Tuli Health | Remote with occasional travel | 2 to 3 days per week | 6 months
Contract: Contract
Level: Senior
About Tuli Health:
Tuli Health is a CQC-registered phlebotomy and diagnostics infrastructure company. We run a network of 180+ phlebotomy hubs, integrated with multiple diagnostic laboratories, alongside our own mobile phlebotomy service currently under development, a SaaS platform and a training arm.
The Role:
We’re developing our compliance function. You will own all quality and compliance projects end to end, working directly with the founders and the Head of Clinical Operations.
This is a formalisation job rather than a from-zero build. The practices largely exist. What is missing is the documented system, the evidence trail and someone to drive it to completion.
What you will deliver:
You first priority is to help Tuli become accredited and certified for the following elements:
- DSP Toolkit published at "Standards Met"
- NHS secure email accreditation (DCB1596) achieved for our domain
- ISO 9001 certification with a UKAS-accredited body, through Stage 1 and Stage 2
- A documented operating system: accurate, owned process maps for how Tuli actually runs, good enough that a new joiner could follow them and an engineer could build from them
The fourth is not a by-product of the first three. We care about it in its own right.
You will own the plan, run a single combined gap analysis across all three, write the documentation, chase the evidence, and manage the certification body and NHS England relationships.
We supply the decisions, the technical work, the clinical input and the facts about how Tuli actually operates. You supply the system and the momentum.
What we are looking for:
Essential:
- You have published a DSPT submission as the responsible person, not as a contributor
- You have implemented ISO 9001 from scratch through to certification, or run it as management representative
- You have worked inside a CQC-registered organisation
- You are comfortable building a compliance function from nothing, working from an existing policy set rather than inheriting a team
- Strong document control discipline
Desirable:
- DCB1596 secure email accreditation experience
- Experience in a distributed, multi-site or franchised delivery model, where the real challenge is evidencing control of processes performed by third parties
- Able to turn a messy real-world process into a clear written specification
- Trained internal auditor
Not required, but a bonus if you have the experience:
- Information security specialism. ISO 27001 is parked for now, with scope to revisit next year
- Clinical background
What you will be working with:
Cyber Essentials certification, an information security policy, existing CQC policies, business continuity plan, QMS document management policy, supplier assessment framework, a hub performance classification framework using 90-day failure rates, and a Jira-based support and incident system.
The interesting part:
Most quality systems are designed for organisations that own their delivery sites. Ours does not. Evidencing control over 180+ locations we work with rather than own is the genuinely difficult problem in this role, and the part that will occupy a Stage 2 auditor.
Practicalities:
- Fractional or interim, 2 to 3 days per week
- 6 month engagement, with a defined end tied to the deliverables
- Remote, with occasional travel for audits and team sessions
- Scope for extension into ISO 27001 next year
- We would like this to become a longer-term relationship. If it works well, there is an ongoing Quality & Compliance Lead role here as the systems move into their annual cycle
To Apply:
Tell us about one certification or accreditation you took an organisation through. What the scope was, what went wrong, and what you would do differently. Please email us with your CV at [email protected].
Pay: £250.00-£400.00 per day
Benefits:
Work Location: Remote