Build CQC policies that match your regulated activities, staffing model, premises, governance system, and patient pathway. Include a responsible owner, creation date, review date, current legislation references, working links, and clear staff responsibilities. Maintain consistency across policies, the Statement of Purpose, risk assessments, training plans, and governance documents. Review policies regularly and update them when services, legislation, staffing, equipment, or risks change.
Policies and procedures are a key part of your CQC registration application. They show how your service will operate safely, how staff will know what to do, and how you will manage risks, complaints, safeguarding, consent, medicines, recruitment and governance.
They are not just paperwork to upload. The CQC uses your supporting documents to understand whether your proposed service is ready to provide regulated activities in a safe, effective and well-managed way. Missing, incomplete or unsuitable documents can contribute to avoidable queries, rework or delay. (For more on this, you may also want to read our guide on common reasons for CQC registration application delays.)
At DKJ Support Services, we help new providers, private clinics and healthcare organisations prepare CQC new registration documents that reflect how their service will actually operate. This article aims to explain what “good” looks like for CQC policies and procedures in 2026, especially for providers who need sector-specific support rather than generic templates.
What Are Policies and Procedures in a CQC Registration Application?

Policies and procedures help the CQC understand how your service will work in practice. They should explain how you will protect people from avoidable harm, manage concerns, recruit suitable staff, maintain infection prevention standards, govern the service and respond when something goes wrong.
A policy pack should connect with your application form, Statement of Purpose, staffing model, premises, regulated activities and governance arrangements. If these documents tell different stories, the CQC may need to ask further questions before your application can progress.
For example, your safeguarding policy should reflect the age groups and patient groups your service will support. Your medicines policy should match whether you prescribe, store, administer, transport or dispose of medicines. Your recruitment policy should match whether your team includes employed staff, contractors, remote clinicians, sessional workers or practising privileges.
What Every CQC Policy Document Must Include in 2026
The CQC’s supporting documents guidance was last updated on 2 February 2026.
Each policy should clearly include:
- Your business name
- The name of the person responsible for the policy
- The date the policy was created
- The date the policy will be reviewed
The named person should be realistic. Depending on the policy, this may be the registered manager, nominated individual, clinical lead, governance lead or another appropriate senior person. What matters is that ownership is clear and the person named has a real role in keeping the policy accurate and in use.
Quality checks of CQC application documents
The CQC also says every document must be complete and relevant, must not contain personal information about service users or members of the public, must include up-to-date references to legislation or guidance with working links, must be consistent with other policies, and must be accessible to staff, people using the service and their representatives.
Before submitting your policy pack, check each document against these questions:
- Is it complete?
- Is it relevant to your service?
- Has personal information about service users or members of the public been removed?
- Are legislation and guidance references current?
- Do all links work?
- Is the policy consistent with your other policies?
- Can staff, people using the service and representatives access it in a suitable format?
Review dates
A review date is not just a footer. It should connect to a working review cycle.
Many providers use annual policy reviews, but policies may need to be reviewed sooner if legislation changes, guidance is updated, staff roles change, new services are added, premises change or incidents show that a policy is not working as intended.
A good policy pack should show that your documents are live, owned and maintained. That matters for registration, but it also matters after registration when your service starts operating.
Core Policies CQC Commonly Asks New Providers to Submit

The exact documents you need will depend on your regulated activity, service model and premises. However, the CQC’s supporting documents guidance includes specific guidance on common policies such as complaints, consent, equality and diversity, governance, infection prevention and control, medicines management, recruitment, safeguarding, restraint and positive behaviour support.
Complaints policy
Your complaints policy should explain how people can raise concerns, how complaints will be acknowledged, how they will be investigated and how outcomes will be shared.
A good complaints policy should include:
- Clear routes for patients, families and representatives
- Timescales for acknowledgement and response
- A named person or role responsible for complaints
- Escalation steps where a complaint is complex or unresolved
- How learning from complaints feeds into governance and quality improvement
The policy should be easy to understand. If someone using your service cannot work out how to complain, the document is not doing its job.
