A photorealistic image of a group of 4 caregivers mix of male and female in tunic uniforms 00072b with accent e51974 in a bright modern board room sitting at a conference table reviewing company policies and proceures. all are content ensuring a safe and well leg domicilary care service

Good Governance Policy and Procedure

This policy details our good governance approach, to support staff with good governance practices.

1. Governance

1.1. This is the Good Governance Policy and Procedure for The Good Place Home Care Services Limited.

1.2. The Good Place Home Care Services Limited will be referred to in this document as "The Good Place Home Care Services Limited","The Good Place","We","Us", or "Our".

1.3. Our registered address is: 186 Wetmore Road, Burton-on-Trent, Staffordshire, DE14 1QZ.

1.4. We can be contacted by:-

1.5. Words importing one gender include all genders, and words in the singular include the plural and vice versa, unless the context requires otherwise.

1.6. Document control sheet:-

MetadataValue
Document fingerprintGOV-2099-V2
Document ownerDean Hill (Nominated Individual)
Document version2
Document statusApproved following a scheduled review on 18/03/2026 by Dean Hill (Nominated Individual)
Document review cycleAnnually or sooner if legislation or guidance changes. Next review planned for March 2027
Summary of changesFollowing an internal governance review informed by current CQC guidance and feedback, we have clarified the responsibilities of specific leaders and staff groups, strengthened our arrangements for risk and quality oversight, and set out in more detail how we will seek and act upon feedback from people using our service.

2. Purpose

2.1. To ensure that we operate a well-led, safe, and high-quality domiciliary care service in compliance with the Care Quality Commission (CQC) Regulation 17 – Good Governance.

2.2. To ensure that we fulfil the legal and regulatory responsibilities.

2.3. To support us to meet, and be able to evidence compliance with, the following CQC Single Assessment Framework quality statements:-

3. Scope

3.1. This policy applies to all staff of The Good Place.

4. Policy Statement

4.1. This policy outlines the governance framework of The Good Place to ensure that we operate a well-led, safe, and high-quality domiciliary care service in compliance with the Care Quality Commission (CQC) Regulation 17 – Good Governance. The policy provides clarity on how we manage and govern our organisation to meet legal, regulatory, and ethical requirements.

5. Legal & Regulatory Framework

5.1. This policy is guided by:-

  • a. Health and Social Care Act 2008 and the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, in particular:
    • aa. Regulation 12 – Safe care and treatment
    • ab. Regulation 13 – Safeguarding service users from abuse and improper treatment
    • ac. Regulation 16 – Receiving and acting on complaints
    • ad. Regulation 17 – Good governance
    • ae. Regulation 18 – Staffing
    • af. Regulation 19 – Fit and proper persons employed
    • ag. Regulation 20 – Duty of candour
  • b. Care Quality Commission (Registration) Regulations 2009.
  • c. Care Act 2014 and Care and Support Statutory Guidance.
  • d. Mental Capacity Act 2005 and associated Code of Practice.
  • e. Equality Act 2010.
  • f. Data Protection Act 2018 and UK General Data Protection Regulation (UK GDPR).
  • g. NHS England Accessible Information Standard (AIS).
  • h. Health and safety legislation relevant to domiciliary care, including the Health and Safety at Work etc. Act 1974 and associated regulations.
  • i. Relevant CQC guidance and the CQC Single Assessment Framework.

5.2. The Good Place is fully committed to meeting the requirements of the Accessible Information Standard (AIS), as set out by NHS England. This means we will ensure that people with a disability, impairment, or sensory loss receive information and communication support that they can understand and use effectively. This may include large print, easy-read versions, audio formats, or the use of interpreters and communication aids. See our Accessible Information Standard (AIS) Policy and Procedure for further details. 

5.3. We also comply with the Equality Act 2010 and are fully committed to promoting diversity, and human rights in all aspects of our service provision and employment practices. We are dedicated to ensuring that all individuals, including staff, service users, and stakeholders, are treated fairly, with dignity and respect, and without discrimination. We will also make reasonable adjustments so that no individual is treated less favourably when using our service. This includes supporting people with protected characteristics such as age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race, religion or belief, sex, and sexual orientation. See our Equality, Diversity and Human Rights Policy and Procedure for further details.

