Policy position
Lazomis QI uses artificial intelligence to assist qualified users with quality-improvement work. AI supports judgement; it does not replace professional accountability, establish clinical truth, make treatment decisions, or authorise care.
Document control
| Policy owner | Flux Medical Limited, trading as Lazomis QI |
|---|---|
| Version | 1.0 |
| Effective date | 15 August 2026 |
| Review date | 15 August 2027, or earlier after a material change |
| Applies to | All Lazomis QI AI-enabled products, personnel, contractors, suppliers and users |
| Status | Board-approved policy template; legal and information-governance review recommended before publication |
1. Purpose
This policy explains how Lazomis QI selects, designs, configures, tests, deploys, monitors and retires artificial-intelligence functionality. It is intended to protect patients, service users, healthcare professionals, organisations and the public while allowing proportionate use of AI to make quality-improvement work more efficient and accessible.
The policy forms part of Lazomis QI's wider governance framework and should be read with its privacy notice, data-processing terms, information-security policies, clinical-safety documentation, acceptable-use terms and incident-response procedures. Where another document sets a stricter requirement, the stricter requirement applies.
2. Scope
This policy applies to all AI or machine-assisted functions made available by Lazomis QI, whether developed internally or supplied by a third party. It includes generative AI, large language models, machine learning, automated classification, summarisation, recommendations, content generation and AI-assisted mapping or validation.
- Examples include suggested audit ideas, aims, criteria, data-collection fields, improvement actions, narrative summaries, reports, presentations, reflections, spreadsheet-column mappings and help content.
- It applies across development, testing, procurement, deployment, support, monitoring, research and decommissioning.
- It applies to employees, directors, contractors, suppliers, organisational customers and individual users where they interact with Lazomis QI AI.
3. Our AI principles
| Principle | Commitment |
|---|---|
| Human-led | AI output remains subject to meaningful human review. The user retains responsibility for project choices, clinical interpretation, organisational approval and action. |
| Purpose-limited | Each AI feature has a defined, documented purpose. We do not silently expand an AI system into a new use. |
| Safe and proportionate | Controls reflect foreseeable harm, clinical proximity, scale, reversibility and the vulnerability of affected people. |
| Transparent | Users are told when meaningful content is AI-generated or materially AI-assisted, what the feature is for, and its important limitations. |
| Evidence-aware | Source-backed standards are distinguished from local targets, configurable choices and AI suggestions. |
| Private and secure | We minimise data, protect confidentiality and prevent customer content from being used for unrelated model training without a valid, transparent basis. |
| Fair and accessible | We assess bias, exclusion, unequal performance and accessibility throughout the lifecycle. |
| Accountable | Material decisions, tests, incidents, supplier assessments and changes are documented and reviewable. |
4. What Lazomis QI AI does - and does not do
4.1 Intended functions
Lazomis QI AI is intended to assist the planning, administration, analysis and communication of audit, quality improvement and service-evaluation activity. It can propose, organise, transform or summarise content within Lazomis QI's structured workflows.
4.2 Boundaries
- It is not a substitute for a clinician, clinical supervisor, audit department, governance lead, ethics committee or regulator.
- It does not diagnose, triage, prescribe, recommend treatment for an individual, or determine whether care is clinically appropriate.
- It does not guarantee that a cited standard is current, applicable locally or correctly interpreted.
- It does not determine whether an activity is audit, QI, service evaluation or research; the responsible user and organisation must confirm classification and approvals.
- It must not be used as the sole basis for employment, training, disciplinary, credentialing, patient-access or other significant decisions about a person.
No autonomous clinical action
Lazomis QI will not intentionally deploy a feature that directly changes patient care, sends an instruction to a clinical system, or makes a significant decision about a person without a separate, documented governance and regulatory assessment.
