Healing Process policy suite
Research, Pilot and Service Evaluation Policy
1. Purpose
To ensure that pilots, audits, service evaluations, research and clinical investigations are correctly classified, approved, conducted and reported, with participant safety, privacy and scientific integrity protected.
2. Scope and status
This policy applies to prototype testing, usability studies, shadow evaluations, live pilots, service evaluation, research, algorithm development, validation and medical-device clinical investigations involving people or their data.
Deployment-specific policy framework
3. Policy principles
- Calling an activity a pilot does not determine its legal or ethical status.
- The purpose, protocol, data use, product version and role of outputs in care must be fixed before participation begins.
- Care must not be made conditional on unrelated research participation unless lawfully and ethically justified.
- Negative, neutral and unintended findings are part of the evidence and will not be suppressed.
4. Mandatory requirements
- Complete a classification assessment distinguishing usability, audit, service evaluation, research and regulatory clinical investigation and obtain the required approvals.
- Use a written protocol covering rationale, population, inclusion/exclusion, intervention, comparator where appropriate, endpoints, sample, analysis, safety, data, version control, stopping rules and dissemination.
- Obtain ethics, HRA, MHRA, provider, data-protection, clinical-safety and other approvals as applicable before starting.
- Provide accessible participant information and consent or document the alternative lawful route; preserve the distinction between care and research choices.
- Register trials or studies where required and manage protocol amendments under approval and version control.
- Use qualified investigators, training, monitoring, adverse-event reporting and independent oversight proportionate to risk.
- Predefine subgroup, bias, missing-data and performance analyses for image or AI evaluation and protect against data leakage.
- Secure research data, minimise identifiers, control access, define retention and prohibit unauthorised reuse.
- Publish or share results with limitations, conflicts and protocol deviations; update product claims only through the approved evidence process.
5. Procedure and escalation
- An evaluation proposal enters a multidisciplinary review before recruitment, live data access or product activation.
- The approved product/software/model version is locked or every change is documented, assessed and included in analysis.
- Safety signals are reported immediately; stopping rules are applied by authorised oversight without commercial interference.
- At closure, data and samples are reconciled, reports completed, participants/providers informed where appropriate and actions entered into product governance.
6. Roles and responsibilities
Research Lead/Sponsor
owns classification, protocol, approvals and conduct.
Chief Investigator/local investigators
protect participants and comply with the plan.
Clinical Safety/Regulatory/DPO
provide specialist approval and monitoring.
Product team
maintains version and technical evidence.
Providers
approve local capacity, pathway, care and record integration.
7. Records, confidentiality and retention
Keep classification, protocol, approvals, consent/information versions, delegation, training, data plan, monitoring, deviations, incidents, analysis, reports, publications and archive index.
Records created under this policy must be accurate, attributable, access-controlled and linked to the applicable retention schedule. Where a provider is the controller or authoritative record holder, its documented instructions and legal duties apply.
8. Monitoring, assurance and review
Review each study at defined milestones and this policy annually. Monitor recruitment, safety, deviations, missing data, subgroup representation, action closure and publication completeness.
Material non-compliance is reported through the relevant clinical-safety, patient-safety, data, security, safeguarding, HR, contractual or whistleblowing route. Corrective actions receive an owner, target date and effectiveness check.
9. Training and communication
The policy owner identifies which roles require awareness, operational or specialist training. Training is accessible, version-controlled, role-specific and refreshed after material change or evidence that understanding is inadequate. Providers communicate local procedures and contact routes before users are granted access.
10. Related documents
11. Approval record
| Role | Name | Decision/date |
|---|---|---|
| Policy owner | To be completed | Draft pending approval |
| Clinical/technical specialist | To be completed | Draft pending approval |
| Board or delegated committee | To be completed | Draft pending approval |
