Care Quality Commission

https://www.cqc.org.uk · 51/92 checks passed · government

Compliance report (framework 0.8)

Gate passed (every Core check must pass) · not counted towards the gate: paused 35, draft 48, ready for review 54.

Site level: 0 (no scored checks yet).

By level

LevelResult
Level 1 — Basic 29/37 (8 failed)
Level 2 — Enhanced 9/27 (18 failed)
Level 3 — Advanced 0/10 (9 failed)

By category

CategoryResult
Accessibility 11/13
Accountability 0/5
AI & Automation 3/8
Interoperability 1/3
Privacy 12/16
Provenance 1/2
Security 5/11
Transparency 5/13
Responsibility to the Future 0/3

Level 1 — Basic

Accessibility

AI & Automation

  • policy_exists: The page about CQC's commitments, values and behaviours contains no AI use policy or statement.
    Fix: Publish a dedicated AI use policy or statement on the site describing whether and how CQC uses AI.
  • scope_clear: Since no AI policy is present, there is no explanation of what AI is used for.
    Fix: Add a clear scope section to an AI policy outlining the specific purposes and contexts in which AI is used.

Privacy

Security

Transparency

  • disclosure_exists: The page contains no funding or sponsorship disclosure, focusing solely on commitments, values, and behaviours.
    Fix: Add a funding disclosure section (or link) on the About page identifying CQC's funding sources such as provider fees and government grant-in-aid.
  • transparent: Because no disclosure is present, funding sources are not clearly identified anywhere on this page.
    Fix: Clearly name each funding source (e.g., Department of Health and Social Care grant-in-aid, registered provider fees) in a dedicated, easy-to-find section.

Level 2 — Enhanced

Accessibility

Accountability

  • named_person: The page lists only generic 'General enquiries' without naming an individual or specific role responsible for handling contacts.
    Fix: Add the name or title of the team lead or accountable officer (e.g., 'Head of Customer Services') responsible for enquiries.
  • response_timeframe: The page does not mention any response timeframes for complaints or feedback.
    Fix: Publish explicit response timeframes (e.g., acknowledgement within X days, resolution within Y days) on the complaints page.
  • specific: No specific timeframes such as days or weeks are provided anywhere on the page.
    Fix: State concrete timeframes in days or weeks rather than vague language when describing complaint handling.
  • steps_clear: The page lists categories of complaints but does not clearly lay out the sequential steps a complainant should take.
    Fix: Add a clear, numbered step-by-step guide explaining how to make a complaint from start to finish.
  • appeals_exists: The page outlines how to complain about care providers but does not describe any appeals process for challenging CQC decisions or outcomes of complaints.
    Fix: Add a clearly labeled section describing how users can appeal a decision, including steps, timelines, and contact details.
  • independent: No independent or escalation route (e.g., Parliamentary and Health Service Ombudsman) is mentioned on the page for unresolved complaints or appeals.
    Fix: Include an escalation path to an independent body such as the Ombudsman, with a link and brief explanation of when to use it.

AI & Automation

  • detailed_scope: The page does not mention AI at all, so no detailed scope of AI use is provided.
    Fix: Include a detailed scope section in an AI policy enumerating the systems, data types, and use cases covered.
  • limitations: No AI limitations are acknowledged anywhere on this page.
    Fix: Add a section acknowledging known limitations such as bias, accuracy, and contexts where AI should not be relied upon.
  • safeguards: The page describes organisational values but does not describe any AI-specific safeguards or quality controls.
    Fix: Document safeguards such as human oversight, testing, audits, and escalation procedures for AI-assisted decisions.
  • marking_policy: The page contains no policy or statement about how AI-assisted content is marked or disclosed.
    Fix: Publish a clear policy describing how AI-assisted content is labelled and disclosed to readers.
  • consistent: Without any AI marking policy visible on the page, consistent application cannot be demonstrated.
    Fix: Adopt a standard AI-content label and apply it consistently across all pages that include AI-generated material.
  • oversight_exists: The page does not document any human oversight arrangements for AI outputs.
    Fix: Add a statement describing how humans oversee and validate any AI-generated outputs used by CQC.
  • review_process: No review or approval process for AI-generated content is described on the page.
    Fix: Document the review and approval workflow (e.g., editor sign-off, subject-matter expert check) for AI-generated content.
  • accountability: No individual, team, or role is identified as accountable for AI-generated content.
    Fix: Name a responsible owner or team (e.g., a named director or governance committee) accountable for AI-generated content.

