30-second briefing
The evidence and the decision
- The 29 September guidance covers the supplier lifecycle, including transition and exit.
- Agree who removes old access and what evidence will verify the handover.
- Secure email needs suitable standards and configuration, alongside a usable staff process.
Changing an IT supplier can leave a service with two kinds of uncertainty: whether the new support works and whether the old supplier still has access. A completed procurement does not answer either question.
DHSC published guidance on choosing and managing software and IT suppliers on 29 September. Its treatment of onboarding, support and the end of a relationship provides a practical basis for examining the whole supplier lifecycle. This retrospective follows that September publication into provider oversight.
Map the service being handed over
Describe the systems, devices, support arrangements and documentation within the supplier’s role. Identify other organisations whose work depends on the change. A generic promise to support IT may conceal important exclusions or dependencies.
An illustrative handover could involve care records, network management and email being supported by different organisations. The incoming supplier needs an agreed account of its responsibility. The provider needs to know who will respond when an issue crosses those boundaries.
Access needs an owner on the provider side
The guidance identifies removal of previous supplier access and changes to relevant credentials as part of a transition. The provider should obtain suitable evidence that the agreed actions were completed and understand any access intentionally retained.
A list of technical accounts is useful only if someone can explain the purpose and authorisation. The provider’s accountable lead should know who approves changes, who verifies them and how an urgent exception is handled. This is an oversight question as well as a technical task.
Agree the exit before the relationship becomes difficult
Ask how records, configuration information and necessary documentation will be returned or transferred. Understand the applicable contract terms and any dependencies on third parties. If the supplier processes personal information, obtain appropriate advice about the relevant data-protection arrangements.
A testable exit plan describes formats, responsibilities and continuity requirements. It should not assume that paying for a service automatically guarantees a simple export or an immediate handover. Commercial and technical details need to meet in the same plan.
Treat email configuration as part of the service
The separate secure-email guidance published on the same day explains that secure communication depends on the relevant standards and configuration. Buying a familiar platform is not, on its own, an account of compliance or a safe workflow.
Include staff support, the routes for sharing sensitive information and the response to misdirected messages in the discussion with the responsible leads. October’s AI and outage coverage extends the same question: can the provider explain and own the process behind the technology?
Questions leaders should ask now
- 01
What exactly is being transferred?Map systems, documentation and support boundaries.
- 02
Has old access been removed?Agree ownership and appropriate verification.
- 03
Can we leave the next contract safely?Define export, handover and continuity before signing.
The Care Circle view
Supplier assurance includes the ending
A good relationship is easier to govern when the provider understands how it starts, changes and ends. The handover should leave an intelligible service and a clear access record.
Care Circle will examine those practical conditions rather than equate a supplier’s reputation with evidence of local control.
Continuing coverage
Follow the question into the later editions.
Care runs around the clock. Does your IT contract? · 10 October 2026
After the rating: the evidence a board needs this month · 9 October 2026
Beyond the toolkit: rehearse the care-record outage · 9 October 2026
How the story develops
Continue from the earlier evidence.
This feature develops a continuing leadership question. Earlier publication dates and evidence periods remain visible.
The evidence reset: follow an issue until care changes · 4 August 2026
July insurance changes: why care providers still need clear risk and claims evidence · 28 July 2026
Develop the analysis
Read the connected flagship reports.
Workforce & delivery: turning sector improvement into dependable care
Digital continuity: can the care service depend on its systems?
Operational assurance: suppliers, equipment and resident voice
Sources, method & limitations
How to read this analysis
September 2026 retrospective, first published and source-reviewed on 9 October 2026. The period discussed is September; this article was not published then. Official statements are attributed to the publications below. Illustrative scenarios and management questions are editorial analysis, not interviews or provider survey findings.
- No provider-specific assessment, eligibility decision or prediction of regulatory outcomes is made.
- Source publication dates and this edition’s review date are separate. Local arrangements and later updates may change the position.
- Suggested management actions support discussion with appropriately qualified advisers; they do not replace individual care planning or professional judgement.