
Key Takeaways
- The Real Compliance Risk
- What Inspectors Often Find
- Common Evidence Gaps
- How to Self-Audit This Area
- Conclusion
7 Essentials Every CQC Risk Register Must Include
A CQC risk register is a critical governance tool that identifies, evaluates, and monitors risks to the safety, quality, and regulatory compliance of a care service. Under Regulation 17 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, providers must demonstrate robust systems to assess and mitigate risks. A well-maintained risk register ensures your service can evidence proactive management of risks during inspections, reducing the likelihood of enforcement action.
A lack of structured risk oversight can lead to challenges in demonstrating compliance with Regulation 17. For example, services may struggle if their risk registers omit key operational risks, such as medication errors or staffing shortages, or fail to evidence timely actions taken to address them. Inspectors will scrutinise whether your risk register is not just a list but a living document tied to your service's day-to-day operations. If you’re a Registered Manager, ask yourself: “Could I confidently explain to an inspector how each identified risk is monitored and mitigated?” If not, you’re already on shaky ground. This article will break down exactly what to include in a CQC risk register, with real-world examples from the care sector to help you avoid common pitfalls.
The Real Compliance Risk
The primary compliance risk in a CQC risk register is failing to maintain a clear, up-to-date, and actionable document that identifies, assesses, and mitigates risks tied to delivering safe, effective, and well-led care. Inspectors will scrutinise whether your risk register demonstrates a proactive approach to managing foreseeable risks under Regulation 17: Good Governance of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014. A poorly managed risk register can indicate governance challenges that may impact compliance ratings.
In our audits, we consistently see services fall short by listing risks without linking them to tangible mitigation strategies or responsible personnel. For example, in one care home, the risk register flagged "falls in communal areas" but failed to outline specific actions like increased staff supervision during peak hours or installing motion sensor alarms. When the CQC inspector reviewed incident reports, they found several unaddressed falls over three months, exposing a gap between identified risks and actual practice. This is exactly the kind of evidence trail that inspectors follow to assess whether governance frameworks are operationally effective.
Another common failure point is ignoring dynamic risks that evolve with the service. For instance, in a supported living setting, a newly admitted resident with complex behaviours triggered several safeguarding concerns. However, the risk register hadn’t been updated to reflect this, nor did it include measures like additional staff training or a behaviour support plan. Inspectors may identify gaps in governance and oversight as potential breaches of Regulation 17. If the risk register doesn’t align with the lived reality of the service, expect serious questions about leadership and oversight.
To pass scrutiny, your risk register must be more than a static document. It should outline specific risks (e.g., medication errors, staffing shortages), assess their likelihood and impact, and—critically—list actionable controls. For example, if staffing levels are a recurring issue, the register should not only highlight the risk but also document steps like active recruitment, agency cover arrangements, and monitoring staff-to-resident ratios daily. A well-maintained risk register signals to inspectors that the service is not only aware of its vulnerabilities but actively working to mitigate them, which is a cornerstone of compliance under Regulation 17.
What Inspectors Often Find
CQC inspectors reviewing risk registers most commonly find gaps in medication administration records (MAR charts), incomplete supervision records, and unsigned governance audits. These issues signal weak oversight and a failure to maintain a robust evidence trail. For example, inspectors frequently uncover MAR charts with missing signatures or unexplained time gaps, suggesting potential medication errors or omissions. Similarly, supervision records often lack documented follow-up actions, and governance audits are left unsigned, undermining accountability and effective risk management.
Inspectors will typically find that MAR charts are incomplete, with missed doses or unclear annotations being a recurring issue. For instance, in one care home audit we conducted, over 20% of MAR charts reviewed had at least one missing staff signature for administered medications. This immediately raised concerns about whether the medication was given or missed entirely. A common failure point is the lack of documented reasons for omissions, such as medication refusals or temporary unavailability of stock. Without this information, inspectors are likely to question how the service mitigates risks related to medication errors or non-compliance.
A common pattern is the absence of follow-up actions in supervision records. In practice, services often document that a staff member attended supervision, but the record fails to outline what actions were agreed upon or how progress would be monitored. For example, in a recent supported living service review, we found a staff member flagged during supervision as needing additional training in moving and handling. However, the risk register did not reflect any follow-up actions, nor was there evidence that the training had been scheduled. This lack of continuity in staff development can create evidence gaps that may affect compliance under the Well-Led Key Question.
