The Accountability Gap - question by question
These are the questions we are most often brought in to answer, and the reason is consistent: each one requires somebody to hold the whole picture, and in most provider organisations nobody does. Operations owns the day-to-day, finance owns the invoices, an MSP owns the tickets, and the clinical software vendor owns its own product. The space between them is unowned.
| The question | Why it goes unanswered | What the board actually needs |
|---|---|---|
| What are our material technology risks, and which are we accepting? | Risks are held as helpdesk tickets and vendor caveats, never aggregated or rated. Nothing reaches the risk register. | Technology risk expressed in the same register, rating scale and review cycle as clinical and workforce risk, as Outcome 2.4 requires. |
| Is our technology spend buying capability or holding off failure? | Spend arrives as renewals and incidents. There is no baseline for what is maintenance and what is investment. | A multi-year view separating run cost from change, so the board is approving a direction rather than a series of invoices. |
| If a system is unavailable for three days, what happens to care? | Continuity planning stops at backups. Nobody has traced a system outage through to its clinical consequence. | Dependency mapping from each system to the care activity it supports, feeding business continuity under Outcomes 2.4 and 2.10. |
| Who is accountable when the clinical system and the network disagree? | Each supplier is individually blameless and collectively the problem is unresolved. | One accountable party who can direct both, rather than relay messages between them. |
If your board cannot answer all four, the issue is rarely the quality of your IT support. It is that oversight of technology has no owner, and an obligation without an owner is the definition of an audit finding waiting to happen.