Sample policy · Reg 17

Risk Management and Risk Register Policy

Statutory anchor: Regulation 17 (good governance), Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 (SI 2014/2936). This policy also engages Regulation 12 (safe care and treatment). · primary source

Download the PDF

The PDF version of this template is the same content, formatted for adaptation in your document control system. The disclaimer above is repeated on the PDF cover.

Verivius pack version v1.1, 2026-07-19

1. What the regulation says

Systems or processes must be established and operated effectively to ensure compliance with the requirements in this Part. (Regulation 17(1))

assess, monitor and improve the quality and safety of the services provided in the carrying on of the regulated activity (including the quality of the experience of service users in receiving those services) (Regulation 17(2)(a))

assess, monitor and mitigate the risks relating to the health, safety and welfare of service users and others who may be at risk which arise from the carrying on of the regulated activity (Regulation 17(2)(b))

Regulation 12 adds the safe-care duties that this policy operationalises:

assessing the risks to the health and safety of service users of receiving the care or treatment (Regulation 12(2)(a))

doing all that is reasonably practicable to mitigate any such risks (Regulation 12(2)(b))

The full text is at https://www.legislation.gov.uk/uksi/2014/2936/regulation/17 and https://www.legislation.gov.uk/uksi/2014/2936/regulation/12. Where this policy and the regulation diverge, the regulation wins.

2. Plain-English summary

You have to run effective systems and processes to assess, monitor and improve quality and safety, and to assess, monitor and mitigate risks to people's health, safety and welfare. A live risk register, with owners, actions and review dates, is how a service shows it knows its risks, is acting on them, and is checking whether those actions work. A risk that is known but not acted on can itself become evidence of poor governance.

3. Purpose

The purpose of this policy is to make sure that risks to people using the service, staff, visitors and others are identified, assessed, controlled, reviewed and escalated.

Risk management is part of safe care, good governance and everyday leadership. The service must show that it understands its risks, reduces them and checks whether controls work.

This policy supports Regulation 12 and Regulation 17 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014.

4. Policy warning

Risks must not be left informal, hidden in manager memory, or discussed repeatedly without ownership and action.

Where a risk could affect the health, safety, welfare, rights or experience of people using the service, it must be recorded, assessed, assigned, monitored and reviewed.

5. Scope

This policy applies to risks relating to:

5.1 Local arrangements before adoption

Before adoption, the provider records:

CQC Regulation 17 requires an effective system but does not prescribe a matrix. If the provider uses a 5 by 5 matrix, it must define the levels, calculation and rating boundaries.

6. Definitions

A risk is something that could cause harm, unsafe care, poor experience, service failure or regulatory non-compliance.

A control is something already in place to reduce the likelihood or impact of the risk.

A risk rating is the service's judgement of likelihood and impact.

A risk register is the live record of significant risks, controls, owners, actions and review dates.

A closed risk is a risk that has been removed or reduced to a level the service formally accepts, with evidence and rationale.

7. Responsibilities

All staff are responsible for identifying and reporting risks.

Managers are responsible for assessing risks, agreeing controls, escalating concerns and ensuring actions are completed.

The Registered Manager is responsible for maintaining the risk register and ensuring that significant risks are reviewed through governance meetings.

The Nominated Individual or provider representative is responsible for reviewing high and persistent risks and ensuring that the provider takes action where service-level controls are not enough.

8. Operational risk workflow and identification

The service follows this sequence for every service-level risk:

  1. Identify: describe the uncertain event or condition, its cause, who or what may be affected and the potential consequence. Take immediate protective action before scoring where harm may be imminent.
  2. Record and link: create or update the risk-register entry and link the incident, complaint, safeguarding concern, audit, alert, change or person-level pattern that revealed it.
  3. Assess: score likelihood and impact using the approved matrix, record the evidence and uncertainty behind the judgement, and distinguish the risk before further controls from the residual risk after current controls.
  4. Control: state the controls already operating, the evidence that they work and any additional action needed. A policy statement is not a control unless it is implemented and checked.
  5. Own and escalate: assign one accountable owner, action owners, deadlines and the next review. Escalate according to rating, acceptance authority and external-reporting thresholds.
  6. Review: reassess after the agreed interval and after change, incident, failed control or new information. Record whether the score, controls, actions and acceptance decision remain justified.
  7. Close or retain: close only when the risk is removed, transferred or formally accepted at a lower level with evidence. Record ongoing monitoring and reopen the risk if conditions change or the issue recurs.
  8. Learn across governance: use trends to update audits, training, business continuity, staffing and improvement plans, and communicate changed controls to affected staff.

