{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Critical Incident and Serious Incident Policy
1. Purpose
The purpose of this Critical Incident and Serious Incident Policy is to establish clear procedures for the recognition, reporting, investigation, management, and learning from critical and serious incidents involving temporary workers employed by {{org_field_name}}. This policy ensures that all incidents, whether occurring within the agency or in client settings such as care homes, nursing homes, or healthcare facilities, are handled in a manner that protects the safety and wellbeing of service users, temporary workers, and all stakeholders. The policy aims to reduce the risk of recurrence and promote a culture of safety, openness, and continuous improvement.
This policy is designed to support compliance with the legal duties applicable to {{org_field_name}} as an employment business supplying temporary workers in England. These include the Employment Agencies Act 1973, the Conduct of Employment Agencies and Employment Businesses Regulations 2003, the Health and Safety at Work etc. Act 1974, the Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013, the Care Act 2014 safeguarding framework, the Data Protection Act 2018 and UK GDPR, and other legislation relevant to the circumstances of an incident.
{{org_field_name}} supplies temporary workers to client organisations but does not itself provide or direct a regulated care activity and is not registered with the Care Quality Commission. The client organisation remains responsible for its own statutory duties as the provider of care or treatment, including any applicable CQC notifications and statutory Duty of Candour obligations. {{org_field_name}} will nevertheless act openly, report concerns promptly, cooperate with the client and relevant authorities, and provide all reasonably required information.
Nothing in this policy transfers a statutory responsibility from the client organisation to {{org_field_name}}, or from {{org_field_name}} to the client organisation. Responsibility for external notification will be determined according to the relevant legislation, the worker’s employment status, control of the workplace and the facts of the incident.
2. Scope
This policy applies to:
- All temporary workers supplied by {{org_field_name}}, including employees, workers, registered nurses, healthcare assistants, support workers and, where applicable, individuals engaged through an approved intermediary or personal service company.
- The application of a particular statutory duty will be determined by the individual’s actual employment status and contractual arrangements, rather than by the label used in a contract.
- All work-related, patient-safety, safeguarding, professional-conduct, information-security and other significant incidents connected with the recruitment, supply, employment or placement of temporary workers by {{org_field_name}}, including incidents occurring at a client’s premises.
- All directors and administrative staff responsible for monitoring, investigating, and reviewing incidents
- All incidents relating to service users, temporary workers, colleagues, visitors, and others affected by the agency’s operations
This policy does not replace the client organisation’s incident, patient-safety, safeguarding, emergency, health and safety or regulatory-notification procedures. Temporary workers must follow both the client’s applicable procedures and this policy.
Where the client is an NHS organisation, the client may manage patient-safety incidents under the NHS Patient Safety Incident Response Framework. {{org_field_name}} will cooperate with that process but will not assume the client’s statutory or organisational responsibilities.
3. Related Policies
- Safeguarding Adults and Children Policy
- Incident Reporting and Management Policy
- Whistleblowing Policy
- Health and Safety Policy
- Complaints Policy
- Infection Prevention and Control Policy
- Record Keeping and Confidentiality Policy
- Duty of Candour Policy
- Data Protection and Personal Data Breach Policy
- Disciplinary and Capability Policy
- Fitness to Practise and Professional Referral Policy
- DBS and Safer Recruitment Policy
- Right to Work Policy
- Worker Suspension and Removal from Assignment Procedure
- RIDDOR and Health and Safety Reporting Procedure
- Business Continuity and Emergency Response Policy
- Records Retention Policy
- Managing Allegations Against Staff Policy
- Information Security Policy
- Lone Working Policy, where applicable
- Medication Management Policy, where workers may administer or assist with medication
4. Definitions
Critical Incident: An unexpected or uncontrolled event connected with {{org_field_name}}’s activities which causes, or presents an immediate and substantial risk of causing, serious harm to a person, significant disruption to services, serious legal or regulatory exposure, or serious damage to information, property or organisational operations. A critical incident may require immediate senior management action even where the full consequences are not yet known.
Serious Incident: For the purposes of this internal policy, an incident involving death, serious injury, abuse or neglect, serious professional misconduct, a substantial risk to service users or workers, a significant personal data breach, major business disruption, or a matter that may require notification to an external authority. This is an internal classification and does not determine whether an incident is legally reportable.
