Sample policy · Reg 17

Good governance policy template

Statutory anchor: Regulation 17 (good governance), Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 (SI 2014/2936). · primary source

Download the PDF

The PDF version of this template is the same content, formatted for adaptation in your document control system. The disclaimer above is repeated on the PDF cover.

Verivius pack version v1, 2026-07-18

1. What the regulation says

Systems or processes must be established and operated effectively to ensure compliance with the requirements in this Part. (Reg 17(1): the umbrella duty)

assess, monitor and improve the quality and safety of the services provided in the carrying on of the regulated activity (including the quality of the experience of service users in receiving those services) ... assess, monitor and mitigate the risks relating to the health, safety and welfare of service users and others who may be at risk which arise from the carrying on of the regulated activity. (Reg 17(2)(a) and (b): quality and risk)

maintain securely an accurate, complete and contemporaneous record in respect of each service user, including a record of the care and treatment provided to the service user and of decisions taken in relation to the care and treatment provided. (Reg 17(2)(c): accurate service-user record)

The full text of the regulation is at https://www.legislation.gov.uk/uksi/2014/2936/regulation/17. Where this policy and the regulation diverge, the regulation wins.

2. Plain-English summary

You have to run effective systems and processes to comply with everything else in Part 3. The regulation lists six things those systems must enable in particular: quality assessment and improvement, risk management, accurate service-user records, accurate employment and management records, seeking and acting on feedback, and continually evaluating and improving how you process all this. If CQC requests a written report on quality and risk plus your improvement plans, you have 28 days from the day after the request.

3. Scope

This policy applies to all employees, contractors, and external parties who participate in any governance forum, decision-making process, or quality-assurance activity at . It covers the governance-meeting cycle (clinical governance committee, leadership team, board, multidisciplinary team), the risk register, the improvement-actions register, the document-control system, and the clinical and operational audit programme.

(Tenant updates the angle-bracket placeholder.)

4. Roles and responsibilities

(Tenant updates the named role-holders.)

5. Procedure

The Reg 17 procedure turns the six governance elements into the working records below.

Use the CQC governance document template guide to decide which live records should sit behind each part of this policy and how those records connect.

  1. Governance-meeting cadence. A clinical governance committee meets at least monthly; a leadership team meets at the cadence the service shape requires (often weekly or fortnightly); a board or equivalent meets at least quarterly. Each meeting has a documented chair, attendees, agenda, and minutes. Recurring agenda items include: previous-month incident summary, complaints summary, safeguarding summary, statutory-notification status, risk-register review, improvement-actions follow-through, training-currency dashboard, audit findings.
  2. Quality-assessment cycle. The audit programme runs the annual clinical-audit calendar (sampled per the audit programme), the quarterly file audits per lifecycle (incidents, complaints, safeguarding, notifications), and the annual policy review (every document past its next-review date is read and refreshed). The audit programme is baselined against the fundamental standards in Regulations 4 to 20A, so that compliance with each is checked on a stated cadence.
  3. Risk-register maintenance. Risks are identified continuously by any team member; the risk-register review at the monthly clinical governance committee tests every Open risk against its current score, its current controls, and its next-review date. Treated risks have improvement actions cross-linked.
  4. Improvement-actions follow-through. Every improvement action carries an owner, a target date, and a completion-evidence requirement. The Quality and Governance Lead presents the overdue-actions view at the monthly committee.
  5. Service-user records. The clinical and care records are maintained securely with an accurate, complete, contemporaneous entry per service user per relevant intervention, held lawfully under the UK GDPR and the Data Protection Act 2018 (health data is special-category data). The documents register holds the policies and procedures that govern record-keeping; the clinical system holds the records themselves.
  6. Staff and management records. The people register holds the Reg 19 Schedule 3 information set per employee. Governance roles (Registered Manager, Nominated Individual, Safeguarding Lead, etc.) are recorded with the named holder and the date of appointment and any change.
  7. Service-user feedback. Feedback channels are operated: complaints register, compliments captured, service-user surveys or family-feedback as fit, public reviews monitored. Aggregate feedback is reviewed quarterly at the governance committee.
  8. System-evaluation review. Annually, the leadership team reviews how the governance system itself is working: are the meetings producing decisions; do the decisions produce actions; do the actions complete with evidence; is the audit programme catching what it should; is the risk register reflecting reality. The review is documented as an annual governance report.
  9. Records availability for CQC. Every record this policy generates is available to be supplied to CQC. The 28-day Reg 17(3) response window applies if CQC requests a written report on quality, safety, risks, and improvement plans. The Registered Manager confirms the read-only export pathway for the workspace is functional quarterly.
  10. Continuous improvement of the governance process itself. Where the governance system surfaces its own gaps (a meeting that does not produce decisions, a register that has drifted, an audit pattern that misses a sector-specific risk), an improvement action is opened against the system itself.