Consent policy and procedure
Your consent policy should explain how you obtain and record informed consent. It should cover capacity, best interests, withdrawal of consent, record keeping and how staff respond when there are concerns about a person’s ability to make a decision.
This policy must reflect your service. A diagnostics provider, private GP clinic, aesthetics clinic, dental provider and online healthcare service may all need different consent workflows.
For example, an online provider may need to explain how identity, capacity and consent are checked remotely. An aesthetics clinic may need clear consent procedures linked to consultation, treatment planning and aftercare information.
Safeguarding policy and procedure
Your safeguarding policy should explain how staff recognise, report and escalate concerns. It should cover adults and children where relevant to your service.
A good safeguarding policy should not rely only on generic wording. It should explain the types of safeguarding risks that may arise in your setting, who staff should contact internally, how external referrals are made and how staff access local safeguarding pathways.
It should also connect with recruitment, training, incident reporting, complaints and governance. Safeguarding is not a standalone topic. It must be part of how your service is run.
Infection prevention and control policy
Your infection prevention and control policy should match your premises, equipment, procedures, staff roles, waste arrangements and cleaning processes.
For a private GP clinic, this may include consultation room cleaning, hand hygiene, clinical waste, sharps management and vaccine storage areas where applicable. For dental services, decontamination and equipment handling may need more detailed procedures. For aesthetics or cosmetic services, the policy should reflect the treatments offered and the infection risks linked to those procedures.
For diagnostics and ambulance services, infection prevention must also reflect equipment use, patient flow, transport, cleaning between patients and any mobile working arrangements.
Medicines management and prescribing policy
Your medicines policy should reflect what your service actually does with medicines.
It may need to cover:
- Prescribing
- Remote prescribing, where relevant
- Storage
- Administration
- Disposal
- Transportation of patient medication
- Controlled drugs, where applicable
- Medicines incidents
- Staff responsibilities
- Audit and governance
The policy should not include processes that do not apply to your service. If your application says you do not store medicines on site, but your medicines policy describes controlled drug storage cupboards and stock checks, that inconsistency may create avoidable questions.
Recruitment policy and procedure
Your recruitment policy should show how you check that staff are suitable for their roles. This may include identity checks, references, DBS checks where required, right to work checks, professional registration, qualifications, induction and probation.
The policy should match your workforce model. A service using sessional clinicians, remote prescribers, contractors or practising privileges needs a recruitment and oversight process that reflects those arrangements.
A good recruitment policy should explain not only what checks are completed, but who completes them, where evidence is stored and what happens if a concern is identified.
Equality, diversity and human rights policy
Your equality, diversity and human rights policy should show how your service will be accessible, fair and respectful.
It may include:
- Reasonable adjustments
- Accessible information
- Interpreter or translation arrangements
- Non-discriminatory recruitment
- Inclusive service design
- Staff responsibilities
- How feedback is used to improve access
This policy should be practical. It should explain what your service will do, not just repeat broad principles.
Governance and quality assurance policies
Governance and quality assurance policies help the CQC understand how you will monitor safety, quality and performance.
A good governance policy should explain:
- Who reviews quality and safety information
- How often governance meetings or reviews happen
- What data is reviewed
- How incidents, complaints and risks are recorded
- How audits are planned and followed up
- How actions are tracked
- How learning is shared with staff
- How you check whether improvements have worked
This is one of the most important areas of the policy pack because it shows how your service will stay safe and compliant after registration. CQC registration is not only about being ready on day one. It is also about having systems that support ongoing compliance.
Restraint and positive behaviour support policies, where applicable
Restraint and positive behaviour support policies will not apply to every provider. Where they do apply, they must be specific, proportionate and legally current.
The policy should reflect the service user group, care environment, staff skills, risk assessment process and escalation routes. It should also connect with safeguarding, incident reporting, staff training and governance.
