CQC record keeping requirements.
Every registered provider knows records matter. Rather fewer can say which regulation requires them, what standard they are held to, or how long they have to be kept. This is a plain summary of what Regulation 17 asks for, which records are in scope, how inspectors assess them now that the key lines of enquiry have gone, and the part of the record that tends to be missing.
The regulation that requires it
Record keeping for providers registered with the Care Quality Commission sits in Regulation 17 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, headed Good governance. It is one of the fundamental standards, the level of care below which no provider may fall, and it is not a records regulation as such: it requires effective governance, including systems and processes that assess, monitor and improve the quality and safety of the service. Records are one of the things it names as part of that.
The wording that matters is in Regulation 17(2). A care provider must securely maintain an accurate, complete and contemporaneous record in respect of each service user, which is the regulation's own term for a person using the service, including a record of the care and treatment provided and of the decisions taken about it. It must also securely maintain such other records as are necessary in relation to persons employed and to the management of the regulated activity.
Regulation 17(1) requires systems and processes to be established and operated effectively. Regulation 17(2) then says what those systems and processes must enable the provider to do, and records are only two of the six limbs:
- Assess, monitor and improve the quality and safety of care provided, including the quality of the experience of people using the service
- Assess, monitor and mitigate the risks relating to the health, safety and welfare of service users and others. Providers must assess the risks arising from the regulated activity itself, not only from individual care
- Maintain securely an accurate, complete and contemporaneous record for each service user, covering the care and treatment provided and the decisions taken about it
- Maintain securely such other records as are necessary about staff and about the management of the regulated activity
- Seek and act on feedback from people using the service, those acting on their behalf, and staff, for the purpose of continually evaluating and improving the service
- Evaluate and improve the provider's own practice in handling all of the above
Reading them together explains why inspectors treat records as evidence about the whole service. A provider must have effective governance arrangements, and the record is what shows the governance happened. CQC's own guidance puts it plainly: providers must securely maintain accurate, complete and detailed records, and where a provider cannot produce them the assumption is not that the care was undocumented but that it was unmanaged.
The stated purpose of the regulation is the welfare of people using services and their safety. That framing explains the rest of it: the same regulation requires providers to assess and mitigate risks, to seek and act on feedback, and to maintain the policies and procedures and auditing systems that make the whole thing work. Two consequences follow. A tidy set of care plans does not satisfy Regulation 17 on its own, because the systems that check and act on those records are equally in scope. And failures of record keeping are read as evidence about the quality of the whole service rather than as an administrative slip.
It is also worth knowing what CQC can do about a breach. CQC can prosecute directly for some regulations, notably those on safe care and treatment and on the duty of candour, but not for this one: CQC cannot prosecute a provider for a breach of Regulation 17 alone. It can take regulatory action, which in escalating order means a requirement notice, a warning notice, conditions on registration, suspension and ultimately cancellation, and a breach will usually show in the service's CQC rating. At the registration stage the position is firmer still: CQC must refuse registration if providers cannot satisfy it that they can and will continue to comply with this regulation.
Which records you have to keep
The regulation splits records into two families, and providers usually attend to the first far more carefully than the second.
Records about each person using the service. Assessments, the care plan and its reviews, consent and mental capacity decisions, risk assessments, daily notes, medicines administration, incidents and accidents affecting them, and the decisions taken about their care with the reasons for them.
Records about staff and about the running of the service. Recruitment and the checks required by Schedule 3, induction, training and competence, supervision and appraisal, rotas and deployment, complaints and their outcomes, safeguarding referrals, audits and the actions arising from them, and the governance information the registered manager and provider use to run the service.
- Records about premises and equipment, including maintenance and safety checks, which sit alongside care records rather than inside them
- Notifications you are required to send CQC, and what prompted each one
- Duty of candour records under Regulation 20, including what was said to the person and when
- Complaints, from first contact through to outcome, not only the ones that were escalated
- Audits, with the action taken and evidence that it was taken, rather than the audit alone
- Board or provider level oversight: what was reported upwards, and what was decided
The second family is where most social care providers are thinner, because those records are generated by managers under pressure rather than by a care system with mandatory fields that will not let a shift be closed until they are complete.
What accurate, complete and contemporaneous means
The three words in the regulation each carry weight, and inspectors read them separately.
Accurate means it reflects what actually happened, in language specific enough to be useful. Entries that could describe any person on any day are the commonest finding: had a good day, ate well, no concerns tells an inspector nothing about that person and cannot support a decision later.
Complete means the record covers the whole of the care provided, including the parts that went wrong, the times a person declined, and the decisions taken not to do something. A record with no refusals, no incidents and no disagreements in it is usually incomplete rather than exemplary.
Contemporaneous means written at or near the time. This is the one that most often fails under scrutiny, because a record written up at the end of a shift or the following morning is both less accurate and visibly so. Where a system stamps its own times, the gap between the event and the entry is part of the evidence.
Securely maintained is the fourth requirement and is easy to overlook. It covers access control, protection against loss and unauthorised alteration, and knowing where the record is. A record held only on a member of staff's own device is not securely maintained, whatever its quality.
Digital records, and what CQC looks for in them
CQC does not require digital records and does not favour any product. Its published position is that what matters is whether records are accessible to the people who need them, accurate, secure and used, whatever form they take. Adult social care providers moving from paper have had national support to do it through the Digitising Social Care programme, run with the Department of Health and Social Care, which assures suppliers of digital social care record systems against a common standard.