6. Governance Framework

6.1. Governance is the system of rules, practices, and processes that The Good Place uses to manage its operations effectively. It provides a structured approach to decision-making, risk management, compliance, and quality assurance.

6.2. A strong governance framework ensures that our domiciliary care service is well-led, safe, and continuously improving in accordance with CQC Regulation 17 – Good Governance. It also ensures that we comply with legal, ethical, and regulatory obligations, including those set by the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014.

6.3. Our governance framework is designed to generate and use evidence in line with the CQC Single Assessment Framework. We routinely collect and triangulate information from people’s experience, staff feedback, observations, policies and processes, and measurable outcomes so that leaders have an accurate, current picture of quality and risk.

6.4. Our governance framework is built on the three key pillars below.

6.5. Strategic Leadership

6.5.1. Strategic leadership ensures that The Good Place operates with a clear mission, vision, and values that align with best practice standards and CQC requirements. Leadership responsibilities include:-

  • a. Setting clear objectives for service delivery and organisational development.
  • b. Developing and reviewing policies to maintain compliance with health and social care regulations.
  • c. Ensuring financial sustainability through effective budgeting and resource allocation.
  • d. Monitoring industry changes and regulatory updates to ensure the organisation remains compliant.
  • e. Providing leadership and support to staff to foster a culture of quality care and continuous improvement.
  • f. Promoting a positive, open and learning culture where staff feel safe to speak up, and where concerns, incidents and near misses are used to drive improvement.
  • g. Ensuring we fulfil our statutory Duty of Candour (Regulation 20) by being open and honest with people and their representatives when things go wrong.
  • h. Ensuring that equality, diversity, inclusion and human rights are embedded in strategic decisions and everyday practice.
  • i. Considering environmental sustainability and efficient use of resources when planning and delivering services.
  • j. Providing governance oversight of digital systems used for care planning, scheduling and record keeping, including data quality, cyber security and contingency planning.

6.5.2. Our leadership team includes:-

  • a. The Registered Provider, responsible for ensuring that the service meets all legal and regulatory requirements.
  • b. The Nominated Individual, responsible for overseeing the management of regulated activities and acting as a key point of contact for CQC.
  • c. The Registered Manager, responsible for the daily operational management of the service.

6.6. Oversight and Monitoring of Service Quality, Safety, and Compliance

6.6.1. Governance ensures that The Good Place has robust monitoring systems in place to oversee the quality, safety, and compliance of the services we provide. This includes:-

  • a. Quality assurance systems to evaluate the standard of care delivered.
  • b. Regular audits and inspections covering:-
    • aa. Care quality and safety audits to ensure compliance with Regulation 12 – Safe Care and Treatment.
    • ab. Health and safety checks to assess risks and prevent accidents.
    • ac. Staff training audits to ensure ongoing competency and professional development.
    • ad. Complaints and incident reporting in line with Regulation 16 – Receiving and Acting on Complaints.
  • c. Performance monitoring to assess staff efficiency, response times, and overall service user satisfaction.
  • d. Incident reporting and learning frameworks to address errors, safeguarding issues, and regulatory breaches.
  • e. Regular CQC compliance reviews, ensuring adherence to statutory obligations and best practice guidelines.

6.6.2. Through data-driven decision-making, The Good Place identifies areas for improvement, implements corrective actions, and continuously enhances service quality.

6.7. Engagement with Stakeholders

6.7.1. Governance is also about building strong relationships with stakeholders who are directly or indirectly impacted by our services. These include:-

6.7.2. Service Users and Families:-

  • a. Feedback mechanisms such as surveys, complaints systems, and regular service reviews.
  • b. Person-centred care planning, ensuring users have a say in how their care is delivered.
  • c. Complaints and concerns handling, ensuring a transparent and responsive approach to service improvement.

