Sample policy · Reg 13

Professional Boundaries and Conduct Policy

Statutory anchor: Regulation 13 (safeguarding service users from abuse and improper treatment), Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 (SI 2014/2936). This policy also engages Regulation 10 (dignity and respect) and Regulation 19 (fit and proper persons employed). · primary source

Download the PDF

The PDF version of this template is the same content, formatted for adaptation in your document control system. The disclaimer above is repeated on the PDF cover.

Verivius pack version v1.1, 2026-07-19

1. What the regulation says

Service users must be protected from abuse and improper treatment in accordance with this regulation. (Reg 13(1) (the headline duty))

Systems and processes must be established and operated effectively to prevent abuse of service users. (Reg 13(2) (prevention systems))

Systems and processes must be established and operated effectively to investigate, immediately upon becoming aware of, any allegation or evidence of such abuse. (Reg 13(3) (investigation systems))

any behaviour towards a service user that is an offence under the Sexual Offences Act 2003, (Reg 13(6)(a) (sexual offences))

theft, misuse or misappropriation of money or property belonging to a service user, or (Reg 13(6)(c) (theft / misuse / misappropriation))

This policy also engages Regulation 10 (dignity and respect) and Regulation 19 (fit and proper persons employed):

Service users must be treated with dignity and respect. (Regulation 10(1))

be of good character, (Reg 19(1)(a) (good character))

The full text of the regulation is at https://www.legislation.gov.uk/uksi/2014/2936/regulation/13. Where this policy and the regulation diverge, the regulation wins.

2. Plain-English summary

Service users must be protected from abuse and improper treatment. You need effective systems to prevent abuse, and effective systems to investigate any allegation or evidence of abuse as soon as you become aware of it. Care must not be provided in a way that discriminates, uses disproportionate control or restraint, is degrading, or significantly disregards the service user's needs. Service users cannot be deprived of their liberty without lawful authority. Professional boundaries are how a service prevents abuse before it happens: clear limits on conduct, money, relationships, communication and access protect people using the service, staff and the provider, and they make breaches easier to spot and investigate.

3. Purpose

The purpose of this policy is to make clear the professional standards and boundaries expected of everyone working in or for [Service Name].

Professional boundaries protect people using the service, staff and the provider. They support safe care, dignity, safeguarding, trust, confidentiality and good governance.

This policy supports Regulation 13 safeguarding, Regulation 10 dignity and respect, Regulation 11 consent, Regulation 12 safe care and treatment, Regulation 17 good governance, Regulation 18 staffing, Regulation 19 fit and proper persons employed, and relevant professional standards.

4. Policy warning

Staff must not use their role, access, knowledge, authority or relationship with a person using the service for personal, sexual, emotional, financial, social, political or other improper advantage.

A breach of professional boundaries may be abuse, misconduct, professional misconduct, a safeguarding matter, a criminal matter, or evidence that the person is not fit to work in the service.

The service will act immediately where boundaries are crossed or where a person using the service may be at risk.

5. Scope

This policy covers conduct and boundaries involving:

It applies at work, during service-related activity, online, and outside work where conduct may affect suitability, safety or trust.

Local adoption decisions

Before adoption, the provider defines:

6. Principles

Staff must:

Professional warmth is encouraged. Personal dependency, secrecy, favouritism or exploitation is not.

7. Responsibilities

All staff are responsible for maintaining professional boundaries and raising concerns.

Managers are responsible for setting expectations, supervising practice, challenging poor conduct and acting on concerns.

The Registered Manager is responsible for investigating boundary concerns, safeguarding escalation, referrals and governance review.

The provider or Nominated Individual is responsible for oversight where concerns are serious, repeated or involve managers.

8. Relationships with people using the service

Staff must maintain a professional relationship with people using the service.

Staff must not:

Any existing personal relationship must be declared to the Registered Manager.

9. Sexual boundaries

Sexual behaviour, sexual comments, sexualised jokes, sexualised touch, grooming, exposure, sharing sexual images or sexual relationships with people using the service are prohibited.

Any sexual boundary concern must be escalated immediately.

