RT01 — Independent Red-Team Findings Report
BritiAI submission — NHS SBS Healthcare AI Solutions Open Framework (SBS10523)
INDEPENDENT RED-TEAM REVIEW — FINDINGS REPORT. ACTION REQUIRED BY BID DIRECTOR AND CTO BEFORE V2 REWRITE CYCLE.
Review date: 17 June 2026
Reviewer posture: Sceptical NHS Foundation Trust evaluator / CCIO / NHS SBS quality moderator
Documents reviewed: 01_Strategic_Plan.md, 03_Proposal_Narrative_Draft.md, 09_BritiAI_ITT_Mapping.md, NHS Procurement Bid Tracker.md
Submission deadline: 12:00 noon BST, Tue 21 Jul 2026
1. Executive Verdict
Would this win a place on the framework today? No — not in its current state, and the risk of disqualification on Lot 5 and Lot 6 is material, not theoretical.
The draft has a real strategic spine — sovereign-by-design, on-prem ambient capture, embedded operating partnership, and a genuine research lab (Beever) most competitors cannot match. The problem is that the prose currently asserts this story rather than evidences it. There are at least eleven specific claims in the narrative that an NHS SBS moderator can mark down on the spot for being unsubstantiated, in-flight, or wrong-jurisdiction. The Clinical Safety Officer is unsigned (gating for Lots 5 and 6 — assume pass/fail), ISO 27001 and Cyber Essentials Plus are unprovable on submission day, there are zero NHS reference letters in the pack, and Votee’s HK headquarters is acknowledged but not neutralised in the prose. The Social Value section is template-level and will lose ~6–7 of the available 10 marks on every lot. Confidence in current scoring: Lot 6 ~5.5/10, Lot 7 ~5.5/10, Lot 5 ~4/10. With the recommended fixes inside the next ten working days, those move to 7.5 / 7 / 6 respectively — enough to win Lot 6 + 7 places (and therefore automatic Lot 8). Lot 5 is the lot we are most likely to lose, and the bid does not currently acknowledge that risk.
2. Lot-by-lot scoring estimate
Lot 6 — Operational Efficiency (Quality 90% / SV 10%)
Estimated score today: 5.5 / 10
The architecture of the response is right — four named solutions, committed KPIs in a table, on-prem differentiator — but every single piece of evidence under §6.3 is either a placeholder ([named enterprise references — to populate from Votee], [comparator], [reference]) or a non-NHS analogue (insurance claims, legal document review). An NHS moderator scoring this section asks one question: “have they done this in a UK NHS environment?” The honest answer reads as “no, but we have done adjacent things elsewhere.” That is a 6 at best. The KPI commitments (≥60 min/clinician/day, ≥40% time-to-find reduction) are bold — they will score well if defensible and badly if challenged with “evidenced where?“. They are currently not defensible. Take 1.5 marks off for unevidenced KPIs, 1 mark off for the placeholder evidence, 1 mark off for thin Clinical Safety Case (“template + named CSO appointed for the framework” when the CSO is not yet appointed), 1 mark off for the Social Value Plan dragging the composite down.
Lot 7 — Advisory & Specialised Support (Quality 70% / Commercial 20% / SV 10%)
Estimated score today: 5.5 / 10
The Fractional CAIO and embedded operating partner story is genuinely differentiated — this is the strongest section of the draft on win-theme through-line. But §7.4 Evidence is one paragraph and reads as a placeholder (“Provide CVs of the named delivery cadre”). Named principals are not in the draft. The rate card is reasonable but the commercial framing is unsupported — there is no value-per-pound narrative against the 20% commercial weighting, no comparison anchor, no outcome-share worked example. NHS evaluators on Lot 7 are buying people — they want to see the CVs, the GMC/HCPC/CIPD registrations where relevant, prior NHS exposure, redacted client outcomes. None of this is in the pack. There is also no acknowledgement that Lot 7 is the lot most exposed to Big-4 incumbents (Deloitte, EY, PA, BCG-X). Without that competitive framing, the bid sounds generic.
