Clinical evaluators read bid responses the way they read incident reports. They are looking for the harm, the control and the person. Most responses give them none of the three.
The generic-risk paragraph and what it costs
Two paragraphs of generic risk copy fail the same reader test as no risk copy at all. The evaluator scores what is specific and discounts what is generic and generic is the default register of bid writing.
Name the harm
Delayed diagnosis. Wrong medication. Missed follow-up. Inappropriate access to a sensitive record. These are the words clinicians use in the meetings they actually hold. A response that uses them is speaking the evaluator's language.
Name the mitigation
A specific control tied to a specific harm, not a shopping list of frameworks. One harm, one control, one test that proves the control works.
Name the accountable person
Not a role - a person. The [Caldicott Guardian](https://www.gov.uk/government/publications/the-caldicott-principles) who signs the DPIA is not the same person as the clinical safety officer who signs the hazard log and a response that conflates them has told the evaluator it has not met either.
What the evaluator sees
A response that reads like the clinical governance meeting the trust actually holds, rather than like the shopping-list response every other bidder submitted. The same discipline underpins the ethics work published through the [NHS AI Lab](https://transform.england.nhs.uk/ai-lab/) - name the harm before naming the technology.
Strategist so-what
Claim. Specificity on harm, mitigation and accountability is the difference between a scored response and a discounted one.
Implication. Write clinical risk in the register clinicians use and the response reads as an insider document rather than a supplier document.