Interoperability

Privacy

  • retention_stated: The visible content does not state how long personal data is retained by CQC.
    Fix: Add a dedicated 'Data retention' section stating how long each category of personal data is kept before deletion or anonymisation.
  • specific: No specific retention time periods (e.g., months or years) are provided for any category of data.
    Fix: Specify concrete retention periods (e.g., 'application data retained for 6 years after the end of registration') for each data type held.
  • equal_choices: The page does not present a consent interface with accept/reject options, so equal prominence of choices cannot be demonstrated on this privacy statement page.
    Fix: Provide a visible cookie/consent banner link or reference on the privacy page showing accept and reject options with equal visual prominence.
  • banner_present: The page content shows no visible cookie or consent banner, only a 'Cookies' link in the site footer.
    Fix: Implement a visible cookie consent banner that appears on first visit, allowing users to accept, reject, or configure cookies before non-essential cookies are set.
  • partner_sharing_mentioned: No banner or on-page consent copy is present, so there is no disclosure of data sharing with third-party partners.
    Fix: Include clear language in the cookie banner disclosing any third-party partners that receive user data, with a link to the full cookie and privacy policy.
  • partner_count_specific: No partner sharing is disclosed and no numeric count of partners appears anywhere on the page.
    Fix: If third-party partners are used, state the specific number of partners (e.g., 'We share data with X partners') in the cookie banner and link to a full list.

Provenance

  • credentials: The page describes CQC's values and commitments but does not explain its regulatory authority, statutory basis, or organisational credentials.
    Fix: Add a brief section describing CQC's statutory role as the independent regulator of health and social care in England, with a link to its founding legislation or governance.

Security

Transparency

  • named_person: Only a generic 'General enquiries' label and shared inbox are shown; no named individual or specifically named team is identified.
    Fix: Identify the responsible team by name (e.g., 'CQC National Customer Service Centre') or list a named contact owner.
  • role_clear: The page does not explain the role, remit, or authority of whoever handles enquiries beyond listing contact channels.
    Fix: Add a short description of the enquiries team's role, scope, and what types of queries they are authorised to handle.
  • detail: No funding information is provided, so there are no amounts, percentages, or categories disclosed.
    Fix: Include meaningful detail such as annual funding amounts, the percentage from fees versus grant-in-aid, and categorised budget breakdowns.
  • complete: With no disclosure present, the page cannot demonstrate coverage of all major funding streams.
    Fix: Publish a complete funding statement covering every major stream (fees, grant-in-aid, and any other income) with links to the annual report and accounts.
  • governance_exists: The page describes commitments, values and behaviours but does not describe the governance or editorial structure of the organisation.
    Fix: Add a section (or link to one) outlining CQC's governance structure, such as the board, executive team, and editorial oversight arrangements.
  • roles_clear: No specific roles or responsibilities of individuals or bodies within CQC are identified on this page.
    Fix: Include a list or link identifying key roles (e.g., Chair, Chief Executive, Board members) with their responsibilities.
  • algorithm_explained: The page describes CQC's commitments and values but makes no mention of any algorithms or automated decision-making used in its regulatory work.
    Fix: Add a section (or link to one) explaining any algorithms or automated tools used by CQC and their purpose in the regulatory process.
  • impact_clear: There is no description of how algorithmic decisions affect providers, the public, or care users on this page.
    Fix: Publish a clear statement describing the impact of any algorithm-driven decisions (e.g., risk scoring for inspections) on providers and the public.
  • annual_statement: The page links to a Privacy policy but shows no evidence of a regular or annual review of data practices on this page.
    Fix: Add a statement or link indicating when the privacy/data practices statement is reviewed (e.g., annually) and link to the review history.
  • dated: While the page itself has a 'Page last updated' date, the linked Privacy statement is not shown as dated or versioned on this page.
    Fix: Display a visible 'last updated' date or version number alongside the Privacy link or within the privacy statement itself.