6.7.3. Staff and Workforce:-

  • a. Employee training and development, ensuring compliance with Regulation 19 – Fit and Proper Persons Employed.
  • b. Whistleblowing policies, allowing staff to report concerns confidentially.
  • c. Performance reviews and supervisions to support professional growth.

6.7.4. Regulatory and External Bodies:-

  • a. Compliance with CQC and local authority requirements.
  • b. Collaboration with NHS partners and safeguarding boards.
  • c. Adherence to UK GDPR and data protection laws when handling sensitive information.

6.7.5. Through effective governance, The Good Place fosters transparency, accountability, and continuous improvement, ensuring a well-led, high-quality domiciliary care service that prioritises the safety and dignity of service users.

7. Organisational Structure

7.1. Our organisational structure provides a clear framework for decision-making, accountability, and effective governance within The Good Place. It ensures that responsibilities are well-defined and that care services are delivered efficiently, safely, and in compliance with CQC regulations.

7.2. By establishing a structured hierarchy, we maintain high standards of leadership, operational efficiency, and care quality, ensuring that every role contributes to the organisation’s success.

7.3. Our organisational structure:-

  • Registered Provider

    The Good Place Home Care Services Limited

    • Nominated Individual & Registered Manager

      Dean Hill

      • Operational Leads

      • Care Co-ordinators

      • Senior Carers

        • Care & Support Workers

7.4. Organisational Structure Chart

7.4.1. Below is a structure chart illustrating the reporting lines and key roles within The Good Place:-

7.4.2. Registered Provider

7.4.2.1. Our Registered Provider is The Good Place.

7.4.2.2. The Registered Provider is the legal entity responsible for the overall management, regulation, and compliance of the domiciliary care service. This role includes:-

  • a. Ensuring that the service meets all legal, regulatory, and ethical requirements.
  • b. Overseeing financial, strategic, and operational governance.
  • c. Maintaining compliance with CQC regulations, Health and Social Care Act 2008, and Care Act 2014.
  • d. Ensuring that effective policies, procedures, and governance structures are in place.
  • e. Responding to CQC inspections, audits, and compliance assessments.

7.4.3. Nominated Individual

7.4.3.1. Our Nominated Individual is Dean Hill.

7.4.3.2. The Nominated Individual is appointed to act on behalf of the Registered Provider and is accountable for supervising the management of regulated activities. Their responsibilities include:-

  • a. Acting as the main point of contact between the provider and CQC.
  • b. Ensuring that the service is well-led and adheres to the CQC fundamental standards.
  • c. Supervising the Registered Manager and other senior leadership roles.
  • d. Ensuring timely action plans for any areas requiring improvement.
  • e. The overall strategic direction, corporate governance, and financial oversight of the company.
  • f. All statutory obligations and adheres to CQC, Health and Social Care Act, and Care Act 2014 requirements.
  • g. Support and scrutiny to the Registered Provider and senior management team.

7.4.4. Registered Manager

7.4.4.1. Our Registered Manager is Dean Hill.

7.4.4.2. The Registered Manager is responsible for the day-to-day running of the service, ensuring that high-quality care is provided in a safe and effective manner. This role is crucial for:-

  • a. Managing care operations, staff, and compliance with all legal requirements.
  • b. Overseeing staff recruitment, training, and performance management.
  • c. Ensuring safe care and treatment in compliance with Regulation 12.
  • d. Implementing and reviewing care policies, risk assessments, and audits.
  • e. Handling complaints, safeguarding issues, and regulatory reporting.

7.4.5. Operational Leads

7.4.5.1. Operational Leads, where appointed, support the Registered Manager in specific areas of operational leadership (for example care coordination, quality and training, rostering or specialist practice).

7.4.5.2. Where Operational Leads are not in post, the Registered Manager will assign delegated responsibilities to a competent senior staff member, document this delegation (including scope, authority and supervision arrangements), and keep this under regular review to ensure effective oversight and continuity.

