Who this is for
- Private GP and GP-led clinics
CQC's GP mythbuster on AI is one of the clearest public statements of what a GP service may be asked to show when AI touches clinical workflows, records, human oversight or patient data.
Read the scope carefully. It is GP-specific. It is not a universal standard for every private clinic, and treating it as one overstates what it does. What it gives a private provider is a reasonable proxy for the questions an inspector, a DPO or a board member is likely to ask, written down by the regulator rather than guessed at by a consultant.
The question a clinic should be able to answer is not whether it uses AI. Nearly every clinic does. It is whether the clinic can show how that use is governed, reviewed and owned.
Evidence areas a GP clinic may need to explain
Checklist
- Which AI tools are in use, including tools staff adopted without asking.
- Who approved each one, and on what basis.
- Whether patient data enters the tool.
- DPIA status, and whether a DPIA is likely required or strongly indicated.
- Vendor evidence: data processing agreement, hosting, retention, model training, sub-processors.
- The human oversight process: who reviews AI output before it reaches the record.
- Staff guidance and training.
- The incident route when AI output is wrong.
- Board or partnership review of AI use.
- Clinical safety ownership, where relevant.
The gaps that show up most often
No AI tool inventory. No approved, conditional and prohibited use position. An ambient scribe running live with no DPIA screening and no vendor file. Clinicians using ChatGPT or Copilot on personal accounts. No written human-review step. No AI-specific incident route. No board-level view of any of it.
Wording that holds up, and wording that does not: use
- evidence gap
- Governance-standard signal
- DPO or legal review required
- Vendor confirmation required
- Priority review required
Avoid
- predictions of inspection outcomes
- Legal conclusions the evidence does not support
- Any claim of regulatory approval or guaranteed inspection readiness
- No consultancy, including this one, can deliver a CQC outcome.
What ELSA AI can help produce
The Clinical AI Exposure Diagnostic™ maps declared and shadow AI use, patient-data exposure and evidence gaps against published expectations, and converts each finding into a dated action with a named owner. Four working days from the start of delivery.
Outputs include
- Board Findings Report
- RAG Exposure Map
- AI Tool and Use Case Inventory
- DPIA Readiness and Patient Data Exposure Note
- Vendor Data Position and Evidence Tracker
- Ambient Scribe Assessment Sheet, where applicable
- MDO, PMI and Insurer Disclosure Readiness Note
- 30-Day Priority Action Plan
- Source and Guidance Mapping Appendix
Advisory governance support only. Not legal advice, DPIA sign-off, CQC approval, ICO approval, insurer coverage advice, MDO indemnity advice or clinical safety case sign-off. Final decisions remain with the organisation's accountable officers and advisers.
Need this evidence mapped for your clinic or group?
The Clinical AI Exposure Diagnostic™ gives clinic leadership a board-ready view of AI use, patient-data exposure, evidence gaps and priority actions in four working days from the start of delivery.