purposes they deem necessary? | Assessor-facing |
| 2a - Q24 | Does the developer inform users that they would like to use their data for the purpose of marketing, or providing information on products or services that might be of interest to the user? | Assessor-facing |
| 2a - Q25 | Does the developer obtain informed consent separately, for the purpose of marketing? | Assessor-facing |
| 2a - Q26 | Is the user informed of how they can opt out of each of these activities? | Assessor-facing |
| 2a - Q27 | If the user can not opt out of all processing activity, does the developer clearly explain which activities they cannot opt out of and why? | Assessor-facing |
| 2a - Q28 | Is the user informed that their data will not be shared with other parties, except for the purposes that have been set out in the privacy policy? | Assessor-facing |
| 2a - Q29 | Does the data privacy policy or equivalent provide detail about where the data collected by the app will be stored (i.e. on the app or in an external data warehouse, cloud server etc.)? | Assessor-facing |
| 2a - Q30 | Where is the data stored? | Assessor-facing |
| 2a - Q31 | Does the Data Privacy Policy, or equivalent, state whether personal data is stored using recognised secure data storage technologies? | Assessor-facing |
| 2a - Q32 | Is all personally identifiable data encrypted in transit between the device and any external host storage? | Assessor-facing |
| 2a - Q33 | Is the user informed that online video consultations use secure encryption methods? | Assessor-facing |
| 2a - Q34 | Is the developer compliant with recognised NHS Data Standards? | Assessor-facing |
| 2a - Q35 | Does the policy state its compliance with recognised International Data Management Standards? (ISO, BSI)? | Assessor-facing |
| 2a - Q36 | Is there a policy or statement that contains details of the length of time data will be retained for? | Assessor-facing |
| 2a - Q37 | Is there a policy or statement that contains details of the method for data destruction? | Assessor-facing |
| 2a - Q38 | Is there a policy or statement that sets out a process for managing data confidentiality breaches? | Assessor-facing |
| 2a - Q39 | Is there a policy or statement that confirms the App's compliance with GDPR? | Assessor-facing |
| 2a - Q40 | Is the user informed of the legal basis for which data is collected from them? i.e. Consent, Performance of Contract, Legal Obligation, Vital Interests, Public Interest or Legitimate Interest. Please Specify. | Assessor-facing |
| 2a - Q41 | Is the user informed of the developer's intent to ensure that data minimisation principles are met? | Assessor-facing |
| 2a - Q42 | Is there a statement that the policy will be updated duly should the purpose of data collection change? This may mean re-obtaining user consent (if consent was the lawful basis). | Assessor-facing |
| 2a - Q43 | Are users informed of their rights with regards to their data? Are users clearly informed of the individual privacy rights they are entitled to expect under GDPR? | Assessor-facing |
| 2a - Q44 | Has the developer made the existence of the data subject's right to request that their personal data is deleted clear? | Assessor-facing |
| 2a - Q45 | Has the developer made the existence of the data subject's right to access their personal data clear? | Assessor-facing |
| 2a - Q46 | Has the developer made the existence of the data subject's right to rectify their personal data clear? | Assessor-facing |
| 2a - Q47 | Has the developer made the existence of the data subject's right to restrict the use of their personal data clear? | Assessor-facing |
| 2a - Q48 | Has the developer made the existence of the data subject's right to object to the processing of his/her personal data clear? | Assessor-facing |
| 2a - Q49 | Has the developer made the existence of the data subject's right to portability of their personal data clear? | Assessor-facing |
| 2a - Q50 | Has the developer made the existence of the data subject's withdraw consent for the use of their personal data clear? | Assessor-facing |
| 2a - Q51 | Has the developer made clear the existence of the user's right to request that they are not subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her? | Assessor-facing |
| 2a - Q52 | Is the user informed of the time frame in which the developer will respond to any requests to exercise their rights? This time frame should be within one month of receipt of any request. | Assessor-facing |
| 2a - Q53 | Are users clearly informed of the use of cookies when first landing on the developers site/app? | Assessor-facing |
| 2a - Q54 | Are user's required to confirm their acceptance of the developer's use of cookies, when initially informed of the use? | Assessor-facing |
| 2a - Q55 | Does the developer provide a full Cookie Policy, separate from the Terms of Service and/or Privacy Policy? | Assessor-facing |
| 2a - Q56 | Is the app 'particularly likely' to be used by children, even if they are not the primary market for the app? | Assessor-facing |
| 2a - Q57 | Are users informed of how they can report, to the developer, any knowledge of a child accessing the app and providing personal data, without parental consent? | Assessor-facing |
| 2a - Q58 | Has the privacy policy been written in plain, age-appropriate language? | Assessor-facing |
| 2a - Q59 | Is the user made aware that by following links to third party websites, the developer's policies no longer apply and that the user should make themselves aware of the third party's policies? | Assessor-facing |
| 2a - Q60 | Is the user informed of how they can make further enquiries about the company's privacy policy? | Assessor-facing |
| 2a - Q61 | Does the app allow the user to set their preferences for sharing the app data with or from other apps (e.g. Facebook / Instagram/Fitbit etc)? | Assessor-facing |
| 2a - Q62 | Is there functionality within the app to allow the user to set their preferences for sharing the app data with other users (e.g. Clinician / Carer / Family Member / Forums / Buddies)? | Assessor-facing |
| 2a - Q63 | Is it strictly necessary for anyone to easily access the information that persists on the app? eg. to access health info during an emergency | Assessor-facing |
| 2a - Q64 | Are users provided options to introduce additional security measures to protect their data on the app? eg. set additional pass codes for access to the app, after accessing the device is unlocked. | Assessor-facing |
| 2a - Q65 | Does the app use a sign up/sign in verification/authentication model? | Assessor-facing |
| 2a - Q66 | What type of model is being used? | Assessor-facing |
| 2a - Q67 | Are users made aware of the use of strictly necessary cookies? | Assessor-facing |
| 2a - Q68 | Is user consent obtained for the use of non strictly necessary cookies? | Assessor-facing |
| 2a - Q69 | Are users informed of how they can easily opt out of the use of cookies? | Assessor-facing |
| 2a - Q70 | Is the product aimed at children or likely to be used by children? | Assessor-facing |
| 2a - Q71 | Has a process been designed and put in place that allows children to easily access, understand and exercise their own data protection rights? | Assessor-facing |
| 2a - Q72 | Where consent was the legal basis for processing data was consent, at the time the individual was a child, then requests for the erasure of data are complied with, whenever possible? | Assessor-facing |
| 2a - Q73 | Have children been consulted when designing this processing practice? | Assessor-facing |
| 2a - Q74 | Is consent sought from a responsible parent /guardian? | Assessor-facing |
| 2a - Q75 | Does the developer ensure they do not seek parental/guardian consent when providing online preventive or counselling services to children? | Assessor-facing |
| 2a - Q76 | Are there two separate versions of privacy policies, one aimed at the child and the other at the responsible parent/guardian? | Assessor-facing |
| 2a - Q77 | When marketing the product outside of their country of residence, has the developer taken into consideration other jurisdictional laws regarding children's privacy (eg. age restrictions)? | Assessor-facing |
→2b. DTAC Developer Questions
| Code | Criteria | Facing |
|---|---|---|
| 2b - Q1 | Does the product or service process any personal data or data about deceased individuals? | Assessor-facing |
| 2b - Q2 | Do you engage in 'high risk' processing activities, that mean you are required to to complete a DPIA? | Supplier-facing |
| 2b - Q3 | Document uploadDPIA | Supplier-facing |
| 2b - Q4 | Does your product have access to any personally identifiable data or NHS held patient data? | Assessor-facing |
| 2b - Q5 | Are you required to register with the Information Commissioner's Office? The ICO has a registration self-assessment tool that you can use to support this determination. https://ico.org.uk/for-organisations/data-protection-fee/data-protection-fee-self-assessment/ | Supplier-facing |
| 2b - Q6 | Document uploadInformation Commissioner's Office current registration or justification for no registration | Supplier-facing |
| 2b - Q7 | If you are required to register with the Information Commissioner please attach evidence of registration and payment. . If you are not required to register please attach a completed self-assessment showing the outcome from the Information Commissioner and your responses which support this determination. | Assessor-facing |
| 2b - Q8 | Has the developer provided evidence of: Current registration from the Information Commissioner Current registration from a similar regulatory authority Alternative documentation stating why they are not required to register None of the above | Assessor-facing |
| 2b - Q9 | Provide EU/UK data protection registration details: | Assessor-facing |
| 2b - Q10 | Is the evidence sufficient in supporting the developers belief that they are not required to register with the ICO or a similar regulatory authority? | Assessor-facing |
| 2b - Q11 | Is the developer of the App a public authority or body? | Assessor-facing |
| 2b - Q12 | Do you have a nominated Data Protection Officer (DPO)? | Supplier-facing |
| 2b - Q13 | If you are required to have a nominated Data Protection Officer please provide their name. If you are not required to have a DPO please attach a completed self assessment showing the outcome from the Information Commissioner and your responses which support this determination. | Supplier-facing |
| 2b - Q14 | Has the developer nominated a Data Protection Officer (DPO)? | Assessor-facing |
| 2b - Q15 | Is the developer required to have a Data Protection Officer? | Assessor-facing |
| 2b - Q16 | Has the developer named a DPO? | Assessor-facing |
| 2b - Q17 | Is there evidence that the DPO has the necessary professional qualities, and in particular, experience and expert knowledge of data protection law? | Assessor-facing |
| 2b - Q18 | Does the DPO hold a position within the organisation that may lead him or her to determine the purposes and the means of the processing of personal data, or require him or her to engage in further tasks and duties that may result in a conflict of interests with the primary tasks of a DPO? | Assessor-facing |
| 2b - Q19 | Has the developer provided alternative documentation that contains a clear justifiable reason as to why they do not need a DPO? | Assessor-facing |
| 2b - Q20 | Do any of the developer's processing activities include automated systematic and extensive profiling with significant effects? | Assessor-facing |
| 2b - Q21 | Do any of the developer's processing activities include large scale use of sensitive/special category data? | Assessor-facing |
| 2b - Q22 | Do any of the developer's processing activities include systematic monitoring of a publicly accessible area on a large scale? | Assessor-facing |
| 2b - Q23 | Do any of the developer's processing activities include any of the following indicators of high risk processing? Evaluation or scoring. Automated decision-making with legal or similar significant effect. Systematic monitoring. Sensitive data or data of a highly personal nature. Data processing/profiling on a large scale. Matching or combining datasets. Data concerning vulnerable data subjects. Innovative use or applying new technological or organisational solutions. Preventing data subjects from exercising a right or using a service or contract. Invisible processing. Risk of physical harm. | Assessor-facing |
