ComplyChat Start free

Guide · Care and CQC

Regulation 17: good governance

Regulation 17 is the fundamental standard that asks whether a provider knows what is happening in its own service and does something about it. It is usually read as the record-keeping regulation, and records are part of it, but most of it is about systems: audit, risk, feedback, and the oversight of whoever runs the provider, whether that is a sole owner, a company board or a charity's trustees. This guide takes the regulation limb by limb, then covers audit that actually changes things, what board or provider oversight should look like, and how CQC assesses governance under the single assessment framework.

By ComplyChatPublished 12 minute read

Three trustees of a care charity walk the garden path of one of its care homes with the registered manager on a breezy spring afternoon, one pointing towards a newly built extension
01

The regulation, in full

Regulation 17 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 is headed Good governance. Regulation 17(1) is one sentence: "Systems or processes must be established and operated effectively to ensure compliance with the requirements in this Part." The Part is Part 3, Regulations 4 to 20A: the requirements on who runs the service and the fundamental standards, so Regulation 17 is the regulation that checks the others are being met. Regulation 17(2) then says that, "without limiting paragraph (1)", those systems or processes must enable the registered person, in particular, to:

  1. "assess, monitor and improve the quality and safety of the services provided in the carrying on of the regulated activity (including the quality of the experience of service users in receiving those services)"
  2. "assess, monitor and mitigate the risks relating to the health, safety and welfare of service users and others who may be at risk which arise from the carrying on of the regulated activity"
  3. "maintain securely an accurate, complete and contemporaneous record in respect of each service user", including the care and treatment provided and decisions taken about it
  4. "maintain securely such other records as are necessary to be kept" about persons employed and the management of the regulated activity
  5. "seek and act on feedback from relevant persons and other persons on the services provided", for the purposes of continually evaluating and improving them
  6. "evaluate and improve their practice in respect of the processing of the information referred to in sub-paragraphs (a) to (e)"

Regulation 17(3) adds a duty to report. When CQC asks, the registered person must send it, "by no later than 28 days beginning on the day after receipt of the request", a written report on how, and how far, limbs (a) and (b) are being complied with, and any plans for improving the standard of the service. CQC's guidance says this "could include a request for an action plan or a Provider Information Return for adult social care services".

The Care Quality Commission's guidance on Regulation 17 states the intention plainly: "providers must have effective governance, including assurance and auditing systems or processes" that "assess, monitor and drive improvement in the quality and safety of the services provided" and "mitigate any risks relating [to] the health, safety and welfare of people using services and others", and "providers must continually evaluate and seek to improve their governance and auditing practice". On enforcement, CQC "can prosecute for a breach of part of this regulation (17(3)) if a provider fails to submit such a report when requested", and can move directly to prosecution for that part; for the other parts it takes regulatory action. It "must refuse registration if providers cannot satisfy us that they can and will continue to comply with this regulation".

Limbs (c) and (d), the records, are covered in our CQC record-keeping guide. This guide is about the rest: the systems that turn records into knowledge and knowledge into change.

02

What each limb asks of you in practice

CQC's guidance is the statement of what providers "must have regard to" for each limb, and it is more specific than the regulation.

Quality, limb (a). The guidance on 17(1) sets the frame: providers must assess and monitor their service against Regulations 4 to 20A, and "the system must include scrutiny and overall responsibility at board level or equivalent". The guidance on 17(2)(a) says providers must have "systems and processes such as regular audits", that audits "should be baselined against Regulations 4 to 20A" and should, where possible, include the experiences of people who use the service. Systems must be fit for purpose, which means they "enable the provider to identify where quality and/or safety are being compromised and to respond appropriately and without delay". Information must be "up to date, accurate and properly analysed and reviewed by people with the appropriate skills and competence to understand its significance", escalated when required, and the results shared with the people who need to know. Providers must seek expert advice without delay, monitor progress against improvement plans, and share relevant information about incidents or risks with bodies including "safeguarding boards, coroners, and regulators".

Risk, limb (b). Providers must be able to identify and assess risks to health, safety and welfare, and where risks are found, "introduce measures to reduce or remove the risks within a timescale that reflects the level of risk and impact on people using the service". Risks must be escalated inside the organisation or to an external body as appropriate, and kept under review, with action "where a risk has increased". The "others" who may be at risk include "staff, visitors, tradespeople or students", which brings health and safety, fire and premises risk inside the regulation.

