Skip to content

CQC quality statement — Well-led

Governance, management and sustainability

"We have clear responsibilities, roles, systems of accountability and good governance. We use these to manage and deliver good quality, sustainable care, treatment and support. We act on the best information about risk, performance and outcomes, and we share this securely with others when appropriate." In MyCareCompliance, 79 mapped checks across 41 audit templates map to this quality statement.

Last reviewed: September 2026. This guidance reflects CQC information available at the date above — always refer to cqc.org.uk for current regulatory requirements.

How we check it

Each check below is a real question from a MyCareCompliance audit template. It names the regulation it evidences, describes what an auditor looks for in good and poor practice, and lists the evidence an inspector would expect you to produce.

  • 79 mapped checks under the "Governance, management and sustainability" quality statement
  • Evidences 4 regulations: Regulation 17 — Good governance, Regulation 20 — Duty of candour, Notifications (Registration Regulation 18) — Notification of other incidents, Regulation 12 — Safe care and treatment
  • Failed checks become tracked improvement actions with an owner, due date and evidence

The 79 checks

  1. Regulation 17 — Good governanceAccessible Information

    Does the provider audit its compliance with the Accessible Information Standard (AIS) and act on the findings to improve?

    What we look for: Look for a specific audit or review of accessible information within the last 12 months. Good looks like the manager identifying gaps (e.g., missing flags) and setting an action plan. A fail is zero management oversight of this standard.

    Evidence: AIS audit reports, quality assurance minutes, action plans, feedback surveys from clients with communication needs

  2. Regulation 17 — Good governanceAppraisal Audit

    Is there an accurate, up-to-date appraisal matrix demonstrating that all eligible staff receive a comprehensive annual appraisal?

    What we look for: Sample the appraisal matrix against the current active staff list. Good looks like a clear schedule showing when appraisals are due, completed, and overdue. Fail if there is no tracker or if significant numbers of staff are overdue without documented mitigation.

    Evidence: Appraisal matrix, HR tracking system, staff files

  3. Regulation 17 — Good governanceBusiness Continuity

    Is there a comprehensive, up-to-date Business Continuity Plan (BCP) that specifically addresses the risks unique to this domiciliary care service?

    What we look for: Review the BCP to ensure it has been updated within the last 12 months and signed by the Registered Manager. Good practice includes specific scenarios (e.g., loss of office, mass staff sickness). Fail if generic or out of date.

    Evidence: Business Continuity Plan, Risk Register, Annual Review minutes, Document control logs

  4. Regulation 17 — Good governanceBusiness Continuity

    How does the provider ensure continuity of operations during an IT outage, cyber-attack, or loss of digital care records?

    What we look for: Ask the manager what happens if the eMAR or digital care planning system goes down. Staff must have access to offline emergency contacts and paper MAR/care plan templates. Fail if total reliance on cloud/apps with no accessible offline backup.

    Evidence: IT Disaster Recovery Plan, Offline backup logs, Cyber Essentials certificate, Staff guidance for paper recording

  5. Regulation 17 — Good governanceCommissioned vs Delivered Care

    Are service users and funding bodies billed accurately based on the actual care delivered, rather than solely on commissioned hours?

    What we look for: Sample a recent billing cycle. Verify that invoices are adjusted for missed or significantly shortened calls in line with local authority contracts. Charging for care not provided is a critical fail.

    Evidence: Invoices, Billing schedules, Credit notes, Commissioner communication

  6. Regulation 17 — Good governanceCommissioned vs Delivered Care

    Do governance and quality assurance frameworks include regular, formal audits of commissioned versus delivered care?

    What we look for: Review the provider's own internal audits. They should routinely compare planned vs actual delivery and set actions for improvement. Absence of this specific management oversight is a fail.

    Evidence: Monthly manager audits, KPI reports, Quality assurance meeting minutes, Action plans

  7. Regulation 17 — Good governanceCompetency Audit

    Is there a clear, documented process for managing staff who fail a competency assessment or spot check?

    What we look for: Ask the manager for examples of failed competencies. Good looks like immediate action: stopping the staff member from performing the task, assigning a shadow shift, and re-assessing before sign-off. A fail is allowing the staff member to continue working solo while awaiting a training course.

    Evidence: Performance improvement plans, re-training records, records of suspension from specific duties

  8. Regulation 20 — Duty of candourComplaints Audit

    Are complainants provided with a clear written outcome, an apology where appropriate, and information on how to escalate if dissatisfied?

    What we look for: Check outcome letters for clarity, empathy, and a clear explanation of findings. Ensure an apology is given when things go wrong (meeting Duty of Candour thresholds if applicable). Fail if escalation details (e.g., LGSCO, funding authority) are missing from the final response.