Patient Safety Incident: Any unintended or unexpected event, including an omission, which could have or did result in harm to one or more patients receiving healthcare. Where the client is an NHS organisation, the client will determine the appropriate response under its Patient Safety Incident Response Policy and Plan.
Near Miss: An event that did not result in harm but had the realistic potential to do so.
Safeguarding Concern: Information indicating that a child or an adult with care and support needs may be experiencing, or be at risk of, abuse, neglect or exploitation.
Responsible Person under RIDDOR: The employer, a self-employed person or the person in control of work premises who has the legal responsibility to submit a RIDDOR report in the circumstances specified by the Regulations.
Personal Data Breach: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
Client Organisation: The hirer or other organisation to which {{org_field_name}} supplies a temporary worker.
Statutory Duty of Candour: The duty imposed by Regulation 20 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 on registered providers and registered managers. It does not apply directly to {{org_field_name}} solely because it supplies workers to a registered provider.
Professional Duty of Candour: The professional obligation applying to regulated healthcare professionals to be open and honest when something has gone wrong with care or treatment.
All incidents, near misses and concerns within the scope of this policy must be reported internally. Internal reporting does not mean that every incident is externally reportable. The Responsible Director will assess whether any legal, regulatory, contractual or professional notification threshold has been met.
5. Legal and Regulatory Framework
The following legislation and guidance may apply to the management of incidents by {{org_field_name}}, depending on the circumstances:
- Employment Agencies Act 1973.
- Conduct of Employment Agencies and Employment Businesses Regulations 2003, as amended.
- Health and Safety at Work etc. Act 1974.
- Management of Health and Safety at Work Regulations 1999.
- Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013.
- Care Act 2014 and the Care and Support Statutory Guidance, in relation to adult safeguarding.
- Children Act 1989 and Children Act 2004, where an incident concerns a child.
- Safeguarding Vulnerable Groups Act 2006, including duties relating to barred persons and, where the statutory conditions are met, referrals to the Disclosure and Barring Service.
- Police Act 1997 and the relevant criminal-record checking framework.
- Data Protection Act 2018 and UK GDPR.
- Equality Act 2010.
- Human Rights Act 1998.
- Mental Capacity Act 2005, where relevant.
- Employment Rights Act 1996, where applicable to the worker’s status and any disciplinary or dismissal action.
- Public Interest Disclosure Act 1998, where a worker raises a protected disclosure.
- Professional standards and referral requirements issued by the Nursing and Midwifery Council, Health and Care Professions Council or another relevant professional regulator.
- NHS England’s Patient Safety Incident Response Framework and Learn from Patient Safety Events requirements, where these apply to the client organisation.
The Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, including Regulation 20 on the statutory Duty of Candour, ordinarily apply to the registered client provider rather than to {{org_field_name}}. The agency will assist the client to comply with those obligations and will not obstruct, delay or improperly influence any notification or communication.
The Employment Agencies Act 1973 and the Conduct of Employment Agencies and Employment Businesses Regulations 2003 form part of the core regulatory framework for employment agencies and employment businesses.
6. Principles of Incident Management
{{org_field_name}} is committed to:
- Promoting a culture of openness, honesty, and learning
- Promoting openness, honesty and cooperation and supporting client organisations and regulated professionals to comply with any applicable statutory or professional Duty of Candour.
- Ensuring the safety and wellbeing of clients and staff
- Ensuring incidents are managed promptly, thoroughly, and transparently
- Working in partnership with client organisations, regulators, and safeguarding authorities
- Using incident data to reduce risk and improve practice
- Separating immediate safety action from subsequent fact-finding and employment decisions.
- Applying a fair and proportionate response based on evidence and risk.
- Avoiding blame-based investigation and considering organisational, environmental and system factors.
- Preserving relevant records and evidence.
- Ensuring that no person is subjected to retaliation for raising a genuine concern.
- Protecting confidentiality while sharing information where necessary and lawful.
- Clarifying at the start of an incident response which organisation is leading the investigation and which organisation is responsible for each external notification.
- Taking account of the wishes of an adult at risk wherever this is safe and legally appropriate.
An incident investigation is a fact-finding and learning process. It is not, by itself, a disciplinary process. Where the evidence may justify disciplinary, capability, contractual or professional action, the matter will be considered under the relevant separate procedure, with appropriate procedural fairness.
