Skip to main content

Part of Data Security Standard 5 - Process reviews

Problem processes (5.2.1)

Current Chapter

Current chapter – Problem processes (5.2.1)


As part of your incident root cause analysis, you may identify problems with processes in your organisation. This could be a wide variety of processes, ranging from the procedure for posting clinical letters to a firewall change rules process.

Problem processes are processes which are repeatedly linked to incidents or near misses. Processes can also be categorised as problem processes if they are linked to one high profile (or high value) incident or near miss.

All relevant stakeholders must be involved in reviewing these processes. You should also monitor these processes, ensuring that lessons are learnt, and actions are taken to improve them. The board or equivalent team should also be provided with updates and assurance, with evidence to justify the assurance.


Last edited: 12 September 2022 3:54 pm