Home Resources Policies for CQC registration

What policies do I need for CQC registration?

The core policies every clinic must hold, the extra ones your regulated activities decide, and how to keep them inspection-ready - a plain-English answer to one of the most common CQC questions.

Last reviewed: June 2026 · Written by the BarkerScott compliance team

In short
To register with the CQC you need a core set of written policies that show your service is safe, effective, caring, responsive and well-led. At minimum, expect to hold safeguarding, infection prevention and control, consent and mental capacity, complaints, health and safety, safer recruitment, medicines management, records and data protection, duty of candour and whistleblowing policies. The exact list depends on your regulated activities, but every clinic needs evidence that these areas are governed, current and understood by staff.

Why policies matter for registration

The CQC does not register a clinic because it owns a folder of documents. It registers because you can demonstrate that the way you run the service keeps people safe and meets the fundamental standards set out in the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014. Policies are the written backbone of that demonstration. They tell an inspector what you intend to do, who is responsible, and how you respond when something goes wrong.

A policy that sits unread on a shared drive carries no weight. Inspectors look for policies that are dated, version-controlled, signed off by a named accountable person, and matched by what staff actually do. The document and the practice have to agree.

The core policies every clinic needs

The following policies form the baseline for almost every healthcare provider applying to register, regardless of sector.

Safeguarding adults and children. Separate or clearly combined policies covering both, with named safeguarding leads, local authority referral routes and links to your training records. This is one of the first things an inspector checks.
Infection prevention and control. Your IPC policy should reflect your premises, your decontamination processes and your audit schedule. Aesthetic and minor-surgery clinics need more detail here than a remote telehealth service.
Consent and the Mental Capacity Act. Cover how informed consent is obtained and recorded, cooling-off periods where relevant, and how you assess capacity. Cosmetic and weight-loss services attract particular scrutiny on consent.
Complaints. A clear, accessible complaints procedure with timescales and escalation to the relevant ombudsman or regulator. Patients must be able to find it easily.
Health and safety. Including risk assessments, COSHH where chemicals are used, and your general duty of care to staff and patients.
Safer recruitment. DBS checks, right-to-work, professional registration verification, references and induction. Inspectors will sample staff files against this policy.
Medicines management. Storage, prescribing, controlled drugs where applicable, cold chain and stock control. Weight-loss and ADHD services need this written tightly because of the medicines involved.
Records management and data protection. GDPR-compliant handling of patient records, retention periods, subject access requests and breach reporting.
Duty of candour. Your process for being open and honest when something goes wrong, in line with Regulation 20.
Whistleblowing. How staff can raise concerns safely, including external routes if internal ones fail.

Policies that depend on your sector

Beyond the core, your regulated activities decide what else you need. A good policy pack is built around your specific service rather than a generic template.

Aesthetic and cosmetic clinics typically need chaperone, sharps and clinical waste, anaphylaxis and emergency response, photography and consent for imaging, and a clear complications and adverse-event procedure. Our aesthetic clinic compliance guidance sets out the full sector list.
GP surgeries and private GP services need prescribing governance, repeat prescribing, results handling, referral management, significant event analysis and a wider clinical governance framework.
ADHD and mental health services need controlled drugs handling, titration and monitoring protocols, transfer of care, and robust diagnostic and prescribing governance given the medicines involved.
Weight-loss clinics need prescribing policies for GLP-1 and similar medicines, patient eligibility and screening, monitoring and follow-up, and clear advertising compliance.
Telehealth and remote services need identity verification, safeguarding at a distance, technology and connectivity failure procedures, and prescribing without a face-to-face consultation.

Supporting documents that sit alongside policies

Registration is not only about policies. The CQC also expects a Statement of Purpose, which is a legal requirement describing your aims, regulated activities, registered manager and locations. You will also need staff training matrices, risk assessments, audit schedules and a business continuity plan. These turn your policies from intentions into a working management system.

How many policies is enough

There is no fixed number, and more is not better. A small single-clinician aesthetic service might run well on around twenty-five well-written policies. A multi-site private GP group will need considerably more. The test is coverage and honesty: every area of risk in your service should be governed by a policy that reflects what you genuinely do. Padding your folder with irrelevant templates signals to an inspector that the documents were bought rather than embedded.

Keeping policies current

Policies are not a one-off task. Each should carry a review date, usually annual, and a named owner. When guidance changes, when you add a service, or when an incident reveals a gap, the relevant policy is updated and re-dated. A policy last reviewed three years ago undermines trust in everything else. Running a mock inspection before your real one is the fastest way to find out whether your policies hold up under questioning.

Practical checklist

Use this to sense-check your policy suite before you submit your application.

  • Every core policy listed above is present, dated and version-controlled
  • Each policy names an accountable owner and a review date
  • Sector-specific policies match your regulated activities
  • Your Statement of Purpose is complete and consistent with your policies
  • Safeguarding leads are named and trained, with referral routes included
  • Staff have read and signed off the policies relevant to their role
  • Training records align with what your policies require
  • Risk assessments exist for your premises and procedures
  • A complaints procedure is visible and accessible to patients
  • Medicines management reflects the actual medicines you handle
  • Records and data protection meet current GDPR requirements
  • A business continuity plan covers your key failure scenarios
A quicker route
Rather than build every policy from scratch, our sector packs give you the complete, expert-written set for your service - editable, branded as your own and ready to embed. See the compliance packs by sector.

Frequently asked questions

Policies for CQC registration

Get an inspection-ready policy set

Complete, expert-written CQC policy and risk-assessment packs by sector - downloadable instantly and ready to brand as your own.

Browse packs by sectorFree mock inspection
Important: This page is general information to help you understand CQC requirements — it is not legal advice and is not affiliated with or endorsed by the Care Quality Commission. Regulations and CQC's assessment approach change over time; always check the current position on cqc.org.uk and have a qualified professional review anything specific to your organisation.