DSPT Audit 26-27 Areas of Mandatory Audit (4 September 2026)
The outcomes and assertions of the DSPT which must be included in a 25-26 DSPT Audit for NHS Trusts, ICBs, ALBs, CSU, OES and Genomics.
DSPT Audit 25-26 Areas of Mandatory Audit NHS Trusts, ICBs, ALBs, and CSUs
For NHS Trusts, ICBs, ALBs, CSUs, OES and Genomics there are 11 mandated outcomes to be audited (listed below) with organisations selecting 1 outcome of their choice.
A1b
Roles and
responsibilities
A3a
Asset management
B2c
Privileged user
management
B2d
Identity and
access management
B3a
Understanding
data
B4c
Secure
management
B6a
Culture
B6b
Training
C1e
Personnel skills
for monitoring and detection
D1c
Testing and
exercising
E4a
Managing records
If you are undecided which optional outomce to audit we would recommend:
OES and Genomics Organisaitons
B5c
Backups
NHS Trusts, ICBs, ALBs and CSUs
D1a
Response Plan
CNI operators
A2a
Risk management process
Audit areas for IT Suppliers will be shared shortly.