Level 3 — Advanced

Accessibility

  • remediation_timeline: The statement commits to fixing issues ('We're working to produce accessible versions') but provides no specific dates or target timeline for completion.
    Fix: Add a concrete target date or milestone (e.g., 'we aim to make all essential documents accessible by December 2026') for resolving the known non-accessible content.

Accountability

  • enforcement: While CQC states it 'reserves the right to refuse or include links' and references trademark law, the page does not explain the enforcement process—how violations are reported, reviewed, or actioned.
    Fix: Add a section describing the enforcement workflow, including how to report misuse (e.g., logo infringement or improper links), who reviews complaints, expected timelines, and what actions or remedies CQC may take.

Interoperability

Security

  • plan_exists: The page describes CQC's commitments, values and behaviours but contains no published incident response plan or policy.
    Fix: Publish a dedicated incident response plan or policy page and link to it from the site's governance or accessibility/security sections.
  • notification_commitment: The page makes no commitment to publicly notify affected users of significant security or data incidents.
    Fix: Add an explicit statement committing to notify the public and affected individuals when significant incidents occur.
  • timeframe: No timeframe for disclosing incidents to affected users is stated anywhere on the page.
    Fix: Specify a concrete disclosure timeframe (e.g., notify affected users within 72 hours of confirming an incident) in the incident response policy.

Transparency

  • criteria_published: The page lists values and commitments but does not publish any specific criteria used in algorithmic decisions.
    Fix: Publish the specific data points and criteria feeding any algorithmic decision-making, or link to a dedicated transparency page that does.
  • weighting: No information is provided about how any criteria are weighted or prioritised in decision-making.
    Fix: Disclose how criteria are weighted or prioritised in any algorithmic models, including relative importance of each input.
  • auditable: The page contains no technical or methodological detail that would enable external audit or review of algorithmic systems.
    Fix: Provide documentation (model cards, methodology papers, or an algorithmic transparency record) sufficient to allow independent audit of any algorithms used.
  • open_source: There is no link to source code or any open-source repository on the page.
    Fix: Publish relevant code (e.g., the CQC widget or data tools) in a public repository such as GitHub and link to it from the about or developer section.
  • tech_docs: The page mentions CQC data and a CQC widget but provides no technical documentation on this about page.
    Fix: Add or link to technical documentation (API specs, data schemas, widget integration guides) from the about page or a dedicated developer section.

Responsibility to the Future

  • disclosure_exists: The page covers CQC's commitments, values and behaviours but contains no environmental impact or sustainability disclosure.
    Fix: Publish a dedicated sustainability or environmental impact statement outlining the organisation's environmental commitments and performance.
  • specific_metrics: The page provides no specific figures on carbon, energy use, or emissions.
    Fix: Include quantitative environmental metrics such as annual carbon emissions and energy consumption in a published disclosure.
  • hosting_disclosure: There is no mention of the carbon or energy profile of the website's hosting infrastructure.
    Fix: Disclose the hosting provider's energy or carbon profile, including whether the site is hosted on renewable-powered infrastructure.
  • plan_exists: The page describes CQC's commitments, values and behaviours but contains no published plan for what happens if the organisation fails or exits.
    Fix: Publish a continuity or succession plan describing arrangements if the organisation ceases to operate, and link to it from the About section.
  • data_and_content_fate: The page does not address what would happen to user data or published content in the event of organisational failure or exit.
    Fix: Add a section specifying how user data and published content would be preserved, transferred, or retired if the organisation shuts down.
  • custodians_or_mirrors: No custodians, mirrors, or archive partners are identified anywhere on the page.
    Fix: Name a custodian or archive partner (e.g. The National Archives) and document mirroring or archival arrangements for the site's content.
  • policy_exists: The careers page describes job categories and benefits but contains no published policy on worker wellbeing or working conditions.
    Fix: Publish a dedicated worker wellbeing or working conditions policy and link to it from the careers page.
  • accountability: The page names a recruitment contact but does not identify any role, team, or body accountable for overseeing worker conditions or wellbeing.
    Fix: State which team or senior role is responsible for worker wellbeing and provide their oversight or contact details on the page.