Lot 5 — Research, Innovation and Development (criteria TBC, treat as 90/10 or similar)
Estimated score today: 4 / 10 — and at material disqualification risk
This is the bid’s weakest lot and the prose hides it. §5.3 cites two ACL 2025 papers from Beever and the Atlas open-source release. ACL is a strong general NLP venue but it is not a healthcare research credential. Neither TheoremExplainAgent nor HKCanto-Eval is healthcare or NHS-relevant — they are general-purpose NLP/multilingual benchmarks. An NHS SBS moderator evaluating Lot 5 expects: prior NIHR or HRA-approved studies, federated learning deployments in NHS or equivalent settings, synthetic data work referencing NHS datasets, peer-reviewed clinical AI publications. We have none of those. “Cross-Trust Federated Research Substrate” is a concept, not a product. “Trial Concierge” is undescribed beyond two sentences. The strategic plan §10 already lists Lot 5 as having a Wed 24 Jun go/no-go gate — that gate should bite. The current draft scores a 4 because the research credentials are real but adjacent, not NHS-grade.
Composite implications
Lot 6 + Lot 7 wins are achievable with focused remediation. Lot 5 should either be dropped (preserving Lot 8 automatic enrolment via 6+7) or massively rewritten to lean on the federated/sovereign-training story rather than the ACL papers. The current draft tries to coast on academic credibility that does not transfer.
3. CRITICAL findings (must fix before submission)
| # | Finding | Evidence in draft | Fix | Owner | Target |
|---|---|---|---|---|---|
| C1 | CSO unsigned — gating for Lot 5 and Lot 6. Tracker item 19 is ⛔. §3 of the proposal claims “a named Clinical Safety Officer is appointed for this framework” (present tense) — that is a misrepresentation as written. | 03 §Clinical Safety: "A named Clinical Safety Officer is appointed for this framework." Tracker: ⛔ Fri 20 Jun EOD. | Contract signed by Fri 20 Jun. Until signed, rewrite the prose to “Clinical Safety Officer engaged under contract dated [X] — registration body [Y], CRN number [Z], training certificate attached at Annex”. No present-tense claim until ink dries. | CEO + COO | Fri 20 Jun |
| C2 | ISO 27001 and Cyber Essentials Plus declared as “in flight” — risk now substantially DE-RISKED by official Q&A. The NHS SBS clarifications confirm: ISO accreditations Pass if held OR formally commenced (evidence at framework award); CE+ may be satisfied by equivalent controls, with ISO/IEC 27001 expressly accepted as the equivalent route; and information-security status is verified at the certification & accreditation due-diligence stage (5 Apr – 19 May 2027), not at submission. A clean “in-flight with roadmap” declaration therefore Passes. | 03 §IG & Cyber | (a) Update stale dates. (b) Add dated, named-assessor evidence: assessor company, booking confirmation, scope statement, target certificate date. (c) Add binding commitments to provide certificates at/ahead of due-diligence. (d) Cite the Q&A explicitly so the moderator cannot mis-score in-flight status as a fail. | CTO | Mon 30 Jun for evidence; CE+ certificate before 21 Jul if achievable |
| C3 | Zero NHS reference letters / case studies. §6.3 evidence is “insurance claims and legal document review” — that is not healthcare and will be scored as such. §7.4 says “Reference letters from existing BritiAI clients (non-NHS)“. | 03 §6.3, §7.4 | Land one warm NHS reference letter by Fri 27 Jun (Strategic Plan §11 already targets this). If genuinely impossible, replace the non-NHS prose with: “BritiAI has no NHS production references at framework submission — by design, as a new entrant SME. We have therefore structured our offer around productised SKUs, transparent KPIs and outcome-share pricing to de-risk the buyer.” That at least owns the gap rather than papering over it. | COO + Sales | Fri 27 Jun |
