- Question to ask
- Do we hold a single register of the AI tools in use, for what, and by whom?
- Evidence to look for
- A current register covering declared tools, embedded AI features, and the purpose of each.
- What an evidence gap may indicate
- The clinic cannot list, on request, what AI it relies on. This is the difference between informal AI use and a documented position.
- Typical owner
- Practice manager or IG lead
ELSA AI · Clinical AI Governance
Where AI exposure hides in a private clinic
Ambient scribes, ChatGPT, Microsoft Copilot, transcription and admin tools are often already in use in a clinic before any governance position is written down. This map sets out the governance questions a clinic should be able to answer, and the evidence that supports each answer.
This map shows the questions. It is illustrative. The Clinical AI Exposure Diagnostic™ establishes your clinic's actual position using a fixed thirteen-dimension advisory RAG map. The map below does not rate any single clinic.
Priority depends on the tool, workflow, patient-data involvement and evidence available. The Diagnostic assigns a clinic-specific advisory RAG position.
How to read the map
Three questions a board, partners or accountable leadership should be able to answer
The exposure a clinic carries is not that AI exists. It is whether the clinic can answer, with evidence, when its DPO, an inspector, its insurer, its MDO or its leadership asks how that AI use is controlled. The map groups the thirteen Diagnostic dimensions under three plain questions.
Question 1
Do we know what is in use?
Declared tools, embedded AI features, informal workflows, and the AI staff reach for when no approved route exists.
Question 2
How may it affect patients and data?
Patient-data processing, supplier position, output accuracy, human oversight, transparency and clinical safety.
Question 3
Can we show how it is controlled?
Ownership, staff guidance, incident handling, external readiness and leadership evidence.
The map
Governance questions and the evidence behind them
Open a card to see the question to ask, the evidence to look for, what an evidence gap may indicate, and the owner who typically holds it. The tag shows whether a dimension is core across clinics or applies by workflow. Every Diagnostic considers all thirteen, recording any that do not apply with a reason.
- Question to ask
- Are staff using AI tools that leadership has not seen or approved?
- Evidence to look for
- A confidential, non-disciplinary signal of actual use, alongside device and account controls.
- What an evidence gap may indicate
- Use is happening around an absent approved route, workload pressure or unclear guidance, rather than any intent to break rules.
- Typical owner
- IG lead, with leadership backing
- Question to ask
- What patient or special category data does each tool process, and where does it go?
- Evidence to look for
- A data flow for each tool, the account type in use, and the contractual and security position.
- What an evidence gap may indicate
- Patient information may sit in consumer-tier accounts where retention, model-improvement use, access controls and contractual protections depend on the provider, account type and settings, and the clinic cannot evidence its position.
- Typical owner
- DPO
- Question to ask
- Have we screened each AI use for a DPIA, and completed one where a data protection impact assessment is likely required or strongly indicated?
- Evidence to look for
- A DPIA screening record, and a completed DPIA where the DPO has determined that the proposed processing is likely to result in high risk.
- What an evidence gap may indicate
- DPIA screening has not been evidenced. Where processing is likely to result in high risk, a DPIA is likely required or strongly indicated. The determination remains with the clinic's DPO.
- Typical owner
- DPO
- Question to ask
- Can we evidence where suppliers process data, under what terms, and with what transfer and security protections?
- Evidence to look for
- A data processing agreement, hosting location, international transfer mechanism, sub-processors, retention, deletion, and recognised security assurance such as ISO 27001.
- What an evidence gap may indicate
- The clinic cannot show where data is processed, which sub-processors are involved, what transfer mechanism applies, or what contractual and security evidence supports the arrangement. This is a point for DPO and legal review and vendor confirmation.
- Typical owner
- DPO, with procurement
- Question to ask
- If an ambient scribe is in use, in trial or planned, is the whole workflow governed, from patient information to deletion?
- Evidence to look for
- Patient information and an objection route, supplier evidence, use within the supplier's stated intended purpose, human review of the note, and retention and deletion settings.
- What an evidence gap may indicate
- The product has been adopted, but the end-to-end consultation workflow has not been evidenced, including patient information, clinician review, retention, supplier evidence and incident arrangements.
- Typical owner
- Clinical lead and DPO
- Question to ask
- Is there a documented, meaningful human review step before AI content reaches the record, a patient, or a decision that may affect care?
- Evidence to look for
- A human-review procedure, and an auditable marker for AI-assisted entries.
- What an evidence gap may indicate
- Review may occur in practice but is not documented, evidenced or audited, and mere formal approval may not amount to meaningful human review. Where AI makes or materially determines a decision with a legal or similarly significant effect, DPO or legal review is required to assess the applicable automated decision-making rules and safeguards.
