Skip to main content

IGPOL51 Registration Authority Policy v8

Page 1


Registration Authority Policy

Version: V8

Ratified by: Finance and Investment Committee

Date ratified: 01/12/2025

Job Title of author: Information Governance Manager

Reviewed by Committee or Expert Group Technology Programme Group

Equality Impact Assessed by: Information Governance Manager

Related procedural documents

IGPOL53 – Information Security Policy

Review date: 01/12/2028

It is the responsibility of users to ensure that you are using the most up to date document template – i.e. obtained via the intranet

In developing/reviewing this policy Provide Community has had regard to the principles of the NHS Constitution.

Version Control Sheet

Version Date

Author Status Comment

V1 March 2010 Information Governance Manager New V1 – joint policy between Provide and the PCT - Expired.

V2 March 2012 Information Governance Co-ordinator Ratified Reviewed to ensure that fits the organisation’s current processes

V3 Feb 2014 Information Governance Manager Ratified 6-month review

V4 October 2014 Information Governance Manager 2 Year Review

V4 November 2014 Information Governance Manager Ratified

V5 December 2016 Information Governance Manager

V6 March 2019 Information Governance and IT Projects Manager

V7 September 2022 Information Governance and IT Projects Manager

2 Year Review. Re-Written to take into account National Policy requirements.

2 Year Review. Reviewed against National Policy Requirements and NELCSU Policy

3 year review Reviewed against National Policy Requirements. New RA parent – AGEM CSU

V8 October 2025 Information Governance Manager 3-year review

1. Introduction

Context

Provide has delegated responsibility to administer the Registration Authority process for staff employed by Provide on behalf of The NHS ARDEN AND GREATER EAST MIDLANDS COMMISSIONING SUPPORT UNIT (hereafter referred to as AGEM CSU) as the Registration Authority.

This policy covers the aspects of the Registrations that Provide undertakes and mirrors the National Registration Authority Policy as set out by NHS England and the AGEM CSU RA Policy.

Approach

Provide must work with regards to the Registration Authority policies of the AGEM CSU as well as national policy defined by NHS England however as they will not wholly apply this document is intended to provide a framework within which Provide staff must operate.

The mechanisms by which this policy is implemented are described within the Registration Authority Procedures (IGSOP01)

The organisation’s documented and implemented processes and procedures provide a consistent approach in the provision of patient care, systems and services, which takes into account the guidance, recommendations and obligations of the following:

• Caldicott - care in confidentiality of patient identifiable information

• Consent to disclosure of patient identifiable information

• Information Quality Assurance

• ISO/IEC 27001:2022- Information Security Management

• Cyber Essentials Plus

• Common law duty of confidentiality

• Data Protection Act 2018

• UK General Data Protection Regulations (UK GDPR)

• Records Management – including Health Records

• The NHS Care Record Guarantee

• Freedom of Information Act 2000; and Data Security and Protection Toolkit

Background

It is a mandatory requirement that organisations that run local Registration Authority (RA) activity have a local policy outlining their approach. The following are mandatory requirements and are addressed within this Policy:

1. The name of the Board accountable person and the RA Manager within the organisation must be named within the policy. The policy needs to outline the governance requirements placed upon these individuals. The local organisation’s policy must be updated to reflect any changes to the named individuals.

2. The policy must describe how access rights will be granted and revoked in a timely way, ensuring that requirements for staff to be able to access electronic records in a timely way can be met and that individuals do not retain access within an organisation once they have left that organisation.

3. The policy must not contradict the mandatory requirements contained within the national RA policy document which is available on NHS England website.

At a minimum the policy must cover:

i. Governance arrangements

ii. A demonstration of the adherence to this policy document requirements in relation to the verification of identity

iii. Roles & responsibilities

iv. Smartcard Use

The policy must be formally signed off by the organisation at an appropriately senior level, e.g. the Technology Programme Group and Finance and Investment Committee on a delegated authority basis, etc.

