CQC compliance software: what it covers, and the gap around staff AI use
Published 18 September 2026 · 8 minute read · General information, not legal advice
If you are searching for CQC compliance software you are probably after one of three things: a policy library that stays current, a way to run audits and evidence them, or a system that logs incidents and actions so nothing falls through. The established platforms do those jobs well, and this guide describes what each covers in its own words.
It also covers the thing none of them were built to see. In May 2026 CQC set out what it expects of providers using AI, and the most common AI use in care today is a care worker pasting a note into ChatGPT on their own phone. No audit module records that. Caredact is not a compliance platform, and this guide says where it fits and where it does not. It is general information, not legal advice.
What the main platforms cover
Three platforms come up most often in this search. The descriptions below are taken from their own websites as read on 18 September 2026; where a site does not say something, we do not guess.
| Platform | What it says it does | Where AI appears |
|---|---|---|
| QCS (Quality Compliance Systems) | Policies and procedures kept up to date, care audits with action tracking, mock inspections, a learning centre for staff training, care management and rostering, presented as "one connected system". | Lyra AI, which answers staff questions "grounded in QCS expert-maintained content". |
| Radar Healthcare | "Connects incidents, risks, audits, actions, compliance evidence and analytics" so teams can "spot risk earlier, prevent repeat harm and prove safer care". Incident management, audit management, risk registers and action plans, used by care homes, care groups and domiciliary agencies. | Analytics and predictive risk on the data held in the platform. Nothing stated about staff use of external AI tools. |
| Log my Care | A care management system: care plans, daily logs, incident management, risk assessments, handovers, eMAR and a family app. | "AI-powered Care Plan Audits" that review care documentation held in the system. |
The pattern is the same across the category. Each platform is good at evidencing what happens inside it: policies, audits, incidents, care records. None of them describes a control for what a member of staff types into an app on a personal phone, and structurally none could, because that text never touches the platform.
What CQC now expects around AI
CQC published its position on AI in health and social care on 21 May 2026. It is clear about its own role:
“We do not assess or approve specific technologies but have a role in ensuring that technology including AI contributes to safe, effective and equitable care across all settings and services.”
It then sets out the principles providers must follow to use AI in line with the regulations. In CQC’s words:
- "AI to support, not to replace: AI can enhance, but not replace human decision making."
- "Human oversight: AI outputs and processes are continuously monitored and evaluated."
- "Transparency and choice: People who use services have appropriate information to make informed decisions about their care, including the role of AI in care pathways."
- "AI readiness and training: Those using AI are sufficiently trained and confident in using the technology, and they assess whether it can be integrated into existing pathways."
- "Data Protection Impact Assessment (DPIA): A DPIA assesses and documents risks to privacy and data subject rights to understand and minimise any interference with people’s rights, to enable lawful use of AI."
Two of those are impossible to satisfy for AI use nobody has approved. You cannot evidence human oversight of outputs you never see, and you cannot write a DPIA for a tool your policy says nobody uses. The ICO’s own guidance says AI processing will usually trigger the legal requirement for a DPIA in any case.
Where it lands in the assessment framework
The quality statement an inspector will be applying sits under Well-led:
“We have clear responsibilities, roles, systems of accountability and good governance. We use these to manage and deliver good quality, sustainable care, treatment and support. We act on the best information about risk, performance and outcomes, and we share this securely with others when appropriate.”
CQC’s explanation of what that statement means includes that "there are robust arrangements for the availability, integrity and confidentiality of data, records and data management systems". A policy that bans ChatGPT is an answer about intent. A record of what staff actually sent, with evidence that no personal data went with it, is an answer about control. That difference is what "systems of accountability" means in practice.
How to evidence AI use, honestly
- Decide in writing what staff are allowed to use, not only what they are not. A prohibition with no approved route pushes the behaviour out of sight. Our AI policy template is a starting point.
- Do a DPIA for the approved route and keep it with your other Well-led evidence. Use our DPIA template for AI in social care if you do not have one.
- Make sure personal data is removed before anything reaches an external model, and keep a record of each send.
- Train staff on the approved route and log the training in whatever system you already use.
- Keep the approved tool’s processor agreement, the DPIA and the send log in the same evidence folder as your audits, so an inspector finds them where they expect.
Where Caredact fits, and where it does not
Caredact is not a compliance platform. It does not hold your policies, run your audits or log your incidents, and you should keep whichever of the systems above you already use. It does one job: it makes staff AI use safe and evidenced. Staff paste a note, names, addresses, NHS numbers and care identifiers are detected and replaced with labelled placeholders before anything reaches the AI, a person reviews the highlights and adds anything missed, and every step is logged with how many items of each type were removed, without storing the details themselves. It runs in the UK and comes with a Data Processing Agreement.
The audit log exports so it can sit in your evidence folder next to the DPIA. If your compliance platform adds a control for staff AI use in future, we would expect it to look much like this, and you should ask them.
Questions
Do I still need compliance software if I use Caredact?
Yes. Caredact covers one risk: staff use of AI with personal data. Policies, audits, incidents and mock inspections belong in a platform built for them.
Does CQC approve or certify AI tools?
No. CQC states that it does not assess or approve specific technologies. It expects providers to meet the regulations whatever technology they use, and sets out the principles above. There is no CQC-approved list to check a tool against.
Is a policy banning ChatGPT enough?
It is a start, but it is evidence of intent rather than control. Staff often use AI tools on personal devices without telling anyone. An inspector applying the governance quality statement will want to know how you know what is happening and what record exists. Our guide on what regulators expect covers this in detail.
What should I ask a compliance vendor about AI?
Three questions. Does the platform record staff use of external AI tools? If it has AI features, does personal data leave your organisation, and to whom? Is there a DPIA and a processor agreement you can put in your evidence folder?
Sources
- [1]CQC, Artificial intelligence in health and social care: CQC’s role, expectations and plans (page last updated 21 May 2026)
- [2]CQC, Quality statement: Governance, management and sustainability (Well-led)
- [3]QCS (Quality Compliance Systems) website
- [4]Radar Healthcare website
- [5]Log my Care website
- [6]ICO, Guidance on AI and data protection: accountability and governance implications