Powering the UK's most efficient NHS Right To Choose providers

Making AI clinical reports hold up at audit: a UK framework

AI can draft a report in minutes, but the clinician who signs it has to be able to defend it. The founder of Cerebric on five things an AI clinical report needs to hold up at audit.

Dr. Moniem Abdu· Founder & CEO, Cerebric· 11 March 2026· 11 min read
Cerebric LogoCerebric
Compliance

An AI clinical report that holds up at audit needs five things: every statement linked to its source, a clinician checking it section by section, a record of what changed from the AI draft, quality checks (QA gates) before approval, and a clinical safety process under DCB0129. This is the framework we built Cerebric around, and the one I would use to judge any tool that drafts clinical reports, ours included.

Can AI write diagnostic reports?

When clinicians ask me whether AI can write diagnostic reports in the UK, I suggest a different question. What matters is that the report meets the same standard it always did, and that responsibility for it still sits with the clinician who signs it.

It helps to be clear about what "write" means here. The software drafts and organises the notes from evidence the clinician has gathered. It does not assess the patient, decide what the findings mean, or reach a diagnosis. AI cannot make a diagnosis and cannot help make one. Whether a person meets the criteria for a condition is a clinical decision, made by a qualified clinician, and no part of that decision is handed to software. A tool like this helps with the paperwork and the workflow around it. If a product starts to weigh up the evidence or steer the clinical conclusion, it becomes a different kind of device with a higher bar to clear with the regulator (more on that under Property 5).

The GMC's Good medical practice, in force since 30 January 2024, requires that formal records of your work, including patients' records, are "clear, accurate, contemporaneous and legible" (contemporaneous meaning written at the time). It says nothing about who, or what, typed the first draft. If the report is wrong, the clinician who signed it is responsible for the error, whatever tool wrote the first draft.

So the real question is whether you can defend what it wrote: in a complaint, at a tribunal, during a CQC inspection, in a clinical audit, or when a patient uses their right to see their records. That takes evidence, and the evidence comes from the system that made the report.

What makes an AI clinical report hold up at audit

A clinical report holds up at audit when, for any sentence, you can show four things: where the information came from, who checked it, what changed between the AI draft and the signed version, and what clinical safety process covered the tool that wrote it.

Building Cerebric with UK neurodevelopmental services, I have come to think of this as five properties. Each one gives part of the evidence an auditor will ask for:

  1. A source for every claim: every factual sentence shows where it came from.
  2. Checked by a clinician: recorded, section by section.
  3. Change tracking: a record of what changed between the AI draft and what was signed.
  4. QA gates: checks that must pass before approval.
  5. A clinical-safety home: DCB0129 paperwork and a named Clinical Safety Officer.

The chain of evidence behind a report that holds up at auditA source for every claimevery sentence cites its sourceChecked by a clinicianrecorded, section by sectionChange trackingAI draft compared with signed versionQA gateschecks pass before approvalClinical safety recordsDCB0129 plus a named CSOA report holds up at audit only when all five are in place, and auditors look at this evidence trail. The clinician checks each section, signs the report and remains fully responsible for it.The five properties of a report that holds up at audit, in the order a report is made.

Property 1: a source for every claim

This means every factual sentence in the report is linked to the evidence it came from: a timestamp in the assessment transcript, an answer on a scored questionnaire, a line in a school report or GP referral.

AI making things up (hallucination) gets most of the attention. For an audit, the bigger problem is that without a source, a true sentence and a made-up one look the same. Two years after an assessment, a tribunal may ask how you knew the patient's symptoms were there before age twelve. You need to point to where that came from, such as the exact minute of the recorded assessment where it was discussed.

Auditors ask where a statement came from. To answer, the citations must be stored with the report, made when it is drafted and kept after signing, not pieced together from memory or produced again when someone asks.

We built Cerebric around this property. Every sentence of an AI-drafted report can be traced back to its source (a transcript timestamp, a questionnaire answer, or a document), and the clinician checks each one in Split View, evidence on one side, draft on the other. Whatever tool you use should be able to do the same.

Property 2: checked by a clinician

This is a fixed, recorded process where a named clinician checks each part of the draft against the evidence before signing. If the check is not recorded, an auditor cannot tell whether it happened.

A single "approve" at the end of a twenty-page document, on its own, tells an auditor little about what was actually checked. Section-by-section sign-off (history, informant evidence, mental state, diagnostic reasoning, recommendations) creates a fuller record that a person actually worked through each part.