7. Temporary Workers’ Responsibilities
Temporary workers must:
- Immediately take reasonable steps to protect life and prevent further harm, including calling 999 or requesting urgent clinical assistance where necessary, and report the incident to the client’s designated manager or other responsible person as soon as it is safe to do so.
- Notify {{org_field_name}} immediately, or as soon as safely practicable, using the agency’s 24-hour incident-reporting contact where the incident involves death, serious injury, abuse, neglect, violence, a missing person, serious medication error, police attendance, suspension or removal from duty, a serious data breach or any continuing risk. All other incidents must be notified before the end of the worker’s shift or within the period specified by the agency.
- Complete any required incident documentation, including client-specific forms and {{org_field_name}}’s internal incident reporting form
- Preserve relevant documents, contemporaneous notes, messages and other evidence.
- Do not amend, backdate, destroy or remove client records.
- Do not make an audio, photographic or video recording unless authorised, required for immediate safety or permitted under the client’s procedure and the law.
- Do not contact a service user, patient, relative, witness or complainant about the incident unless authorised by the client or agency.
- Do not make admissions of legal liability or speculate about cause or blame.
- Do not discuss the incident on social media or with unauthorised persons.
- Inform {{org_field_name}} immediately if the client removes the worker from duty, asks the worker to leave the premises, reports the matter to the police or indicates that a regulatory referral may be made.
- Cooperate with lawful safeguarding, police, regulatory, professional and employment investigations.
- Participate in incident investigations, debriefs, or reviews as required
- Maintain confidentiality at all times when discussing incidents
- Cooperate with safeguarding processes where applicable
Temporary workers must not delay reporting because of uncertainty about severity; all incidents should be reported so that appropriate classification and action can be determined by the director.
A worker must make a safeguarding referral directly to the appropriate authority or emergency service where there is an immediate risk and the client does not act, cannot be contacted, is implicated in the concern or reporting only through the client would expose a person to further harm. The worker must also notify {{org_field_name}} as soon as it is safe to do so.
Workers who raise genuine concerns in the public interest will be supported in accordance with the Whistleblowing Policy and the Public Interest Disclosure Act 1998.
8. Types of Incidents Requiring Internal Notification
Examples of reportable critical and serious incidents include but are not limited to:
- Unexpected death of a service user during or following temporary worker involvement
- Service user sustaining a serious injury (e.g., fracture, head injury) under the supervision of a temporary worker
- Medication errors resulting in or with the potential for serious harm
- Missing or absconded service users
- Physical or sexual assault, including allegations
- Safeguarding concerns relating to abuse or neglect
- Environmental hazards leading to evacuation or closure of a service
- Failure to follow infection control procedures resulting in or risking an outbreak
- Major health and safety breaches
- Data protection breaches involving personal information of clients or staff
- Death, attempted suicide, serious self-harm or unexpected deterioration involving a temporary worker or occurring during an assignment.
- A specified injury, occupational disease or dangerous occurrence that may fall within RIDDOR.
- Violence, harassment, sexual harassment, discrimination, victimisation or hate-related conduct.
- Alleged abuse, neglect, exploitation, organisational abuse or improper restraint.
- A worker attending an assignment while impaired by alcohol, illegal drugs, misused medication, extreme fatigue or illness.
- Falsification of timesheets, qualifications, training records, clinical records, identity or right-to-work documents.
- A concern that a worker may be barred from regulated activity or may pose a risk of harm.
- Arrest, police investigation or criminal allegation materially relevant to the placement.
- Serious breach of confidentiality or inappropriate access to records.
- Loss, theft or unauthorised disclosure of personal data, including special-category data or DBS information.
- Cybersecurity incidents affecting agency systems or worker information.
- Serious staffing failure, abandonment of shift or failure to attend where this creates a foreseeable risk to safety.
- An allegation against a worker made by a child or adult at risk.
- A client instructing a worker to act outside their competence, scope of practice or lawful authority.
- A client preventing or discouraging a worker from reporting a safety or safeguarding concern.
- Serious failure of personal protective equipment, infection-control arrangements or workplace safety measures.
- Any event that could materially affect a worker’s suitability for future assignments.
Inclusion in this list requires internal notification but does not automatically establish that the matter must be reported externally. External reporting thresholds must be assessed separately.