    Evidence: Outcome letters, Duty of Candour records, Local Government and Social Care Ombudsman (LGSCO) leaflets

  9. Regulation 17 — Good governanceComplaints Audit

    Does management conduct monthly trend analysis on complaints to identify systemic issues or recurring themes (e.g., late calls, a specific staff member)?

    What we look for: Review the manager's monthly governance report. They should be categorising complaints by type and location/staff to spot trends. Fail if the complaints log is just a list with no overarching analysis or if obvious trends are ignored.

    Evidence: Monthly quality reports, governance dashboards, audit matrices

  10. Regulation 17 — Good governanceCompliments / Feedback

    Are all received compliments and general feedback recorded in a central log to enable effective tracking and trend analysis?

    What we look for: Review the central compliments/feedback log. It should capture the date, source, nature of feedback, and any actions taken. A fail is feedback being kept loosely in local files without central oversight or trend analysis.

    Evidence: Compliments log, feedback tracker, quality assurance dashboard, electronic care management system reports

  11. Regulation 17 — Good governanceContinuity of Care

    Is there an effective business continuity and contingency plan to maintain care delivery during staff shortages or emergencies?

    What we look for: Review the business continuity plan. It must include a RAG-rated priority list of service users to ensure the most vulnerable receive care during extreme events (e.g., snow, sudden sickness). A fail is an outdated or generic plan.

    Evidence: Business Continuity Plan, emergency staffing protocols, on-call logs, prioritization matrix for service users

  12. Regulation 17 — Good governanceCQC Notifications Audit

    Is there a robust, up-to-date policy and procedure for CQC statutory notifications that details what, when, and how to report?

    What we look for: Review the notifications policy. Good looks like a clear, accessible guide detailing all notifiable events, timelines, and the provider portal process. Fails if the policy refers to outdated legacy forms or lacks clarity on off-hours reporting.

    Evidence: Notifications Policy, Incident Management Policy, Staff Handbook

  13. Notifications (Registration Regulation 18) — Notification of other incidentsCQC Notifications Audit

    Are CQC statutory notifications submitted 'without delay' according to the required regulatory timeframes?

    What we look for: Compare the time of the incident to the timestamp of the CQC submission receipt. Good looks like submissions made within 24-48 hours, or immediately for serious events. Fails if notifications are routinely delayed or batched at the end of the week.

    Evidence: CQC Submission Receipts, Incident Logs with timestamps, On-call records

  14. Notifications (Registration Regulation 18) — Notification of other incidentsCQC Notifications Audit

    Are notification forms accurately completed with sufficient detail while strictly preserving the anonymity of the service user?

    What we look for: Read a sample of recent notifications. Good looks like clear, factual descriptions of the event and actions taken, using unique IDs rather than names. Fails if service user names or highly identifiable information are inappropriately shared in the narrative.

    Evidence: Copies of submitted CQC Notifications, Service User Care Plans (for cross-referencing)

  15. Regulation 17 — Good governanceDaily Care Records Audit

    Are daily care logs fully completed for every scheduled visit, with no missing entries or unexplained gaps?

    What we look for: Sample logs for 5 service users over a 7-day period. Cross-reference with the rota. Good looks like a corresponding log entry for every scheduled visit. A fail is missing entries where care was allegedly delivered but not documented.

    Evidence: Electronic call monitoring (ECM) records, paper daily logs, rota schedules

  16. Regulation 17 — Good governanceDaily Care Records Audit

    Do the recorded visit times (start, end, and duration) accurately match the scheduled times and ECM data?

    What we look for: Compare log entry times against ECM/rota. Good looks like accurate logging reflecting the actual time spent, matching the commissioned duration. A fail is systematically logging 30 minutes for a 15-minute visit, or leaving before tasks are complete.

    Evidence: ECM data, daily logs, timesheets, scheduling software reports

  17. Regulation 17 — Good governanceDBS Compliance

    Are DBS records stored and destroyed in compliance with the DBS Code of Practice and GDPR guidelines (not keeping certificates longer than 6 months)?

    What we look for: Inspect staff files to see if physical or scanned copies of DBS certificates are kept indefinitely. The provider should only record the certificate number, date, and clearance status after 6 months. A fail is finding years of original DBS certificates hoarded in staff files.

    Evidence: HR filing cabinets, secure digital drives, DBS retention policy, document destruction logs

  18. Regulation 17 — Good governanceDriving Compliance

    Is there a comprehensive and up-to-date 'Driving at Work' policy that clearly outlines staff responsibilities regarding vehicle maintenance, insurance, and legal compliance?

    What we look for: Review the service's driving policy to ensure it covers business insurance, MOT, road tax, and DVLA license checks. Good practice includes staff signing to confirm their understanding. A fail would be an absent, generic, or outdated policy.

    Evidence: Driving at work policy, Employee handbook, Staff induction records, Signed policy declarations

  19. Regulation 17 — Good governanceDriving Compliance

    Is there verified evidence on file that all staff using their own vehicles for work hold valid 'Business Use' motor insurance?

