Most care providers who use AI tools now have an AI policy. Fewer have AI governance. The difference between the two is not a matter of degree — it is a matter of kind. And it is precisely the gap between them where CQC findings emerge.
An AI policy is a document. It states that the organisation recognises AI is being used in its operations, sets out what uses are permitted and what are not, identifies who is responsible for oversight, and commits the organisation to responsible use. A well-written AI policy covers data protection, accuracy verification, human oversight, staff training, and supplier assessment. It can be produced in an afternoon by someone with a reasonable understanding of the regulatory landscape and a template to work from.
AI governance is what happens after the policy is written. It is the system of processes, checks, records, and accountabilities that ensures the commitments made in the policy are actually kept — every day, across every staff member who uses an AI tool, in every situation where AI output enters a care record, a governance document, or a professional decision.
The distinction is the same one that runs through CQC's entire assessment framework. A safeguarding policy is not safeguarding. A complaints procedure is not complaints handling. A training schedule is not a trained workforce. The document describes the intention. The governance system is the evidence that the intention is being fulfilled.
What an AI Policy Contains
An AI policy typically covers five areas. It identifies approved AI tools and permitted purposes, sets conditions for human review and verification, names an individual responsible for oversight, commits the organisation to staff training, and addresses data protection — specifically, that service-user data is not transmitted to unapproved AI systems.
These are the right areas to cover. But a policy that is filed, distributed to staff in an induction pack, and never consulted again has not produced governance. It has produced documentation of an intention that may or may not be reflected in actual practice.
What AI Governance Requires
AI governance requires that each commitment made in the policy is operationalised — translated into a specific, recurring process that produces evidence of compliance as a natural byproduct of normal operation.
The commitment to approved tools becomes an AI Systems Register — a maintained inventory of every AI tool in use across the service, updated when tools are introduced or discontinued, reviewed at defined intervals, and accessible to anyone who needs to demonstrate to an inspector what AI is being used and under what conditions.
The commitment to human review becomes an Output Review Record — a documented process confirming that AI-generated content has been reviewed by a named professional before it enters a care record, governance document, or formal output. Without a record, the commitment exists only in the policy. With a record, it exists in the evidence.
The named responsible individual becomes an accountable role with defined responsibilities, regular reporting obligations, and documented decisions. Staff training becomes a training record with completion dates, a refresher schedule, and evidence that training has changed practice. Data protection becomes supplier due diligence — documented assessment of each tool's data handling, terms of service, and UK GDPR compliance.
Turn policy into governance
The complete governance infrastructure in one pack
ReporticaAI's AI Governance Management Pack provides the operational infrastructure for CQC-regulated care settings — AI Systems Register, Risk Assessment, Acceptable Use Standard, Output Review Record, Supplier Due Diligence, and five further editable templates aligned to the 2026 Single Assessment Framework.
Where CQC Findings Emerge
The gap between policy and governance is exactly where CQC's Well-led key question is designed to look. An inspector who asks to see an AI policy and receives a well-written document has learned something. An inspector who then asks how the policy is implemented, who reviews AI outputs, what the AI Systems Register shows, and when staff last received training — and receives vague or inconsistent answers — has found the gap.
The Kevin Humphreys case, shared publicly at the South East Social Care Alliance conference, made this concrete. A care provider received an Inadequate rating partly because AI tools were being used without governance — not because they had no policy, but because the policy had not been translated into the processes and records that demonstrate governance in practice.
CQC's assessment framework does not distinguish between an organisation with no AI policy and one with a policy but no governance. Both represent a failure of the Well-led key question. The policy may make the second situation harder to defend: it demonstrates awareness of the requirement without evidence of compliance.
The Test
The simplest test is this: if a CQC inspector arrived today and asked to see evidence that the AI policy is being followed, what would you show them?
If the answer is the policy itself, you have a policy. If the answer is an AI Systems Register, Output Review Records, training records, and supplier due diligence documentation, you have governance. The policy is the starting point. Governance is what follows from it.
Related articles
- Shadow AI in Care Homes: The Unapproved Tools Staff Are Already Using
- AI Governance in Care Settings: What CQC Is Already Looking For
- What Is an AI Impact Assessment and Why Every Care Provider Needs One Now
- AI Governance Management Pack
This article is published in accordance with PAIDS™ (Professional AI Documentation Standards) — well-sourced, thoroughly researched, and defensible with verifiable data.