| 2b - Q24 | Please attach the Data Protection Impact Assessment (DPIA) relating to the product. | Assessor-facing |
| 2b - Q25 | Is the developer required to have written a DPIA? | Assessor-facing |
| 2b - Q26 | Has the developer submitted a DPIA or made a DPIA publicly available? | Assessor-facing |
| 2b - Q27 | Does the DPIA describe how the developer will collect data about individuals? | Assessor-facing |
| 2b - Q28 | Does the DPIA describe how the developer will store the data collected? | Assessor-facing |
| 2b - Q29 | Does the DPIA describe what the data collected by the developer will be used for? | Assessor-facing |
| 2b - Q30 | Does the DPIA provide details of who will have access to the data collected? | Assessor-facing |
| 2b - Q31 | Does the DPIA provide details of who the developer will share data with (any third parties)? | Assessor-facing |
| 2b - Q32 | Does the information regarding data sharing include details of the developer's use of any processors? | Assessor-facing |
| 2b - Q33 | Does the DPIA provide details of their own data retention periods? | Assessor-facing |
| 2b - Q34 | Does the DPIA provide details of the length of time each third party recipient of data will retain data for? | Assessor-facing |
| 2b - Q35 | Does the DPIA provide details of the security measures that have been put in place in order to protect the data being processed? | Assessor-facing |
| 2b - Q36 | Does the DPIA provide details of the developer using any new technologies? | Assessor-facing |
| 2b - Q37 | Does the DPIA describe any novel types of processing that the developer is using? | Assessor-facing |
| 2b - Q38 | Does the DPIA describe which screening criteria they have identified/flagged as high risk? | Assessor-facing |
| 2b - Q39 | Has the developer sufficiently established the nature of the data processing? | Assessor-facing |
| 2b - Q40 | Does the DPIA describe the nature of the personal data being processed? | Assessor-facing |
| 2b - Q41 | Does the DPIA describe the volumes and variety of personal data that is being processed? | Assessor-facing |
| 2b - Q42 | Does the DPIA describe the sensitive nature of any items of personal data being processed? | Assessor-facing |
| 2b - Q43 | Does the DPIA provide details of the extent and frequency of the processing? | Assessor-facing |
| 2b - Q44 | Does the DPIA provide details on the duration of any processing activities covered by the DPIA? | Assessor-facing |
| 2b - Q45 | Does the DPIA detail the number of data subjects involved in the processing activities described? | Assessor-facing |
| 2b - Q46 | Does the DPIA provide details of the geographical area covered by the processing activities described? | Assessor-facing |
| 2b - Q47 | Has the developer sufficiently established the scope of the data processing? | Assessor-facing |
| 2b - Q48 | Does the DPIA identify all sources of the data being collected? | Assessor-facing |
| 2b - Q49 | Does the DPIA describe the nature of the developer's relationship with the individuals whose data is being processed? | Assessor-facing |
| 2b - Q50 | Does the DPIA describe how far individuals have control over their data? | Assessor-facing |
| 2b - Q51 | Does the DPIA describe how far individuals are likely to expect the processing of their data to occur? | Assessor-facing |
| 2b - Q52 | Does the DPIA provide details on whether the data subjects concerned include children or other vulnerable individuals? | Assessor-facing |
| 2b - Q53 | Does the DPIA identify any previous experience that the developer has in dealing with the intended type of processing? | Assessor-facing |
| 2b - Q54 | Does the DPIA identify any relevant advances in the technology and/or security being used in the processing? | Assessor-facing |
| 2b - Q55 | Does the DPIA identify any current issues of public concern with regards to the intended processing? | Assessor-facing |
| 2b - Q56 | Does the DPIA detail compliances with any UK GDPR codes of conduct or UK certification schemes? | Assessor-facing |
| 2b - Q57 | Does the DPIA detail whether the developer has considered and complied with relevant codes of practice? | Assessor-facing |
| 2b - Q58 | Has the developer sufficiently established the context of the data processing? | Assessor-facing |
| 2b - Q59 | Does the DPIA provide details of the developer's legitimate interests, with regards to the purpose of processing data? | Assessor-facing |
| 2b - Q60 | Does the DPIA detail the legal basis/bases upon which the developer relies for processing the data collected? | Assessor-facing |
| 2b - Q61 | Does the DPIA provide details of the intended outcomes of the data processing for the individuals concerned? | Assessor-facing |
| 2b - Q62 | Does the DPIA provide details of the anticipated benefits of the processing for the developer or for society as a whole? | Assessor-facing |
| 2b - Q63 | Has the developer sufficiently established the purpose of the data processing? | Assessor-facing |
| 2b - Q64 | Has the developer sought and documented the views of the individuals whose data will be processed, or their representatives? | Assessor-facing |
| 2b - Q65 | Does the DPIA provide a justifiable reason for not carrying out consultation with individuals or their representatives? | Assessor-facing |
| 2b - Q66 | Does the DPIA provide details of consultation with any third party data processors who will be involved in the processing of user data? | Assessor-facing |
| 2b - Q67 | Does the DPIA provide details of consultation with all relevant internal stakeholders? | Assessor-facing |
| 2b - Q68 | Does the DPIA provide details of any advice being sought from other independent experts? | Assessor-facing |
| 2b - Q69 | Does the DPIA include details on how the developers plans will help achieve their purpose? | Assessor-facing |
| 2b - Q70 | Does the DPIA provide evidence that the developer has considered whether there are any other reasonable ways to achieve the same result? | Assessor-facing |
| 2b - Q71 | Does the DPIA include details on how the developer will prevent function creep? | Assessor-facing |
| 2b - Q72 | Does the DPIA include details on how the developer will ensure data quality? | Assessor-facing |
| 2b - Q73 | Does the DPIA include details on how the developer will ensure data minimisation? | Assessor-facing |
| 2b - Q74 | Does the DPIA include details on how the developer intends to provide privacy information to individuals? | Assessor-facing |
| 2b - Q75 | Does the DPIA include details on how the developer intends to implement and support individuals' rights? | Assessor-facing |
| 2b - Q76 | Does the DPIA include details on the measures that will be taken to ensure any processors comply with their obligations? | Assessor-facing |
| 2b - Q77 | Does the DPIA include details of the safeguarding measures that have been put in place for international transfers of data? | Assessor-facing |
| 2b - Q78 | Has the developer sufficiently established the necessity and proportionality of the data processing? | Assessor-facing |
| 2b - Q79 | Has the developer detailed, in the DPIA, all the risks that they have identified relating to each of their processing activities and those relating to third party processors? | Assessor-facing |
| 2b - Q80 | Are there any additional risks, that you have been able to identify, which have not been included in the DPIA? (please detail) | Assessor-facing |
| 2b - Q81 | Does the DPIA include an assessment of potential security risks? | Assessor-facing |
| 2b - Q82 | Does the assessment of security risks include the sources of the risks and the potential impacts of the each type of breach? | Assessor-facing |
| 2b - Q83 | Has an objective approach to assessing the risks been taken through the use of a structured risk matrix that takes into account both the likelihood of harm and the severity of the impact? | Assessor-facing |
| 2b - Q84 | Has the developer used a different, but acceptable structured approach to objectively assessing the risks associated with their processing activities? | Assessor-facing |
| 2b - Q85 | Has the developer also considered their own corporate risk, such as the impacts of regulatory action, reputational damage of loss of public trust? | Assessor-facing |
| 2b - Q86 | Has the developer detailed the source of each risk that they have identified? | Assessor-facing |
| 2b - Q87 | Has the developer conducted an acceptable risk assessment that has taken into consideration the likelihood and severity of the risks, using an objective assessment approach? | Assessor-facing |
| 2b - Q88 | Has the developer identified the measures that they will put in place in order to mitigate each of the identified risks? | Assessor-facing |
| 2b - Q89 | Where mitigations have not been put in place, has the developer provided justified reasons for not doing so? | Assessor-facing |
| 2b - Q90 | Are there any additional mitigations, that you have been able to identify as achievable, that the developer does not appear to have considered? (please detail). | Assessor-facing |
| 2b - Q91 | Does the DPIA contain details of the additional measures that the developer planned on taking? | Assessor-facing |
| 2b - Q92 | Does the DPIA contain a record on whether each of the risks have been removed, reduced, or accepted? | Assessor-facing |
| 2b - Q93 | Does the DPIA provide details of the overall residual risk, after taking additional measures? | Assessor-facing |
| 2b - Q94 | Have any of the residual risks been assessed as being "high risk"? | Assessor-facing |
| 2b - Q95 | Does the DPIA provide details that the need to consult the ICO has been considered? | Assessor-facing |
| 2b - Q96 | Does the DPIA provide details or evidence of the advice of the DPO being sought, as part of the sign-off process? | Assessor-facing |
| 2b - Q97 | If the developer has decided not to follow the advice provided by the DPO, have they recorded their reasons? | Assessor-facing |
| 2b - Q98 | Has the developer provided details on how they will treat the risks identified through mitigation and ensuring the protection of personal data, while demonstrating compliance with the GDPR? | Assessor-facing |
| 2b - Q99 | Please confirm your risk assessments and mitigations / access controls / system level security policies have been signed-off by your Data Protection Officer (if one is in place) or an accountable officer where exempt in question DP2_2. | Assessor-facing |
| 2b - Q100 | Has the developer confirmed that their DPO (or accountable officer) has signed-off the risk assessments and mitigations /access controls and system level security policies? | Assessor-facing |
| 2b - Q101 | Has the developer submitted evidence that their, risk assessments and mitigations, system controls and system level security policies have been signed off by their DPO (or accountable officer)? | Assessor-facing |
| 2b - Q102 | Please confirm where you store and process data (including any third party products your product uses) | Supplier-facing |
| 2b - Q103 | Document uploadIf the country in which you store and process data is not considered adequate by the ICO, please provide any evidence of the appropriate safeguards in place. | Supplier-facing |
| 2b - Q104 | Are there any locations that the developer has not confirmed they will store and process data (including any third party products their product uses)? | Assessor-facing |
| 2b - Q105 | If you store or process data outside of the UK, please name the country and set out how the arrangements are compliant with current legislation | Assessor-facing |
| 2b - Q106 | If the developer processes or stores data outside of the UK, have they stated the country in which this activity takes place? | Assessor-facing |
| 2b - Q107 | If the developer stores and/or processes data outside the UK, have they provided a sufficient explanation as to how the arrangements for processing data, outside the UK, ensure data remains within the EU or are processed in compliance with current legislation? | Assessor-facing |
| 2b - Q108 | Please confirm whether the DPIA meets all requirements. | Assessor-facing |
| 2b - Q109 | Please provide a summary of your findings and recommended improvements for Data Protection: | Assessor-facing |
→3Evidence of Impact
Considers the regulatory status of the product (including registration requirements and medical device classification) alongside the evidence available to support any clinical or behavioural-change claims it makes, the professional backing behind it, and its compliance with a proportionate evidence standards framework.