Records, limbs (c) and (d). Care records fit for purpose, and the other records the service needs about staff and about management, which CQC's guidance says "may include governance arrangements such as policies and procedures, service and maintenance records, audits and reviews, purchasing, action plans in response to risk and incidents". Both must meet the Data Protection Act 2018.

Feedback, limb (e). "All feedback should be listened to, recorded and responded to as appropriate", whether it is formal or informal, written or verbal, and from people using the service, their representatives, staff or others. It should be analysed and used to drive improvement, and the provider "should have systems in place to communicate how feedback has led to improvements". Where relevant, providers should also seek the views of external bodies such as fire and environmental health.

Improving governance itself, limb (f). "Providers must ensure that their audit and governance systems remain effective." A governance system that has not changed in five years, while the service has, is a finding waiting to happen.

03

Audit that changes something

Almost every provider audits. The question Regulation 17 asks is whether the audits find what is there and whether anything happens next. CQC's wording, "assess, monitor and drive improvement", describes a cycle, and each stage leaves evidence:

  1. A programme. What is audited, how often, by whom, and against which standard, covering the fundamental standards rather than only the areas that are easy to count. For a care home that usually means care plans and risk assessments, medicines, infection prevention, falls and incidents, safeguarding, complaints, staffing and training, recruitment files, premises and equipment, and notifications to CQC.
  2. A finding. Specific, dated and signed. An audit that has found nothing for twelve months is more often a weak audit than a perfect service.
  3. An action. Named owner, deadline, and what done will look like.
  4. A check. The action closed with evidence, and a re-audit showing whether it worked.
  5. A pattern. Someone above the auditor reading across audits, incidents, complaints and feedback, and asking what they say together.

The two commonest weaknesses are easy to recognise. The first is an audit that measures whether something was written, not whether it was right: every care plan reviewed monthly, none of them changed after a fall. The second is the action plan that grows, with the same items carried forward month after month and no one above the manager noticing. Both show up the moment an inspector asks to see the last three audits and the actions that came out of them.

Audit also has to be independent enough to be believed. A manager auditing her own service is necessary; it is not sufficient. The provider's own quality visits, a peer audit from another service, or an external review of medicines or infection control give the board something the manager's audit cannot, and the regulation's requirement to evaluate and improve the governance itself is the reason to build them in.

04

Provider and board oversight

Regulation 17 binds the registered person, which means the provider as well as the registered manager, and CQC's guidance puts the top of the system at "board level or equivalent". Who that is depends on the provider. For a sole trader it is the owner. For a company it is the directors, with a nominated individual under Regulation 6 "responsible for supervising the management of the carrying on of the regulated activity". For a charity it is the trustees, and for an NHS trust the trust board. Where the provider is a body other than a partnership, its directors and those in equivalent posts, which CQC says includes "trustees of charitable bodies", must also meet the fit and proper persons requirement in Regulation 5. The registered manager guide covers the manager's side of the same line.

Oversight means the people at the top see enough to know whether the service is safe, and can show that they acted on it. In practice a board or owner should receive, at a regular interval and in a form it can compare over time:

  • Incidents, accidents and the CQC notifications made, with the decisions not to notify
  • Safeguarding concerns and referrals, and complaints with their outcomes
  • Audit results and the status of open actions
  • Staffing: vacancies, agency use, turnover, training and supervision compliance
  • Feedback from people using the service, families and staff, and what changed as a result
  • The risk register, with the risks that have grown since last time
  • Anything external: inspection reports, commissioner visits, safety alerts, local authority quality reviews

What the board does with that information is the evidence. Minutes that record challenge, a question asked, a decision taken, a deadline set and a follow-up at the next meeting show oversight. Minutes that record "report noted" show that a report existed. Trustees and directors who visit the service, talk to staff and people living there, and write down what they saw, add a line of evidence that no dashboard can supply.

A deputy manager in a navy tunic turns over printed audit sheets on a clipboard beside a medicines trolley in a care home corridor, a carer walking with a resident behind her
05

How CQC assesses governance now

Under CQC's single assessment framework, Regulation 17 sits mainly under the well-led key question, which CQC summarises as "There are effective governance and management systems. Information about risks, performance and outcomes is used effectively to improve care." The governance, management and sustainability quality statement reads: "We have clear responsibilities, roles, systems of accountability and good governance. We use these to manage and deliver good quality, sustainable care, treatment and support. We act on the best information about risk, performance and outcomes, and we share this securely with others when appropriate."