Where a service has gone digital, CQC's own material on good digital social care records is the clearest statement of best practice: records available at the point of care, entries attributable to a named person, an audit trail of changes, and information that can be shared safely with the people who need it, including the person themselves and other services involved in their care. CQC frames the question as whether digital record systems are achieving good outcomes for people using the service, not whether the record system is modern.
Electronic records bring one advantage that paper cannot match and one risk that paper does not carry. The advantage is that the same record can be at the point of care and in the office at once, which is what makes person-centred care visible to the people managing quality of care rather than only to the person delivering it. The risk is that an electronic record can be changed silently.
The audit trail is the point that distinguishes a digital record from a typed one. If a record can be altered without trace, its evidential value collapses at exactly the moment it matters. A system that shows who wrote what and when, and preserves what an entry said before it was amended, is doing something a paper file cannot.
Digital does not remove the second family of records described above. Care planning systems capture care; they rarely capture the conversation between a support worker and a manager at nine in the evening about whether to call the GP.
How long records must be kept
CQC does not publish its own retention schedule. The reference point for health and adult social care in England is the Records Management Code of Practice 2021, published by NHS England, which sets retention periods that CQC and commissioners both recognise.
The headline periods to plan around are that adult social care records are generally retained for eight years after the last entry or after the person's death, and that records relating to a child or young person are retained until their twenty fifth birthday, or their twenty sixth where the person was seventeen when the record concluded. Staff records have their own periods, and some, such as those relating to certain hazardous exposures, run for decades.
Two practical points sit underneath those numbers. Retention is a maximum as well as a minimum: keeping everything indefinitely is a data protection failure, not a safe default, and UK GDPR's storage limitation principle applies to care records like any other. And a retention period is only meaningful if something actually deletes at the end of it, which is a question about systems rather than about policy.
If you are writing this down for the first time, do it as a retention schedule that names the record type, the period, the trigger that starts the clock and who is responsible, rather than as a paragraph in a policy.
How this is assessed now the KLOEs have gone
The key lines of enquiry were retired with the introduction of CQC's single assessment framework. The five key questions remain, safe, effective, caring, responsive and well-led, but underneath them sit quality statements written as commitments in the first person, and evidence categories that describe where the assurance comes from.
For record keeping this changes the shape of the conversation rather than the standard. Inspectors are looking for evidence across categories: what people using the service and their families say, what staff and leaders say, observation, and the processes themselves. Records appear in the processes category, but they are also the thing that corroborates or contradicts the other three.
The practical test has not changed. An inspector asks about a specific event, on a specific date, and asks to see the record of it. What follows is either a record produced in a few minutes, or an explanation. Services rarely fail this because the care was poor. They fail it because the evidence of good care was scattered, informal, or on someone's phone. Providers are expected to work to current legislation and guidance, and that includes the health and safety records that sit alongside care records rather than inside them.
Across health and care organisations the underlying question is the same one: can this service show that the care it provides is safe, effective and personalised. Records are how a provider evidences personalised care to someone who was not there.
The well-led question is where record keeping most often surfaces, because it asks whether leaders have the information they need to run the service. A manager who cannot show what was escalated to them, and when, is answering that question badly regardless of how good the care plans are.
The part of the record that is usually missing
Care planning systems capture care. They do not capture the conversations that surround it, and those conversations are increasingly where decisions are actually made.
A support worker messages the manager at eleven at night about a resident who has fallen. A staff group chat carries the handover that the written handover summarises. A family member sends a concern by text because that is how they have always contacted the home. A manager approves something over the phone and it reaches the file, if it reaches the file, as a line written afterwards by someone else.
Each of those is a record within the meaning of Regulation 17, because each shows care provided or a decision taken about it. Almost none of them is securely maintained. They sit on personal phones, on both sides, belonging to people who may since have left, and they are the first thing anyone asks for when something is investigated.
The asymmetry matters. Duty of candour under Regulation 20 requires a record of what was said to the person and when. A safeguarding investigation asks when the concern was first raised. A coroner asks who knew what. In each case a family or a member of staff can usually produce their own messages, and a service that cannot produce its side is not neutral in that exchange, it is silent.
It is worth asking, at your next governance meeting, where the first report of a concern in your service lands, and whether you could produce it tomorrow.
Where to read the official guidance
CQC's guidance on Regulation 17 is the primary source and is short enough to read in full. Its material on good digital social care records is the clearest statement of what inspectors expect from a digital system. For retention, use the Records Management Code of Practice 2021, and for practical implementation the Digital Care Hub publishes sector guidance for providers.
Regulation 17 also expects providers to work to nationally recognised guidance where it exists, so the relevant practice guidance for your service type sits alongside the regulation rather than beneath it. For adult social care services that includes NICE guidance and the sector's own codes; for services delivering health care it includes the professional codes of practice for health and care staff.
This page is a summary rather than advice on your service. Registration and enforcement decisions turn on their own facts; take proper advice on a live one.
ComplyChat gives the conversations in section 07 a channel your organisation owns, on the record from the first message. Once your Microsoft 365 tenant is connected, the lasting record files there under your own retention rules, so the messages that show what was escalated and when sit alongside the care record rather than on someone's phone. We wrote this guide because that gap is the one providers most often discover during an investigation.
How it works · Why us · Pricing · FAQ