→3a. Registration Requirements
| Code | Criteria | Facing |
|---|---|---|
| 3a - Q1 | Do you deliver any services via the product in England which may require registration with the Care Quality Commission (CQC)? | Supplier-facing |
| 3a - Q2 | Document uploadCQC registration (certificate, last inspection results, CQC account number) | Supplier-facing |
| 3a - Q3 | Does the App deliver any services in England which may require registration with the Care Quality Commission (CQC)? | Assessor-facing |
| 3a - Q4 | Is the Developer/Publisher Registered with the CQC? | Assessor-facing |
| 3a - Q5 | Detail the CQC Account Number and the date of the most recent certificate. | Assessor-facing |
| 3a - Q6 | When was the last CQC inspection complete? | Assessor-facing |
| 3a - Q7 | When is the planned date of the first or next inspection? | Assessor-facing |
| 3a - Q8 | What were the outcomes of the last inspection? | Assessor-facing |
| 3a - Q9 | Do you deliver any services via the product in Wales which may require registration with Health Inspectorate Wales (HIW)? | Supplier-facing |
| 3a - Q10 | Document uploadHIW registration (certificate, last inspection results, HIW account number) | Supplier-facing |
| 3a - Q11 | Does the product provide any services involving a GMC registered doctor? | Assessor-facing |
| 3a - Q12 | Is the app supplier providing services based in Wales (e.g. a private psychiatrist based in Cardiff)? | Assessor-facing |
| 3a - Q13 | Is the app supplier registered with HIW? | Assessor-facing |
→3b. Medical Devices
| Code | Criteria | Facing |
|---|---|---|
| 3b - Q1 | Does your DHT product, or any component within it, qualify as Software or Artificial Intelligence as a Medical Device under the UK Medical Devices Regulations 2002? | Supplier-facing |
| 3b - Q2 | Is your product classified as a standalone medical device? | Supplier-facing |
| 3b - Q3 | Document uploadPAQ form and relevant attachments i.e. conformity certificate | Supplier-facing |
| 3b - Q4 | Is the app a medical device? (autofill but there to validate) | Assessor-facing |
| 3b - Q5 | Does the app have a CE Mark? | Assessor-facing |
| 3b - Q6 | Does the app state that it has been assessed by the MHRA or other UK based notified body (SEE LIST) and does not require a CE Mark? | Assessor-facing |
| 3b - Q7 | What Class is the App Certified as? | Assessor-facing |
| 3b - Q8 | If the UK Medical Device Regulations 2002 are applicable, please provide your Declaration of Conformity and, if applicable, certificate of conformity issued by a Notified Body / UK Approved Body | Assessor-facing |
| 3b - Q9 | Is your product registered with Medicines and Healthcare Products Regulatory Authority (MHRA) if it falls within the Medical Device Regulations? | Assessor-facing |
| 3b - Q10 | If the developer confirmed that their product is registered with the MHRA, have they provided a valid MHRA registration number? | Assessor-facing |
| 3b - Q11 | Is the product a medical device, as defined by the FDA? | Assessor-facing |
| 3b - Q12 | Is the app exempt from 510(k) premarket notification? | Assessor-facing |
| 3b - Q13 | Which pathway has the app been authorised through by the FDA? | Assessor-facing |
| 3b - Q14 | What Device Class is the App certified as? | Assessor-facing |
→3c. ESF Determination
| Code | Criteria | Facing |
|---|---|---|
| 3c - Q1 | Is the app ESF Tier 3b? | Assessor-facing |
| 3c - Q2 | Is the app ESF Tier 3a? | Assessor-facing |
| 3c - Q3 | Is the app ESF Tier 2b? | Assessor-facing |
| 3c - Q4 | Is the app ESF Tier 2a? | Assessor-facing |
| 3c - Q5 | Is the app ESF Tier 1? | Assessor-facing |
→3d. Evidence Analysis
| Code | Criteria | Facing |
|---|---|---|
| 3d - Q1 | What type/s of evidence is available? | Assessor-facing |
| 3d - Q2 | How many pieces of evidence does the app provide? | Assessor-facing |
| 3d - Q3 | How many RCT's and/or observational studies does the app have? | Assessor-facing |
| 3d - Q4 | What category does the evidence relate to? | Assessor-facing |
| 3d - Q5 | What benefit does the evidence relate to? | Assessor-facing |
| 3d - Q6 | Provide links to the publicly available evidence/published evidence that the developer has provided. | Assessor-facing |
| 3d - Q7 | Is the sample size appropriate? | Assessor-facing |
| 3d - Q8 | Does the evidence found provide a p-value or Confidence Interval (CI)? | Assessor-facing |
| 3d - Q9 | Does the P-Value demonstrate significance (p<0.05)? | Assessor-facing |
| 3d - Q10 | Does the P-Value demonstrate near significance (p<0.2)? | Assessor-facing |
| 3d - Q11 | Is there a comparator? | Assessor-facing |
| 3d - Q12 | Is the comparator validated? | Assessor-facing |
| 3d - Q13 | For each type of relevant research article: Has the research article been published in a Journal? | Assessor-facing |
| 3d - Q14 | For each type of relevant research article: Does the journal use peer-review? | Assessor-facing |
| 3d - Q15 | For each type of relevant research article: Is the research article supplied a conference poster? | Assessor-facing |
| 3d - Q16 | For each type of relevant research article: Is the research article self published only? | Assessor-facing |
| 3d - Q17 | Does the sample of the research study meet the relevant characteristics for the users of the app? | Assessor-facing |
→3e. Behavioural Change
| Code | Criteria | Facing |
|---|---|---|
| 3e - Q1 | Does the App have its own high quality study? | Assessor-facing |
| 3e - Q2 | Does the App reference and evidence its behaviour change technique? | Assessor-facing |
→3f. Professional Backing
| Code | Criteria | Facing |
|---|---|---|
| 3f - Q1 | Is there a suitably qualified Professional involved in the Development team of the App? | Assessor-facing |
| 3f - Q2 | Who was the suitably qualified Professional involved, and what are their qualifications? | Assessor-facing |
| 3f - Q3 | Has the app been developed by a recognised or national health body? | Assessor-facing |
| 3f - Q4 | Who was the recognized or national health body involved in the development of the app? | Assessor-facing |
| 3f - Q5 | Is there evidence of an endorsement by a relevant body? | Assessor-facing |
| 3f - Q6 | Who are the relevant body who have endorsed the app? | Assessor-facing |
| 3f - Q7 | Are organisations using the App? | Assessor-facing |
| 3f - Q8 | Which relevant organization are using the app? | Assessor-facing |
| 3f - Q9 | Is there a statement that it has been positively evaluated or validated by a relevant healthcare professional? | Assessor-facing |
| 3f - Q10 | Please specify who the relevant experts are and what qualifications they hold. | Assessor-facing |
| 3f - Q11 | Is there evidence within the app that the developer has validated any guidance with relevant reliable information sources or references? | Assessor-facing |
| 3f - Q12 | Is there any evidence within the app that the developer has validated the information, advice or guidance with relevant and appropriate academic studies or relevant academic expert input? | Assessor-facing |
| 3f - Q13 | Does the DHT offer 24-7 peer or clinical support? | Assessor-facing |
| 3f - Q14 | What kind of support is offered? | Assessor-facing |
| 3f - Q15 | Are trained professionals involved in supporting? | Assessor-facing |
| 3f - Q16 | Who are these trained professionals who offer support? | Assessor-facing |
| 3f - Q17 | Is appropriate peer reviewed scientific literature used in the development of the health app? | Assessor-facing |
→3g. Safety / Risk Management
| Code | Criteria | Facing |
|---|---|---|
| 3g - Q1 | Is there a statement or any evidence showing that appropriate safeguarding measures are in place around peer-support and other communication functions within the platform? | Assessor-facing |
| 3g - Q2 | Does the Developer clearly identify who the app should be used by? | Assessor-facing |
| 3g - Q3 | Does the Developer clearly identify who the app should not be used by? | Assessor-facing |
| 3g - Q4 | Does the Developer publish their risk management processes? | Assessor-facing |
| 3g - Q5 | Does the Developer make clear risks associated with using the app? | Assessor-facing |
| 3g - Q6 | Is there a way for the user to confirm that the data input is accurate? | Assessor-facing |
| 3g - Q7 | Does the Developer list a Clinical Safety Officer on/in any relevant sites/content? | Assessor-facing |
| 3g - Q8 | Please provide more detail | Assessor-facing |
→3h. ESF Compliance
| Code | Criteria | Facing |
|---|---|---|
| 3h - Q1 | Has the app met Tier 1 minimum requirements? | Assessor-facing |
| 3h - Q2 | Has the app met Tier 2a minimum requirements? | Assessor-facing |
| 3h - Q3 | Has the app met Tier 2b minimum requirements? | Assessor-facing |
| 3h - Q4 | Has the app met Tier 3a minimum requirements? | Assessor-facing |
| 3h - Q5 | Has the app met Tier 3b minimum requirements? | Assessor-facing |
| 3h - Q6 | Does the app have appropriate evidence for the ESF tier? | Assessor-facing |
→4Clinical Safety
Considers whether the product has been developed and is maintained in line with recognised clinical risk management standards, including its clinical risk management system, safety case, hazard log, supporting documentation, and the role of a named Clinical Safety Officer.
