Sample policy · Reg 12

Business Continuity and Emergency Preparedness Policy

Statutory anchor: Regulation 12 (safe care and treatment), Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 (SI 2014/2936). This policy also engages Regulation 17 (good governance) and Regulation 15 (premises and equipment), and Civil Contingencies Act principles where relevant. · primary source

Download the PDF

The PDF version of this template is the same content, formatted for adaptation in your document control system. The disclaimer above is repeated on the PDF cover.

Verivius pack version v1, 2026-06-10

1. What the regulation says

Care and treatment must be provided in a safe way for service users. (Reg 12(1) (the headline duty))

assessing the risks to the health and safety of service users of receiving the care or treatment, (Reg 12(2)(a) (risk assessment))

doing all that is reasonably practicable to mitigate any such risks, (Reg 12(2)(b) (risk mitigation))

ensuring that the premises used by the service provider are safe to use for their intended purpose and are used in a safe way, (Reg 12(2)(d) (premises safety))

where equipment or medicines are supplied by the service provider, ensuring that there are sufficient quantities of these to ensure the safety of service users and to meet their needs, (Reg 12(2)(f) (sufficient equipment + medicines supply))

Regulation 17 adds the governance duties that this policy operationalises:

Systems or processes must be established and operated effectively to ensure compliance with the requirements in this Part. (Reg 17(1): the umbrella duty)

assess, monitor and improve the quality and safety of the services provided in the carrying on of the regulated activity (including the quality of the experience of service users in receiving those services) ... assess, monitor and mitigate the risks relating to the health, safety and welfare of service users and others who may be at risk which arise from the carrying on of the regulated activity. (Reg 17(2)(a) and (b): quality and risk)

The full text is at https://www.legislation.gov.uk/uksi/2014/2936/regulation/12 and https://www.legislation.gov.uk/uksi/2014/2936/regulation/17. Where this policy and the regulation diverge, the regulation wins.

2. Plain-English summary

Care and treatment must be provided in a safe way. The regulation lists the areas a provider must address, including risk assessment, risk mitigation, staff competence, safe premises, safe equipment, sufficient equipment and medicines, medicines safety, infection prevention and shared-care planning. Good governance under Reg 17 means running effective systems and processes to assess, monitor and mitigate risks to people's health, safety and welfare, and a tested, current business continuity plan is how a service shows it can keep people safe when normal systems fail.

3. Purpose

The purpose of this policy is to make sure that [Service Name] can continue to provide safe care and treatment during disruption, emergency or service failure.

Business continuity is part of safe care and good governance. The service must be able to identify essential functions, plan for disruption, respond quickly, communicate clearly and protect people from avoidable harm.

This policy supports Regulation 12 safe care and treatment, Regulation 17 good governance, Regulation 18 staffing, Regulation 15 premises and equipment, health and safety duties and CQC notification requirements.

4. Policy warning

A service disruption does not remove the provider's duty to keep people safe.

Where normal systems fail, the service must move quickly to safe contingency arrangements. Staff must know who is in charge, what to prioritise, who to contact and what must be recorded.

A continuity plan that is not tested, not known by staff, or not updated after changes may fail when needed.

Before adoption, replace [Service Name] and record local activation thresholds, essential functions, minimum safe staffing, priority people or treatments, emergency leadership, paper-record fallback, alternative premises, critical suppliers, contact lists and external reporting routes. Staff must be able to use the plan when the usual IT, telephone or building is unavailable.

5. Scope

This policy applies to disruption involving:

6. Essential services

The Registered Manager must identify essential functions that must continue during disruption.

These may include:

Essential functions must be prioritised in the continuity plan.

7. Responsibilities

The Registered Manager is responsible for maintaining the business continuity plan, training staff, leading the response and reviewing incidents.

The provider or Nominated Individual is responsible for ensuring that resources, insurance, systems and provider-level support are available.

Senior staff are responsible for following the plan, escalating concerns and recording actions.