7.4.5.3. All delegation arrangements will be recorded in our governance records so that lines of accountability remain clear for staff, people using the service and external partners.

7.4.5.4. Designated Safeguarding Lead (DSL):-

  • a. Our Designated Safeguarding Lead is Dean Hill.
  • b. The DSL is responsible for overseeing all safeguarding concerns, ensuring they are recognised, reported and referred in line with local multi-agency procedures, the Care Act 2014 and Regulation 13. The DSL provides advice to staff, maintains safeguarding records, monitors themes and reports safeguarding activity into governance meetings.

7.4.5.5. Information Governance Lead:-

  • a. Our Information Governance Lead is Dean Hill.
  • b. The Information Governance Lead oversees compliance with UK GDPR and the Data Protection Act 2018, including data protection impact assessments (DPIAs) for new systems, staff training on data protection, monitoring of breaches, and advising the Registered Manager and Nominated Individual on information risks.

7.4.6. Care Co-ordinators

7.4.6.1. Care Co-ordinators play a key role in organising and managing service delivery. They:-

  • a. Oversee the scheduling and allocation of care & support workers.
  • b. Maintain communication with service users, families, and staff.
  • c. Ensure that care plans are up-to-date and tailored to individual needs.
  • d. Monitor and address any operational challenges such as staff shortages or care quality concerns.
  • e. Assist in incident reporting, safeguarding, and regulatory compliance.

7.4.7. Senior Carers and Care & Support Workers

7.4.7.1. Senior Carers and Care & Support Workers are the frontline staff delivering direct care and support to service users in their own homes. They:-

  • a. Provide personal care, medication assistance, meal preparation, and companionship.
  • b. Work in line with individualised care plans to ensure person-centred support.
  • c. Adhere to safeguarding policies to protect service users from harm.
  • d. Report any concerns, incidents, or service user changes to senior staff.
  • e. Complete mandatory training and ongoing professional development.

7.4.7.2. Senior Carers will also:-

  • a. Supervise Care & Support Workers where needed.
  • b. Spot check Care & Support Workers as and when required.

8. Governance Responsibilities

8.1. Our governance responsibilities ensure that The Good Place operates in a well-led, safe, and compliant manner, meeting all regulatory and legal obligations. This section outlines how governance is embedded into our organisation through leadership, monitoring, quality assurance, and compliance.

8.2. Culture and Speaking Up

8.2.1. We are committed to a positive, open and inclusive culture where people who use the service, staff and others feel safe to raise concerns, ideas and feedback without fear of blame or reprisal. We support this through our Raising Concerns, Freedom to Speak Up and Whistleblowing Policy and Procedure, open-door management approach, regular team meetings and supervision. Leaders model candour and learning, and we review speaking-up themes at governance meetings to ensure concerns are responded to and used to improve the service.

8.3. Accountability and escalation

8.3.1. Accountability within The Good Place is clear and documented.

  • a. The Nominated Individual provides oversight of regulated activities and holds the Registered Manager to account for operational delivery and compliance. They also provide strategic oversight and hold the Provider to account for quality, safety, compliance and financial sustainability.
  • b. The Registered Manager is accountable for day-to-day quality and safety, staff performance, and implementing governance systems (audits, action plans, risk management and record keeping).
  • c. Care Co-ordinators are accountable for safe scheduling, communication and ensuring care plans are available and up to date for staff delivering care.
  • d. Senior Carers and Care & Support Workers are accountable for delivering care in line with care plans, reporting concerns and completing records accurately and promptly.

8.3.2. Escalation: Any significant concern (for example safeguarding, serious incident, repeated missed calls, medication errors, data breach, or regulatory non-compliance) is escalated immediately to the Registered Manager and, where required, to the Nominated Individual. The Registered Manager ensures that statutory notifications and referrals (for example to the local authority safeguarding team, CQC, police or ICO) are made in line with legal and contractual requirements. Decisions and actions are recorded, monitored and tracked to completion, and learning is fed back into audits, training and practice.