→4a. DCB0129 Compliance
| Code | Criteria | Facing |
|---|---|---|
| 4a - Q1 | Is your product designed to provide electronic information to influence, support or manage the real time or near real time direct care of patients/service users? | Supplier-facing |
| 4a - Q2 | Please provide a justification for why your product does not fall in scope of DCB0129 | Supplier-facing |
| 4a - Q3 | Document uploadClinical Safety Case Report | Supplier-facing |
| 4a - Q4 | Document uploadHazard Log | Supplier-facing |
| 4a - Q5 | Document uploadClinical Risk Management System. | Supplier-facing |
| 4a - Q6 | Is the developer in scope of DCB0129? | Assessor-facing |
| 4a - Q7 | Have you undertaken Clinical Risk Management activities for this product that complies with DCB0129? | Assessor-facing |
| 4a - Q8 | If the developer does not believe they are in scope of DCB0129, have they provided a justification? | Assessor-facing |
| 4a - Q9 | Is the proposed justification accurate? | Assessor-facing |
→4b. Clinical Risk Management System
| Code | Criteria | Facing |
|---|---|---|
| 4b - Q1 | Has the developer detailed their Clinical Risk Management System? | Assessor-facing |
| 4b - Q2 | Does the clinical risk management governance contain the governance arrangements that are in place? (This should include an organisation chart, Personnel, and Governance Arrangements) | Assessor-facing |
| 4b - Q3 | Does the Clinical Risk Management Documentation contain the governance arrangements that are in place? (This should include an organisation chart, Personnel, and Governance Arrangements) | Assessor-facing |
| 4b - Q4 | Does the clinical risk management system outline the clinical risk management activities (The clinical safety process - Hazard ID, Risk assessment, Evaluation, Control, Incident management) | Assessor-facing |
| 4b - Q5 | Does the Clinical Risk Management System outline the Clinical Safety competence and training given? | Assessor-facing |
| 4b - Q6 | Does the clinical risk management system outline the process for Audits? (Audits section should include an overview, Internal safety audits and any third party supplier audits) | Assessor-facing |
| 4b - Q7 | Has the developer provided a sufficient level of information regarding their Clinical Risk Management System? | Assessor-facing |
→4c. Documentation
| Code | Criteria | Facing |
|---|---|---|
| 4c - Q1 | Please supply your Clinical Safety Case Report and Hazard Log | Assessor-facing |
| 4c - Q2 | If the App/Solution has been deemed in scope, has the Developer supplied suitable Risk Management Documentation? | Assessor-facing |
| 4c - Q3 | Has the developer provided their Clinical Safety Risk Management Documentation? | Assessor-facing |
| 4c - Q4 | Does the Developer outline the need for the Risk Management Documentation? | Assessor-facing |
| 4c - Q5 | Does the Business Continuity Plan include an analysis of Clinical Risk? | Assessor-facing |
→4d. Safety Case
| Code | Criteria | Facing |
|---|---|---|
| 4d - Q1 | Does the Safety Case have full version history and issue date published? | Assessor-facing |
| 4d - Q2 | Is there evidence of a CSO reviewing, contributing or approving the safety case? | Assessor-facing |
| 4d - Q3 | Has the Developer described their clinical risk management system? (identification of key personnel, their roles and responsibilities; identification of clinical risk management governance structure.) | Assessor-facing |
| 4d - Q4 | Does the Safety Case make a mention of a test summary? (Summary of any outstanding test issues and the impact on clinical safety) | Assessor-facing |
| 4d - Q5 | Does the Safety Case have a summary statement showing sign off from the CSO. | Assessor-facing |
| 4d - Q6 | Is the Clinical Risk analysis carried out by a multi-disciplinary group including a Clinical Safety Officer? | Assessor-facing |
| 4d - Q7 | Does the Risk Management Documentation make it clear where the App fits into the Clinical Workflow – How would a patient use the app appropriately to become well again? | Assessor-facing |
| 4d - Q8 | Are there any third-party products integrated within the Health IT System to be released? | Assessor-facing |
| 4d - Q9 | What are the third-party products integrated with the Health IT System? | Assessor-facing |
| 4d - Q10 | Have risk assessments taken place on these products? | Assessor-facing |
| 4d - Q11 | Have risks associated with third parties been included in the Hazard Log? | Assessor-facing |
| 4d - Q12 | Is there usability and human factors related evidence within the scope? | Assessor-facing |
| 4d - Q13 | Has the Developer disclosed any infrastructure at the Health Organisation that will be needed within the Manufacturer's scope of influence, required to support the deployment of the Health IT System. This may be achieved by the Manufacturer specifying the minimum system requirements | Assessor-facing |
| 4d - Q14 | Where data migration is to be undertaken by the Developer it should be included in the scope of the clinical risk management activities. Is the Developer undertaking any Data Migration? | Assessor-facing |
| 4d - Q15 | Is the Data Migration being undertaken by the Developer properly covered in the documentation? | Assessor-facing |
| 4d - Q16 | Has the end to end clinical process, including functionality and how that functionality is used, been considered? | Assessor-facing |
| 4d - Q17 | Has inter and intra Health IT System messaging been considered? | Assessor-facing |
| 4d - Q18 | Has the Health IT System architecture and design been considered? | Assessor-facing |
| 4d - Q19 | Has the Developer implemented the clinical risk analysis activities defined in the Clinical Risk Management Plan? | Assessor-facing |
| 4d - Q20 | Has the Manufacturer defined the clinical scope of the Health IT System which is to be delivered? | Assessor-facing |
| 4d - Q21 | Has the Manufacturer defined the intended use of the Health IT System which is to be delivered? | Assessor-facing |
| 4d - Q22 | Has the Developer deploying the Health IT System considered how it will impact on the current business processes and ways of working? | Assessor-facing |
→4e. Hazard Log
| Code | Criteria | Facing |
|---|---|---|
| 4e - Q1 | Has the developer identified any hazards associated with the data migration that has been analyzed and suitably mitigated (working in conjunction with the relevant health organization, as appropriate)? | Assessor-facing |
| 4e - Q2 | Is there evidence of a CSO reviewing, contributing or approving the hazard log | Assessor-facing |
| 4e - Q3 | Do the harms outline what the clinical impact may be for the user/patient? | Assessor-facing |
| 4e - Q4 | Are hazards split incorrectly into potential and actual harm? | Assessor-facing |
| 4e - Q5 | Does the Hazard Log have full version history and issue date published? | Assessor-facing |
| 4e - Q6 | For each identified hazard, has the Developer evaluated whether the initial clinical risk is acceptable? | Assessor-facing |
| 4e - Q7 | Has the Developer used the risk acceptability criteria previously defined? | Assessor-facing |
| 4e - Q8 | Is there a clear matrix, which is used to define the risk ratings? | Assessor-facing |
| 4e - Q9 | Has the Developer assessed Proposed clinical risk control measures to determine whether new hazards will be introduced as a result of the measures? | Assessor-facing |
| 4e - Q10 | Has the Developer assessed proposed clinical risk control measures to determine whether the clinical risks for previously identified hazards will be affected? | Assessor-facing |
| 4e - Q11 | Is the Developer managing new hazards, or increased clinical risks? | Assessor-facing |
| 4e - Q12 | Where a residual clinical risk is judged unacceptable, has the Developer identified additional clinical risk control measures in order to reduce the clinical risk? | Assessor-facing |
| 4e - Q13 | If the Developer determines that no suitable risk control measures are possible then has the Developer conducted a clinical risk benefit analysis of the clinical risk? | Assessor-facing |
| 4e - Q14 | Where a residual clinical risk is deemed unacceptable and further clinical risk control is not practicable, has the Developer determined if the clinical benefits of the intended use outweigh the residual clinical risk? | Assessor-facing |
| 4e - Q15 | Do the clinical benefits outweigh the residual clinical risk? (If not then the clinical risk remains unacceptable and the project SHOULD be re-appraised) | Assessor-facing |
| 4e - Q16 | Has the Developer implemented the clinical risk control measures identified? (except where these are to be implemented by another organisation.) | Assessor-facing |
| 4e - Q17 | Are the hazards/risks listed complete? (From a review of the listed hazards, do they have all of the details required completed such as name, clinical impact and risk ratings. Do the risk ratings look appropriate or do they appear to be copy and paste throughout the listed hazards? Are they scored on the low side? Does the consequence change pre and post assessment? | Assessor-facing |
| 4e - Q18 | Are the potential harms related to the user/patient? | Assessor-facing |
| 4e - Q19 | Has the Developer covered all of the possible causes for each Hazard? | Assessor-facing |
| 4e - Q20 | Do the risk ratings look appropriate or do they appear to be copy and paste throughout the listed hazards? | Assessor-facing |
| 4e - Q21 | Has the Developer identified appropriate clinical risk control measures to remove any unacceptable clinical risk? | Assessor-facing |
| 4e - Q22 | For each identified hazard, has the Developer evaluated whether the residual clinical risk is acceptable? | Assessor-facing |
| 4e - Q23 | Have the clinical risks from all identified hazards been considered and accepted? | Assessor-facing |
| 4e - Q24 | Have any hazard rating reductions been fully justified? | Assessor-facing |
| 4e - Q25 | Do the Clinical Safety Case and Hazard Log meet with the requirements set out in DCB0129? | Assessor-facing |
→4f. Clinical Safety Officer
| Code | Criteria | Facing |
|---|---|---|
