Domain H: Infrastructure & Compute Capacity¶
Using the domain reference
Domain H includes the five maturity descriptors and the source-verified minimum evidence for L3–L5. Expand the evidence section beneath each indicator and retain an auditable assessment record. See How to Apply HDRL.
Focus: Technical infrastructure including secure data environments, compute, security and artificial intelligence capability
Indicators: 9 (6 Core, 3 Enhancement)
The business question
Is our technology safe and scalable? Assesses whether the environment can handle artificial intelligence (AI) workloads and cyber threats.
Secure data environments (SDEs), including trusted research environments (TREs), are the technical backbone of health data research. As workloads shift toward machine learning and large-scale genomics, compute demands are growing exponentially while cyber threats intensify. This domain assesses whether infrastructure meets relevant standards—including National Health Service secure data environment specifications, the Standardised Architecture for Trusted Research Environments (SATRE) and ISO 27001—can scale for emerging use cases, and maintains the security posture that underpins all other domains. Two of the five proposed Foundational Indicators sit here.
Contains 2 proposed Foundational Indicators
HDRL v1.0.1 treats indicators H.3.1 and H.3.2 as proposed Foundational Indicators with a minimum of Level 3 in its internal baseline assessment logic. They are not official UK Health Data Research Service (HDRS) participation requirements.
Indicator Summary¶
| ID | Indicator | Type | Class | Unit | Foundational |
|---|---|---|---|---|---|
| H.1.1 | SDE Architecture & Standards | Core | B0 | Service | |
| H.1.2 | User Environment & Experience | Core | B0 | Service | |
| H.2.1 | Compute Scalability | Core | B0 | Service | |
| H.2.2 | Storage & Data Management | Enhancement | O | Service | |
| H.3.1 | Security Certification & Audit | Core | B0 | Service | |
| H.3.2 | Security Operations | Core | B0 | Service | |
| H.3.3 | Privacy-Enhancing Technologies | Enhancement | O | Service | |
| H.4.1 | ML/AI Platform Capability | Enhancement | O | Service | |
| H.4.2 | Responsible AI Practices | Core | C3/4 | Service |
H.1 — Secure Data Environment¶
H.1.1 SDE Architecture & Standards¶
CORE · B0 · Service
| Level | Description |
|---|---|
| L1 | No dedicated SDE. Ad-hoc access. Controls inconsistent. |
| L2 | SDE developing. Architecture defined. NHS SDE specs and SATRE reviewed. |
| L3 | Operational meeting basic requirements. ISO 27001 in progress. Some gaps vs gold-standard/SATRE. |
| L4 | Mature meeting NHS SDE gold-standard and SATRE mandatory. ISO 27001. DEA accredited. |
| L5 | Advanced exceeding baseline. Most SATRE recommended. Enables emerging uses. Contributing to UK standards. |
Minimum evidence for L3–L5
Use this source-defined minimum evidence with the maturity descriptors above. Record the artefact, date, scope and the claim it supports.
L3 minimum evidence
- SDE architecture documented and aligned to key specs; gaps identified
- Evidence of implemented controls and progress towards certification/accreditation
L4 minimum evidence
- Architecture documentation showing compliance with NHS SDE specs and SATRE mandatory controls
- ISO 27001 certificate (scope includes service) and DEA accreditation evidence
- Independent gap assessment evidence and remediation status
L5 minimum evidence
- Evidence of exceeding baseline (SATRE recommended controls implemented) with documentation
- Continuous improvement evidence (security/architecture roadmap + delivery)
- Contribution to UK standards/specs (working groups, shared patterns)
H.1.2 User Environment & Experience¶
CORE · B0 · Service
| Level | Description |
|---|---|
| L1 | Poor experience. Difficult access. Tools outdated. Significant complaints. |
| L2 | Issues identified. Roadmap defined. Upgrades underway. |
| L3 | Functional. Standard tools (R, Python, SQL). Process works but cumbersome. |
| L4 | Good with modern environment. Tools updated. Onboarding <1 day. Satisfaction tracked. |
| L5 | Excellent matching commercial platforms. Rich tools. Rapid onboarding. >= 80% satisfaction. |
Minimum evidence for L3–L5
Use this source-defined minimum evidence with the maturity descriptors above. Record the artefact, date, scope and the claim it supports.
