
Registration Authority Policy
Version: V8
Ratified by: Finance and Investment Committee
Date ratified: 01/12/2025
Job Title of author: Information Governance Manager
Reviewed by Committee or Expert Group Technology Programme Group
Equality Impact Assessed by: Information Governance Manager
Related procedural documents

IGPOL53 – Information Security Policy
Review date: 01/12/2028
It is the responsibility of users to ensure that you are using the most up to date document template – i.e. obtained via the intranet
In developing/reviewing this policy Provide Community has had regard to the principles of the NHS Constitution.
Version Control Sheet
Version Date

Author Status Comment
V1 March 2010 Information Governance Manager New V1 – joint policy between Provide and the PCT - Expired.
V2 March 2012 Information Governance Co-ordinator Ratified Reviewed to ensure that fits the organisation’s current processes
V3 Feb 2014 Information Governance Manager Ratified 6-month review
V4 October 2014 Information Governance Manager 2 Year Review
V4 November 2014 Information Governance Manager Ratified
V5 December 2016 Information Governance Manager
V6 March 2019 Information Governance and IT Projects Manager
V7 September 2022 Information Governance and IT Projects Manager
2 Year Review. Re-Written to take into account National Policy requirements.
2 Year Review. Reviewed against National Policy Requirements and NELCSU Policy
3 year review Reviewed against National Policy Requirements. New RA parent – AGEM CSU
V8 October 2025 Information Governance Manager 3-year review


1. Introduction
Context
Provide has delegated responsibility to administer the Registration Authority process for staff employed by Provide on behalf of The NHS ARDEN AND GREATER EAST MIDLANDS COMMISSIONING SUPPORT UNIT (hereafter referred to as AGEM CSU) as the Registration Authority.
This policy covers the aspects of the Registrations that Provide undertakes and mirrors the National Registration Authority Policy as set out by NHS England and the AGEM CSU RA Policy.
Approach
Provide must work with regards to the Registration Authority policies of the AGEM CSU as well as national policy defined by NHS England however as they will not wholly apply this document is intended to provide a framework within which Provide staff must operate.
The mechanisms by which this policy is implemented are described within the Registration Authority Procedures (IGSOP01)
The organisation’s documented and implemented processes and procedures provide a consistent approach in the provision of patient care, systems and services, which takes into account the guidance, recommendations and obligations of the following:
• Caldicott - care in confidentiality of patient identifiable information
• Consent to disclosure of patient identifiable information
• Information Quality Assurance
• ISO/IEC 27001:2022- Information Security Management
• Cyber Essentials Plus
• Common law duty of confidentiality
• Data Protection Act 2018
• UK General Data Protection Regulations (UK GDPR)
• Records Management – including Health Records
• The NHS Care Record Guarantee
• Freedom of Information Act 2000; and Data Security and Protection Toolkit
Background
It is a mandatory requirement that organisations that run local Registration Authority (RA) activity have a local policy outlining their approach. The following are mandatory requirements and are addressed within this Policy:
1. The name of the Board accountable person and the RA Manager within the organisation must be named within the policy. The policy needs to outline the governance requirements placed upon these individuals. The local organisation’s policy must be updated to reflect any changes to the named individuals.
2. The policy must describe how access rights will be granted and revoked in a timely way, ensuring that requirements for staff to be able to access electronic records in a timely way can be met and that individuals do not retain access within an organisation once they have left that organisation.

3. The policy must not contradict the mandatory requirements contained within the national RA policy document which is available on NHS England website.
At a minimum the policy must cover:
i. Governance arrangements
ii. A demonstration of the adherence to this policy document requirements in relation to the verification of identity
iii. Roles & responsibilities
iv. Smartcard Use
The policy must be formally signed off by the organisation at an appropriately senior level, e.g. the Technology Programme Group and Finance and Investment Committee on a delegated authority basis, etc.
2. Scope
This document outlines the actions to be performed in relation to the creation and operation of the registration function within the organisation. Senior Managers, Human Resources, Caldicott Guardian, Senior Information Risk Owner (SIRO) and staff who are going to be involved in the registration function need to be familiar with this document and its obligations.
This policy applies to RA and all staff that use smartcard enabled applications and, systems accessed/used by Provide staff. There will be monitoring of use of these applications and of Smartcard usage. Breach of the policy constitutes a disciplinary offence, which may lead to dismissal. All staff using the system will need to be made aware of and follow the national principles upon which this policy is based.
3. Definitions
The following terms are used throughout this Policy:
• Smartcard - is a credit card-sized plastic card containing an electronic chip for security. It is printed with name, photograph and unique user identity number (UUID)
• Care Identity Service (CIS) - is the electronic system for registering, issuing and maintaining NHS smartcards. It is a national system owned by NHS England
• Digital Identity – Is the unique representation of a subject engaged in an online transaction (NIST Special Publication 800-63-4). For the purpose of this policy, it is the unique and verified user profile of a registered user on CIS
• Registration Authority (RA) Staff – Consist of those staff who are involved in the issuance and maintenance of smartcards. For the purposes of this policy these roles consist of RA Agents, HR ID Checkers, Sponsors, Local Smartcard Administrators (LSA’s)
4. Roles and Responsibilities
Chief Executive
The Chief Executive has overall responsibility for the use of smartcards within Provide in partnership with AGEM CSU.
Responsibility is delegated through members of staff who undertake a Registration Authority role within Provide: This includes the role of RA Agents, HR ID Checkers, Sponsors and Local Smartcard Administrators.

