What DCB0129 and DCB0160 cover
DCB0129 sets clinical risk management requirements for manufacturers of health IT systems. NHS England summarises them as three things: implement proportionate clinical risk management processes, maintain clinical safety documentation, and appoint a clinical safety officer throughout the development lifecycle. DCB0160 sets the matching requirements for the care organisations that deploy and use those systems, such as NHS trusts, primary care organisations and social care providers.
Both are information standards published under section 250 of the Health and Social Care Act 2012, a power that relates to health and adult social care in England. The current versions, DCB0129 version 4.2 and DCB0160 version 3.2, date from 2018, when they were updated to include medical devices. Software that is a medical device and is used in health or care in England therefore sits within the medical device regime and within these standards at the same time.
What the review has found so far
NHS England ran 11 focus groups between January and July 2025, with manufacturers, health and care providers, clinical safety officers and industry experts. It then opened a public consultation on 29 June 2026, which closed on 11 September 2026. Its supporting information reports what the focus groups said. These are findings, not decisions: NHS England has said the proposed approach to revising the standards will come in a consultation response report.
- All focus groups supported keeping clinical risk management mandatory; voluntary compliance was seen as insufficient.
- A risk-based, tiered approach, similar to medical device classification, was widely supported, with enhanced requirements for high-risk areas and more flexibility elsewhere.
- The groups identified gaps, including artificial intelligence governance, complex system interactions, modern development practices, and post-implementation monitoring.
- Current compliance mechanisms were described as insufficient, with calls for stronger compliance tracking and clearer consequences for non-compliance.
- Participants favoured modernising the standards over retiring them, and found no existing alternative standard that could replace them.
The legal duty: what has changed and what has not
Section 95 of the Health and Care Act 2022 changed the duty attached to information standards, from a duty to have regard to them to a duty to comply with them. Since 7 July 2025, section 250(6A) of the 2012 Act has provided that a person to whom an information standard applies must comply with it, unless the requirement is waived.
That change does not reach the current DCB0129 and DCB0160. The regulations that brought it into force, SI 2025/807, include a saving provision: for any information standard already in effect before 7 July 2025, the 2012 Act applies as if the amendment had not been made. NHS England states the position plainly in its supporting information: as the standards stand, bodies exercising a health and care function must continue to have regard to them.
A second change widens who a future standard can bind. Section 121 of, and Schedule 15 to, the Data (Use and Access) Act 2025, in force since 5 February 2026, allow an information standard to apply to a relevant IT provider: a person who markets, supplies or otherwise makes available information technology or IT services used in health or adult social care in England, whether for payment or free of charge.
Put together, a revised DCB0129 published under the amended section 250 could apply to manufacturers directly and carry a duty to comply rather than to have regard. NHS England describes future revisions as likely to use these powers; it has not yet said how. Publishing a replacement standard now also follows the Health and Social Care Information Standards (Procedure) Regulations 2025 (SI 2025/950), in force since 6 August 2025.
Where this sits next to UK MDR
DCB0129 and DCB0160 do not decide whether software can be placed on the market. For a software medical device in Great Britain, that is decided under the Medical Devices Regulations 2002 (SI 2002/618), the UK MDR, through UKCA marking or recognition of a CE mark, with the MHRA as the regulator. The clinical risk management standards answer a different question: how the software's clinical safety is managed, by the manufacturer under DCB0129 and again by each deploying organisation in England under DCB0160.
The two regimes run on different legal bases and are read by different people. A device's technical documentation is assessed through its conformity assessment route; a clinical safety case is read by the organisations that deploy the software and assess its clinical risk in their own setting. Much of the underlying hazard analysis overlaps, which is the practical reason to build it once.
What a software or AI device maker can do now
Nothing in the review changes the standards you work to today. These steps keep you ready for a revision without guessing at its content.
- Keep your DCB0129 documentation current against version 4.2. It remains the version in force until a revision is published.
- Run one risk process. If your device risk management file and your clinical safety case draw on the same hazard analysis, a revised standard becomes an update to one process rather than a second programme of work.
- Know where your software would sit on a tiered scale. The focus groups asked for enhanced requirements in high-risk areas and flexibility elsewhere, so your risk position will matter more than it does today.
- If your product uses AI or machine learning, note that the review names AI governance as a gap the current standards do not adequately address.
- Plan for a direct duty. If a revised DCB0129 is issued under the amended section 250, the duty to comply could fall on you as a relevant IT provider, not only on the NHS organisations you sell to.
- Watch for the consultation response report, which NHS England has said will set out the proposed approach to revising both standards.