The Registered Manager must consider:

10. Gifts, money and financial boundaries

Staff must not borrow from, lend to, sell to, buy from, or financially exploit people using the service.

Staff must not accept gifts, money, loans, tips, personal benefits, bequests or favours except in line with the service's Gifts and Hospitality Policy.

Staff must not:

Any financial irregularity must be reported immediately.

11. Social media and digital contact

Staff must not contact, follow, message, befriend or interact with people using the service or their relatives through personal social media accounts unless there is a pre-existing relationship declared and approved by the Registered Manager.

Staff must not:

Digital contact must be professional, recorded and service-approved.

12. Communication

Staff must communicate in a way that is respectful, clear and appropriate.

Staff must not use:

Where a person has communication needs, staff must adapt communication to support understanding and involvement.

13. Confidentiality and access to records

Staff must only access records where they have a legitimate work reason.

Staff must not access records because they know the person, are curious, or have a personal interest.

Staff must not disclose confidential information to unauthorised people.

Breaches of confidentiality may be treated as misconduct, data breach, safeguarding concern or professional-regulatory matter.

14. Working within competence

Staff must work within their role, training, competence and authorisation.

Staff must not:

Concerns about competence must be raised with a manager immediately.

15. Conflicts of interest

Staff must declare conflicts of interest.

Examples include:

The Registered Manager must record the conflict and any controls required.

16. Boundaries in lone working and home settings

Where staff work alone or in people's homes, professional boundaries remain essential.

Staff must:

17. Boundary-concern workflow

Staff must report concerns immediately where they see or suspect:

Concerns may be raised with the line manager, Registered Manager, safeguarding lead, provider representative or through the whistleblowing route.

  1. Protect. The receiving manager checks immediate safety, supports the person affected and preserves relevant records, messages, rota information or devices lawfully.
  2. Create the concern trail. The concern is recorded and linked to any incident, complaint, safeguarding or data-breach record. The reporter's words and observed facts are kept separate from assumptions.
  3. Triage external duties. Safeguarding, police, professional-regulator, DBS, CQC, commissioner and ICO thresholds are considered without waiting for the internal process to finish where urgent action is required.
  4. Investigate without conflict. A suitably independent lead, decision maker and timescale are named. The staff member is informed and given a fair opportunity to respond unless another authority requires delay.
  5. Decide and refer. The outcome, fitness decision, employment action and each referral or non-referral rationale are approved by the Registered Manager or provider representative.
  6. Close and learn. Support, restrictions and follow-up are confirmed. Training, supervision, policy, staffing and risk actions are assigned before the record closes.

18. Immediate protective action

Where a boundary concern may place a person at risk, the Registered Manager must consider immediate protective action.

This may include:

The decision must be recorded.

19. Investigation

Boundary concerns must be investigated proportionately and fairly.

The investigation may include:

Internal investigation must not interfere with safeguarding or police enquiries.

20. Referral duties

The Registered Manager must consider whether the concern requires referral to:

The decision to refer or not refer must be recorded with rationale.

21. Staff support and training

Staff must receive training on professional boundaries appropriate to their role.

Training must cover:

Supervision must include discussion of boundaries where risk or role requires it.

22. Records and evidence

The service must keep records of:

Records must be factual, secure and restricted to authorised people.

The concern record is cross-linked to any incident, safeguarding, complaint, data-breach or person record. Referral references and decisions are linked to the relevant record, and resulting controls are entered in the risk, training, supervision, audit and improvement-actions registers with owners and review dates.

23. Audit and governance

The Registered Manager must review professional-boundary concerns through governance.

The review must consider:

Serious or repeated boundary concerns must be escalated to provider level.

Governance findings are recorded in the audit register. Corrective actions are assigned in the improvement-actions register, systemic or repeated concerns are linked to the risk register, and competence or conduct controls are linked to training and supervision records.

24. Related policies

This policy should be read with:

25. Review

This policy will be reviewed annually, or sooner following a safeguarding concern, complaint, boundary incident, professional-regulatory matter, CQC finding, data breach, staff conduct theme or change in legal or professional guidance.