2. Scope

This document outlines the actions to be performed in relation to the creation and operation of the registration function within the organisation. Senior Managers, Human Resources, Caldicott Guardian, Senior Information Risk Owner (SIRO) and staff who are going to be involved in the registration function need to be familiar with this document and its obligations.

This policy applies to RA and all staff that use smartcard enabled applications and, systems accessed/used by Provide staff. There will be monitoring of use of these applications and of Smartcard usage. Breach of the policy constitutes a disciplinary offence, which may lead to dismissal. All staff using the system will need to be made aware of and follow the national principles upon which this policy is based.

3. Definitions

The following terms are used throughout this Policy:

• Smartcard - is a credit card-sized plastic card containing an electronic chip for security. It is printed with name, photograph and unique user identity number (UUID)

• Care Identity Service (CIS) - is the electronic system for registering, issuing and maintaining NHS smartcards. It is a national system owned by NHS England

• Digital Identity – Is the unique representation of a subject engaged in an online transaction (NIST Special Publication 800-63-4). For the purpose of this policy, it is the unique and verified user profile of a registered user on CIS

• Registration Authority (RA) Staff – Consist of those staff who are involved in the issuance and maintenance of smartcards. For the purposes of this policy these roles consist of RA Agents, HR ID Checkers, Sponsors, Local Smartcard Administrators (LSA’s)

4. Roles and Responsibilities

Chief Executive

The Chief Executive has overall responsibility for the use of smartcards within Provide in partnership with AGEM CSU.

Responsibility is delegated through members of staff who undertake a Registration Authority role within Provide: This includes the role of RA Agents, HR ID Checkers, Sponsors and Local Smartcard Administrators.

SIRO

The Senior Information Risk Owner (SIRO) is responsible for understanding how the strategic business goals of the organisation may be impacted by information risks and for the ongoing development and day-to-day management of the organisation’s Risk Management Programme for information privacy and security.

The SIRO will review and agree action in respect of identified information risks, ensure that the organisation’s approach to information risk is effective in terms of resource, commitment and execution and that this is communicated to all staff.

The SIRO will provide a focal point for the resolution and/or discussion of information risk issues and ensure the Board is adequately briefed on information risks.

Registration Authority (RA) Manager (AGEM CSU)

As per National RA Policy the RA Manager is responsible for running the governance of RA. As such they must agree and sign off on local operational processes and should assure themselves regularly that these processes are being adhered to. They are also responsible for ensuring the effective training of RA Agents.

The RA manager function sits in AGEM CSU (NHS ARDEN AND GREATER EAST MIDLANDS COMMISSIONING SUPPORT UNIT).

Information Governance and IT Projects Manager (Provide)

The Information Governance and IT Projects Manager has operational responsibility for running of the RA function within Provide ensuring that service needs are met, risks are identified and any work streams are identified and carried out.

The IG and IT Projects Manager will provide assurances to the AGEM CSU RA Manager regarding the running of the Registration Authority function within Provide. In addition, the IG and IT Projects Manager will liaise with the RA Manager where there are any significant changes to local operational processes or where there are any changes to assigned RA Agents or HR ID Checkers.

In addition, the IG and IT Projects Manager will provide regular internal reports to the various subcommittees of the Provide Board. Risks pertaining to the RA Service will be reported through an Information Risk Report presented to the Finance and Investment Committee and a Service Report through the Technology Programme Board.

Registration Authority Agents (Provide)

RA Agent responsibilities are assigned to appropriate staff within the Technology team and are assigned by the Information Governance Manager with authorisation from the RA Manager in line with the above.

RA Agent responsibilities are to:

• Grant users access assignment

• Renew Smartcard certificates for users if self-service functionality not used

• Responsible for ensuring users at the time of registration or assigned a role in the organisation comply with the terms and conditions of Smartcard usage

• Ensure leavers from an organisation have their access rights removed in a timely way

• Adhere to local processes that meet policy and guidance for the creation of digital identities, production of smartcards, assignment of access rights, modifications to access and people and certificate renewal and card unlocking

• Provide guidance to end users, Sponsors, Local Smartcard Administrators (LSA’s) and HR ID Checkers. This will involve explanation of their roles and responsibilities regarding smartcard sponsorship.