8.4. Managing and Governing the Organisation

8.4.1. We maintain robust governance by implementing structured leadership, oversight mechanisms, and accountability frameworks that support our strategic direction and operational efficiency.

8.4.2. Key governance practices include:-

8.4.3. Regular Management Meetings:-

  • a. Monthly governance and performance meetings to evaluate key performance indicators (KPIs), staffing, financial sustainability, service user outcomes, incidents, complaints, safeguarding, and audit findings.
  • b. Quarterly strategy and quality review meetings to consider trends, review our CQC Single Assessment Framework self-assessment, and agree priorities for improvement.
  • c. Annual business and quality planning sessions to set objectives and align with CQC and legal requirements, including Regulation 17 – Good Governance.

8.4.4. Compliance with CQC Regulations:-

  • a. Adherence to Regulation 17 – Good Governance, ensuring systems are in place to monitor, assess and improve service quality and manage risks.
  • b. Regular self-assessment against the CQC Single Assessment Framework, drawing on evidence from people’s experience, staff feedback, audits, incidents and outcomes.
  • c. Implementation and monitoring of Corrective Action Plans (CAPs) following any CQC feedback, inspections, or identified shortfalls.

8.4.5. Policy and Procedure Management:-

  • a. Policies aligned with Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 to ensure best practices.
  • b. Regular policy reviews and updates based on emerging risks, regulatory updates, and sector best practices.
  • c. Staff training on policy adherence, ensuring awareness and compliance across the organisation.

8.5. Continuous Assessment and Improvement

8.5.1. At The Good Place, we have a comprehensive approach to assessing and monitoring the quality of our service. We use a range of quality assurance systems and processes—including regular audits, performance reviews, feedback collection, and incident monitoring—to ensure that our care is safe, effective, and meets regulatory standards. These systems enable us to identify trends, measure outcomes, and benchmark our performance against national standards.

8.5.2. We triangulate information from audits with people’s feedback, incidents, safeguarding concerns and outcome data so that we can understand the full picture of quality and safety and prioritise improvement actions.

8.5.3. Internal Audits:-

  • a. Quarterly audits covering care quality, staff training, safeguarding, medication management, and infection control.
  • b. Spot-checks and unannounced visits to service users’ homes to assess care delivery.
  • c. Audit reports reviewed by senior management, ensuring recommendations are actioned.
  • d. Learning from audits and CAPAs is shared with staff through meetings, supervision and training, and where appropriate with people using the service (for example, explaining what has changed as a result of their feedback or concerns).

8.5.4. Audit programme (examples and responsibilities)

8.5.4.1. The Good Place maintains an audit plan so we can consistently assess, monitor and improve quality and safety. Audits are recorded, scored where appropriate, and actioned through an improvement plan with named owners and deadlines.

  • a. Care plan and person-centred care audit – quarterly – completed by Registered Manager/ Operational Lead – reviewed by Nominated Individual.
  • b. Medication management audit – quarterly (and after any significant error) – completed by Registered Manager – actions monitored monthly.
  • c. Safeguarding and incident audit – quarterly – completed by Registered Manager – themes reported at governance meetings.
  • d. Complaints and feedback audit – quarterly – completed by Registered Manager – improvement actions tracked to closure.
  • e. Staff file and recruitment compliance audit – quarterly – completed by Registered Manager – oversight by Nominated Individual.
  • f. Training and competency audit – monthly/ quarterly (as scheduled) – completed by Registered Manager/ Care Co-ordinator – actions fed into supervision.
  • g. Health & safety / lone working audit – quarterly – completed by Registered Manager – escalated risks added to the Risk Register.
  • h. Data protection and record quality audit – quarterly – completed by IG/ IT lead (or delegated competent person) – reviewed by Registered Manager and Nominated Individual.

8.5.4.2. Audit results and action plans are discussed at monthly governance meetings and retained as evidence of continuous improvement.

