Tick-box compliance exists on both the developer and implementer sides of digital health, argues Dean Mawson, a clinical safety officer and founder of DPM Digital Health Consultancy. 

As a nurse working on hospital wards, I saw firsthand how compliance that exists on paper, but not in practice, can lead to avoidable harm.

Patient notes are completed, but sometimes hours after the care is delivered. Busy, tired, stressed nurses cast their minds back to Mrs Biggs in bed three 12 hours ago. Was her wound better or worse? Was her dressing changed? 

Twelve hours is a long time when you’ve done hundreds of things – and our memories aren’t always accurate.

We document as best we can, hand over, and go home. Those notes then shape the next shift’s decisions. If something isn’t recorded, as far as the system is concerned, it didn’t happen.

The box is ticked. The risk remains.

Today, handheld devices at the point of care eliminate some of this delay. Observations are recorded in real time, workflows are structured, and systems prompt the next step. On the surface, it certainly looks like progress.

But it hasn’t solved an important underlying issue: the system rewards completion – box-ticking – over accuracy, and presence over quality. As long as something has been recorded, the requirement is technically met. Whether it reflects what happened at the time is a different question, and that’s a problem.

The most common pitfalls leading to a false sense of security

Tick-box compliance creates confidence that isn’t always justified.

As a clinical safety officer (CSO), I see this all the time. The self-certified ambient voice technology (AVT) registry is just a recent example where a box is ticked, but it doesn’t mean anything without further scrutiny from the buying organisation to confirm it.

Across NHS organisations, limited awareness of safety standards, stretched resources, and the sheer number of systems in use all contribute to a significant assurance gap. Around 70% of digital technologies in secondary care are estimated to be in use without proper safety assurance. 

That means no evaluation of potential software failures, no clinical safety case and no risk and incident management plans. This is a huge patient safety shortfall and puts everyone at risk.

The same pattern exists on the supplier side.

Documentation without evidence is a really common issue – I’ve seen hazard logs with one-word descriptions to back up safety claims. On paper, the requirement is met. In reality, the argument is shockingly weak.

At that point, the burden shifts to the NHS organisation to identify missing pieces. Sometimes they do. Sometimes they don’t. When they do, it can kill trust, slow procurement, or even stop it in its tracks.

We saw a good example of the system working well at Frimley Health NHS Foundation Trust, which halted plans to trial EPIC’s ambient voice technology after concerns were raised about its compliance with Class I medical device requirements.

It was reported in some quarters as a failure or over-caution, but really the trust should be applauded – its clinical risk management process worked exactly as designed. It identified a difference between what was claimed (the box that was ticked) and what could be evidenced, and it stopped the deployment before it reached patients.

That is what good assurance looks like. It goes beyond accepting documentation at face value and tests it properly.

But unfortunately this level of rigour is not applied consistently across organisations.

We don’t have a clear picture of how many incidents are linked to poorly assured digital systems, because the data isn’t captured in a way that makes that visible. But we do know that unmanaged risk will only become more of a problem if organisations bury their heads in the sand.

Compliance has become a proxy for safety, when it was never designed to be. Having documentation in place is not the same as understanding and managing risk properly. 

Dean Mawson, founder of DPM Digital Health Consultancy. 
Dean Mawson, founder of DPM Digital Health Consultancy.

What needs to change

For NHS organisations, the priority should be to start where the risk is highest. Focus on the most critical systems and ensure they have been through a meaningful clinical risk management process, aligned to national standards such as DCB0129 and DCB0160.

For suppliers, clinical safety needs to be treated as part of the product, not something layered on afterwards to satisfy procurement. Weak evidence will be exposed eventually – either through due diligence or in real-world use. Deploying organisations are savvy – and becoming more so – so ticking a box without proper attention will only end up delaying commercial conversations and deployment.

For both, this is not a task to be absorbed into an already stretched role. It requires properly trained, accountable expertise. Without that, “tick-box” behaviour is almost inevitable.

With growing scrutiny around AI and digital health, organisations must demonstrate that their systems are safe and well governed.

There is a real risk that the response to that pressure is more visible compliance rather than better assurance. 

If that happens, the system will look more controlled with more documents and processes, but it won’t necessarily be safer.

We cannot afford to test safety for the first time in the context of real patient care.