• Maintain a current list of sponsors and LSA’s within the organisation and make these details available to end users

• Send out regular briefings to Sponsors and LSA’s with regards to their responsibilities and important information to take note of with regardsto running of the service

• Provide ad hoc training sessions for Sponsors, LSA’s and HR ID Checkers

• Check monthly leavers and mover’s lists provided by Human Resources and liaise with sponsors to ensure that access rights have been revoked/ amended accordingly

• Run regular and ad-hoc reports from CIS to assure that the correct processes are being adhered to

Additionally, RA Agents can:

• Verify users ID to e-GIF level 3 and NHS Employer standards

HR ID Checkers (Provide)

The HR ID Checker Role is assigned to appropriate staff within the Provide HR and Workforce teams and are assigned by the Information Governance Manager with authorisation from the RA Manager.

HR ID Checker responsibilities are to:

• Verify users ID to e-GIF level 3 and NHS Employer standards

• Take the applicant’s photo for their smartcard

• Enter the relevant information onto CIS to create a “Digital Identity”

• Adhere to local processes that meet policy and guidance for the creation of digital identities

• Cannot print or issue smartcards

• Cannot manage or authorise addition/ removal of access rights for end users

Registration Authority Sponsors (Provide)

In order to apply for a smartcard, users will need to have their role identified by a sponsor. Sponsors are appointed and entrusted to act on behalf of the Executive of the organisation in determining who should have what access and maintaining the appropriateness of that access.

Sponsors are responsible for granting access on behalf of the organisation, who can access what healthcare information. Sponsors will be held accountable by the organisation for their actions.

Sponsors need to ensure that they only sponsor users in accordance with their given remit.

Sponsors will be from an appropriate level in the organisation to vouch for the user and assign the role and business function that the user carries out. This will ensure that a smartcard user will only be able to view aspects of patient care records relevant to their role. The Information Governance team will ensure that there are sufficient sponsors within Provide services to fulfil this role.

All sponsors will be registered on the Spine as a Sponsor and be issued with a smartcard. Sponsors who hold a smartcard will have the ability to unlock users

Smartcards, where the user has locked them accidentally (usually due to incorrect password entries).

Sponsors responsibilities are:

Raising requests for new users

• Approving users’ assignment to access control positions, or,

• Directly assigning users under position management

• Unlocking Smartcards and renewing smartcard certificates for non-RA staff

• cannot verify User’s ID

Local Smartcard Administrators (LSA’s) (Provide)

Local Smartcard Administrators or LSA’s will be nominated by Sponsors embedded within Provide Services to provide assistance with regards to unlocking of smartcards

LSA’s responsibilities are:

• Assisting with unlocking of users (Not including RA Agents/ RA ID Checkers, Sponsors) smartcards

• Cannot manage or authorise addition/ removal of access rights for end users

• Cannot verify an end user’s identity

Line Managers

Line Managers should ensure all current and newly appointed staff are instructed in the correct use of Smartcards as detailed within the RA Procedures. Line Managers must inform their local sponsor or a registration Authority Agent when a staff member leaves the team or where the role changes which affects their smartcard access requirements.

All Staff

Each employed, contracted and voluntary staff member is personally responsible for ensuring that no breaches of computer security result from their actions.

Each staff member must comply with the terms of this policy, the National Smartcard terms and conditions and additionally the organisation’s Information security and Confidentiality policies and procedures.

All staff issued with a smartcard, must additionally:

• Register for the Self Unlocking of their smartcard to ensure that any disruption to clinical services is minimised.

• Ensure that they renew the certificates on their smartcards before they expire, by seeking help from their local sponsor or RA Agent when prompted by the identity agent that their certificates are going to expire

5. Requirements in Relation to Smartcards

Smartcards enable an individual to access sensitive patient data and therefore how they are issued and ensuring safe receipt and appropriate use are of vital importance. As a result, the following are mandatory requirements in relation to Smartcards.

