Skip to content

DSPT Access Controls: Meeting Standard 4 and the v8 Admin Agreement

By Brian CrockerLast reviewed: 4 August 2026

Standard 4 of the DSPT — Managing Data Access — requires you to demonstrate that you know who has access to what, that access matches job roles, and that you have a process for managing joiners and leavers. DSPT v8 added a new mandatory requirement to this standard: your IT system administrators must sign an agreement holding them accountable to higher standards of confidentiality.

Access control evidence is often incomplete not because organisations have bad practices, but because they've never documented what they're already doing. The work here is mostly documentation of existing processes.

What Standard 4 requires

An access control policy. A written statement of how access is granted, reviewed, and removed. This can be a section of your data security policy rather than a standalone document. It should cover: who can authorise new access, what the minimum-access principle means in practice for your organisation, and what the leaver process involves.

An access register. A list of who has access to which systems and at what level. For a small care provider, this might be a spreadsheet with columns for: staff name, role, system, access level, date granted, date last reviewed, and date removed (if applicable). The register needs to be current — a register that includes people who left 18 months ago is worse evidence than no register.

A joiner process. Documentation of how new starters get system access: who requests it, who approves it, what level of access is appropriate for the role, and confirmation that access was set up correctly.

A leaver process. Documentation of how access is removed when staff leave: who is notified, what systems need to be updated, who confirms removal, and how quickly. The timeline matters — leavers with high-level access are a security risk for every day their credentials remain active.

A signed administrator accountability agreement (new in v8). All administrators of your IT systems must sign an agreement holding them accountable to higher standards of confidentiality. This is a new mandatory requirement for the 2025/26 cycle and one of the areas where small providers are most likely to have an evidence gap simply because it wasn't required before.

The new v8 administrator agreement

DSPT v8 introduced a new mandatory question (4.3.1): "Have all the administrators of your organisation's IT system(s) signed an agreement to hold them accountable to higher standards?" The people who administer your IT systems can access more information than other staff, so they need to be formally held to higher standards of confidentiality than others.

This requirement applies to IT system administrators in external companies that support your systems, not just internal staff. For a typical small Category 3 provider, the people in scope might include:

  • Whoever administers your clinical or care management software
  • Your NHSmail or email administrator
  • Your IT support company or managed service provider (MSP)
  • Anyone with administrator access to cloud storage or backup services holding personal data

How to meet it. The agreement can be part of a job description or built into a contract with your IT support company or systems supplier. Digital Care Hub (the care-sector DSPT support service, formerly Better Security, Better Care) publishes a Privileged Access Agreement template that you can download and adapt. The evidence is the signed agreement (or the relevant clause in a contract or job description) for each administrator.

Keep access minimised too. While documenting who your administrators are, it's good practice to confirm that admin access exists only where genuinely needed. If your care management software has ten staff with admin access because it was easier to set everyone up that way, that's a weakness worth addressing. The ideal position is the minimum number of administrators needed to manage each system, all of whom have signed the accountability agreement and have MFA enabled.

If your IT provider holds administrator accounts, ask them to confirm in writing that their administrators are bound by an equivalent accountability agreement. That confirmation can serve as part of your evidence.

Managing joiners: a practical process

The most common access control failure for small providers is ad hoc access management — giving new starters access when they ask for it, without a documented process. The DSPT doesn't require a formal IT ticketing system. A simple documented workflow is sufficient.

A practical joiner process for a small provider:

  1. Line manager or practice manager completes a brief access request form (or email): name, role, start date, systems needed, access level requested.
  2. Access is provisioned and confirmed — ideally by IT if you use an MSP, or by the systems admin if not.
  3. A record is added to the access register: name, systems, access level, date granted.
  4. New starter confirms receipt of credentials and completes initial data security training before first access to patient/client data.

The form doesn't need to be elaborate. An email chain that shows these steps happened is sufficient evidence.

Managing leavers: what often goes wrong

Leavers with active system credentials are one of the most common access control failures identified in DSPT assessments. The failure mode is usually not malicious — it's administrative: someone leaves, the manager handles the handover, and nobody specifically tells the system admin to remove access.

A robust leaver process should trigger on notice, not on last day. When someone hands in their notice, that's the time to start planning access removal — including lining up who will take over their admin responsibilities if applicable.

On the last day (or as close to it as possible):

  • Disable or delete accounts in all systems holding personal data
  • Change any shared passwords the leaver knew
  • Recover any employer-provided devices
  • Update the access register with the deactivation date

Keep a record that access was removed and when. If you use an IT provider, ask them to confirm removal in writing and file that confirmation.

For the DSPT, the evidence is: your policy says leavers get access removed promptly, your access register shows current staff only (or shows leavers with a removal date), and your process documentation shows who is responsible for removal.

Reviewing access periodically

An access register isn't a one-time document. The DSPT expects periodic review to ensure access remains appropriate as roles change. For small providers, a quarterly or six-monthly review is proportionate:

  • Is every person on the register still employed?
  • Has anyone's role changed in a way that should change their access level?
  • Are there any access levels that were granted temporarily and should now be removed?
  • Are admin accounts still held only by people who need them?

A dated review note at the bottom of your access register spreadsheet is sufficient evidence of periodic review. "Reviewed by [name], [date] — no changes required" is a valid review record.

Common gaps before submission

Access register not current. Leavers still listed, or register not updated since it was created. Update before submission.

No signed administrator agreement. New for v8 — this is the most likely gap for providers who have been completing the DSPT for multiple years. Get each IT administrator (internal and external) to sign an accountability agreement now, using the Digital Care Hub Privileged Access Agreement template or a clause in their contract or job description.

Joiner and leaver procedures not documented. If your process is informal, document it. A one-page description of who does what is sufficient.

MFA not enabled on admin accounts. If any of your system admin accounts don't have MFA, this will be flagged. Contact your IT provider or system vendor about enabling MFA — for most platforms it's a settings-level change.

Use the DSPT evidence checklist generator to track your Standard 4 evidence items alongside the rest of your submission. For the full evidence framework, see our DSPT evidence requirements guide.

This guide is based on DSPT v8 (2025/26) requirements as published by NHS England. Always verify current requirements on the official DSPT portal. This is not legal or compliance advice.

Sources

Get guided DSPT compliance when we launch

Join the waitlist for early access to DSPTready — step-by-step DSPT guidance built for small providers.

No spam. Unsubscribe any time. Privacy policy