Requirements - Solution Design & Methods - SD03 - Standards Compliance

The solution should be compliant with relevant standards.

Requirement description

This requirement is concerned with ensuring that the solution complies with the technical, architectural, security, interoperability, data, regulatory and industry standards that apply to the service.

Compliance should be actively assessed and evidenced rather than assumed. Relevant standards may originate from NHS England, central government, regulatory bodies, technology suppliers, industry best practice or statutory obligations.

The standards selected should be appropriate to the nature of the solution and its operating environment. Any exceptions or departures should be documented, understood and appropriately governed.

In simple terms:
The solution should demonstrate compliance with the standards that apply to it and be able to justify any exceptions.

Scoring rubric table – SD03 Compliance with Relevant Standards

Score What it looks like Typical evidence Key gaps / risks
0 No evidence that applicable standards have been identified or assessed. No compliance assessments.
No standards register.
No governance review.
No documented compliance activity.
Significant service risk. The solution may breach mandatory requirements, create interoperability problems, or introduce security and operational weaknesses.
1 Limited awareness of relevant standards. Compliance is largely assumed rather than demonstrated. Informal discussions.
Undocumented assumptions.
Limited references to standards.
No structured compliance assessment.
High-risk gaps. Important requirements may not have been identified or validated.
2 Some standards have been identified and assessed, but coverage is incomplete or inconsistently evidenced. Partial compliance assessment.
Limited traceability to standards.
Some architecture review activity.
Basic governance involvement.
Significant notable gaps. Important standards may not have been considered or compliance evidence may be weak.
3 Much of the solution demonstrates compliance with relevant standards and supporting evidence exists for most significant areas. Compliance assessments.
Architecture review outputs.
Solution documentation.
Standards mapping exercises.
Documented remediation activities where gaps exist.
Notable gaps remain. Some standards may not have been fully assessed, evidence may be incomplete, or remediation activities remain outstanding.
4 Most relevant standards have been assessed and the solution demonstrates strong compliance. Deviations are documented and governed. Comprehensive standards compliance assessment.
Traceability between standards and solution design.
Governance review records.
Approved exceptions.
Compliance remediation tracking.
Minor gaps only. Remaining non-compliance is understood, documented and actively managed.
5 Comprehensive and exemplar standards compliance. Compliance activities are embedded within design, governance and delivery processes. Comprehensive compliance evidence.
Regular standards reviews.
Proactive monitoring of standards changes.
Governance oversight.
Clearly managed exception process.
Evidence that standards compliance directly influences architecture decisions.
Minimal or no significant gaps. Compliance is continuously managed and contributes to high-quality architecture outcomes.

What assessors should look for

  1. Identification of standards – Has the team identified the standards that apply to the solution?
  2. Compliance assessment – Has compliance been formally assessed and evidenced?
  3. Traceability – Can compliance claims be traced to architecture artefacts, requirements or technical implementation?
  4. Exception management – Are deviations documented, justified and approved through governance?
  5. Governance involvement – Has compliance been reviewed through appropriate architecture or assurance processes?
  6. Ongoing compliance – Is compliance reviewed as standards, technologies or solution designs evolve?

What separates a 3 from a 4 or 5

A score of 3 generally indicates that most significant standards have been considered and there is acceptable evidence of compliance, but gaps remain in coverage, evidence quality, governance or ongoing monitoring.

A score of 4 requires a structured and comprehensive compliance approach. Relevant standards are assessed, compliance evidence is maintained, and any exceptions are documented and governed.

A score of 5 requires standards compliance to be embedded within architecture and delivery practices. Compliance is actively monitored, changes in standards are tracked, and evidence demonstrates continuous improvement beyond basic compliance expectations.

Suggested evidence examples (not SAF-mandated artefacts)

  • Standards compliance assessments
  • Architecture review reports
  • Solution Design Overview (SDO) documents
  • Architecture Decision Records (ADRs)
  • Technical standards mappings
  • Security and interoperability assessments
  • Governance and Design Authority review outputs
  • Approved waivers or exception records
  • Compliance remediation plans
  • Assurance and audit reports

Updated: 04 September 2026 (SAF Version 1.1)