1. Smartcards issued to anyone holding RA roles (RA Agent, HR ID Checker, Sponsor and Local Smartcard Administrator) must be handed over to that individual in a face-to-face encounter. This is because RA staff have significant powers in relation to the system and they are entrusted with much of the delegated responsibilities from NHS England– therefore it is vital that

risks are minimised in the process of the Smartcard getting to the right person. It is also a Public Key Infrastructure requirement for these reasons.

2. Secure process must be in place to ensure that the Smartcard reaches all non-RA end users for whom it is intended. Failure to do so can result in an individual receiving a card and potentially gaining access to patient data when they are not the person entitled to do so. Any replacement cards for Non – RA Staff can be placed in the post to a Sponsor or LSA in a locked state. Confirmation is required from the end Sponsor/ LSA that the card has been received within 7 working days of sending the card otherwise the card will be cancelled by the RA Agent.

3. Only the end user for whom the Smartcard is intended should know their passcode for their Smartcard, no-one else should, including RA staff. If anyone else knows the end user’s passcode it breaches the Smartcard terms and conditions of us, the Provide Information Security Policy and the Computer Misuse Act 1990. Any such breaches must be reported to the user’s line manager and raised on Datix for investigation. Where an end user suspects that their PIN number may have been compromised, they must change their PIN number immediately.

4. When Smartcard users leave the organisation, they must have their Provide smartcard position and associated SystmOne workgroups removed from their profile. However, unless it can be reasonably foreseen that they will not require access in another organisation in the future, leavers should retain their Smartcard, and their digital identity should remain open on the Care Identity Service

5. It is mandatory that users sign the Terms & Conditions of Smartcard use. This reminds them of their responsibilities and obligations, including not sharing the card, leaving the card unattended, and not disclosing their passcode to others.

6. RA staff (RA Agents, RA ID Checkers, Sponsors and LSA’s) are reminded that it is their responsibility to ensure that users comply with these terms and conditions.

Photographs for smartcards

The photo must be a true and accurate likeness of the applicant, showing their head and shoulders against a neutral background. Given the small size of the photograph when printed on the Smartcard, the photograph must clearly show the Smartcard holder’s face.

The photograph should include:

• close-up head and shoulders,

• the full head without any covering, unless worn for religious reasons,

• the full uncovered face with open eyes,

• looking straight at the camera,

• taken against a plain background,

• in sharp focus. The photograph must not:

• show the applicant with sunglasses, heavily tinted lenses or spectacle frames that cover the eyes,

• show reflections on the lenses of spectacles

6.

Creation of a National Identity

The Registration Authority needs to be assured that users who have a digital identity created are subject to the same standards of identity verification, to prove identity beyond reasonable doubt, irrespective of which local organisation creates the identity. This is vital as the identity created is a national identity and must be trusted by each organisation where an individual is required to access the National Spine to access data. To achieve this, identity is required to be verified to the previous intergovernmental standard known as eGFI Level 3. This provides assurance that the identity is valid across any organisation an individual works within.

In order to ensure this the following requirements in creating a digital identity are mandatory:

1. Identity must be verified in a face-to-face meeting. The Identification process must be carried out by Provide HR ID Checkers or RA Agent’s only. This will usually be carried out by an HR ID Checker in the HR or Workforce solutions teams at the same time as the employment checks. It must be done by examining original documents and seeing that identity relates to the individual who presents themselves at the meeting.

2. The person verifying the identity must be trained to do so. In Registration Authority terms this means that individuals holding the roles of HR ID Checker or RA Agents must perform these checks at face-to-face meetings since part of their responsibilities and requirements are that they are trained to carry out this activity. Please see Section 4 (Training) below.

3. The documents that can be used to verify an identity have been jointly determined by NHS England and NHS Employers and the list is contained in the NHS Employers ‘Verification of Identity Checks’ standard which can currently be found at Identity checks | NHS Employers No other documents are approved for verification of identity, including those contained within other NHS Employers standards.