    What we look for: Sample insurance certificates for staff who drive between calls. Ensure the certificate explicitly states cover for 'business use' (Class 1 minimum), not just social, domestic and pleasure. A fail is missing proof or standard commute-only coverage.

    Evidence: Insurance certificates, Annual declaration forms, Compliance tracking matrix, Copies of policy schedules

  20. Regulation 17 — Good governanceDuty of Candour

    Is there an up-to-date Duty of Candour policy that clearly defines Notifiable Safety Incidents (NSIs) in a domiciliary care context?

    What we look for: Review the policy to ensure it explains the legal threshold for NSIs in community settings (e.g., severe harm, prolonged psychological harm, death). Fails if it only uses hospital/clinical examples or is past its review date.

    Evidence: Duty of Candour Policy, Incident Management Policy, Staff Handbook

  21. Regulation 20 — Duty of candourDuty of Candour

    Are all accidents, incidents, and safeguarding alerts effectively triaged by management to identify if the Duty of Candour threshold is met?

    What we look for: Select a sample of moderate-to-severe incidents from the last 3 months. Verify the manager has explicitly documented whether DoC was triggered. Fails if severe incidents occurred but DoC assessment was completely missed.

    Evidence: Accident/Incident log, Safeguarding tracker, Manager triage notes or checklists

  22. Regulation 20 — Duty of candourDuty of Candour

    For identified NSIs, is there evidence that a verbal apology and explanation was provided to the relevant person as soon as reasonably practicable?

    What we look for: Review the files of any recent NSIs. Look for clear documentation of a phone call or visit offering a sincere expression of sorrow or regret (an apology, not just an admission of liability). Fails if no verbal apology is documented.

    Evidence: Client care notes, Incident reports, Duty of Candour log, Communication logs

  23. Regulation 20 — Duty of candourDuty of Candour

    Is the verbal notification followed by a formal written notification and apology detailing the incident and inquiries to be made?

    What we look for: Check that a letter was sent following the verbal apology. It must contain a true account of the incident, what further inquiries will happen, and a written apology. Fails if the letter lacks a direct apology or is significantly delayed.

    Evidence: Copies of DoC letters sent to clients/relatives, email correspondence, postal receipts

  24. Regulation 17 — Good governanceDuty of Candour

    Does the service maintain a secure, comprehensive audit trail of all Duty of Candour correspondence and actions taken?

    What we look for: Review the tracking system used for DoC. It should securely hold the incident details, dates of verbal/written apologies, and copies of letters. Fails if records are scattered, missing, or lack dates and signatures.

    Evidence: Dedicated Duty of Candour register/log, central governance folder, archived correspondence

  25. Regulation 17 — Good governanceElectronic Call Monitoring

    Is there evidence that care staff consistently use the Electronic Call Monitoring (ECM) system to log in and out of all scheduled visits without bypassing the system?

    What we look for: Sample a minimum of 10 staff members' ECM records for the past month. Good looks like over 95% compliance with electronic logging, with valid reasons for manual overrides (e.g., phone broken). Frequent manual log-ins without justification or disciplinary follow-up constitutes a fail.

    Evidence: ECM compliance reports, manual timesheet adjustments, staff supervision records, app usage logs

  26. Regulation 17 — Good governanceElectronic Call Monitoring

    Are robust contingency plans in place and followed when the ECM system experiences an outage or staff have no mobile signal?

    What we look for: Review the ECM policy and business continuity plan. Good looks like clear instructions for staff (e.g., using a freephone landline system, SMS backup, or paper timesheets) during app failures, and mapping of known rural 'blackspots'. No clear procedure for data capture during an outage is a fail.

    Evidence: Business continuity plan, staff ECM training records, paper timesheet backups, signal blackspot registers

  27. Regulation 17 — Good governanceEmergency / On Call

    Are all incoming on-call queries, emergencies, and actions taken accurately documented in a central log?

    What we look for: Sample 10 random out-of-hours entries from the last quarter to check for detail, timeframes, and clear outcomes. Good logs detail the exact time, caller, issue, advice given, and subsequent actions. A fail would be fragmented, missing, or illegible on-call notes that do not explain how issues were resolved.

    Evidence: Out of hours logs, electronic call management system, on-call record books

  28. Regulation 12 — Safe care and treatmentEmergency / On Call

    Do on-call staff have immediate access to the Business Continuity Plan and understand how to activate it during a major incident?

    What we look for: Ask an on-call staff member how they would handle a systemic IT failure or extreme weather event out of hours. They must know where the BCP is and how to invoke it. A fail would be the BCP only being accessible on the office server with no offline backup for the on-call team.

    Evidence: Business Continuity Plan, on-call staff competency checks, emergency contacts list

  29. Regulation 17 — Good governanceGovernance / Quality Assurance

    Are routine audits (e.g., medication, daily care logs, care plans) completed according to the provider's monthly schedule, with clear action plans for identified shortfalls?