| C4 | Votee HK HQ — sovereignty risk not neutralised in the prose. §2 introduces Votee with “Votee’s Chief Scientist is the former Dean of the Deloitte AI Institute, and the company holds the Baidu Innovation Award 2026”. Naming a Baidu award in an NHS sovereignty submission is a strategic error — it actively imports the China-adjacency risk the topology diagram is supposed to neutralise. | 03 §2 About our partners | (a) Remove the Baidu reference entirely from the submitted prose. (b) Re-anchor Votee’s introduction to its UK operating entity (or a stated UK subsidiary), UK data residency, and UK-only sub-processors. (c) Cite the HKMA pilot only as evidence of regulated-environment competence, not as the headline. (d) Add an explicit “Group structure and data sovereignty” paragraph: “All NHS data processing is undertaken within the UK by [BritiAI Ltd] as data controller-side prime. Votee Limited’s role under the Teaming Agreement is restricted to IP licensing and UK-resident technical support; no NHS data crosses the UK boundary.” | COO + Legal | Wed 24 Jun |
| C5 | Lot 5 evidence base does not survive contact with an NHS Lot 5 moderator. ACL 2025 papers cited are general NLP, not healthcare AI. There is no NIHR, no HRA, no published NHS dataset work, no real federated learning deployment. | 03 §5.3 | Recommended: drop Lot 5 at the Wed 24 Jun gate. Lot 6 + Lot 7 wins still trigger automatic Lot 8 enrolment. Submitting a weak Lot 5 risks pulling the moderator’s overall confidence in the bidder down across all lots (NHS SBS evaluation panels often share moderators). If keeping Lot 5: rewrite around MAGIC-NHS as a sovereign training pipeline with a named NHS academic partner letter of intent (UHB PIONEER, GOSH DRIVE, or Imperial iCARE — Strategic Plan §11) — that is the only credible Lot 5 path inside 20 days. | CEO + Beever | Wed 24 Jun gate decision |
| C6 | Solution architecture diagrams not produced (tracker item 13 🔴). Without these, every named solution in the prose is unevidenced. NHS SBS moderators are technical — they expect a diagram per solution showing data flows, hosting boundaries, sub-processors, and clinical-safety touchpoints. | Tracker item 13, due Wed 24 Jun | Produce 1-page architecture per: Scribe-On-Site, WardFlow Copilot, Atlas for Trusts, FOI Triage, MAGIC-NHS, Trial Concierge. Each must show: (i) UK hosting boundary, (ii) where the trust’s data sits, (iii) sub-processor list, (iv) DCB0129 hazard interface points. | CTO + Votee | Wed 24 Jun |
| C7 | Teaming Agreement unsigned (tracker item 33 🔴). Until signed, naming Votee and Beever as bid partners is a contractual hazard and NHS SBS may treat the bid as incomplete. | Tracker item 33 | Heads of Terms in place this week, full TA signed Fri 26 Jun per tracker. No slippage permitted — this is the single contractual gate for naming subs. | CEO + Legal | Fri 26 Jun |
4. HIGH findings (should fix — 1–2 marks per section)
| # | Finding | Fix |
|---|---|---|
| H1 | KPI commitments are bold but undefended. “≥60 min/clinician/day reclaimed” is a number routinely contested in ambient documentation literature (Nuance/DAX claims 7 min/encounter; Abridge claims similar). 60 min/day requires ~8–10 encounters/day × meaningful per-encounter saving. Cite the source or the modelled assumption inline. | Add a single sentence under each KPI: “Derived from [source / Votee internal benchmark / modelled from N encounters at X minutes saved per encounter]“. Failing that, downgrade to a range (e.g., 30–60 min/day) — far more defensible. |
| H2 | ”On-prem” is asserted across the entire stack — partially true. V-Note has on-prem; Beever Atlas is open-source so deployable on-prem; MAGIC training pipeline on-prem is plausible. But BritiAI Copilot and BritiAI ASR on-prem capability are not evidenced in source documents. The bid currently implies the whole stack runs inside the trust boundary. | Audit each named solution and state per-component hosting: “V-Note: on-prem. Atlas: on-prem. BritiAI Copilot: UK sovereign cloud (Crown Hosting / UKCloud / equivalent) with on-prem option roadmap by [date].” Honesty here is a scoring positive, not a negative. |
