Automated verification: the questions to ask before you buy a credentialing platform

Automated verification: the questions to ask before you buy a credentialing platform

Two supplier responses sit side by side on the scoring sheet. The clause they answer asks every supplier of automated verification for evidence of compliance with the legislation and standards governing artificial intelligence. Both have written that a person confirms the decision before it takes effect. Both attach a policy. Neither response tells the panel where that person sits in the sequence that clears a consultant for Monday's theatre list, or whether they had the information and the authority to disagree with the system. The two score the same, and the real difference between them never reaches the sheet.

The clause has no good answer yet, and two things caused the gap. The badge you hoped to rely on is barely a badge yet, and the law the clause points at was rewritten in February. The fourteen questions below produce different answers from different suppliers, and a buyer who asks them has framed the automated verification decision properly.

The assurance infrastructure you wanted to rely on is seven months old

The Department for Science, Innovation and Technology published its report Trusted third-party AI assurance roadmap on 3 September 2025. On certification it said: "There are existing certifications that can demonstrate competencies in AI assurance. However, it is difficult to ascertain their quality, and none are issued by UKAS-accredited organisations."

That changed on 15 January 2026, when UKAS granted BSI "the first accreditation for certification of artificial intelligence (AI) management systems to ISO/IEC 42001:2023".

Three claims look alike in a tender response and mean different things. Aligned is self-attested. Certified means a certification body audited the organisation and issued a certificate. Accredited certification means the certifying body is itself accredited, in the UK by UKAS, possible for ISO/IEC 42001 only since January 2026. Ask which rung a supplier of automated verification stands on, and who issued the certificate.

Then read the standard's scope. ISO notes that it "provides a practical way of managing AI-related risks and opportunities across an organization" instead of "looking at the details of specific AI applications". A certificate says nothing about whether one candidate decision was correct.

No regulator will define this for you before you sign

Article 22 of the UK GDPR no longer exists. Articles 22A to 22D replaced it on 5 February 2026, under the Data (Use and Access) Act 2025. The prohibition the old article opened with survives only for special category data and for one narrow lawful basis. Whether a decision counts as solely automated now turns on Article 22A(1)(a) and its test of "meaningful human involvement in the taking of the decision". No regulations have been made under Article 22D, the power the Secretary of State would use to define that phrase. The ICO's guidance on automated decision-making is still draft.

You are the controller, and no external definition is going to arrive in time to make this decision for you. Asking whether a platform makes automated decisions produces a yes from every supplier and separates none. What scores is whether it can evidence the Article 22C safeguards for every significant decision taken with no meaningful human involvement.

Where the automated verification boundary sits, check by check

  1. Which checks does the platform complete without a person in them, and which stop for a person? Ask per check type: right to work, professional registration, criminal record, occupational health, references, indemnity. One answer for the whole platform means the boundary has not been set.
  2. Can we configure the automated verification boundary ourselves, per check and per role? Article 22A(1)(a) is tested decision by decision, so a reference check on a healthcare assistant and a consultant's registration check need not sit on the same side of the line.
  3. What does the product require a reviewer to do before the record moves on? The ICO's draft guidance says a human should "assess and review the decision at an appropriate point to ensure actual impact on the outcome" and hold "discretion and authority to alter the decision".
  4. Does every decision of that type get a human, or does a sample? The same guidance: "Using ad hoc spot-checking isn't sufficient because some automated decisions won't receive a check".
  5. Does the human step happen before the outcome reaches the candidate? The ICO expects involvement "before you apply the decision to a person and at a time you can still change any recommendation". Designing the system does not count.

Your reviewer will see less than the system did

  1. On the review screen, what can the reviewer see that the automated step did not use? From the ICO's AI guidance, dated March 2023 and under review: "If human reviewers can only access or use the same data used by the AI system... the decision may end up being considered as 'solely automated'."
  2. What does the platform record about the reviewer's part? The ICO is direct: "You should keep a record of how the human was involved in the decision." Ask to see the log fields: who opened the record, what was on screen when they did, whether they changed the outcome, and when.
  3. How does the platform find and correct its own errors? The ICO expects "manually reviewing a sample of automated decisions, to identify any bias or discriminatory effects", with corrective action "such as adjusting thresholds, re-training or updating the model". Ask whether your team can pull the sample.
  4. If the product uses a confidence score, who sets the threshold and what happens below it? No UK statute or regulator requires a confidence score or defines a threshold. A supplier presenting thresholds as a compliance standard is worth marking down.

The candidate contests it, and you have a month to answer

  1. Can the platform produce an audit trail of the decision itself? The ICO's wording reads like a specification: "You should use a system that is able to deliver an audit trail showing the key decision points that formed the basis for the decision".
  2. Can it explain one decision about one named person, in plain language? The ICO and Alan Turing Institute guidance, under review because of the Data (Use and Access) Act, separates two kinds of explanation. A process-based explanation covers system governance, and an outcome-based explanation covers a particular case. A supplier with only the first has no answer for the candidate.
  3. Where does a candidate get told the decision was automated, make representations, request human intervention and contest the result? Those four are the Article 22C(2) safeguards. Require a walkthrough of those four screens.
  4. Does the platform ever take a significant decision on health or occupational health information without meaningful human involvement? That is special category data under Article 9, and Article 22B(1) blocks such a decision unless one of two conditions is met.
  5. What response times will the supplier commit to contractually? The statutory clock sits on you: one month from the request. That extends by two months for complex or multiple requests, if you notify the person inside the first month. A supplier silent on review requests at service level has taken none of that load.