- Typical owner
- Clinical lead, with DPO
- Question to ask
- Have we documented how patients are informed about AI use and how questions or objections are handled?
- Evidence to look for
- Patient-facing information, a route for questions, concerns or objections, and a record of how privacy and confidentiality were assessed.
- What an evidence gap may indicate
- Transparency, lawful basis, duty of confidence and the objection route have not been documented or assessed. DPO or legal review may be required. Patient objection itself does not determine the lawful basis.
- Typical owner
- DPO and clinical lead
- Question to ask
- Who owns AI governance in the clinic, and what is their remit and authority?
- Evidence to look for
- A named owner, brief terms of reference, and a place where AI decisions are recorded.
- What an evidence gap may indicate
- AI is being adopted tool by tool, with no single accountable owner.
- Typical owner
- Registered manager, partners or leadership
- Question to ask
- Do staff have clear guidance on approved AI use, and have they been trained on it?
- Evidence to look for
- Written guidance on patient-data use, an approved-tool list, and a record of training.
- What an evidence gap may indicate
- Staff are left to judge for themselves what is safe, with no approved route to fall back on.
- Typical owner
- Practice manager
- Question to ask
- Is there a route for when an AI tool produces an unsafe output or a suspected data leak?
- Evidence to look for
- An AI incident route that connects to the clinic's existing clinical safety, information governance, data protection and complaints processes.
- What an evidence gap may indicate
- The clinic would have to improvise rather than follow an agreed route. AI incidents may not be connected to the clinic's existing clinical safety, information governance, data protection and complaints processes.
- Typical owner
- IG lead and DPO
- Question to ask
- Could we answer, with evidence, if the DPO, an inspector, the insurer or the MDO asked how our AI use is controlled?
- Evidence to look for
- An assembled evidence position ready to share, and a record of what has and has not been reviewed.
- What an evidence gap may indicate
- The clinic holds no documented position to hand over. This may affect indemnity support and should be clarified with the insurer or MDO.
- Typical owner
- Registered manager and DPO
- Question to ask
- Has the board, partners or accountable leadership considered the clinic's AI governance position and agreed the priority actions?
- Evidence to look for
- A leadership summary, recorded decisions, agreed owners and action dates, and any risk acceptance that has been formally documented.
- What an evidence gap may indicate
- AI risk sits below leadership visibility, with no recorded decision on what remains open.
- Typical owner
- Board, partners or accountable leadership
Clinical safety and intended purpose
Not every AI tool is a medical device, and formal clinical safety assurance is applicable in some cases and advised in others. DCB0129 covers manufacturer-side clinical safety evidence; DCB0160 covers the deploying organisation's local clinical risk process, including the local hazard log and Clinical Safety Case Report. Applicability depends on the technology, deployment and organisational context. NHS contracts, NHS data-sharing arrangements and use of NHS systems may introduce additional contractual or standards requirements that need separate confirmation. ELSA AI identifies where DPIA screening, supplier clinical safety evidence or review by a Clinical Safety Officer may be needed. It does not determine medical device or SaMD classification, author DCB0160, or appoint a Clinical Safety Officer.
Uneven performance across populations
Performance may vary across accents, language patterns, demographics or clinical contexts. Whether that matters depends on whether it can alter the record, a referral, treatment or patient communication. The clinic should establish whether supplier testing and local monitoring cover the population and workflow in which the tool is used. For GP services, CQC Mythbuster 109 provides a relevant governance signal. Other clinic types should apply the sources relevant to their own regulatory and professional context.
Ambient scribing and NHS England guidance
NHS England's guidance on AI-enabled ambient scribing products (Version 2) applies to health and care settings in England and is NHS-focused in its implementation arrangements. ELSA AI uses it as a governance-standard signal for private clinics where relevant. Where a scribe is in use, in trial or planned, the engagement routes to the Clinical AI Exposure Diagnostic with Ambient Scribe Assessment.
From questions to controls
Common control directions
These are directions, not a prescribed plan. The right controls, their cost and their sequence depend on the clinic's environment, and the Diagnostic determines what applies. Nothing here is low cost or sufficient by default.
Provide an approved route and restrict unsafe use
- Typical owner
- IG lead, with leadership
- Evidence
- Interim guidance on patient-data use, a sanctioned alternative where appropriate, and proportionate technical restrictions.
- Applies where
- Staff may enter patient data into consumer-tier tools.
- Closure signal
- An approved route is in place and communicated, and use outside the approved route is restricted.
Screen for DPIA and clinical safety requirements
- Typical owner
- DPO and clinical lead
- Evidence
- A DPIA screening record, a clinical safety applicability decision, and supplier DCB0129 evidence where relevant.
- Applies where
- AI processes patient data or informs clinical decisions.