L3 minimum evidence
- Operational user environment with documented tooling and onboarding process
- Evidence of user feedback collection and response
L4 minimum evidence
- Onboarding metrics showing <1 day for standard users + process evidence
- Tooling/environment list showing modern, maintained stack
- Satisfaction survey results and improvement actions
L5 minimum evidence
- Benchmarking against leading platforms (comparators and results)
- Sustained high satisfaction (>=80%) with methodology documented
- Evidence of rapid enhancement cycle driven by users (release notes/backlog)
H.2 — Compute & Storage¶
H.2.1 Compute Scalability¶
CORE · B0 · Service
| Level | Description |
|---|---|
| L1 | Severely limited. Analysis constrained. Frequent delays/failures. |
| L2 | Assessed. Upgrade requirements defined. Cloud/HPC evaluated. |
| L3 | Adequate for standard. Queuing for intensive. GPU limited. Cloud/HPC for exceptions. |
| L4 | Scalable meeting demand with headroom. GPU for AI/ML. Scaling pathway. Cost management. |
| L5 | Elastic auto-scaling. Advanced GPU. Cost-optimised. Benchmarked internationally. |
Minimum evidence for L3–L5
Use this source-defined minimum evidence with the maturity descriptors above. Record the artefact, date, scope and the claim it supports.
L3 minimum evidence
- Compute environment operational with scaling plan; utilisation monitored
- Evidence of meeting routine demand without persistent capacity constraints
L4 minimum evidence
- Capacity and utilisation metrics showing headroom + scaling pathway
- GPU availability evidence for AI/ML where required
- Cost management evidence (chargeback/showback, monitoring)
L5 minimum evidence
- Elastic autoscaling evidence (architecture + performance under load tests)
- Advanced GPU/accelerator capability evidence + utilisation metrics
- Benchmarking evidence (UK/international) or independent performance review
H.2.2 Storage & Data Management¶
ENHANCEMENT · O · Service
| Level | Description |
|---|---|
| L1 | Constrained. Retention unclear. No tiering. Costs unmanaged. |
| L2 | Assessment completed. Tiered strategy. Retention developing. |
| L3 | Adequate with tiering. Retention operational. Costs monitored. |
| L4 | Scalable. Comprehensive lifecycle. Costs optimised. Backup/DR tested. |
| L5 | Advanced with automated tiering/lifecycle. Costs benchmarked. Multi-site resilience. |
Minimum evidence for L3–L5
Use this source-defined minimum evidence with the maturity descriptors above. Record the artefact, date, scope and the claim it supports.
L3 minimum evidence
- Storage management process documented (retention, backup) with implementation evidence
- Evidence of DR/backups functioning (test or restore logs)
L4 minimum evidence
- Storage lifecycle policy (tiering, retention) + implementation evidence
- Backup/DR test results and audit trail
- Cost optimisation evidence (monitoring, tiering usage)
L5 minimum evidence
- Automated lifecycle/tiering evidence with monitoring and alerts
- Cost benchmarking evidence and continuous optimisation
- Multi-site resilience evidence (replication, failover tests)
H.3 — Security¶
H.3.1 Security Certification & Audit¶
CORE · B0 · Service · FOUNDATIONAL REQUIREMENT (minimum L3)
| Level | Description |
|---|---|
| L1 | No certification. Controls undocumented/untested. |
| L2 | Assessment initiated. Gap analysis vs ISO 27001. Remediation plan. |
| L3 | Controls implemented. ISO 27001 in progress. Penetration testing. Incident process defined. |
| L4 | ISO 27001 certified (full scope). Annual penetration with remediation. Incident management. DEA accredited. |
| L5 | Continuous assurance and independent testing. Demonstrable security outcomes; additional certifications as appropriate. |
Minimum evidence for L3–L5
Use this source-defined minimum evidence with the maturity descriptors above. Record the artefact, date, scope and the claim it supports.
L3 minimum evidence
- Controls implemented with certification in progress and regular testing
- Evidence of incident management process defined and used
L4 minimum evidence
- ISO 27001 certificate (full scope) + annual penetration test summary with remediation evidence
- Incident management SOP + exercised/tested evidence
- DEA accreditation evidence (where applicable)
L5 minimum evidence
- Continuous assurance evidence (control monitoring, frequent independent testing/red teaming)
- Demonstrable security outcomes (incident metrics, risk reduction) and improvement actions
- External assurance beyond ISO where appropriate (optional, scope stated)
H.3.2 Security Operations¶
CORE · B0 · Service · FOUNDATIONAL REQUIREMENT (minimum L3)
| Level | Description |
|---|---|
| L1 | No dedicated ops. Monitoring ad-hoc. Incident response untested. |
| L2 | Function identified. Monitoring implementing. Incident plan drafted. |
| L3 | Basic ops monitoring key systems. Incident plan documented. |
| L4 | Mature with comprehensive monitoring. 24/7 alerting. Incident tested. Metrics reported. |
| L5 | Advanced with threat intelligence. Proactive hunting. Automated response. Benchmarked. |
Minimum evidence for L3–L5
Use this source-defined minimum evidence with the maturity descriptors above. Record the artefact, date, scope and the claim it supports.