4. Any changes to a person’s core identity attributes (Name, Date of Birth or National Insurance Number) need to go through the same face to face check with either an HR ID Checker or RA Agent and provide appropriate original documentary evidence.

5. Smartcards can only be issued to individuals who have a national verified digital identity

7. Assignment of Positions and Workgroups

Assignment of Smartcard Positions and SystmOne Workgroups must be authorised by the relevant local RA Sponsor (See Appendix 2). A list of smartcard positions are detailed in the PBAC spreadsheet.

RA Sponsors may directly assign some positions through CIS. Any positions with sensitive characteristics are not assignable and must be assigned by an RA Agent with authorization from the relevant Sponsor. Regular audits on assignable positions will be completed by the Information Governance team.

Assignment of the following Smartcard positions must be authorized by the AGEM CSU RA Manager before being assigned.

1. RA Agent

2. RA Agent (Advanced)

3. HR ID Checker

8. Smartcard Maintenance

The RA Sponsors and LSA can carry out basic Smartcard maintenance operations including unlocking Smartcards and renewing unexpired Smartcard certificates. When users experience problems using their Smartcard that cannot be resolved by the Sponsor or LSA they must report it to the Technology Service Desk (Smartcard Support). An RA Agent will investigate the problem.

Where an issue cannot be resolved by the RA Agent, the issue will be escalated to AGCSU RA Service Desk for help with resolution and where necessary escalation to the National RA team.

9. Certificate Expiry and Renewal

Smartcard certificates are valid for one year after which the smartcard will need to be renewed. If a user attempts to log in with their smartcard and there is less than ninety days before the certificates are due to expire, the Identity Agent will notify the user that the certificates are about to expire. The user will be given the option to self-renew, and if their desktop is enabled to use the CIS Software. If a software fault prevents the user from renewing their smartcard, then it is the user’s responsibility to inform a Sponsor, or the Technology Service Desk (Smartcard Support) that their smartcard is due to expire. After the Certificates have expired, that smartcard can still be renewed with the assistance of an RA Agent (by contacting the Technology Service desk (Smartcard Support)).

10.Implementing the Registration Authority Policy

The RA process is implemented through a set of procedures, which are documented in the Registration Authority Procedures (IGSOP01)

11.Training

It is stipulated in the National Registration Authority Policy from NHS Digital that RA staff are competent to carry out their roles and adhere to policy and process.

All RA Staff must complete the E-Learning module “000 National Registration Authority and Smartcard Policy”. This is a mandatory requirement and training uptake is monitored within the organisation.

RA Agents and HR ID Checkers must complete additional training that satisfies the requirements of the RA Manager at AGEM CSU

In addition to the E-Learning and training provided by AGEM CSU, ad-hoc face to face training is run by the Information Governance team for HR ID Checkers, Sponsors and LSA’s. Regular bulletins are also sent out to these staff to inform them of any changes or reminders.

Training needs are identified in Appendix 1.

12.Risk Management and Information Governance Principles

To identify and counter possible threats to the Registration Authority policy and procedures in line with the organisation’s Risk Management Policy.

All systems will be subject to periodic reviews by system managers and conducted in line with official accreditations including Cyber Essentials and ISO27001.

Regular Reporting of RA activity and issues will be performed through the organisation’s Technology Programme Group, and risks will be raised through the Finance and Investment Committee

13.Monitoring and Review

An audit of this policy will be supported and informed by analysis of incidents raised, breaches of confidentiality and complaints from the public.

This policy will be reviewed every 3 years by the Information Governance and IT Projects Manager and members of the Technology Programme Group. Earlier review may be required in response to exceptional circumstances, organisational change or relevant changes in legislation

The Policy will be ratified through the Finance and Investment Committee, which is a sub- committee of the Provide Board.

Appendix 1: Training Requirements for RA Agents and HR ID Checkers

Organisations must both identify, and provide for, the training needs of staff involved in the establishment and management of Registration Authorities. This will include ensuring staff have access to the latest software, national e-learning, the national RA Policy and the latest RA Process Guidance and the integration of these into the organisation’s RA policy and RA procedures.

