Reading time 3 mins
Introduction
The Quality Audit Toolkit provides an auditable event pathway to capture a baseline snapshot of a specific quality concern prior to commencing a Quality Improvement (QI) project and to follow that work through to assured, sustainable improvement. It standardises baseline measurement, risk triage, governance approval, iterative testing (PDSA), assurance and closure so improvements are traceable, evidence‑based and embedded into routine practice.
Legislative Requirements
- Care Act 2014 — QI activity must support delivery of safe, effective and person‑centred care, promote wellbeing and prevent harm. Organisations must identify and mitigate risks from poor quality care, maintain continuous improvement systems and respond timely to identified service failures. Failure to act on QI findings may amount to unsafe care, safeguarding failures or neglect.
- Mental Capacity Act 2005 — where QI initiatives affect care decisions for people who may lack capacity, projects must document capacity considerations, apply best‑interest decision‑making, use least‑restrictive options and involve advocates as appropriate.
- Data Protection Act 2018 / UK GDPR — QI projects handling personal or health data must establish lawful bases for processing, apply data minimisation, use pseudonymisation/anonymisation where possible, limit retention and maintain secure audit trails of access and sharing.
Regulatory Guidance
- CQC (England) — QI should evidence compliance with Regulation 12 (Safe care and treatment) and Regulation 17 (Good governance). Organisations must keep auditable records of QI activity, ensure staff competence (Regulation 18) and feed QI outcomes into incident reporting and Duty of Candour where harm is identified.
- Care Inspectorate (Scotland) — expects demonstrable QI activity within governance and evidence of continuous improvement aligned to Health & Social Care Standards.
- Care Inspectorate Wales (CIW) — QI is integral to meeting national minimum standards and must be evident in leadership, monitoring and improvement arrangements.
Statutory Guidance
- Accountability — QI projects must sit within clear governance structures with named owners, documented decision‑making and board‑level oversight of risks, progress and outcomes.
- Reporting — issues, risks and outcomes identified through QI must be reported in line with statutory and local frameworks (safeguarding, commissioners, regulators).
- Safeguarding — QI activity must identify and mitigate safeguarding risks and prompt referrals where poor quality care has caused or may cause harm.
- Duty of Candour — apply where QI uncovers incidents or failures that have caused or could cause reportable harm.
HealthCare Guidance
- Department of Health & Social Care / NICE — align QI priorities with national standards and measurable indicators. Use NICE quality standards and guidance to set improvement aims and measures.
- Scottish Government / SIGN — embed QI in clinical governance, drawing on SIGN and Healthcare Improvement Scotland for whole‑system approaches and sustaining improvement.
- Wales H&S Service Group — QI should support national clinical standards, continuous monitoring of outcomes and contribute to national safety priorities.
- Clinical & Digital Safety — where QI changes clinical systems or decision support, apply controlled change processes, testing and safety assurance before deployment.
Evidence Based Practice
- Operate a central QI governance framework to prioritise projects by risk, impact and strategic alignment.
- Use recognised QI methodologies (Model for Improvement, PDSA cycles) with an explicit measurement plan: baseline, process and outcome metrics.
- Ground interventions in national evidence (NICE, SIGN) and local intelligence (incidents, complaints, audits, patient/staff feedback).
- Ensure iterative testing, robust data collection, and documented sustainability checks before project closure.
Clinical governance and Safety (NHS)
- Embed QI outputs into risk registers, board reporting and quality assurance, with named owners and verification evidence for actions.
- Require formal clinical risk assessments for proposed changes and readiness/rollback plans for system or pathway modifications.
- Provide QI training and competency assurance for staff leading initiatives; maintain peer review and audit of QI outputs.
- Link QI activity with incident reporting, PSIRF responses and service improvement programmes to maximise organisational learning.
PSIRF
Integrate QI with PSIRF where improvement work arises from or addresses patient safety incidents. Focus on system‑based learning, select proportionate review methods, avoid individual blame and embed corrective actions into the Patient Safety Incident Response Plan. Define escalation triggers where QI uncovers recurrent harm or systemic vulnerability.