26. Sources and further reading

This template is based on CQC's guidance for providers and managers, the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, and other topic-specific legislation and guidance listed below. It is a starting point for adaptation, not a substitute for legal, clinical, HR, safeguarding or specialist professional advice.

27. When to seek further advice

Seek specialist advice where the issue involves serious harm, safeguarding, deprivation of liberty, restraint, children, professional misconduct, controlled drugs, radiation, termination of pregnancy, infection outbreak, water safety, employment dismissal, DBS barring referral, or regulatory enforcement.

28. Document control

Version Date Author Changes
v1 2026-06-10 Verivius (sample) Initial sample template, conformed to the Verivius policy standard.
v1.1 2026-07-19 Verivius (sample) Added local boundary rules, a six-stage concern workflow and explicit links between concern evidence, referrals, risk, training, supervision and improvement actions.

This sample policy template was issued by Verivius. It is a template, not a substitute for legal advice or the provider's own policy-development process. Where this template and live law or regulator guidance diverge, the live source wins.

What good looks like here

Written from an ex-CQC inspector's chair, but the point is safe, well-led care your team can stand behind. Each row shows what strong evidence looks like, what thin evidence looks like, and where the expectation comes from.

Boundary breaches are rarely a single dramatic event. They build through small, deniable steps: an extra unrostered visit, a personal mobile number handed over so the person can reach someone at night, a favour, a loan, a secret kept from the team. Each step is defensible on its own, which is exactly why the trail matters. The harm shows in the pattern rather than in any single entry, and the people most at risk are often those who least want the relationship examined, because it is also the warmest one they have. A service that records boundary concerns properly can see grooming or financial dependency forming while it is still preventable, and can act without wrecking the trust of someone who does not experience the relationship as abusive at all. A service that treats each concern as a private conduct conversation between a manager and a member of staff loses the pattern, loses the evidence and usually learns how bad it had become from somebody outside the organisation.

  1. An allegation or evidence of a boundary breach or abuse is acted on as soon as the service becomes aware, not parked while someone decides if it is serious. Immediate protective action follows, and a named, suitably independent investigation lead takes the concern on rather than the person being left at continued risk.

    Strong evidence: The boundary-concern record showing immediate protective action taken (section 18) and a named independent lead, decision maker and timescale (section 17 stages 1 and 4), engaging the Reg 13(3) duty to investigate 'immediately upon becoming aware' of any allegation or evidence of abuse.

    Weak evidence: The first dated entry on the concern record sits well after the shift on which someone first raised it, and the gap is bridged by a manager's later recollection rather than a contemporaneous note. Protective action reads as "monitored" or "kept an eye on the situation", with nothing showing what actually changed on the rota or in direct-contact duties. The investigation lead is the same line manager the concern was about, and no decision maker or timescale is named anywhere on the file.

    A legal duty. This comes from legislation that applies to your service, so meeting it is not optional. The exact provision is cited beneath the badge.

    Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, reg 13(3)

  2. Each external referral decision is made and recorded, including a decision not to refer. Safeguarding, police, barring, professional-regulator and CQC-notification thresholds are each considered and the rationale written down, not a single internal outcome with no referral trail. A local-authority safeguarding referral is not itself a CQC notification; the notification duty rests on the abuse allegation itself.

    Strong evidence: The referral decision record with rationale for each of safeguarding authority, police, Disclosure and Barring Service, professional regulator, CQC, commissioner or local authority and Information Commissioner's Office (section 20), cross-linked to the concern record (section 22).

    Weak evidence: A single line reading "safeguarding informed" or "no further action required", with nothing to show that police, Disclosure and Barring Service, professional-regulator and CQC-notification thresholds were each considered on their own facts. In the weakest files only the referrals actually made are recorded, so a considered decision not to refer looks identical to never having thought about it, and a local-authority safeguarding referral is logged as though it discharged the CQC notification duty as well.

    Our recommended baseline. Not a legal or regulatory requirement, but a sensible standard we suggest where the rules leave the detail to you. Adapt it to your service.
  3. The concern trail keeps observed fact separate from assumption and preserves evidence lawfully. The reporter's words and observed facts are recorded apart from opinion, and relevant messages, rota information or devices are preserved lawfully rather than lost, so whoever picks the concern up next is working from what actually happened.