8.5.4.3. Action Plans for Improvement:-

  • a. Corrective and preventive action plans (CAPAs) implemented for any identified non-compliance.
  • b. Staff performance reviews and competency checks to ensure adherence to care standards.
  • c. Benchmarking against national standards, using sector data to measure service effectiveness.

8.5.4.4. Staff Training and Development:-

  • a. Mandatory and ongoing professional development training for all staff, in line with the Care Certificate (where applicable) and role requirements.
  • b. Planned one-to-one supervision for all staff at least every three months, and a formal annual appraisal, to monitor performance, wellbeing and development needs.
  • c. Workforce planning and skills gap assessments to ensure we have the right numbers of staff with the right skills mix to deliver safe, person-centred care.

8.5.4.5. Continuous improvement is central to our governance framework. We regularly review audit outcomes, feedback, and performance data to identify areas for development. Where improvements are required, we implement targeted action plans, allocate resources to support change, and set measurable goals for improvement. Progress is tracked through regular management meetings and audits, and successful improvements are embedded into policy and practice. We also promote a culture of learning, encouraging staff to contribute ideas and take part in quality improvement initiatives.

8.6. Seeking and acting on feedback from people using the service

8.6.1. The Good Place actively seeks feedback from people who use our service (and, where appropriate and with consent, their relatives/representatives) so that we can monitor and improve quality and safety. We gather feedback in accessible ways, in line with the Accessible Information Standard, including:-

  • a. asking for feedback during initial assessments and care plan reviews;
  • b. routine phone calls/check-ins by the office team;
  • c. spot-checks and quality assurance visits;
  • d. compliments, complaints and concerns (formal and informal);
  • e. surveys (paper, digital or telephone) offered in accessible formats; and
  • f. feedback following significant events (for example after a service change or incident).
  • g. feedback from professionals and partner organisations (for example local authority commissioners, community health services, GPs and safeguarding teams) gathered through routine contact, contract monitoring and review meetings.

8.6.2. How we act on feedback: All feedback is recorded, reviewed and responded to appropriately. The Registered Manager Dean Hill  is responsible for ensuring:

  • a. feedback is logged and categorised (for example communication, missed calls, staff conduct, care quality, safety);
  • b. urgent concerns are acted on immediately, including escalation to safeguarding processes where needed;
  • c. themes and trends are analysed at governance meetings;
  • d. improvement actions are agreed with named owners and deadlines and tracked to completion; and
  • e. learning is shared with staff through supervision, team updates and training.

8.6.3. We will also communicate improvements to people using the service (for example “You said, we did”) where appropriate, so they can see how their feedback has influenced service development.

8.6.4. We foster a culture of openness and continuous improvement by actively engaging with service users, families, staff, and external stakeholders.

8.6.5. Service User Engagement:-

  • a. Annual and quarterly service user satisfaction surveys to collect direct feedback.
  • b. Regular care plan reviews with service users and their families to ensure needs are met.
  • c. Feedback reports analysed and acted upon to improve service quality.

8.6.6. Staff Consultations and Engagement:-

  • a. Monthly staff forums and team meetings to discuss service performance, policy updates, and challenges.
  • b. Whistleblowing policies to protect staff who report concerns.
  • c. Open-door management policy to encourage staff participation in decision-making.

8.6.7. Complaints Handling:-

  • a. Clear, accessible complaints procedure, in line with Regulation 16 – Receiving and Acting on Complaints.
  • b. Independent investigation of complaints, ensuring transparency and accountability.
  • c. Trends analysis of complaints to identify systemic issues and implement corrective actions.
  • d. Making sure complaint information and processes are available in accessible formats, in line with the Accessible Information Standard, and offering support (for example advocacy or interpreters) so that everyone can raise concerns.

8.7. Assessing, Monitoring, and Improving Quality & Safety

8.7.1. Ensuring high standards of care, safety, and compliance is at the core of our governance framework.

8.7.2. Risk Management and Health & Safety:-

  • a. Regular risk assessments to identify and mitigate potential hazards in service users’ homes and staff work environments.
  • b. Proactive risk mitigation plans implemented to reduce incidents, accidents, and safeguarding concerns.
  • c. Lone worker safety policies and emergency response procedures to protect care staff.

