What Compliance Certifications Should a Healthcare AI Vendor Have in the UK?

Key Takeaways
The honest answer: it depends on where the vendor's software runs. A vendor that hosts your patient data needs its own NHS Data Security and Protection Toolkit (DSPT) submission, Digital Technology Assessment Criteria (DTAC) evidence, clinical safety documentation under DCB0129, and security certifications. A vendor that deploys inside your environment needs to evidence its engineering, because the data never leaves your governance boundary. Asking for one fixed certification list, without asking where the data goes, is how procurement checklists mislead.
Is there a single NHS approval a healthcare AI vendor can hold?
No. There is no NHS-wide approval, licence, or badge that clears a supplier for use across the NHS. NHS organisations approve digital products through their own local governance: the DSPT, a local DTAC assessment, and information governance review. National mechanisms exist for specific categories, such as NHS England's Ambient Voice Technology (AVT) Supplier Registry for AI scribing products (launched January 2026, self-certified), but these accelerate local assurance rather than replace it.
For a buyer, this means "are you NHS-approved?" is the wrong question. The right questions are which frameworks apply to this product, in this deployment model, and what evidence the vendor supplies for each.
Which frameworks make up the UK compliance checklist?
Eight frameworks cover the ground for healthcare AI in the UK. Acronyms first, then what each one is.
- UK GDPR and the Data Protection Act 2018. The legal foundation. UK General Data Protection Regulation obligations apply to any processing of patient data; the roles that matter in a contract are data controller (your organisation) and data processor (typically the vendor). Regulated by the Information Commissioner's Office (ICO).
- NHS DSPT. The NHS Data Security and Protection Toolkit is the annual self-assessment NHS England requires of organisations that access NHS patient data, measured against the National Data Guardian's data security standards and UK GDPR obligations. Whether the vendor needs its own submission depends on whether patient data flows to the vendor.
- DTAC. The Digital Technology Assessment Criteria, published by NHS England, is the baseline assessment NHS organisations run on a digital health product across five areas: clinical safety, data protection, technical security, interoperability, and usability and accessibility. NHS England refreshed the DTAC form in 2026, cutting questions by roughly a quarter and de-duplicating against the DSPT, with full transition to the new form by 6 April 2026. DTAC is completed by the deploying organisation; the vendor supplies the evidence.
- DCB0129 and DCB0160. The paired clinical risk management standards for health IT in England, mandated under section 250 of the Health and Social Care Act 2012. DCB0129 is held by the manufacturer of a health IT system; DCB0160 is completed by the deploying organisation, with its own safety case and hazard log. One vendor-side, one buyer-side; an AI product with clinical impact should not arrive without the vendor's DCB0129 position stated.
- Cyber Essentials and Cyber Essentials Plus. The National Cyber Security Centre (NCSC) certification scheme covering baseline technical controls. Commonly required in NHS procurement, and the controls behind it are a reasonable engineering floor for any supplier.
- ISO/IEC 27001. The international information security management standard. Evidence of a certified or audit-tested security management system, rather than a healthcare-specific signal.
- SOC 2 (Type I and Type II). A US-origin attestation of security controls, increasingly asked for in UK procurement where the vendor or its cloud stack is international.
- MHRA device registration. If the AI product performs a medical purpose, Medicines and Healthcare products Regulatory Agency registration applies at the appropriate device class. NHS England's AVT registry, for example, requires at least Class 1 registration from scribing suppliers. Data infrastructure and analytics platforms typically sit outside device scope; a vendor should be able to state its position and reasoning.
How does the deployment model change the list?
The single largest variable in that checklist is not the product's feature set. It is where patient data lives.

Neither column is wrong. Vendor-hosted is a fit for commodity tools where the data flow is narrow and the supplier's certification stack is mature. The private deployment column exists because for a growing class of AI systems, the ones that touch the full patient record rather than one conversation, keeping data inside the organisation's existing governance is the shorter and safer compliance path. We wrote about when that class applies in our explainer on private AI in healthcare.
What should you actually ask a vendor for in procurement?
Six requests separate a prepared vendor from an unprepared one, whatever the deployment model:
- A data flow diagram. One page: where patient data originates, every system it touches, where it rests, what leaves the organisation. If this takes weeks to produce, that is itself the answer.
- Controller/processor terms and a Data Processing Agreement (DPA) aligned to UK GDPR and the Data Protection Act 2018, naming sub-processors if any.