In order to satisfy these principles, the following training will be undertaken by Provide RA Agents and HR ID Checkers:

1) E-Learning module 000 National Registration Authority and Smartcard Policy to be completed on OLM portal.

2) Additional training required as required by the AGCSU RA Manager

Policy/ Procedures

New staff will be required to familiarise themselves with the following Policies and Procedures:

1) IGPOL51 - Registration Authority Policy

2) IGSOP01 - Registration Authority Procedures

These documents are available on MyCompliance or Access, the organisation’s Policy Management System

Latest Guidance

All RA Agents will be subscribed to the NHS England email bulletins to be kept up to date with developments and latest guidance.

All RA Agents will be required to have their email address entered as part of their personal details held within the database of Smartcard users. They are also required to subscribe to the national email address list by sending an email with their details to ramanagers.agents@hscic.gov.uk

Latest Software

Through the NHS Digital bulletins, the RA team will be kept up to date with regards to any changes or updates to RA Software which may be required for improvements in functionality or security. Any software updates will be discussed with the Provide Technology team to be tested and deployed.

The Provide RA team will build a knowledge base of RA Hardware and software issues which will be accessible through the Service desk system.

RA Process Training

In order to be familiar with the CIS processes any new RA Agents will shadow an existing member of the team where they will be given training on the various processes documented in the organisation’s RA Procedures. Ad hoc one to one or small group facilitated training will be run by the Information Governance team for HR ID Checkers.

Additional Training

Additional training and development will be identified through the organisation’s Personal Development Plan (PDP) process.

Appendix 2: RA Contacts

Role Contact

RA Agents (Technology Service Desk –Smartcard Support)

Local Sponsor

Local LSA

RA ID Checkers (Employed Staff)

0300 303 9955 – Option 2

Provide.smartcards@nhs.net

See Sponsor List on staff intranet

See Sponsor List on staff intranet

0300 303 2661

Provide.peoplepartnering@nhs.net

RA ID Checkers (Workforce Solutions) 0300 303 2692

Provide.workforcesolutions@nhs.net

EQUALITY IMPACT ASSESSMENT TEMPLATE

Stage 1: ‘Screening’

The Equality Impact Assessment needs to be completed so that any decisions made are compliant with the aims of the Public Sector Equality Duty – and that any adverse impact for any protected characteristics are identified and resolved.

Policy Title

IGPOL51 Registration Authority Policy

Provide a brief summary (bullet points) of the aims of the Policy

This document outlines the policy for the operation and management of the delegated aspects of RA by the organisation. This policy is to ensure that all smartcard users are correctly identified and given appropriate levels of system access.

EQIA Assessor Name and Job Title

Date of Assessment

Information Governance Manager October 2025

This stage establishes whether a proposed initiative will have an impact from an equality perspective on any particular group of people or community or whether it is “equality neutral” (i.e. have no effect either positive or negative)

Q1. Will this policy affect one of the following groups more or Less favourably than another?

Details

Group

Age

Consider impact and detail across age ranges on old and younger people. This can include safeguarding, consent and child welfare

Disability

Consider and detail impact on attitudinal, physical, and social barriers.

Sex

Consider and detail impact on men and women (potential to link to carers)

Gender reassignment (including transgender)

Consider and detail impact on transgender and transsexual people. This can include issues such as privacy of data and harassment.

Pregnancy and maternity

Consider and detail impact on working arrangements, part-time working, infant caring responsibilities.

Race

Consider and detail impact on different ethnic groups, nationalities, Roma

If more or less, explain impact and any valid legal and/or justifiable exception. Include the source of any evidence

gypsies, Irish travellers, language and communication barriers.

Religion or belief

Consider and detail impact on people with different religions, beliefs or no belief.

