Definition
Implementing PSIRF means moving an organisation onto the Patient Safety Incident Response Framework: analysing its incident profile, building response and oversight capability, writing a patient safety incident response policy and plan, agreeing the plan with its integrated care board, and publishing both. NHS-contracted secondary care providers completed this transition by autumn 2023.
Source: NHS England, August 2022 · Last reviewed 6 July 2026
Who is implementing now
The national transition window closed in autumn 2023, so for most NHS trusts implementation is history and the live question is embedding. But the framework keeps gaining new implementers: independent providers taking on NHS-funded contracts, new services within existing providers, and primary care organisations adopting it voluntarily. The sequence below applies to them as it did to the trusts, minus the national deadline pressure.
The implementation sequence
NHS England's preparation guidance orders the work deliberately, and the order is the lesson: capability and understanding come before documents.
- Secure executive sponsorship and name a transition lead, usually the patient safety specialist. PSIRF changes governance, so it cannot be run from the middle of the organisation.
- Orient the leadership. Boards and oversight roles need to understand what they will stop doing (counting reports) as much as what starts. The oversight training expectations exist for this step.
- Diagnose the incident profile. Analyse incident data alongside complaints, claims and staff feedback to establish where harm and risk concentrate. This analysis becomes the spine of the incident response plan.
- Build response capability. Train learning response leads and engagement leads, and decide which learning responses the organisation will operate and who facilitates each.
- Write the policy and the plan. The policy describes the enduring system; the plan commits to responses for the priority incident types, with the rationale on show.
- Test before you commit. Early adopters ran learning responses on live incidents during preparation, which exposed training gaps and template problems while they were still cheap to fix.
Agreement and go-live
Transition completes when the policy and plan have been through the organisation's own governance to board level, reviewed and agreed with the lead ICB, and published on the organisation's website. From that point incident response follows the plan rather than the old framework's thresholds. Go-live is also where recording arrangements matter: incidents flow through the LFPSE service, and response outputs need a tracked home so oversight can see whether safety actions complete and work.
Embedding: the part after the plan
Publishing a plan changes documents; embedding changes behaviour. The organisations that make PSIRF stick treat the first years after go-live as part of implementation:
- Response discipline. Incidents get the response the plan says, and the temptation to escalate everything sensitive into a full investigation is resisted with the plan's own rationale.
- Learning consolidation. Findings from responses feed safety improvement plans, and safety actions are tracked to the point of measurable effect, not to the point of being assigned.
- Plan maintenance. The incident profile is re-examined on the plan's review cycle, and the plan moves when the profile does.
- Capability upkeep. Trained responders keep practising, new leads are trained as people move on, and peer networking continues, as the response standards expect.
Where implementations struggle
Three failure patterns come up repeatedly in published trust papers and ICB reviews. The plan is written before the profile is understood, so it inherits the old framework's assumptions with new headings. Training is bought for a launch cohort and never refreshed, so capability decays with staff turnover. And oversight keeps its old habits, asking for report counts, which quietly rebuilds the incentives PSIRF removed. All three have the same root: treating implementation as a documentation exercise. The framework's own guidance, summarised across this site from the principles to the toolkit, is unambiguous that it is an operating model change.