5. Roles and accountability
| Role | Core accountability |
|---|---|
| Board / accountable director | Approves risk appetite, this policy and high-risk AI deployment; receives material incident and assurance reports. |
| AI governance lead | Maintains the AI inventory, coordinates impact assessments, approvals, monitoring and policy review. |
| Clinical safety lead / CSO where applicable | Assesses clinical hazards, safety controls and whether DCB0129 or related clinical-safety processes apply. |
| Data protection lead / DPO where appointed | Advises on controller/processor roles, lawful basis, DPIAs, individual rights, international transfers and breaches. |
| Product owner | Defines intended purpose, users, limits, acceptance criteria, monitoring and change controls. |
| Engineering and security | Implements technical controls, testing, logging, access control, resilience and supplier integration. |
| Content / clinical reviewer | Checks clinical accuracy, authoritative sources, wording, currency and safe presentation. |
| Organisational customer | Determines local lawful use, permissions, governance, deployment controls and staff training; completes its own assurance where required. |
| Individual user | Reviews outputs, uses appropriate data, follows local policy and does not present unverified AI content as established fact. |
6. Permitted, restricted and prohibited uses
6.1 Permitted
- Drafting and refining non-patient-specific QI content within a structured workflow.
- Summarising aggregate or appropriately de-identified project data, subject to verification.
- Suggesting mappings, labels, fields or presentation formats for user review.
- Generating administrative, educational or portfolio-support material that is clearly a draft.
6.2 Restricted - enhanced approval required
- Processing special-category or identifiable patient data.
- Features likely to influence clinical care, organisational performance management, employment or training progression.
- Automated profiling, prediction, ranking or benchmarking of identifiable people or small groups.
- New model providers, new jurisdictions, model fine-tuning, retrieval over customer documents, or material repurposing of existing data.
6.3 Prohibited
- Autonomous diagnosis, triage, treatment, prescribing or escalation decisions.
- Fabricating, altering or concealing audit results, sources, approvals, authorship or evidence.
- Uploading information a user is not authorised to disclose, including unnecessary patient identifiers.
- Re-identifying anonymised data, inferring protected characteristics without an approved purpose, or conducting covert surveillance.
- Solely automated significant decisions about patients, staff or learners without lawful authority and appropriate safeguards.
- Developing deceptive, discriminatory, harmful or unlawful content, or bypassing technical and organisational controls.
7. Human oversight and user responsibility
Meaningful human oversight requires more than a user clicking 'accept'. The reviewer must have sufficient competence, information, time and authority to question the output and must be able to amend or reject it without penalty.
- Check that the output answers the intended question and uses the correct population, denominator, exclusions and timeframe.
- Verify material clinical or legal claims against current authoritative sources and local policy.
- Check calculations, tables, charts and narrative conclusions against the underlying data.
- Consider missing data, small numbers, bias, confounding, alternative explanations and unintended consequences.
- Remove unsupported statements and clearly identify local choices or assumptions.
- Obtain required local approvals before collection, implementation, dissemination or publication.
8. Data protection and confidentiality
Where AI processing involves personal data, Lazomis QI applies the UK data-protection principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Controller and processor roles will be defined contractually and by the facts of each processing activity.
- A documented lawful basis is required before personal data is processed. Special-category data requires an additional valid condition where applicable.
- A data protection impact assessment (DPIA) is completed or updated where processing is likely to create high risk, and before restricted AI uses are released.
- Only the minimum necessary data is sent to an AI service. Prompt templates and interfaces should discourage identifiers and free-text excess.
- Retention periods, deletion processes, access permissions and international-transfer safeguards are defined for each relevant system and supplier.
- Privacy information explains material AI processing in clear language, including purposes, data categories, recipients and rights.
- Lazomis QI does not use customer project content to train general-purpose models unless this is separately assessed, transparently described and supported by an appropriate agreement or genuinely optional permission.
9. Patient and service-user data
Default rule
Lazomis QI projects should use anonymous or appropriately pseudonymised data wherever the purpose can be achieved without direct identifiers. Names, NHS numbers, full addresses, photographs and unstructured clinical narratives should not be entered merely because a custom field permits free text.
Users and organisations remain responsible for confirming that their project design, data fields, access model and disclosures comply with local information-governance rules. Custom fields must not be used to circumvent safeguards. If identifiable or special-category data is genuinely required, use is permitted only under an approved organisational arrangement defining necessity, lawful basis, security, retention, access, processor terms and AI exposure.
- AI features should be disabled or isolated from fields containing sensitive data unless specifically approved.
