{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Safe and Secure Business Premises Policy
1. Purpose
This policy sets out how {{org_field_name}} ensures the care home premises and all equipment used to deliver care are clean, secure, suitable for purpose, properly used, properly maintained and appropriately located, in line with Regulation 15 (Premises and equipment) of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 and the CQC Fundamental Standards. It also describes the controls we use to prevent unauthorised access, manage environmental and fire risks, and respond to incidents.
Where CCTV or other surveillance is used, we comply with UK GDPR and the Data Protection Act 2018 and follow ICO guidance on video surveillance. We also meet our duties to notify CQC of relevant events in line with the Care Quality Commission (Registration) Regulations 2009 (Regulation 18) and to report to other bodies where required (e.g., safeguarding authorities, HSE under RIDDOR, and the ICO for notifiable data breaches).
2. Scope
This policy applies to all staff, contractors, visitors, and people we support within {{org_field_name}}. It covers security measures, risk assessments, emergency response, and staff responsibilities to ensure the safety of the premises and everyone within it.
3. Related Policies
- Health and Safety at Work Policy (CH16)
- Risk Management and Assessment Policy (CH18)
- Fire Safety and Evacuation Procedures Policy (CH20)
- Infection Prevention and Control Policy (CH17)
- Safeguarding Adults from Abuse and Improper Treatment Policy (CH13)
4. Legal and regulatory framework
This policy supports compliance with (as applicable):
- Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 – Regulation 15 (Premises and equipment) and related Fundamental Standards.
- CQC Single Assessment Framework – Safe key question / “Safe environments” quality statement (evidence of maintenance, monitoring, suitability of premises/equipment and technology).
- Care Quality Commission (Registration) Regulations 2009 – Regulation 18 (Notification of other incidents) and other notification requirements.
- Regulatory Reform (Fire Safety) Order 2005 (fire risk assessment, emergency arrangements, maintenance and drills).
- UK GDPR and Data Protection Act 2018 (CCTV and access control data).
- Mental Capacity Act 2005 (where access restrictions/locked doors are used to keep people safe, ensuring restrictions are lawful, proportionate and the least restrictive option).
- Relevant health and safety legislation and guidance for premises management (e.g., statutory inspections/servicing of systems and equipment).
5. Policy statement
{{org_field_name}} will maintain premises and equipment so they are safe, clean, secure and suitable for people’s needs. We will:
- complete and document planned preventative maintenance and statutory servicing,
- complete and document routine environmental safety checks,
- act on hazards within defined timescales,
- investigate and report incidents and near misses, and
- use learning from audits/incidents to improve safety and security.
These arrangements provide evidence for CQC that people are cared for in safe environments and that facilities, equipment and technology are well-maintained and consistently support safe care.
6. Physical Security Measures
6.1 Access Control
Entry points are monitored and controlled to prevent unauthorised access.
Any door locking, keypad codes or other access restrictions used to prevent unsafe exit or unauthorised entry will be risk-assessed, person-centred, and the least restrictive option. Where restrictions relate to an individual’s safety, the decision and rationale will be recorded in the person’s care plan and reviewed, in line with the Mental Capacity Act 2005 and safeguarding best practice.
6.2 CCTV and video surveillance
Where CCTV is used, {{org_field_name}} will ensure it is lawful, necessary and proportionate for safety/security purposes and is operated in line with UK GDPR and the Data Protection Act 2018, following ICO guidance. This includes:
- clear signage and an accessible privacy notice explaining purpose, lawful basis, who to contact and how footage is used;
- completion and review of a Data Protection Impact Assessment (DPIA) before installation or significant change;
- cameras positioned to avoid intrusion into private areas (e.g., bedrooms, bathrooms) unless there is a specific, documented lawful basis and safeguards;
- controlled access to live/recorded footage (authorised roles only), secure storage, audit trail of access, and encryption where available;
- a defined retention period (minimum necessary) and secure deletion;
- clear procedures for Subject Access Requests and lawful sharing with police/insurers; and
- reporting and escalation of any CCTV/data security breach in line with data protection incident procedures (including ICO reporting where required).
6.3 Lighting
Adequate outdoor and indoor lighting is maintained to deter intrusions and improve safety.
6.4 Visitor and contractor management
- All visitors/contractors sign in/out, provide identification on request, and are issued a visitor badge.
- Visitors are informed of safeguarding expectations, infection prevention requirements, and privacy/confidentiality rules (including photography/recording restrictions).
- Contractors working in clinical/secure areas must be authorised by the Registered Manager (or delegate) and supervised where required.
- Any concerns about a visitor’s behaviour or risks to people’s safety are escalated immediately and may result in restricted access and/or contacting safeguarding/police.
6.5 Key Management:
- Access to keys is restricted to authorised personnel.
- Lost or stolen keys must be reported immediately to management.
7. Fire Safety and Emergency Preparedness
- A fire risk assessment will be completed by a competent person and reviewed at least annually and following any significant change (e.g., building works, layout changes, changes in dependency).
- Personal Emergency Evacuation Plans (PEEPs) will be in place where required and aligned to individual needs and mobility/assistance levels.
- Fire exits, escape routes and fire doors will be checked to ensure they are unobstructed, functional and compliant.
- Fire detection/alarm systems, emergency lighting and firefighting equipment will be tested and serviced in line with manufacturer guidance and the fire risk assessment, with records retained.
- Fire drills will take place at planned intervals and include different times of day/night where applicable, with learning captured and actions tracked.
