DRAFT FOR REVIEW BY APPOINTED CLINICAL SAFETY OFFICER — MUST BE REVIEWED, AMENDED AND SIGNED BY A GMC/NMC/HCPC-REGISTERED CLINICIAN WITH FORMAL DCB0129 CLINICAL SAFETY OFFICER TRAINING BEFORE USE.

CSO04 — Clinical Safety Case Report (CSCR): Atlas for Trusts

Document reference: BRITI-CSCR-ATLAS-001 Version: 0.9 (Draft for CSO review) Manufacturer: BritiAI Limited Subcontractor (in-scope): Beever AI (Beever Atlas neural memory) Applicable standard: DCB0129:2018 Status: Draft pending CSO sign-off


1. Executive Summary

Atlas for Trusts is a trust-wide retrieval and reasoning layer over institutional knowledge — local policies, Standard Operating Procedures (SOPs), clinical guidelines (national and locally adapted), Morbidity and Mortality (M&M) notes, induction materials and similar documents. It is a read-only assistant over institutional content. It is not a clinical decision support system, not a guideline authoring tool, and not a patient-data analytics platform. Its outputs are presented with explicit provenance (citations back to the source document, version and page or section anchor) and are intended to assist staff in locating and understanding trust knowledge — never to substitute for clinician judgement.

This CSCR documents intended use, environment, claims, hazards (CSO07 entries ATL-01 to ATL-10), and the basis on which release is proposed subject to CSO sign-off and trust DCB0160 assurance.


2. Solution Description

  • Ingestion pipeline. Trust-curated corpora are ingested with metadata including document owner, version, effective date, review date and supersession links.
  • Beever Atlas neural memory. Provides embeddings and retrieval across the corpus, with explicit document-version awareness.
  • Reasoning layer. A clinical LLM hosted within the trust boundary composes responses grounded in retrieved passages. Every assertion in a response is anchored to a citation; ungrounded statements are suppressed.
  • Provenance UI. Surfaces the source document, version, effective date, and explicit warnings where a candidate source has been superseded.
  • Governance dashboard. Trust knowledge owners can review retrieval analytics, flag outdated content and trigger re-indexing on document updates.

There is no write-back to clinical systems. No patient identifiable data is processed in the standard configuration.


3. Intended Use

Atlas for Trusts is intended to help staff find and understand institutional knowledge efficiently. Example queries include “What is our trust’s policy on extravasation management?” or “Show me the most recent local guideline for acute kidney injury escalation”. It is intended to be used alongside the original documents, not to replace consulting them where the user requires definitive guidance.

It is not intended to:

  • Provide patient-specific clinical decision support.
  • Make or recommend diagnoses or treatments for individual patients.
  • Replace consultation of original guideline or policy documents where this is mandated.
  • Operate over patient identifiable data in the standard configuration.

4. Intended Users

All trust staff authorised by the deploying organisation, including clinical and non-clinical staff. Role-aware access controls are configurable to restrict sensitive content (e.g. M&M notes) to appropriate audiences.


5. Environment of Use

Trust-managed devices accessing the Atlas interface via the trust network, or via approved managed mobile devices where the trust has authorised this.


6. Clinical Claims

BritiAI claims that Atlas for Trusts:

  • Retrieves the most relevant passages from the configured institutional corpus for a given query, with explicit provenance.
  • Composes responses grounded in retrieved passages with citations.
  • Surfaces explicit supersession warnings where a candidate source has been superseded by a more recent version.

Explicit non-claims

Atlas for Trusts does not claim to:

  • Be a medical device.
  • Provide patient-specific clinical decision support.
  • Guarantee retrieval of every relevant passage.
  • Replace the user’s responsibility to consult the source document for definitive guidance.
  • Provide independent clinical interpretation of retrieved content.

7. Risk Envelope

Principal hazard categories (CSO07, ATL-01 to ATL-10):

  1. Stale or superseded guidance retrieval — surfaced content reflects an out-of-date policy or guideline.
  2. Incorrect attribution — a statement is attributed to a source that does not contain it.
  3. Misuse for direct clinical decision-making outside the scoped intended use.
  4. Partial retrieval — a clinically critical caveat in a source document is not surfaced.
  5. Role-access leakage — content retrieved by a user not authorised for that content class.
  6. Misleading composition — multiple sources combined in a way that distorts meaning.
  7. Loss of version awareness — retrieved content lacks the effective-date context needed to interpret it.
  8. Confidence overstatement — a response presented in a tone of certainty disproportionate to evidence.
  9. Prompt injection via content embedded in ingested documents.
  10. Drift in retrieval or composition behaviour following model update.

8. Risk Control Strategy

  • Elimination by design. Read-only over institutional knowledge. No patient identifiable data in standard configuration. No write-back to clinical systems.
  • Reduction by design. Mandatory citation for every assertion. Active supersession check at retrieval time using ingestion metadata. Role-based access controls enforced at retrieval, not composition.
  • Protective measures. Visual badges for “current”, “review overdue”, “superseded”. Standard banner: “Atlas helps you find guidance. For definitive direction, consult the source document.” UI nudges discouraging patient-specific decision queries with redirect to appropriate tools.
  • Information for safety. Mandatory user induction; trust knowledge-owner training; release notes.

9. Residual Risks Summary

Subject to CSO judgement:

  • Stale guidance retrieval is reduced by metadata-driven supersession but cannot be wholly eliminated; residual risk amber.
  • Misuse for direct clinical decision-making is reduced by UI nudges and training; residual risk amber and dependent on trust SOPs.
  • Prompt injection is mitigated by content sanitisation and provenance-based composition; residual risk amber.

10. Assumptions and Dependencies

  • Trust knowledge owners maintain accurate document metadata including supersession links.
  • Trust role-based access definitions are accurate and maintained.
  • Deploying trust CSO performs DCB0160 assessment including consideration of how Atlas interacts with existing decision-support tools and care pathways.

11. Clinical Safety Verification

  • Retrieval evaluation against a curated query set across multiple specialties.
  • Adversarial probing for fabricated citations and ungrounded assertions.
  • Supersession detection evaluation using a corpus with known versioning relationships.
  • Penetration testing of ingestion and retrieval interfaces, including prompt-injection probes.

12. Post-Deployment Monitoring

  • Citation-grounding rate (proportion of responses with valid citations).
  • Supersession warning rate and user response.
  • User query patterns indicating off-label use (e.g. patient-specific decision queries).
  • Trust knowledge-owner feedback on retrieval quality.

A safety review per deploying trust is conducted at three months post go-live and annually thereafter.


13. Change Control

Material changes triggering re-assessment include: change to retrieval or composition model; change to ingestion metadata schema; new content class introduced to scope; change to role-based access architecture.


14. Statement of Conformance

Subject to CSO review and sign-off, BritiAI confirms that the clinical risk management activities undertaken for Atlas for Trusts have been performed in accordance with DCB0129:2018.


Linked artefacts: CSO01, CSO07 (ATL-01 to ATL-10), CSO08, BRITI-CRMP-ATLAS-001, BRITI-IFU-ATLAS-001.

CSO name: _________________________ Registration body and number: _________________________ Signature: _________________________ Date: _________________________