L3 minimum evidence
- Operational security monitoring and incident response capabilities
- Evidence of regular patching/vulnerability management and reporting
L4 minimum evidence
- Monitoring/alerting evidence (coverage, 24/7 or equivalent) and runbooks
- Incident response exercises and lessons learned documentation
- Security ops KPIs reported (MTTD/MTTR, patch cadence)
L5 minimum evidence
- Threat intelligence and hunting capability evidence (process + outputs)
- Automation evidence (SOAR, auto-remediation) with controls
- Benchmarking or independent assessment of security operations maturity
H.3.3 Privacy-Enhancing Technologies¶
ENHANCEMENT · O · Service
| Level | Description |
|---|---|
| L1 | No PETs. All analysis requires pseudonymised data in secure environment. |
| L2 | Options assessed. Federated/differential privacy pilots planned. |
| L3 | Selected capabilities (DataSHIELD, federated). Limited use cases. |
| L4 | Routinely available (federated, secure computation, differential privacy). Support. Governance. |
| L5 | Advanced with multiple technologies. PET default where appropriate. Contributing to standards. |
Minimum evidence for L3–L5
Use this source-defined minimum evidence with the maturity descriptors above. Record the artefact, date, scope and the claim it supports.
L3 minimum evidence
- At least one PET capability piloted or operational for selected use cases
- Governance guidance exists for when to use PETs
L4 minimum evidence
- Documented PET services available (federation, DP, secure computation) and governance
- Use case evidence showing PETs used routinely where appropriate
- Risk assessment templates/policies supporting PET selection
L5 minimum evidence
- Evidence PETs are default for suitable use cases (policy + adoption metrics)
- Multiple PETs with validation evidence and staff capability
- Contribution to PET standards/pilots beyond the service (optional)
H.4 — AI & Advanced Analytics¶
H.4.1 ML/AI Platform Capability¶
ENHANCEMENT · O · Service
| Level | Description |
|---|---|
| L1 | No ML/AI capability. Cannot run ML workloads. |
| L2 | Requirements assessed. Platform evaluated. Pilot planned. |
| L3 | Basic with standard libraries. GPU limited. No MLOps. |
| L4 | Mature with MLOps (tracking, registry, pipelines). GPU. Governance defined. |
| L5 | Advanced full lifecycle. Automated pipelines. Monitoring. Synthetic data. Contributing to UK AI standards. |
Minimum evidence for L3–L5
Use this source-defined minimum evidence with the maturity descriptors above. Record the artefact, date, scope and the claim it supports.
L3 minimum evidence
- Basic ML platform components available (tools, GPU) for selected projects
- Governance for ML workflows documented
L4 minimum evidence
- MLOps tooling evidence (experiment tracking, model registry, pipelines) and governance
- GPU and platform capacity evidence supporting routine ML workloads
- Security/privacy controls for ML workflows (data handling, model release)
L5 minimum evidence
- End-to-end ML lifecycle evidence (monitoring, drift, retraining, audit trails)
- Advanced capabilities (synthetic data, federated learning where relevant) with evaluation
- Contribution to UK AI standards/tooling or shared patterns
H.4.2 Responsible AI Practices¶
CORE · C3/4 · Service
Capability module
Within HDRL v1.0's original six-capability mapping, this indicator is included when assessing Capability 3 (Multi-modal data) or Capability 4 (Trial acceleration). The mapping preserves the initial 2025 HDRS proposition; it should not be treated here as a current programme requirement.
| Level | Description |
|---|---|
| L1 | No consideration. Projects without ethics, bias assessment, or reporting. |
| L2 | Principles acknowledged. STANDING Together, TRIPOD-AI, CONSORT-AI reviewed. Some awareness. |
| L3 | Framework developing. Diversity assessed for some using STANDING Together. Guidelines referenced. Selected bias assessment. |
| L4 | Comprehensive framework. All projects assess diversity per STANDING Together. TRIPOD-AI/CONSORT-AI mandated. Bias embedded. NICE AI aligned. |
| L5 | Leading practice. Full STANDING Together. Contributing to standards. Advanced fairness monitoring. Scottish AI Playbook aligned. Sharing frameworks. |
Minimum evidence for L3–L5
Use this source-defined minimum evidence with the maturity descriptors above. Record the artefact, date, scope and the claim it supports.
L3 minimum evidence
- Responsible AI expectations documented and applied to some projects
- Evidence of bias/representativeness assessment performed for selected AI studies
L4 minimum evidence
- Responsible AI framework/policy + mandated reporting standards (e.g., TRIPOD-AI/CONSORT-AI where relevant)
- Evidence all AI projects assess dataset representativeness (e.g., STANDING Together) and bias
- Governance evidence (review, approvals, monitoring) linked to project delivery
L5 minimum evidence
- Evidence of advanced fairness/monitoring and continuous improvement
- External contribution/leadership in responsible AI standards/practice
- Independent assurance or peer review of responsible AI governance (optional)