Complying with the Care Quality Commission (CQC) is not about shoring up your documents for an inspection and continuing on as you were before. It is about building a safe, well-led and sustainable healthcare service that protects patients, supports staff and meets your legal responsibilities. Whether you are setting up a private clinic, running a GP practice or expanding an independent healthcare service, learning how to comply with CQC requirements is fundamental, first and foremost because you will not legally be able to operate if you do not.
At DKJ Support Services, we support healthcare providers across England with CQC registration, governance systems, inspection preparation and ongoing compliance. Our team works within NHS and private healthcare settings, so our guidance is grounded in real operational experience. We understand that you want clear, practical steps that reduce your workload and remove the mysticism around the process.
This article explains exactly how to comply with CQC and what they expect of you. For practical solutions and continuous development, have a look at our guide to CQC mandatory training for healthcare staff.
CQC Compliance and Your Legal Responsibilities

The Care Quality Commission is the independent regulator of health and adult social care services in England. If you provide regulated activities, you must register with the CQC and meet the requirements set out in the Health and Social Care Act 2008 and associated regulations.
Compliance is not optional. Operating without registration, failing to meet Fundamental Standards, or breaching conditions of registration can result in enforcement action. This may include warning notices, conditions being imposed, suspension or cancellation of registration.
However, compliance is not about avoiding enforcement. Strong governance systems improve patient safety, staff confidence and organisational stability. When compliance is embedded properly, it becomes part of how you operate rather than an additional burden.
Five Key Questions: The Foundation of CQC Compliance
All CQC assessments are structured around five key questions. To comply with CQC, you must be able to demonstrate that your service is:
- Safe
- Effective
- Caring
- Responsive
- Well-led
Under the current Single Assessment Framework, these questions are supported by quality statements and evidence categories. Inspectors assess both on-site and off-site evidence.
1. Safe: Protecting People From Harm
To comply with the “Safe” requirement, you must show that patients are protected from abuse and avoidable harm.
This includes:
- Robust safeguarding systems
- Safer recruitment practices, including DBS checks
- Infection prevention and control procedures
- Medicines management systems
- Clear incident reporting processes
- Risk assessments for clinical and environmental hazards
Compliance means more than having policies. You must demonstrate that risks are identified, reviewed and mitigated. Incident logs should show learning and improvement, not just documentation.
2. Effective: Delivering Evidence-Based Care
An effective service delivers care in line with current guidance and ensures staff are competent in their roles.
You should be able to evidence:
- Staff training and competency assessments
- Clinical audits and outcome reviews
- Supervision and appraisal systems
- Compliance with the Mental Capacity Act
- Clear consent processes
Inspectors will look at whether your systems translate into good outcomes. Audit cycles should demonstrate improvement, not simply data collection.
3. Caring: Treating People With Dignity and Respect
The “Caring” question focuses on compassion, communication and respect.
You should be able to show:
- Positive patient feedback
- Clear communication practices
- Respect for privacy and dignity
- Inclusion in decision-making
- Equality and diversity awareness
Patient surveys, compliments, complaints analysis and observation of interactions all form part of the evidence base.
4. Responsive: Meeting People’s Needs
A responsive service adapts to patient needs and handles concerns effectively.
Compliance includes:
- Accessible complaints procedures
- Timely response to feedback
- Clear referral and triage systems
- Adjustments for diverse patient groups
- Evidence of service improvements following feedback
Inspectors expect to see that complaints lead to learning and service change.
5. Well-led: Strong Governance and Leadership
Well-led services have effective governance systems and clear leadership accountability.
This includes:
- Defined organisational structure
- Regular governance meetings
- Risk registers
- Clear policies and review schedules
- Open and transparent culture
- Demonstrable learning from incidents
Well-led is often the determining factor in inspection outcomes. Weak governance is one of the most common compliance gaps we see.
Complying with the Fundamental Standards of Care

To comply with CQC, you must meet the Fundamental Standards set out in regulations. These are legal requirements and include:
- Person-centred care
- Dignity and respect
- Need for consent
- Safe care and treatment
- Safeguarding
- Staffing
- Fit and proper persons
- Duty of candour
- Good governance
- Complaints handling
- Accurate record keeping
Failure to meet these standards can result in enforcement action.
For example, the duty of candour requires you to be open and honest when things go wrong. Good governance requires you to maintain accurate records, assess risks and ensure compliance with regulations.
Compliance is not achieved through paperwork alone. It requires active monitoring, leadership oversight and documented improvement actions.
