Audits and Independent Assessments for Trusts and CCGs 2020-21(including NHS Digital-administered ones)

This communication is for all NHS Trusts and CCGs

Following recommendations to improve the level of assurance provided against self-assessments, set out in the NDG for Health and Care: Review of Data Security, Consent and Opt-outs (2016), NHS Digital has published new guidance for audit providers and Trusts.


Organisations in scope

The guidance is designed to be used by DSPT independent assessment providers, including internal auditors, when assessing DSPT submissions. The organisations in scope for mandatory annual audits of their DSPT self-assessments are:

- NHS Trusts (Acute, Foundation, Ambulance and Mental Health)

- Clinical Commissioning Groups

- Commissioning Support Units

- Arm’s Length Bodies


Assessment and Audit Scope for 2020-21

The minimum mandated scope for 2020-21 is reduced in size for this year, following feedback from the Pilot and taking into account the shortened timescale for completing the 2020-21 DSPT. DSPT independent assessments and audits must follow the scope set out below (also detailed in the DSP Toolkit Independent Assessment Guide)

- Org Profile Check - Check sector, key roles (Mail system & CE plus scope - validity)

- 13 Selected Assertions (mandatory evidence items only) - 1.6, 1.8, 2.2, 3.1, 4.2, 5.1, 7.2, 6.2, 7.3, 8.4, 8.3, 9.2 and 10.2


This year (2020-21) NHS Digital will be delivering centrally commissioned DSPT audits/independent assessments to a sample of approximately 20-30 Trusts (Foundation Trusts, Ambulance Trusts, Acute Trusts and Mental Health Trusts) and CCGs, to gain insight into areas of strength and weakness with regards Data Security and Protection. The sample of organisations will be selected by NHS Digital to cover a range of Trusts and CCGs across England. Organisations for which an NHS Digital arranged audit is provided will not need to self-commission an audit for the same financial year / toolkit period.


We will be in touch with Organisations directly, within the next month, with further details once the selection is confirmed.