    What we look for: Review a sample of internal audits from the last month. Good practice shows not just tick-boxes, but detailed analysis of shortfalls with assigned responsibilities and deadlines. Fail if audits are missing, generic, or lack action plans.

    Evidence: Completed audit tools, Monthly audit planner, Action plans, Sign-off sheets

  30. Notifications (Registration Regulation 18) — Notification of other incidentsGovernance / Quality Assurance

    Are statutory CQC notifications (e.g., serious injuries, safeguarding, police involvement) submitted without delay and documented in the provider's central log?

    What we look for: Cross-reference the incident and safeguarding logs against the CQC notification log. Good practice means all reportable events are notified within required timeframes. Fail if reportable incidents occurred but no notification was made.

    Evidence: CQC notification log, Copies of submitted notification forms, Cross-reference with incident and safeguarding logs

  31. Regulation 17 — Good governanceGovernance / Quality Assurance

    Are essential policies and procedures reviewed regularly, aligned with current legislation, and effectively communicated to all care staff?

    What we look for: Check the policy index for review dates and sample recent updates (e.g., infection control, safeguarding). Good looks like staff signing to acknowledge reading new versions. Fail if policies reference outdated legislation or staff are unaware of changes.

    Evidence: Policy review schedule, Policy index, Staff newsletter, Memo sign-off sheets for policy updates

  32. Regulation 17 — Good governanceHealth & Safety

    Is the business continuity and emergency plan up-to-date, comprehensive, and understood by the management team?

    What we look for: Check the BCP covers extreme weather, IT failure, mass staff sickness, and loss of office premises. Test the on-call manager's knowledge of the plan. A fail is an out-of-date plan with old contacts or no clear prioritization of vulnerable clients.

    Evidence: Business continuity plan, Emergency contact lists, On-call grab bags/digital access logs, Management meeting minutes

  33. Regulation 17 — Good governanceHealth & Safety

    Is there a clear, up-to-date Health and Safety policy and a designated lead person overseeing H&S governance across the service?

    What we look for: Verify the H&S policy is reviewed annually and names the responsible person. Check the office environment (fire exits, extinguisher checks, PAT testing). A fail is an outdated policy, no designated lead, or an unsafe branch office environment.

    Evidence: Health and Safety Policy, Employer's Liability Insurance certificate, H&S committee minutes, Office risk assessment

  34. Regulation 20 — Duty of candourIncidents / Accidents Audit

    Is the Duty of Candour applied correctly for notifiable safety incidents, including verbal and written apologies?

    What we look for: Identify any 'notifiable safety incidents' (moderate harm or above). Check for evidence of a verbal apology, followed by a formal written apology and explanation of the investigation. A fail is failing to recognise a qualifying incident or missing the written apology.

    Evidence: Duty of Candour log, correspondence with next of kin/service user, incident investigation files

  35. Regulation 17 — Good governanceIncidents / Accidents Audit

    Does management conduct routine trend analysis to identify recurring themes and take proactive preventative action?

    What we look for: Examine the monthly incident overview. Look for analysis by time, location, staff member, and incident type to spot patterns (e.g., falls always happening at 8pm). A fail is merely counting the number of incidents without analyzing data for trends.

    Evidence: Monthly audit reports, KPI dashboards, incident matrix, management meeting minutes

  36. Regulation 17 — Good governanceInduction / Care Certificate

    Is there robust management oversight and final quality assurance sign-off by a competent assessor for completed Care Certificate portfolios?

    What we look for: Review completed portfolios to ensure they are signed off by an occupationally competent person, not merely self-certified by the worker. Management should have a clear dashboard tracking induction status. Poorly completed workbooks being signed off indicates a QA failure.

    Evidence: Signed Care Certificates, Internal QA records, Assessor qualifications, Management dashboards

  37. Regulation 17 — Good governanceInformation Governance / GDPR

    Are comprehensive Information Governance and GDPR policies in place and reviewed annually?

    What we look for: Review the core IG policies. Good looks like policies that are tailored to domiciliary care, up-to-date with current legislation, and accessible to staff. Fail: generic, out-of-date policies.

    Evidence: Data Protection Policy, GDPR Policy, Subject Access Request Procedure, Information Sharing Policy

  38. Regulation 17 — Good governanceInformation Governance / GDPR

    Has the provider successfully completed and published an annual Data Security and Protection Toolkit (DSPT)?

    What we look for: Check the DSPT status online or ask for the certificate. Good looks like 'Standards Met' or higher within the last 12 months. Fail: unpublished DSPT or missing action plans for unmet standards.

    Evidence: DSPT publication certificate, DSPT action plan, DSPT submission confirmation

  39. Regulation 17 — Good governanceInformation Governance / GDPR

    Are physical records (e.g., paper care plans, staff files) stored securely to prevent unauthorized access?

