Independent audit buyer’s guide

Choose the reviewer before you share the records.

Sixteen practical checks to use before hiring someone for a private CQC-style audit, mock inspection or compliance review.

Use the checklist
4 areas to check16 checksSaved in this browser
Reviewed against published CQC, ICO and Care England guidance · 4 September 2026
Before you appoint anyone

A confident promise is not proof.

A private consultant can offer a useful fresh view, but the work is not a CQC inspection and the consultant cannot decide a rating. Ask for proof behind claims, insist on a written plan and understand exactly how sensitive records will be handled.

Use the same questions for every supplier, including GR Safi. Keep a dated note of what you checked, what remains unanswered and why the chosen reviewer suits the decision your service needs to make.

  1. 01
    Define the decision

    Decide whether you need a whole-service view, one issue checked, inspection preparation or independent follow-up.

  2. 02
    Verify, do not infer

    Check qualifications, relevant skills, current insurance, references and any criminal-record or right-to-work evidence needed for the role. Use current documents or direct checks, not website wording alone.

  3. 03
    Agree before access

    Do not share care records until you know what will be reviewed, who is responsible for the data, what is needed, who can access it, how it will be sent, how long it will be kept and when it will be deleted.

  4. 04
    Judge the output

    Read a sample report and confirm how findings, supporting records, limits, fact checking and actions will be shown.

Current CQC position · checked 4 September 2026

Require a dated source, not an old “CQC checklist”.

CQC is testing a new assessment method during 2026. Its published update says tests run from June to October, with a final review planned for November, while the five key questions remain central. Ask every reviewer which current guidance and version they use.

Read CQC’s June 2026 pilot update

This is a buyer’s guide, not legal advice or an approval scheme. It does not certify a consultant, decide whether a contract is legally sound or replace the checks your organisation needs for its risks and data.

Private working copy0 of 16 reviewedSaved only in this browser
Area to check 01

Experience and independence

Can you check who the reviewer is, why their experience is relevant, their limits and their independence?

4 checks

Identity, qualifications and appointment checks can be verified.

Names, dates, roles and issuing organisations are clear enough to check. Important claims are supported by current documents or independent sources, not only by website wording.

Ask for a current CV, qualification or training evidence, relevant insurance and any criminal-record or right-to-work check the role requires. Confirm who issued each item, its date and whether it is still current.
Status for C1

Relevant care-sector experience is described precisely.

The reviewer separates direct care-service experience, management work, auditing, clinical expertise and knowledge of regulation instead of blending them into one vague claim.

Ask which service types, roles, review areas and recent jobs are genuinely relevant. Where appropriate, ask whether recent clients can confirm comparable work directly.
Status for C2

Conflicts and commercial relationships are disclosed.

The provider knows about any earlier work, referral deal, supplier relationship, competing interest or later paid work that could affect, or appear to affect, independence.

Ask: what conflicts have been checked, what will be disclosed and how will any conflict be managed?
Status for C3

Private status and limits are clear.

The reviewer does not imply that they work for CQC, have inspection powers or control CQC decisions. Terms such as “CQC-style” and “mock inspection” are clearly explained as private support.

Confirm: only CQC carries out official assessments and decides findings and ratings.
Status for C4
Area to check 02

What will be checked and how

Will the work answer the agreed question and be honest about what it cannot show?

4 checks

The question, goal and standards used are written down.

The written plan states the question and which current regulations, guidance, provider procedures, contracts or other standards will be used.

Confirm: source titles or links, relevant versions or dates checked, and what happens if guidance changes.
Status for S1

The proposed sample is sensible and explained.

The plan defines the locations, people, records, staff roles, time period, interviews and observations, or explains how they will be chosen according to risk.

Ask: why is this sample enough for the question, and what would be unsafe to conclude from it?
Status for S2

The plan clearly states what is excluded and what the findings depend on.

The provider can see what is not covered, what the findings depend on, whether practice will be observed and when specialist clinical, legal or data-security advice may be needed.

Confirm: which services, dates, records, locations, professional areas, regulations and decisions are not covered.
Status for S3

Access, responsibilities, timing and price are agreed.

The quote states what each party must provide, whether work is onsite or remote, meetings, key dates, the final report, travel or other costs, payment terms and what happens if the work changes.

Ask for: one written document that brings together the work, assumptions, what you receive, price and timing.
Status for S4
Area to check 03

Keeping records and data safe

Is only the information needed used and protected throughout the work?

4 checks

Data responsibilities, purpose and written terms are clear.

Both sides state why personal information is needed, who is responsible for it and whether a data-protection contract is required.

Ask the right privacy or legal lead to confirm the arrangement before sensitive information, such as health data, is shared.
Status for D1

Only the information needed is requested.

Names are removed or replaced with reference codes where possible, unneeded fields are removed and access is limited to the agreed sample instead of a large transfer “just in case”.

Confirm: which fields are needed, how details will be removed or replaced, the sample limits and who approves sharing.
Status for D2

Sharing, storage, access and working methods match the risk.

The provider understands how records will be sent, how they will be protected, who can access them, which devices, locations and suppliers are involved, whether backups exist and how working copies stay safe.

Do not place identifiable care records in a public enquiry form or an ordinary scoping email.
Status for D3

How long records are kept, returned or deleted, and what happens after a breach are stated.

Both sides know how long source records, notes, reports and backups may be kept, what will be returned or deleted, how deletion will be proved when needed and whom to contact if information is lost or shared wrongly.

Confirm: when the keeping period starts, final deletion, any legal reason to keep information, the breach contact and who must notify affected people or authorities.
Status for D4
Area to check 04

Report and follow-up

Will the report show how it reached each finding, be fair and useful, and make responsibilities clear?

4 checks

The report shows how it reached its findings.

It states the purpose, what was reviewed, standards used, sample, dates, method and limits, so a reader can see what was and was not checked.

Read a sample report and check that findings link back to what was reviewed before buying the service.
Status for O1

Facts, supporting records, professional opinion and recommendations are kept separate.

Important findings link to what was checked, professional opinion is labelled, and there is a clear way to correct factual errors or provide important missing information before the report is finished.

Fact checking should improve accuracy without allowing difficult findings to be bargained away.
Status for O2

Good practice and gaps are put in order without pretending to rate the service.

The report separates immediate safety or reporting needs from high, medium and longer-term improvement. It explains why and does not present a private score as a predicted CQC result.

Confirm which urgent concerns must be raised during the review instead of waiting for the final report.
Status for O3

Actions, owners, proof of completion and follow-up are practical.

Recommendations state the intended result, named owner, date based on risk and proof that would show the change worked. The provider remains responsible for decisions and carrying out the work.

Ask which follow-up is included, optional, charged separately or not covered, and how the reviewer could check that change lasted.
Status for O4
Record the reasons

Keep a clear record of your decision.

Record only non-confidential buying notes here. The working copy stays in this browser until you clear it and is not sent to GR Safi.

Private working copy. These notes use local browser storage. Clear them before using a shared device, and do not enter confidential or identifiable information.

Check the official guidance

CQC’s approach is changing during 2026, while the five key questions and providers’ legal duties remain important. Information Commissioner’s Office guidance says data should be limited to what is needed and protected according to the risk.

Care-sector discussions have also called for clearer, more consistent private mock inspections and consultancy. This checklist turns those concerns into questions a provider can ask.

Now use the same checks for GR Safi.

Check the published qualifications, sample report, working method, limits and guide prices before deciding whether to get in touch.