Service-specific Policies and Documents

Some providers need additional documents because of their service type, equipment, premises or regulated activity.
The CQC’s supporting documents guidance lists extra documents such as radiography risk assessments and local rules, Health and Safety Executive ionising radiations regulations registration, LOLER lift safety certificates and other safety or premises documents where applicable.
| Service or setting | Possible additional policies or documents | What “good” looks like |
| Diagnostics or imaging | Radiography risk assessment, local rules, HSE ionising radiation registration | Documents match the equipment, staff roles, safety arrangements and clinical pathway |
| Dental services | Infection prevention and control, decontamination, radiography, medical emergencies | Policies reflect dental-specific risks, equipment and staff responsibilities |
| Aesthetics and cosmetic services | Consent, complications, infection prevention, medicines, emergency protocols | Policies reflect the actual procedures offered and how risks are managed |
| Online healthcare | Remote prescribing, identity checks, consent, safeguarding, information governance | Policies explain how risks are managed when care is delivered remotely |
| Ambulance services | Vehicle safety, medicines transport, infection control, incident response | Policies reflect mobile working, patient transfer and equipment management |
| Premises with lifts | LOLER lift safety certificate, where applicable | Evidence is current and linked to premises risk management |
The CQC also makes clear that if you use a third-party template, it must suit your service type. It gives the example that a residential care template will not work for home care applicants. The same principle applies across private healthcare. A care home policy pack, NHS GP pack or generic social care template may not fit an aesthetics, diagnostics, dental, online healthcare or ambulance service unless it has been carefully adapted.
Why Generic CQC Policy Templates Often Fail
Templates are not always the problem. A well-designed template can help you structure your thinking and avoid missing key sections. The problem comes when templates are used without tailoring them to the provider’s regulated activities, staffing model, premises and patient pathway.
Common issues with generic policy packs include:
- The wrong service type
- Old legislation references
- Broken links to guidance
- Different business names across documents
- Different responsible people listed in different policies
- Review dates that have already passed
- References to services the provider does not offer
- Missing sections that apply to the actual regulated activity
- Contradictions between policies, the application form and the Statement of Purpose
- Policies written for a large organisation when the provider is a small clinic
- Policies written for face-to-face care when the provider works remotely or online
Inconsistent cross-references are a common red flag
Policies should work as a set. If the complaints policy says complaints are reviewed at a monthly governance meeting, the governance policy should describe that meeting. If the safeguarding policy says all staff complete safeguarding training at induction, the staff training plan should include safeguarding.
A common problem is when one policy has been copied from one source and another policy from somewhere else. The wording may look professional, but the documents do not join up.
For example, a medicines policy may say controlled drugs are stored on site, while the service model says there is no medicine storage. Or a recruitment policy may refer to care workers when the provider is registering a private diagnostics clinic. These issues can make the application look less prepared than it may actually be.
Expired links and outdated law weaken the pack
CQC expects up-to-date references to legislation or guidance, with working links. That means someone should check every link before submission.
This is a simple task, but it is often missed. A policy with broken links, expired dates or outdated references may suggest that the document has not been properly reviewed. It can also make life harder for staff once the service is operating.
What “Good” CQC Policies and Procedures Look Like in 2026
1. They are written for your actual service.
Good policies reflect your regulated activities, premises, workforce, opening hours, patient groups, equipment and care pathways.
They should not describe a service you do not provide. They should not refer to staff you do not employ or locations you do not operate from.
2. They match your staffing model.
Your policies should explain who does what. This includes employed staff, contractors, sessional clinicians, remote workers, administrative staff, clinical leads and managers.
For example, if your service uses remote clinicians, your policies should explain how they are recruited, supervised, trained and included in governance.
3. They are internally consistent.
Your policies, risk assessments, training plan, governance arrangements and Statement of Purpose should all align.
If your Statement of Purpose says you provide online consultations, your consent, safeguarding, prescribing and information governance policies should reflect online care. If your application says you provide minor procedures, your infection prevention and clinical emergency arrangements should reflect that.