- The DTAC evidence pack mapped to the five areas, current against the 2026 form.
- The clinical safety position: the vendor's DCB0129 documentation where the product has clinical impact, or a reasoned statement of why the standard does not apply, plus the inputs your DCB0160 assessment will need.
- Security certifications or audit evidence: Cyber Essentials Plus, ISO/IEC 27001, SOC 2 reports, or engineering documentation of the same controls where the deployment model keeps data out of the vendor's hands.
- A model training statement in writing: whether your data is used to train shared or third-party models. The acceptable answer for patient data is no.
How does GreenM fit this picture?
GreenM sits in the second column of the table. The platforms we build and run for UK healthcare organisations deploy inside the organisation's own cloud or on premises, so patient data never leaves the client's boundary and the work sits within the client's existing DSPT scope and information governance. GreenM acts as data processor under UK GDPR and the Data Protection Act 2018, with the client as controller, and supplies the documentation local governance needs: DTAC platform evidence across the five areas, data protection and residency detail, interoperability design over Health Level Seven (HL7) Fast Healthcare Interoperability Resources (FHIR) R4 where clinical systems are integrated, and the technical inputs for the client's clinical safety process. This deployment model is what our Private AI Foundation service delivers.
GreenM does not hold a separate DSPT submission, because it does not host patient data; it engineers to the controls behind Cyber Essentials and ISO/IEC 27001 and has supported client organisations through ISO/IEC 27001 and SOC 2 (Type I and Type II) audits. The full detail, including the FAQ our UK clients ask first, is on our UK healthcare compliance page.
Frequently asked questions
Does a healthcare AI vendor need its own NHS DSPT?
Only if patient data flows to the vendor. A vendor hosting your data needs a current DSPT submission with Standards Met. A vendor deploying inside your environment does not need its own, because the data stays within your DSPT-assessed boundary; it should instead supply platform documentation for your toolkit submission.
Is DTAC a certification the vendor holds?
No. DTAC is an assessment the deploying NHS organisation completes, using evidence the vendor supplies across five areas: clinical safety, data protection, technical security, interoperability, and usability and accessibility. A vendor claiming to "hold DTAC" is describing having an evidence pack ready, which is still worth asking for.
What is the difference between DCB0129 and DCB0160?
Both are clinical risk management standards for health IT in England. DCB0129 is the manufacturer's standard: the vendor documents the clinical risks of building the product. DCB0160 is the deploying organisation's standard: your team documents the risks of using it in your setting, with a safety case and hazard log. They are complementary, not alternatives.
Are ISO 27001 or SOC 2 legally required in the UK?
No. They are voluntary certifications and attestations, commonly requested in procurement as evidence of security management. The legal requirements come from UK GDPR and the Data Protection Act 2018; NHS-specific requirements such as the DSPT flow from NHS England policy rather than certification schemes.
Where should patient data be stored for a UK deployment?
In a UK region or on premises, with no cross-region replication and no outbound egress beyond the organisation's environment: in practice Azure UK South or AWS London (eu-west-2) for cloud deployments. UK GDPR permits international transfers under safeguards, but for NHS-adjacent work, UK residency is the default buyers expect and the simplest position to evidence.
Sources and further reading
- NHS England, Data Security and Protection Toolkit: https://www.dsptoolkit.nhs.uk/
- NHS England, Digital Technology Assessment Criteria (DTAC), buyer and supplier guidance: https://transform.england.nhs.uk/key-tools-and-info/digital-technology-assessment-criteria-dtac/
- NHS Innovation Service, Updated NHS England DTAC form and guidance (2026): https://innovation.nhs.uk/news/updated-nhs-england-digital-technology-assessment-criteria-dtac-form-and-guidance/
- NHS England, DCB0129 and DCB0160 clinical risk management standards (section 250, Health and Social Care Act 2012): https://digital.nhs.uk/data-and-information/information-standards/information-standards-and-data-collections-including-extractions/publications-and-notifications/standards-and-collections
- NCSC, Cyber Essentials scheme: https://www.ncsc.gov.uk/cyberessentials/overview
- ICO, UK GDPR guidance for organisations: https://ico.org.uk/for-organisations/
- HL7, FHIR R4 specification: https://hl7.org/fhir/R4/
Certification lists feel safe because they are checkable. The data flow is what actually determines your risk, your governance burden, and which certificates matter at all.
When you last assessed an AI vendor, did the conversation start from their certificate list, or from where your patient data would go?