Sexual orientation

Consider and detail impact on heterosexual people as well as lesbian, gay and bi-sexual people

Carers

Consider and detail impact on part-time working, shift-patterns, general caring responsibilities

Other identified groups

Consider and detail on different socioeconomic groups, area inequality, income, resident status (migrants) and other groups experiencing disadvantage and barriers to access.

Is the impact of the initiative – whether positive or negativesignificant enough to warrant a more detailed Stage 2 assessment?

Yes X No

Guidelines: Things to consider

Equality impact assessments at Provide take account of relevant equality legislation and include age, (i.e. young and old,); race and ethnicity, gender, disability, religion and faith, and sexual orientation.

The initiative may have a positive, negative or neutral impact, i.e. have no particular effect on the group/community.

Where a negative (i.e. adverse) impact is identified, it may be appropriate to make a more detailed EIA (see Stage 2), or, as important, take early action to redress this – e.g. by abandoning or modifying the initiative. NB: If the initiative contravenes equality legislation, it must be abandoned or modified.

Where an initiative has a positive impact on groups/community relations, the EIA should make this explicit, to enable the outcomes to be monitored over its lifespan.

Where there is a positive impact on particular groups does this mean there could be an adverse impact on others, and if so can this be justified? - e.g. are there other existing or planned initiatives which redress this?

It may not be possible to provide detailed answers to some of these questions at the start of the initiative. The EIA may identify a lack of relevant data, and that data-gathering is a specific action required to inform the initiative as it develops, and also to form part of a continuing evaluation and review process.

It is envisaged that it will be relatively rare for full impact assessments to be carried out at Provide. Usually, where there are particular problems identified in the screening stage, it is envisaged that the approach will be amended at this stage, and/or setting up a monitoring/evaluation system to review a policy’s impact over time.

QUALITY IMPACT ASSESSMENT TEMPLATE

Stage 2

To be used where the ‘screening phase has identified a substantial problem/concern)

This stage examines the initiative in more detail in order to obtain further information where required about its potential adverse or positive impact from an equality perspective. It will help inform whether any action needs to be taken and may form part of a continuing assessment framework as the initiative develops.

Policy/ Project Title

EIA Assessor Name and Job Title Date of Assessment

EIA Review by Chief Officer name and Job Title Date Of Review

Outcome of Chief Officer Review

Q1. What data/information is there on the target beneficiary groups/communities?

Are any of these groups under- or over-represented?  Yes  No

Do they have access to the same resources?  Yes  No

What are your sources of data and are there any gaps?

Q2. Is there a potential for this initiative to have a positive impact, such as tackling discrimination, promoting equality of opportunity and good community relations?  Yes  No

If yes, how? Which are the main groups it will have an impact on?

Q3. Will the initiative have an adverse impact on any particular group or community/community relations?  Yes

No

If yes, in what way? Will the impact be different for different groups – e.g. men and women?

No

Q4. Has there been consultation/is consultation planned with stakeholders/ beneficiaries/ staff who will be affected by the initiative?  Yes

Summarise (bullet points) any important issues arising from the consultation

Q5. Given your answers to the previous questions, how will your plans be revised to reduce/eliminate negative impact or enhance positive impact?

Are there specific factors which need to be taken into account?  Yes  No

Q6. How will the initiative continue to be monitored and evaluated, including its impact on particular groups/ improving community relations? Where appropriate, identify any additional data that will be required

Guidelines: Things to consider

An initiative may have a positive impact on some sectors of the community but leave others excluded or feeling they are excluded. Consideration should be given to how this can be tackled or minimised.

It is important to ensure that relevant groups/communities are identified who should be consulted. This may require taking positive action to engage with those groups who are traditionally less likely to respond to consultations, and could form a specific part of the initiative.

The consultation process should form a meaningful part of the initiative as it develops, and help inform any future action.

If the EIA shows an adverse impact, is this because it contravenes any equality legislation? If so, the initiative must be modified or abandoned. There may be another way to meet the objective(s) of the initiative.

Turn static files into dynamic content formats.

Create a flipbook
IGPOL51 Registration Authority Policy v8 by Provide Community - Issuu