All staff are responsible for knowing emergency procedures relevant to their role.

8. Business continuity plan

The service must maintain a written business continuity plan.

The plan must include:

The plan must be accessible to senior staff during an emergency, including where IT systems are unavailable.

Step-by-step activation and recovery procedure

  1. Identify and declare the disruption. Record what has failed, when it started, people or services affected and the trigger used to activate the plan.
  2. Appoint the response lead. Name the lead and deputy, open a decision log and confirm how the response team will communicate if normal systems are unavailable.
  3. Make people safe. Address immediate danger, account for people, call emergency services where needed and stop activity that cannot continue safely.
  4. Protect essential functions. Use the priority list to deploy staffing, records, medicines, equipment, premises and supplier contingencies. Record any care delayed, changed or missed.
  5. Communicate and report. Give staff and affected people clear instructions, update relevant partners and record each external-notification decision against the current route.
  6. Reassess and hand over. Review risk at stated intervals, record changes and complete a clear handover whenever response leadership or operational ownership changes.
  7. Recover and reconcile. Confirm safe return to normal arrangements, reconcile paper and electronic records, check missed care and supplies, and tell affected people what happens next.
  8. Review and improve. Complete the post-incident review, update the risk register and continuity plan, assign actions and test that the revised control works.

9. Leadership during disruption

The plan must identify who leads the response.

The lead person must:

There must be a deputy where the Registered Manager is unavailable.

10. Staff shortage

The service must have a plan for unexpected staffing shortage.

The plan must include:

The service must not continue unsafe activity without risk assessment and escalation.

11. Loss of premises, utilities or environment

Where premises, utilities or environment are unsafe, the service must assess:

Decisions must be recorded.

12. IT, records and cyber disruption

The service must have contingency arrangements for loss of IT, telephone or record systems.

This must include:

Staff must know how to work safely if electronic systems are unavailable.

13. Medicines and equipment continuity

The continuity plan must cover disruption affecting medicines, clinical supplies, equipment, vehicles or devices.

The service must consider:

Unsafe workarounds must not be used.

14. Infection outbreak or public health emergency

The service must follow current public health guidance during infectious disease outbreaks or public health emergencies.

The response must consider:

The service must record decisions and updates to the plan.

15. Communication

The plan must include communication arrangements for:

Communication must be timely, factual and proportionate.

Where communication is disrupted, alternative methods must be used where possible.

16. Prioritisation

During disruption, the service must prioritise according to risk.

Priority should be given to:

Non-essential activity may be delayed where necessary, but the decision and rationale must be recorded.

17. External reporting

The Registered Manager must consider whether the disruption requires notification to:

The decision to notify or not notify must be recorded.

18. Recovery

The service must have a recovery process after disruption.

Recovery must include:

The service must not assume that recovery is complete because the immediate emergency has ended.

19. Testing the plan

The business continuity plan must be tested at least annually.

Testing may include:

The test must be recorded and any actions tracked.

Audit and monitoring cadence

Unless local risk requires more frequent checks, the Service uses the following minimum operating rhythm:

20. Training and awareness

Staff must receive training appropriate to their role on:

New staff must receive relevant continuity information during induction.

21. Records

The service must keep:

Records must show what happened, what was decided, who was informed and what changed afterwards.

22. Post-incident review

After any significant disruption, the Registered Manager must complete a post-incident review.

The review must consider:

Findings must be reviewed through governance.

23. Related policies in this pack

This policy should be read with:

24. Review

This policy will be reviewed annually, or sooner following a serious incident, service disruption, business continuity test, CQC finding, change in service model, change in premises, major system change, or new legal or regulatory guidance.

25. Sources and further reading

This template is based on CQC's guidance for providers and managers, the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, and other topic-specific legislation and guidance listed below. It is a starting point for adaptation, not a substitute for legal, clinical, HR, safeguarding or specialist professional advice.