| 4f - Q1 | Do you have a Clinical Safety Officer (CSO)? | Supplier-facing |
| 4f - Q2 | Please confirm the name of your Clinical Safety Officer (CSO), their profession and registration details? | Supplier-facing |
| 4f - Q3 | Document uploadCSO registration (Certificate, screenshot of register etc) | Supplier-facing |
| 4f - Q4 | Does the named CSO have appropriate qualifications and up to date registration details? | Supplier-facing |
| 4f - Q5 | Has the Clinical Safety Officer received appropriate training to be able to act in their role? | Supplier-facing |
| 4f - Q6 | What formal training has the Clinical Safety Officer received in clinical risk management? | Supplier-facing |
| 4f - Q7 | If you have selected other, please explain what training has taken place | Supplier-facing |
| 4f - Q8 | Is the CSO a suitably qualified and experienced clinician? | Assessor-facing |
| 4f - Q9 | Does the CSO hold a current registration with an appropriate professional body relevant to their training and their experience? | Assessor-facing |
| 4f - Q10 | Is there evidence the CSO has played an active part in the clinical safety process – approval of the risk management file, hazard assessment participation etc? | Assessor-facing |
| 4f - Q11 | Does the developer evidence an approval process for their documentation beyond the CSO? | Assessor-facing |
→4g. Outcome
| Code | Criteria | Facing |
|---|---|---|
| 4g - Q1 | Please confirm whether the app has passed or failed the criteria for Clinical Risk Management: | Assessor-facing |
| 4g - Q2 | Please provide a summary of your findings and recommended improvements for Clinical Risk Management: | Assessor-facing |
→5Usability & Accessibility
Considers whether the product has been designed and developed with usability and accessibility in mind, including compliance with recognised design and accessibility standards, user involvement in design and testing, ongoing user support, and adherence to relevant service standards.
→5a. Design and Development
| Code | Criteria | Facing |
|---|---|---|
| 5a - Q1 | Do you develop the product in line with any app usability and/or design standards? | Supplier-facing |
| 5a - Q2 | What design standards is the app compliant with? | Supplier-facing |
| 5a - Q3 | Is the app compliant with any app design standards? | Assessor-facing |
| 5a - Q4 | If yes, please state what app design standards the app is compliant with. | Assessor-facing |
| 5a - Q5 | What is the level of user involvement in the development of the product? | Supplier-facing |
| 5a - Q6 | Has the developer provided evidence of research carried out with relevant user groups? | Assessor-facing |
| 5a - Q7 | Has the developer provided evidence of engagement with users, communities or stakeholders within Wales? | Assessor-facing |
| 5a - Q8 | Has the developer identified the user needs through their research? | Assessor-facing |
| 5a - Q9 | Has the developer provided evidence that user needs have been considered with appropriate stakeholders? | Assessor-facing |
| 5a - Q10 | Has the developer detailed how frequently they consider user needs in their product development? | Assessor-facing |
| 5a - Q11 | Does the evidence provided support the developer's reported level of user involvement in the development of their product? | Assessor-facing |
| 5a - Q12 | Please describe the intended target audience for the app, including any specific user groups the product has been designed for. | Supplier-facing |
| 5a - Q13 | Have you engaged Welsh speakers in the development and/or testing of the product? | Supplier-facing |
| 5a - Q14 | Has the developer clearly stated the app's target audience? | Assessor-facing |
| 5a - Q15 | Is there any evidence of user testing? | Assessor-facing |
| 5a - Q16 | Was there evidence of a cross-section of society included? | Assessor-facing |
| 5a - Q17 | Has the user testing included Welsh speakers? | Assessor-facing |
| 5a - Q18 | Has the user testing included both Welsh and English speakers to ensure an equitable approach to user testing across languages? | Assessor-facing |
| 5a - Q19 | Is the user testing group representative of the target audience by reference to age? | Assessor-facing |
| 5a - Q20 | Is the user testing group representative of the target audience by reference to gender? | Assessor-facing |
| 5a - Q21 | Is the user testing group representative of the target audience by reference to ethnicity? | Assessor-facing |
| 5a - Q22 | Has the user testing included users who have physical disabilities? | Assessor-facing |
| 5a - Q23 | Has the user testing included users who have cognitive disabilities? | Assessor-facing |
| 5a - Q24 | Has the user testing included users who have visual impairments? | Assessor-facing |
| 5a - Q25 | Has the user testing included users who have hearing impairments? | Assessor-facing |
| 5a - Q26 | Has the user testing been carried out with the relevant population the app has been designed for? | Assessor-facing |
| 5a - Q27 | Are all key user journeys mapped to ensure that the whole user problem is solved or it is clear to users how it fits into their pathway or journey? | Assessor-facing |
| 5a - Q28 | Has the developer identified where the user need fits into the wider healthcare journey or clinical pathway, or how it solves a problem for users? | Assessor-facing |
| 5a - Q29 | Has the developer ensured minimisation of user entered data? | Assessor-facing |
| 5a - Q30 | Has the developer detailed all key user journeys mapped, to ensure that the whole user problem is solved or it is clear to users how it fits into their pathway or journey? | Assessor-facing |
| 5a - Q31 | Do you continuously develop your product? | Supplier-facing |
| 5a - Q32 | Has the developer detailed their approach to continuous development, including reviewing user feedback? | Assessor-facing |
| 5a - Q33 | Does the developer have a post-release schedule, or indicate how frequently they look at the need for changes? | Assessor-facing |
| 5a - Q34 | Has the developer indicated their process for reviewing content in line with up to date clinical guidelines? | Assessor-facing |
| 5a - Q35 | Does the developer continuously develop the product? | Assessor-facing |
→5b. Accessibility
| Code | Criteria | Facing |
|---|---|---|
| 5b - Q1 | Has the app been designed to work on Mobile Devices and Tablets? | Assessor-facing |
| 5b - Q2 | Does the app have a web based version for users who are unable to or prefer not to download the app? | Assessor-facing |
| 5b - Q3 | Is the product international Web Content Accessibility Guidelines (WCAG) compliant, at a minimum of AA conformance? | Supplier-facing |
| 5b - Q4 | Please specify whether the product is fully or partially compliant with WCAG and the version and conformance level with which you are compliant. | Supplier-facing |
| 5b - Q5 | Is the product international Web Content Accessibility Guidelines (WCAG) compliant, at a minimum of AA conformance? | Assessor-facing |
| 5b - Q6 | Has the developer provided a published accessibility statement? | Assessor-facing |
| 5b - Q7 | Does the accessibility statement detail whether the product is 'fully,' 'partially' or 'not' compliant with accessibility standards? | Assessor-facing |
| 5b - Q8 | Is the accessibility statement 'fully,' 'partially' or 'not' compliant with accessibility standards? | Assessor-facing |
| 5b - Q9 | If not fully compliant, does the accessibility statement detail which parts of the product do not meet accessibility standards and why? | Assessor-facing |
| 5b - Q10 | Does the accessibility statement detail how users can get alternatives to content which is not accessible to them? | Assessor-facing |
| 5b - Q11 | Does the accessibility statement provide contact details for the user, to report accessibility problems, and a website link if they are not happy with the response? | Assessor-facing |
| 5b - Q12 | Is the accessibility statement suitable? | Assessor-facing |
| 5b - Q13 | Please confirm that you have read the Accessible Communication and Information Standards in Healthcare and considered how it's requirements should be reflected in the design of your product. | Supplier-facing |
| 5b - Q14 | Describe how you have considered the Accessible Information Standard and its requirements in the design of your product and service. | Supplier-facing |
| 5b - Q15 | Has the developer confirmed they have read and considered the Accessible Communication and Information Standards in Healthcare? | Assessor-facing |
| 5b - Q16 | What measures have you taken to promote digital inclusion within your product? | Supplier-facing |
| 5b - Q17 | Can the user change the font size within the App or does the app respond to font preferences in the device? | Assessor-facing |
| 5b - Q18 | Does the app provide support options for users with poor sight? | Assessor-facing |
| 5b - Q19 | Does the app provide support options for users with hearing difficulty? | Assessor-facing |
| 5b - Q20 | Has consideration been given to users with restricted data usage allowances? | Assessor-facing |
| 5b - Q21 | Are there any components of the app which can be used to operate without Wi-Fi? | Assessor-facing |
| 5b - Q22 | Is the app suitable for low-bandwidth connections? | Assessor-facing |
→5c. Usability
| Code | Criteria | Facing |
|---|---|---|
| 5c - Q1 | Does the user have options to manage the notification settings for push/email notifications within the app for convenience/privacy? | Assessor-facing |
| 5c - Q2 | Does the app inform the user how to manage notification settings for convenience / privacy (eg to prevent divulging personal information if the device is locked but on show?) | Assessor-facing |
| 5c - Q3 | Can the user change the presentation theme? | Assessor-facing |
| 5c - Q4 | Are any clinical or technical terms used explained clearly to the user? (either within the content of the app or via a glossary) | Assessor-facing |
| 5c - Q5 | During review, was there any evidence of bugs? | Assessor-facing |
| 5c - Q6 | Does the app include the following functions: | Assessor-facing |
| 5c - Q7 | Can the user download individual pages or content within the app? | Assessor-facing |