4. They use current legislation and guidance.
Good policies include current references and working links. They should be reviewed when relevant law or guidance changes.
This does not mean every policy needs pages of legal text. It means references should be accurate, relevant and useful.
5. They are clear enough for staff to use.
A policy should help staff understand what to do.
A staff member should be able to answer:
- What is my responsibility?
- Who do I tell?
- Where do I record this?
- What happens next?
- When do I escalate?
If a policy is full of vague statements but does not explain the process, it may not be useful in practice.
6. They include ownership and review arrangements.
Every policy should have a clear owner and review date. Good policies also explain when an early review may be needed.
Triggers may include:
- A serious incident
- A complaint trend
- A change in legislation
- A change in guidance
- A new regulated activity
- A new location
- A change in staffing model
- A change in equipment or clinical pathway
7. They are accessible.
CQC expects documents to be accessible to staff, people who will use the service and their representatives. In practice, this means thinking about where policies are stored, who can access them and whether information can be provided in a suitable format when needed.
Staff should know where to find policies. Service users should be able to access relevant policies or public-facing versions, such as complaints, consent and privacy information.
8. They connect to governance.
Good policies are part of a live governance system. Incidents, complaints, audit findings, feedback and changes in guidance should feed into policy review.
A policy pack should not sit untouched after registration. It should support how your service learns, improves and keeps people safe.
How to Build a CQC Policy Pack Before You Apply

Step 1: Confirm your regulated activities and service model.
Start with what you are applying to do. Confirm your regulated activities, service users, premises, staffing model, opening hours, equipment and patient pathway.
Your policies should be built around this information.
Step 2: Map CQC’s required documents to your service.
Check the CQC’s supporting documents guidance and identify which documents apply to your application. The CQC advises applicants to check which documents they need, then read the guidance for each relevant document.
Do not assume every provider needs exactly the same pack. A private GP clinic, dental provider, diagnostics service, aesthetics clinic, ambulance provider and online healthcare service may need different supporting documents.
Step 3: Create a policy register.
A policy register helps you keep control of the pack.
It should include:
- Policy title
- Owner
- Version number
- Date created
- Review date
- Linked policies
- Relevant legislation or guidance
- Staff groups affected
This makes it easier to spot missing ownership, expired review dates or inconsistent document versions.
Step 4: Tailor each policy to your pathway.
Work through what happens before, during and after a patient uses your service.
Ask:
- How does the person access the service?
- How do you check identity, eligibility or suitability?
- How do you obtain consent?
- How do you assess and manage risk?
- Who provides care or treatment?
- How is information recorded?
- How are concerns escalated?
- How is follow-up managed?
Your policies should support this pathway.
Step 5: Check consistency across the full pack.
Review your policies against your Statement of Purpose, application answers, staff training plan, risk assessments, business plan and governance arrangements.
Look for contradictions. Check job titles, business names, service descriptions, opening hours, locations, responsibilities and review dates.
Step 6: Set up the review cycle before submission.
Your policy pack should not be treated as complete forever once uploaded. Before submitting your application, decide who will maintain each policy, how reviews will be recorded and how staff will be told about changes.
This helps show that your policies are part of your operating model, not just your application pack.
Policy Pack Checklist for New CQC Providers
Before submitting your CQC application, check that each policy:
- Includes the correct business name
- Names the person responsible
- Has a creation date
- Has a review date
- Matches your regulated activities
- Matches your Statement of Purpose
- Uses current legislation and guidance
- Has working links
- Removes personal information about service users or members of the public
- Uses clear, plain English
- Explains staff responsibilities
- Shows how risks are reported and escalated
- Links to training, governance and audit where relevant
- Is accessible to staff and relevant service users or representatives
- Has been reviewed as part of the full policy pack, not in isolation
How DKJ Support Services Helps with Sector-specific CQC Policy Packs
At DKJ Support Services, we support you to prepare policies and procedures that reflect your actual service. That includes reviewing whether your documents match your regulated activities, staffing arrangements, governance structure, premises and patient pathway.
