2C — Safeguarding, Risk, Remote Delivery and Information Governance
What must be in place to keep client work safe, confidential, recorded and lawful.
2C
What must be in place to keep client work safe, confidential, recorded and lawful
About this section
2C sets out what safeguarding, risk, remote delivery and information-governance arrangements must be in place for a site delivering the Restitute Model.
It covers safeguarding infrastructure, risk recording, worker location, Lamplight, data protection, information governance, disclosure routes, accessibility arrangements and worker-safety arrangements for in-person contact.
It does not set out the client pathway or the worker's client-stage response. Those sit in Client Pathway Standards and Practice.
2C.1 Safeguarding infrastructure
- A site must have safeguarding arrangements in place before client work begins.
- Safeguarding arrangements must include a named safeguarding lead and clear local safeguarding routes.
- Local safeguarding arrangements must cover children, adults at risk, immediate danger, non-immediate concerns and escalation where a worker is unsure.
- Where the client, worker and Delivery Site are in different areas, safeguarding concerns should usually be directed through the safeguarding route for the client's local authority area. Immediate danger must use emergency routes first.
- Workers using the Restitute Model must know how to access safeguarding advice and escalation routes.
- The Restitute Model does not replace local safeguarding procedures. Each site must follow its own local thresholds, referral routes and statutory partnership arrangements.
- Safeguarding arrangements must be reviewed where local procedures, staff responsibilities or statutory routes change.
2C.2 Risk recording and escalation infrastructure
- The site must have arrangements in place for recording client risk and the actions needed to reduce or manage that risk.
- Workers must have access to the Lamplight risk assessment tools and must know how risk should be recorded, reviewed and updated.
- Where a risk is identified, the record must show the risk and the mitigation agreed to reduce or manage it.
- Where the support worker has not encountered the risk before, is unsure how to respond, or the risk cannot be managed safely through ordinary support work, this must be discussed in supervision.
- Where supervision identifies that the risk requires safeguarding, emergency action, governance review or wider escalation, the site's relevant escalation route must be followed.
- Risk decisions, mitigation and escalation actions must be recorded in Lamplight.
2C.3 Remote client delivery, worker location and in-person contact infrastructure
- The site must have arrangements in place for safe remote client delivery and any approved in-person client contact before client work begins.
- Remote delivery may include telephone, video, email, SMS or WhatsApp contact through approved work routes.
- Workers may deliver support from home, Delivery Site premises or another approved confidential work setting.
- The worker's location must allow confidential conversations, safe access to records, access to required systems and access to agreed support routes.
- Clients must not be invited to, seen in, or supported from a worker's home.
- Workers must not deliver client support from public or shared spaces where they can be overheard or where client information may be seen by others.
- Where a worker is home-based, home-working approval and a home-working risk assessment must be completed before regular home-based delivery starts.
- Where a worker is premises-based, the site must confirm that the premises provide confidential space, approved system access and safe recording arrangements.
- Delivery Sites must have lone-working and worker-safety arrangements in place where in-person client contact may occur.
- Those arrangements must cover approval, risk consideration, check-in/check-out, escalation and recording.
- Before remote contact begins, the Delivery Site must have a way to confirm with the client which contact routes are safe, private and accessible, whether messages or calls may be seen or overheard by someone else, and whether any contact restrictions are needed. The agreed safe-contact route and restrictions must be recorded in Lamplight.
2C.4 Lamplight, recording access and data quality
- A site must have Lamplight access, permissions and recording arrangements in place before client work begins.
- Lamplight is the approved case management system for the Restitute Model unless a formal future implementation decision approves an alternative.
- Lamplight access must be role-based and limited to what the user needs for their role.
- Workers and Delivery Site users must only access client records where they have a legitimate reason for access linked to delivery, supervision, safeguarding, quality assurance, reporting, research/evaluation, business continuity, case transfer or model governance.
- In normal delivery, this means Delivery Site users should only access records for clients allocated to their site or role.
- The Restitute Core Team may have wider access where this is needed for system administration, supervision, safeguarding, quality assurance, reporting, research/evaluation, business continuity, case transfer or model governance.
- Where a client transfers between sites, access and responsibility must be updated so that records are available to those who need them and not available to those who no longer have a legitimate reason for access.
- Delivery Sites must not change Lamplight configuration, fields, categories, assessment set-up, reporting structures or site sections independently. Lamplight changes must be made through the Restitute Core Team because changes may affect other Delivery Sites, data consistency, audit, reporting and model consistency.
- The site must have arrangements for checking that records are complete, accurate and usable.
- The site must be able to track required assessments and identify missed or overdue assessments.
- Temporary recording arrangements should only be used where approved, time-limited and transferred into Lamplight as soon as possible.
2C.5 Data protection, information governance and data-sharing arrangements
- The site must have data protection and information-governance arrangements in place before client work begins.
- The site must have an agreed process for information-sharing decisions, including consent, safeguarding, legal or other lawful bases for sharing.
- Access to client information must be role-appropriate. Workers and Delivery Site users must only access client records where they have a legitimate reason linked to their role.
- Information governance must support safeguarding. Confidentiality must not prevent necessary safeguarding action.
- Before delivery starts, the relevant data-controller, data-sharing or data-processing position must be confirmed in writing.
- The written data arrangement must set out responsibilities for Lamplight access, information sharing, subject access requests, data rights, breaches, retention, site exit, research/evaluation data use and transfer of records.
- The Delivery Site must have a clear process for recognising and escalating any client request to see, receive or copy information held about them in Lamplight.
- A request does not need to use formal wording to be treated as a possible information-rights request. If a client asks to see what has been written about them, asks for their notes, asks for their Lamplight record, or asks for copies of information held about them, the worker must route this through the agreed data-protection process.
- Workers and Delivery Sites must not respond informally by downloading, printing, screenshotting, copying, redacting or sending Lamplight records. Records must only be reviewed, redacted, shared, withheld or disclosed through the agreed data-protection route, including consideration of third-party information, safeguarding information, legal restrictions and any required redactions.
2C.6 Court, police and disclosure requests
- A site must have a clear route for handling requests from police, CPS, family court, solicitors or other legal processes.
- Workers using the Restitute Model should not respond to requests for records, statements, opinions or disclosure without using the agreed advice and approval route.
- The route should cover criminal justice requests, family court requests, solicitor correspondence, witness requests and requests for case notes.
- Decisions about disclosure should be recorded, including what was requested, what was shared or refused, the lawful basis or reason, and who approved the response.
2C.7 Accessibility, interpreters and reasonable-adjustment infrastructure
- A site must know what accessibility, language and communication arrangements it can offer before delivery starts.
- This may include accessible formats, adjusted communication routes, support with digital access, interpreter arrangements, translation support or adapted appointment arrangements.
- Where interpreter or translation support is needed, the site must consider how this can be provided safely, confidentially and without creating pressure on the client or family.
- Family members should not usually be used as interpreters. A family member may support communication only where they are already acting as a joint lead carer, the client is comfortable with this, and it does not create pressure, conflict, safeguarding risk or confidentiality concerns.
- Where formal interpretation is needed, the site should use a suitable interpreter who understands confidentiality. The arrangement should be recorded.
- Arrangements must be realistic within a remote specialist service and must not create unsafe or unclear practice.
- Where the site cannot safely meet a communication need, this must be discussed through supervision or governance so the person is not left without advice about other suitable support.
- The site must have a way to record agreed accessibility needs and adjustments in Lamplight.