Aligning TRE Assurance Frameworks in the UK: A SATRE-Based Control Alignment Approach
Main Article Content
Abstract
Trusted Research Environments (TREs) are a core part of the UK’s sensitive data research infrastructure. There is an unclear assurance landscape for operators, however. Currently, organisations can rely on different overlapping frameworks such as ISO 27001, the Digital Economy Act, the NHS England Data Security and Protection Toolkit, Cyber Essentials, and a draft NHS Secure Data Environment (SDE) Accreditation, each with its own language and level of detail. As a result, TREs are often required to evidence the same controls multiple times, and data controllers struggle to judge whether different assurance routes are genuinely equivalent. The Standardised Architecture for TREs (SATRE) specification is a community-developed definition of the capabilities that TREs should have to ensure safe and secure management of sensitive data for the purposes of research. Here, we describe a SATRE-centred alignment method that maps controls from the major UK frameworks into a single Control Alignment Table (CAT). The aim was to create a common structure that makes alignment clearer and reduces duplication. The CAT will help TRE operators organise evidence more consistently, simplify audit preparation, and provide data controllers with a transparent basis for assessing governance and risk. Case studies from the Health Informatics Centre (University of Dundee) and East of England SDE show how the CAT supports continuous improvement, highlights gaps, and demonstrates the maturity of TRE operations. The SATRE-based Control Alignment Table provides a practical path to make assurance more coherent and reusable for TRE operators and data controllers in the UK and, potentially, internationally.
