Not for emergencies. If someone is seriously unwell or in immediate danger, call 999. For urgent medical help use NHS 111 or your local urgent-care route.
Display: Accessibility statement

Healing Process policy suite

AI Image Alignment, Comparison and Human Oversight Policy

StatusWorking draft
Version1.0-draft
OwnerAI Governance Lead and Clinical Safety Officer
Review date23 July 2027 or earlier
Approval status: this is a substantive governance draft for review. It is not evidence that a production control has been implemented, audited or approved. Each live NHS or care deployment must align it with the provider’s policies, law, contract and configured service.

1. Purpose

To govern any automated image quality, alignment, segmentation, normalisation, apparent-change estimation or prioritisation used by Healing Process, ensuring traceability, proportional claims, fairness and meaningful human control.

2. Scope and status

This policy applies to rules-based, statistical, machine-learning and generative techniques used in the app, portal, research or content operation. It covers development data, model evaluation, user interface, deployment configuration, monitoring and retirement.

Core supplier and product policy

3. Policy principles

  • The original image is the primary source record. A derivative must never be presented as though it were the original.
  • The system supports review; it does not independently diagnose infection, healing, deterioration or treatment need unless and until a separately regulated and evidenced intended purpose lawfully permits a specific claim.
  • No generative process may invent, remove or conceal clinical detail in a view used for care. Where a non-clinical illustrative transformation is used, it must be isolated and unmistakably labelled.
  • Human oversight must be effective: the reviewer receives the source, limitations and authority to reject the output, and workflow design must not punish appropriate override.

4. Mandatory requirements

  • Document the exact input, output, intended user, clinical context, decision influence, exclusions and prohibited uses for every analytical function.
  • Preserve baseline and follow-up originals with immutable identifiers and link each derivative to source hashes, algorithm/model version, parameters, time and processing result.
  • Show capture quality, alignment confidence, uncertainty and relevant failure reasons in language appropriate to the user.
  • Evaluate performance using representative data across skin tones, devices, lighting, body areas, wound or skin presentations, age and other relevant factors; report confidence intervals and important gaps.
  • Use a documented data-governance route for training and validation data, with provenance, lawful processing, annotation quality, separation of datasets and controls against leakage.
  • Prevent an automated result from suppressing a user concern, closing a clinical queue, cancelling review or downgrading urgent action without an authorised protocol and human decision.
  • Monitor drift, data quality, subgroup performance, override, complaints, false reassurance and false escalation after deployment.
  • Maintain a rollback or kill switch and a safe fallback that continues to show originals and permits ordinary review when analysis is unavailable.
  • Provide understandable user information about what the analysis does, the main limitations and who makes the decision; avoid anthropomorphic or certainty-inducing language.

5. Procedure and escalation

  • A model or material algorithm change follows controlled development, independent or appropriately separated validation, clinical-safety review, regulatory impact assessment and provider approval before activation.
  • Where the output falls below quality or confidence thresholds, the system displays “unable to compare reliably” and requests a retake or human review rather than forcing a better/worse label.
  • A suspected bias or harmful performance issue triggers containment, subgroup analysis, customer notification and corrective action. Continued use requires documented justification and risk acceptance.
  • Requests to use care data for model improvement are handled as a separate purpose and do not rely on hidden terms or assumed consent.

6. Roles and responsibilities

AI Governance Lead

maintains model inventory, evaluation, change and monitoring controls.

Clinical Safety Officer

assesses clinical hazards and the adequacy of human oversight.

Data Protection Officer

governs training/validation data and transparency.

Engineering/Data Science

maintains reproducibility, provenance, secure pipelines and tests.

Providers/clinicians

use outputs within approved scope, review originals and report errors.

7. Records, confidentiality and retention

Retain model cards, intended-use statements, dataset records, annotation protocols, evaluation reports, subgroup results, approvals, versions, source/derivative audit, overrides, incidents, monitoring and retirement records.

Records created under this policy must be accurate, attributable, access-controlled and linked to the applicable retention schedule. Where a provider is the controller or authoritative record holder, its documented instructions and legal duties apply.

8. Monitoring, assurance and review

Review before every material release and at a risk-based interval in operation. Monitor quality failure, comparison failure, false-positive/negative proxies, overrides, subgroup performance, drift, backlog and safety events.

Material non-compliance is reported through the relevant clinical-safety, patient-safety, data, security, safeguarding, HR, contractual or whistleblowing route. Corrective actions receive an owner, target date and effectiveness check.

9. Training and communication

The policy owner identifies which roles require awareness, operational or specialist training. Training is accessible, version-controlled, role-specific and refreshed after material change or evidence that understanding is inadequate. Providers communicate local procedures and contact routes before users are granted access.

10. Related documents

11. Approval record

RoleNameDecision/date
Policy ownerTo be completedDraft pending approval
Clinical/technical specialistTo be completedDraft pending approval
Board or delegated committeeTo be completedDraft pending approval
Return to policy centre