Governance and Leadership Responsibilities
Strong governance is central to CQC compliance, and there are certain expectations to meet.
The Role of the Registered Manager
If you provide regulated activities, you must have a Registered Manager (unless exempt). The Registered Manager is legally responsible for the day-to-day management of regulated activities.
Their responsibilities include:
- Ensuring compliance with regulations
- Overseeing staff competence
- Managing incidents and complaints
- Maintaining governance systems
- Acting as the main point of contact with CQC
They must meet the Fit and Proper Person Requirement, demonstrating appropriate skills, experience and character.
Building an Effective Governance Structure
To comply effectively, you should implement:
- Monthly governance meetings
- Structured agendas aligned to the five key questions
- Risk registers reviewed regularly
- Clear action logs with named leads
- Annual policy review schedules
- Internal audit programmes
Governance should be proactive rather than reactive. When systems are embedded properly, inspection preparation becomes much easier.
At DKJ Support Services, we often help providers design governance frameworks that are proportionate to their size and complexity. This reduces unnecessary administrative burden while maintaining regulatory strength.
Policies, Records and Audits: The Operational Backbone of Compliance
Documentation plays a critical role in CQC compliance. While strong leadership and good clinical practice are essential, you must be able to evidence what you do. Inspectors will not assume systems are working — they will look for proof.
Well-structured policies, accurate records and meaningful audits form the operational backbone of compliance. When these are maintained properly, they demonstrate that your service is safe, effective and well-led. When they are weak, even high-quality care can appear disorganised or non-compliant.
Maintaining Accurate Policies
Your policies and procedures set out how your service operates. They show the CQC that you understand your regulatory responsibilities and have systems in place to meet them.
Essential policies include:
- Safeguarding – outlining how you protect children and adults at risk, including referral pathways and escalation processes.
- Infection prevention and control – detailing cleaning schedules, hand hygiene standards, waste disposal and outbreak management.
- Health and safety – covering fire safety, equipment maintenance, environmental risks and staff responsibilities.
- Medicines management – explaining prescribing, storage, administration, stock control and incident reporting procedures.
- Recruitment – demonstrating safer recruitment checks, DBS verification, references and employment history review.
- Consent and capacity – confirming compliance with the Mental Capacity Act and clear documentation of informed consent.
- Complaints handling – outlining how concerns are received, investigated, responded to and learned from.
- Data protection and confidentiality – ensuring compliance with the Data Protection Act 2018 and secure handling of patient information.
However, having these policies is not enough. To comply with CQC requirements, policies must be:
- Tailored to your specific service. A private aesthetic clinic will require different details from a GP practice or diagnostic centre. Inspectors can quickly identify generic, template-only policies that have not been adapted.
- Reviewed at least annually. Each policy should include a clear review date, version control and named policy lead.
- Accessible to staff. Staff must know where policies are stored and be able to explain how they apply them in practice.
- Reflected in day-to-day operations. There must be alignment between written procedures and what actually happens in your service.
A common compliance risk arises when policies are created during registration and then left untouched. Regulations evolve, services expand and staffing structures change. If policies do not reflect your current operations, they may undermine your “well-led” rating.
Regular policy review meetings, documented sign-off and staff awareness checks help ensure policies remain live documents rather than static paperwork.
The Audit Cycle

Audits are a method of demonstrating ongoing monitoring.
A compliant audit cycle includes:
- Identifying an area of review
- Measuring performance
- Implementing improvement actions
- Re-auditing to confirm progress
Audits should cover clinical practice, infection control, medicines management and governance processes.
Demonstrating Your Compliance Through Evidence Collection
Complying with CQC is about being able to demonstrate that your systems are working well. The question is: How do you prove that?
Evidence collection is where many providers feel uncertain. You may be delivering safe and effective care, but unless you can present clear, structured evidence, inspectors cannot assess it confidently.
Under the current assessment framework, CQC gathers evidence across multiple categories. These include:
- Policies and procedures
- Staff interviews and discussions
- Patient feedback and experience data
- Direct observations of care delivery
- Data submissions and notifications
- Provider Information Returns (PIR)
Inspectors assess evidence both on-site and off-site. This means compliance is not limited to what happens during inspection day. Your documentation, submissions and governance records are reviewed before inspectors arrive.
To comply effectively, you must organise evidence systematically and ensure it clearly aligns with the five key questions: Safe, Effective, Caring, Responsive and Well-led.
Structuring Your Evidence Around the Five Key Questions
One of the most effective ways to demonstrate compliance is to map evidence directly to the five key questions.
