Guide
Healthcare provider annual compliance checklist
Annual checklist of recurring compliance obligations for CQC-registered healthcare providers covering registration, workforce, clinical governance, premises, data protection, and policy reviews.
Check your healthcare business meets all annual rules. Pay your CQC fee, update staff registrations, review policies, and check insurance covers are in place. Do this before your CQC inspection every year.
- Pay CQC annual fee (from £1,164, due in April)
- Check staff registrations (GMC, NMC, HCPC)
- Renew insurance (employers' liability, £5m minimum)
- Update DBS checks every 3 years
- Complete mandatory staff training (safeguarding, IPC, fire)
- Do medicines audits and check expiry dates
- Review fire risk assessment annually
- Submit NHS Data Security Toolkit by 30 June
- Update all policies (safeguarding, complaints, data)
- Check right to work for staff with time-limited visas
Use this checklist to verify that your CQC-registered healthcare service meets its recurring annual compliance obligations. Work through each section and address any gaps before your next CQC inspection or annual governance review.
-
CQC annual fee paid (due each April)
-
CQC registration details up to date (locations, nominated individual, registered manager)
-
All professional registrations verified (GMC, NMC, GDC, GPhC, HCPC)
-
Employers' liability insurance renewed (minimum £5 million cover)
-
Public liability insurance renewed
-
Professional indemnity insurance renewed
-
Medical malpractice insurance renewed (if applicable)
-
ICO data protection fee paid (due annually on registration anniversary)
-
DBS checks current for all staff in regulated activity (recheck every 3 years)
-
DBS Update Service status checked for subscribed staff
-
Fit and proper persons requirement reviewed for directors and registered manager
-
Mandatory training completed by all staff (safeguarding, IPC, fire, manual handling, MCA/DoLS, medicines, basic life support)
-
Staff appraisals completed for all employees
-
Clinical supervision sessions completed and recorded
-
Professional revalidation dates tracked and upcoming renewals flagged
-
Right to work checks repeated for time-limited permissions before expiry
-
Medicines audit completed (stock check, expiry dates, storage conditions)
-
Controlled drugs quarterly stock check done and CD register reconciled (Schedule 2)
-
Infection prevention and control audit completed and action plan in place
-
Clinical waste contracts reviewed and consignment notes filed
-
Incident reports reviewed and learning disseminated to staff
-
Complaints log reviewed and themes reported to governance meeting
-
Clinical policies reviewed within their stated review dates
-
Duty of candour notifications completed for all notifiable safety incidents
-
Fire risk assessment reviewed (annually minimum)
-
Fire drill conducted and evacuation procedure tested
-
Equipment maintenance and calibration up to date (PAT testing, medical devices)
-
Health and safety risk assessments reviewed
-
Legionella risk assessment current and water management plan followed
-
Emergency procedures tested and staff briefed
-
First aid supplies checked and replenished
-
Waste disposal arrangements reviewed (clinical and non-clinical streams)
-
NHS Data Security and Protection Toolkit (DSPT) submitted by 30 June deadline
-
Privacy notices reviewed and up to date
-
Subject access request process tested
-
Data breach reporting procedure reviewed
-
Information governance training completed by all staff
-
Caldicott Guardian role assigned and active (if processing NHS patient data)
-
Safeguarding adults and children policy reviewed
-
Whistleblowing (raising concerns) policy reviewed
-
Business continuity plan reviewed and tested
-
Complaints procedure reviewed
-
Medicines management policy reviewed
-
Infection prevention and control policy reviewed
-
Health and safety policy reviewed
-
Recruitment and selection policy reviewed (including DBS procedures)
-
Data protection and confidentiality policy reviewed
What to do next
For items where you identified gaps:
- See Register with the CQC for registration update procedures
- See Healthcare professional registration for revalidation guidance
- See Medicines and controlled drugs compliance for medicines audit procedures
- See Healthcare data protection for DSPT and information governance
- See Clinical governance and quality improvement for governance framework guidance