Domiciliary

How to Create a Domiciliary Care Risk Register

Sheref Ergun25 September 2026Last updated: 25 September 2026
How to Create a Domiciliary Care Risk Register

Key Takeaways

  • The Real Compliance Risk
  • What Inspectors Often Find
  • Common Evidence Gaps
  • How to Self-Audit This Area
  • Conclusion

How to Create a Domiciliary Care Risk Register: A Step-by-Step Guide

A risk register in domiciliary care is a structured document that identifies, assesses, and monitors risks across your service. It provides a centralised view of potential hazards—such as missed medication visits, lone worker safety, or safeguarding breaches—and outlines the controls in place to mitigate them. Inspectors may review your risk register to assess compliance with Regulation 12 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, which focuses on safe care and treatment.

In practice, failing to maintain a robust risk register may lead to compliance concerns. For example, if an incident occurs—such as a missed care call leading to harm—and your risk register doesn’t evidence proactive measures to reduce this risk, this could raise questions about your service’s governance framework under Regulation 17 (Good Governance). Poorly maintained or incomplete risk registers are often a challenge for providers. This article will give you a step-by-step guide to creating a risk register that not only meets regulatory requirements but also provides tangible operational value for your team.


The Real Compliance Risk

The primary compliance risk in domiciliary care when it comes to risk registers is failing to evidence a comprehensive and dynamic approach to risk management, as required under Regulation 17 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014. Inspectors look for documented systems that not only identify client-specific and operational risks but also demonstrate how these risks are regularly reviewed, mitigated, and communicated across the service. Without this, providers are at significant risk of a breach for poor governance.

In our audits, we consistently see providers stumble on the “dynamic” aspect of risk management. For example, a care service might have a risk register that lists generic hazards like “slips and trips” or “medication errors,” but fails to update it when a new client with complex needs is taken on. If a client with dementia is prone to wandering, inspectors expect to see this risk assessed, added to the register, and cross-referenced with care plans and staff training records. Anything less creates an evidence gap that inspectors will flag under Key Question 2: “Is your service safe?”

The evidence trail inspectors follow starts with the governance framework. They’ll examine whether your risk register links directly to incident reports, audits, and staff meetings. A common failure point is when services treat the risk register as a static document rather than a living, breathing tool. For instance, if there’s an incident involving a missed medication dose, the root cause analysis should feed into the risk register to prevent recurrence. If not, this could raise concerns about your ability to learn from adverse events, which may impact your compliance status.

Another red flag we often encounter is poor alignment between the risk register and staff awareness. In one case, a provider had a well-documented risk of lone working in the register but failed to provide staff with practical guidance or training on managing this risk. When inspectors interviewed staff, they found inconsistent knowledge of the safety protocols, leading to concerns under Regulation 18 (staffing and training). This underscores the importance of not just creating a robust risk register but ensuring its contents are operationalised and understood by the entire team.


What Inspectors Often Find

CQC inspectors reviewing domiciliary care risk registers most commonly find incomplete or outdated entries, a lack of evidence linking risks to care plans, and a failure to review or update risks after significant incidents. Other frequent issues include unsigned governance audits, supervision records lacking follow-up actions, and gaps in medication administration records (MAR charts) where signatures or timings are missing. These gaps may indicate weak oversight and a poor governance framework, which could raise concerns under Regulation 17.

Inspectors will typically find that risk registers fail to capture dynamic risks linked to changes in service users' needs. For example, if a service user has experienced a fall or been discharged from hospital, the risk register should reflect this with updated entries detailing new or revised control measures. Outdated risk registers where such incidents haven’t been documented can lead to questions about how the service is actively managing risks. The evidence trail here starts with the incident log—if it mentions a fall but the risk register hasn’t been updated, you’ve got a clear governance failure.

Another common failure point is unsigned governance audits. For example, a service may have conducted a health and safety audit, but the document is missing the manager’s signature or a date. This raises immediate red flags about whether the audit was completed thoroughly or acted upon. A typical scenario is where a fire risk assessment has been created but not signed off, leaving inspectors wondering whether any identified actions were implemented. If you’re relying on these audits as evidence of compliance, missing signatures will undermine your credibility.

Supervision records are another area where inspectors often spot issues. A common pattern is that supervision meetings are documented, but there’s no evidence of follow-up actions being completed. For instance, if a care worker’s supervision highlighted the need for additional medication training, inspectors will expect to see a corresponding training record or competency assessment. Without this, it appears the service isn’t taking staff development or safe care delivery seriously, which can quickly escalate concerns under Key Question 2: "Is care safe?"

Check Your Inspection Readiness

Free 2-minute assessment — instant results tailored to your service type.

Perhaps the most glaring oversight inspectors encounter involves MAR charts. Gaps in signatures for administered medication or missing timings are red flags that can lead to serious questions about whether service users are receiving their prescribed medicines. For example, in one service we audited, a MAR chart for a service user on time-critical insulin lacked signatures for two consecutive doses. When questioned, the manager could not provide an incident report or evidence of follow-up actions, leading to significant concerns about the overall safety of the service.

If you recognise any of these issues in your service, address them immediately. Start by cross-referencing your risk register with recent incident logs, ensure all audits are signed and dated, and implement a robust system to track supervision follow-ups and medication administration. These practical steps can help close the evidence gaps inspectors are most likely to find.


Common Evidence Gaps

The most common evidence gaps in domiciliary care risk registers include incomplete risk assessments, missing review dates, lack of evidence showing staff awareness of individual risks, inconsistencies between care plans and risk registers, and an absence of clear mitigation measures. Inspectors will also flag when there’s no documented audit trail of how risks are identified, monitored, and updated over time.