For example:
- Safe: Risk assessments, safeguarding logs, infection control audits, medicines audits.
- Effective: Training matrices, clinical audits, supervision records, competency assessments.
- Caring: Patient feedback results, communication policies, equality and diversity evidence.
- Responsive: Complaints logs, response timelines, service improvement actions.
- Well-led: Governance meeting minutes, risk registers, action plans, leadership structures.
When evidence is structured this way, it becomes easier for inspectors to see how your systems align with regulatory expectations. It also reduces last-minute stress because information is readily accessible.
Organising Evidence Systematically
Many providers benefit from implementing:
- Digital compliance folders structured around the five key questions.
- Evidence mapping documents that cross-reference policies and audits to regulatory requirements.
- Live action plans showing ongoing improvement and oversight.
- Inspection preparation checklists to ensure nothing is overlooked.
A digital system (for example, secure cloud-based folders) allows you to update documents in real time, track version control and maintain consistency across teams.
Evidence mapping is particularly valuable. This involves creating a structured document that shows exactly where each regulatory requirement is addressed within your service. During inspection, this enables you to guide inspectors clearly to relevant documentation.
Live action plans demonstrate that governance is active. Rather than presenting static documents, you are showing that risks are identified, assigned to responsible leads and reviewed within defined timeframes.
Staff and Patient Evidence
CQC does not rely solely on documentation. Inspectors will speak directly to staff and patients.
Staff interviews assess whether:
- Staff understand safeguarding processes
- Training is embedded in practice
- Policies are applied correctly
- Leadership is visible and supportive
Patient feedback provides insight into whether care is compassionate, respectful and responsive.
You should ensure that:
- Staff are familiar with policies and governance structures
- Supervision sessions reinforce regulatory expectations
- Patient surveys are conducted regularly
- Complaints are analysed for learning and improvement
Evidence must be consistent. If written policies do not match staff understanding or observed practice, this can create compliance concerns.
Provider Information Return (PIR) and Data Submissions
The Provider Information Return is an important element of off-site evidence collection. It requires you to describe how your service meets regulatory standards and outline key developments.
Incomplete or poorly structured PIR submissions can limit your inspection outcomes, particularly in the “Well-led” domain.
You should approach the PIR as a governance document rather than an administrative form. It should reflect your:
- Audit findings
- Service improvements
- Staffing updates
- Risk management processes
- Leadership oversight
Strong PIR submissions demonstrate transparency and organisational control.
Continuous Preparation, Not Reactive Response
A common compliance risk occurs when services only prepare evidence once an inspection is announced. This reactive approach creates pressure and increases the likelihood of gaps.
Preparation should be continuous.
Effective services:
- Review compliance folders quarterly
- Update action plans monthly
- Conduct internal mock inspections
- Keep governance documentation current
- Brief staff regularly on regulatory expectations
When evidence collection is embedded into daily operations, inspection becomes a presentation of existing systems rather than a scramble to assemble documents.
How DKJ Support Services Can Help
Organising evidence can feel overwhelming, particularly if you are balancing clinical responsibilities with governance oversight. Many providers struggle not because they lack systems, but because their evidence is not structured clearly.
At DKJ Support Services, we support healthcare providers by:
- Designing structured digital compliance frameworks aligned to the five key questions
- Conducting mock inspections to identify evidence gaps
- Reviewing and strengthening Provider Information Returns
- Creating evidence mapping tools tailored to your service
- Developing live governance action plans
- Preparing Registered Managers and leadership teams for inspection interviews
Because we work within NHS and private healthcare environments, our support is practical and proportionate. We focus on systems that are sustainable, not overly complex.
We aim to reduce uncertainty and lighten your administrative burden while strengthening your compliance position. When evidence is organised clearly, leadership gains confidence and inspections become significantly less stressful.
Common CQC Compliance Gaps and How to Avoid Them
Through our work supporting clinics and GP practices, we regularly see avoidable compliance gaps. Identifying and addressing these early reduces enforcement risk and significantly lowers stress before inspections.
| Outdated or Generic Policies | Tailor policies to your specific service, ensure they reflect current practice, and implement a structured annual review schedule with version control and named policy leads. |
| Weak Governance Oversight | Introduce regular, minuted governance meetings aligned to the five key questions, maintain a live risk register, and track actions with clear deadlines and accountable leads. |
| Poor Training Monitoring | Maintain a live training matrix that includes mandatory and role-specific training, renewal dates, competency assessments, and refresher planning. |
| Incomplete Recruitment Records | Use a safer recruitment checklist aligned to regulations, ensuring DBS checks, references, employment history, and identity verification are consistently documented. |
| Limited Evidence of Learning From Incidents | Document reflective discussions, learning outcomes, and resulting service improvements. Ensure re-audits or follow-up reviews demonstrate that changes have been embedded. |
| Reactive Inspection Preparation | Conduct regular internal mock inspections, maintain structured compliance folders, and review evidence quarterly rather than waiting for inspection notification. |
Addressing these gaps early prevents enforcement risk and reduces stress before inspections.