8.7.3. We identify risks through audits, incidents, safeguarding concerns, complaints, feedback, staff reports and business monitoring. Each risk is:-

  • a. logged on the Organisational Risk Register with a named owner;
  • b. rated for likelihood and impact;
  • c. assigned controls and actions with deadlines;
  • d. reviewed at least monthly (or sooner where risk is high); and
  • e. escalated to the Nominated Individual/Board where the risk is significant, increasing, or requires additional resources.
  • f. Learning from risks is shared with staff through team communications, supervision and training updates.

8.7.4. Business continuity and emergency planning:-

  • a. We maintain a Business Continuity Plan that covers risks such as loss of premises or IT systems, severe weather, pandemic, fuel shortages and significant staffing shortages.
  • b. The plan prioritises the safety and welfare of people using the service and includes arrangements for communication with people, families, staff, commissioners and other partners.
  • c. The Business Continuity Plan is reviewed at least annually and after any major incident, with learning used to update procedures and training.

8.7.5. Incident Reporting and Learning Culture:-

  • a. Mandatory incident reporting system, covering medication errors, falls, safeguarding concerns, and complaints.
  • b. Root Cause Analysis (RCA) for significant incidents, ensuring lessons are learned and recurrence is prevented.
  • c. Quarterly incident review meetings to share findings and improve practice.

8.7.6. Safeguarding Compliance:-

  • a. Strict adherence to safeguarding policies, ensuring compliance with Regulation 13 – Safeguarding service users from abuse and improper treatment, the Care Act 2014, and local multi-agency safeguarding procedures.
  • b. A Designated Safeguarding Lead (DSL) responsible for ensuring prompt action on safeguarding concerns, including making referrals to the local authority and notifications to CQC where required.
  • c. Staff safeguarding training refreshed at least annually, ensuring competency in recognising, reporting and responding to abuse and neglect.

8.8. Record Keeping and Data Protection

8.8.1. We ensure accurate, secure, and confidential management of service user records, staff files, and operational data.

8.8.2. Accurate and Secure Record-Keeping:-

  • a. Service user records include detailed care plans, risk assessments, medical history, and consent forms.
  • b. Staff records include background checks, employment contracts, training logs, and performance reviews.
  • c. Digital record-keeping system with encrypted access, ensuring data integrity.

8.9. Risk management and risk assessments

8.9.1. We maintain an Organisational Risk Register (clinical, safeguarding, IPC, workforce, finance, business continuity). Each risk has an owner, controls, and a target review date. At service level, we complete and review individual risk assessments (e.g., moving & handling, medication, home environment, infection control) and embed controls in care plans. High or emerging risks are escalated at the weekly operations meeting, with actions tracked to closure and reported to the Nominated Individual.

8.9.2. The Organisational Risk Register is reviewed regularly at governance meetings and escalated risks are discussed with the Nominated Individual to ensure appropriate mitigation and resourcing.

8.10. UK GDPR and Data Protection Compliance

8.10.1. The Good Place is committed to full compliance with both the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We ensure that all staff understand their responsibilities under these laws and that robust processes are in place to protect the privacy and confidentiality of all service user and staff data.

8.10.2. Further detail on how we meet our data protection and information governance responsibilities is set out in our Confidentiality and Data Protection (UK GDPR) Policy and Procedure.

  • a. Strict adherence to the UK General Data Protection Regulation (UK GDPR), ICO, and the Data Protection Act 2018, ensuring all personal data is handled lawfully, fairly, and transparently.
  • b. Regular staff training on data protection laws and handling of sensitive information.
  • c. Data security audits conducted quarterly to identify risks and ensure compliance.

