Sample policy · Reg 17

Good governance policy template

Statutory anchor: Regulation 17 (good governance), Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 (SI 2014/2936). · primary source

Download the PDF

The PDF version of this template is the same content, formatted for adaptation in your document control system. The disclaimer above is repeated on the PDF cover.

Verivius pack version v1, 2026-07-18

1. What the regulation says

Systems or processes must be established and operated effectively to ensure compliance with the requirements in this Part. (Reg 17(1): the umbrella duty)

assess, monitor and improve the quality and safety of the services provided in the carrying on of the regulated activity (including the quality of the experience of service users in receiving those services) ... assess, monitor and mitigate the risks relating to the health, safety and welfare of service users and others who may be at risk which arise from the carrying on of the regulated activity. (Reg 17(2)(a) and (b): quality and risk)

maintain securely an accurate, complete and contemporaneous record in respect of each service user, including a record of the care and treatment provided to the service user and of decisions taken in relation to the care and treatment provided. (Reg 17(2)(c): accurate service-user record)

The full text of the regulation is at https://www.legislation.gov.uk/uksi/2014/2936/regulation/17. Where this policy and the regulation diverge, the regulation wins.

2. Plain-English summary

You have to run effective systems and processes to comply with everything else in Part 3. The regulation lists six things those systems must enable in particular: quality assessment and improvement, risk management, accurate service-user records, accurate employment and management records, seeking and acting on feedback, and continually evaluating and improving how you process all this. If CQC requests a written report on quality and risk plus your improvement plans, you have 28 days from the day after the request.

3. Scope

This policy applies to all employees, contractors, and external parties who participate in any governance forum, decision-making process, or quality-assurance activity at . It covers the governance-meeting cycle (clinical governance committee, leadership team, board, multidisciplinary team), the risk register, the improvement-actions register, the document-control system, and the clinical and operational audit programme.

(Tenant updates the angle-bracket placeholder.)

4. Roles and responsibilities

(Tenant updates the named role-holders.)

5. Procedure

The Reg 17 procedure turns the six governance elements into the working records below.

Use the CQC governance document template guide to decide which live records should sit behind each part of this policy and how those records connect.

  1. Governance-meeting cadence. A clinical governance committee meets at least monthly; a leadership team meets at the cadence the service shape requires (often weekly or fortnightly); a board or equivalent meets at least quarterly. Each meeting has a documented chair, attendees, agenda, and minutes. Recurring agenda items include: previous-month incident summary, complaints summary, safeguarding summary, statutory-notification status, risk-register review, improvement-actions follow-through, training-currency dashboard, audit findings.
  2. Quality-assessment cycle. The audit programme runs the annual clinical-audit calendar (sampled per the audit programme), the quarterly file audits per lifecycle (incidents, complaints, safeguarding, notifications), and the annual policy review (every document past its next-review date is read and refreshed). The audit programme is baselined against the fundamental standards in Regulations 4 to 20A, so that compliance with each is checked on a stated cadence.
  3. Risk-register maintenance. Risks are identified continuously by any team member; the risk-register review at the monthly clinical governance committee tests every Open risk against its current score, its current controls, and its next-review date. Treated risks have improvement actions cross-linked.
  4. Improvement-actions follow-through. Every improvement action carries an owner, a target date, and a completion-evidence requirement. The Quality and Governance Lead presents the overdue-actions view at the monthly committee.
  5. Service-user records. The clinical and care records are maintained securely with an accurate, complete, contemporaneous entry per service user per relevant intervention, held lawfully under the UK GDPR and the Data Protection Act 2018 (health data is special-category data). The documents register holds the policies and procedures that govern record-keeping; the clinical system holds the records themselves.
  6. Staff and management records. The people register holds the Reg 19 Schedule 3 information set per employee. Governance roles (Registered Manager, Nominated Individual, Safeguarding Lead, etc.) are recorded with the named holder and the date of appointment and any change.
  7. Service-user feedback. Feedback channels are operated: complaints register, compliments captured, service-user surveys or family-feedback as fit, public reviews monitored. Aggregate feedback is reviewed quarterly at the governance committee.
  8. System-evaluation review. Annually, the leadership team reviews how the governance system itself is working: are the meetings producing decisions; do the decisions produce actions; do the actions complete with evidence; is the audit programme catching what it should; is the risk register reflecting reality. The review is documented as an annual governance report.
  9. Records availability for CQC. Every record this policy generates is available to be supplied to CQC. The 28-day Reg 17(3) response window applies if CQC requests a written report on quality, safety, risks, and improvement plans. The Registered Manager confirms the read-only export pathway for the workspace is functional quarterly.
  10. Continuous improvement of the governance process itself. Where the governance system surfaces its own gaps (a meeting that does not produce decisions, a register that has drifted, an audit pattern that misses a sector-specific risk), an improvement action is opened against the system itself.

