CORSALVEO
  • Home
  • About
  • ROHIT
  • Assurance
  • Privacy
  • Contact
Corsalveo
About ROHIT Assurance Privacy Contact
Make a referral ↗

Governance and assurance

Safety and accountability are part of the product.

Corsalveo develops clinical digital services within a defined framework of clinical-safety management, information governance, human oversight and organisational responsibility.

Our principles

Governance should shape how a service is designed—not merely document it afterwards.

01

Clinically led

Intended use, clinical risks and controls are considered with clinicians who understand the pathway.

02

Human controlled

ROHIT supports clinical communication. Clinical decisions remain with appropriately qualified professionals.

03

Proportionate

Information and access are limited to what is required for the defined clinical and operational purpose.

04

Accountable

Referral, review, advice, updates and outcomes form part of an auditable pathway.

Clinical safety

A hazard-led approach to clinical risk.

Corsalveo applies a structured clinical-safety process to ROHIT. Potential hazards are identified, assessed and linked to controls within the product, its operating procedures and the organisations deploying it.

Clinical-safety work is overseen by a named Clinical Safety Officer. Documentation is reviewed as the product, its intended use or the clinical pathway changes.

Defined intended use

Each service has a stated purpose, user group, clinical scope and boundary.

Clinical hazard log

Identified hazards, causes, consequences, controls and residual risks are recorded and maintained.

Clinical-safety case

Evidence supporting the safe design and intended use of a defined product release is assembled and reviewed.

Change control

Material changes are assessed for potential clinical, operational and information-governance consequences.

Incident learning

Safety concerns and incidents can inform corrective action, revised controls and service improvement.

Clinical-safety standards

Corsalveo’s supplier clinical-safety documentation is developed with reference to DCB0129. Deploying healthcare organisations retain their own responsibilities, including those arising under DCB0160.

Information governance

Information should be used deliberately, transparently and securely.

Privacy, access, data flows and retention are considered as part of pathway design and reviewed as services change.

Privacy by design

Information requirements and data flows are considered during pathway design rather than after deployment.

Data minimisation

Services are designed to process information relevant to the defined clinical and operational purpose.

Controlled access

Access is assigned according to role and operational need, with administrative privileges restricted.

Auditability

System activity and clinical workflow events support accountability, investigation and service assurance.

Defined retention

Retention arrangements reflect the information processed, the service purpose and organisational requirements.

Incident response

Processes support identification, escalation, investigation and learning after information or security incidents.

Shared responsibility

Safe deployment requires coordinated action by Corsalveo and each deploying healthcare organisation.

Corsalveo manages the clinical safety of the ROHIT product. Each healthcare organisation remains responsible for deploying and using it safely within its own clinical pathways, systems and operating environment.

Corsalveo responsibilities

Supplier responsibilities aligned with DCB0129

  • Define and document the product’s intended use, limitations and safety boundaries.
  • Maintain the clinical risk-management plan, hazard log, clinical safety case and clinical safety case report.
  • Identify product-related clinical hazards and implement proportionate risk controls.
  • Apply appropriate design, testing, release and change-control processes.
  • Provide deploying organisations with the information needed for local clinical-safety, information-governance and implementation assessments.
  • Communicate material changes, newly identified hazards and relevant safety information.
  • Support the investigation of incidents or safety concerns involving ROHIT.

Deploying organisation responsibilities

Local deployment responsibilities aligned with DCB0160

  • Assess ROHIT within the organisation’s local clinical pathways, technical environment and operating context.
  • Appoint appropriate clinical-safety leadership and complete the organisation’s local clinical risk-management process.
  • Identify and control hazards arising from local configuration, workflow, integration and use.
  • Complete applicable information-governance, data-protection, cyber-security and procurement processes.
  • Define local clinical ownership, user roles, escalation routes and operational procedures.
  • Provide appropriate access controls, induction, training and user support.
  • Maintain emergency, downtime and business-continuity arrangements. ROHIT must not replace established emergency pathways or primary PCI activation processes.
  • Monitor local use and report incidents, hazards and material pathway changes to Corsalveo.

Assurance evidence

Documentation for proportionate due diligence.

The documentation available depends on the product release, intended use, pathway and responsibilities of the participating organisations.

Clinical hazard log

Records identified clinical hazards, controls and residual risks.

Maintained

Clinical-safety case

Summarises the safety argument and supporting evidence for a defined product release.

Release-based

Data Protection Impact Assessment

Describes relevant processing, data flows, privacy risks and controls.

Reviewed

Privacy information

Explains relevant processing and how information rights may be exercised.

Maintained

User and operational guidance

Defines appropriate use, user responsibilities, escalation, handover and contingency arrangements.

Maintained

Data Security and Protection Toolkit

Organisational evidence and supporting policies assembled and reviewed.

Maintained
Status descriptions

These descriptions refer to Corsalveo’s internal assurance activity. They do not represent external certification, regulatory approval, NHS accreditation or NHS endorsement. Published external assurance status will be linked to its authoritative source when available.

Safe-use boundaries

ROHIT supports communication. It does not replace clinical judgement or emergency pathways.

Clinical decisions remain with appropriately qualified clinicians. Users remain responsible for assessing the patient, recognising deterioration, following local escalation arrangements and acting through the appropriate emergency pathway.

Where decision-support or draft content is introduced, it must remain subject to review and approval by an appropriately qualified clinician before contributing to patient care.

ROHIT is not a substitute for emergency services, direct primary PCI activation or any other established pathway for an immediately life-threatening condition.

Due diligence

Assurance should be inspectable.

Relevant clinical-safety, privacy, security, technical and operational documentation can be shared with prospective partner organisations as part of proportionate due diligence and deployment planning.

Requests should identify the proposed clinical pathway and organisation so that the appropriate documentation can be supplied.

Contact Corsalveo →
Corsalveo.

Clinician-led digital infrastructure for connected care.

About ROHIT Governance Privacy Contact
Data Security and Protection Toolkit

Data Security and Protection Toolkit View Corsalveo’s current published assessment and status on the official DSP Toolkit register.

© 2026 Corsalveo Limited · Registered in England and Wales · Company number 06776365 · Registered office: 63 Calbourne Road London SW12 8LS.
Corsalveo is an independent organisation. References to NHS services do not imply endorsement by the NHS or by any individual NHS organisation.
  • Home
  • About
  • ROHIT
  • Assurance
  • Privacy
  • Contact