9. Reporting Procedure
9.1 Immediate Actions
The temporary worker must:
- Ensure the immediate safety of all parties
- Seek emergency medical attention if required
- Notify the client’s responsible person without delay
- Contact {{org_field_name}} as soon as safely possible using the agreed reporting channels
- Do not place yourself or others at further risk.
- Call emergency services where there is an immediate threat to life, serious injury, suspected crime or urgent safeguarding risk.
- Preserve the scene and evidence where it is safe and lawful to do so.
- Follow the client’s emergency, safeguarding and escalation procedures.
- Record the names and roles of persons notified and the times of notification.
- Make contemporaneous notes as soon as possible, separating observed facts from assumptions or information provided by others.
- Where the allegation concerns the client’s designated manager, report to an alternative senior person, the agency and, where necessary, the relevant external authority.
9.2 Formal Incident Reporting
The temporary worker must:
- Complete the client’s incident report form as per the client’s procedures
- Complete {{org_field_name}}’s Incident Reporting Form as soon as reasonably practicable and ordinarily within 24 hours. Immediate verbal notification must not be delayed while the written form is being completed.
- Provide factual, clear, and objective information
- The report must identify what the worker personally saw, heard or did.
- Information obtained from another person must be clearly attributed to that person.
- The report must not contain unnecessary personal data or speculative conclusions.
- Any late report must record the reason for the delay.
- A copy of a client record must not be removed or copied without lawful authority. Where the agency requires information, it should request this through the client’s authorised process.
9.3 Determining Responsibility for External Notifications
The Responsible Director will promptly determine:
- whether the matter may require notification to an external body;
- which organisation or person is legally responsible for making that notification;
- whether the agency must make a separate notification or referral;
- the relevant notification deadline;
- what information may lawfully be shared;
- whether urgent interim action is required before the external notification is completed.
The client organisation will ordinarily be responsible for:
- CQC statutory notifications where it is the registered provider;
- notifications through its NHS patient-safety reporting arrangements;
- reporting incidents concerning patients or service users under its own safeguarding and regulatory procedures;
- notifications arising from its control of the premises, where legislation places the duty on the person in control.
{{org_field_name}} will be responsible for making a notification where the law places the duty on the agency, including where:
- it is the employer and is the responsible person under RIDDOR;
- it is the data controller responsible for a notifiable personal data breach;
- it has a statutory duty to refer a person to the Disclosure and Barring Service;
- it decides that a referral to a professional regulator is necessary;
- it is required to report a suspected criminal offence, modern slavery concern or other matter to the appropriate authority;
- a safeguarding referral is necessary and there is no reasonable assurance that the client has made, or will make, an adequate referral.
Where responsibility is unclear, the agency must not assume that the client will report. The Responsible Director must obtain written confirmation of who will make the notification and retain evidence of the decision. If necessary to protect a person or comply with the law, both organisations may make separate reports.
9.4 RIDDOR Assessment and Reporting
Not every accident, injury, hospital attendance or absence from work is reportable under the Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013. The Responsible Director will assess the statutory criteria, including whether the event arose out of or in connection with work and whether it resulted in a reportable death, specified injury, over-seven-day incapacity, occupational disease or dangerous occurrence.
Responsibility for submitting a RIDDOR report will depend on the circumstances:
- Where {{org_field_name}} is the legal employer of the temporary worker, the agency may be the responsible person and must comply with the applicable reporting and record-keeping duties.
- Where the worker is not employed by the agency, or where the incident concerns a non-worker at premises controlled by the client, the client or person in control of the premises may be responsible.
- The parties must exchange sufficient information promptly to determine responsibility and avoid duplicate, inaccurate or missed reports.
Where an incident requires immediate notification, the responsible person must notify the enforcing authority without delay and submit the report using the prescribed reporting procedure. The agency must retain a copy of any report it submits and a written record of any decision that an event was not reportable.
9.5 Personal Data Breaches
Any suspected loss, unauthorised disclosure, alteration, destruction or inappropriate access involving personal data must be reported immediately to the agency’s Data Protection Lead.
