Introduction

Policy templates are sold widely in this space, sometimes with the implication that buying a complete set is itself sufficient for compliance. It isn't — a policy is evidence of intent, and CQC's actual assessment (see CQC's guidance) looks at whether practice genuinely reflects the policy, not just whether the policy document exists.

Policies CQC explicitly expects

Core policies genuinely expected for any CQC-regulated service typically include: safeguarding, medication management (where relevant to the service), infection prevention and control, recruitment and staff vetting, complaints handling, health and safety, governance and quality assurance, data protection, and equality/diversity/human rights. These map directly to the fundamental standards CQC assesses against.

Each of these exists to answer a specific regulatory question CQC will ask in one form or another: how do you protect people from harm (safeguarding, medication, infection control), how do you make sure the right people are delivering care (recruitment), how do you respond when things go wrong (complaints, health and safety), and how do you know your service is actually working as intended (governance, data protection, equality). Understanding the question a policy is answering, rather than treating it as a document to have on file, is what separates genuine compliance from box-ticking.

Policies that are good practice but not strictly mandatory

Some policies commonly bundled into generic "complete" template packs — highly specific procedural documents for scenarios that may not apply to every service type — are good practice where relevant, but aren't universally required in the same way the core set above is. Buying a large generic bundle doesn't mean every document in it applies to your specific service.

This matters commercially as much as it matters for compliance: paying for, and then having to maintain and periodically review, a large set of policies that don't genuinely apply to your service is both wasted cost and a genuine governance burden, since every policy on file is something your governance process should be reviewing and keeping current, whether or not CQC ever specifically asks about it.

Why templates alone aren't enough

A policy that reads as generic — not referencing your actual service, your actual staffing structure, your actual client group — is exactly the kind of document that tends to be probed at interview or during an assessment. The difference between a template and a genuinely useful policy is specificity: does it describe how your service actually runs, or could it belong to any provider with the name changed?

A practical test worth applying to your own policy set: read a policy and ask whether removing your organisation's name would make it indistinguishable from a competitor's version of the same document. If the answer is yes, the policy is describing a generic process, not your actual one — and that gap is precisely what an experienced assessor or interviewer is trained to notice.