The gap between completing an audit and learning from one
Most care homes and adult social care services complete audits. Medication audits, infection control audits, care plan audits, health and safety audits: the list is long, and for most registered managers, working through it is a significant part of the governance year. The audits are completed. Scores are recorded. The folder is filed.
That is where many services stop.
CQC inspectors who review audit records are not looking for evidence that audits were completed. They are looking for evidence that audits drove improvement. Those are different things, and the difference is what separates a service rated Requires Improvement under Well-Led from one rated Good.
An audit without a dated action plan is a photograph of a problem. It is not evidence that anything changed.
The CQC draft assessment framework for adult social care (2026) is specific about this under the Improvement, innovation and learning KLOE within the Well-Led key question. At Good level, the framework expects staff and leaders to understand how to drive improvement through consistent approaches, including measuring outcomes and acting on what is found. At Outstanding level, it expects a fully embedded and systematic approach to quality improvement, with learning used to inform future processes. Completing an audit and filing it does not meet either standard.
What the framework expects from audit processes
The Governance and management KLOE within Well-Led requires effective systems for monitoring and managing service performance and risk. At Good level, this includes evidence that quality assurance systems are operating and that the service has a clear picture of its own compliance position. The audit cycle is central to this, but only if the cycle is complete.
A complete audit cycle has four stages: conduct the audit and record the findings; produce a dated action plan that identifies who is responsible for addressing each gap and when; implement the actions; and review the action plan at a later date to confirm what changed. The fourth stage is the one most commonly missing. Services complete the first three and move on to the next audit. The cycle is never closed, which means there is no evidence of learning.
Regulation 17 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 requires providers to assess, monitor and improve the quality and safety of services. A sequence of audits that identifies the same gaps year after year, with no evidence that actions were taken or sustained, is not evidence of compliance with this regulation. It is evidence that the monitoring function is working but the improvement function is not.
Under the Safety culture KLOE within the Safe key question, the framework also expects the service to look for safety-related themes and trends. The audit record is a primary source for this analysis. Services that review their audit results over time, identify recurring themes, and respond to those themes with structural changes rather than one-off fixes, demonstrating exactly the kind of sustained learning CQC expects.
What strong audit evidence looks like
A dated findings report for every audit. Every audit should produce a written record of what was found: not just a score or a checklist, but a note of what was observed, what records were reviewed, and what the specific gaps were. Without this, the action plan has no foundation and the inspector has no context for understanding what the service found and what it did about it.
A specific, owned action plan. Each gap identified in the audit should become a specific action in a plan: what needs to happen, who is responsible, and when it will be completed. Actions recorded as "improve documentation" with no owner and no deadline are not governance evidence. Actions recorded as "all staff to be reminded at the team meeting on [date] that incident records must include an outcome, and [named person] to review compliance at the next monthly audit" are.
Evidence that actions were completed. The action plan should be signed off when actions are completed, with a note of what was done. Where the action required a change to a document, the updated document should be stored alongside the plan. Where the action required a conversation with staff, a note of that conversation (or a supervision record referencing it) should be attached. Evidence of completion is what closes the cycle.
A review that asks whether anything actually changed. At the next audit, the comparison matters. Were the gaps identified last time still present? Running a structured mock inspection alongside your audit cycle is one of the most effective ways to check whether changes to practice have actually held, not just that actions were completed. Have they been addressed? If the same finding appears for the second time, what does that mean? What has the service done differently in response? This pattern of review over time is the evidence of a service that learns, not just a service that monitors.
Trend analysis across the audit year. Looking at the audit record across twelve months, are there recurring themes? A service that completes monthly medication audits and notices that errors cluster around weekend shifts has useful, actionable data. A service that completes the same audits and files them without comparing them has data it is not using. The analysis does not need to be complex. A brief, dated note in the governance meeting minutes, for example that "medication audit scores have improved since the agency induction process was updated", is evidence of a service that connects its audit findings to its improvement activity.
How AlwaysReady supports your audit cycle
The most common reason audit cycles are not closed is that the action plan and the evidence of follow-up end up in different places. AlwaysReady gives you a single location to store audit records, action plans and completion evidence, linked to the KLOEs they support.
Upload audit reports and action plans linked to the relevant KLOE. Store your medication audit report, the resulting action plan, and the completion evidence together in AlwaysReady, linked to the Safe medicines and treatments KLOE. Store your care plan audit linked to the Assessing needs KLOE under Effective. This organises your audit cycle evidence by KLOE before an inspection begins.
Use the evidence trail to demonstrate improvement over time. Upload each cycle's audit report and action plan in sequence. A chronological record showing three consecutive medication audits (each with a dated action plan and evidence of follow-up) is one of the strongest Well-Led evidence items a service can hold. It shows that the monitoring system is working and that the improvement function is active.
Delegate the audit review to senior staff. Using AlwaysReady's task delegation feature, assign the post-audit action plan review to a deputy manager or senior colleague. They confirm which actions have been completed, note any that remain outstanding, and sign off the task via a link. The record is timestamped and stored alongside the original audit plan. This creates the governance oversight that CQC expects under Governance and management.
Download AlwaysReady's free Annual Compliance Audit Calendar. The calendar provides a structured monthly audit schedule across all five key questions, with prompts for action plan follow-up and trend review built into each quarter. Working through it means your audit cycle is planned, consistent and evidenced, never assembled from memory at the end of the year. Download it here.
References and regulatory sources
- Care Quality Commission (2026). Draft assessment framework for adult social care. Published 19 March 2026. Available at: cqc.org.uk
- Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, Regulation 17: Good governance.