Regulation

Regulation 17: Good governance

Regulation 17 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 is the well-led regulation. It is the regulation CQC inspects most heavily under the well-led key question, and the regulation that carries through to the rating outcome more reliably than any other. This page is the plain-English explainer; the verbatim statute is at legislation.gov.uk.

What the regulation says

Reg 17(1) sets the headline duty: providers must establish and operate effective systems and processes to ensure compliance with the requirements in Part 3 of the regulations (Reg 17 is, in effect, the regulation that requires the system that runs the rest of the regulations). Reg 17(2) lists six things those systems must enable in particular: assessing and improving the quality and safety of the service, assessing and mitigating the risks to service users, maintaining an accurate and contemporaneous record for each service user, maintaining accurate records of employment and management, seeking and acting on feedback, and continually evaluating the processes themselves.

Reg 17(3) gives CQC the power to require a written report on quality, safety, risks, and improvement plans on 28 days' notice. The 28-day clock starts the day after the request is made. Most providers never receive a Reg 17(3) request; the ones who do are usually those whose ratings or reports already suggest the governance system is not visible.

What CQC expects

CQC inspects Reg 17 through the well-led key question. Inspectors expect to see a leadership team that knows what its service is doing, has a working cadence of review meetings, holds a live risk register, runs an audit programme that produces visible change, and can describe what the team learned from the last quarter without rehearsing it. The well-led question is essentially: does the leadership team know what its service is doing, and is it acting on what it knows.

The records the inspector samples are the meeting minutes, the risk register, the improvement-actions register, the clinical-audit programme, the complaints log aggregate view, the safeguarding-pattern view, the staffing-currency dashboard. Reg 17 is the regulation that ties all of them together; absent evidence on any one of them produces a Reg 17 finding even when the underlying lifecycle (incidents, complaints, etc.) is operating cleanly.

If you are deciding what each record should do, the CQC governance document template guide maps the written framework to the live risk, audit, action and meeting records CQC follows.

Accurate, complete and contemporaneous records

Regulation 17(2)(c) requires each service-user record to be kept securely and to be accurate, complete and contemporaneous. CQC's Regulation 17 guidance says a fit-for-purpose record is legible, up to date and filed without undue delay. It should include the care or treatment provided, the decisions taken and the relevant discussion with the person or someone lawfully acting for them.

  • Accurate means the record matches what happened, who was involved and what information was available at the time.
  • Complete means another authorised person can understand the assessment, decision, care, outcome and follow-up without relying on staff memory.
  • Contemporaneous means information is recorded at the time or without undue delay. A later entry should be clearly identifiable, not written as though it was made earlier.
  • Secure means access, amendment, retention and destruction are controlled, whether the record is electronic or on paper.

An inspector may select one person and follow the record across a consultation, consent decision, diagnostic result, referral, incident or complaint. Gaps become a safety and governance issue when the next person cannot see what was decided or what still needs to happen. Use the record keeping and documentation standards policy with the record keeping and confidentiality checklist to test that trail.

What providers most often miss

The Reg 17 patterns that surfaced repeatedly in thirteen years of CQC inspections come from the meeting trail more often than the individual registers. The most common: meetings scheduled in the policy but actually meeting four times in the last twelve months when the policy says monthly; minutes that record what was discussed but not what was decided; decisions that produced no corresponding improvement actions; standing agenda items that quietly disappeared because nothing was being found (the inspector reads the disappearance as the team stopping looking, not as the service improving); the risk register where every entry was scored eighteen months ago and not reviewed since. Each of these is a well-led finding on its own. The aggregate pattern is the rating signal. Services rated Outstanding on well-led almost always show a meeting trail where decisions get documented, actions get opened, completions get evidenced, and patterns get reviewed in the open.

How Verivius handles it

Verivius drives this regulation through the risk-register lifecycle, the clinical-audit cycle, the improvement-actions register, and continuous inspection readiness. Governance meetings carry attendance, decisions, and cross-linked actions in the platform's governance-meeting register, so the meeting trail inspectors read is reconstructable in the platform rather than scattered across email threads and shared drives.

Sample policy template: Reg 17 Good governance. Article worth reading alongside: the governance meeting cadence that actually works.

Related sample policies

Verivius-authored templates that pair with this page. Verbatim statutory text plus plain-British summary and adoption sections; for adaptation, not adoption unchanged.

Get started free

Free to start, no card. A 14-day trial when you subscribe.

Last reviewed 19 July 2026