26. When to seek further advice

Seek specialist advice where the issue involves serious harm, safeguarding, deprivation of liberty, restraint, children, professional misconduct, controlled drugs, radiation, termination of pregnancy, infection outbreak, water safety, employment dismissal, DBS barring referral, or regulatory enforcement.

27. Document control

Version Date Author Changes
v1.1 2026-07-18 Verivius (sample) Added local adoption prompts, the activation-to-recovery procedure and a practical audit and testing cadence.
v1 2026-06-10 Verivius (sample) Initial sample template, conformed to the Verivius policy standard.

This sample policy template was issued by Verivius. It is a template, not a substitute for legal advice or the provider's own policy-development process. Where this template and live law or regulator guidance diverge, the live source wins.

What good looks like here

Written from an ex-CQC inspector's chair, but the point is safe, well-led care your team can stand behind. Each row shows what strong evidence looks like, what thin evidence looks like, and where the expectation comes from.

Continuity failures rarely announce themselves as clinical incidents. They surface as a person whose time-critical medicine arrived late because the electronic record was down, or whose visit was quietly dropped when the rota collapsed in snow. What makes this policy different from the rest of the pack is that the harm is distributed and close to invisible, spread thinly across a whole caseload rather than landing on one person, so it never generates the single incident form that would normally trigger a review. That is why the decision log and the recovery reconciliation carry more weight here than the plan document itself: they are the only records that can tell a person, or their family, what they did not receive while the service was coping. A plan written once and filed gives false assurance, because the moment it is needed is the moment staff have least capacity to improvise. Services that lead well take the fallback out for a run while it is still safe to fail, rather than discovering during a real cyber incident that nobody knows where the paper contact list lives.

  1. The continuity plan has actually been exercised against a real essential function, not just written and filed. A plan that has never been run, with staff who have never had to use the fallback arrangements, is the one that fails on the day people depend on it.

    Strong evidence: Test and drill records from the annual documented exercise that disrupts at least one essential function and requires staff to use the fallback (section 19 and the audit and monitoring cadence), with the resulting actions tracked.

    Weak evidence: The only test record is a line in team meeting minutes saying the continuity plan was reviewed, or an exercise that talked a scenario through without ever taking an essential function away, so nobody had to retrieve the paper contact list, work from the fallback record or ring the on-call number. Weaker still is a dated exercise that predates the current clinical system, premises, supplier or staff team, with no actions arising and nothing tracked to completion.

    Our recommended baseline. Not a legal or regulatory requirement, but a sensible standard we suggest where the rules leave the detail to you. Adapt it to your service.
  2. Senior staff can reach and use the plan when the usual IT, telephone or building is unavailable, not just that a plan exists on the shared drive. When those systems are down, what keeps people safe is a paper fallback that works and contact lists that are still current.

    Strong evidence: An accessible copy of the plan and emergency contact list with a paper fallback for records (sections 8, 12 and 21); a staff member is asked to locate and open it during a simulated IT loss (checklist: 'Plan is accessible to senior staff during disruption', 'Contact lists are current and accessible if IT is unavailable').

    Weak evidence: The plan exists as a file on the shared drive and nobody can say where the printed copy is kept or who holds one off site. The emergency contact list still names a manager who left, a contractor the service no longer uses, or numbers nobody has dialled since the list was typed, and no member of staff has ever been asked to find and open the plan with the computers switched off.

    Our recommended baseline. Not a legal or regulatory requirement, but a sensible standard we suggest where the rules leave the detail to you. Adapt it to your service.
  3. A named response lead and a deputy both exist for when the Registered Manager is unavailable, so the response does not rest on a single person. When disruption starts out of hours, someone knows they are the lead and knows the escalation route, rather than a phone that rings out with no one clear who takes charge.

    Strong evidence: Leadership and out-of-hours escalation arrangements in the plan showing the lead, deputy and provider-level escalation route (sections 8 and 9; checklist: 'Deputies and out-of-hours leadership arrangements are clear').