8.10.3. Records we maintain

8.10.3.1. We properly maintain and store records relating to:-

  • a. People who use our service: assessments, care plans, risk assessments, consent, MAR charts (where applicable), daily notes, reviews, incident records, safeguarding records, complaints/ compliments relating to the person, and correspondence relevant to care.
  • b. Staff: recruitment checks, contracts, training and competency records, supervision/appraisal notes, disciplinary/grievance records (where applicable), and role-related qualifications.
  • c. Management and governance procedures: policies and version control, audit reports, action plans, meeting minutes, KPI reports, risk register, business continuity plans, and data protection records.

8.10.4. Secure storage, access control and quality of records

8.10.4.1. Records are stored securely (digital and/or locked storage as applicable). Access is role-based and limited to authorised staff on a need-to-know basis. We maintain appropriate audit trails for access and changes, and we check record quality through routine spot checks and audits.

8.10.4.2. We maintain appropriate technical and organisational security measures (for example strong access controls, multifactor authentication where available, secure configuration and regular updates) for all digital systems used to store or process personal data. Cyber security risks are included on our Risk Register and reviewed at governance meetings.

8.10.5. Retention and disposal

8.10.5.1. We retain records only for as long as necessary and in line with legal and contractual requirements. When records reach the end of their retention period, they are disposed of securely (for example, secure deletion and/or confidential shredding).

8.10.6. Data breaches and subject access requests (SARs)

8.10.6.1. Any suspected data breach is reported immediately to the Information Governance Lead: Dean Hill

8.10.6.2. We will investigate, reduce risk, record actions taken, and where required report to the relevant authorities in line with UK GDPR and the Data Protection Act 2018.

8.10.6.3. People have the right to request access to their personal data. Requests are handled promptly and normally within one month, in line with data protection requirements. Identity checks are completed before disclosure, and any extensions or exemptions are applied lawfully and documented.

8.10.7. Business continuity and backups

8.10.7.1. We take reasonable steps to ensure records remain available and protected, including secure backups and contingency arrangements so that essential information is accessible to deliver safe care.

8.10.7.2. We test our business continuity and data recovery arrangements periodically (for example through table-top exercises or system recovery tests) and use learning from these tests to strengthen our resilience.

8.11. Compliance with Statutory Requirements

8.11.1. We are committed to full compliance with all legal, ethical, and professional regulations governing domiciliary care services.

8.11.2. CQC Registration and Compliance:-

  • a. Ongoing compliance with CQC regulations, ensuring adherence to fundamental standards of care.
  • b. Regular self-assessment against the CQC Single Assessment Framework and use of this evidence to inform governance discussions, risk management and quality improvement plans.

8.11.3. Mental Capacity Act 2005 and Care Act 2014 Compliance:-

  • a. Ensuring service users’ rights and decisions are respected, in line with the Mental Capacity Act 2005.
  • b. Comprehensive staff training on mental capacity assessments and best interest decision-making.
  • c. Adherence to the Care Act 2014, ensuring person-centred care and safeguarding responsibilities are met.

8.11.4. Mental Capacity, consent and restrictive practices governance:-

  • a. We monitor whether capacity assessments, best interest decisions and consent records are completed and reviewed appropriately, through regular care plan and record audits.
  • b. Any restrictive practice (for example use of assistive technology, environmental controls or agreed restrictions in a person’s care plan) is risk-assessed, proportionate, time-limited and reviewed, with clear documentation of legal and ethical justification.
  • c. Learning from MCA/ consent audits and any concerns raised by people, families or professionals is fed into staff training, supervision and policy review.

8.11.5. Duty of Candour (Regulation 20):-

  • a. Transparent communication with service users, families, and regulatory bodies regarding significant incidents.
  • b. Open disclosure policies, ensuring timely and honest responses to adverse events.
  • c. Training on Duty of Candour, ensuring staff understand their responsibilities when something goes wrong.
  • d. Governance meetings include review of notifiable safety incidents and Duty of Candour compliance to ensure that apologies, explanations and remedial actions are timely, compassionate and fully documented.
Elderly hands on a walking sitck

We're becoming a fully regulated service

While we are not currently regulated, meaning there are some services we cannot currently provide, we are in the process of registering to become a fully regulated service.

CQC