    Strong evidence: The concern record linked to any incident, complaint, safeguarding or data-breach record, with the reporter's words and observed facts kept separate from assumptions (section 17 stage 2, section 22).

    Weak evidence: The record opens with a conclusion, for example "staff member denies any inappropriate relationship, appears to be a personality clash between the two of them", and the reporter's own words appear nowhere in the file, so there is no way to separate what was observed from what was inferred. Rota sheets have been overwritten, the message thread was deleted by the person who reported it, or a manager scrolled through a staff member's personal phone with no lawful basis under data-protection law and no record of what was looked at or why.

    Our recommended baseline. Not a legal or regulatory requirement, but a sensible standard we suggest where the rules leave the detail to you. Adapt it to your service.
  4. Sexual-boundary concerns are escalated immediately, not handled as a private conduct matter. A sexual comment, sexualised touch, grooming or a relationship with a person using the service triggers immediate escalation and full protective and referral consideration, not an informal word with the staff member.

    Strong evidence: The escalation and incident record for the sexual-boundary concern showing consideration of safeguarding referral, police contact, suspension or restriction, Disclosure and Barring Service referral, professional-regulator referral, CQC notification and support for the person affected (section 9).

    Weak evidence: The trail is a supervision note saying the staff member was "reminded of professional boundaries" after a sexualised comment or an unwanted touch, with no incident record raised at all. Nothing shows that suspension or restriction from duties, a safeguarding referral, police contact, a Disclosure and Barring Service referral or a professional-regulator referral were even weighed, and support offered to the person affected is missing from the file entirely.

    Our recommended baseline. Not a legal or regulatory requirement, but a sensible standard we suggest where the rules leave the detail to you. Adapt it to your service.
  5. Financial boundaries are controlled and irregularities reported at once, not noticed and left. Money handling is authorised and recorded, staff are kept out of wills, bank cards and personal identification numbers, and any financial irregularity is reported immediately.

    Strong evidence: Authorisation and recording of any money handling, declared conflicts of interest with the controls the Registered Manager set (sections 10 and 15), and the report of any financial irregularity.

    Weak evidence: Money handling appears only in daily notes as "shopping done, change returned", with no authorisation recorded through care planning, no running total of what was held and spent, and no second person's check where the service's own scheme calls for one. Personal identification numbers are passed on verbally because it is quicker, a staff member is named in a will or holds a bank card with no declared conflict of interest and no controls recorded by the Registered Manager, and a small unexplained shortfall was written in a handover book and never reported or followed up.

    Our recommended baseline. Not a legal or regulatory requirement, but a sensible standard we suggest where the rules leave the detail to you. Adapt it to your service.
  6. Boundary concerns are reviewed through governance for repeated themes, not closed one at a time. Governance review links recurring concerns to training, supervision, lone-working and recruitment or fitness, and serious or repeated concerns are escalated to provider level.

    Strong evidence: The audit register and governance findings, with corrective actions in the improvement-actions register and systemic or repeated concerns linked to the risk register, training and supervision records (section 23).

    Weak evidence: Boundary concerns exist as a set of individually closed cases with no register that would let anyone see three concerns attaching to the same team, the same lone-working round or the same pattern of out-of-hours messaging. Governance minutes count how many were closed rather than naming what was found, and no corrective action can be traced forward into training records, supervision notes, the risk register or recruitment and fitness decisions.

    Our recommended baseline. Not a legal or regulatory requirement, but a sensible standard we suggest where the rules leave the detail to you. Adapt it to your service.

Last verified 20 July 2026

Spotted something to improve?

These are sample templates, not the last word. If you would change a wording, or want to help us confirm a detail, tell us and we will look at it.

Related Verivius content

Want help adapting this to your service?

A Verivius consultant can read your adapted policy against the live regulation and your service shape. The work fits inside a Mock Inspection engagement or a shorter consulting brief. A 20-minute conversation is the fastest way to find out whether the fit is right.

Get started free

Free to start, no card. A 14-day trial when you subscribe.

Last reviewed 19 July 2026