| H3 | §3 Delivery model (Diagnose → Design → Deploy → Demonstrate) is generic consulting boilerplate. Every Big-4 bid uses this exact pattern. It does not differentiate. | Replace with NHS-specific milestones: e.g., “Week 1: DTAC v2 gap. Week 2: DPIA + DCB0160 onboarding with trust CSO. Week 4: DCB0129 Clinical Safety Case v1. Week 6: shadow deployment. Week 8: go-live decision gate with trust CCIO.” That is differentiated; “Diagnose → Design → Deploy → Demonstrate” is not. |
| H4 | Fractional CAIO claim has no named individual or CV. Lot 7 hangs on this. | Name the Fractional CAIO with a one-paragraph bio and prior healthcare exposure. If no individual is available, downgrade the claim to “available on call-off”. |
| H5 | ”Class IIa medical device” framing in Appendix A is technically loose. UKCA marking applies to all medical device classes (I, IIa, IIb, III). The phrase “deliberately scoped outside Class IIa medical device territory” suggests the team is comfortable up to Class I — which itself requires UKCA registration. | Rewrite as: “Our Lot 5, 6 and 7 solutions are deliberately scoped as non-medical-device software (general administrative / operational support tooling per MHRA guidance on Software and AI as a Medical Device). Should any future call-off require a medical-device claim, we will follow MHRA SaMD route in full.” |
| H6 | NCIS levy and pricing — the rate card does not show NCIS bake-in. Lot 7 has 20% commercial weight; if competitors price net-of-NCIS and we price gross-of-NCIS we lose marks for being more expensive at headline rate. | Pricing table footnote: “Rates inclusive of 0.90% NCIS levy and standard framework discounting.” |
| H7 | Outcome-share pricing is mentioned but not specified. §6.5 says “Outcome-linked pricing variant available where the trust agrees a baseline measurement.” That is a teaser, not a proposal. | One worked example: “On Scribe-On-Site, up to 20% of per-user fees held in escrow against achievement of the ≥45-min/clinician/day floor measured over 90 days.” Specificity scores; vagueness does not. |
| H8 | No competitive framing. The bid never names — even abstractly — the incumbents it must beat (Big-4 advisories on Lot 7; US ambient incumbents on Lot 6; NHS-AI specialists like Sensyne / Lantum / Cera adjacents). Evaluators score relative to a competitive set; bids that ignore that set look naïve. | Add a “Why us, specifically” paragraph per lot: one sentence per archetype competitor and why our position differs. Example: “Where US ambient incumbents route audio to overseas inference, we run on the trust’s infrastructure.” |
| H9 | Lot 8 narrative left in the document. §Lot 8 is correctly flagged as automatic, but the prose (“This narrative is preserved here for use in post-award trust call-off pitches”) might survive into a submitted PDF by accident. | Move §Lot 8 to a separate post-award sales doc. Delete from the submission pack. |
| H10 | The 8-week Scribe-On-Site deployment claim contradicts the 90-day “time-to-value” win theme. Win theme: “≤90 days from call-off to first measurable KPI.” Solution claim: 8-week deployment + 90-day measurement window = 14 weeks to first KPI. | Pick one and be consistent. Either tighten the deployment to 6 weeks (deployment + 30-day KPI = 90-day TTV) or widen the win theme. |
5. MEDIUM findings (polish)
- M1. §0 Exec summary opens with “BritiAI is a UK-incorporated artificial intelligence company that exists to bring frontier AI into regulated environments responsibly” — the word “frontier” is a flag word in NHS procurement (associates with experimental/unsafe). Replace with “production-grade” or “operationally proven”.
- M2. “Operating partner” is used 4 times in §0 and §7.1 — risks sounding like a consultancy euphemism. Use “embedded delivery team” once and “operating partner” once.
- M3. §6.2(iv) FOI Triage KPI “zero increase in upheld complaints” is unmeasurable in 60 days at most trusts (statutory complaint cycles are 6 months). Reframe as “no statistically significant increase”.
- M4. §Lot 7 rate card has both £950 (Senior Consultant) and a tagline elsewhere of “Senior £950” — keep one grade per row, currently inconsistent with
01_Strategic_Plan.md§8 which uses different grade names. - M5. Appendix A Q&A uses first-person voice inconsistently (“Our current Lot 5, 6, 7 and 8 solutions”). Standardise.