The Data Protection Lead will:
- contain the breach and preserve relevant evidence;
- establish whether {{org_field_name}}, the client or both organisations are acting as data controllers;
- assess the nature, scope and likely consequences of the breach;
- record the breach and the decision-making process;
- notify the client without undue delay where client-controlled data is involved;
- determine whether notification to the Information Commissioner’s Office is required;
- where required, ensure notification to the ICO is made without undue delay and, where feasible, within 72 hours of the agency becoming aware of the breach;
- determine whether affected individuals must be informed without undue delay because the breach is likely to result in a high risk to their rights and freedoms.
All personal data breaches must be documented, including breaches that are assessed as not requiring notification to the ICO.
9.6 Police, Coroner and Emergency Authority Involvement
The police must be contacted immediately where there is an immediate threat, suspected serious criminal offence, assault, sexual offence, theft, fraud, deliberate harm, unlawful restraint, wilful neglect or unexplained disappearance requiring police assistance.
The agency must not conduct an internal interview or take any step that could compromise a police, coroner or safeguarding investigation. The Responsible Director will agree appropriate information-sharing and sequencing with the lead authority.
The client will ordinarily manage contact with the coroner concerning the death of a service user or patient. {{org_field_name}} will preserve and provide relevant worker and assignment information when lawfully requested.
10. Investigations
The director will:
- Carry out an initial risk and jurisdiction assessment promptly after notification to decide whether the agency should investigate, support a client-led investigation, defer to a statutory authority or take a different proportionate learning response.
- Work collaboratively with client organisations, safeguarding teams, and other relevant bodies
- Review all relevant documentation, including witness statements, records, and care plans
- Conduct interviews with temporary workers if required
- Identify root causes, contributing factors, and learning points
- Set a documented and proportionate target timescale for the agency’s response. The target will take account of immediate risk, the complexity of the matter, the availability of evidence and any police, safeguarding, regulatory, professional or client-led process. Any delay and revised target date must be recorded and communicated to relevant participants where appropriate.
- Identify the lead organisation and investigation terms of reference.
- Conduct an immediate risk assessment concerning future assignments.
- Decide whether the worker should remain at the placement, be removed from that placement or be temporarily withheld from other assignments.
- Avoid reaching conclusions solely because a client has removed or suspended a worker.
- Give the worker written details of the concern where disclosure is lawful and will not prejudice another investigation.
- Give the worker a reasonable opportunity to respond.
- Consider evidence that supports as well as evidence that contradicts the allegation.
- Distinguish findings of fact from recommendations and risk-control measures.
- Apply the civil standard of proof, namely the balance of probabilities, to internal factual findings, unless another lawful standard applies.
- Record whether each allegation is substantiated, partially substantiated, unsubstantiated or incapable of determination.
- Consider system factors, including staffing levels, induction, supervision, competence, communication, equipment and client procedures.
- Ensure the investigator is sufficiently independent and has no material conflict of interest.
- Keep safeguarding, disciplinary, professional-referral and contractual decisions separate, although they may rely on common evidence.
Temporary workers are required to:
- Fully cooperate with investigations
- Attend debrief meetings if requested
- Participate in reflective practice discussions
Participation in an agency fact-finding meeting is not a substitute for any statutory right to be accompanied at a formal disciplinary hearing. Where the matter progresses to a disciplinary process, the worker will be informed of any applicable right to be accompanied and any right of appeal.
10.1 Preservation and Disclosure of Evidence
Relevant evidence must be secured as soon as possible. This may include assignment records, booking communications, training records, competency assessments, timesheets, statements and correspondence with the client.
{{org_field_name}} must not direct a worker to obtain, copy or remove confidential care records unlawfully. Relevant client records should be requested through the client’s authorised information-governance process.
Information will be shared only where there is a lawful basis and only to the extent reasonably necessary for the incident response.
10.2 Interim Removal from Assignment
Where an allegation or incident creates a potential risk, {{org_field_name}} may remove a temporary worker from a particular assignment or temporarily withhold them from some or all assignments while enquiries are made. This is a precautionary risk-management measure and is not a disciplinary finding.
Any decision to remove or withhold a worker must:
- be based on an individual risk assessment;
- consider whether less restrictive safeguards are available;
- specify its scope and reasons;
- be reviewed regularly;
- take account of the worker’s contractual and employment status;
- avoid unjustified discrimination;
- be confirmed in writing where practicable.
Pay during any period of suspension or non-assignment will be determined by the worker’s contract, employment status and applicable law. The policy must not promise unpaid suspension or continued pay without checking the relevant contractual position.