- The home will maintain documented emergency arrangements for power failure, heating/hot water loss, flood/severe weather, loss of utilities, and other events that could affect safe care delivery.
8. Risk Assessments and Environmental Safety
- Regular Premises Inspections:
- Weekly health and safety checks.
- Monthly risk assessments for potential hazards.
- Maintenance of Facilities:
- Equipment and premises repairs are conducted promptly.
- Flooring, stairways, and handrails are regularly inspected for safety.
- Hazard Reporting:
- Staff must report any hazards immediately to management.
- A risk assessment must be conducted following any reported hazard.
Planned preventative maintenance and statutory checks (records we keep)
{{org_field_name}} will maintain a documented schedule for premises and equipment checks and servicing (as applicable), including: fire safety systems; emergency lighting; gas safety; electrical safety and portable appliance testing; water safety/Legionella controls; lifts/hoists and lifting equipment; call bell systems; beds and pressure-relieving equipment; heating/ventilation; and security systems (door controls/alarms/CCTV).
Records will show: date of check/service, findings, actions required, actions completed, and the person/contractor responsible. Any high-risk defects will be escalated immediately and mitigated until rectified.
This provides evidence that premises and equipment are maintained, suitable for purpose and used properly in line with Regulation 15.
9. Infection Prevention and Hygiene Control
- Cleaning Protocols:
- Regular cleaning schedules are followed to maintain hygiene.
- High-touch surfaces are disinfected frequently.
- Hand Hygiene Stations: Available at key locations throughout the premises.
- PPE Availability: Masks, gloves, and sanitisers are accessible to staff and visitors.
- Air Quality Management: Ventilation systems are maintained to reduce airborne risks.
10. Safeguarding and Protection of People We Support
- Prevention of Unauthorised Access:
- Secure doors and alarm systems to protect vulnerable individuals.
- Restricted access to sensitive areas such as medication rooms.
- Managing unauthorised exit / missing person risk: Where a person is at risk of unsafe exit, the service will implement a person-centred plan (e.g., supervision levels, engagement, environmental design, technology aids where appropriate). If a person is missing or unaccounted for, staff will follow the home’s missing person procedure, including immediate search actions, escalation to the Registered Manager, and contacting emergency services and the person’s representatives where appropriate. All actions and outcomes will be recorded and reviewed for learning.
- Incident Reporting:
- Any security breaches must be reported to the Registered Manager immediately.
- A full investigation must follow any unauthorised access incidents.
- Training for Staff:
- Regular safeguarding training to recognise and prevent potential risks.
- De-escalation strategies for managing security incidents involving individuals in distress.
11. Handling of Personal Belongings and Property
- Secure Storage:
- Lockable storage is provided for people we support to secure their personal items.
- Staff lockers are available for securing their belongings.
- Lost and Found:
- Any found items must be reported to management and securely stored until claimed.
- Unclaimed items will be disposed of responsibly or donated where appropriate.
12. Staff Responsibilities
- Registered Manager:
- Oversees security and safety policies, ensuring compliance.
- Investigates and addresses any security or safety concerns.
- Ensures that staff are trained and aware of their responsibilities.
- All Staff:
- Follow all security protocols and report concerns immediately.
- Ensure that the premises remain secure during and after working hours.
- Monitor the safety of people we support and visitors at all times.
13. Staff Training and Awareness
- Mandatory Induction Training:
- Security, health and safety, fire safety, and infection control.
- Refresher Training:
- Conducted annually or as required based on regulatory changes.
- Incident Drills and Role-Play:
- Staff are trained in security incident responses through simulated drills.
- Emergency procedures are reinforced to ensure swift and efficient responses.
14. Incident Reporting and Continuous Improvement
- Incident Logs:
- All security incidents are logged and reviewed to identify improvements.
- Regular analysis of incident trends to mitigate recurring risks.
- Feedback Mechanisms:
- Staff and people we support can provide feedback on security concerns.
- Regular security audits and updates are made based on feedback and risk assessments.
External reporting and notifications (where required)
The Registered Manager (or delegate) will ensure that relevant incidents are reported and/or notified to external bodies in line with legal duties, including:
- CQC notifications under the Care Quality Commission (Registration) Regulations 2009 (Regulation 18) for applicable incidents affecting people’s health, safety and welfare;
- Local authority safeguarding reporting where abuse/neglect is suspected or alleged;
- HSE reporting under RIDDOR where applicable (e.g., specified injuries, dangerous occurrences);
- ICO reporting where a personal data breach is likely to result in a risk to individuals’ rights and freedoms (including where CCTV footage/data is compromised).
Evidence of decisions to notify (or not notify) will be recorded, including rationale and reference to the relevant criteria.
15. Evidence and assurance (CQC – Safe environments / Regulation 15)
To evidence ongoing compliance, {{org_field_name}} will maintain and make available (on request) the following:
- premises safety checklists and audit results;
- maintenance plans and servicing certificates;
- fire risk assessment and fire drill records;
- environmental risk assessments and action plans;
- CCTV DPIA (where CCTV is used), signage checks and access logs;
- incident logs, investigations, learning and improvement actions (including notification records).
These records demonstrate that facilities, equipment and technology are well-maintained and that there are effective arrangements to monitor safety and upkeep, as expected by CQC.
16. Policy Review
This policy will be reviewed at least annually and immediately following: significant premises changes; serious incidents/fire/security breaches; updates to CQC Regulation 15 guidance or the Single Assessment Framework expectations; or changes to data protection/fire safety legislation affecting premises security and surveillance.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.