AI GovernanceMarch 2026 · 7 min read

Governance frameworks for AI: why the NHS trust model does not scale down

Article

The governance frameworks that NHS trusts have built for AI are, on the whole, well designed. They assign the work to roles that exist: a chief clinical information officer, a Caldicott Guardian, a data protection officer, a clinical safety officer, an information governance team. They route decisions through committees that meet. They rest on procurement processes with stages and sign-offs. The framework works because the organisation underneath it has the shape the framework assumes.

Independent providers are handed these frameworks, or versions of them, and asked to comply. The result is rarely governance. It is the appearance of governance: a policy that names roles nobody holds, a committee that exists on paper, a risk register completed once and never opened. The document mirrors the trust's artefact without performing the trust's function.

Why the translation fails

The roles collapse into one person

In a trust, the six or seven roles a framework names are six or seven people, each with a remit and a fraction of their time protected for it. In a care home or a small clinic they are the registered manager. Writing “the Caldicott Guardian will review” into a policy does not create a Caldicott Guardian. It creates a sentence the registered manager will read at the next inspection and be unable to evidence.

The committees do not exist

Trust frameworks route decisions to groups: a digital board, a clinical safety group, an information governance committee. The value of a committee is not the meeting; it is that several people with different expertise see the decision before it is made. A small provider has no such groups and cannot conjure them. What it needs is the function, a second pair of eyes on the decision, not the form.

Procurement is informal

Frameworks assume tools arrive through a process with gates. In small organisations they arrive through individuals: a clinician trials an app, an administrator adopts a tool, a manager signs up to a trial. Governance that begins at the procurement gate never sees most of what is actually in use.

There is no protected time

A framework that requires quarterly review, annual training, incident analysis and periodic audit assumes someone has the hours. Where nobody does, the requirements are quietly not met, and the framework becomes a record of non-compliance rather than a means of assurance.

Scaling a framework down is not a matter of shortening it. It is a matter of keeping the function and abandoning the form.

What proportionate governance actually keeps

Regulators already apply proportionality. The CQC assesses a two-bed supported living service and a 400-bed hospital against the same quality statements but does not expect the same machinery. The ICO expects accountability that fits the scale of the processing. Governance frameworks for AI should be held to the same standard. Stripped of trust-specific form, the functions that must survive are five:

  • Someone decides. A named person approves each tool for a stated purpose, and their approval is recorded in a sentence, not a form.
  • Someone knows what is in use. A list of tools, their purposes and their owners, kept current, including the ones that arrived informally.
  • Someone is watching. A person responsible for noticing when a tool misbehaves, with a route for staff to reach them.
  • Someone can stop it. Authority to withdraw a tool without escalation through a hierarchy that does not exist.
  • Someone looks again. A fixed point, quarterly is enough, at which the list is reviewed and the question asked whether each tool is still appropriate.

In a small provider those five functions may all rest with the registered manager and a deputy. That is not a weakness. It is a clarity that large organisations struggle to achieve. What matters is that the functions are real, named and evidenced, rather than that they are distributed across roles the organisation does not have.

The test

A useful test for any framework offered to a small provider: for each requirement, ask who in this organisation will actually do this, when, and how it would be evidenced. Where the honest answer is nobody, the requirement should be redesigned or removed rather than left in place to fail. A framework that will be complied with is worth more than one that reads well.

This article sets out Novatib's advisory position. It is not legal or regulatory advice.

Next

Governance designed for the organisation you have.

The advisory assessment produces an oversight framework proportionate to the provider's size, resources and risk, with every requirement assigned to a person who exists.