- Small-number reporting must be assessed for re-identification risk before dashboards, exports or benchmarking are shared.
- Anonymisation claims must consider the data in context, including linkage with other reasonably available information.
10. Transparency and explainability
- AI-assisted features are labelled at the point of use where the assistance is material.
- Users receive a concise explanation of the feature's purpose, inputs, output type, major limitations and review requirement.
- Where practical, outputs identify the sources or evidence used, the date accessed, assumptions and uncertainty.
- Lazomis QI will maintain a plain-language AI notice and, for higher-risk functions, an internal system or model card recording intended use, limitations, testing and ownership.
- We will not imply that AI output has been independently clinically validated when it has not.
11. Accuracy, evidence and hallucination controls
Generative AI can produce plausible but false content, incorrect citations, outdated standards and misleading summaries. Lazomis QI therefore uses layered controls appropriate to the feature.
- Structured templates constrain outputs to the Lazomis QI workflow rather than allowing unconstrained project creation.
- Authoritative sources are preferred for clinical standards; retrieved material is separated from model-generated suggestions.
- Source-backed standards, local targets and AI-suggested targets are visibly distinguished.
- Material calculations use deterministic code where feasible rather than language-model arithmetic.
- Representative tests include empty data, all records excluded, all responses not applicable, missing values, contradictory input, prompt injection and edge denominators.
- Outputs that cannot be safely verified are withheld, simplified or accompanied by a clear limitation.
- Users can edit, regenerate within controlled limits, reject and report outputs.
12. Fairness, equality and accessibility
Before deployment and during monitoring, Lazomis QI considers whether an AI function may disadvantage people because of protected characteristics, language, disability, geography, professional grade, institution type, data sparsity or other relevant factors.
- Testing uses realistic and diverse scenarios, including community, primary, secondary and non-UK contexts where claimed.
- Benchmarking avoids unfair comparisons caused by case mix, service configuration, missingness or small samples.
- Accessibility is assessed for AI interfaces and outputs, including keyboard use, readable language, contrast, headings and export formats.
- Known performance differences and population limits are documented. A feature is restricted or withdrawn where unfairness cannot be adequately mitigated.
13. Safety and regulatory classification
A feature's regulatory status depends on its intended purpose and actual functionality, not on its label. Before release, Lazomis QI assesses whether a function may constitute health IT subject to clinical-safety standards or software/AI as a medical device. Marketing, instructions and product behaviour must remain aligned with the approved intended purpose.
- Where DCB0129 applies, appropriate clinical risk-management documentation, a hazard log and safety case are maintained under qualified clinical-safety oversight.
- Organisational customers may have separate DCB0160 deployment responsibilities.
- Where medical-device rules may apply, the feature is not marketed or deployed for that purpose until the necessary regulatory pathway is completed.
- Safety-significant changes trigger reassessment before release.
14. AI lifecycle governance
| Stage | Required controls |
|---|---|
| 1. Proposal | Define problem, intended users, benefit, alternatives, prohibited uses, data and foreseeable harm. |
| 2. Triage | Assign risk tier; decide whether DPIA, equality assessment, clinical-safety review, legal review or board approval is required. |
| 3. Design | Apply data minimisation, human oversight, secure architecture, clear labelling, fallbacks and user controls. |
| 4. Supplier review | Assess provider terms, security, data use, retention, locations, sub-processors, availability, IP and exit arrangements. |
| 5. Validation | Test accuracy, robustness, bias, safety, usability, privacy, prompt injection, edge states and failure modes against acceptance criteria. |
| 6. Approval | Record evidence, residual risks, owners, monitoring thresholds and release decision. |
| 7. Deployment | Use staged rollout where proportionate; publish user instructions and limitations; enable logging and support. |
| 8. Monitoring | Review performance, user reports, incidents, drift, supplier changes and unequal outcomes. |
| 9. Change control | Reassess after material model, prompt, data, workflow, supplier, purpose or regulatory change. |
| 10. Retirement | Notify affected users where necessary; preserve required records; delete or return data; disable integrations safely. |
15. Third-party models and suppliers
- No AI provider is approved solely because it is widely used or claims enterprise security.
