Sample policy · Reg 12

Incident Reporting, Investigation and Learning Policy

Statutory anchor: Regulation 12 (safe care and treatment), Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 (SI 2014/2936). This policy also engages Regulation 17 (good governance) and Regulation 20 (duty of candour). · primary source

Download the PDF

The PDF version of this template is the same content, formatted for adaptation in your document control system. The disclaimer above is repeated on the PDF cover.

Verivius pack version v1.1, 2026-07-19

1. What the regulation says

Care and treatment must be provided in a safe way for service users. (Reg 12(1) (the headline duty))

assessing the risks to the health and safety of service users of receiving the care or treatment, (Reg 12(2)(a) (risk assessment))

doing all that is reasonably practicable to mitigate any such risks, (Reg 12(2)(b) (risk mitigation))

Regulation 17 adds the governance duties that this policy operationalises:

Systems or processes must be established and operated effectively to ensure compliance with the requirements in this Part. (Reg 17(1): the umbrella duty)

assess, monitor and improve the quality and safety of the services provided in the carrying on of the regulated activity (including the quality of the experience of service users in receiving those services) ... assess, monitor and mitigate the risks relating to the health, safety and welfare of service users and others who may be at risk which arise from the carrying on of the regulated activity. (Reg 17(2)(a) and (b): quality and risk)

Regulation 20 adds the duty of candour that applies where an incident is a notifiable safety incident:

Registered persons must act in an open and transparent way with relevant persons in relation to care and treatment provided to service users in carrying on a regulated activity. (Reg 20(1) (the headline duty))

The full text is at https://www.legislation.gov.uk/uksi/2014/2936/regulation/12, https://www.legislation.gov.uk/uksi/2014/2936/regulation/17 and https://www.legislation.gov.uk/uksi/2014/2936/regulation/20. Where this policy and the regulation diverge, the regulation wins.

2. Plain-English summary

Care and treatment must be provided in a safe way. The regulation lists the areas a provider must address, including risk assessment, risk mitigation, staff competence, safe premises, safe equipment, sufficient equipment and medicines, medicines safety, infection prevention and shared-care planning. Good governance under Regulation 17 means running effective systems to assess, monitor and improve quality and safety, and where an incident is a notifiable safety incident the duty of candour under Regulation 20 requires you to be open and transparent with the person affected.

3. Purpose

The purpose of this policy is to make sure that incidents, accidents, near misses and safety concerns are identified, reported, investigated, acted on and used for learning.

The service will not treat incident reporting as blame or paperwork. Incident reporting is a safety system. It allows the provider to understand what happened, protect people from further harm, identify patterns, meet statutory duties and improve the quality and safety of care.

This policy supports compliance with Regulation 12, Regulation 17, Regulation 20, safeguarding duties, Reporting of Injuries, Diseases and Dangerous Occurrences Regulations (RIDDOR) where applicable, and CQC statutory notification requirements.

4. Policy warning

All staff must report incidents, accidents, near misses and safety concerns without delay.

A failure to report, concealment of an incident, alteration of records, or delay in escalation may be treated as a serious conduct matter and may also create safeguarding, professional-regulatory or criminal concerns.

Where an incident has caused harm, may have caused harm, or indicates abuse, neglect, unsafe care or serious service failure, the Registered Manager must make sure that immediate protective action is taken before administrative review begins.

5. Scope

This policy applies to:

5.1 Local arrangements before adoption

Before adoption, the provider records and tests:

The local procedure must identify the registered person who remains accountable for CQC notifications even when submission is delegated. Staff must not have to decide alone whether a serious incident is externally reportable.

6. Definitions

An incident is any event that caused harm, had the potential to cause harm, disrupted safe care, or showed that a system did not work as intended.

A near miss is an event that could have caused harm but did not, either by chance or because someone intervened.

A serious incident is an incident involving serious harm, death, abuse, serious neglect, major service disruption, police involvement, or a risk that may require notification to CQC, safeguarding, RIDDOR or another authority.

A learning action is an action taken to reduce the chance of the same or similar incident happening again.

7. Responsibilities

All staff are responsible for recognising and reporting incidents immediately, taking urgent action to keep people safe, and recording what they saw or did accurately.

The person in charge of the shift, clinic, visit, transport journey or session is responsible for immediate safety actions, escalation and initial fact gathering.