8.1 Risk identification

Risks may be identified through:

Staff must be encouraged to raise risks early. A risk raised in good faith must not be treated as criticism or disloyalty.

9. Risk assessment

Each risk must be assessed by a competent person. The assessment must consider:

The assessment must balance safety with the person's rights, choices, preferences and independence where relevant.

10. Risk rating

The service will use its approved risk matrix based on likelihood and impact. Each risk will be assigned a score and one of these governance ratings:

The record must show both the starting or inherent risk where useful and the residual rating after current controls have been considered. Staff must use the local definitions rather than choosing a colour by instinct.

High and extreme risks must be escalated to the Registered Manager immediately. Extreme risks must also be escalated to the Nominated Individual or provider representative.

11. Risk register

The risk register must include:

The risk register must be kept up to date. It must be a live governance tool, not a document updated only before inspection.

12. Controls and actions

For each risk, the service must decide whether to:

Actions must have an owner, due date and evidence requirement.

Where a control depends on staff behaviour, training or supervision, the service must check whether it is actually being followed in practice.

13. Escalation

A risk must be escalated where:

Escalation may be internal, to the provider or board, or external to safeguarding, CQC, commissioner, professional body, emergency services or another relevant organisation. The escalation decision must be recorded.

14. Review frequency

Risks must be reviewed at a frequency proportionate to their rating:

Risks must also be reviewed after incidents, complaints, safeguarding concerns, staffing changes, new guidance, inspection findings or material changes in the service.

15. Closing a risk

A risk may only be closed where the Registered Manager is satisfied that:

The closure record must include:

A risk must not be closed simply because an action has been completed. The service must consider whether the risk has actually changed.

16. Links with incidents, complaints, safeguarding and audits

The risk register must link to other governance processes.

The Registered Manager must consider adding or updating a risk where there is:

The service must be able to show how information from one governance process affects the others.

17. Service-level and person-level risks

Person-level risks must be recorded in the person's care record, risk assessment or care plan.

Service-level risks must be recorded on the risk register.

Where a person-level risk reveals a wider service issue, such as repeated falls, medicine errors or staffing shortage, the wider issue must be added to the risk register.

18. Provider oversight

The provider, Nominated Individual or responsible director must review the risk register at least quarterly. They must pay particular attention to:

Provider review must be recorded.

19. Evidence

The service must keep evidence of:

20. Audit

The Registered Manager must audit the risk register at least quarterly. The audit must check:

Audit findings must be recorded and actioned.

21. Related policies in this pack

This policy should be read with:

22. Review

This policy will be reviewed annually, or sooner following a serious incident, safeguarding concern, CQC inspection finding, significant service change, or repeated failure to manage risk effectively.

23. Sources and further reading

This template is based on CQC's guidance for providers and managers, the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, and other topic-specific legislation and guidance listed below. It is a starting point for adaptation, not a substitute for legal, clinical, HR, safeguarding or specialist professional advice.

24. When to seek further advice

Seek specialist advice where the issue involves serious harm, safeguarding, deprivation of liberty, restraint, children, professional misconduct, controlled drugs, radiation, termination of pregnancy, infection outbreak, water safety, employment dismissal, DBS barring referral, or regulatory enforcement.

25. Document control

Version Date Author Changes
v1 2026-06-10 Verivius (sample) Initial sample template, conformed to the Verivius policy standard.
v1.1 2026-07-19 Verivius (sample) Added local matrix decisions and an end-to-end risk workflow.

This sample policy template was issued by Verivius. It is a template, not a substitute for legal advice or the provider's own policy-development process. Where this template and live law or regulator guidance diverge, the live source wins.

What good looks like here

Written from an ex-CQC inspector's chair, but the point is safe, well-led care your team can stand behind. Each row shows what strong evidence looks like, what thin evidence looks like, and where the expectation comes from.

The danger this policy guards against is not the unknown risk but the known one that sits recorded and unmanaged: the falls pattern, the medicines-storage fault or the staffing shortfall that everyone in the building can name yet no one owns. A register earns its place only when it changes what happens on the floor, so the person at risk of a fall is protected before it happens rather than written up afterwards. The trap is the register that becomes a museum of concerns, refreshed before a visit and ignored between them, leaving the same hazards live while the paperwork looks managed. For the person using the service the difference is concrete: whether the control written in the controls column is the control they actually receive on a Tuesday afternoon when the regular staff are off. A service that can show one real event travelling into the register, changing a control and lowering the rating is doing the everyday leadership that keeps people safe, and that same trail is what a well-led judgement later rests on.