Unsigned governance audits are another red flag inspectors frequently encounter. A typical scenario involves audits of infection control, care plans, or incident reporting being completed but left unsigned by the responsible person. Without a signature, there’s no way to confirm that the audit was reviewed, let alone acted upon. In one domiciliary care service we audited, a monthly health and safety audit identified a faulty fire door, but because the audit wasn’t signed, there was no evidence to show that the issue was escalated or resolved. Inspectors will see this as a systemic failure to manage risks effectively and ensure the safety of service users.
Check Your Inspection Readiness
Free 2-minute assessment — instant results tailored to your service type.
Lastly, outdated or inconsistent care plans often appear on the radar. For instance, after a hospital admission due to a fall, a service user’s care plan should be updated to reflect any new risks, such as changes in mobility or the introduction of mobility aids. However, in many services, we find that care plans remain static, even after significant incidents. Inspectors will follow the evidence trail by cross-referencing incident logs, hospital discharge summaries, and the care plan itself. If updates are missing, it’s a clear indicator that the service is not adequately identifying, assessing, or mitigating risks for individuals, which could lead to breaches in Regulation 12 or 17.
Common Evidence Gaps
The most common evidence gaps in a CQC risk register include missing risk assessments for key areas such as fire safety or medication errors, outdated mitigation plans that haven’t been reviewed or updated in months, incomplete incident logs with no evidence of follow-up actions, and risks that are identified but lack clear ownership or timelines for resolution. Inspectors may identify these gaps as potential breaches of Regulation 17 due to insufficient governance and oversight.
Providers who embed their risk register into their day-to-day operations are generally better prepared for inspection. For example, services often identify recruitment challenges as a risk but fail to include a detailed assessment of the potential impact on care delivery, such as delayed calls in domiciliary care or unsafe staff-to-resident ratios in care homes. Inspectors will look for evidence of a clear mitigation plan, such as using agency staff or adjusting rotas, and will question how regularly this plan is reviewed. When they don’t see this, it’s a red flag for poor governance.
Another common failure point is incomplete or outdated documentation for incidents and near-misses. For instance, services may log a medication error but fail to document the investigation, actions taken, or lessons learned. This creates an evidence gap that inspectors will note, as it suggests that the service is not learning from incidents to prevent future risks. The evidence trail here starts with the incident log and should lead to updated training records, changes in policy, or revised risk assessments. If these links are broken, it’s a clear indicator of weak quality assurance processes.
We also consistently see gaps in maintenance-related risks, particularly with fire safety. A typical example is when a service has a fire risk assessment that hasn't been reviewed in over a year or lacks evidence of follow-up actions for identified hazards, such as replacing faulty fire doors or ensuring regular fire drills. Inspectors will scrutinise this and ask for evidence such as drill records, maintenance logs, and staff training records. Without these, you’re likely to face a compliance challenge under Regulations 12 and 17.
Lastly, risks related to compliance with the Mental Capacity Act (MCA) and Deprivation of Liberty Safeguards (DoLS) are often poorly documented. For example, a risk register may flag a resident as requiring a DoLS authorisation, but when inspectors check the evidence file, they find no record of the application or an expired authorisation with no follow-up. Additionally, MCA assessments often lack the required decision-specific detail, leaving inspectors questioning whether care is being delivered lawfully. These gaps not only reflect poorly on your governance framework but also raise significant safeguarding concerns.
How to Self-Audit This Area
To self-audit your CQC risk register, start by reviewing the last six months of key incidents, complaints, and safeguarding concerns to ensure they are clearly logged as risks with corresponding actions. Cross-check these risks against your risk register, ensuring each has a named owner, review date, and evidence of mitigation. Then, validate that your register aligns with your service’s Statement of Purpose and reflects current operational realities.
Begin by pulling your incident reports, complaints log, safeguarding notifications, and accident records for the past six months. Inspectors will expect these to feed directly into your risk register. For example, if you've had three medication errors in the past quarter, they should appear as a risk category with clear mitigation strategies such as additional staff training, competency checks, or changes to your medication policy. If they don’t appear, you’ve got a glaring evidence gap.
