Published March 30, 2026 | Version v1

Eastern England SDE Airlock Manager Model Disclosure Control SOP

  • 1. Eastern England Secure Data Environment
  • 2. Health Innovation East

Description

This document explains how airlock managers in the Eastern England Secure Data Environment (EE‑SDE) check machine‑learning (ML) models before they are allowed to leave the secure platform. ML models can unintentionally reveal whether a person’s data was used during training, the Model Disclosure Control (MDC) process ensures that every model undergoes rigorous privacy checks before release.

The SOP outlines what information researchers must provide, such as model files, training data, and a clear description of the model’s purpose, and how airlock managers verify that the model matches what was approved in the project’s AI Risk Assessment. A key part of the process is the use of SACRO‑ML, a specialist tool that tests models for signs of overfitting or data leakage through simulated privacy attacks.

Airlock managers review these results alongside documentation to decide whether a model is safe, needs further evidence, or requires redesign. All decisions follow a transparent governance process and may be escalated if risks are unclear.

Files

EE_SDE_Airlock_Manager_MDC_Documentation.pdf

Files (271.1 kB)

Name Size Download all
md5:8c783be62a8ac225ac42b3652f894c96
271.1 kB Preview Download