- M6. No glossary. DCB0129, DCB0160, DTAC, DSPT, DPIA, NCIS, PPN, TTOC, M&M, EHR, CRF, EDC — all appear undefined. NHS moderators know these but their evaluation peers (commercial moderators) may not.
- M7. Acronym “MAGIC” is not expanded on first use anywhere in the prose.
- M8. The “buy-once, deploy-many” win theme is asserted but not visible in the pricing schedule. Add a framework-rate concept: trusts that adopt within X months get the framework call-off rate locked.
6. Overclaim audit
Every claim below cannot currently be evidenced and must be either fixed, softened, or evidenced before submission.
| # | Claim (quoted from draft) | Issue | Recommended action |
|---|---|---|---|
| O1 | ”a named Clinical Safety Officer is appointed for this framework” (§Clinical Safety) | False at time of writing — CSO is ⛔ unsigned per tracker | Rewrite to future-conditional until signed; do not submit with the present tense |
| O2 | ”Votee’s MAGIC LLM training platform and V-Note ambient capture tools are deployed across enterprise, government and financial services” (§0) | Plural “deployments” implies multiple references. Source documents cite HKMA FSS 3.1 (one pilot) — not plural government and financial services deployments | Reduce to verifiable list: “Votee’s tools have been deployed in regulated financial services (HKMA FSS 3.1 pilot) and enterprise settings”. Drop “government” unless we can name one |
| O3 | ”Beever’s published work … gives this submission a rare property in the AI vendor market: every model behaviour we claim is benchmarked, and every benchmark is published” (§2) | The ACL 2025 papers are not benchmarks of the products we are selling. TheoremExplainAgent ≠ Scribe-On-Site. HKCanto-Eval ≠ WardFlow Copilot. The benchmarks are on adjacent academic work, not our NHS stack | Rewrite as “Our partners’ research lab publishes peer-reviewed work in top NLP venues, demonstrating the technical depth behind our productised stack” — true and defensible. The “every claim benchmarked” line is the most overclaimed sentence in the bid |
| O4 | ”Target KPI: ≥60 minutes per clinician per day of documentation time reclaimed” (§6.2) | Aggressive vs published ambient documentation literature. Defensible only with workings | See H1 fix |
| O5 | ”Target KPI: ≥40% reduction in time-to-find for clinical and operational queries” (§6.2) | No baseline, no measurement methodology, no comparator | Either remove or define baseline (e.g., “vs trust’s current intranet search median latency”) |
| O6 | ”Target KPI: 25% reduction in time-to-discharge-letter; 10% improvement in TTOC compliance” (§6.2) | TTOC compliance is a clinically governed metric. Claiming a 10% improvement requires either a published prior or a modelled assumption | Soft-target with methodology footnote, or remove the TTOC number |
| O7 | ”production deployments at [named enterprise references — to populate from Votee]” (§6.3) | Placeholder text. Must not survive into the submitted PDF | Populate before v2 submission |
| O8 | ”Open-source release of Beever Atlas (with adopter metrics)” (§5.3) | “Adopter metrics” not produced. Likely a GitHub star count, not enterprise adopters | Either publish actual adopter list or remove “(with adopter metrics)“ |
| O9 | ”production deployments at [named enterprise / public sector references]” (§5.3) | Same placeholder issue as O7 | Populate before v2 |
| O10 | ”Carbon-aware inference scheduling; UK-grid-aware deployment topology” (§Sustainability) | Sounds like a feature, but no implementation evidence in supporting documents | Either describe the implementation (e.g., “scheduled batch inference deferred to off-peak grid-carbon windows via [tool]”) or replace with a measurable Carbon Reduction Plan commitment |
| O11 | ”Algorithmic bias testing built into every model release cycle; bias evaluation reports shared with each deploying trust” (§EDI) | Strong claim, no testing framework named, no sample report attached | Name the framework (e.g., Aequitas, IBM AIF360, Fairlearn) and commit to a sample bias report annex |
| O12 | ”Our Teaming Agreement contains step-in rights and source-code escrow” (Appendix A) | Tracker item 33 is 🔴 not started. Escrow agent not named | Either name the escrow agent (NCC Group / Iron Mountain) or remove the escrow claim |
