In this article, we continue our review of the DCB 0129 and DCB 0160 standards and consider further areas that may warrant attention as part of NHS England's technical consultation, which remains open until 11 September 2026.

In this case, we’re going to tackle a thorny subject which would appear to create much confusion in the industry (at least by our experience of running 25+ courses a year where this topic always comes up). Here we turn to the issue of ‘Initial clinical risk’ and ‘Existing controls’.

NHS England, in their template for a DCB 0129/0160 hazard log, prominently use the terms Initial Clinical Risk and Existing Controls. At Safehand we see a great deal of interpretation with regards how these terms are used. Consequently, the content of the corresponding columns in the hazard log varies enormously between organisations. When we encounter inconsistency of this nature, the obvious place to turn is the standards themselves. So what do we learn?

Existing controls – There is no definition in the standard itself. However, the Implementation Guidance contains the following field description “Identification of existing controls or measures that are currently in place and will remain in place post implementation that provide mitigation against the hazard, i.e. used as part of initial Hazard Risk Assessment”

Initial clinical risk - “The clinical risk derived during clinical risk estimation taking into consideration any retained risk control measures.” Note that ‘retained risk control measures’ is not itself defined.

Let’s take a closer look at ‘existing controls’. The description tells us that the term relates to measures which are ‘currently in place’. Thus, this suggests that any other type of control (presumably additional controls) represent something we may (or may not) introduce in the future. Yet, it is the additional controls which form the basis of our Residual Risk assessment and therefore go-live decision. Thus, the description encourages us to base our decision-making on measures which are not ‘currently in place’. This feels wrong.

Similarly, when we eventually introduce new control measures, as these are now ‘current’ presumably they become existing controls and therefore lower the initial clinical risk. Yet common sense would tell us that it should be the residual risk which is reduced not the initial risk.

Unfortunately, this conundrum haunts the industry. Everyone has a way of ‘making it work’, and many practitioners adopt a strong position that their interpretation is the right one. The point is, that’s not how standards work – they are there to provide clarity and minimise ambiguity rather than introduce it.

At Safehand, we’ve adopted a convention which is commonly seen in other safety critical industries. We use the term ‘existing controls’ to mean those risk mitigation measures which are present in the context of the clinical environment taking into account the product’s intended use. These might include measures such as common practices and procedures, professional training and limitation of risk by nature of the product’s intended purpose. These are soft controls but ultimately set the envelope of initial risk. Then, everything else we put in place, is taken to be an additional control which ultimately contributes to the residual risk rating.

This approach has stood the test of time at Safehand and, if this is what NHS England are trying to achieve, I believe that clarification in this area would be greatly appreciated by the industry.

What are your thoughts?