6. Training requirement

Governance roles complete:

All staff complete Reg 17 awareness training at induction (covering what the governance system is, what their part in it is, and how to raise patterns).

Training records held in the tenant's training matrix register.

7. Audit

Compliance with this policy is monitored by the Quality and Governance Lead (or the Registered Manager in small services) through:

Audit findings recorded in the tenant's audit register; actions logged in the improvement-actions register.

8. Record-keeping

Governance records (meeting minutes, audit reports, risk-register snapshots, improvement-actions records, annual governance reports) are held in the tenant's governance system for a minimum of 8 years from the date of the record per the NHS Code of Practice on Records Management. Board-level records (constitution, board minutes, statutory company filings) are held for the longer of the period the company exists or the period required by company-law retention rules (typically 6 years post-event under the Companies Act 2006 for accounting records, longer for some categories).

Verivius preserves the per-record audit trail indefinitely while the workspace is active.

9. Related policies in this pack

10. Sources and further reading

This template is based on CQC's guidance for providers and managers, the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, and other topic-specific legislation and guidance listed below. It is a starting point for adaptation, not a substitute for legal, clinical, HR, safeguarding or specialist professional advice.

11. When to seek further advice

Seek specialist advice where the issue involves serious harm, safeguarding, deprivation of liberty, restraint, children, professional misconduct, controlled drugs, radiation, termination of pregnancy, infection outbreak, water safety, employment dismissal, DBS barring referral, or regulatory enforcement.

12. Document control

Version Date Author Changes
v1 2026-05-19 Verivius (sample) Initial sample template.
v1.1 2026-06-01 Verivius (sample) Filled out Sections 3 to 8 with concrete content. Section 4 names the typical governance role-set with their committee-level accountability. Section 5 procedure expanded to a 10-step Reg 17 flow covering the meeting cadence, the audit programme, the risk register, the improvement actions, the records, the feedback channels, and the annual system review. Section 6 names training topics by governance role. Section 7 names the four audit cadences. Section 8 references the NHS Code of Practice on Records Management and the Companies Act 2006 retention for board-level records.
v1.2 2026-06-05 Verivius (sample) CQC content-checklist pass. Added a board / senior-leadership role holding designated overall responsibility for, and scrutiny of, the governance system (CQC's red flag was the absence of board-level scrutiny). Stated that the audit programme is baselined against the fundamental standards in Regulations 4 to 20A. Added the UK GDPR and Data Protection Act 2018 to the service-user records element. Updated stale related-policy slugs.
v1.3 2026-06-10 Verivius (sample) Re-conformed to the current Verivius policy standard, preserving the original content. Added the current disclaimer, policy owner / applies-to line, verbatim Reg 17 quotes with cite labels, the plain-English summary, a Sources and further reading block, and a When to seek further advice block. No operational content removed.
v1.4 2026-07-18 Verivius (sample) Added the CQC governance document template guide as practical further reading for connecting the policy to live governance records.

This sample policy template was issued by Verivius. It is a template, not a substitute for legal advice or the tenant's own policy-development process. Where this template and live law or regulator guidance diverge, the live source wins.

What a CQC inspector checks

The same requirement seen through an ex-CQC-inspector's eyes: what they actually ask to see, and the gap they are testing for.

  1. That the governance cycle produces decisions and actions, not just meetings.

    Evidence: A recent run of minuted governance and board meetings, each with a named chair, attendees, agenda and standing items: incidents, complaints, safeguarding, statutory-notification status, the risk register, improvement actions, training currency and audit findings.

  2. That the risk register is a live, scored and reviewed tool, not a spreadsheet tidied the week before inspection.

    Evidence: Every open risk with a named owner, current controls, a current score and a next-review date, with overdue reviews visible and cross-linked to the improvement actions that treat them.

  3. That improvement actions close with evidence the issue was fixed, not just get marked complete.

    Evidence: An overdue-actions view where each action carries an owner and a target date, and every closed action shows the completion evidence.

  4. That the audit programme runs on cadence and turns findings into action.

    Evidence: An annual audit calendar baselined to the fundamental standards (Regulations 4 to 20A), with completed reports whose findings became tracked, owned actions rather than filed.

  5. That a named senior leader scrutinises the whole cycle and can see repeated themes and unresolved risks.

    Evidence: An annual governance report tabled and reviewed at board or senior-leadership level, with the review and its decisions recorded.

  6. That service-user records are accurate, complete, contemporaneous and held securely (Reg 17(2)(c)).

    Evidence: A sampled record made at the time, with corrections that preserve the original entry and late entries labelled with the reason for delay.

Related Verivius content

Want help adapting this to your service?

A Verivius consultant can read your adapted policy against the live regulation and your service shape. The work fits inside a Mock Inspection engagement or a shorter consulting brief. A 20-minute conversation is the fastest way to find out whether the fit is right.

Get started free

Free to start, no card. A 14-day trial when you subscribe.

Last reviewed 18 July 2026