    Weak evidence: The plan names the Registered Manager in every leadership box and the deputy field is blank, says something vague such as the senior person on duty, or names someone who has never been briefed and does not know they hold the role. Out-of-hours reads as contact the manager, with no route on if that phone goes unanswered, and staff asked who takes charge when disruption starts out of hours give different answers.

    What the regulator expects to see. Not a law in itself, but CQC judges you against it, so an inspector will look for it and expect a reason where you depart from it.
  4. Each external report is a separate decision, recorded on its own terms whether the outcome is to report or not, not merely 'considered'. A statutory notification to CQC, an alert to the commissioner, a safeguarding referral to the local authority, a report to the Health and Safety Executive and a personal-data breach report to the Information Commissioner's Office are separate duties, and significant disruption can trigger more than one at once, so one is never treated as covering the rest.

    Strong evidence: External notification records showing each notify-or-not-notify decision and its rationale (sections 17 and 21; checklist: 'CQC notification decision is considered for significant service disruption', evidence 'Notification decision record').

    Weak evidence: The disruption record says notification considered or not required, with no name, no date and no reasoning, so there is no way to see who weighed it or on what basis. Or a single CQC notification is treated as covering everything, with nothing showing whether a local authority safeguarding referral, a commissioner alert, a report to the Health and Safety Executive or a personal data breach report to the Information Commissioner's Office was separately due.

    Our recommended baseline. Not a legal or regulatory requirement, but a sensible standard we suggest where the rules leave the detail to you. Adapt it to your service.
  5. Disruption closes with a post-incident review and an updated plan, not simply because the immediate emergency ended. The point is learning that becomes owned, dated actions rather than a filed report, so the same failure does not catch the next person out.

    Strong evidence: The post-incident review, the updated risk register and continuity plan, and improvement actions with owners and due dates (sections 18 and 22, and the audit cadence 'assign gaps as improvement actions').

    Weak evidence: The file holds a narrative account of what happened, ending with a phrase such as staff responded well and lessons have been learned, while the continuity plan carries the same version number and review date as it did before the disruption, so nothing in the service actually changed. Actions are written as themes such as improve communication, with no named owner, no due date and no evidence that anyone went back to test whether the revised arrangement works.

    Our recommended baseline. Not a legal or regulatory requirement, but a sensible standard we suggest where the rules leave the detail to you. Adapt it to your service.
  6. Care that was delayed, changed or missed during the disruption is recorded, and then reconciled on recovery, not lost in the response. Reconciliation is what stops a silent gap opening in the person's care history across the days that mattered most.

    Strong evidence: Decision-log entries recording delayed, changed or missed care during activation, and the recovery checks of missed or delayed care and reconciled temporary records (section 8 step 4 and section 18).

    Weak evidence: The response records show what the service managed to do but never what people did not get: no note of the visits shortened or dropped, the appointments stood down, the doses given late or the treatment deferred. On recovery, the handwritten notes taken during the outage sit in a folder or a drawer and are never reconciled into the person's record, leaving a silent gap in the care history across the days that mattered most.

    A legal duty. This comes from legislation that applies to your service, so meeting it is not optional. The exact provision is cited beneath the badge.

    Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, reg 17(2)(c)

Last verified 20 July 2026

Audit this policy

Business continuity and emergency preparedness procedure checklist

A policy is the intent; the evidence is what a CQC inspector actually asks to see. This matching checklist turns the policy above into the records to keep, the audit to run, and the places small services most often fall short.

Open the Business continuity and emergency preparedness procedure checklist

Spotted something to improve?

These are sample templates, not the last word. If you would change a wording, or want to help us confirm a detail, tell us and we will look at it.

Related Verivius content

Want help adapting this to your service?

A Verivius consultant can read your adapted policy against the live regulation and your service shape. The work fits inside a Mock Inspection engagement or a shorter consulting brief. A 20-minute conversation is the fastest way to find out whether the fit is right.

Get started free

Free to start, no card. A 14-day trial when you subscribe.

Last reviewed 10 June 2026