DSPT Risk Assessment: How to Document Data Security Risks Under Standard 5
Standard 5 of the DSPT — Process Reviews — requires you to demonstrate that you actively review your data security arrangements and manage risks. The primary evidence is a data security risk assessment, typically presented as a risk register: a record of identified risks, their likelihood and impact, and the controls you've put in place.
For small providers, the hardest part of this standard isn't the assessment methodology — it's getting started. Many providers have good data security practices but have never sat down to document what risks those practices are managing.
What the DSPT wants to see
Standard 5 is less about having perfect security than about showing that you've looked. The assessor is checking:
- You have a risk register — documented risks specific to your organisation
- Risks are scored — some form of likelihood × impact assessment, even if informal
- Risks are owned — a named person responsible for each risk
- Controls are recorded — what you've done to reduce each risk to an acceptable level
- The register is reviewed — a recent review date shows it's a live document, not a one-time exercise
You don't need a formal risk management framework. A spreadsheet with those columns, updated within the last 12 months, with risks that are clearly specific to your organisation, satisfies the requirement.
How to structure your risk register
A practical risk register format for a small provider:
| # | Risk description | Likelihood (1-5) | Impact (1-5) | Risk score | Risk owner | Controls in place | Residual risk | Review date |
|---|
Likelihood and impact can be scored 1-5 or Low/Medium/High — the scale matters less than applying it consistently. A risk score of likelihood × impact gives you a relative priority ranking.
Risk owner is the named person responsible for monitoring and managing that risk. In a small organisation, this is usually the practice manager, registered manager, or data protection lead for most risks.
Controls in place describes what you're already doing to reduce the risk. This is where your existing good practices get documented: encrypted devices, staff training, access controls, supplier DPAs.
Residual risk is the level of risk that remains after controls. Some risks can be reduced to near-zero (a fully encrypted, remote-wipe-capable device fleet reduces the risk from a lost device significantly). Others remain medium even with controls (phishing is a persistent risk regardless of training).
Risks to include for a small healthcare provider
These are realistic starting points — adapt them to your specific systems and setting:
Staff credentials shared or compromised. Likelihood: medium. Impact: high. Controls: unique accounts per staff member, no shared passwords policy, password manager or IT provider-managed credentials.
Mobile device lost or stolen with patient data. Likelihood: medium (particularly relevant for domiciliary care, dental/optician site visits). Impact: medium-high. Controls: full-disk encryption, MDM with remote wipe capability, no local storage of patient data where avoidable.
Phishing email resulting in account compromise. Likelihood: medium. Impact: high. Controls: staff phishing awareness training, MFA on all email accounts, email filtering.
Care or practice management system unavailable (ransomware or outage). Likelihood: low-medium. Impact: high. Controls: cloud-hosted systems reduce local ransomware risk, business continuity plan with manual procedures, daily backups.
Leaver retaining system access. Likelihood: low (with good process). Impact: medium-high. Controls: documented leaver procedure, access register with removal confirmation, access review at least quarterly.
Out-of-date software with unpatched vulnerabilities. Likelihood: low-medium. Impact: high. Controls: automated update policies, IT provider responsible for patching schedule, unsupported system register.
Supplier processing patient data without a DPA. Likelihood: low (if Standard 10 is in place). Impact: high. Controls: supplier register with DPA status tracked, annual DPA review.
Verbal disclosure of patient information. Likelihood: medium. Impact: medium. Controls: staff training on confidentiality, consulting room / private conversation spaces, visitor management.
Aim for 6-12 risks. A register with 6 specific, realistic risks is better evidence than one with 20 generic risks copied from a template.
Conducting the annual review
The annual risk review should be a deliberate activity — not just updating a date. For a small provider, a one-hour review session with the practice manager or registered manager is proportionate. The review should ask:
- Are all the risks on this register still relevant?
- Has anything changed that creates a new risk? (New systems, new staff structure, new service types)
- Have any controls improved or deteriorated since the last review?
- Did any incidents occur in the last year that the risk register should have predicted? If so, does the register need updating?
- Are risk owners still in post?
Record the review: date, participants, whether risks were updated, and the next review date.
Connecting your risk register to other evidence
The risk register doesn't exist in isolation. It should connect to your other Standard evidence:
- Standard 2 (staff responsibilities) — risks relating to staff behaviour (credential sharing, misdirected emails) should be addressed by your data security policy
- Standard 3 (training) — training records should cover the risks you've identified as training-mitigable (phishing, confidentiality)
- Standard 4 (access controls) — access register and leaver procedure directly mitigate access-related risks
- Standard 6 (incident response) — your incident procedure is the response to risks that materialise
- Standard 7 (continuity) — your BCP addresses the system-unavailability risks
- Standard 10 (suppliers) — your supplier register with DPAs addresses the third-party processing risk
If assessors see a risk on your register for which you have no control listed — and that control is also absent from your other evidence — that's a substantive gap. If every risk on the register points to a documented control in another standard, that's coherent, well-integrated evidence.
Common gaps before submission
No risk register at all. This is the most straightforward gap to close — spend two hours identifying and documenting your top 8 risks. A spreadsheet created today is better than nothing.
Template risks not adapted. Generic risks from a download that don't reference your actual systems, staff structure, or services. Personalise each risk to your setting.
No named risk owner. "The organisation" is not a risk owner. Name a person.
Controls listed but not evidenced elsewhere. If your control is "staff training" but you don't have Standard 3 training records, the risk register control isn't backed by evidence.
Last reviewed date more than 12 months ago. Update it now, even if the risks haven't changed — record the review and confirm the risks remain accurate.
Use the DSPT evidence checklist generator to see your Standard 5 evidence items in the context of your full submission. For the full NDG standards framework, see our evidence requirements guide.
This guide is based on DSPT v8 (2025/26) requirements as published by NHS England. Always verify current requirements on the official DSPT portal. This is not legal or compliance advice.