7. Win-theme audit — do the 5 themes actually thread through?
| Theme | Lot 6 | Lot 7 | Lot 5 | Cross-cutting | Verdict |
|---|---|---|---|---|---|
| Sovereign by design | ✅ Present (on-prem V-Note) | 🟡 Weak — advisory section barely mentions sovereignty | 🟡 Mentioned (MAGIC-NHS) but undermined by Votee HK intro | ✅ Strong in IG section | Drops out in Lot 7. Add a sentence to Lot 7 about advisory teams being UK-resident, security-cleared where required |
| Clinically safe without overclaiming | 🟡 Asserted via DCB0129 line, but CSO unsigned | ❌ Not present in Lot 7 narrative | 🟡 Mentioned in Trial Concierge “with clinical sign-off” | ✅ Strong in Clinical Safety section | Drops out in Lot 7. Add: “Our advisors are governed by our Clinical Safety Management System even in non-clinical work” |
| Evidence-grade | ❌ Placeholders everywhere | ❌ “Provide CVs” placeholder | 🟡 ACL papers cited but mis-aligned to NHS use cases | 🟡 Bias testing claim unsupported | Largest gap across the bid. This theme is asserted in §0 then evaporates |
| Embedded, not delivered | 🟡 Implementation Pods mentioned in Lot 7 only | ✅ Strong in Lot 7 Fractional CAIO | ❌ Not present in Lot 5 | ❌ Not present cross-cutting | Concentrated in Lot 7 only. Should thread through Lot 5 (embedded researcher) and Lot 6 (on-site delivery lead) |
| Buy-once, deploy-many | 🟡 Implied via volume discounts | 🟡 Implied via rate card | ❌ Not present in Lot 5 | ❌ Not present in Pricing | Weakest theme overall. Make explicit: a single trust’s procurement work unlocks framework-wide reuse |
Conclusion: Of 5 themes × ~4 sections, only ~7 of 20 cells score strongly. Win themes are introduced in §0 then drop out. Rewrite with a discipline that every section’s opening sentence cites one or two of the five themes by name.
8. Devil’s advocate questions (20)
Questions an NHS CCIO, IG lead, or commercial moderator will privately ask. Our answer in italics.
- “Who is your Clinical Safety Officer, when did they qualify, what is their NHS clinical registration?” — Currently unanswered. Must answer in writing before 21 Jul.
- “Show me one NHS trust where Scribe-On-Site has run for 90 days.” — None. Reframe: “We are a new framework entrant by design; our solutions have run in adjacent regulated environments and we de-risk via outcome-share pricing.”
- “Where physically does an NHS clinician’s voice recording sit when V-Note processes it?” — On the trust’s V-Note appliance, never leaves the trust boundary. Add as one paragraph with diagram.
- “You name Beever as Toronto-based via Votee, which is Hong Kong-headquartered. Under what UK legal entity does NHS data get processed?” — BritiAI Ltd, UK. Votee + Beever are IP licensors and UK-resident technical support only. Make this explicit in §2.
- “Your Lot 5 evidence is two ACL papers on theorem explanation and Cantonese — what is the healthcare relevance?” — Honest answer: none directly. Reframe Lot 5 around MAGIC-NHS pipeline + a named NHS academic partner.
- “What is your ISO 27001 certificate number?” — None today. Provide named assessor, scope, target date, and binding award-condition commitment.
- “Cyber Essentials Plus — date of issue?” — In progress. Per the NHS SBS Q&A, CE+ may be satisfied by equivalent controls (ISO/IEC 27001 accepted) and is verified at the Apr–May 2027 due-diligence stage, not at submission. Have credible dated proof or the ISO equivalent-controls position ready by 21 Jul.
- “Your 60 min/clinician/day claim — what is the published evidence?” — Currently none. Provide modelled assumption or downgrade.
- “You claim outcome-share pricing. What percentage, against what metric, paid back to the trust how?” — Specify, don’t tease.
- “Who specifically is the Fractional CAIO and what is their NHS background?” — Name them. Without a name, this offer is hollow.
