The Board of Digital Health and Care Wales (DHCW) is responsible for the overall leadership and direction of the organisation. This includes:
The Board is accountable for ensuring that robust arrangements are in place for governance, risk management and internal control.
As Chief Executive, I am responsible for making sure that appropriate governance structures, systems and processes operate effectively across the organisation. This includes maintaining a sound system of internal control that supports the delivery of DHCW’s objectives, while safeguarding public money and the organisation’s assets for which I am personally accountable. These responsibilities are carried out in line with the duties assigned by the Accountable Officer of NHS Wales.
The Annual Report describes how DHCW has worked during 2025/26, both internally and with partners, to deliver its objectives. It explains how we maintain good standards of governance, identify and manage risks, and obtain assurance that our arrangements are working as intended.
This Governance Statement provides additional detail where necessary but aims to avoid repeating information already set out elsewhere in the Annual Report. For this reason, it should be read alongside other sections of the report, particularly the Performance Report, which explains DHCW’s role, functions and plans.
This statement explains how DHCW’s governance structures are organised and how they support the delivery of our objectives.
The Board sits at the top of DHCW’s governance and assurance framework. It:
The Board receives assurance through its committees, as well as through assessments against recognised professional standards and regulatory frameworks.
Select any card below to explore our detailed statutory functions, Board objectives, escalations, risk boundaries, and committees.
The Board and its Committees carried out a self-assessment of effectiveness for 2025/26 between January and March 2026. The results were considered at the relevant Committee meetings and reported to the SHA Board. This process supports continuous improvement by helping the Board and Committees reflect on how effectively they carry out their roles.
The self-assessment questionnaires were informed not only by recognised good practice and relevant guidance, but also by learning from an external review of Board and Committee effectiveness. This helped ensure the questions focused on areas such as clarity of roles, quality of leadership, effectiveness of support arrangements, and how well the Board and Committees provide challenge, assurance and oversight.
The Audit and Assurance Committee questionnaire was based on the Audit Committee Handbook and was circulated to Committee members and regular attendees. The questionnaires used for the SHA Board, Digital Governance and Safety Committee, Programmes Delivery Committee and Local Partnership Forum were aligned to this approach and tailored to reflect each group’s composition, purpose and responsibilities, drawing on the governance, leadership and support themes used by the Audit and Assurance Committee.
In addition, the Committee Chairs and Chair of the Board met collectively to discuss the effectiveness of the Board & Committees. This approach helped provide a consistent and informed view of effectiveness across the Board and its Committees, while also taking account of external insight and good practice.
Appendix 1 shows who served on the Board and its Committees, and how often meetings were attended, during the period 1 April 2025 to 31 March 2026. In addition to formal meetings, Board members also take part in a range of other activities on behalf of the organisation, including Board development sessions, briefing meetings, and both internal and external meetings.
Any changes to the structure or membership of Board committees must be approved by the Board. During the year, the Audit and Assurance Committee, Digital Governance and Safety Committee, and Programmes Delivery Committee each reviewed their own terms of reference and made recommendations to the Board. The Board reviews the terms of reference for all committees every year to make sure they remain up to date and clearly reflect governance requirements, delegated responsibilities and areas of oversight.
All Board committees and advisory groups produce an annual report summarising their work and key activities. These reports were received and noted by the Board in March 2025. Details of lead officers are included in Appendix 2, and the schedule of Board and Committee meetings for 2025/26 is set out in Appendix 3.
The DHCW Local Partnership Forum (LPF) is the main way the organisation works in partnership with trade unions and staff representatives. It provides a formal space for discussion, consultation and communication between DHCW management and staff organisations, helping to ensure that staff views are considered when decisions are made.
During 2025/26, the LPF met four times a year and focused on both strategic and practical workforce issues. Topics discussed included organisational culture and values, staff recognition and wellbeing, new ways of working, organisational development, employment policies, and equality and diversity.
Through this partnership approach, the LPF supports open dialogue, constructive challenge and joint working on issues that affect staff and the wider organisation.