That framework is due to change. In its initial response to its consultation, published on 24 March 2026, CQC said it will remove scoring, replace quality statements with new key lines of enquiry and re-introduce rating characteristics, and it scheduled pilots for June to October 2026. No date for the new approach to go live had been published when this guide was checked, so until CQC announces one the well-led quality statements described here are the ones it assesses against. A change to CQC's framework is not a change to Regulation 17 itself.

CQC's page for the governance, management and sustainability statement says what it means in terms a board can test itself against: "Managers can account for the actions, behaviours and performance of staff"; "Data or notifications are consistently submitted to external organisations as required"; and "There are robust arrangements for the availability, integrity and confidentiality of data, records and data management systems." Its subtopics include roles and accountability, quality assurance, data security and the Data Security and Protection Toolkit, emergency preparedness, financial and workforce sustainability, statutory requirements, workforce planning, safety alerts and records. The regulations it names are Regulation 17 and Regulation 20A, with Regulation 12 and the notification regulations to "also consider".

Two other well-led statements carry the rest of Regulation 17. Learning, improvement and innovation expects "processes to ensure that learning happens when things go wrong", with people using the service and their families involved in improvement. Freedom to speak up expects "a positive culture where people feel that they can speak up and that their voice will be heard", which is limb (e) seen from the staff side. Our guide to evidence categories explains how inspectors gather and score the evidence for each statement.

Governance also shows up everywhere else. A medicines error that recurs because the audit never looked at the right thing is a Regulation 12 finding with a Regulation 17 cause. Where inspectors find breaches in several regulations, the governance failure that let them persist is usually cited as well, because the system that should have found them did not.

06

The governance that happens in messages

A great deal of real governance never reaches the minutes. The registered manager messages the owner on a Friday night: two night staff off sick, agency cannot cover, can she pay a bank carer double time? The owner replies "yes, do it". A trustee sees a local news story and asks the chair, in a direct message, whether it is one of their homes. The action plan after a poor inspection is argued out in a group chat between the manager, the deputy and the nominated individual, and the final version is typed up for the file.

Those exchanges are governance in the sense Regulation 17 means: a risk identified, escalated and mitigated; a question from the board and the answer to it; an improvement plan agreed. They are records about "the management of the regulated activity", and limb (d) requires them to be kept securely. Held on personal phones, they are not held by the provider at all, and the evidence that the board knew and acted sits with whoever sent the messages.

ComplyChat provides a channel for those work conversations, with everyone in it told that it is on the record and a mobile number verified by SMS as the identity, so a trustee, a bank carer or an owner with no work account can be in it. Messages are recorded on the server as they are sent, and on paid plans the lasting record files into the provider's own Microsoft 365 once the tenant is connected, under its own retention rules. It is not an audit tool or a quality management system, and it does not do the governance; it keeps the conversations in which governance is done.

A question for the next board or provider meeting: of the last five decisions this board took about risk or staffing between meetings, how many could you show an inspector from records the provider holds?

07

Official guidance and your next step

The primary sources are Regulation 17 itself; CQC's guidance on Regulation 17, which is short enough to read in full and is the text providers "must have regard to"; and the well-led quality statements, each of which lists the regulations and best-practice guidance behind it. Quotations are from those pages as published on 25 September 2026.

This guide is a summary for providers in England, not legal advice about a particular inspection or enforcement action.

Then do one thing: take the last three months of your audits and list every action they produced, with its owner and whether it is closed. Then check whether the board or owner saw that list. If they did not, that is the first thing to fix, and it costs nothing.

Why we publish this

We build ComplyChat for the work conversations organisations need to keep. Good governance is largely a record of who knew what and what they decided, and much of that is now said in messages between managers, owners and trustees. Explore Free personal messaging, or compare the paid plans if your organisation needs a lasting Microsoft 365 archive.

Explore Free · How it works · Compare plans

Sources

Every document this guide quotes or links to, in the order it first cites them.

  1. Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 legislation.gov.uk
  2. Guidance on Regulation 17 cqc.org.uk
  3. Single assessment framework cqc.org.uk
  4. Governance, management and sustainability cqc.org.uk
  5. Initial response to its consultation cqc.org.uk
  6. Pilots cqc.org.uk
  7. Well-led quality statements cqc.org.uk