A frequent failure point we see during audits is incomplete or generic risk assessments. For example, a risk register might list "falls risk" for a service user, but when the inspector asks to see the corresponding risk assessment, it’s either missing or lacks detail. A robust risk register should clearly link to a detailed, up-to-date risk assessment that specifies the risk level, control measures, and the person responsible for implementation. Without this, inspectors are left questioning how risks are being managed in practice.

Another common issue is outdated or missing review dates. In some services, we’ve seen risk registers that haven’t been updated for months, even when there has been a significant change in a service user’s needs—such as a hospital discharge after a fall. Inspectors will look for evidence that risks are being reviewed regularly, typically every month or following any significant incident. If the review dates are blank or the updates are superficial, it raises serious concerns about the provider’s governance and oversight.

In practice, we often find that the risk register doesn’t align with individual care plans. For instance, a care plan might highlight a service user’s severe allergies, but this information is absent from the risk register. This disjointed documentation creates a clear evidence gap that inspectors will pick up on. They’ll ask how care workers are expected to manage risks if critical information isn’t consistently recorded across all relevant documents.

Finally, a major red flag is the absence of evidence showing staff engagement with the risk register. For example, inspectors might request training records or team meeting minutes to verify that staff are aware of the risks listed and understand their role in managing them. If these records cannot be produced or show no mention of the risk register, this may indicate a breakdown in communication and training, potentially raising concerns under Regulation 17.


How to Self-Audit This Area

To self-audit your domiciliary care risk register, start by pulling the current version of the register and cross-checking it against your service’s key risks, as identified in care plans, incident reports, and staff feedback. Ensure each risk is accurately described, rated for severity and likelihood, and linked to clear mitigation actions. Pay particular attention to whether high-risk areas, such as lone working or medication errors, are consistently monitored and reviewed.

Begin by reviewing the last three months of incident reports and complaints. Look for patterns — are there recurring issues, such as missed visits, medication discrepancies, or safeguarding concerns? For instance, if three missed visits are recorded in the last month, but no corresponding risk entry exists, this is a red flag. Update the risk register to include these issues, categorising them under operational risks, and assign them appropriate mitigation strategies, such as changes in scheduling processes or additional staff training.

Next, audit your care plans for individual service users, focusing on those with complex needs or recent changes in their health or circumstances. For example, if a service user has recently been discharged from hospital with a new mobility issue, but there is no corresponding entry in the risk register around falls or manual handling, you’ve identified a gap. Add this to the register, ensuring it’s cross-referenced with staff training records to confirm that carers are competent to manage the new risk.

Then, check your staff files for training and competency records, particularly around high-risk activities like administering medication, moving and handling, or lone working. If you find that a staff member is overdue for refresher training, this should be reflected in the risk register under workforce risks, with a clear plan for action. For example, you might need to schedule immediate refresher sessions and implement short-term supervision until training is completed.

Finally, schedule a governance review meeting with your senior team to validate the updated risk register. Bring along your last three months of audit reports, complaints logs, and any feedback from service users or staff. Use this session to challenge each other on whether the listed risks are up to date, whether the mitigations are realistic and actionable, and whether there’s an effective system in place to monitor and review these risks regularly. Document the outcomes of this discussion, and ensure the updated risk register is circulated to all relevant staff.


Conclusion

If you take ONE thing from this post, let it be this: a well-maintained risk register isn’t just a compliance tick-box—it’s your front-line defence against regulatory breaches and operational chaos. By systematically identifying, assessing, and managing risks, you’re not only safeguarding your service users and staff but also demonstrating to inspectors that your governance framework is robust and proactive. Inspectors will look for evidence that your risk assessments are dynamic, regularly reviewed, and directly influence your day-to-day operations. If your risk register is a stagnant document collecting dust, you’ve already lost the argument.

A strong risk register can play a key role in improving a service’s compliance outcomes. Our compliance templates are designed to help you track, update, and evidence risks with precision, ensuring you’re always one step ahead of inspections. Don’t wait for an inspector to point out what’s missing—run a self-audit today and close those evidence gaps before they become a problem. It’s the difference between firefighting and leading with confidence.


Run Your Own Compliance Check

Use our free Audit Checklist Generator to instantly create a tailored compliance checklist for your service. It takes under two minutes and covers all key regulatory areas.

Generate Your Free Checklist →


Need Help Passing Your Next Inspection?

MyCareAudit offers expert-led support to help you prepare with confidence:

Speak to our compliance team today.


Further Reading

Explore more compliance guides and inspection preparation resources in our CQC Domiciliary Care Compliance hub.


Frequently Asked Questions

Q: How often should I audit this area?
A: Best practice is to conduct focused audits monthly, with a comprehensive review at least quarterly.

Q: What evidence will inspectors look for?
A: Inspectors typically request documented policies, completed audit trails, staff training records, and evidence of continuous improvement.

Q: Can I use MyCareAudit to prepare?
A: Yes — our free audit tool and checklist generator are designed specifically for UK care providers preparing for inspection.

Available in Your Area

MyCareAudit supports care providers across England. See how we help in these regions:

Sheref Ergun

Sheref Ergun

Founder & Independent Health and Social Care Advisor at MyCareAudit. 20+ years in CQC, Ofsted, and NRSA compliance.

View full profile →

CQC & Ofsted regulatory updates

Providers using MyCareAudit

Palm 2 Palm Care— Domiciliary Care & Supported Living, London & SouthendCQC Good
Jothno Care and Support— Domiciliary Care & Supported Living, LondonCQC Good
Nari Care Services Ltd— Domiciliary Care, London
Palmerston Care Home— Residential Care, Southend

Ready to Simplify Your Compliance?

Take a 2-minute audit readiness check — free, instant results, no commitment.