SIRO
The Senior Information Risk Owner (SIRO) is responsible for understanding how the strategic business goals of the organisation may be impacted by information risks and for the ongoing development and day-to-day management of the organisation’s Risk Management Programme for information privacy and security.
The SIRO will review and agree action in respect of identified information risks, ensure that the organisation’s approach to information risk is effective in terms of resource, commitment and execution and that this is communicated to all staff.
The SIRO will provide a focal point for the resolution and/or discussion of information risk issues and ensure the Board is adequately briefed on information risks.
Registration Authority (RA) Manager (AGEM CSU)
As per National RA Policy the RA Manager is responsible for running the governance of RA. As such they must agree and sign off on local operational processes and should assure themselves regularly that these processes are being adhered to. They are also responsible for ensuring the effective training of RA Agents.
The RA manager function sits in AGEM CSU (NHS ARDEN AND GREATER EAST MIDLANDS COMMISSIONING SUPPORT UNIT).
Information Governance and IT Projects Manager (Provide)
The Information Governance and IT Projects Manager has operational responsibility for running of the RA function within Provide ensuring that service needs are met, risks are identified and any work streams are identified and carried out.
The IG and IT Projects Manager will provide assurances to the AGEM CSU RA Manager regarding the running of the Registration Authority function within Provide. In addition, the IG and IT Projects Manager will liaise with the RA Manager where there are any significant changes to local operational processes or where there are any changes to assigned RA Agents or HR ID Checkers.
In addition, the IG and IT Projects Manager will provide regular internal reports to the various subcommittees of the Provide Board. Risks pertaining to the RA Service will be reported through an Information Risk Report presented to the Finance and Investment Committee and a Service Report through the Technology Programme Board.
Registration Authority Agents (Provide)
RA Agent responsibilities are assigned to appropriate staff within the Technology team and are assigned by the Information Governance Manager with authorisation from the RA Manager in line with the above.
RA Agent responsibilities are to:
• Grant users access assignment
• Renew Smartcard certificates for users if self-service functionality not used
• Responsible for ensuring users at the time of registration or assigned a role in the organisation comply with the terms and conditions of Smartcard usage
• Ensure leavers from an organisation have their access rights removed in a timely way
• Adhere to local processes that meet policy and guidance for the creation of digital identities, production of smartcards, assignment of access rights, modifications to access and people and certificate renewal and card unlocking

• Provide guidance to end users, Sponsors, Local Smartcard Administrators (LSA’s) and HR ID Checkers. This will involve explanation of their roles and responsibilities regarding smartcard sponsorship.
• Maintain a current list of sponsors and LSA’s within the organisation and make these details available to end users
• Send out regular briefings to Sponsors and LSA’s with regards to their responsibilities and important information to take note of with regardsto running of the service
• Provide ad hoc training sessions for Sponsors, LSA’s and HR ID Checkers
• Check monthly leavers and mover’s lists provided by Human Resources and liaise with sponsors to ensure that access rights have been revoked/ amended accordingly
• Run regular and ad-hoc reports from CIS to assure that the correct processes are being adhered to
Additionally, RA Agents can:
• Verify users ID to e-GIF level 3 and NHS Employer standards
HR ID Checkers (Provide)
The HR ID Checker Role is assigned to appropriate staff within the Provide HR and Workforce teams and are assigned by the Information Governance Manager with authorisation from the RA Manager.
HR ID Checker responsibilities are to:
• Verify users ID to e-GIF level 3 and NHS Employer standards
• Take the applicant’s photo for their smartcard
• Enter the relevant information onto CIS to create a “Digital Identity”
• Adhere to local processes that meet policy and guidance for the creation of digital identities
• Cannot print or issue smartcards
• Cannot manage or authorise addition/ removal of access rights for end users
Registration Authority Sponsors (Provide)
In order to apply for a smartcard, users will need to have their role identified by a sponsor. Sponsors are appointed and entrusted to act on behalf of the Executive of the organisation in determining who should have what access and maintaining the appropriateness of that access.
Sponsors are responsible for granting access on behalf of the organisation, who can access what healthcare information. Sponsors will be held accountable by the organisation for their actions.
Sponsors need to ensure that they only sponsor users in accordance with their given remit.
Sponsors will be from an appropriate level in the organisation to vouch for the user and assign the role and business function that the user carries out. This will ensure that a smartcard user will only be able to view aspects of patient care records relevant to their role. The Information Governance team will ensure that there are sufficient sponsors within Provide services to fulfil this role.
All sponsors will be registered on the Spine as a Sponsor and be issued with a smartcard. Sponsors who hold a smartcard will have the ability to unlock users

