
Key Takeaways
- The Real Compliance Risk
- What Inspectors Often Find
- Common Evidence Gaps
- How to Self-Audit This Area
- Conclusion
How to Conduct a Regulation 17 Audit That Stands Up to CQC Scrutiny
A Regulation 17 audit refers to the systematic review of a care service’s governance, quality assurance processes, and evidence trails to ensure compliance with the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014. Specifically, Regulation 17 focuses on “Good Governance” and requires providers to maintain robust systems to assess, monitor, and improve the quality and safety of their services. Without clear, documented evidence of these systems, services risk failing inspections and breaching this fundamental regulation.
In practice, a Regulation 17 audit is not just a tick-box exercise; it’s your first line of defence against a Requires Improvement or even Inadequate rating. Inspectors will typically dive into how you monitor incidents, complaints, and staff performance—and, crucially, whether you've acted on those findings. For example, in our audits at MyCareAudit, we consistently see services stumble when they lack a robust audit trail linking action plans to measurable outcomes. If your service isn’t regularly auditing care plans, reviewing key policies, or tracking the effectiveness of training, you’re leaving yourself open to scrutiny. This article will guide you through conducting a Regulation 17 audit that not only ticks the compliance boxes but also strengthens your operational resilience.
The Real Compliance Risk
The primary compliance risk in Regulation 17 audits lies in failing to maintain a robust governance framework that consistently assesses, monitors, and improves the quality and safety of care. This often manifests as insufficient or poorly documented evidence of audits, action plans, and follow-ups, leaving services unable to demonstrate continuous improvement or compliance with the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, specifically Regulation 17.
In our audits at MyCareAudit, we consistently see providers falling short in areas such as incomplete or outdated quality assurance records. For example, a care home might have a medication audit template but fail to complete it for months, leaving no documented evidence of how medication errors are being identified and addressed. When CQC inspectors review these gaps, it signals a lack of oversight and poor governance, which can quickly lead to a “Requires Improvement” or “Inadequate” rating. The evidence trail inspectors follow usually begins with your latest internal audits and corresponding action plans. If these are missing—or worse, exist but show no follow-up—you’re immediately on the back foot.
Another potential failure point is the absence of a clear link between risk assessments and service improvement plans. For instance, recurring issues noted in complaints logs may not always be adequately addressed in quality improvement plans. Inspectors will want to see how you’ve identified risks, what actions you’ve taken to mitigate them, and the measurable outcomes of those actions. Without this, you may face challenges in demonstrating compliance with Regulation 17. Always ensure that your governance documents are not just “filed” but actively reviewed, updated, and actioned.
What Inspectors Often Find
CQC inspectors may identify issues such as gaps in Medication Administration Records (MAR), missing signatures on governance audits, or incomplete supervision records without documented follow-up actions. These issues may indicate weak oversight and poor quality assurance systems, potentially impacting the service's compliance status. Inspectors will flag these as breaches of the provider's duty to maintain accurate, complete, and contemporaneous records under Regulation 17(2)(c).
A potential failure point is incomplete MAR charts—often with missed signatures, unexplained time gaps, or no recorded reason for non-administration. If MAR charts are not cross-checked daily by senior staff, these gaps may slip through unnoticed, raising concerns about governance and compliance with Regulation 12 (safe care and treatment).
Unsigned governance audits are another red flag. Inspectors may find audits—such as infection control checks, care plan reviews, or health and safety inspections—that are either incomplete or missing evidence of managerial oversight. This can lead inspectors to question whether actions identified in the audits were ever implemented, creating a clear evidence gap.
Supervision records are also a frequent problem area. In practice, services often keep basic records of supervision meetings but fail to document agreed actions or follow-up dates. A pattern of generic supervision templates with no evidence of meaningful discussions around staff performance or training needs may raise concerns about governance and oversight. For example, if staff flag concerns about manual handling practices during supervisions, but there is no evidence of training being arranged or risk assessments updated, this could indicate a lack of follow-through on identified issues.
Finally, inspectors will scrutinise care plans and incident logs for evidence of timely updates and escalation. A typical issue during audits is care plans that haven’t been updated after a fall or hospital admission. For instance, if a resident has been hospitalised after a fall, but their care plan still describes them as "independent with mobility" weeks later, this disconnect between events and documentation may undermine the credibility of the service's governance framework and could lead to regulatory scrutiny.
Check Your Inspection Readiness
Free 2-minute assessment — instant results tailored to your service type.
Common Evidence Gaps
The most common evidence gaps in Regulation 17 audits include missing or incomplete supervision records, care plans that lack regular review dates, unsigned risk assessments, incident logs without clear safeguarding escalation evidence, and outdated staff training matrices. These gaps may indicate weak governance and poor oversight, potentially impacting the service's compliance under the "Well-Led" key question.
In our audits, we consistently see supervision records that are either missing altogether or lack critical details such as dates, signatures, or evidence of follow-up actions. For example, an inspector might request a sample of supervision records for a specific staff member and find that the last recorded session was over a year ago, despite the provider's policy stating these should occur quarterly. This immediately raises questions about how well staff performance and well-being are being monitored and supported.
Another frequent failure point is outdated or incomplete care plans. Inspectors will typically find care plans that have not been reviewed within the required timeframes or lack evidence of involvement from the service user or their family. For instance, a care plan might specify the need for fortnightly weight monitoring for a resident at risk of malnutrition, but the associated records are either blank or show no entries for months. This suggests a systemic failure in monitoring and responding to individual care needs.
