NEUVIOR governance standard · 03
NEUVIOR Third Party Data Responsibility Standard
A NEUVIOR authored public governance principle. It is not a national, regulatory or certification standard. Use it to keep data responsibility visible when hosting, software or services are entrusted to another organisation.
The principle
Outsource infrastructure. Never make responsibility disappear.
NEUVIOR treats external hosting, software and service providers as part of the operating system, not as responsibilities outside it.
The purpose of processing, legal role of each party, applicable lawful authority, binding instructions and contractual responsibilities should be established before sensitive information is entrusted to a supplier. Applicable law, regulation, professional duties, mandatory standards and binding contracts prevail.
Purpose and legal role assessment
Determine whether each party acts as a controller, joint controller, processor or in another role for the specific processing operation, and record the duties that follow.
GovernanceSupplier responsibility
A hosting, software or service provider may occupy different legal roles in different contexts. Define its instructions, safeguards, evidence and incident responsibilities without assuming one category.
DeliverySubprocessor and wider supply chain
Where subprocessors or subcontractors are used, keep them visible in the contractual, access, location, assurance and exit chain.
Extended supply chainBefore information is entrusted
The accountable organisations should establish:
The answers should be defined, approved and retained in the relevant legal, governance, security and operational records.
- 01
Information and location
what categories of information are involved and where they are stored;
- 02
Access chain
which individuals, systems and subcontractors may access them;
- 03
Monitored activity
how access and privileged activity are monitored;
- 04
Detection and escalation
who detects, investigates and escalates abnormal activity;
- 05
Evidence and affected parties
how evidence is preserved and affected parties are identified;
- 06
Notification responsibility
who owns regulatory, contractual and individual notification responsibilities, subject to applicable law and each party’s legal role;
- 07
Continuity and recovery
how continuity, recovery and essential information availability will operate; and
- 08
End of relationship
how information can be securely returned, transferred or deleted when the relationship ends.
Retained responsibility
Outsourcing infrastructure does not outsource responsibility.
Controllers, processors and other accountable parties retain the duties attached to their roles. A contract should allocate work and information flows clearly; it cannot erase a statutory duty.
This principle does not determine the legal role or lawful basis for a particular processing operation and is not legal, data protection or security advice.
The ICO material linked below provides wider accountability context. Accessed 2 August 2026, the ICO marks this material as under review following the Data (Use and Access) Act. Readers should check current official guidance and context specific advice. The link does not endorse NEUVIOR, certify any supplier or make this a regulatory standard.
Before the relationship
Map roles, information flows, locations, subprocessors, safeguards, evidence and approval conditions.
During the relationship
Monitor access, material changes, abnormal activity, incidents, continuity and the evidence needed for accountable decisions.
At exit
Evidence return, transfer, permitted retention and secure deletion across active systems, backups and relevant derived copies.
Publication and evidence boundary
This principle is not a security certificate or operating claim.
This standard describes a governance principle. It does not indicate cybersecurity certification, regulatory approval, NHS deployment, customer adoption or independently demonstrated security performance.
Publication is not evidence that NEUVIOR holds health data or has implemented, audited or independently validated this principle in an operating service.
Publisher
NEUVIOR
Publication ownerRevision history
Version 1.0 · Initial publication · 2 August 2026
Current public versionReview trigger
Material change in applicable law, regulator guidance, supplier context, operating model or NEUVIOR’s public position.
Reassess and republish- Podcast appearance. AI Ethics Now / University of Warwick IATL. AI and Accountability: When Does a Suggestion Become a Decision?. 23 August 2026.
- Contributed opinion. TechRadar Pro. Five questions to test whether an AI stack is truly under your control. 11 August 2026.
- Founder commentary. ET Pharma. India’s pharma quality reset will be won after the inspector leaves. 4 August 2026.
- NEUVIOR analysis. NEUVIOR Insights. From pilot theatre to financial grip: how NHS CFOs should evaluate AI in medicines optimisation. 18 March 2026.
- NEUVIOR analysis. NEUVIOR Insights. NHS digital programmes do not fail on dashboards. They fail on deployment. 20 March 2026.
- Expert commentary. Manufacturing Chemist. NICE approval is not enough: why the UK's next medicines challenge is operational delivery. 4 June 2026.
- Founder commentary. PharmaTimes. How we roll. 10 June 2026.
- Editorial roundup. Digital Health. Digital Health Coffee Time Briefing. 26 May 2026.
Classified public record
ANALYSIS + EVIDENCE BOUNDARY
Read the argument. Verify the product separately.
Published analysis can explain why governance matters. It cannot evidence security, clinical authority, certification, product readiness or local approval. Use the dated NEUVIOR records for that.
AI and Accountability: When Does a Suggestion Become a Decision?
Varun Sharma joins AI Ethics Now to examine false confidence, human responsibility and the point where AI assisted suggestions become accountable decisions.
Hear where an AI suggestion becomes a decisionFive questions to test whether an AI stack is truly under your control
In TechRadar Pro, Varun Sharma sets out five tests for enterprise AI control across provenance, infrastructure, legal authority and safe exit.
Test provenance, control and safe exitFrom pilot theatre to financial grip: how NHS CFOs should evaluate AI in medicines optimisation
NHS finance leaders do not need another AI pitch. They need a disciplined way to decide whether a technology can release value within the financial rules they are already being held to.
See how a finance leader should test an AI claim
NEUVIOR Insights and After Publication reflections are company or founder analysis. Publisher records evidence publication, not endorsement, adoption, product readiness, savings or clinical outcomes.
The test
Can the organisation still see every duty across the supplier chain?
If roles, access, incident decisions, notifications, continuity and exit cannot be traced, the third party accountability record is incomplete.