    What we look for: Walk around the office. Good looks like locked cabinets for staff/client files and a clear desk policy. Ensure care plans left in clients' homes are kept respectfully. Fail: loose files left out.

    Evidence: Office security walkaround, locked filing cabinets, clear desk policy, archived record storage

  40. Regulation 17 — Good governanceInformation Governance / GDPR

    Are digital care records, mobile devices, and systems protected by robust access controls and passwords?

    What we look for: Check how digital systems are accessed. Good looks like unique logins (no sharing), complex passwords, and remote wipe capabilities for staff phones. Fail: shared generic logins or unlocked PCs.

    Evidence: IT security policy, mobile device management (MDM) software evidence, password policy, staff leaver checklist

  41. Regulation 17 — Good governanceInformation Governance / GDPR

    Are records retained for appropriate legal timeframes and destroyed securely when no longer needed?

    What we look for: Review the retention schedule and disposal methods. Good looks like clear timelines (e.g., care records kept for 3 years post-discharge) and use of cross-cut shredders or secure waste contractors. Fail: hoarding old files indefinitely.

    Evidence: Data Retention Schedule, confidential waste bins, certificates of secure destruction

  42. Regulation 17 — Good governanceLate / Shortened Visits Audit

    Does the Registered Manager routinely analyze late/shortened visit data to identify trends, adjust rotas, and ensure accurate billing?

    What we look for: Examine the monthly governance reports. The manager should track the percentage of late/short calls, identify underlying causes (e.g., specific rounds, traffic, overbooking), and take corrective action. A fail is collecting ECM data but never using it to drive improvements.

    Evidence: Monthly management reports, Quality assurance audits, Invoicing adjustments, KPI dashboards

  43. Regulation 17 — Good governanceLearning Lessons

    Does the provider conduct quarterly thematic or trend analysis on incidents, accidents, complaints, and safeguarding alerts?

    What we look for: Check the most recent quarterly governance report for data analysis (e.g., falls at specific times, recurrent missed visits). Good looks like data being actively grouped by theme, location, or staff member to spot patterns. Fail if data is collected but not analysed for trends.

    Evidence: Quarterly quality reports, clinical governance minutes, data dashboards, trend analysis charts

  44. Regulation 17 — Good governanceLearning Lessons

    Is there a robust system for tracking action plans generated from lessons learned through to completion?

    What we look for: Review the continuous improvement or action tracker. Ensure every lesson learned has specific actions, assigned owners, and target dates. Fail if actions are left open indefinitely, or if there is no check to ensure the implemented action was actually effective.

    Evidence: Continuous Improvement Plan, action trackers, meeting minutes showing action closures

  45. Regulation 17 — Good governanceManagement Governance

    Are comprehensive quality assurance audits completed on schedule, with clear, time-bound action plans that are monitored until completion?

    What we look for: Sample 3 recent audits. Good looks like clear identification of shortfalls with specific actions, owners, and deadlines. Fail if audits are a tick-box exercise, actions are open without progress, or audits are missed.

    Evidence: Audit schedule, completed audit tools (e.g. care plans, meds), action plans, sign-off records

  46. Regulation 17 — Good governanceManagement Governance

    Are all organisational policies and procedures up to date, aligned with current legislation (e.g., MCA, Health and Safety), and accessible to staff?

    What we look for: Review the policy index and sample 3 key policies. Good looks like policies reviewed within the last year, reflecting current local guidelines, and easily accessible by field staff. Fail if policies reference outdated legislation (e.g., DoLS instead of LPS preparations, old safeguarding boards).

    Evidence: Policy index, updated policies (Safeguarding, Whistleblowing), staff handbooks, digital portal access logs

  47. Regulation 17 — Good governanceManagement Governance

    Does the service have a robust, tested Business Continuity Plan (BCP) that covers severe weather, IT failure, and staffing crises?

    What we look for: Check the BCP. Good looks like specific, actionable steps for domiciliary care scenarios (e.g., prioritizing highly dependent clients during snow). Fail if the BCP is a generic template, out of date, or lacks prioritized client lists.

    Evidence: Business Continuity Plan, emergency contact lists, testing/drill records, risk register

  48. Regulation 17 — Good governanceMCA / Consent / Best Interests

    Is there effective management oversight and a central register of all people who lack capacity, have LPAs, or are subject to restrictive practices?

    What we look for: Ask the manager for their tracker of capacity, LPAs, and restrictions. Check that it is accurate, up to date, and used to trigger reviews. Fails if the manager relies solely on individual files and lacks a service-wide overview of MCA compliance.

    Evidence: MCA/LPA central register, Audits of care plans, Management meeting minutes

  49. Regulation 17 — Good governanceMedication / MAR Audit

    Are completed MAR charts returned to the office promptly at the end of the cycle and audited by management to drive improvement?