- Due diligence covers data ownership and use, training defaults, retention, deletion, encryption, access, sub-processors, locations, transfer mechanisms, incident notification, service continuity, model changes, audit rights and exit support.
- Contracts must reflect the parties' data-protection roles and prohibit unauthorised secondary use.
- Only approved accounts, endpoints and configurations may process Lazomis QI or customer information.
- Material supplier or model changes are reviewed; an emergency suspension or fallback route is maintained for critical dependencies.
16. Security and resilience
- Least-privilege access, strong authentication, environment separation, encryption, secrets management and secure logging are applied proportionately.
- Inputs and retrieved content are treated as untrusted. Controls address prompt injection, malicious files, data exfiltration, insecure tool use and excessive agency.
- Outputs are encoded and validated before being rendered, exported or passed to downstream systems.
- Rate limits, timeouts, fallbacks, backups and recovery arrangements reduce dependency and availability risk.
- Security testing and vulnerability management cover the AI integration as well as the underlying application.
17. Monitoring, incidents and complaints
Users can report inaccurate, unsafe, biased or inappropriate output through a clearly signposted route. Reports are triaged by potential harm, data sensitivity, scale, recurrence and clinical proximity.
- Contain: suspend the feature, model, tenant or workflow where continued use may cause harm.
- Preserve: retain proportionate logs, prompts, outputs, model/configuration versions and affected records.
- Assess: involve security, privacy, clinical safety, product and legal leads as appropriate.
- Notify: meet contractual and legal notification duties, including customer, regulator or patient-safety routes where applicable.
- Correct: remediate the cause, validate the fix and decide whether historical outputs need review.
- Learn: update the risk assessment, tests, training, documentation and monitoring.
18. Research, analytics and model improvement
Operational service data may be used to secure, support and improve the contracted service where lawful, necessary and transparently described. Any broader use of project data for research, publication, product discovery, benchmarking or model development requires a separate governance assessment.
- Optional consent for use of anonymised data must be specific, informed, freely given and capable of withdrawal for future use where consent is the chosen basis; refusal must not reduce the core service.
- Anonymised datasets must undergo a documented re-identification risk assessment. Pseudonymised data remains personal data.
- Research classification, ethics, sponsorship, protocol, GCP and publication requirements are addressed before research begins; a product-improvement label does not remove those duties.
- Published findings use appropriate disclosure control and accurately describe AI involvement, limitations and conflicts of interest.
19. Intellectual property
- Users must not submit third-party confidential or copyrighted material without authority.
- AI output may resemble existing material and may not qualify for exclusive protection; users must review before publication or commercial reuse.
- Lazomis QI will respect licences and attribution requirements for standards, guidance and retrieved content.
- AI assistance must not be used to misrepresent authorship, professional work or academic contribution.
20. Training and acceptable use
People who build, approve, support or materially rely on Lazomis QI AI receive role-appropriate training. Training covers limitations, hallucinations, verification, bias, confidentiality, prompt injection, incident reporting, clinical-safety boundaries and local governance.
- Access may be restricted until required training is completed.
- Deliberate misuse, control bypass, concealment of AI use or repeated unsafe practice may lead to suspension, investigation or contract action.
21. Records, audit and assurance
- Lazomis QI maintains an inventory of material AI systems, features, owners, models, purposes, risk tiers and status.
- For higher-risk features, records include impact assessments, model/system cards, test evidence, release approvals, known limitations, supplier reviews, changes, monitoring and incidents.
- Logs are proportionate, access-controlled and retained only as long as needed for security, support, safety, contractual or legal purposes.
- Periodic assurance includes policy compliance, supplier review, sample output review, incident trends and verification that public statements match actual practice.
22. Rights and contact routes
Individuals may raise questions about Lazomis QI's use of AI, request applicable data-protection rights, challenge a significant AI-assisted outcome, or report harmful output using the contact and privacy routes published on the Lazomis QI website. Requests will be routed to the responsible controller where Lazomis QI acts only as a processor.