11. Safeguarding Concerns and Allegations
Where an incident raises a safeguarding concern:
- The temporary worker must take immediate action to protect any person at imminent risk and must follow the client’s safeguarding procedure unless doing so would expose a person to additional risk.
- The worker must notify both the client and {{org_field_name}} as soon as possible.
- The Responsible Director will establish whether a referral has been made to the relevant local authority safeguarding team and will obtain confirmation of the referral reference where appropriate.
- {{org_field_name}} will make its own referral where the client is implicated, the client fails to act, there is continuing risk, or the agency has an independent legal or safeguarding reason to report.
- The agency will cooperate with any enquiry under section 42 of the Care Act 2014 and with any safeguarding children process.
- The agency will not investigate in a way that compromises a safeguarding, police or local-authority enquiry.
- The agency will consider immediate risks to all other people with whom the temporary worker is placed.
- The wishes, feelings and desired outcomes of an adult at risk will be considered wherever this is safe and consistent with the law.
- Information will be shared on a necessary and proportionate basis. Consent is not always required where disclosure is necessary to protect a person from serious harm or meet another legal obligation.
- The agency will document decisions, referrals, consultations and reasons for sharing or withholding information.
Where the concern involves a child, the agency must follow the applicable local safeguarding-children arrangements and make an immediate referral where a child is suffering, or is likely to suffer, significant harm.
The establishment of Safeguarding Adults Boards and local-authority adult-safeguarding functions arises under the Care Act 2014.
11.1 Disclosure and Barring Service Referral Consideration
Where {{org_field_name}} removes a person from regulated activity, or would have removed them had they not resigned, ceased accepting assignments or otherwise left, because the agency considers that the person has harmed or poses a risk of harm to a child or vulnerable adult, the Responsible Director must promptly assess whether the statutory conditions for a referral to the Disclosure and Barring Service are met.
A DBS referral decision must not be left solely to the client. The agency must consider its own legal position and retain a written record of the assessment, evidence considered, decision and date of any referral.
The agency will not delay a required DBS referral until the completion of unrelated employment proceedings where sufficient information is already available to meet the statutory referral conditions.
11.2 Professional Regulator Referrals
Where an incident raises concerns about the fitness to practise of a registered nurse, nursing associate or other regulated professional, the Responsible Director will assess whether a referral should be made to the relevant professional regulator.
The assessment will consider:
- the seriousness and nature of the concern;
- risk to patients, service users or the public;
- dishonesty, violence, abuse, serious incompetence or repeated unsafe practice;
- whether the professional has complied with any applicable professional Duty of Candour;
- the outcome of available investigations;
- whether local measures are sufficient to manage the risk;
- whether the concern requires urgent interim regulatory action.
The agency will inform the professional of the referral unless doing so would create a risk, breach the law or prejudice another investigation. A client’s decision to refer does not remove the agency’s responsibility to consider whether it should make its own referral.
12. Openness, Candour and Cooperation
{{org_field_name}} is not a registered provider solely because it supplies temporary workers to client organisations and is therefore not ordinarily the “registered person” responsible for the statutory Duty of Candour under Regulation 20.
The registered client provider is responsible for determining whether a notifiable safety incident has occurred and for completing any communication, apology, written notification and record required by Regulation 20.
{{org_field_name}} will:
- notify the client promptly of relevant facts;
- preserve and provide information lawfully required by the client;
- support workers to participate honestly and appropriately in the client’s candour process;
- not obstruct, discourage or improperly influence disclosure to a patient, service user or relevant person;
- ensure that any communication made by the agency is accurate, sensitive and consistent with legal and confidentiality requirements;
- support registered professionals to comply with their professional Duty of Candour;
- distinguish an expression of regret or apology from an admission of legal liability.
Unless specifically agreed with the client, {{org_field_name}} will not independently communicate clinical explanations or findings to a patient, service user or family on the client’s behalf.
13. Record Keeping and Confidentiality
All incident-related documentation must be:
- Accurate, factual, and completed promptly
- Stored securely in compliance with the Data Protection Act 2018 and UK GDPR
- Available for audit, inspection, and regulatory scrutiny
Temporary workers must not disclose information relating to an incident beyond those with a legitimate need to know.
Incident records must be relevant, accurate, objective and limited to information necessary for the purpose for which they are processed. Access must be restricted to authorised persons.