  1. The risk register is a live working record that holds up when opened on any ordinary day, current rather than tidied up retrospectively, so a colleague coming on shift can see what is actually being managed.

    Strong evidence: A recent review or version date, with every entry carrying a named owner, a current rating and status, actions with due dates, and a next-review date.

    Weak evidence: The register is produced, but every line carries the same review date, entered in the days before the visit, so nothing shows risks being monitored in between. Owners are blank or generic ('management'), ratings have not moved in a year, and actions carry no due date and no next-review date, so there was never a point at which anyone was due to look again.

    Our recommended baseline. Not a legal or regulatory requirement, but a sensible standard we suggest where the rules leave the detail to you. Adapt it to your service.
  2. For a high or extreme risk, the controls listed on the register are the controls the person actually receives, not just words in the controls column.

    Strong evidence: The assessment showing what could happen and who is affected, the scored rationale, the named controls, and supervision, observation or audit evidence that a behaviour-dependent control works.

    Weak evidence: For a high or extreme risk the controls column names a policy, a training course and a checklist, but nothing shows the behaviour-dependent control actually happening: no supervision note, spot check, observation or audit confirming staff do it. A control that exists only on paper is the commonest gap on this check.

    A legal duty. This comes from legislation that applies to your service, so meeting it is not optional. The exact provision is cited beneath the badge.

    Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, reg 12(2)(a)-(b)

  3. The register is fed by real events, so incidents, complaints, safeguarding concerns and audit failures reach it as well as running through their own reporting routes.

    Strong evidence: A recent serious or repeated incident, complaint theme or audit finding traced to the register entry it created or updated, and a person-level risk escalated to a service-level risk where it showed a wider issue.

    Weak evidence: A recent serious or repeated incident, a running complaint theme or a failed audit left no trace on the register, so the incident log and the register tell different stories about the same service. A repeated person-level pattern such as falls or medicines errors stayed in the care files and never rose to a service-level risk, so nobody owns the pattern.

    What the regulator expects to see. Not a law in itself, but CQC judges you against it, so an inspector will look for it and expect a reason where you depart from it.
  4. Overdue actions are visible and escalated rather than sinking down the page, and high or extreme risks are reviewed at the level and frequency their rating demands.

    Strong evidence: The action tracker showing escalation of overdue items, and governance minutes (with provider or Nominated Individual review) where high and extreme risks were tabled.

    Weak evidence: Actions sit marked 'ongoing' with no movement and nothing escalated, and the tracker lists overdue items in date order rather than flagging them, so they disappear down the page. High or extreme risks are missing from governance minutes, or they appear with no record of provider or Nominated Individual challenge and no fresh review since the risk was raised.

    Our recommended baseline. Not a legal or regulatory requirement, but a sensible standard we suggest where the rules leave the detail to you. Adapt it to your service.
  5. A risk is closed because the risk to people actually reduced, not because one action was ticked off.

    Strong evidence: A closed risk with its closure reason, the evidence reviewed and who approved it, and for an accepted risk, senior sign-off and an ongoing monitoring plan.

    Weak evidence: A risk is closed on the day its single action is ticked, the closure reason reads 'action complete', and nothing shows the likelihood or impact actually fell. An accepted risk is signed off with no senior name against it and no monitoring plan, so an open hazard has been moved off the register rather than reduced.

    Our recommended baseline. Not a legal or regulatory requirement, but a sensible standard we suggest where the rules leave the detail to you. Adapt it to your service.

Last verified 20 July 2026

Audit this policy

Risk management and risk register procedure checklist

A policy is the intent; the evidence is what a CQC inspector actually asks to see. This matching checklist turns the policy above into the records to keep, the audit to run, and the places small services most often fall short.

Open the Risk management and risk register procedure checklist

Spotted something to improve?

These are sample templates, not the last word. If you would change a wording, or want to help us confirm a detail, tell us and we will look at it.

Related Verivius content

Want help adapting this to your service?

A Verivius consultant can read your adapted policy against the live regulation and your service shape. The work fits inside a Mock Inspection engagement or a shorter consulting brief. A 20-minute conversation is the fastest way to find out whether the fit is right.

Get started free

Free to start, no card. A 14-day trial when you subscribe.

Last reviewed 19 July 2026