DHCW has systems in place to help manage risk and support good decision making. These arrangements are designed to reduce risks to an acceptable level, rather than to remove all risk entirely. This approach is set out in DHCW’s risk appetite statement. As a result, the system of internal control can provide reasonable assurance that things are working as intended, but it cannot guarantee that problems will never occur.
The system of internal control is an ongoing process. It helps DHCW to identify and prioritise risks that could affect the achievement of its aims and objectives, assess how likely those risks are to occur and the impact they could have, and put proportionate controls in place to manage them effectively and efficiently. This system was in operation throughout the year ending 31 March 2026 and remains in place up to the approval of the Annual Report and Accounts.
The Board Assurance Framework (BAF) is a key part of this system. It was reviewed and approved by the Board in May 2025 and sets out the main risks facing the organisation, along with the controls and sources of assurance used to manage those risks. The Board uses the BAF as part of its annual cycle of assurance and scrutiny.
The Board and its Committees regularly review information from the BAF and the Corporate Risk Register to monitor risks, seek assurance and make sure that any gaps or weaknesses are addressed. Key controls are those systems and processes that support the delivery of the Board’s strategic objectives.
The effectiveness of DHCW’s internal control arrangements is reviewed by both internal and external auditors, who provide independent assurance to the Board.
The Chief Executive, as Accountable Officer, has overall responsibility for managing risk across DHCW. Day-to-day leadership for risk management is delegated to the Director of Corporate Affairs/Board Secretary, who oversees how risks are identified, managed and reported through DHCW’s Risk Management Framework and Board Assurance Framework.
DHCW recognises that taking some risks is necessary to achieve its strategic aims and deliver benefits for patients, staff and partners. The organisation’s risk appetite statement explains the level of risk the Board is prepared to accept and how risks are approached. In summary, this means that:
In some cases, higher levels of risk may be accepted where, for example, the likelihood of the risk occurring is low, the potential benefits are significant, the cost of controlling the risk would be greater than the impact if it occurred, the risk exists only for a short period, or where action is required by another organisation.
DHCW’s approach to risk also takes account of its capacity for risk. This reflects how much risk the organisation can reasonably manage, given its financial position and other resources, before it would be unable to meet its legal duties or statutory responsibilities.
Clear risk tolerance levels are used to guide when risks should be escalated to senior management, Committees or the Board. Risks are grouped into defined risk areas, each with an agreed level of appetite and expectation about the controls in place. This information is used by the Board when reviewing the Board Assurance Report.
| Appetite | Escalation Rule Threshold | Assigned Risk Domain Areas |
|---|---|---|
| Hungry | Risk with rating 25 or above are escalated for consideration to report to the Board. | None |
| Open | Risk with rating 20 or above are escalated for consideration to report to the Board. | Development of Services |
| Moderate | Risk with rating 15 or above are escalated for consideration to report to the Board. | Corporate Social Responsibility |
| Cautious | Risk with rating 12 or above are escalated for consideration to report to the Board. | Financial, Reputational Safety and Wellbeing, Service Delivery Reputational, Information - Access and Sharing |
| Adverse | Risk with rating 9 or above are escalated for consideration to report to the Board. | Compliance, Information - Storing and Maintaining, Citizen Safety |
All risks are linked directly to DHCW’s strategic objectives and reported through the Board Assurance Framework (BAF). The BAF identifies the organisation’s five principal risks, which were agreed by the Board in May 2025 following detailed discussion.
Throughout 2025/26, DHCW took a proactive and structured approach to managing its key risks, supported by Board and Committee oversight.
The organisation’s risk profile reflected the pace and complexity of delivering national digital priorities, alongside dependencies on partner commitment, funding certainty and system wide decision making.
Key areas of focus included delivery confidence against agreed milestones, the impact of funding uncertainty on programme delivery, the need for clear national direction to support sustainable digital transformation, and ongoing information governance challenges linked to the wider legal and policy environment for data use. These risks were actively monitored through the corporate risk register and assurance processes, with a small number managed in private where confidentiality was required.
The Board and its Committees maintained regular scrutiny throughout the year, alongside continued work to strengthen risk management processes and organisational resilience.