6. Training requirement

Governance roles complete:

All staff complete Reg 17 awareness training at induction (covering what the governance system is, what their part in it is, and how to raise patterns).

Training records held in the tenant's training matrix register.

7. Audit

Compliance with this policy is monitored by the Quality and Governance Lead (or the Registered Manager in small services) through:

Audit findings recorded in the tenant's audit register; actions logged in the improvement-actions register.

8. Record-keeping

Governance records (meeting minutes, audit reports, risk-register snapshots, improvement-actions records, annual governance reports) are held in the tenant's governance system for a minimum of 8 years from the date of the record per the NHS Code of Practice on Records Management. Board-level records (constitution, board minutes, statutory company filings) are held for the longer of the period the company exists or the period required by company-law retention rules (typically 6 years post-event under the Companies Act 2006 for accounting records, longer for some categories).

Verivius preserves the per-record audit trail indefinitely while the workspace is active.

9. Related policies in this pack

10. Sources and further reading

This template is based on CQC's guidance for providers and managers, the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, and other topic-specific legislation and guidance listed below. It is a starting point for adaptation, not a substitute for legal, clinical, HR, safeguarding or specialist professional advice.

11. When to seek further advice

Seek specialist advice where the issue involves serious harm, safeguarding, deprivation of liberty, restraint, children, professional misconduct, controlled drugs, radiation, termination of pregnancy, infection outbreak, water safety, employment dismissal, DBS barring referral, or regulatory enforcement.

12. Document control

Version Date Author Changes
v1 2026-05-19 Verivius (sample) Initial sample template.
v1.1 2026-06-01 Verivius (sample) Filled out Sections 3 to 8 with concrete content. Section 4 names the typical governance role-set with their committee-level accountability. Section 5 procedure expanded to a 10-step Reg 17 flow covering the meeting cadence, the audit programme, the risk register, the improvement actions, the records, the feedback channels, and the annual system review. Section 6 names training topics by governance role. Section 7 names the four audit cadences. Section 8 references the NHS Code of Practice on Records Management and the Companies Act 2006 retention for board-level records.
v1.2 2026-06-05 Verivius (sample) CQC content-checklist pass. Added a board / senior-leadership role holding designated overall responsibility for, and scrutiny of, the governance system (CQC's red flag was the absence of board-level scrutiny). Stated that the audit programme is baselined against the fundamental standards in Regulations 4 to 20A. Added the UK GDPR and Data Protection Act 2018 to the service-user records element. Updated stale related-policy slugs.
v1.3 2026-06-10 Verivius (sample) Re-conformed to the current Verivius policy standard, preserving the original content. Added the current disclaimer, policy owner / applies-to line, verbatim Reg 17 quotes with cite labels, the plain-English summary, a Sources and further reading block, and a When to seek further advice block. No operational content removed.
v1.4 2026-07-18 Verivius (sample) Added the CQC governance document template guide as practical further reading for connecting the policy to live governance records.

This sample policy template was issued by Verivius. It is a template, not a substitute for legal advice or the tenant's own policy-development process. Where this template and live law or regulator guidance diverge, the live source wins.

What good looks like here

Written from an ex-CQC inspector's chair, but the point is safe, well-led care your team can stand behind. Each row shows what strong evidence looks like, what thin evidence looks like, and where the expectation comes from.

