DSP Toolkit Assurance Auditing

NHS England Data Security

An independent assurance audit is crucial for the DSP Toolkit because it provides an independent and objective evaluation of an organisation’s data security measures. This process verifies the accuracy and reliability of the information submitted in the DSPT, ensuring that the organisation truly meets the required Standards.

What is the DSP Toolkit and Assurance Auditing?

The Data Security and Protection Toolkit (DSPT) is an online assessment tool designed to help organisations with access to NHS patient data and systems demonstrate their adherence to the National Data Guardian’s 10 data security Standards.

In addition, some organisations are required to have an Independent Assurance Audit. Assurance auditing is crucial for the DSP Toolkit because it provides an independent and objective evaluation of an organisation’s data security measures.

The deadline for the 2024-25 Data Security and Protection Toolkit and Assurance Auditing is 30th June 2025.

Our Independent DSP Toolkit Assurance Auditing Process

Gap analysis

Scoping

A pre-audit scoping exercise will help determine the audit’s scope

Find out more

Review

We will conduct an audit of your DSP Toolkit responses and review key evidence sets, to assess compliance with the DSP Toolkit requirements

Find out more

Report

We will provide a summary report of our findings, with individual and overall risk ratings, plus an overall confidence rating and detail any opportunities for improvement and upload this to the DSP Portal.

Find out more

Let us undertake an independent Assurance Audit for your business

DSP Toolkit Assurance Audits, must be undertaken by an independent competent auditor – and we are here to help.

Our expert team of competent auditors provide comprehensive support to guide you through the entire process, undertaking your assurance audit to verify that your organisation meets all the necessary DSP Toolkit security requirements.

Trust Teamwork IMS to make your DSPT Assurance Audit smooth and stress-free – get in touch here.

Why choose Teamwork IMS?

Experienced Professionals

Experienced Professionals

Teamwork IMS is a leading provider of Compliance and Sustainability solutions to a wide range of business sectors worldwide. Our solutions support compliance, expedite ISO certification, promote sustainability and drive improvement initiatives.  Our team of professionals includes MBCI, GDPR, ISEP, ESOS and ISO Lead Assessor, CMIOSH, CISSP, PCI Security Standards Council QSA qualified consultants.

Multi-disciplinary team

Multi-disciplinary team

Our knowledge and experience across a broad base of management and technical Standards make us uniquely equipped to help organisations to develop an information security management system and integrate with existing management systems to achieve significant savings and efficiencies.

Part of your business

Part of your business

The continued success of both the project delivery and maintenance phases of our Compliance and Sustainability programmes is built on two key principles:

 The exceptional insight of our consultants, who consistently go beyond the Standards and services to identify, define, and align with the core business drivers that truly matter to our clients

– Our unique ability to integrate effortlessly with our clients’ teams, fostering collaboration and trust, and becoming a valued extension of their operations.

Global credentials

Global credentials

We have developed and led IAF National accredited ISO as well as other Standard and compliance-based service improvement programmes for private and public-sector organisations across an international client base.

Frequently asked questions

What is the DSP Toolkit (DSPT)?

The Data Security and Protection Toolkit (DSPT) is an online self-assessment tool designed for organisations with access to NHS patient data and systems. It helps these organisations measure their data security practices, ensuring they meet NHS England’s required Standards for data protection and compliance. By completing the DSPT, organisations can demonstrate their commitment to safeguarding sensitive information and maintaining high levels of data security.

Why is assurance auditing important for DSPT?

Assurance auditing is crucial for the DSP Toolkit because it provides an independent and objective evaluation of an organisation’s data security measures. This process verifies the accuracy and reliability of the information submitted in the DSPT, ensuring that the organisation truly meets the required Standards. An assurance audit can identify potential weaknesses in data security practices, offering recommendations for improvement and helping to maintain compliance with regulatory requirements.

Who needs to complete the DSP Toolkit?

It is now a mandatory requirement for the following NHS organisations to complete an annual independent audit assessment as part of their submission:

  • NHS Trusts (Acute, Foundation, Ambulance and Mental Health)
  • Integrated Care Boards
  • Commissioning Support Units
  • DHSC Arm’s Length Bodies
  • IT Suppliers
What are the benefits of an independent DSPT audit?

An external and independent DSPT assurance audit offers several benefits, including:

  • Unbiased Review: An independent auditor provides an objective assessment of your data security practices, ensuring that your organisation meets the required Standards.
  • Identification of Weaknesses: The audit can uncover potential vulnerabilities in your data security measures, allowing you to address them proactively.
  • Regulatory Compliance: An external audit helps ensure that your organisation complies with data protection regulations, reducing the risk of penalties or breaches.
  • Continuous Improvement: Regular audits promote a culture of continuous improvement, helping your organisation stay up-to-date with the latest data security best practices.
How often should organisations undertake an independent assurance audit?

Assurance auditing should take place on an annual basis in conjunction with your annual submission of the DSP Toolkit.  Regular audits help ensure that any changes in regulations or best practices are promptly addressed to provide ongoing assurance that your organisation is effectively safeguarding sensitive information.

Related Standards

ISO 27001

ISO 27001

Information Security Management System Certification (ISMS)

Cyber Essentials

Government-backed cyber security scheme

GDPR

GDPR

Meet your compliance obligations and build customer trust.

PCI DSS & QSA

Payment Card Industry Data Security Standard Consultancy and Assessment.

Get in touch today

    Name

    Email address

    Phone number

    Where did you first hear about us?

    Message

    Latest news and articles from Teamwork

    Inspiration Healthcare Group PLC Achieves ISO 14001 Certification

    Who are Inspiration Healthcare? Inspiration Healthcare Group is a pioneering, UK-based medical technology company who specialise in the design, manufacture and…

    Diktamen achieve ISO 9001, 14001 & PPN006 compliant carbon reduction plan

    Who are Diktamen? Headquartered in Helsinki, Finland – Diktamen offer Dictation, Documentation Workflow and Task Management AI-Powered Solutions For Healthcare…

    Advania UK achieve the TISAX® Label (Certification)

    Who are Advania UK Ltd? Part of the Advania Group, Advania UK Limited is a technology services business and managed…