Back to Insights
AI Governance14 September 2026

What Evidence Will CQC Expect to See When a Provider Uses AI?

The question is becoming unavoidable. As AI tools enter care settings — for documentation, care planning, quality assurance reporting and staff communications — providers are asking not just whether they can use AI, but what using it will mean at inspection. What will CQC look for? What evidence will be expected? And what does the absence of that evidence mean for a rating?

The honest answer is that CQC has not yet published specific inspection guidance on AI use in care settings. There is no dedicated KLOE for AI governance and no published checklist of what inspectors will examine when AI tools are in use. What exists is a framework — the Single Assessment Framework and its quality statements — that is sufficient to derive what evidence will be required. Providers must demonstrate that they understand what is happening in their service, have assessed and managed the risks associated with their operational choices, and that care meets required standards regardless of the tools used.

AI use in care settings creates specific evidence requirements under that framework. Understanding them before an inspector asks is the governance task that matters now.

The Starting Point: Does the Provider Know What AI Is Being Used?

The first evidence requirement is the most basic and the one most commonly absent. A provider must demonstrate that it knows what AI tools are in use across its service — which tools, for what purposes, by which staff members and under what conditions.

This is not theoretical. Shadow AI — staff using general-purpose AI tools on personal devices without organisational knowledge or approval — is documented and widespread. A registered manager who cannot answer “what AI tools are in use in your service?” with specificity has a governance gap visible to an inspector before any other AI-related question is asked.

The evidence that addresses this is an AI Systems Register: a maintained inventory of every AI tool in use, approved or otherwise, updated when tools are introduced, reviewed at defined intervals and accessible to the registered manager and any inspector who asks to see it. It needs to exist, be current and reflect the actual state of AI use.

Safe: Is the AI Being Used Safely and Is Its Output Being Verified?

Under Safe, inspectors assess whether the service reliably identifies and manages risk. AI tools that produce care records, care plan summaries, medication administration notes or incident reports can introduce factual inaccuracies, omissions or content that does not reflect what a professional observed, decided or did.

The professional using the AI tool remains responsible for the accuracy of its output. The evidence CQC will look for is therefore evidence that AI outputs are reviewed before entering the formal record. This means an Output Review Record or equivalent process confirming that AI-generated content has been checked by a named professional before use. Without this, the commitment to accuracy exists only in policy; with it, the commitment is evidenced in practice.

Inspectors will also ask staff directly. A care worker who cannot describe what they check before submitting AI output, or who believes AI is accurate without verification, has provided evidence of a governance failure regardless of the written policy.

Effective: Does AI Use Support or Substitute for Professional Judgement?

Under Effective, inspectors assess whether care is person-centred, reflects individual needs and preferences, and whether professional judgement is being applied. The evidence question is whether AI organises the professional’s own observations and decisions, or produces care documentation that is endorsed without genuine engagement.

A care plan produced by AI from a brief prompt, reviewed cursorily and filed, is not evidence of person-centred care. Inspectors look for care plans reflecting the individual — their history, preferences, goals and circumstances — and speak to people using the service and staff to assess whether the documentation reflects genuine engagement.

AI-generated documentation that is generic, could describe any service user, or that staff cannot discuss in depth will be identified as poor quality regardless of whether AI produced it. The AI tool does not change the standard. It changes the risk that the standard will not be met.

Well-Led: Is There a Governance Framework for AI Use?

Well-led is where AI governance evidence is most directly assessed. Inspectors look for evidence that leadership understands what is happening, manages risk systematically and can demonstrate that governance processes are embedded in practice rather than documented only in policy.

AI use is a governance responsibility. A provider introducing AI without an AI policy, risk assessment, output review process or supplier due diligence has introduced a risk that its governance system has not managed.

The evidence CQC will expect includes at minimum: a current AI use policy known to staff; an AI Systems Register; a risk assessment of AI tools; evidence of staff training on responsible AI use; and supplier due diligence on data handling and UK GDPR compliance.

Build your AI governance evidence base

The complete governance infrastructure in one pack

ReporticaAI's AI Governance Management Pack provides all seven governance elements in editable format — AI Systems Register, Risk Assessment, Acceptable Use Standard, Supplier Due Diligence framework, Output Review Record, Staff Training Log and Review Schedule — aligned to the 2026 Single Assessment Framework.

The Kevin Humphreys Precedent

The governance consequence of absent AI oversight is not hypothetical. At the South East Social Care Alliance conference, Kevin Humphreys, CEO of Oakland Care Group, described a CQC Inadequate rating received partly because AI tools were being used without governance. The tools themselves were not the problem. The absence of oversight, policy, training and accountability for what the tools produced was.

This is the clearest available signal of what evidence CQC will expect when AI is present: the same evidence it expects for any operational risk — that the risk has been identified, assessed, managed and monitored through a governance system producing contemporaneous documentation.

What Good AI Governance Evidence Looks Like

Bringing together the requirements across all five key questions, a provider should be able to produce seven elements:

  1. AI Systems Register confirming what tools are in use, purposes and conditions.
  2. AI use policy that is current, accessible and demonstrably known to staff.
  3. Risk assessment covering accuracy, data protection and context-specific risks.
  4. Supplier due diligence confirming appropriate handling of personal data and UK GDPR compliance.
  5. Staff training records showing training on responsible use, output checks and inaccuracies.
  6. Output review records confirming AI-generated content is reviewed by a named professional before entering the formal record.
  7. AI governance review process defining when the register, assessment and policy are reviewed and updated.

None requires elaborate infrastructure. Together they demonstrate that the provider is aware of the risk AI introduces, has assessed it, managed it through specific processes and can evidence that those processes operate in practice.

The question has a clear answer. It is the same evidence CQC expects for every operational risk — systematic, contemporaneous and sufficient to demonstrate that governance is real rather than documented.

Related articles


This article is published in accordance with PAIDS™ (Professional AI Documentation Standards) — well-sourced, thoroughly researched and defensible with verifiable data.

We have introduced Reportica Pulse to support your clinical education.

Try the pre-pilot now. No log in required.