Regulation 17 is the one an inspector reaches for when the specific failing sits somewhere else. A medicines error, a missed safeguarding referral or a recurring complaint theme almost always also shows a governance system that did not see it coming or did not act on it. Providers who can evidence a working cycle, with risks scored and owned, audits that change practice, and actions that close with proof, rarely meet a good-governance breach on its own, because the same records answer the other questions too.

  1. The governance cycle produces decisions and actions, not just meetings.

    Strong evidence: A recent run of minuted governance and board meetings, each with a named chair, attendees, agenda and standing items: incidents, complaints, safeguarding, statutory notifications to CQC, the risk register, improvement actions, training currency and audit findings. Safeguarding and notification are tracked as separate lines, because a referral to the local authority does not discharge a statutory notification to CQC and a notification does not discharge a referral.

    Weak evidence: Minutes that log attendance and "noted" items but no decisions, owners or follow-through, or a run where the difficult months simply have no meeting at all.

    What the regulator expects to see. Not a law in itself, but CQC judges you against it, so an inspector will look for it and expect a reason where you depart from it.
  2. The risk register is a live, scored and reviewed tool that reflects the risks people using the service actually face, not a spreadsheet tidied up the week before someone asks to see it.

    Strong evidence: Every open risk with a named owner, current controls, a current score and a next-review date, with overdue reviews visible and cross-linked to the improvement actions that treat them.

    Weak evidence: Stale scores, blank owners, every review date set to the same recent day, and risks that never change status or link to any action.

    Our recommended baseline. Not a legal or regulatory requirement, but a sensible standard we suggest where the rules leave the detail to you. Adapt it to your service.
  3. Improvement actions close with evidence that the issue was fixed, not just marked complete.

    Strong evidence: An overdue-actions view where each action carries an owner and a target date, and every closed action shows the completion evidence.

    Weak evidence: Actions marked complete with nothing attached, or a closed action whose underlying issue is still visibly open elsewhere in the service, so the people it affects meet the same problem again.

    Our recommended baseline. Not a legal or regulatory requirement, but a sensible standard we suggest where the rules leave the detail to you. Adapt it to your service.
  4. The audit programme runs on cadence and turns findings into action.

    Strong evidence: An annual audit calendar baselined to the fundamental standards (Regulations 4 to 20A), with completed reports whose findings became tracked, owned actions rather than filed.

    Weak evidence: A calendar of planned audits with few completed reports, or reports whose findings have no corresponding tracked action. The annual cadence itself is a Verivius default, not a fixed statutory interval.

    Our recommended baseline. Not a legal or regulatory requirement, but a sensible standard we suggest where the rules leave the detail to you. Adapt it to your service.
  5. A named senior leader scrutinises the whole cycle and can see repeated themes and unresolved risks across it.

    Strong evidence: An annual governance report tabled and reviewed at board or senior-leadership level, with the review and its decisions recorded.

    Weak evidence: A report written for the inspection rather than used during the year, with no record that anyone challenged it or decided anything from it.

    What the regulator expects to see. Not a law in itself, but CQC judges you against it, so an inspector will look for it and expect a reason where you depart from it.
  6. Service-user records are accurate, complete, contemporaneous and held securely, so the colleague who picks up the care next can rely on what is written (Reg 17(2)(c)).

    Strong evidence: A sampled record made at the time, with corrections that preserve the original entry and late entries labelled with the reason for delay.

    Weak evidence: Back-filled entries with no delay reason, corrections that overwrite the original, or records reachable by staff who have no need to see them.

    A legal duty. This comes from legislation that applies to your service, so meeting it is not optional. The exact provision is cited beneath the badge.

    Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, reg 17(2)(c)

Last verified 20 July 2026

Spotted something to improve?

These are sample templates, not the last word. If you would change a wording, or want to help us confirm a detail, tell us and we will look at it.

Related Verivius content

Want help adapting this to your service?

A Verivius consultant can read your adapted policy against the live regulation and your service shape. The work fits inside a Mock Inspection engagement or a shorter consulting brief. A 20-minute conversation is the fastest way to find out whether the fit is right.

Get started free

Free to start, no card. A 14-day trial when you subscribe.

Last reviewed 18 July 2026