    What we look for: Look at the service's own monthly MAR audit process. Good looks like all paper MARs returned within 3 days of cycle end, audited for errors, with a clear action plan generated for any missing signatures. A fail is a backlog of unaudited MAR charts in the office.

    Evidence: Returned MAR charts, previous MAR audit records, quality assurance action plans

  50. Regulation 17 — Good governanceMedication Competency Audit

    Are the staff who conduct medication competency assessments (assessors) suitably qualified, experienced, and themselves assessed as competent?

    What we look for: Check the credentials of the supervisors/seniors doing the assessing. They must have up-to-date advanced medication training or 'train the trainer' qualifications, and their own practice must be periodically observed.

    Evidence: Train the trainer certificates, Assessor competency records, Assessor job descriptions

  51. Notifications (Registration Regulation 18) — Notification of other incidentsMissed Visits Audit

    Where a missed visit caused harm or met the threshold for a statutory notification, has the CQC been notified without delay?

    What we look for: Cross-reference the missed visit log with CQC notifications. If a missed visit resulted in police/ambulance attendance or serious injury, check that a notification was submitted. A fail is missing mandatory CQC notifications.

    Evidence: CQC notification portal records, Incident reports, Provider's notification log

  52. Regulation 20 — Duty of candourMissed Visits Audit

    Has the Duty of Candour been applied appropriately where a missed visit resulted in a notifiable safety incident?

    What we look for: If any missed visit resulted in moderate or severe harm, verify that a formal Duty of Candour letter was sent, offering an apology and explaining the investigation. A fail is failure to formally apologise and document it in writing.

    Evidence: Duty of Candour letters, Communication logs with families, Incident investigation files

  53. Regulation 17 — Good governanceMoving & Handling

    Does management have effective oversight of moving and handling practices, audits, and equipment safety across the service?

    What we look for: Review internal quality audits and management meetings. Good looks like the Registered Manager tracking LOLER expiries, analyzing fall trends, and auditing care plan quality systematically. Fail if the service lacks a central overview of equipment safety or moving and handling compliance.

    Evidence: Quality assurance audits, management reports, KPI dashboards, action plans.

  54. Regulation 17 — Good governanceNutrition & Hydration

    Does the service regularly audit nutrition and hydration records to identify shortfalls and drive care improvement?

    What we look for: Review management audits of fluid/food charts over the past quarter. Good looks like identified issues (e.g., missed fluid targets) resulting in staff coaching or care plan reviews. Fail if no oversight exists.

    Evidence: Internal audits, spot check reports, management action plans, team meeting minutes

  55. Regulation 17 — Good governanceOnboarding New Staff

    Have new staff been trained on the electronic care planning system and issued secure, individual logins, alongside clear guidance on data protection?

    What we look for: Check that staff are using their own logins for care apps and have signed data protection agreements. Sharing passwords or generic 'new starter' logins being used to document care is a clear fail.

    Evidence: IT acceptable use policies, signed confidentiality agreements, system audit trails, training logs

  56. Regulation 17 — Good governancePolicy & Procedure Audit

    Are all mandatory policies and procedures readily accessible to all staff, including remote domiciliary care workers?

    What we look for: Check if care workers can easily access key policies (e.g., via an app or secure portal) while in the community. Good practice means immediate access without having to visit the office. A fail is if staff rely on outdated paper copies or cannot locate policies.

    Evidence: Staff app or portal access, policy index, staff handbook, spot checks with staff on duty

  57. Regulation 17 — Good governancePolicy & Procedure Audit

    Is there a robust version control system ensuring all policies are reviewed annually or when legislation changes?

    What we look for: Review a sample of 5 key policies (e.g., Safeguarding, Medication, IPC). Ensure they have an active version number, date of last review, and date of next review. A fail is finding past-due review dates or multiple versions of the same policy in circulation.

    Evidence: Policy review schedule, policy document footers (version control), minutes of management meetings

  58. Regulation 17 — Good governancePolicy & Procedure Audit

    Are data protection and confidentiality policies compliant with UK GDPR, with clear guidelines for mobile devices and remote working?

    What we look for: Ensure policies cover the secure use of digital care planning apps on personal or company mobile phones (e.g., screen locks, not sharing passwords). A fail is the absence of clear instructions on handling sensitive data securely in the community.

    Evidence: Data protection policy, mobile device usage policy, staff confidentiality agreements

  59. Regulation 17 — Good governancePrevious Actions / QIP Review

    Is there a live, consolidated Quality Improvement Plan (QIP) that captures actions from all audits, inspections, and incident investigations?

    What we look for: Review the central action tracker/QIP. Good looks like a single, accessible document or dashboard capturing all service improvements with clear owners and deadlines. Fails if actions are scattered across different folders or there is no master tracker.