Our focus is on sector-specific policy packs, not recycled paperwork. The policies the CQC checks for a private GP service are not identical to those for an aesthetics clinic, diagnostics provider, online healthcare service, dental provider or ambulance provider.
We can help you understand which policies are needed, tailor documents to your service model and identify avoidable gaps before submission. That may include expired review dates, missing policy owners, broken links, inconsistent job titles, irrelevant wording or policies written for the wrong sector.
DKJ Support Services also supports providers with CQC registration, private clinic setup, compliance documentation and bid management. Our existing private clinic support content explains that clinic governance may include CQC registration, policy creation and practical regulatory support tailored to the needs of different healthcare providers.
The aim is not to create paperwork for its own sake. It is to help your policy pack reflect how your service will operate in practice.
Frequently Asked Questions about CQC Policies and Procedures

What policies do I need for CQC registration?
The policies you need depend on your service, regulated activities, premises and patient group. Common policies include complaints, consent, safeguarding, infection prevention and control, medicines management, recruitment, equality and diversity, governance and quality assurance. Restraint or positive behaviour support policies may also be needed where they apply to the service.
Some providers also need service-specific documents, such as radiography risk assessments, local rules, HSE ionising radiation registration or LOLER lift safety certificates.
Can I use CQC policy templates?
Yes, but templates must be carefully tailored. The CQC says that if you use a third-party template, it must suit your service type.
A template should be treated as a starting point, not a finished policy. You still need to check that it matches your regulated activities, staffing model, premises, patient pathway and governance arrangements.
Why might the CQC query my policies?
The CQC may query policies if they are missing required details, use the wrong business name, have outdated legislation references, include broken links, contain irrelevant content or contradict your other application documents.
Queries may also arise if your policies appear to have been written for another service type. For example, a policy pack written for a care home may not be suitable for a private clinic, dental service, diagnostics provider or online healthcare service.
How often should CQC policies be reviewed?
Every policy should have a review date. Many providers use an annual review cycle, but policies should be reviewed sooner if legislation, guidance, staffing, premises, equipment, regulated activities or service pathways change.
A serious incident, safeguarding concern, complaint trend or audit finding may also trigger an earlier review.
Do policies need to match the Statement of Purpose?
Yes. Your policies and Statement of Purpose should align.
If your Statement of Purpose describes one service model but your policies describe another, this can create avoidable confusion. The same applies to staffing, premises, regulated activities, patient groups and governance arrangements.
Do small clinics need the same policies as larger providers?
Small clinics still need relevant policies, but the content should be proportionate. A small private clinic should not use a policy pack written for a large hospital or care home unless it has been carefully adapted.
Good policies should match the scale and complexity of the service. They should be detailed enough to explain how risks are managed, but not so generic or oversized that staff cannot use them.
Final Thoughts
Good CQC policies are not generic documents collected to satisfy a checklist. They should be specific to your service, internally consistent, up to date, accessible and part of a working governance system.
In 2026, CQC expects supporting documents to include clear ownership, creation and review dates, current references, working links and consistency across the full policy pack. It also expects documents to be relevant to the service type. That is where many generic templates fall short.
DKJ Support Services can support you with CQC registration documents, policy review and practical compliance planning, so your application reflects how your service will operate in practice.

Author: Kiran Johnson
Kiran Johnson is the Director of DKJ and a specialist in health and social care with over a decade of experience. As an expert in Bid Management, CQC Compliance, and primary care operations, Kiran has supported over 250 GP practices and numerous private clinics to achieve excellence in governance and service delivery. Currently, Kiran also manages Abbey Health PCN, focusing on operational efficiency and workforce optimisation. A key contributor to the setup of 81 PCNs in 2019 and now supporting 137 nationwide, Kiran is committed to advancing healthcare services across both NHS and private sectors.