An NHS buyer needs confidence that a successful supplier will protect sensitive information throughout the contract. This may include patient records, staff details, operational data, commercially sensitive documents and information generated by connected medical or digital systems.
Weak tender responses often list policies, certifications and technical standards without explaining how they apply to the proposed service. Stronger answers follow the information through the contract, identify the risks at each stage and show how responsibilities, controls and reporting will work in practice.
Information governance covers the responsibilities and controls used to manage information safely, lawfully and effectively. The exact requirements will depend on the contract. A digital health supplier processing patient information will face different risks from a consultancy that only receives NHS employee contact details.
Relevant information might include:
Information governance also extends beyond cyber security.
| Area | Main purpose |
| Data protection | Ensuring personal information is used lawfully and fairly |
| Information governance | Managing accountability, quality, confidentiality and sharing |
| Cyber security | Protecting information and systems from digital threats |
| Clinical safety | Reducing the risk of patient harm caused by health technology |
| Records management | Controlling accuracy, retention, access and disposal |
A supplier may have strong technical security but weak retention controls. Another may comply with UK GDPR but lack the clinical safety documentation required for its software. Buyers need evidence covering the areas relevant to the actual service.

Before drafting the response, establish how information will move through the proposed delivery model. Identify:
This exercise can expose important tender questions. For example, a supplier may discover that its support team can access live patient information, that data is backed up outside the UK or that a software provider acts as a sub-processor. Requirements may also vary across direct trust procurements, national frameworks and other NHS procurement routes and platforms. Do not reuse the same information-governance response without checking the contract’s data flow. The technology, organisations, processing purpose and level of risk may be different.
The Data Security and Protection Toolkit, or DSPT, is an NHS online self-assessment tool. It allows organisations to measure their performance against the National Data Guardian’s data-security standards. Organisations with access to NHS patient data or systems must use the toolkit to provide assurance that they handle information appropriately.
Where the DSPT is relevant, a tender response should confirm:
The toolkit is one of several possible framework accreditations and assurance requirements that suppliers should organise before an NHS tender deadline. Do not simply state that your wider company group is compliant. Confirm that the published DSPT submission covers the bidding entity and the service being proposed.
For IT suppliers, the current assurance framework includes mandatory audited areas such as governance, identity and access management, privileged access, vulnerability management, incident response and continuity testing. DSPT status is useful evidence, but it does not replace a contract-specific explanation of how information will be controlled.
The tender should make clear whether the NHS organisation and supplier will act as controllers, joint controllers, processors or sub-processors. These roles are determined by what each organisation does. A processor handles personal information on the controller’s instructions, while a controller determines the purposes and essential means of processing.
Where the supplier acts as a processor, a written contract or equivalent legal act is required. The agreement should address matters including:
The Information Commissioner’s Office guidance on controller and processor contracts confirms that processors must also have appropriate written terms with any sub-processors they appoint.
A privacy policy is not a substitute for this operating model. Your response should explain how instructions are recorded, how requests are supported and who makes decisions when an issue arises.

Statements such as “we use industry-standard security” provide little assurance. Evaluators need to understand the controls applied to the systems and information used for their contract. Depending on the service, this might include:
Explain who approves access, how privileges are reviewed and how quickly accounts are removed when someone leaves.
Where the procurement requires Cyber Essentials Plus, confirm the certification’s scope and expiry date. Check that it covers the organisation, devices and services used for contract delivery. The government’s Cyber Essentials procurement guidance supports proportionate use of Cyber Essentials or Cyber Essentials Plus in public contracts where cyber risks make certification appropriate. Cyber Essentials Plus provides useful technical assurance. It does not, by itself, prove DSPT compliance, lawful processing, records management or clinical safety.
Digital suppliers should provide a transparent picture of where NHS data will be held and which third parties may access it. Prepare evidence covering:
Suppliers pursuing opportunities through cloud frameworks should keep this information consistent across service listings, contracts and tender responses.
Maintain a controlled sub-processor register. It should identify each provider, its service, data access, processing location, contractual position and current assurance status. Do not omit a third party because it sits several layers below your organisation. If it processes the NHS organisation’s personal information, the buyer may expect it to be declared and appropriately controlled.
Clinical safety requirements are particularly relevant where digital technology could affect patient diagnosis, treatment, monitoring or care. DCB0129 applies to manufacturers of health IT systems. DCB0160 applies to health and care organisations deploying and using those systems.
Where applicable, a supplier may need to provide:
NHS England’s digital clinical safety assurance guidance explains that the hazard log is a core document used to record and evaluate safety risks associated with a product.
Information security and clinical safety overlap, but they are not interchangeable. A system might be well protected from unauthorised access yet still create a clinical risk if it displays inaccurate information, delays an alert or becomes unavailable at a critical point.
Suppliers should also be aware that NHS England launched a national review of DCB0129 and DCB0160 in June 2026. The existing standards remain relevant while that review continues.

NHS buyers will want to know what happens when a control fails. A clear response should explain:
Cyber incidents, personal data breaches and service interruptions may involve different teams and reporting thresholds. The response should show how those processes connect. Useful evidence could include continuity-test results, incident exercises, recovery times and examples of changes introduced following previous events.
Avoid saying that the NHS organisation will be told “as soon as possible” if the tender asks for a specific notification period. Agree achievable timescales with technical and governance teams before submission.
Policies and certifications support an answer, but evaluators also need to understand how controls operate.
| General claim | Stronger evidence |
| We control system access | Access matrix, approval process and removal timescale |
| Staff receive IG training | Completion rate, refresher cycle and specialist modules |
| We test continuity | Exercise date, scenario, recovery result and actions |
| Data is encrypted | Encryption standard, scope and key-management process |
| We manage suppliers | Due diligence, assurance reviews and escalation |
| We comply with DSPT | Published status, reporting period and improvement actions |
| Our product is clinically safe | Clinical Safety Officer, hazard log and safety case |
Relevant measures should be specific wherever possible. Instead of saying that access is reviewed regularly, state the review frequency, owner and process for resolving inappropriate permissions.
At Bidding, we also recommend testing whether supporting evidence is consistent across the technical response, implementation plan and contract schedules. Contradictions can undermine an otherwise credible submission.
NHS bids are often weakened by:
A large evidence pack will not resolve these problems if the written answer does not explain how the controls apply.
Maintain current information covering:
Select evidence according to the question rather than attaching every available document.
Information governance answers often need contributions from data protection, cyber security, technical, operational and clinical teams. Build enough time into the tender programme to gather, check and approve their input.
NHS buyers want confidence that sensitive information will remain confidential, accurate, available and appropriately controlled. Achieving that requires more than listing policy names or technical certifications.
Bidding helps healthcare and digital suppliers interpret tender requirements, coordinate specialist contributors and turn complex governance controls into clear, scoreable answers. We can develop priority responses, challenge an internally prepared draft or support the wider submission through to completion.
Speak to Bidding about strengthening the information-governance sections of your next NHS bid.
Bidding Ltd © 2026