| 5c - Q8 | Does the search function support spelling correction, phonetic matching, fuzzy search or similar to assist users in locating content? | Assessor-facing |
| 5c - Q9 | Do you undertake user acceptance testing to validate usability of the system? | Assessor-facing |
| 5c - Q10 | Has the developer attached supporting information to show user acceptance testing? | Assessor-facing |
| 5c - Q11 | Has the developer evidenced frequent testing with actual or potential users, using appropriate research techniques? | Assessor-facing |
| 5c - Q12 | Has the developer provided evidence of testing of all parts of the service which the user interacts with, both online and offline? | Assessor-facing |
| 5c - Q13 | Has the developer undertaken user acceptance testing to validate usability of the system? | Assessor-facing |
→5d. Support
| Code | Criteria | Facing |
|---|---|---|
| 5d - Q1 | If there is a forum, is there a statement within the app that the forum content is moderated? | Assessor-facing |
| 5d - Q2 | Is there any statement or evidence of how to report issues to the developers? (e.g. this may be a help button with contact form, instructions or email details) | Assessor-facing |
| 5d - Q3 | Is there any statement within the app about the developer's commitment to addressing problems reported to them? (e.g. timescales to respond, commitment to eradicate reported bugs and faults) | Assessor-facing |
| 5d - Q4 | What kind of support is offered? | Assessor-facing |
→5e. Service Standards/Provisions
| Code | Criteria | Facing |
|---|---|---|
| 5e - Q1 | Do you have a benefits case that includes your objectives and the benefits you will be measuring and have metrics that you are tracking? | Supplier-facing |
| 5e - Q2 | Has the developer outlined their benefits case, including objectives and metrics which can be measured? | Assessor-facing |
| 5e - Q3 | Has the developer considered a range of benefits such as cost, usability and clinical benefits? | Assessor-facing |
| 5e - Q4 | Has the developer indicated how they consider any negative impact, and how to fix problems? | Assessor-facing |
| 5e - Q5 | Does the developer demonstrate transparency with their performance information, by making this publicly available? | Assessor-facing |
| 5e - Q6 | Has the developer provided a benefits case, including their objectives and the benefits they will be measuring, and have metrics that they are tracking? | Assessor-facing |
| 5e - Q7 | Has the app been designed in line with the DHCW design system? | Supplier-facing |
| 5e - Q8 | Please evidence how you have designed your product in line with the DHCW design system. | Supplier-facing |
| 5e - Q9 | Has the supplier evidenced how they developed the product in line with the DHCW design system? | Assessor-facing |
| 5e - Q10 | Do you provide a Service Level Agreement to all customers purchasing the product? | Supplier-facing |
| 5e - Q11 | If you do not provide a Service Level Agreement to all customers, do you provide any other form of assurance to them relating to performance and uptime? | Supplier-facing |
| 5e - Q12 | Please detail how. | Supplier-facing |
| 5e - Q13 | Do you report to customers on your performance with respect to support, system performance (response times) and availability (uptime) at a frequency required by your customers? | Supplier-facing |
| 5e - Q14 | Please provide your average service availability for the past 12 months, as a percentage to two decimal places | Supplier-facing |
| 5e - Q15 | Do you perform testing to ensure those assurances can be upheld? | Supplier-facing |
| 5e - Q16 | Please detail how. | Supplier-facing |
| 5e - Q17 | Does the developer report to customers on performance with respect to support? | Assessor-facing |
| 5e - Q18 | Does the developer report to customers on performance with respect to system performance (response time)? | Assessor-facing |
| 5e - Q19 | Does the developer report to customers on performance with respect to availability (uptime)? | Assessor-facing |
| 5e - Q20 | Is the provided uptime 99% or above? | Assessor-facing |
| 5e - Q21 | Does the developer test the service regularly, in an environment that's as similar as live to possible? | Assessor-facing |
| 5e - Q22 | Does the developer provide a Service Level Agreement to all customers purchased the product? | Assessor-facing |
| 5e - Q23 | Has the developer attached a copy of the information provided to customers? | Assessor-facing |
| 5e - Q24 | Does the developer report to customers on their performance with respect to support, system performance (response times) and availability (uptime) at a frequency required by their customers? | Assessor-facing |
| 5e - Q25 | Has the developer provided an uptime of 99.9% or above? | Assessor-facing |
→6Technical Security & Stability
Considers the technical security and stability controls in place to protect the product and its users, including authentication, security testing and assurance, secure development, monitoring, patch management, decommissioning, technical stability, and supply chain management, assessed proportionately according to the product's software risk level and applicable Welsh Health Circular risk category.
→6a. TS&S Scene Setters
| Code | Criteria | Facing |
|---|---|---|
| 6a - Q1 | Does the app connect to an internet-based API (e.g. App Developer Web Service, Social Media, Advertisements)? | Assessor-facing |
| 6a - Q2 | List the APIs the app connects to. | Assessor-facing |
| 6a - Q3 | Does the App access, process or store Personal and/or Sensitive Data? | Assessor-facing |
| 6a - Q4 | Is sensitive data persisted to the mobile device? | Assessor-facing |
| 6a - Q5 | Is the application a native application for a mobile device? | Assessor-facing |
| 6a - Q6 | Is the application a web application? | Assessor-facing |
| 6a - Q7 | What OWASP level is the app? | Assessor-facing |
| 6a - Q8 | Can users sign into the product? | Assessor-facing |
→6b. Proportionality
| Code | Criteria | Facing |
|---|---|---|
| 6b - Q1 | Does the product, or any party within its supply chain, already or intend to store, process, or have access to patient, staff, or other sensitive personal information or other sensitive/confidential NHS Wales corporate information? | Supplier-facing |
| 6b - Q2 | Do you (or any party in the supply chain) already or intend to store or process this information on your own system? | Supplier-facing |
| 6b - Q3 | What volume of information does the product already or intend to handle? Select the closest description. | Supplier-facing |
| 6b - Q4 | Is or does the product intend to be essential to supporting a clinical capability? | Supplier-facing |
| 6b - Q5 | Does the product, or any party within its supply chain, already or intend to require any form of networked or electronic connection to devices on the NHS Wales network (including connecting into networks or devices while supplier staff are physically on an NHS site)? | Supplier-facing |
| 6b - Q6 | On what sort of basis is access needed? Select the closest description. | Supplier-facing |
| 6b - Q7 | How is this access achieved? | Supplier-facing |
| 6b - Q8 | What Welsh Health Circular 2017 risk category does the product fall into? | Assessor-facing |
| 6b - Q9 | What Security Requirement Level is the DHT? | Assessor-facing |
→6c. Deferred Assurances
| Code | Criteria | Facing |
|---|---|---|
| 6c - Q1 | Do you have a valid Cyber Essentials or Cyber Essentials Plus certificate? | Supplier-facing |
| 6c - Q2 | Document uploadPlease upload your Cyber Essentials certificate. This should be dated within the past 12 months. | Supplier-facing |
| 6c - Q3 | Does the organisation have a Cyber Essentials accreditation? | Assessor-facing |
| 6c - Q4 | Does the organisation have a Cyber Essentials Plus accreditation? | Assessor-facing |
| 6c - Q5 | Is the certificate within the last 12 months? | Assessor-facing |
| 6c - Q6 | When is the certificate dated? | Assessor-facing |
| 6c - Q7 | Validation against the IASME Database | Assessor-facing |
| 6c - Q8 | Do you have a valid ISO 27001:2022 certificate? | Supplier-facing |
| 6c - Q9 | Document uploadPlease upload your ISO 27001:2022 certificate. | Supplier-facing |
| 6c - Q10 | Document uploadPlease upload your ISO 27001:2022 Statement of Applicability. | Supplier-facing |
| 6c - Q11 | Document uploadPlease upload an ISO 27001 implementation roadmap. | Supplier-facing |
| 6c - Q12 | Does the organisation have ISO27001:2022 accreditation? | Assessor-facing |
| 6c - Q13 | Is the certification body in the UKAS list of ISO27001:2022 certification bodies? | Assessor-facing |
| 6c - Q14 | If the certification body isn't in the UKAS list of ISO27001:2022 certification bodies, does it hold any other relevant accreditations? | Assessor-facing |
| 6c - Q15 | Has the supplier provided their Statement of Applicability? | Assessor-facing |
| 6c - Q16 | Does the Statement of Applicability cover the entire product's development and associated services? | Assessor-facing |
| 6c - Q17 | Has the supplier appropriately defined the scope of their ISO 27001 certification? | Assessor-facing |
| 6c - Q18 | Has the certification been completed within the last 3-year period? | Assessor-facing |
| 6c - Q19 | Does the supplier's ISO 27001:2022 submission meet all requirements? | Assessor-facing |
| 6c - Q20 | Does the product already or intend to connect with any NHS Wales Cloud Infrastructure? | Supplier-facing |
| 6c - Q21 | Document uploadPlease upload your ISO/IEC 27017:2015 certificate. | Supplier-facing |
| 6c - Q22 | Does the organisation have ISO/IEC 27017:2015 accreditation? | Assessor-facing |
| 6c - Q23 | Please confirm that software has been produced in adherence to the Department for Science, Innovation and Technology (DSIT) / National Cyber Security Centre (NCSC) Software Security Code of Practice and commits to meeting the principles of secure design and development, secure build environment, secure deployment and maintenance and communication with customers? | Supplier-facing |
