Requirements - Solution Design & Methods - SD02 - NHSE Principles

The solution should be compliant with NHS England principles, policy, patterns and best practice.

Requirement description

This requirement is concerned with ensuring that solution designs align with established NHS England architectural principles, organisational policies, approved patterns and recognised best practices.

The intent is to encourage consistency across the NHS England technology estate and reduce the risks that arise when teams create bespoke approaches that diverge from agreed standards. Compliance should be deliberate and demonstrable, rather than assumed.

Where deviations from principles, policies or patterns are necessary, they should be documented, assessed and approved through appropriate governance processes.

In simple terms:
Design solutions in line with NHS England's agreed ways of working, and justify any exceptions.

Scoring rubric table – SD02 Compliance with Principles, Policies, Patterns and Best Practice

Score What it looks like Typical evidence Key gaps / risks
0 No evidence that NHS England principles, policies, patterns or best practices have been considered during solution design. No compliance assessment.
No architecture rationale.
No governance evidence.
No documented alignment activity.
Significant service risk. The solution may conflict with organisational standards, increase technical debt or create operational and governance issues.
1 Limited awareness of relevant principles, policies or patterns. Alignment is assumed rather than evidenced. Informal discussions.
Undocumented assumptions.
Limited architecture review activity.
No structured compliance assessment.
High-risk gaps. Important requirements may be missed and non-compliance may remain unidentified.
2 Some relevant principles, policies or patterns have been considered, but assessments are incomplete or inconsistently applied. Partial compliance assessments.
Basic architecture reviews.
Some references to policies or patterns.
Limited exception documentation.
Significant notable gaps. Important standards may not have been assessed or supporting evidence may be missing.
3 Much of the solution demonstrates alignment with relevant principles, policies and approved patterns. Most significant areas have supporting evidence. Architecture compliance assessments.
Solution Design Overview documentation.
Architecture Decision Records.
Governance review outputs.
Documented alignment to organisational standards.
Notable gaps remain. Some requirements may not have been assessed, deviations may lack approval, or evidence may be incomplete.
4 Most relevant principles, policies, patterns and best practices have been assessed and the solution demonstrates strong alignment. Comprehensive compliance assessment.
Documented policy and pattern alignment.
Approved exception records.
Governance reviews.
Traceability between requirements and solution design decisions.
Minor gaps only. Remaining deviations are understood, documented and considered low risk.
5 Comprehensive and exemplar compliance. Alignment to principles, policies, patterns and best practice is embedded throughout solution design and governance activities. Comprehensive compliance evidence.
Regular review against evolving standards.
Well-managed exception process.
Architecture governance endorsement.
Evidence that compliance considerations actively influence design decisions.
Contribution to organisational best practice and reuse of approved patterns.
Minimal or no significant gaps. Compliance is proactively managed and supports long-term architectural consistency.

What assessors should look for

  1. Compliance assessment – Has the team evaluated the solution against relevant NHS England principles, policies and patterns?
  2. Evidence of alignment – Can the team demonstrate how the design complies with organisational expectations?
  3. Use of approved patterns – Are recognised architecture or solution patterns being used where appropriate?
  4. Exception management – Are departures from approved standards documented, justified and approved?
  5. Governance involvement – Has compliance been reviewed through appropriate architecture governance processes?
  6. Ongoing maintenance – Is compliance periodically reviewed as requirements, policies and architecture evolve?

What separates a 3 from a 4 or 5

A score of 3 generally indicates that the solution appears broadly compliant and there is reasonable supporting evidence, but assessments may be incomplete, governance evidence may be limited or some exceptions may not be fully documented.

A score of 4 requires clear and structured evidence that relevant principles, policies and patterns have been assessed and that any deviations have been consciously managed through governance.

A score of 5 requires compliance to be embedded within the architecture lifecycle. Evidence should show proactive management of standards alignment, effective governance and consistent use of approved patterns and best practices across the solution.

Suggested evidence examples (not SAF-mandated artefacts)

  • Architecture compliance assessments
  • Solution Design Overview (SDO) documents
  • Architecture Decision Records (ADRs)
  • Policy compliance reviews
  • Pattern selection assessments
  • Architecture governance papers
  • Design Authority or TRG review outputs
  • Approved exception or waiver records
  • Technical standards assessments
  • Architecture review and assurance reports

Updated: 04 September 2026 (SAF Version 1.1)