What Happens If You Do Not Comply With CQC Regulations?

While the regulator aims to work proportionately with providers, it also has clear legal powers to protect people using services. If concerns are identified and not addressed effectively, enforcement action can escalate.
CQC enforcement powers include:
- Action plans
- Warning notices
- Imposed conditions on registration
- Suspension of registration
- Cancellation of registration
- Prosecution in serious cases
The level of enforcement used will depend on the severity of the concerns, the level of risk to patients and whether the provider demonstrates willingness and ability to improve.
Action Plans
Where breaches are identified but there is no immediate risk of harm, CQC may request a formal action plan.
You will be required to:
- Identify the areas of non-compliance
- Set out how you will address them
- Provide realistic timescales
- Demonstrate leadership oversight
Action plans are often the first stage of enforcement. However, they are not informal. Failure to respond adequately or within agreed timeframes can lead to escalation.
Strong governance systems and clear action tracking significantly reduce the likelihood of an action plan progressing further.
Warning Notices
Warning notices are more serious. They are issued when CQC believes a provider is failing to comply with regulations and must improve within a specified timeframe.
A warning notice may:
- Highlight specific regulatory breaches
- Set clear deadlines for compliance
- Be published publicly
CQC will usually follow up within three months to assess whether improvements have been made. If improvements are insufficient, further enforcement action can follow.
A warning notice often indicates weaknesses in governance oversight, monitoring systems or leadership response.
Suspension, Cancellation and Prosecution
Where serious risks to patient safety are identified, CQC can escalate enforcement beyond warning notices or conditions.
Suspension of registration may be used where immediate protective action is required. During suspension, you cannot carry out regulated activities, meaning your service may be unable to operate. Although usually time-limited, suspension can be extended if improvements are not demonstrated.
If concerns persist or breaches are repeated, CQC may move to cancellation of registration. This means you can no longer legally provide regulated activities and must cease operations. Re-registration is complex and not guaranteed.
In the most serious cases — such as significant harm, neglect, obstruction of inspectors or operating without registration — CQC may pursue criminal prosecution, which can result in unlimited fines, criminal convictions or imprisonment.
These actions are reserved for serious or sustained non-compliance and highlight the importance of proactive governance and early intervention.
Final Thoughts: Learning How to Comply with CQC Regulations

Complying with CQC is about embedding safe systems, strong governance and clear leadership into your everyday operations. It goes far beyond the initial registration and inspections and should become a cornerstone of your practice.
By understanding the five key questions, meeting the Fundamental Standards, maintaining accurate policies and records, implementing robust audits, and continuously monitoring performance, you can build a service that is both compliant and resilient.
At DKJ Support Services, we combine hands-on NHS and private sector experience with practical consultancy support. Our experts can help you reduce uncertainty, strengthen governance and approach inspections with confidence. Whether you are registering a new service, preparing for inspection or addressing compliance gaps, we work alongside you to lighten your workload and ensure your systems are fit for purpose.
When compliance is embedded properly, it protects your patients, supports your staff and safeguards your organisation’s future. Contact us today for more information.
Sources:
- The 5 key questions we ask (CQC)
- Our new single assessment framework (CQC)
- The single assessment framework – evidence categories (CQC)
- Regulations for service providers and managers (CQC)
- The regulations covered by this guidance (CQC)
- Review of CQC’s single assessment framework and its implementation (PDF) (CQC)

Author: Kiran Johnson
Kiran Johnson is the Director of DKJ and a specialist in health and social care with over a decade of experience. As an expert in Bid Management, CQC Compliance, and primary care operations, Kiran has supported over 250 GP practices and numerous private clinics to achieve excellence in governance and service delivery. Currently, Kiran also manages Abbey Health PCN, focusing on operational efficiency and workforce optimisation. A key contributor to the setup of 81 PCNs in 2019 and now supporting 137 nationwide, Kiran is committed to advancing healthcare services across both NHS and private sectors.