| 6c - Q24 | Document uploadDepartment for Science, Innovation and Technology (DSIT) / National Cyber Security Centre (NCSC) Software Security Code of Practice self-assessment form that demonstrates that your development, deployment and maintenance process aligns with the Code of Practice's secure design focused principles. | Supplier-facing |
| 6c - Q25 | Has the developer provided their DSIT/NCSC self-assessment form to demonstrate self-stated compliance? | Assessor-facing |
| 6c - Q26 | Have you undergone any NCSC assurance schemes? | Supplier-facing |
| 6c - Q27 | Which NCSC assurance schemes? | Supplier-facing |
| 6c - Q28 | Has the developer undergone any NCSC assurance schemes? | Assessor-facing |
→6d. Authentication
| Code | Criteria | Facing |
|---|---|---|
| 6d - Q1 | Do you enforce multi-factor authentication for all privileged account types at an organisational level? | Supplier-facing |
| 6d - Q2 | If not applicable, explain why you do not enforce multi-factor authentication for all privileged account types at an organisational level. | Supplier-facing |
| 6d - Q3 | Do you enforce multi-factor authentication for all standard user accounts on your product? | Supplier-facing |
| 6d - Q4 | If not applicable, explain why you do not enforce multi-factor authentication for all standard user accounts on the product. | Supplier-facing |
| 6d - Q5 | Document uploadPlease upload your access policies that cover both privileged and standard user multi-factor authentication AND screenshots of the dashboard(s) used to accomplish this to demonstrate that MFA is enabled by default. | Supplier-facing |
| 6d - Q6 | Has the developer provided appropriate evidence of enforcing Multi Factor Authentication for all privileged accounts? | Assessor-facing |
| 6d - Q7 | Has the developer provided appropriate evidence of enforcing Multi Factor Authentication for all standard user accounts? | Assessor-facing |
→6e. Testing
| Code | Criteria | Facing |
|---|---|---|
| 6e - Q1 | Do you follow any formal testing standards? | Supplier-facing |
| 6e - Q2 | Document uploadPlease provide copies of your testing procedures. | Supplier-facing |
| 6e - Q3 | Does the organization follow any formal testing standards? | Assessor-facing |
| 6e - Q4 | Provide details of any associated processes / procedures and tools that are used. | Assessor-facing |
| 6e - Q5 | Which of these types of testing do you carry out? | Supplier-facing |
| 6e - Q6 | For each of the testing types selected, please describe the people / roles that are involved and the processes you work to even if they are informal. | Supplier-facing |
| 6e - Q7 | For unit testing please describe the people / roles that are involved, the processes that they work to even if they are informal. | Assessor-facing |
| 6e - Q8 | For Regression testing please describe the people / roles that are involved, the processes that they work to even if they are informal. | Assessor-facing |
| 6e - Q9 | For End-to-end / Integration please describe the people / roles that are involved, the processes that they work to even if they are informal. | Assessor-facing |
| 6e - Q10 | For User Acceptance please describe the people / roles that are involved, the processes that they work to even if they are informal. | Assessor-facing |
| 6e - Q11 | For A/B please describe the people / roles that are involved, the processes that they work to even if they are informal. | Assessor-facing |
| 6e - Q12 | Please provide the summary report of an external penetration test of the product that included Open Web Application Security Project (OWASP) Top 10 vulnerabilities from within the previous 12-month period. | Supplier-facing |
| 6e - Q13 | Provide the date of the summary report of the external penetration test. This should be dated within the last 12 months and completed annually. Please provide this in the format date/month/year. | Supplier-facing |
| 6e - Q14 | Document uploadExternal penetration test report for the product that includes Open Web Application Security Project (OWASP) Top 10 vulnerabilities from within the previous 12-month period. | Supplier-facing |
| 6e - Q15 | Is the external body CREST or CHECK certified? | Assessor-facing |
| 6e - Q16 | Does the scope of the report cover the full Technical Architecture of Application? | Assessor-facing |
| 6e - Q17 | Has an industry-standard been used for the risk model in the associated PEN /Vulnerability testing? | Assessor-facing |
| 6e - Q18 | Is the method of the PEN testing appropriate? | Assessor-facing |
| 6e - Q19 | Does the penetration testing / summary report demonstrate there are no vulnerabilities that score seven or above using the Common Vulnerability Scoring System (CVSS)? | Assessor-facing |
| 6e - Q20 | Has any retesting been undertaken with 12 weeks of the original PEN test? | Assessor-facing |
| 6e - Q21 | Has the PEN testing been undertaken within the last 12 months? | Assessor-facing |
| 6e - Q22 | Does the external penetration test summary report meet all requirements? | Assessor-facing |
| 6e - Q23 | For Testing across devices please describe the people / roles that are involved, the processes that they work to even if they are informal. | Assessor-facing |
| 6e - Q24 | For Load / Performance please describe the people / roles that are involved, the processes that they work to even if they are informal. | Assessor-facing |
| 6e - Q25 | For Other non-functional tests please describe the people / roles that are involved, the processes that they work to even if they are informal. | Assessor-facing |
| 6e - Q26 | For Other testing please describe the people / roles that are involved, the processes that they work to even if they are informal. | Assessor-facing |
| 6e - Q27 | Do you perform security-focused code reviews on all code prior to deployment? | Supplier-facing |
| 6e - Q28 | Document uploadPlease provide a copy of your code review procedure. | Supplier-facing |
| 6e - Q29 | Please confirm whether all custom code had a security review. | Assessor-facing |
| 6e - Q30 | Do you perform automated vulnerability detection testing as part of the development lifecycle? | Supplier-facing |
| 6e - Q31 | Document uploadPlease provide an example output report from one of your automated vulnerability scans. | Supplier-facing |
| 6e - Q32 | Has the developer provided appropriate evidence of their vulnerability detection testing? | Assessor-facing |
| 6e - Q33 | Does the supplier run this detection on a continuous basis? | Assessor-facing |
→6f. Development
| Code | Criteria | Facing |
|---|---|---|
| 6f - Q1 | Does your organisation maintain a secure development policy? | Supplier-facing |
| 6f - Q2 | Document uploadPlease provide your secure development policy. | Supplier-facing |
| 6f - Q3 | Is a secure by design process followed? | Assessor-facing |
| 6f - Q4 | Are security vulnerabilities reported, identified, assessed, logged, responded to, disclosed, and quickly and effectively resolved? | Assessor-facing |
| 6f - Q5 | Is a validation and verification plan used for the health app? | Assessor-facing |
→6g. Monitoring
| Code | Criteria | Facing |
|---|---|---|
| 6g - Q1 | Do you enforce audit logging and monitoring across all critical infrastructure used to support the product? | Supplier-facing |
| 6g - Q2 | Document uploadPlease upload a copy of the policy that governs your audit logging and reporting procedures AND a screenshot of the tool(s) you employ. | Supplier-facing |
| 6g - Q3 | Do you proactively monitor running of systems and system components to automatically identify faults and technical issues? | Supplier-facing |
| 6g - Q4 | Provide details of any associated processes / procedures and tools that are used. | Supplier-facing |
| 6g - Q5 | Does the supplier proactively monitor their systems to detect suspicious user behaviour? | Assessor-facing |
| 6g - Q6 | Does the developer confirm how long user activity logs are stored for? | Assessor-facing |
| 6g - Q7 | How long are user activity logs retained for? | Assessor-facing |
| 6g - Q8 | Does the policy define processes to ensure that all security alerts from logging and monitoring solutions are reviewed and actioned as necessary? | Assessor-facing |
| 6g - Q9 | Does the policy outline that the logs are stored on a hardened server that is logically separate from the systems being logged? | Assessor-facing |
| 6g - Q10 | Do you follow a formal incident response policy with a focus on security related incidents? | Supplier-facing |
| 6g - Q11 | Document uploadPlease upload a copy of the policy that governs incident response. | Supplier-facing |
| 6g - Q12 | Has the supplier evidenced an incident response policy? | Assessor-facing |
| 6g - Q13 | Does the policy contain a classification strategy for information security events? | Assessor-facing |
| 6g - Q14 | Does the policy include consideration for legal and regulatory commitments? | Assessor-facing |
| 6g - Q15 | Does the policy include consideration for alternative communication systems in case usual systems are disrupted? | Assessor-facing |
| 6g - Q16 | Does the policy outline a disclosure process for employees, contractors and suppliers? | Assessor-facing |
→6h. Patch Management
| Code | Criteria | Facing |
|---|---|---|
| 6h - Q1 | Do you follow a formal patch management policy? | Supplier-facing |
| 6h - Q2 | Document uploadPlease upload a copy of the policy that governs patch management. | Supplier-facing |
| 6h - Q3 | Does the supplier have a security patch management policy? | Assessor-facing |
| 6h - Q4 | Does the supplier report on their SLAs for remediating security vulnerabilities? | Assessor-facing |
| 6h - Q5 | Is the SLA for high/critical vulnerabilities within 14 working days? | Assessor-facing |
→6i. Decommissioning
| Code | Criteria | Facing |
|---|---|---|
| 6i - Q1 | Do you have a plan for the eventuality that the product is decommissioned? | Supplier-facing |
| 6i - Q2 | Document uploadPlease upload a copy of the policy that governs decommissioning plan. | Supplier-facing |
| 6i - Q3 | Has the developer provided appropriate evidence of a plan to decommission their product? | Assessor-facing |