The Registered Manager is responsible for incident triage, investigation, external reporting, duty of candour decisions, action tracking and governance review.

The Nominated Individual or provider representative is responsible for ensuring that serious incidents, themes and overdue actions are reviewed at provider level.

8. Operational incident workflow and immediate response

The service follows this sequence from first response to closure:

  1. Protect: make people safe, call emergency or clinical help, preserve essential care and prevent recurrence.
  2. Escalate: tell the person in charge and use safeguarding, on-call or senior routes immediately where harm, abuse, neglect, police involvement or serious service failure may be present.
  3. Record: create the incident record on the same working day, separate facts from opinion and link relevant care, treatment, medicine, equipment or staffing records.
  4. Triage: grade actual and potential harm, appoint the reviewer, set immediate controls and decide which external reporting and duty of candour assessments are required.
  5. Notify and communicate: make required referrals or notifications without waiting for the full investigation, preserve submission references and keep the person affected informed through the appropriate route.
  6. Investigate: gather proportionate evidence, involve people fairly, identify contributory system factors and record findings and uncertainties.
  7. Act and verify: assign learning actions with owners, deadlines and evidence, update risk assessments or the risk register, and check whether the action changed practice.
  8. Close and share learning: approve closure only when reporting, communication, investigation and actions are complete or safely transferred. Share learning without unnecessary personal data and include the event in trend review.

8.1 Immediate response

When an incident occurs, staff must:

Immediate care and safety always come before form completion.

9. Reporting timescales

All incidents must be reported internally on the same working day, or immediately if urgent.

Serious incidents must be escalated to the Registered Manager immediately.

Where the incident occurs out of hours, the on-call escalation process must be followed.

A written incident record must be completed as soon as possible and normally before the staff member finishes their shift or duty period, unless urgent care needs prevent this.

10. Incident record

The incident record must include:

Records must be factual, dated, attributable and written in plain language. Staff must not speculate, blame or alter records retrospectively without clear audit trail.

11. Triage and grading

The Registered Manager, or delegated competent person, must review each incident and decide:

The grading must be reviewed if new information emerges.

12. Investigation

The depth of investigation must be proportionate to the level of harm, potential harm and learning value.

An investigation may include:

A serious incident investigation must be led or reviewed by a competent person who was not directly involved in the incident, where possible.

13. Duty of candour

The Registered Manager must consider whether the incident meets the threshold for statutory duty of candour.

Where the duty applies, the service must act openly and transparently with the person affected or their relevant person. This includes giving a truthful account, an apology, reasonable support, information about further enquiries, written follow-up and a record of the process.

Saying sorry is not an admission of liability. It is part of safe, open and compassionate care.

14. External reporting

The Registered Manager must consider whether the incident requires reporting to:

The decision to report or not report must be recorded, including the rationale.

External reporting must not be delayed because an internal investigation is unfinished.

For a CQC statutory notification, the service checks the current notification page and uses the current portal or form for that event. It retains the submission, acknowledgement or reference number. NHS bodies and primary medical services must only rely on an LFPSE reporting route where current CQC guidance expressly permits it for that notification type.

15. Actions and learning

Every incident review must consider whether action is required.

Actions must have:

Examples of learning actions include care plan review, risk assessment update, staff briefing, training, supervision, equipment repair, environmental change, audit, policy update, staffing review or referral to an external body.

An action is not complete just because it has been written down. It is complete when there is evidence that it was done and, where appropriate, checked.

16. Trend review

The Registered Manager must review incidents at least monthly, or more often where risk is high.

The review must consider:

Themes must be discussed through the service's governance process and used to improve care.

17. Support for people and staff

People affected by incidents must receive appropriate support, information and involvement.

Staff involved in incidents must be supported, supervised and debriefed where appropriate. Support does not replace accountability. Where unsafe practice, neglect, dishonesty or professional misconduct is suspected, the service must follow the relevant safeguarding, disciplinary and referral processes.

18. Audit and governance

The Registered Manager must audit incident records at least quarterly.

The audit must check:

Findings must be recorded and reviewed by the provider.

19. Related records

The service should maintain:

20. Related policies

This policy should be read with:

21. Review

This policy will be reviewed annually, or sooner following a serious incident, safeguarding concern, CQC inspection finding, change in legislation, external guidance, or repeated incident theme.