The Board sees effective risk management as an essential part of how DHCW operates and delivers its objectives.
The Board and its Committees identify and oversee the key risks facing the organisation, with significant risks escalated to the Board for consideration where appropriate.
At an operational level, Executive Directors regularly review risks within their areas of responsibility and make sure appropriate controls and actions are in place.
DHCW’s risk management framework links strategic and day to day risks and provides a consistent approach for identifying, assessing and monitoring risks across the organisation.
DHCW places strong emphasis on building a positive and open risk culture, where risks are identified early, discussed openly and managed consistently.
Staff are supported through training, guidance and access to clear tools that help them understand and manage risk in their day-to-day work.
Over the past year, this approach has strengthened understanding of risk across the organisation, improved the quality of risk information, and empowered staff to escalate issues appropriately.
As a result, DHCW has a clearer, more accurate view of its risk profile, allowing greater focus on the most critical and emerging risks, supported by regular Board and Committee oversight.
An analysis of corporate risks including the movement in corporate risks since the establishment of DHCW, from October 2024 to September 2025, was undertaken during the year and presented to our Board in November 2025.
DHCW is not required to comply with every requirement of the corporate governance code for central government departments. However, the Board assesses how DHCW applies the main principles of the code in a way that is appropriate for an NHS public body. This assessment is carried out annually and reported to the Board, with no departures identified. Where relevant information is not included in this Governance Statement, it is reported more fully in the wider Annual Report.
DHCW’s risk management arrangements are also aligned with the Orange Book – Management of Risk principles, taking account of the organisation’s size, structure and responsibilities. There have been no reported departures from these principles.
DHCW are committed to fostering a culture of openness across all parts of the organisation to support and encourage all staff to communicate any concerns they might have, with the confidence that they will be treated with respect and dignity when doing so.
During 2025-26 there were two Raising Concerns cases which were managed within the appropriate processes and reported to Audit & Assurance Committee. The NHS Wales Staff Survey Results for DHCW indicate that:
Quality and Duty of Candour
DHCW continues to operate under the Duty of Quality, as set out in the Health and Social Care (Quality and Engagement) (Wales) Act 2020, having come into scope in April 2023. During 2025/26, DHCW maintained compliance with the Duty of Quality and continued to strengthen organisational arrangements to support the delivery of high quality, safe and continuously improving digital health services.
Following the publication of its inaugural Duty of Quality Annual Report in the previous reporting period, DHCW’s focus during 2025/26 shifted from establishment to the embedding and operationalisation of duty led quality arrangements across the organisation.
A key milestone during the year was the formal approval and implementation of the DHCW Quality Framework, which provides a clear, organisation wide approach to defining, assuring and improving quality. The Framework is explicitly aligned to the Duty of Quality, underpinned by the Health and Care Quality Standards, and structured around Quality Planning, Quality Control and Quality Improvement. It establishes clear governance, roles and responsibilities and supports consistent quality oversight through quarterly and annual quality reporting.
In parallel, DHCW continued the strategic development of its Quality Management System (QMS). During 2025/26, the DHCW Quality Management System Development Early Position Statement (EPS) was formally approved and submitted to NHS Performance & Improvement (NHS P&I). The EPS sets out DHCW’s current QMS maturity position, confirms alignment with national expectations, and describes a phased approach to developing an enterprise wide, proportionate and scalable QMS appropriate to a national digital health organisation.
Together, the approval of the Quality Framework and the submission of the QMS EPS represent significant progress in strengthening DHCW’s quality governance, assurance and improvement arrangements, providing clearer line of sight from statutory duty through to operational delivery and supporting a culture of continuous learning and improvement in line with the Duty of Quality.
DHCW has a statutory obligation to have in place the knowledge, processes, and procedures to appropriately implement and manage the Duty of Candour.
To ensure this all incidents are reviewed and actioned by the Patient Safety team and any escalation, subsequent review of reports and learning from events is managed by the Incident Review & Learning Group (IRLG) and in turn this group reports to the Digital Safety & Governance Committee, allowing for robust levels of assurance that the Duty is appropriately and effectively implemented.