Regulation
Clinical Triage Chatbots and the NHS Duty of Candour
When an automated triage tool routes a patient wrongly, the statutory duty of candour sits on the registered care provider, not the software vendor — this guide sets out what triggers it, who holds which obligation across CQC, MHRA, DCB0160, UK GDPR and the EU AI Act, and what an honest account of an algorithmic decision has to include.
A patient uses your online triage tool on a Friday evening. They describe abdominal pain and a temperature. The tool routes them to "contact your GP within three working days". On Monday they are admitted with sepsis. The incident review lands on your desk on Tuesday, and the first thing you notice is that no clinician saw the interaction until after admission. The chatbot set the route.
Two questions now sit in front of you. The first is whether this is a notifiable safety incident engaging the statutory duty of candour. The second, harder one, is what "an account of all the facts" means when the decision was made by a system your organisation did not build, whose logs you may not hold, and whose behaviour you may not be able to explain by the time you must speak to the patient.
What triggers the duty when a chatbot is in the path
In England the organisational duty of candour is Regulation 20 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014. It bites when a notifiable safety incident occurs: broadly, an unintended or unexpected incident during the provision of a regulated activity which, in the reasonable opinion of a healthcare professional, could result in or appears to have resulted in death or a defined degree of harm. The threshold and the harm definitions differ between health service bodies and other registered persons, so check which limb of Regulation 20 you fall under before calibrating anything else. Scotland and Wales operate their own organisational duty of candour regimes under separate statutes. There is no single equivalent EU-wide duty; EU readers should work from national patient-safety and adverse-event law alongside medical device vigilance.
Three misreadings recur. The incident is treated as an IT fault rather than a care incident, so it goes to the digital team and never reaches the patient safety route. The chatbot is treated as outside the regulated activity because it sits on a website: if it routes your patients within your service, it is inside. And no clinician involvement is read as no clinical incident, when that absence is often the incident.
Who is responsible, and who is not
The statutory duty sits on the registered person: the CQC-registered provider carrying on the regulated activity. Not the software company. Not the commissioner. It cannot be delegated, contracted out, or discharged by a vendor's own incident process. Individual clinicians hold a separate professional duty of candour under GMC and NMC guidance, which runs alongside the organisational duty rather than replacing it.
"Provider" is the most dangerous word in this file, because it means something different in each framework you are simultaneously subject to. Keep the mapping explicit:
- CQC / Regulation 20: you are the registered provider. The duty of candour is yours.
- EU AI Act (where it applies): the software company that places the system on the market under its own name is the provider; your organisation is the deployer. Article 26 deployer duties include following the instructions for use, assigning human oversight to people with the competence and authority to exercise it, monitoring operation, and retaining automatically generated logs under your control.
- UK/EU GDPR: you are almost always the controller for triage data; the vendor is usually a processor under an Article 28 contract. If it uses transcripts to improve its model for its own purposes, it becomes a controller for that processing and needs its own lawful basis and Article 9 condition. Check the contract, not the sales deck.
- NHS clinical risk standards: the manufacturer works to DCB0129; your deploying organisation works to DCB0160, with its own named Clinical Safety Officer, hazard log and clinical safety case for your deployment context. The vendor's safety case is not yours.
The other clocks that start at the same time
One chatbot triage incident starts several clocks at once, owned by different parties. Confusing them is how organisations file a device report and believe they have been candid with a patient.
| Obligation | Who holds it | Owed to | Timing |
|---|---|---|---|
| Statutory duty of candour | Registered provider | Patient or their representative | Notify in person as soon as reasonably practicable, then confirm in writing |
| Professional duty of candour | Individual registrant | Patient | Promptly, per GMC/NMC guidance |
| Patient safety event recording | Provider organisation | National learning system (LFPSE) and your PSIRF response | Per local policy |
| Medical device adverse incident report | Deploying organisation reports to MHRA; manufacturer has separate vigilance duties | MHRA | Per MHRA guidance |
| AI Act serious incident report (EU deployments) | The AI Act provider reports; the deployer must inform the provider immediately | Market surveillance authority | Article 73 sets tiered deadlines, shortest where death is involved |
| Personal data breach notification | Controller | ICO or lead supervisory authority | 72 hours, only if a breach occurred |
The last row matters: a wrong triage outcome is usually not a personal data breach. Do not manufacture one to fit a familiar process.
What "all the facts" means when the decision was algorithmic
Regulation 20 requires an account of all the facts the registered person knows at the date of notification, an explanation of what further enquiries are believed appropriate, an apology, and a written record. Applied honestly here, that means telling the patient an automated triage tool set the route, and what it recommended. Organisations routinely omit this and describe the outcome in the passive voice. That is not an account of the facts.
You are not required to have finished the technical investigation before you speak. You are required to say what you know and what you will look into. A defensible first notification says: an automated symptom checker was used, this is the advice it gave, here is what happened next, we are reviewing the tool's questioning logic with the supplier and will come back to you. An apology is required and, in England and Wales, section 2 of the Compensation Act 2006 provides that an apology is not of itself an admission of negligence or breach of statutory duty.
Limits, and when to take advice
Several points here are genuinely unsettled and should not be presented internally as though they were not. The UK medical device framework is under reform, and the class a triage tool carries under the current Medical Devices Regulations 2002 may be lower than the same product would take under EU MDR Rule 11; do not infer the rigour of the assessment from the marking alone. Under the EU AI Act, emergency healthcare patient triage systems are named in Annex III, and separately a regulated medical device requiring third-party conformity assessment is high-risk under Article 6(1); harmonised standards, implementing acts and the application timetable have all remained in motion, so verify against the current text rather than a summary. Where the AI Act applies, penalties reach up to 7% of global annual turnover for prohibited practices and up to 3% for most other obligations; data protection breaches reach up to 4%.
Take specialist advice where the incident may have contributed to death or severe harm, where litigation or a coroner's interest is foreseeable, where the vendor disputes the account or refuses to release logs, and before accepting any characterisation of the incident drafted by the supplier. The duty to be open with the patient is yours: your timetable, your words.
- Duty of Candour
- Healthcare AI
- Patient Safety
- EU AI Act
- Medical Devices
- UK GDPR