Next, review the governance meeting minutes for the same period. Inspectors will typically ask to see evidence that risks are actively discussed and monitored at these meetings. Check whether risks recorded in the register have been reviewed, and whether any decisions or actions were documented. For instance, if “staffing shortages” is listed as a risk, there should be minutes showing discussions about recruitment efforts, agency staff usage, or rota adjustments. If these links are missing, you’re at risk of a Regulation 17 breach.
Now, audit the "ownership" of risks in your register. Each risk must have a named owner responsible for managing and reviewing it. In our audits, we consistently see services fail here, with risks either left without an owner or being assigned to someone no longer in the organisation. For example, if a Registered Manager has left, ensure their risks have been reassigned. Inspectors will follow this evidence trail to determine if risks are being proactively managed.
Finally, conduct a spot-check of your risk register entries against the actual environment. For example, if your register lists “infection control” as a high-priority risk, visit specific areas of your service and evaluate whether mitigation measures are visibly in place—are hand sanitiser stations stocked? Is PPE stored appropriately? Are cleaning schedules up to date? This real-world verification is crucial because inspectors will look for practical evidence that your risk management is not just a paper exercise.
Conclusion
If you take ONE thing from this post, it's that a robust, well-maintained risk register is not just a regulatory box-ticking exercise — it’s your frontline defence during CQC inspections. By clearly documenting risks, mitigation strategies, review dates, and responsible persons, you’re not only safeguarding your service but also creating an evidence trail that demonstrates proactive governance under Regulation 17 of the Health and Social Care Act 2008. Inspectors will actively look for this level of detail to ensure you’re identifying and managing risks effectively.
The key is to move beyond generic entries and focus on service-specific risks — from medication errors and staffing shortages to infection control breaches. Providers who embed their risk register into their day-to-day operations are generally better prepared for inspection. If you're unsure where to start or want to ensure your risk register stands up to scrutiny, run a self-audit using MyCareAudit's risk register templates. Don't wait until the inspection notice lands — act now to close your evidence gaps and protect your rating.
Run Your Own Compliance Check
Use our free Audit Checklist Generator to instantly create a tailored compliance checklist for your service. It takes under two minutes and covers all key regulatory areas.
Generate Your Free Checklist →
Need Help Passing Your Next Inspection?
MyCareAudit offers expert-led support to help you prepare with confidence:
- Book a Mock Inspection — a realistic, no-risk rehearsal with detailed feedback
- Get CQC Registration Support — end-to-end guidance through the application process
Speak to our compliance team today.
Further Reading
Explore more compliance guides and inspection preparation resources in our CQC Domiciliary Care Compliance hub.
Frequently Asked Questions
Q: How often should I audit this area?
A: Best practice is to conduct focused audits monthly, with a comprehensive review at least quarterly.
Q: What evidence will inspectors look for?
A: Inspectors typically request documented policies, completed audit trails, staff training records, and evidence of continuous improvement.
Q: Can I use MyCareAudit to prepare?
A: Yes — our free audit tool and checklist generator are designed specifically for UK care providers preparing for inspection.
Related Articles

Care Governance Dashboard Templates for UK Providers
Care Governance Dashboard Templates for UK Care Providers Care governance dashboard templates are structured tools designed to help UK care providers monitor compliance, performance, and quality...

Care Compliance Audit Checklist: 10 Key Areas to Review
The Ultimate Care Compliance Audit Checklist: 10 Essential Areas to Review A care compliance audit checklist refers to a structured tool used by UK care providers to ensure their services meet regu...

The Ultimate Home Inspection Checklist for Buyers
The Ultimate Home Inspection Checklist: 15 Key Areas to Review A home inspection checklist refers to a structured guide used to assess the condition of a property, focusing on its structural inte...
Available in Your Area
MyCareAudit supports care providers across England. See how we help in these regions:

Sheref Ergun
Founder & Independent Health and Social Care Advisor at MyCareAudit. 20+ years in CQC, Ofsted, and NRSA compliance.
View full profile →CQC & Ofsted regulatory updates
Providers using MyCareAudit
Ready to Simplify Your Compliance?
Take a 2-minute audit readiness check — free, instant results, no commitment.