The same evidence populates your data protection impact assessment, so run both exercises together.

What DTAC, DSPT and the EU AI Act do not require of you

Suppliers offer all three, and none answers the question you asked. NHS England's Digital Technology Assessment Criteria is "an assessment framework for care commissioners and providers to use when assuring digital health technology (DHT) products". The Data Security and Protection Toolkit is the self-assessment "all organisations must use if they have access to NHS patient data and systems". Treat NHS-funded patients or hold NHS data and the toolkit reaches you. Otherwise a completed DTAC answers a question nobody asked.

The EU AI Act became applicable on 2 August 2026. Its rules for high-risk uses, which include employment, apply from 2 December 2027. Whether it reaches a UK group buying a UK platform for UK use is a territorial scope question for your own legal advisers, to settle before it becomes a scored criterion.

One supplier's answer on automated verification

Question two is where answers diverge most. Credentially's is that its checks are configured as a requirement set per client and per role. Registration checks and reference checks can sit on different settings, and the activity trail logs what the system did and what a person did to it. The credentialing and compliance monitoring pages list the connected registers. The security and data processing documentation covers the processor side.

The difference shows inside one record. A right to work check on a locum anaesthetist returns a surname mismatch between the share code and the practising certificate at 19:40 on a Friday. The automated verification step declines the record. On Monday the compliance officer opens it and sees one field, the decline reason. She cannot open the two documents the system compared, cannot see that the mismatch is a married name, and has nowhere to log an override. The candidate is stood down from Monday's list, which is covered at an agency rate. When the written request for an explanation arrives, the group has one month to answer and one field to answer from.

Configured the other way, the same mismatch is classified as an exception instead of a decline. The record routes to a named reviewer with both source documents on one screen, and the override, the reason and the timestamp are written to the activity log. The candidate works Monday, and the written request is answered from the log inside one working day.

How to use the list inside a live procurement

Put question one in the ITT as a table, a row for every check type you buy and a column headed "taken without meaningful human involvement, yes or no". Suppliers who have thought about it will fill it in. The rest answer in prose, and that is your first score.

Move questions 7, 10 and 12 out of the written response and into the demo, with a redacted review log and one candidate-facing explanation shown on screen.

Weight those answers above the certificates, since accredited certification for ISO/IEC 42001 has existed only since January 2026.

Then write the re-ask into the contract. Regulations under Article 22D and the ICO's final guidance will both change what a good automated verification answer looks like. A 2026 agreement should require the supplier to answer this set again when either lands, at no charge. The new answers attach to the agreement as a contract variation.

References

  • Data (Use and Access) Act 2025, section 80 (automated decision-making). https://www.legislation.gov.uk/ukpga/2025/18/section/80
  • The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026, S.I. 2026/82, regulation 2. https://www.legislation.gov.uk/uksi/2026/82/regulation/2/made
  • UK GDPR Article 22A. https://www.legislation.gov.uk/eur/2016/679/article/22A
  • UK GDPR Article 22B. https://www.legislation.gov.uk/eur/2016/679/article/22B
  • UK GDPR Article 22C. https://www.legislation.gov.uk/eur/2016/679/article/22C
  • UK GDPR Article 22D. https://www.legislation.gov.uk/eur/2016/679/article/22D
  • Information Commissioner's Office, automated decision-making, including profiling (draft guidance, updated 31 March 2026). https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/automated-decision-making-and-profiling/
  • Information Commissioner's Office, consultation on the draft ADM guidance, closed 29 May 2026. https://ico.org.uk/about-the-ico/ico-and-stakeholder-consultations/2026/03/ico-consultation-on-the-draft-guidance-about-automated-decision-making-including-profiling/
  • Information Commissioner's Office, Guidance on AI and data protection, updated 15 March 2023, under review. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/how-do-we-ensure-individual-rights-in-our-ai-systems/
  • Information Commissioner's Office and The Alan Turing Institute, Explaining decisions made with AI. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/explaining-decisions-made-with-artificial-intelligence/
  • Department for Science, Innovation and Technology, Trusted third-party AI assurance roadmap, 3 September 2025. https://www.gov.uk/government/publications/trusted-third-party-ai-assurance-roadmap/trusted-third-party-ai-assurance-roadmap
  • UKAS, UKAS grants first accreditation for ISO/IEC 42001, 15 January 2026. https://www.ukas.com/resources/latest-news/ukas-grants-first-aims-accreditation/
  • ISO/IEC 42001:2023, AI management systems. https://www.iso.org/standard/42001
  • NHS England, Digital Technology Assessment Criteria (DTAC), revised form issued February 2026. https://digital.nhs.uk/services/digital-technology-assessment-criteria-dtac
  • NHS England, Data Security and Protection Toolkit. https://digital.nhs.uk/cyber-and-data-security/cyber-security-services/data-security-and-protection-toolkit
  • European Commission, AI Act regulatory framework and application timeline, in force 1 August 2024. https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
Automated verification: the questions to ask before you buy a credentialing platform
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.