Purpose
To provide a systematic, evidence-based cycle of assurance that identifies risk early, drives improvement and demonstrates oversight.
Scope
All regulated activities, all locations and all levels of management.
The assurance cycle
Assess: scheduled audits and self-assessment against the five key questions.
Identify: findings rated by risk, harm potential and equity impact.
Act: actions assigned with owner, priority and target date.
Evidence: documentary proof of completion attached to each action.
Review: effectiveness re-tested at the next audit rather than assumed.
Improve: themes feed policy, training and staffing decisions.
Assure: independent or peer review of the service's own conclusions.
Audit calendar
Monthly: medicines, care plans, infection control, health and safety, dignity observation, complaints and incidents.
Quarterly: safeguarding themes, mortality and deterioration review, staffing and skill mix, training compliance, equality data.
Annually: full mock inspection against all five key questions, business continuity test, policy review schedule.
Reporting and escalation
A monthly governance report is produced covering risk register movement, incidents, complaints, safeguarding, staffing and improvement action status.
Red-rated risks are escalated to the provider or board within five working days with a mitigation plan.
Training and competency
All staff receive induction training on this policy before working unsupervised, refreshed at least annually or sooner following incident learning or a change in guidance.
Competency is confirmed through observation of practice, supervision discussion and reflective questioning — not attendance records alone.
Training records are maintained centrally and gaps are reviewed monthly against the training matrix.
Governance, monitoring and accountability
The registered manager holds overall accountability for this policy. Day-to-day implementation is delegated to named leads recorded in the service's accountability matrix.
Compliance is monitored through the service audit calendar, with findings reported to the monthly governance review and escalated to the provider board where risk is rated high.
Every audit finding is converted into an entry on the improvement action tracker with a named owner, priority rating, target date and evidence of completion.
Learning is shared with the whole team through team meetings, supervision and reflective practice sessions. Where a theme recurs, the policy itself is reviewed rather than the individual blamed.
- Live risk register reviewed monthly with likelihood, consequence and mitigation owner.
- Improvement action tracker with overdue actions automatically escalated.
- Annual independent or peer mock inspection to test internal assurance.
- Serious incidents trigger a structured root-cause analysis within 10 working days.
- Learning is published internally and tested at the next audit cycle to confirm change has held.
- Audit data is disaggregated by protected characteristic where numbers allow, to expose differences in experience and outcome.
- An annual equality impact review considers access, experience and outcomes for people and for staff.
Evidence of compliance
- Audit calendar and completed audits
- Governance minutes
- Risk register
- Action tracker exports
Suggested review cycle: Annually.