22. Sources and further reading

This template is based on CQC's guidance for providers and managers, the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, and other topic-specific legislation and guidance listed below. It is a starting point for adaptation, not a substitute for legal, clinical, HR, safeguarding or specialist professional advice.

23. When to seek further advice

Seek specialist advice where the issue involves serious harm, safeguarding, deprivation of liberty, restraint, children, professional misconduct, controlled drugs, radiation, termination of pregnancy, infection outbreak, water safety, employment dismissal, DBS barring referral, or regulatory enforcement.

24. Document control

Version Date Author Changes
v1 2026-06-10 Verivius (sample) Initial sample template, conformed to the Verivius policy standard.
v1.1 2026-07-19 Verivius (sample) Added tested local reporting routes, an end-to-end incident workflow and current CQC notification submission controls.

This sample policy template was issued by Verivius. It is a template, not a substitute for legal advice or the provider's own policy-development process. Where this template and live law or regulator guidance diverge, the live source wins.

What good looks like here

Written from an ex-CQC inspector's chair, but the point is safe, well-led care your team can stand behind. Each row shows what strong evidence looks like, what thin evidence looks like, and where the expectation comes from.

The distinctive risk in incident reporting is not the first event, it is the second one that lands on the same person for the same reason. A fall at the same point of the night, a missed dose from the same medicines round, a deterioration nobody escalated: these repeat because the first incident was recorded and closed rather than understood and acted on. The person affected feels the difference directly, in whether their care plan actually changed, whether anyone told them honestly what happened, and whether they were supported afterwards. Staff feel it too, because a service that treats reporting as blame quietly stops hearing about near misses, and a near miss is the cheapest warning a service will ever get. Inspection will test whether reporting, candour, external duties and learning join up, but the reason to hold that trail together is that it is the mechanism by which care gets safer.

  1. Each incident's CQC statutory notification, safeguarding referral and Reporting of Injuries, Diseases and Dangerous Occurrences Regulations (RIDDOR) decision is opened or ruled out with a recorded reason, and reporting is not held back for the investigation. A local-authority safeguarding referral is not itself a CQC notification, and the notification is assessed on the event itself.

    Strong evidence: The triage decisions on CQC notification, safeguarding referral and external reporting (section 11), section 14's requirement that the decision to report or not report is recorded with its rationale and the submission or reference number retained, and that external reporting is not delayed while the investigation is unfinished; matched by the checklist's 'Linked duties and external reporting' evidence rows (notification decision plus submitted notification, safeguarding decision plus referral receipt, RIDDOR decision plus report receipt).

    Weak evidence: The incident form has a "Care Quality Commission (CQC) notified?" box that is blank on most records, or ticked with no submission or acknowledgement reference retained. Weak files log "safeguarding raised" with no local-authority referral receipt behind it, leave the Reporting of Injuries, Diseases and Dangerous Occurrences Regulations (RIDDOR) line untouched rather than ruled out with a recorded reason, and show the reporting decision being taken only once the internal investigation closed weeks later.

    Our recommended baseline. Not a legal or regulatory requirement, but a sensible standard we suggest where the rules leave the detail to you. Adapt it to your service.
  2. The record shows the incident was assessed against the Regulation 20 duty of candour (notifiable safety incident) threshold and, where the duty applies, the person affected received a truthful account, an apology, support and written follow-up. This duty is owed to the person and is separate from any notification.

    Strong evidence: The Registered Manager's recorded consideration of the duty-of-candour threshold and the openness steps (truthful account, apology, reasonable support, information about further enquiries, written follow-up and a record of the process) in section 13; the checklist's 'candour decision, linked record' evidence row.

    Weak evidence: The candour column reads "N/A" on every incident, including ones that plainly reach the notifiable safety incident threshold for this provider type, such as an injury that changed the structure of the person's body or pain that carried on long after the event, so nothing shows the threshold was ever assessed. A second tell is a service applying another provider type's wording, quoting "moderate harm" as though it were the universal trigger when that limb belongs to health service bodies. Where candour was attempted, the only trace is "family informed by phone": no truthful account of what happened, no apology recorded, no offer of support, no written follow-up, and the duty filed as if submitting a notification discharged what was owed to the person.

    A legal duty. This comes from legislation that applies to your service, so meeting it is not optional. The exact provision is cited beneath the badge.

    Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, reg 20 (notifiable safety incident threshold at reg 20(8)-(9); truthful account, apology and reasonable support at reg 20(2)-(3); written follow-up at reg 20(4))

  3. Incident records are contemporaneous, factual and attributable, created on the same working day, with fact separated from opinion and no retrospective alteration without an audit trail.

    Strong evidence: The incident-record contents and the section 10 rule against speculation, blame or retrospective alteration without a clear audit trail, the same-working-day internal reporting timescale (section 9, a Verivius operational default), and the checklist's 'Incident record quality' rows including 'late entries or corrections have a clear audit trail'.

    Weak evidence: Several incident records written up in one sitting days afterwards, all under one login, all in the same tone, so nothing is contemporaneous. Descriptions blur fact with judgement ("she was being difficult", "he is always unsteady") instead of what was seen and done, and corrections are overwritten or scribbled over with no late-entry marker, no author and no audit trail showing what the record said before.

    Our recommended baseline. Not a legal or regulatory requirement, but a sensible standard we suggest where the rules leave the detail to you. Adapt it to your service.
  4. Investigation depth is proportionate to the harm and looks beyond individual blame to system causes, with serious or repeated incidents reviewed by someone who was not involved.

    Strong evidence: Section 12's proportionate investigation scope, including identifying immediate and root causes, and the requirement that a serious-incident investigation is led or reviewed by a competent person not directly involved where possible; the checklist's 'Triage and investigation' rows on system causes and senior or independent review.

    Weak evidence: Every investigation is the same half page whatever the harm, so a near miss and a serious injury get identical treatment. Findings stop at the individual ("staff member did not follow the policy, staff member re-trained") with no look at staffing levels, workload, equipment, handover or the care plan, and the serious incident was reviewed by the person who was on shift or by the manager whose own decision is in question, with no note explaining why nobody independent was available.

    What the regulator expects to see. Not a law in itself, but CQC judges you against it, so an inspector will look for it and expect a reason where you depart from it.
  5. Learning actions carry an owner, due date and evidence requirement, and higher-risk actions are effectiveness-checked, not treated as done just because they were written down.

    Strong evidence: The action fields in section 15 (owner, due date, evidence required, completion date, review date, check that the action worked) and workflow step 7 which verifies whether the action changed practice (section 8); the checklist's 'Actions and evidence of learning' rows.

    Weak evidence: The action log reads "staff reminded at handover" or "training booked" with no named owner, no due date and no statement of what evidence would prove it happened. Actions are marked complete on the day they were written, nothing is attached to show they were carried out, no higher-risk action is revisited to see whether practice actually changed, and the same action reappears word for word after the next similar incident.

    Our recommended baseline. Not a legal or regulatory requirement, but a sensible standard we suggest where the rules leave the detail to you. Adapt it to your service.
  6. Incidents are reviewed for themes at a stated cadence, repeated or serious themes reach the risk register, and overdue actions stay visible to the Registered Manager.

    Strong evidence: The at-least-monthly trend review of repeated people, types, locations, shifts, late reporting and overdue actions (section 16), the quarterly audit and governance review (section 18), and the checklist's 'Governance and themes' rows on updating the risk register from repeated or serious themes.

    Weak evidence: Incidents are counted but never analysed: a monthly total of falls or medication errors with no breakdown by person, time of day, location, shift or staff group, and no minute showing the themes were discussed at governance. The risk register is untouched despite three similar incidents in a quarter, and overdue actions only surface when somebody asks for them rather than being visible to the Registered Manager as a matter of routine.

    Our recommended baseline. Not a legal or regulatory requirement, but a sensible standard we suggest where the rules leave the detail to you. Adapt it to your service.

Last verified 20 July 2026

Audit this policy

Incident reporting and learning procedure checklist

A policy is the intent; the evidence is what a CQC inspector actually asks to see. This matching checklist turns the policy above into the records to keep, the audit to run, and the places small services most often fall short.

Open the Incident reporting and learning procedure checklist

Spotted something to improve?

These are sample templates, not the last word. If you would change a wording, or want to help us confirm a detail, tell us and we will look at it.

Related Verivius content

Want help adapting this to your service?

A Verivius consultant can read your adapted policy against the live regulation and your service shape. The work fits inside a Mock Inspection engagement or a shorter consulting brief. A 20-minute conversation is the fastest way to find out whether the fit is right.

Get started free

Free to start, no card. A 14-day trial when you subscribe.

Last reviewed 19 July 2026