Regulation 17 Explained: How to Build a Governance Framework That Satisfies CQC Inspectors
Of all the CQC regulations, Regulation 17 — Good Governance is the one that separates clinics that survive inspection from those that achieve Outstanding. It’s also the regulation that causes the most confusion, because “governance” can feel abstract until an inspector is sitting in front of you asking for your risk register.
This guide breaks down exactly what Regulation 17 requires for aesthetic clinics, and how to build a governance framework that’s evidenced, maintained, and inspection-ready.
What Regulation 17 Actually Requires
Regulation 17 of the Health and Social Care Act 2008 places a legal duty on registered providers to have effective governance systems in place. Specifically, this means:
- Systems for assessing, monitoring, and improving the quality and safety of services
- Systems for assessing and mitigating risks
- Maintaining accurate, complete, and contemporaneous records
- Seeking and acting on feedback from patients, staff, and other stakeholders
- Operating with transparency and having effective oversight of the service
In plain terms: your clinic must have a living governance framework — not a folder of documents created at registration and never updated.
The Four Pillars of a Compliant Governance Framework
Pillar 1: A Live Risk Register
A risk register is not a one-time exercise. It’s a working document that reflects the current risk landscape of your clinic. Inspectors want to see:
- Identified risks across clinical, operational, and premises categories
- Risk ratings (likelihood × impact) for each item
- Named owners for each risk
- Mitigation actions recorded and dated
- Evidence the register has been reviewed — with a date stamp
A common failure: clinics create a risk register at registration, then don’t touch it for two years. An undated or stale register tells an inspector your governance is performative, not functional.
Pillar 2: Clinical Audit Schedule
Regulation 17 requires you to monitor the quality of your services. For aesthetic clinics, this means completing regular clinical audits across key areas:
- Consent form completion rates and quality
- Medical history documentation
- Adverse event and complication rates
- Prescription and medicines management
- Staff training compliance
Audits must be documented, signed off, and — critically — show evidence that findings led to action. An audit that identified a gap but led to nothing is worse than no audit, because it shows you knew about a problem and didn’t act.
Pillar 3: Policy Management
Your clinic policies must be reviewed, updated, and formally acknowledged by staff. Inspectors check:
- Whether policies have a version number and review date
- Whether they’ve been reviewed within the last 12 months
- Whether staff have formally acknowledged they’ve read the policy
- Whether policies reflect current legislation — including post-2025 prescribing rules
Pillar 4: Incident and Complaint Management
Every aesthetic clinic will have incidents — minor adverse reactions, complaints, near-misses. What differentiates Good and Outstanding clinics is what happens next. Inspectors look for:
- A log of all incidents, complaints, and concerns — even minor ones
- Evidence of investigation — what happened, why, and what was learned
- Documented changes made as a result
- Communication back to the patient where appropriate (Regulation 20 — Duty of Candour)
The Evidence Challenge — Making Governance Visible
Most clinic owners understand what good governance looks like. The challenge is maintaining it across a busy clinical environment — and being able to surface that evidence quickly when required.
INTENTIQ™‘s Governance Audit Framework addresses this directly. The platform maintains a scheduled audit programme across 18 audit types — covering CQC-mapped compliance areas from medicines management to fire safety to DBS renewal. Each audit is assigned, tracked, and timestamped. When an item is completed, it’s evidenced in the system with the name of the person who signed it off and the date.
The result: a real-time compliance dashboard that shows exactly where your governance framework stands — not just on inspection day, but every day.
A Practical Governance Action Plan
- Create or update your risk register — review it now, date it, assign owners to each risk
- Map your audit schedule — what needs to be audited, how often, and by whom
- Review all policies — check review dates, update any that reference pre-2025 prescribing rules
- Confirm staff policy acknowledgements are on file for every current employee
- Review your incident log — document the process and confirm it’s accessible
- Check your complaint handling process — can you demonstrate complaints were investigated and resolved?
Governance Is Evidence of Leadership
When a CQC inspector assesses the Well-Led domain, they’re not just checking that policies exist. They’re trying to understand whether the person running your clinic has genuine oversight of its quality and safety. Governance documentation is the evidence of that oversight.
INTENTIQ™ was designed to make that oversight effortless — not by replacing clinical judgement, but by ensuring the evidence of good practice is captured, maintained, and always accessible.
Want to see INTENTIQ™’s Governance Audit Framework in action? Book a demonstration and we’ll walk you through how it maps directly to Regulation 17.
See every one of INTENTIQ™’s 18 audit modules — each mapped to a specific CQC regulation, with full detail on what it captures and why inspectors require it.