- “What’s your DSPT submission status — registered, in progress, Standards Met?” — Tracker shows 🟡. Get to Standards Met by submission or commit to it in writing.
- “How do we get out if Votee is acquired by a non-UK entity?” — Step-in rights and source-code escrow — but name the escrow agent.
- “You mention a Baidu Innovation Award. What is the NHS data protection implication of a partner with Baidu adjacency?” — Remove Baidu from the submitted prose. Full stop.
- “Your pricing is mid-market premium — why are you more expensive than a Big-4 deploying the same tech?” — We are embedded operating partners with productised, sovereign, evidence-grade delivery; Big-4 charge for slideware. Make the argument.
- “How many of your delivery cadre have an NHS Smartcard / clinical system experience?” — Currently unanswered. Even one named example would help.
- “What is your DTAC v2 score?” — Self-assessment pending. Must be in evidence pack.
- “Atlas for Trusts is open-source — what stops a trust deploying it without you?” — Nothing technically; we sell the integration, hosting, clinical safety wrap, support, and DSPT compliance. Make the value-add explicit.
- “Your social value commitment is generic. Specifically — how many UK apprenticeships, in which constituencies, by when?” — Currently template-level. Fix per §9.
- “If we direct-award you a £500k call-off in 2027, what does month 1 look like?” — Provide a worked 90-day mobilisation plan in an annex.
- “What happens to data when a trust exits?” — Data exit + destruction process not described. Add a paragraph.
9. Social Value Plan audit
Current state: template-level boilerplate. §Sustainability and §EDI together total ~120 words and read as policy summary, not as a Social Value Plan. Tracker item 31 is 🟡 with “UPGRADE PRIORITY” tag — that warning is correct and unactioned.
At 10% of every lot, the SV Plan is worth ~3 marks in a 30-mark composite. A well-written PPN 06/20-aligned SV Plan scores ~8/10; the current draft scores ~2/10. That is a 2-mark loss on Lot 6, 2 marks on Lot 7, 2 marks on Lot 5 — 6 marks across the bid for one document we control entirely. This is the highest-leverage fix in the whole pack.
Specific improvements needed:
- Adopt the PPN 06/20 Model Award Criteria structure. Pick 2–3 of the 5 themes: COVID-19 recovery, tackling economic inequality, fighting climate change, equal opportunity, wellbeing. NHS evaluators score against this structure.
- Make every commitment SMART. “Apprenticeships” → “4 Level 4 Data Technician apprenticeships per £1m of framework revenue, sourced from constituencies in the bottom IMD quintile, by end of Year 2.”
- Tie commitments to deployment regions. Northern Ireland, Scotland, Wales, and English Midlands have specific levelling-up framings — match the SV commitments to where call-off trusts physically sit.
- Carbon Reduction Plan must be attached and dated. Tracker item 6 says drafted — attach it; declare a Scope 1/2/3 baseline and Net Zero year.
- Quantify open-source value. “Beever Atlas open-source release” — quantify it: “$X equivalent value of clinical-grade software released to the NHS community at no cost; commitment to maintain for framework term.”
- Add SME supplier diversity. Subcontracting £X to UK SMEs and VCSEs annually.
- Add measurable workforce wellbeing. Clinician time reclaimed via Scribe-On-Site has a wellbeing valuation — quantify it.
- Add an external SV measurement framework. Social Value TOMs (Themes, Outcomes, Measures) is the de facto NHS standard. Cite it.
- Add a governance commitment. Quarterly SV reporting to NHS SBS, annual independent verification.
- One named senior accountable owner for the SV Plan, not “BritiAI” as an abstract entity.
A properly drafted SV Plan is the single most cost-effective rewrite in the next 10 days. Owner: COO. Deadline: Fri 27 Jun (per tracker).
10. Differentiation pressure test
A Big-4 bid (Deloitte, EY, KPMG, PwC, PA) on these lots looks like:
- Lot 7: 200+ named consultants, NHS-credentialed partners, prior NHSE/NHSX engagement, Cabinet Office security clearances, dedicated AI Centre of Excellence in London, hundreds of pages of methodology. Out-prices us on rate card by 20–40% but out-credentials us 10x.
