The short answer
DCB0129 applies to the manufacturer of a health IT system. DCB0160 applies to the NHS or care organisation that deploys and uses it. They are two halves of the same clinical safety picture: one covers the product as built, the other covers the product as used in a real care setting.
Most digital health products that touch NHS care need assurance under both — but the responsibility sits with different people, at different points in the product's life.
Side-by-side comparison
| DCB0129 | DCB0160 | |
|---|---|---|
| Full title | Clinical Risk Management: its Application in the Manufacture of Health IT Systems | Clinical Risk Management: its Application in the Deployment and Use of Health IT Systems |
| Who it applies to | Manufacturers building or changing a health IT system | NHS trusts, primary care networks and other organisations deploying and using a system |
| Named safety role | Clinical Safety Officer (manufacturer) | Clinical Safety Officer (deploying organisation) |
| Focus of risk assessment | Hazards inherent in the system's design and intended use | Hazards arising from local configuration, integration and workflow |
A product doesn't automatically "pass" DCB0160 because it passed DCB0129. Each deploying organisation must still complete its own clinical risk management activity for how that product is configured and used on the ground.
Why both standards exist
Health IT risk isn't fixed at the point of manufacture. The same system can be safe in one NHS trust's workflow and hazardous in another's, depending on integration, local configuration, staff training and how it sits alongside other systems. DCB0129 controls what the manufacturer can reasonably foresee and design against; DCB0160 controls what only the deploying organisation can see and manage — its own people, processes and environment.
What this means in practice
- If you're a manufacturer: you need a named Clinical Safety Officer, a clinical risk management process aligned to DCB0129, and safety artifacts kept current as the product changes.
- If you're an NHS organisation procuring or deploying a system: you need your own DCB0160 process — don't assume the supplier's DCB0129 assurance covers your deployment risk.
- If you're building AI-enabled or SaMD products: both standards still apply where the product is used in NHS care, alongside any separate medical device risk management obligations under ISO 14971.
Getting this right
The most common failure mode we see isn't ignorance of the standards — it's treating them as a paperwork exercise instead of a live risk management discipline. A Clinical Safety Case Report that isn't updated when the product changes, or a deployment risk assessment copied from another site without re-assessment, creates exactly the gap these standards exist to close.