- Closure signal
- Screening documented and routed to the Clinical Safety Officer or accountable clinical lead.
Require meaningful human review
- Typical owner
- Clinical lead
- Evidence
- A human-review procedure and an auditable marker for AI-assisted entries.
- Applies where
- AI content may reach the record, a patient, or a decision that may affect care.
- Closure signal
- The procedure is documented and followed, not a formal sign-off only.
Set and evidence retention rules
- Typical owner
- DPO
- Evidence
- A documented position on what is retained, why, for how long, and who can delete it.
- Applies where
- Tools capture audio, transcripts or patient data.
- Closure signal
- The retention period is documented, justified and configured consistently with the approved position.
Inform patients and provide a route for questions, concerns or objections where relevant
- Typical owner
- DPO and clinical lead
- Evidence
- Patient information, a route for questions, concerns or objections, and a recorded confidentiality assessment.
- Applies where
- AI touches the consultation, the record or patient communication.
- Closure signal
- Information and route are in place, and the assessment is recorded.
Hold an incident route connected to existing processes
- Typical owner
- IG lead and DPO
- Evidence
- An AI incident route into the clinic's clinical safety, information governance, data protection and complaints processes.
- Applies where
- Any AI sits in a patient-facing or record workflow.
- Closure signal
- Routes are documented and tested, not improvised on the day.
Source basis
What informs this map, and its status
These sources inform the questions above. They carry different status, and are grouped accordingly. Referencing a security framework does not mean ELSA AI has tested any application.
Legislation and regulatory guidance
| Source | What it supports | Status |
|---|---|---|
| UK GDPR | Lawful basis, transparency, DPIA duty, restrictions on solely automated decisions | Legislation |
| Data Protection Act 2018 | The UK data protection framework alongside the UK GDPR | Legislation |
| Data (Use and Access) Act 2025 | Reformed automated decision-making rules (from 5 February 2026) and the controller duty to handle data protection complaints (from 19 June 2026) | Legislation |
| ICO guidance on AI and data protection | Lawful basis, transparency, accuracy in AI systems | Regulatory guidance |
| ICO DPIA guidance | When a DPIA is required, and how to screen and complete one | Regulatory guidance |
| CQC GP Mythbuster 109 | GP-specific AI governance considerations | GP-specific signal, not an identical requirement for every private clinic |
| NHS England ambient scribing guidance | Ambient scribe adoption governance | NHS England guidance for health and care settings in England; used as a governance-standard signal for private clinics where relevant |
| DCB0129 and DCB0160 | Clinical safety for manufacturers and deployers of health IT | Clinical safety standards; applicability determined in context |
| MHRA software and AI as a medical device guidance | Where an AI tool meets the medical device definition | Medical device guidance; ELSA AI flags where review may be needed and does not classify |
Governance frameworks
| Source | What it supports | Status |
|---|---|---|
| NIST AI Risk Management Framework | Structuring an internal AI governance programme | Governance-standard signal, not a UK requirement |
| ISO/IEC 42001:2023 | An AI management system a clinic or supplier may adopt | Governance-standard signal, not required |
Security and supplier-evidence references
| Source | What it supports | Status |
|---|---|---|
| NCSC and international partner AI guidance | Questions to ask suppliers on secure AI design, development and operation | Governance-standard signal |
| ISO/IEC 27001:2022 | Whether a supplier holds recognised information security assurance | Evidence, not a guarantee |
| OWASP LLM Top 10 v2.0 2025 | Supplier LLM-security evidence questions, such as prompt injection and data poisoning | Technical reference; referencing it does not mean ELSA AI has tested an application |
Source basis last reviewed July 2026. Sources should be checked against the current official publication before reliance.
See where your clinic actually stands
This map shows the questions. The Clinical AI Exposure Diagnostic™ maps your declared and shadow AI use and evidence gaps, then produces a 30-day priority action plan. For clinics within the published Standard scope envelope, the Diagnostic is delivered in four working days from the start of delivery. The fixed fee is confirmed in writing before the delivery clock starts.
What ELSA AI does not do
- Provide legal advice or determine legal compliance
- Give CQC, ICO or NHS approval
- Determine insurer coverage or MDO indemnity
- Complete or sign a DPIA
- Sign off a clinical safety case, author DCB0160 or act as your Clinical Safety Officer
- Classify a medical device or SaMD
- Perform penetration testing or technical security testing
- Guarantee compliance or a CQC outcome
This resource is an illustrative governance map of common AI exposure questions in private healthcare. It is advisory and does not determine breach, regulatory failure, indemnity position or clinical-safety status for any specific clinic. Final legal, data protection, clinical safety, regulatory, insurer and indemnity decisions remain with the clinic's accountable officers, including the DPO, legal counsel and Clinical Safety Officer.