Safety & governance
Safety is a system requirement
Mental-health technology must be designed for uncertainty, vulnerability and the possibility of harm. BioTekk’s governance approach is intended to combine defined clinical boundaries, human oversight, evidence generation, information governance and continuous safety monitoring.
Crisis and safeguarding boundaries
BioTekk is not an
emergency service
If you or someone else is in immediate danger, contact the emergency services. Urgent mental-health need should be met by people, not by software. The routes below are available in the United Kingdom.
- Emergency
- 999 Immediate danger to life
- Urgent health advice
- NHS 111 Select the mental-health option
- Samaritans
- 116 123 Free, 24 hours, every day
- Text support
- SHOUT to 85258 Free 24/7 text service
In-product behaviour
Stated before use,
and repeated
during it.
BioTekk is not an emergency service. The platform should communicate this limitation clearly before and during use, so that no user forms the impression that submitting a message is equivalent to contacting help.
When an interaction suggests immediate danger or urgent mental-health need, the user should receive direct instructions to contact appropriate emergency or urgent-care services. Organisational deployments may additionally activate locally approved safeguarding and escalation procedures.
Escalation design is a joint decision with the deploying organisation. A notification route that no one is resourced to answer is not a safety control, so escalation capacity and out-of-hours arrangements are assessed before a configuration goes live.
Intended purpose
Documented before
anything is
deployed.
Each BioTekk product configuration should have a documented intended purpose specifying its users, use environment, supported activities, excluded uses and role within the wider care pathway. Clinical and regulatory requirements should be assessed against that intended purpose before deployment.
Clinical safety management
Accountability,
hazards, controls,
evidence.
Clinical safety management should include nominated accountability, hazard identification, risk controls, testing, residual-risk review, incident management and documented safety cases where applicable.
Deployment should also consider local workflows, staffing, escalation capacity and foreseeable misuse. A control that depends on a step no one has time to perform will not hold in live service.
Nominated accountability
A named individual is responsible for clinical safety activity, with the authority to require changes or halt a release.
Hazard identification
Systematic identification of ways the system could contribute to harm, including missed indicators, over-escalation, misinterpretation and misuse.
Risk controls
Design, process and training controls proportionate to each hazard, with an explicit record of what each control depends on.
Testing
Verification that controls behave as specified, including safety-critical paths and behaviour under unusual or distressing input.
Residual-risk review
Documented judgement on the risk that remains after controls, reviewed by people with appropriate clinical expertise.
Incident management
Defined routes for reporting, investigating and learning from incidents and near misses, with feedback into design.
Human-in-the-loop operation
Designed to augment human support, not displace judgement
Where automated analysis influences triage, escalation or prioritisation, qualified or appropriately trained personnel should retain responsibility for review and action within a defined service model.
Continuous monitoring
Governance that
continues after
go-live
Safety assurance is not completed at launch. Model behaviour, service performance and organisational context all change, so monitoring, evidence generation and information governance are treated as continuing obligations.
Performance drift
Monitored against the baseline established at evaluation, with investigation triggered by change rather than by complaint.
Incidents & near misses
Recorded, investigated and reported through agreed routes, including near misses that caused no harm.
Information governance
Lawful basis, data-protection assessment, retention and access reviewed per deployment and re-reviewed on material change.
Evidence generation
Evaluation of defined functions in the populations and settings for which they are intended, reported with their limitations.
BioTekk is in active development. Statements on this page describe the governance approach the product is being built to satisfy. They are not claims of completed regulatory assessment, certification or clinical validation. Documentation relevant to a specific deployment is provided during pilot discussions.
Bring your
governance team.
Clinical safety officers, DPOs and information-governance leads are the right people to be in the room early. Tell us who they are and what they need to see.