The usual objection is time. At the clinics using Cerebric, writing a report used to take around two hours and now takes under 30 minutes.

Measured at UK Right to Choose and private neurodevelopmental providers using Cerebric, 2025–26.

Time to produce a report, before and afterWritingWith Cerebric: under 30 minutes totalWriting time removedBefore: writing about 2 hoursWriting about 2 hoursWith Cerebric: under 30 minutes totalDraft and checkDrafting drops to minutes, but the clinician still reviews and checks every section before signing, and that review is part of what makes the report hold up at audit. The whole pass, draft to signature, now finishes in under 30 minutes, over one and a half hours saved per report.Measured at UK Right to Choose and private neurodevelopmental providers using Cerebric, 2025–26.

Checking still takes time, but much less than writing, and it is the part only a clinician can do. "I was sceptical about AI in clinical work, but Cerebric genuinely feels like it was built by people who understand the pressures we face. It slots into my workflow without adding friction," a clinical lead at one provider told us. A recorded check lets clinicians who are unsure about AI use the tool and still review everything it drafts.

Property 3: change tracking against the AI draft

Change tracking means the system keeps the AI's original draft and records every edit the clinician made before signing. It is a record of the difference between what the AI wrote and what went out.

This matters in both directions. If you changed a great deal, the record shows clinical judgement being used: a strong answer to "did a human really review this?". If you changed nothing, the record shows that too, and an auditor may fairly ask whether any checking happened at all. Either way, the record needs to exist. Without it, all you have is someone's word that the draft was read.

An auditor, or a claimant's solicitor, will ask to see what the AI wrote and what the clinician changed. Copying and pasting from a chat window into your clinical system wipes that record the moment you paste. In Cerebric, sections can be redrafted and edited, and the change history is kept after approval.

There is another benefit. The edits clinicians make most often show where the drafting is weak, so change tracking also shows where it needs improving.

Property 4: QA gates before approval

A QA gate is a check that must pass before a report can be approved and sent: a fixed checklist at sign-off, rather than a general hope that everyone "reads things carefully".

Diagnostic reports fail in predictable ways:

  • a section missing;
  • an informant questionnaire mentioned but never scored;
  • recommendations that do not match the stated diagnosis;
  • the wrong patient details after a template change.

Gates let you check for each of these. In Cerebric, approval runs through QA checklists that each clinic sets up for each report template, and redrafting a section does not skip them.

Here auditors want to know that every report, from every clinician, meets the same standard, and how you know. It is hard to prove that each person is careful across a whole service. A gate record attached to every report you send is the kind of evidence a CQC inspection looks for under well-led: a written process, applied the same way every time, with records to prove it.

Property 5: a clinical-safety home

Health IT used in UK care has to meet clinical safety standards, and AI tools that write clinical notes are no exception. The main one is DCB0129, a required NHS standard for the companies that build health IT, set under the Health and Social Care Act 2012. It asks the company that makes the software to manage clinical risk from the start and to prove it, with three things:

  • A hazard log: the risks and how each is handled.
  • A clinical safety case: the written case that the product is safe for what it is meant to do.
  • A named Clinical Safety Officer: a registered clinician who is responsible for it.

A partner standard, DCB0160, puts matching duties on the provider that uses the system, which means you.

When digital tools are bought for the NHS, the DTAC checklist asks suppliers for this safety evidence, alongside data protection, security, interoperability (working with other systems) and usability.

StandardWho it applies toWhat it asks for
DCB0129The company that makes the software (the vendor)A process for managing clinical risk, backed up by a hazard log, a clinical safety case report and a named Clinical Safety Officer
DCB0160The healthcare provider using it (you)Matching duties: set the system up for your pathway, train staff, manage the risks of day-to-day use, keep your own safety case
DTACThe buying process between you and the vendorAsks the supplier for the clinical safety evidence, plus data protection, technical security, interoperability and usability
MHRA / UKCAThe software maker, decided by intended purposeSoftware meant to inform diagnosis or treatment is a medical device, usually Class IIa or above; a documentation and workflow tool that leaves every clinical decision to the clinician sits lower

For our part, Cerebric is registered as a UKCA Class I medical device, a documentation and workflow tool whose intended purpose is not to make or inform the diagnosis. The clinician carries out the assessment, reaches the diagnosis and signs the report; Cerebric drafts and organises the notes they check. We run a DCB0129 clinical safety process, and our full position is on our compliance page. Ask any vendor for the same paperwork, and treat vague answers as a big gap.