Smartcards, where the user has locked them accidentally (usually due to incorrect password entries).
Sponsors responsibilities are:
Raising requests for new users
• Approving users’ assignment to access control positions, or,
• Directly assigning users under position management
• Unlocking Smartcards and renewing smartcard certificates for non-RA staff
• cannot verify User’s ID
Local Smartcard Administrators (LSA’s) (Provide)
Local Smartcard Administrators or LSA’s will be nominated by Sponsors embedded within Provide Services to provide assistance with regards to unlocking of smartcards
LSA’s responsibilities are:
• Assisting with unlocking of users (Not including RA Agents/ RA ID Checkers, Sponsors) smartcards
• Cannot manage or authorise addition/ removal of access rights for end users
• Cannot verify an end user’s identity
Line Managers
Line Managers should ensure all current and newly appointed staff are instructed in the correct use of Smartcards as detailed within the RA Procedures. Line Managers must inform their local sponsor or a registration Authority Agent when a staff member leaves the team or where the role changes which affects their smartcard access requirements.
All Staff
Each employed, contracted and voluntary staff member is personally responsible for ensuring that no breaches of computer security result from their actions.
Each staff member must comply with the terms of this policy, the National Smartcard terms and conditions and additionally the organisation’s Information security and Confidentiality policies and procedures.
All staff issued with a smartcard, must additionally:
• Register for the Self Unlocking of their smartcard to ensure that any disruption to clinical services is minimised.
• Ensure that they renew the certificates on their smartcards before they expire, by seeking help from their local sponsor or RA Agent when prompted by the identity agent that their certificates are going to expire
5. Requirements in Relation to Smartcards
Smartcards enable an individual to access sensitive patient data and therefore how they are issued and ensuring safe receipt and appropriate use are of vital importance. As a result, the following are mandatory requirements in relation to Smartcards.
1. Smartcards issued to anyone holding RA roles (RA Agent, HR ID Checker, Sponsor and Local Smartcard Administrator) must be handed over to that individual in a face-to-face encounter. This is because RA staff have significant powers in relation to the system and they are entrusted with much of the delegated responsibilities from NHS England– therefore it is vital that

risks are minimised in the process of the Smartcard getting to the right person. It is also a Public Key Infrastructure requirement for these reasons.
2. Secure process must be in place to ensure that the Smartcard reaches all non-RA end users for whom it is intended. Failure to do so can result in an individual receiving a card and potentially gaining access to patient data when they are not the person entitled to do so. Any replacement cards for Non – RA Staff can be placed in the post to a Sponsor or LSA in a locked state. Confirmation is required from the end Sponsor/ LSA that the card has been received within 7 working days of sending the card otherwise the card will be cancelled by the RA Agent.
3. Only the end user for whom the Smartcard is intended should know their passcode for their Smartcard, no-one else should, including RA staff. If anyone else knows the end user’s passcode it breaches the Smartcard terms and conditions of us, the Provide Information Security Policy and the Computer Misuse Act 1990. Any such breaches must be reported to the user’s line manager and raised on Datix for investigation. Where an end user suspects that their PIN number may have been compromised, they must change their PIN number immediately.
4. When Smartcard users leave the organisation, they must have their Provide smartcard position and associated SystmOne workgroups removed from their profile. However, unless it can be reasonably foreseen that they will not require access in another organisation in the future, leavers should retain their Smartcard, and their digital identity should remain open on the Care Identity Service
5. It is mandatory that users sign the Terms & Conditions of Smartcard use. This reminds them of their responsibilities and obligations, including not sharing the card, leaving the card unattended, and not disclosing their passcode to others.
6. RA staff (RA Agents, RA ID Checkers, Sponsors and LSA’s) are reminded that it is their responsibility to ensure that users comply with these terms and conditions.
Photographs for smartcards
The photo must be a true and accurate likeness of the applicant, showing their head and shoulders against a neutral background. Given the small size of the photograph when printed on the Smartcard, the photograph must clearly show the Smartcard holder’s face.
The photograph should include:
• close-up head and shoulders,
• the full head without any covering, unless worn for religious reasons,
• the full uncovered face with open eyes,
• looking straight at the camera,
• taken against a plain background,
• in sharp focus. The photograph must not:
• show the applicant with sunglasses, heavily tinted lenses or spectacle frames that cover the eyes,
• show reflections on the lenses of spectacles
