It can be easy to assume that a long-standing clinical system is safe simply because it has been in use for years. It’s comforting that that ‘old-faithful’ system is still around and is considered by many to be “proven in use”. But time alone is not necessarily evidence of safe operation. Proven in use only applies when safety has been monitored and documented. Without that, age does not reduce risk. As systems age, it may well increase.

Suppose aviation worked the same way. The aircraft manufacturer certifies the aeroplane when it is built. At that point, the manufacturer has demonstrated that the aircraft, as designed, meets its safety requirements. This is comparable to a supplier’s DCB 0129 responsibilities.

Once the aircraft enters service, responsibility shifts to the airline. The operator must carry out routine checks, monitor defects, review issues raised by air crew and engineers, and continually demonstrate that the aircraft remains safe to fly in day-to-day operations. This is not a one-off exercise. It’s work that continues as the aircraft is operated and changed.

Now imagine that same aircraft ten years into service having had none of those operator checks. No inspections. No defect logging. No follow-up on issues raised during flights. No testing after updates. No oversight of the workarounds crews have adopted. The aircraft flies more routes, for longer durations, with increasing pressure and no operational safety review. By year fifteen, would you board that aircraft?

Probably not. And the reason would not be that the manufacturer failed. It is that the operator had not carried out their side of the safety lifecycle.

The same principle applies in healthcare. Safety is not something that can be established once and then assumed forever. It needs to track systems as they are used, adapted, and relied upon in real clinical settings.

Before going further, it is worth acknowledging that a clinical system may or may not have had a formal DCB 0129 assessment when it was first developed or procured. That’s a separate discussion, and one for another blog post. What matters here is the part of the safety lifecycle that sits with us today.

For many trusts, that reality applies to systems that were deployed before DCB 0160 became part of normal practice. In some cases, this meant there was no formal baseline DCB 0160 assessment at the point of deployment. Those systems have then continued to grow, adapt and expand without a consistent cycle of DCB 0160 activities to keep pace with change. The key issue is not what was or was not required at the time, but the compounding risk created when a system starts without a baseline and continues to evolve without structured safety oversight. That’s where the real legacy risk sits.

As a result, when those systems move into new areas, gain additional functionality, undergo configuration changes, receive supplier updates, or accumulate informal workarounds, the safety gap does not remain historical. It becomes active, it’s today’s problem - growing incrementally with every unassessed change.

In practice, the absence of ongoing DCB 0160 activity rarely shows up as one obvious failure. It usually appears as a collection of small, disconnected gaps that build over time.

  • Configuration changes may be made locally without always being fully recorded, tested, or reviewed through a formal change process.
  • UAT may take place, but not always with full coverage of clinical safety controls.
  • Issues may be raised in live systems but not routinely reviewed or assessed by a CSO once the system is established.
  • CSO involvement may reduce significantly after go-live, particularly for incremental changes or defect management.
  • New functionality may be introduced without structured, safety-focussed training.

A system that has changed significantly but has no ongoing safety case or active assurance is not a stable legacy asset. It is an aircraft that has been flying for years with unlogged faults and an absence of inspections.

The real legacy risk is not the age of the system, but the absence of safety work around the changes it has accumulated over time.

So, what do you think, does the risk really reduce just because a system has been live for ten years, or does it quietly and covertly increase every time something changes without assurance?

Michelle Emmerson, CSO and Team Lead, Safehand Consulting.