Special-category data, criminal-offence data, safeguarding information and DBS information must receive additional protection and must be processed only where an appropriate lawful basis and condition are identified.
Incident records must not be retained indefinitely. They will be retained in accordance with the agency’s Records Retention Schedule, taking account of legal limitation periods, safeguarding requirements, regulatory requirements, insurance conditions and any litigation hold.
Where legal proceedings, a police investigation, safeguarding enquiry, regulatory process or insurance claim is reasonably anticipated, relevant records must not be deleted until the hold is formally released.
Information may be shared without consent where this is necessary and lawful to protect a person from harm, comply with a legal obligation, establish or defend legal claims, assist law enforcement or meet a regulatory requirement. The agency must document the lawful basis and necessity of significant disclosures.
Workers must not retain incident information on personal devices, personal email accounts or unauthorised messaging applications.
A worker’s confidentiality obligation does not prevent them from making a protected disclosure, reporting a crime, raising a safeguarding concern, cooperating with a regulator or obtaining confidential legal or professional advice.
14. Learning and Continuous Improvement
The director will:
- Analyse incident data to identify themes, trends, and recurring issues
- Update training programmes to address learning from incidents
- Review policies and procedures where necessary following incident findings
- Share anonymised learning with temporary workers and client organisations
- Ensure all serious incidents are considered as part of quality improvement activities
- Track actions to completion and verify that they have reduced risk.
- Consider whether learning applies to other clients, workers, job roles or placements.
- Share anonymised learning only where this can be done without identifying individuals indirectly.
- Review whether recruitment checks, matching, induction, competency assessment, supervision or assignment information contributed to the incident.
- Review information supplied by the client about the role, risks, required qualifications and health and safety arrangements.
- Consider whether the agency complied with its suitability and information-gathering obligations under the Conduct Regulations.
- Monitor for repeated concerns involving the same client, location, worker, role or working practice.
- Escalate unresolved client safety concerns and consider whether continued supply is appropriate.
15. Support for Temporary Workers
{{org_field_name}} recognises that involvement in a critical or serious incident can be distressing. The director will:
- Offer debriefing and emotional support following incidents
- Provide temporary workers with access to appropriate guidance and, where needed, signposting to counselling or occupational health
- Ensure temporary workers are supported throughout the investigation process without prejudice
- Review whether additional supervision or training is needed
- Provide information about the process, expected timescales and the worker’s point of contact.
- Explain that support does not prevent the agency from taking proportionate risk-management or disciplinary action.
- Consider reasonable adjustments for disability, language, literacy, neurodiversity, trauma or other communication needs.
- Provide access to an interpreter where reasonably required.
- Take reasonable steps to protect the worker from retaliation or victimisation for raising a genuine concern.
- Signpost registered professionals to their trade union, professional body or professional regulator’s support resources.
- Consider support for workers who witnessed an incident even if they were not directly involved.
- Maintain appropriate contact during any period when the worker is withheld from assignments.
16. Director’s Responsibilities
In the absence of a registered manager, the director will:
- Take full responsibility for the implementation, oversight, and review of this policy
- Ensure that all temporary workers are trained on incident management procedures during induction
- Review all incidents involving temporary workers for quality, safety, and safeguarding concerns
- Ensure that learning is shared internally and externally as appropriate
- Lead the agency’s response to regulatory, safeguarding, or legal enquiries regarding serious incidents
- Maintain a current 24-hour escalation route for serious incidents.
- Ensure responsibility for external notifications is expressly allocated and recorded.
- Ensure that the client is provided with accurate and timely information about the worker’s identity, status and agency contact.
- Keep a central incident register.
- Maintain separate logs for safeguarding concerns, personal data breaches, RIDDOR assessments, DBS-referral assessments and professional-regulator referrals where appropriate.
- Ensure that conflicts of interest are identified and managed.
- Review whether insurance providers, legal advisers or commissioners must be notified.
- Ensure that workers receive incident-reporting and safeguarding training during induction and refresher training.
- Audit compliance with reporting timescales and action plans.
- Ensure no worker is supplied where the agency knows, or has reasonable grounds to believe, that they are unsuitable for the role or pose an unmanaged risk.
- Consider whether an incident requires notification to the Employment Agency Standards Inspectorate or indicates a breach of the Employment Agencies Act or Conduct Regulations.
