Skip to main content

NHS England Post Audit Review: South East London Integrated Care Board

This report provides the formal closure of the remote data sharing audit of NHS South-East London Integrated Care Board (SEL ICB) between 8 and 22 September 2025.

Audit summary

Purpose

This report provides the formal closure of the remote data sharing audit of NHS South-East London Integrated Care Board (SEL ICB) between 08 and 22 September 2025 against the requirements of:

  • the data sharing framework contracts (DSFC) CON-739910-L4J3M-v2.03
  • the data sharing agreement (DSA) DARS-NIC-615981-K2W5D-v4.3
  • the organisations’ own policies, processes and procedures

Details of the datasets received under this DSA can be found in the original report - NHS SEL ICB Data Sharing remote Audit.

The Controller is SEL ICB, and the Processors are NHS North Central London Integrated Care Board (ICB), NHS North-East London ICB, NHS North of England Commissioning Support Unit, NHS North-West London ICB, NHS South West London ICB, Snowflake Computing UK Limited (Snowflake) and Microsoft Limited. Microsoft Limited does not have access to the data and only provides cloud hosting services.

Post Audit Review 

This post audit review comprised of a desk-based assessment of the action plan and supporting evidence supplied by SEL ICB between April to July 2026.

Post Audit Review Outcome 

Based on the evidence, the Audit Team has found that SEL ICB has not suitably addressed all the findings. 1 point for follow-up (Ref 6) whilst closed from an audit perspective still requires further action in order to ensure it is fully addressed.

Updated risk statement

Based on the results of this post audit review the risk statement has been reassessed against the options of Critical - High - Medium - Low.

Original risk statement: Medium

Current risk statement: Low

Data Recipient’s Acceptance Statement 

SEL ICB has reviewed this report and confirmed that it is accurate.


Findings

The following table identifies the 3 agreement nonconformities and 4 points for follow-up raised as part of the original audit.

SEL ICB

Ref Finding Link to area Update Designation Status
1

There were no contractual arrangements provided to evidence arrangements between SEL ICB (the Controller) and Snowflake (the Processor).

Following the audit SEL ICB have provided additional information which clarifies the arrangements between all the parties going forwards.

Operational Management

Additional supporting information, which clarified contractual arrangements between the Controller and Processor, was provided to the Audit Team shortly after the original audit.

Agreement nonconformity

Closed
2

There was no up-to-date Memorandum of Understanding (MoU) between NEL ICB (Host for OneLondon) and SEL ICB.

Following the audit SEL ICB provided an up-to-date MOU with NEL ICB.

Operational Management

An up-to-date MoU which set out the arrangements between both NEL ICB and SEL ICB, was provided to the Audit Team shortly after the original audit.

Agreement nonconformity

Closed
3

Liaison Financial Services Limited is not named on NHS England’s list of Controlled Environment for Finance organisations against SEL ICB.

Access Control

SEL ICB have had dialogue with the Data Access Service (DAS) within NHS England and have ensured Liaison Financial Services Limited have been removed as a processor from the latest version of the DSA (DARS-NIC-615981-K2W5D-v6.2).

Agreement nonconformity

Closed
4

At the post audit review the Audit Team will review sub-licencing arrangements to confirm compliance with the DSA.

Access Control

Sub-licensing arrangements have been updated and reflected in the latest version of the DSA (DARS-NIC-615981-K2W5D-v6.2). A copy of the latest DSA showing these changes was provided to the Audit Team.

Follow-up

Closed
5

At the post audit review the Audit Team will review plans being developed for the OneLondon Secure Data Environment (SDE) and ensure they align with the updated DSA.

Access Control

The OneLondon proposal is currently on hold with no indication of when this will change.

Follow-up

No longer applicable
6

At the post audit review the Audit Team will review the updated Data Protection Impact Assessment (DPIA) for the Snowflake platform.

Operational Management

SEL ICB have been unable to review and update the DPIA at the time of this post audit review. No issue with the content was identified during the original audit. Whilst this finding has been closed, SEL ICB should ensure as a priority that a review is undertaken when appropriate resource become available.

Follow-up

Closed
7

At the post audit review the Audit Team will review the exemption process outlined in the Equipment and Acceptable Use Policy to confirm that it has been updated to specify that NHS England data can only be accessed from within the permitted territory of use.

Access Control

Strict technical controls prevent staff from using SEL ICB provided equipment abroad. In addition to this the Equipment and Acceptable Use Policy, while not specifically providing reference to NHS England, does include a thorough and comprehensive section which outlines the considerations, checks and approval gateways required to be completed by staff in order to work abroad. It also clearly sets out the consequences of not seeking and gaining such approval.

Follow-up

Closed

Disclaimer

NHS England takes all reasonable care to ensure that this audit report is fair and accurate but cannot accept any liability to any person or organisation, including any third party, for any loss or damage suffered or costs incurred by it arising out of, or in connection with, the use of this report, however such loss or damage is caused. NHS England cannot accept liability for loss occasioned to any person or organisation, including any third party, acting or refraining from acting as a result of any information contained in this report.

Last edited: 24 July 2026 4:41 pm