The pipeline nobody can check

The other option is what I call the pipeline nobody can check: a clinician pastes case details into a general chat tool, gets back well-written text, and pastes it into the clinical record.

The problem here is not how well it writes. Current AI models often write well, and clinicians working this way are usually trying to clear a real backlog with the tools they have. The problem is that it leaves no evidence:

  • No source for each statement. The sources live in the prompt and vanish with it.
  • No record of checking. Reading the output leaves no trace.
  • No record of what changed. Pasting wipes the draft history.
  • No QA gates.
  • Usually no clinical-safety home. No hazard log, no safety case, no Clinical Safety Officer, and often no clear answer on where patient data was processed.

Here are the five properties side by side.

PropertyPipeline that holds up at auditPipeline nobody can check (paste into a chat window)
A source for every claimCitation stored with the report when it is draftedSources live in the prompt and vanish with it
Record of checkingSection-by-section sign-off loggedReading the output leaves no record
Change trackingRecord of what changed from AI draft to signed version survives approvalPasting wipes the draft history
QA gatesChecklist you set up must passNone
Clinical-safety homeDCB0129, hazard log, named CSONo safety case, data location unclear

The same point applies, more gently, to ambient AI scribes. They do what they are built for: turning a consultation into a note, with a human check. But a neurodevelopmental diagnostic report pulls together evidence gathered over months (screening, patient and informant questionnaires, school documents, a structured assessment). No scribe was built to track sources across that span. I have written more on the difference in AI scribes vs assessment platforms.

A better AI model would not fix this, because the gaps are in the process around the model.

Five questions to ask before signing

Before any AI-drafted report goes out under your name, you should be able to answer five questions with evidence, not promises:

  1. Source: can I show the source for any sentence in this report?
  2. Checking: where is it recorded that a named clinician checked each section?
  3. Change tracking: can I produce the AI draft and show what changed before signing?
  4. QA gates: which checks had to pass before approval, and where is the record?
  5. Clinical safety: who is the vendor's Clinical Safety Officer, and can they show me a hazard log, a clinical safety case report, and their MHRA registration status?

If you can answer all five, you have a drafting process you can defend. If you cannot, start with the questions you could not answer.

Frequently asked questions

Can AI write diagnostic reports in the UK?

It can draft the report, but it does not make the diagnosis. What matters is scope: the software drafts and organises the notes from evidence the clinician has gathered, while the assessment, what the findings mean and the diagnosis stay clinical decisions made by a qualified clinician. The GMC's expectations have not changed: formal records must be clear, accurate, written at the time and legible, and the clinician who signs stays fully responsible for what the report says. AI drafting holds up only when the system around it links each statement to its source, records the clinician's checks section by section, tracks changes, and runs quality checks before approval.

What is DCB0129 and does it apply to AI report-writing tools?

DCB0129 is a required NHS standard for managing clinical risk, published under section 250 of the Health and Social Care Act 2012. It applies to the companies that make health IT systems, including AI tools that write clinical notes. They need a process for managing clinical risk, backed up by a hazard log, a clinical safety case report and a named Clinical Safety Officer. Buyers should ask any vendor for this paperwork before they start using the tool.

Is AI report-writing software a medical device in the UK?

It depends on intended purpose. The MHRA's guidance on software and AI as a medical device makes intended purpose the deciding factor: software meant to give information that informs diagnosis or treatment can count as a medical device, and is usually Class IIa or higher. A tool whose intended purpose is to support documentation and workflow, and which does not weigh up the evidence or play any part in the diagnosis, sits at the lower end. Ask any vendor whether their product is registered with the MHRA, in which class, and what intended purpose that class is based on. Cerebric is registered as a UKCA Class I medical device: its intended purpose is to support documentation and workflow, with the assessment and diagnosis carried out by the clinician.

What will an auditor or CQC inspector ask about AI-drafted reports?

Expect specific requests for evidence: show the source for a statement, show who checked each section and when, show what changed between the AI draft and the signed report, and show the quality checks that ran before approval. Inspectors also look for the supplier's clinical safety paperwork: DCB0129 compliance, a hazard log and a named Clinical Safety Officer.

Does using AI reduce a clinician's responsibility for report accuracy?

No. Responsibility sits with the clinician who signs the report, just as it did before AI. That is why the checking process matters more than how well the AI writes: a recorded, section-by-section check is what shows you used your clinical judgement on the report, and did not approve the AI's output unread.

Citations

Join leading practices already using Cerebric