    Evidence: Central QIP document, action trackers, governance meeting minutes, digital audit system dashboards

  60. Regulation 17 — Good governancePrevious Actions / QIP Review

    Are overdue or delayed actions on the QIP clearly flagged, escalated to senior management, and updated with revised timelines and rationales?

    What we look for: Filter the QIP for overdue actions. Good looks like active management of delays, with documented reasons and evidence of senior oversight. Fails if target dates have passed with no updates or escalation to the provider/directors.

    Evidence: QIP tracker, senior management meeting minutes, escalation emails, risk register

  61. Regulation 17 — Good governanceProbation Audit

    Are structured probation review meetings (e.g., 4, 8, 12 weeks) taking place and documented?

    What we look for: Look for a clear timeline of probation reviews. Good looks like documented discussions covering performance, training gaps, and feedback. It is a fail if reviews are consistently delayed, skipped, or missing entirely.

    Evidence: Supervision notes, probation review forms, meeting minutes in staff files

  62. Regulation 17 — Good governanceProbation Audit

    Is the final decision to pass, extend, or terminate the probationary period clearly documented and communicated?

    What we look for: Check the end of the probation timeline for a formal sign-off. If probation was extended, the reasons and new targets must be explicitly documented. A fail is a staff member drifting past their probation end date with no formal review or confirmation letter.

    Evidence: End of probation sign-off letter, final review meeting notes, HR portal records

  63. Regulation 17 — Good governanceRight to Work

    Does the service maintain a robust, active tracking system for staff with time-limited right to work (visas/BRPs)?

    What we look for: Examine the tracking matrix for all staff on List B (time-limited visas). The system must show upcoming expiry dates and trigger alerts 1-3 months in advance. A fail occurs if the tracking system is missing, outdated, or relies entirely on manual memory rather than a systematic process.

    Evidence: HR software reports, Excel tracking matrices, automated alert systems, staff visa tracker

  64. Regulation 17 — Good governanceRight to Work

    For international students, are term dates strictly recorded and weekly working hours monitored to prevent visa breaches?

    What we look for: Identify any staff on Tier 4 / Student Visas. Ensure the provider has a physical printout of their specific university term dates and that timesheets prove they never exceed their limit (e.g., 20 hours/week) during term time. A fail occurs if term dates are not on file or timesheets show breaches of working hour limits.

    Evidence: University term-date printouts, student declaration forms, weekly timesheets, rota software alerts

  65. Regulation 17 — Good governanceRight to Work

    If the provider holds a Sponsor Licence, are Sponsor Management System (SMS) reporting duties being met?

    What we look for: For providers sponsoring migrant workers, review evidence that the SMS is actively managed and updated within 10 days for significant changes (e.g., staff changing address, unauthorised absence). A fail occurs if the SMS is neglected, putting the provider's licence and safe staffing levels at risk.

    Evidence: SMS login records, change of address reports, absence reporting records, sponsorship policy

  66. Regulation 17 — Good governanceRight to Work

    Are RTW records stored securely and retained for a minimum of two years after a staff member's employment ends?

    What we look for: Sample files of staff who left the organisation within the last two years. Ensure their RTW evidence is still securely accessible and has not been prematurely destroyed. A fail is indicated if RTW records for recent leavers cannot be produced for inspection.

    Evidence: Archived personnel files, digital HR system records, data retention policy, leaver files

  67. Regulation 17 — Good governanceRota / Staffing Capacity

    Is staffing capacity formally assessed before accepting new care packages to ensure current commitments are not compromised?

    What we look for: Review the process for accepting new referrals over the past month. Look for evidence that management calculates available staff hours and geographical capacity before saying yes. A fail is taking on new packages that immediately lead to late/rushed calls across the board.

    Evidence: Capacity planning documents, new referral assessments, management meeting minutes, documented decline of packages

  68. Regulation 17 — Good governanceService User Experience

    Does the provider actively seek and analyze service user feedback on safety and governance, driving continuous improvement?

    What we look for: Examine the latest quality assurance surveys specifically looking at questions around safety, reliability, and management responsiveness. Good looks like high return rates and a published action plan based on results. A fail is collecting surveys but never analyzing the data or acting on negative feedback.

    Evidence: Annual/Quarterly quality surveys, Survey analysis reports, "You said, we did" newsletters, Continuous Improvement Plan

  69. Regulation 17 — Good governanceService User Experience

    Is there robust senior management oversight of service user experience metrics, ensuring governance structures actively monitor safety indicators?

    What we look for: Look at the monthly management or clinical governance meetings to see if service user experience (complaints, incidents, late calls) is a standing agenda item. Good looks like leaders triangulating this data to identify systemic issues. A fail is a disconnect where the registered manager collects data but it is never reviewed for strategic oversight.