- Lot 6: licenses Microsoft/Nuance/Google Health tech; positions itself as integrator. Weaker on sovereignty narrative because the underlying tech is US-cloud. This is where we differentiate hardest.
- Lot 5: prior NIHR partnerships, named clinical academic advisors, MHRA engagement. They beat us on Lot 5.
A US ambient documentation incumbent bid (Nuance/DAX, Abridge, Suki, Microsoft) on Lot 6 looks like:
- Hundreds of US health system deployments, peer-reviewed JAMA/NEJM studies on time savings, mature Epic/Cerner integrations, FDA precedent, scale economics. Beats us on volume and evidence.
- But: routes audio through US cloud, sovereignty headache, expensive per-clinician, less embedded operating partnership.
- Our differentiation is genuine here: on-prem, UK-sovereign, embedded, mid-market premium not enterprise-only.
Where we are genuinely differentiated (defendable):
- On-prem ambient capture (V-Note) — most competitors cannot honestly claim this.
- UK-sovereign LLM training pipeline (MAGIC-NHS concept) — Big-4 don’t own the IP, US incumbents are not UK-sovereign.
- Open-source Beever Atlas + neural memory layer — unique technical asset, transparency story.
- Fractional CAIO embedded model — Big-4 sell partners by the day, not by the operating role.
- Outcome-share pricing willingness — Big-4 won’t, US incumbents won’t.
Where we sound like everyone else (must fix):
- “Diagnose → Design → Deploy → Demonstrate” — every Big-4 bid says this.
- “Embedded operating partner” — every consultancy bid says this.
- “DCB0129-aligned Clinical Safety Case” — table stakes, not differentiation.
- “UK-only data residency” — table stakes when stated; differentiation when evidenced with topology.
- “AI Readiness Programme” — generic title. Rename to something specific (e.g., “NHS AI Operating Readiness — 12 Weeks to Board Decision”).
Net: We have ~5 real differentiators that the bid currently buries. The win-rewrite job is to make them load-bearing in the first three sentences of every lot response.
11. Closing recommendations — top 5 prioritised actions for Wed 1 Jul rewrite cycle
-
Sign the CSO contract by Fri 20 Jun and rewrite every clinical-safety sentence in present tense with the CSO’s name, registration number, and training certificate cited. This unlocks Lots 5 and 6 from gating risk. No CSO = no submission on those lots.
-
Kill the Baidu reference; rewrite the Votee/Beever introduction to lead with UK data sovereignty. Restructure §2 to: BritiAI UK prime → UK data controller posture → Votee + Beever as IP licensors with UK-resident technical support only → no NHS data crosses UK boundary. This single rewrite neutralises the largest non-technical scoring risk in the bid.
-
Decide Lot 5 at the Wed 24 Jun gate. Recommendation: drop Lot 5 unless a signed Letter of Intent from a UK academic health partner (UHB / GOSH / Imperial / Manchester) is in hand by that date. A weak Lot 5 will drag moderator confidence on Lots 6 and 7. Automatic Lot 8 enrolment only needs two lot wins; Lots 6 + 7 deliver that.
-
Write a proper Social Value Plan to PPN 06/20 / TOMs structure by Fri 27 Jun. This is the single highest-leverage fix — 6 marks recoverable across the bid for a document we control entirely. Assign a single owner (COO) with a Tuesday and Thursday review with CEO.
-
Replace every placeholder, populate every evidence bracket, attach architecture diagrams to each named solution, and run a “fact-check pass” where every numeric KPI, every “production deployment” claim and every certification status is cross-checked against a source document. No
[X],[reference], or[to populate]strings may survive into the v2 submission pack.
Run-of-show: Mon 22 Jun — CSO + Baidu rewrite committed. Wed 24 Jun — Lot 5 gate. Fri 26 Jun — Teaming Agreement signed + Social Value Plan v1. Mon 30 Jun — all v2 drafts, architectures, evidence in. Internal submit target Fri 3 Jul, well ahead of the 12:00 noon, Tue 21 Jul deadline. The buffer exists; protect it.
End of report. Reviewer recommends a 90-minute walkthrough with Bid Director and CTO before v2 rewrite cycle commences.