Incident logs are another area where evidence gaps are often glaring. In practice, services often omit key details, such as whether an incident was escalated to safeguarding or if any lessons were learned and actions taken to prevent recurrence. A common example is an incident form describing a fall but missing documentation of whether a body map was completed, a GP was informed, or the risk assessment was updated. Inspectors will cross-reference these logs with safeguarding referrals to identify inconsistencies, and any discrepancies can severely undermine your governance framework.
Finally, training matrices frequently fail to provide a clear picture of compliance. A typical issue is that the matrix may show staff as "trained," but the actual certificates are either missing or expired. For example, inspectors may request to see evidence of medication competency assessments for staff administering medicines and discover that these are overdue or absent entirely. This not only breaches Regulation 12 (Safe Care and Treatment) but also highlights a governance failure under Regulation 17, as it shows a lack of oversight in ensuring staff are competent and up to date with critical training.
These evidence gaps are red flags that signal poor record-keeping and oversight, and they directly impact your ability to demonstrate compliance with Regulation 17. Addressing these issues should be a priority in your audit process, as they are often the starting point for inspectors when assessing governance and leadership in your service.
How to Self-Audit This Area
To self-audit Regulation 17 compliance, start by reviewing your governance framework to ensure it includes robust quality assurance processes and a clear evidence trail. Focus on key areas such as audits, policies, risk assessments, and incident reporting. Cross-check documented actions against outcomes to confirm they address identified risks. Inspectors will scrutinise whether your systems are effective and continuously improving, so prioritise evidence of learning and changes made as a result of audits or incidents.
Begin with your audit schedule. Pull out your last three months of internal audits—whether for medication, care plans, infection control, or staff supervision. Check if these audits were completed on time, action plans were created, and follow-ups were documented. For instance, if an infection control audit flagged a lack of hand hygiene posters, can you show they were put up and that staff were reminded in a team meeting? Inspectors will look for this closed-loop process.
Next, review your incident and accident log. Inspectors will typically follow the evidence trail from an incident to see how it was reported, investigated, and resolved. Pick three incidents at random—check if investigations were timely, outcomes recorded, and lessons shared with staff. For example, if a fall occurred, was the risk assessment updated? Was additional training provided to staff? If there’s no evidence of these steps, you’re leaving yourself open to criticism.
Don’t overlook your governance meeting minutes. Schedule a 30-minute review this week and pull your last three sets of minutes. Inspectors often find that meetings lack depth or fail to cover key areas like complaints, safeguarding alerts, or audit findings. Confirm that each meeting has clear actions, deadlines, and responsible persons. For example, if a safeguarding concern was raised, is there evidence of follow-up actions being monitored in subsequent meetings?
Finally, check your staff supervision and training records. In practice, services often fall down here when supervision records don’t align with appraisals or training logs. Randomly select five staff files and verify that supervision notes include discussions on performance, training needs, and any concerns raised. If training gaps were identified, can you evidence that relevant training was completed? This is a potential failure point that inspectors may identify during Regulation 17 reviews.
Conclusion
If you take ONE thing from this post, let it be this: a Regulation 17 audit is only as strong as the evidence you can produce — and how well that evidence aligns with your governance framework. It’s not just about having policies or processes on paper; it’s about demonstrating how they’re actively implemented, monitored, and improved. From tracking incident trends to ensuring supervision records are up to date, the devil is always in the detail. Inspectors will scrutinise the consistency of your quality assurance processes, so don’t wait until the notification of inspection to start filling gaps.
A proactive, structured approach to compliance can help services prepare more effectively and reduce inspection-related stress. Our compliance templates and evidence-tracking tools are designed to help you identify and close those gaps before an inspector does. Don’t leave your CQC rating to chance — take control of your Regulation 17 obligations today with MyCareAudit.
Run Your Own Compliance Check
Use our free Audit Checklist Generator to instantly create a tailored compliance checklist for your service. It takes under two minutes and covers all key regulatory areas.
Generate Your Free Checklist →
Need Help Passing Your Next Inspection?
MyCareAudit offers expert-led support to help you prepare with confidence:
- Book a Mock Inspection — a realistic, no-risk rehearsal with detailed feedback
- Get CQC Registration Support — end-to-end guidance through the application process
Speak to our compliance team today.
Further Reading
Explore more compliance guides and inspection preparation resources in our CQC Domiciliary Care Compliance hub.
Frequently Asked Questions
Q: How often should I audit this area?
A: Best practice is to conduct focused audits monthly, with a comprehensive review at least quarterly.
Q: What evidence will inspectors look for?
A: Inspectors typically request documented policies, completed audit trails, staff training records, and evidence of continuous improvement.
Q: Can I use MyCareAudit to prepare?
A: Yes — our free audit tool and checklist generator are designed specifically for UK care providers preparing for inspection.
Related Articles

Care Governance Dashboard Templates for UK Providers
Care Governance Dashboard Templates for UK Care Providers Care governance dashboard templates are structured tools designed to help UK care providers monitor compliance, performance, and quality...

7 Essentials for Your CQC Risk Register
7 Essentials Every CQC Risk Register Must Include A CQC risk register is a critical governance tool that identifies, evaluates, and monitors risks to the safety, quality, and regulatory complianc...

Care Compliance Audit Checklist: 10 Key Areas to Review
The Ultimate Care Compliance Audit Checklist: 10 Essential Areas to Review A care compliance audit checklist refers to a structured tool used by UK care providers to ensure their services meet regu...
Available in Your Area
MyCareAudit supports care providers across England. See how we help in these regions:

Sheref Ergun
Founder & Independent Health and Social Care Advisor at MyCareAudit. 20+ years in CQC, Ofsted, and NRSA compliance.
View full profile →CQC & Ofsted regulatory updates
Providers using MyCareAudit
Ready to Simplify Your Compliance?
Take a 2-minute audit readiness check — free, instant results, no commitment.