23. Policy review and enforcement
This policy is reviewed at least annually and sooner following a material legal or regulatory change, a serious incident, a new high-risk use, a material supplier or model change, or evidence that controls are ineffective. Exceptions must be documented, time-limited, approved by the accountable owner and supported by compensating controls.
Failure to comply may result in feature withdrawal, access restriction, disciplinary action, supplier remediation or termination, customer notification, regulatory reporting or other proportionate action.
Appendix A: AI risk assessment
Every material AI use should be screened against the following factors. A single high-severity factor may justify enhanced governance regardless of the overall score.
| Factor | Lower risk indicators | Higher risk indicators |
|---|---|---|
| Clinical proximity | Administrative drafting | Output may influence individual care or safety |
| People affected | Professional user only | Patients, learners, staff or vulnerable people |
| Decision effect | Advisory and reversible | Significant, automated or difficult to challenge |
| Data | Anonymous aggregate data | Identifiable, special-category or free-text clinical data |
| Scale | Small, contained trial | Multi-organisation, high-volume or public output |
| Evidence | Constrained, source-grounded, deterministic checks | Open-ended generation or weak provenance |
| Human oversight | Competent reviewer can reject | Automation bias, time pressure or rubber-stamping likely |
| Fairness | Low distributional impact | Ranking, benchmarking or subgroup performance concerns |
| Security | No tools or sensitive retrieval | External tools, document retrieval, agents or write actions |
| Changeability | Stable rules and version control | Provider can change model behaviour without notice |
Minimum approval by risk tier
| Tier | Illustrative use | Minimum governance |
|---|---|---|
| Tier 1 - low | Copy refinement, generic help | Product-owner approval, basic testing, user disclosure where material |
| Tier 2 - moderate | Project suggestions, aggregate summaries | Documented assessment, clinical/content review, security/privacy check, monitoring |
| Tier 3 - high | Sensitive data, ranking, clinical proximity | DPIA and/or equality and clinical-safety assessment, specialist review, senior approval, staged deployment |
| Tier 4 - unacceptable as designed | Autonomous clinical decisions or covert harmful profiling | Do not deploy; redesign or abandon |
Appendix B: User-facing AI notice
Suggested website wording
Some Lazomis QI features use artificial intelligence to help you draft, organise, analyse or summarise quality-improvement work. AI output can be incomplete, inaccurate or out of date. Review it carefully, verify important claims against current authoritative and local sources, and do not use it to make decisions about an individual patient's care. Do not enter patient-identifiable or other confidential information unless your organisation has expressly approved that use and the feature is configured for it. You remain responsible for your project, approvals, interpretation and actions.
Appendix C: Reference framework
This policy was informed by the following authoritative UK sources. They should be checked again at each policy review because AI and data-protection guidance is changing.
- Information Commissioner's Office: Guidance on AI and data protection (noting the ICO states that this guidance is under review following the Data (Use and Access) Act). https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/
- UK Parliament: Data (Use and Access) Act 2025, including provisions concerning automated decision-making. https://www.legislation.gov.uk/ukpga/2025/18/part/5/chapter/1/crossheading/automated-decisionmaking/2025-08-20
- NHS England: Artificial intelligence and machine learning guidance; version 1.2, updated April 2025. https://www.england.nhs.uk/long-read/artificial-intelligence-ai-and-machine-learning/
- NHS England: Digital clinical safety assurance, including DCB0129 and DCB0160; updated March 2025. https://www.england.nhs.uk/long-read/digital-clinical-safety-assurance/
- MHRA / GOV.UK: Software and artificial intelligence as a medical device. https://www.gov.uk/government/publications/software-and-artificial-intelligence-ai-as-a-medical-device/software-and-artificial-intelligence-ai-as-a-medical-device
- GOV.UK: Algorithmic Transparency Recording Standard guidance for public-sector bodies. https://www.gov.uk/government/publications/guidance-for-organisations-using-the-algorithmic-transparency-recording-standard/algorithmic-transparency-recording-standard-guidance-for-public-sector-bodies
Legal note
This policy is a governance document, not legal advice. Before publication or contractual adoption, Lazomis QI should align it with its actual technical architecture, supplier terms, privacy notice, data-processing agreements, security controls and clinical-safety position, and obtain specialist advice where required.