| 6i - Q4 | Has the developer provided appropriate evidence of a plan to deal with personal data once the product is decommissioned? | Assessor-facing |
→6j. Technical Stability
| Code | Criteria | Facing |
|---|---|---|
| 6j - Q1 | Do you have a policy that governs your version controlling, covering the source code and all configuration items for the product? | Supplier-facing |
| 6j - Q2 | Document uploadPlease upload a copy of the policy that governs version controlling. | Supplier-facing |
| 6j - Q3 | Are the source code and any configuration items for the product version controlled with all changes audited? | Assessor-facing |
| 6j - Q4 | Do you have a policy that governs your backup procedures, including regular backups of personal/sensitive data, regular testing and immutability? | Supplier-facing |
| 6j - Q5 | Document uploadPlease upload a copy of the policy that governs backups. | Supplier-facing |
| 6j - Q6 | Does the supplier maintain regular backups of all personal/sensitive data? | Assessor-facing |
| 6j - Q7 | Does the supplier maintain regular backups of all systems used to deliver the product? | Assessor-facing |
| 6j - Q8 | Are backups tested for data verification at least quarterly? | Assessor-facing |
| 6j - Q9 | Are backups tested for for full restore capabilities at least yearly? | Assessor-facing |
| 6j - Q10 | Does the supplier implement immutable backups? | Assessor-facing |
| 6j - Q11 | What technology or storage mechanism does the supplier use to enforce immutability? | Assessor-facing |
| 6j - Q12 | Are backups tested regularly to confirm they are complete, uncorrupted, and restorable? | Assessor-facing |
| 6j - Q13 | Where are the backups stored? | Assessor-facing |
| 6j - Q14 | Has the supplier confirmed that backups are stored in the UK? | Assessor-facing |
| 6j - Q15 | Do you have the capacity to rollback to previous versions of your product? | Assessor-facing |
| 6j - Q16 | Do you have a policy that governs your Recovery Time Objective and routine testing? | Supplier-facing |
| 6j - Q17 | Document uploadPlease upload a copy of the policy that governs your Recovery Time Objective. | Supplier-facing |
| 6j - Q18 | Has the supplier defined a Recovery Time Objective? | Assessor-facing |
| 6j - Q19 | Has the RTO been formally agreed and documented? | Assessor-facing |
| 6j - Q20 | Has the RTO been validated through a formal recovery test within the last 12-month period? | Assessor-facing |
| 6j - Q21 | Do you have a policy that governs how you accept and respond to technical faults from end users? | Supplier-facing |
| 6j - Q22 | Document uploadPlease upload a copy of the policy that governs how you accept and respond to technical faults from end users. | Supplier-facing |
| 6j - Q23 | Are the processes for accepting and responding to technical faults from end users appropriate? | Assessor-facing |
| 6j - Q24 | Do you have a documented technical roadmap? | Supplier-facing |
| 6j - Q25 | Document uploadPlease upload a copy of your roadmap. | Supplier-facing |
| 6j - Q26 | Has the developer provided appropriate evidence of the roadmap for the development of their product? | Assessor-facing |
| 6j - Q27 | Do you have a plan to ensure the continued availability of your product? | Supplier-facing |
| 6j - Q28 | Document uploadPlease upload your plan to ensure the continued availability of your product. | Supplier-facing |
| 6j - Q29 | Does the Developer provide details of how they will ensure the continued availability of their product? | Assessor-facing |
| 6j - Q30 | Do you have a policy that governs your disaster recovery processes and routine testing? | Supplier-facing |
| 6j - Q31 | Document uploadPlease upload a copy of the policy that governs disaster recovery. | Supplier-facing |
| 6j - Q32 | Does the App Developer have robust Disaster Recovery (DR)/ back-up regimes in place? | Assessor-facing |
| 6j - Q33 | Has the Disaster Recovery Plan been tested within the last 12-month period? | Assessor-facing |
| 6j - Q34 | Do you have a policy that governs your business continuity plan and routine testing? | Supplier-facing |
| 6j - Q35 | Document uploadPlease upload a copy of the policy that governs business continuity. | Supplier-facing |
| 6j - Q36 | Does the app developer have a Business Continuity Plan (BCP) in place? | Assessor-facing |
| 6j - Q37 | Has the Business Continuity Plan been tested within the last 12-month period? | Assessor-facing |
→6k. Supply Chain Management
| Code | Criteria | Facing |
|---|---|---|
| 6k - Q1 | Do you maintain a Software Bill of Materials that covers all third party components in the supply chain for this product and describes what contracts/certifications/standards are enforced to ensure continuity and security of the service delivery? | Supplier-facing |
| 6k - Q2 | Document uploadPlease upload a copy of your Software Bill of Materials. | Supplier-facing |
| 6k - Q3 | Does the supplier maintain a Software Bill of Materials (SBOM)? | Assessor-facing |
| 6k - Q4 | Has the supplier identified all key third-party components that are used to deliver the service? | Assessor-facing |
| 6k - Q5 | Does the supplier require by contract that all third-party providers meet specific standards and/or certifications? | Assessor-facing |
| 6k - Q6 | For third party providers where bespoke contractual terms cannot be negotiated (e.g. large cloud providers), has the supplier confirmed that they have reviewed the provider's published shared responsibility model and confirmed it covers the security controls they are relying on? | Assessor-facing |
| 6k - Q7 | If no to WALES_SBOM03 and/or SBOM04, how does the supplier ensure the security of their supply chain? | Assessor-facing |
| 6k - Q8 | Are the supplier's alternative mitigations sufficiently described and appropriate? | Assessor-facing |
| 6k - Q9 | Does the organisation conduct regular assurance activities against suppliers to ensure they are meeting their information security requirements? | Assessor-facing |
| 6k - Q10 | Does the supplier use a standardised classification risk model for third-party providers? | Assessor-facing |
→6l. Summary
| Code | Criteria | Facing |
|---|---|---|
| 6l - Q1 | Please confirm whether the product has passed the required criteria for the Technical Security & Stability section of the assessment? | Assessor-facing |
→7Welsh Language
Considers whether the product meets the Welsh language requirements applicable to products used or procured within NHS Wales, including whether the product and its supporting materials and functionality are available in Welsh.
| Code | Criteria | Facing |
|---|---|---|
| 7 - Q1 | Who are the intended users of the DHT? | Supplier-facing |
| 7 - Q2 | Has the product been procured by NHS Wales? | Supplier-facing |
| 7 - Q3 | Is the product fully available in Welsh? | Supplier-facing |
| 7 - Q4 | Has the product's Welsh translation been approved by NHS Wales Shared Services Partnership? | Supplier-facing |
| 7 - Q5 | Please provide further details. | Supplier-facing |
| 7 - Q6 | Is the product currently being piloted by NHS Wales? | Supplier-facing |
| 7 - Q7 | Please provide further details. | Supplier-facing |
| 7 - Q8 | Has the product been granted an exemption by the Welsh Government from providing a Welsh translation? | Supplier-facing |
| 7 - Q9 | Please provide further details. | Supplier-facing |
| 7 - Q10 | Does the product have the technical capacity to host translation options? | Supplier-facing |
| 7 - Q11 | Describe the technical architecture of the product. | Supplier-facing |
| 7 - Q12 | Can the supplier / product support a sandbox environment to enable NWSSP to provide translation services? | Supplier-facing |
| 7 - Q13 | What is the level of assurance the product has attained? | Assessor-facing |
| 7 - Q14 | Should this product be referred to NWSSP? | Assessor-facing |
→8Interoperability
Considers the product's ability to integrate and exchange data with other digital health technologies, electronic health and care record systems, and external/wearable devices, via APIs and other integration channels.
→8a. APIs
| Code | Criteria | Facing |
|---|---|---|
| 8a - Q1 | Does your product expose any Application Programme Interfaces (API) or integration channels for other consumers? | Supplier-facing |
| 8a - Q2 | Does the product have the capability to read data from EHRs? | Assessor-facing |
| 8a - Q3 | Does the product have the capability to write data into EHRs? | Assessor-facing |
| 8a - Q4 | Have you integrated with any EHRs in the past? | Supplier-facing |
| 8a - Q5 | Which other EHRs (e.g., Epic, Cerner/Oracle Health, athenahealth, NextGen)? | Supplier-facing |
| 8a - Q6 | Do you intend to integrate with any NHS Wales systems with the assessed product? | Supplier-facing |
| 8a - Q7 | For what purpose do you intend to integrate with NHS Wales systems? | Supplier-facing |
| 8a - Q8 | If you have integrated this product with EHRs in the past, but do not intend to integrate with any NHS Wales systems, please justify why. | Supplier-facing |
| 8a - Q9 | Which national and international interoperability standards does the product support or conform to (e.g., HL7 FHIR, GP Connect, SNOMED, dm+d, etc.)? | Supplier-facing |
| 8a - Q10 | What is your process and typical timeline for onboarding a new integration? | Supplier-facing |
| 8a - Q11 | Do you provide a test/sandbox environment for integration testing prior to go-live? | Supplier-facing |
| 8a - Q12 | Do you adhere with any standards for the purpose of collaborative scaling (including standards relating to data governance and interoperability)? | Supplier-facing |
| 8a - Q13 | Which standards do you adhere to? | Supplier-facing |
→8b. Wearable Integration
| Code | Criteria | Facing |
|---|---|---|
| 8b - Q1 | Is your product a wearable or device, or does it integrate with them? | Supplier-facing |
| 8b - Q2 | If yes, does your product comply with ISO/IEE11073 Personal Health Data (PHD) Standards? | Supplier-facing |
| 8b - Q3 | If yes, has the developer evidenced how their product complies with ISO/IEE 11073 Personal Health Data (PHD) Standards? | Assessor-facing |