Using the Toolkit — Practical Steps
- Initiate & Log — record the quality concern as an event: date, location, scope, brief description and initial risk flag to create an auditable baseline.
- Define Scope & Baseline — identify affected services, cohorts and metrics; capture baseline measurement and supporting evidence (audit extracts, incident counts, surveys).
- Risk Assess — complete a clinical/safeguarding risk assessment to determine immediate mitigations required before QI activities proceed.
- Plan & Prioritise — agree aim (SMART), measures (outcome/process/balancing), methodology (PDSA), resource needs, owners, timeline and governance approvals.
- Test & Implement — run iterative PDSA cycles, document changes and measure impact against baseline; apply controlled implementation for system or digital changes with testing and rollout controls.
- Communicate — maintain a communications log of stakeholder engagement, staff briefings and patient/carer involvement; record legal bases for any data sharing.
- Assure & Verify — perform audits, spot checks and sustainability testing to verify change adoption and measure outcomes for sign‑off.
- Close & Sustain — close the event when sustained improvement is demonstrated; embed changes into policy, training and routine monitoring and update governance records.
Templates & Data Fields (recommended)
- Project reference, status (open/closed), priority, date opened and project owner.
- Concern summary, detailed description, baseline measures and supporting evidence (audit extracts, incident counts, survey data).
- Affected services/locations, patient cohorts, digital systems and pathways implicated.
- Risk assessment: immediacy, likely harm, safeguarding flag, regulator/commissioner notification needs.
- QI plan: aim statement, measures (outcome/process/balancing), methodology (PDSA), milestones and target dates.
- Actions & interventions: description, owner, due date, completion evidence and verification notes.
- Communications log: staff briefings, patient/carer involvement, governance approvals and dissemination records.
- Assurance: audit results, monitoring data, sustainability checks and board sign‑off.
- Data protection fields: lawful basis, pseudonymisation/anonymisation approach, retention and access metadata.
Monitoring, Audit and Reporting
- Maintain a QI register/dashboard showing open projects, age, progress against measures, % implemented and assurance status.
- Report regular progress to Quality & Safety Committees and Boards with trend analysis, exceptions and closed‑loop evidence.
- Audit samples of closed projects to confirm sustained change, documentation quality and embedding into operational practice.
- Link QI outcomes to incident, safeguarding and commissioning data to identify system‑level improvements or unintended consequences.
Value Proposition
- Delivers a single, auditable workflow to capture baseline concerns, run QI activity and evidence sustained improvement across services.
- Enables timely mitigation of identified risks, reduces regulatory exposure and demonstrates governance for inspections.
- Integrates QI with PSIRF, safeguarding and board assurance so improvements address root causes rather than symptoms.
- Supports data‑driven decisions, staff engagement and transfer of learning into policy, training and service redesign.
References
- Care Act 2014
- Mental Capacity Act 2005
- UK GDPR / Data Protection Act 2018
- Department of Health & Social Care (DHSC)
- Scottish Government — Health & Social Care Directorate
- Health & Social Services Group (Wales)
- CQC Regulations (2014)
- Care Inspectorate — Health & Social Care Standards (Scotland)
- Care Inspectorate Wales (CIW) — National Minimum Standards
- NICE (England/Wales)
- Scottish Intercollegiate Guidelines Network (SIGN)
- NHS Clinical Safety Standards
- Patient Safety Incident Response Framework (PSIRF)
Disclaimer
Radar Healthcare provides configuration templates and implementation guidance to support effective use of the platform. This toolkit summarises legislative, regulatory and practical considerations for quality audits and Quality Improvement projects and is for general guidance only. It does not constitute legal, clinical or data protection advice. Radar Healthcare acts as a data processor under customer instruction. The customer, as data controller, remains responsible for assessing and managing data protection and compliance obligations and for determining lawful processing.
