Governance
In preparation

Care Home Risk Register Template

A starter risk register aligned to CQC Regulation 17 governance

Not available yet

This resource is still being written. There is no file to download today. The form on this page joins a notification list, and we will email you once it is published. No publication date has been set. The sections below set out what the resource will contain.

A care home risk register is a maintained record of the risks a service has identified, how likely and how serious each one is, who owns it, what is being done to control it, and when it was last reviewed. Under Regulation 17 it is the evidence that risk is assessed and mitigated systematically rather than reactively.

A pre-structured risk register covering the categories CQC inspectors expect to see: clinical, staffing, environmental, safeguarding, medication, and infection control. Includes likelihood × impact scoring and owner / review fields.

Planned format: Excel risk register template + governance guidance PDF
Aligned to
CQC Regulation 17: Good governance
Get notified when this is published
Free when published • No credit card • Care providers only

This resource is still being written. There is nothing to download yet. Leave your email and we will send it to you once it is published.

We will use your email to tell you when this resource is published, and to send occasional emails about Statixs. Unsubscribe anytime.

What this will contain

The scope we are building to. Built for care providers, not generic HR teams, and anchored on the regulations rather than on assessment process wording.

Pre-populated risk categories aligned to CQC inspection focus areas
Likelihood × impact scoring matrix
Owner, review date, and mitigation tracking columns
Escalation rules and ownership patterns
Linked actions and control reference fields

Who this is for

  • Registered managers building or rebuilding a governance framework
  • Nominated individuals reviewing risk across multiple locations
  • Quality leads preparing for a governance review or board report

How it is designed to be used

  1. 1Populate the pre-set categories with the risks that actually apply to your service.
  2. 2Score each risk for likelihood and impact and record the resulting rating.
  3. 3Assign a named owner and a review date to every entry — an unowned risk is not managed.
  4. 4Link each significant risk to an action in your action plan, and review the register at a fixed governance meeting.
Why this matters

CQC Regulation 17 requires evidence that risks are systematically identified, assessed, and managed. A spreadsheet that nobody maintains is not a risk register. This template gives you the structure to start.

Common questions

A description of the risk, the category it sits in, a likelihood and impact score, the controls currently in place, a named owner, a review date, and a link to any corrective action. Services commonly cover clinical, staffing, environmental, safeguarding, medication and infection control risk categories.
The register itself is usually reviewed at each governance meeting, typically monthly or quarterly, while individual high-rated risks carry shorter review dates of their own. The review date on each entry matters more than the overall cycle, because it is what shows a risk is being actively managed.
Regulation 17 requires providers to assess, monitor and mitigate risks relating to the health, safety and welfare of people using the service. A maintained register with owners, scores, controls and review dates is the most direct way to evidence that requirement, provided the entries show movement over time rather than a static list.

See Statixs in your environment

Statixs is the compliance operating system that turns templates like this into a live, governed workflow.

Book a demonstration