    Evidence: Board/Management meeting minutes, Monthly KPI dashboards, Audit schedules, Provider Information Return (PIR) drafts

  70. Regulation 17 — Good governanceService User Reviews Audit

    Is there a robust oversight system managed by the Registered Manager to ensure no service user is overdue for their review?

    What we look for: Examine the service's tracking system for reviews. The manager should have a clear view of what is due, overdue, and completed. Fails if the manager cannot easily identify when reviews are due.

    Evidence: Quality assurance matrix, Review tracker spreadsheet, Management meeting minutes

  71. Regulation 17 — Good governanceSponsor Worker Compliance

    Is the Sponsorship Management System (SMS) accurately updated within 10 working days for any changes to sponsored workers' circumstances?

    What we look for: Review a sample of workers who have changed addresses, roles, or left the service. Check that these changes were reported on the SMS within 10 days. A fail is a backlog of unreported changes, jeopardising the provider's sponsor license.

    Evidence: SMS login records, Change of circumstance reports, Worker address history, Leavers log

  72. Regulation 17 — Good governanceSponsor Worker Compliance

    Are working hours closely monitored to ensure compliance with visa conditions (e.g., maximum 20 hours supplementary work) and Working Time Regulations?

    What we look for: Examine rotas for sponsored workers. Verify they are fulfilling their primary sponsored hours and that any secondary work is legally permitted and declared. A fail is staff working excessive hours causing fatigue, or breaching their visa conditions by working unauthorized second jobs.

    Evidence: Timesheets, Rota system reports, Opt-out agreements, Declarations of secondary employment

  73. Regulation 17 — Good governanceSpot Checks Audit

    When spot checks identify poor practice or non-compliance, are clear action plans created, communicated, and followed up promptly?

    What we look for: Trace 2-3 spot checks where issues were identified (e.g., missed PPE, lateness). Good looks like an immediate debrief, documented retraining/shadowing, and a follow-up spot check within a few weeks. Failure to address identified poor practice is a regulatory breach.

    Evidence: Failed spot check records, performance improvement plans, training records, disciplinary notes

  74. Regulation 17 — Good governanceSpot Checks Audit

    Does the Registered Manager maintain an overarching matrix to analyze spot check data for systemic issues or widespread training gaps?

    What we look for: Ask the Registered Manager how they use spot check data. They should be able to show a tracker that flags overarching trends (e.g., multiple staff failing on manual handling, triggering a whole-team refresher). Siloed spot checks with no management oversight fail this check.

    Evidence: Spot check tracker, monthly audit reports, management meeting minutes, training matrix

  75. Regulation 17 — Good governanceSupervision Audit

    Are actionable, SMART goals set during supervision, and are previous action points reviewed at the next session?

    What we look for: Look at a sequence of 2-3 supervisions for the same staff member to track the continuity of action points. Good practice ensures goals are Specific, Measurable, Achievable, Relevant, and Time-bound. A fail is seeing the exact same uncompleted action carried over multiple times without escalation or support.

    Evidence: Consecutive supervision records, action plans, performance improvement plans

  76. Regulation 17 — Good governanceSupervision Audit

    Are supervision records detailed, securely stored, and signed and dated by both the supervisor and the supervisee?

    What we look for: Check the physical or digital files for completeness, legibility, and appropriate signatures indicating mutual agreement. Good looks like contemporaneous notes uploaded securely to the HR system with both parties signing off. Missing signatures, loose papers, or vague one-word answers constitute a fail.

    Evidence: Signed supervision agreements, digital signature logs, secure HR files

  77. Regulation 17 — Good governanceSupervision Audit

    Are the results of field spot checks, direct observations, and client feedback integrated into the formal supervision discussion?

    What we look for: Ensure that observational data from field visits (e.g., medication competency, infection control practice) feeds directly into one-to-one supervisions. Good records triangulate client feedback with the worker's self-assessment. Operating supervision completely in isolation from field performance data is a major governance gap.

    Evidence: Spot check forms, client survey results, supervision records, compliments/complaints logs

  78. Regulation 17 — Good governanceTraining Matrix Audit

    Does the training matrix accurately reflect staff training records and certificates?

    What we look for: Cross-reference the matrix against actual certificates in 5 staff files. Good looks like 100% accuracy between the matrix and certificates. Fail if the matrix shows completed training but no certificate or evidence exists.

    Evidence: Training matrix, 5x random staff personnel files, Physical/Digital certificates

  79. Regulation 17 — Good governanceTraining Matrix Audit

    Does the system proactively flag training expiry dates to allow for timely re-booking?

    What we look for: Look at how upcoming expiries (next 30-90 days) are tracked. Good looks like a RAG-rated matrix where amber items are already booked onto future courses. Fail if training only gets booked after it has already expired.

    Evidence: Training matrix (conditional formatting/RAG rating), Booking emails, Training calendar

Other Well-led quality statements

See it with your own service

Book a free demonstration and we will walk through the platform using scenarios from a service like yours.