- Ensure that serious concerns about a client are escalated and that supply is paused or stopped where risks cannot be adequately controlled.
17. Working with Client Organisations
Before supplying workers, {{org_field_name}} will seek clear contractual arrangements covering incident notification, safeguarding referrals, RIDDOR responsibility, data protection, investigation leadership, access to records, professional referrals, communication with affected persons and preservation of evidence.
{{org_field_name}} will:
- Work in partnership with client organisations to manage critical and serious incidents effectively
- Support client-led investigations and comply with client-specific reporting requirements
- Provide relevant information and reasonable assistance to support a client’s statutory notifications, without assuming responsibility for a notification that legally belongs to the client.
- Collaborate in post-incident learning, service improvement, and client safeguarding arrangements
- Agree named incident and safeguarding contacts, including out-of-hours contacts.
- Clarify whether the worker is employed by the agency for health and safety and RIDDOR purposes.
- Require the client to notify the agency promptly of any allegation, injury, police involvement, safeguarding referral, removal from duty, CQC notification or professional concern involving an agency worker.
- Require the client to provide sufficient information for the agency to assess risks to other assignments.
- Request written confirmation of external reports made by the client where this is relevant to the agency’s own duties.
- Avoid duplicate interviews where these may unnecessarily distress witnesses or compromise another process.
- Establish who will communicate with the patient, service user, family or complainant.
- Ensure that information-sharing complies with data-protection legislation.
- Escalate disagreements concerning safety or reporting responsibility to senior management.
- Reserve the right to cease supplying workers where a client obstructs lawful reporting, fails to manage serious risks or does not cooperate with necessary enquiries.
18. Governance, Monitoring and Audit
The Responsible Director will:
- maintain oversight of the incident register and outstanding actions;
- review serious incidents and emerging themes at appropriate governance meetings;
- monitor reporting timeliness, investigation quality and action completion;
- audit compliance with safeguarding, RIDDOR, data-breach, DBS-referral and professional-referral procedures;
- review repeated incidents connected with particular workers, clients, locations or types of assignment;
- ensure that learning results in measurable changes to recruitment, matching, training, supervision or client arrangements;
- report significant risks and unresolved actions to the agency’s governing body or senior leadership;
- retain evidence of policy reviews, audits and corrective action.
19. Agency Status and Division of Responsibilities
{{org_field_name}} operates as an employment business supplying temporary workers to client organisations. It does not itself provide, manage or direct personal care or another regulated activity and does not assume the client’s responsibility for the delivery of care or treatment.
The client organisation is responsible for:
- managing and supervising the placement at its premises;
- providing a safe system of work, site induction and relevant risk information;
- managing the immediate response to incidents at its service;
- meeting its obligations as a registered provider, where applicable;
- making CQC notifications and applying the statutory Duty of Candour, where applicable;
- operating its safeguarding, clinical-governance and patient-safety procedures.
{{org_field_name}} is responsible for:
- responding to incidents as an employment business and, where applicable, as the worker’s employer;
- obtaining and communicating information necessary for the suitability and safe placement of workers;
- taking proportionate action concerning the worker’s continued supply;
- complying with its own health and safety, employment, data-protection, safeguarding and recruitment-sector duties;
- considering RIDDOR, DBS, professional-regulator and other referrals where responsibility rests with the agency;
- cooperating with client and statutory investigations.
These responsibilities may overlap. The existence of a client investigation does not remove the agency’s obligation to assess and discharge its own duties.
20. Incident Triage and Risk Classification
On receipt of an incident report, the Responsible Director or on-call manager must carry out and record an initial triage assessment addressing:
- whether anyone remains at immediate risk;
- whether emergency services are required;
- whether the worker should remain on duty;
- whether other assignments or service users may be affected;
- whether safeguarding, police, RIDDOR, ICO, DBS or professional-regulator notification may be required;
- whether the client is leading the response;
- whether evidence requires immediate preservation;
- whether insurance or legal notification is required;
- whether senior leadership must be informed.
Incidents may be classified internally as:
- Level 1 — Low: limited impact, no continuing risk and capable of routine local management;
- Level 2 — Moderate: actual harm or material service disruption requiring management review and corrective action;
- Level 3 — Serious: serious harm, significant safeguarding or professional concern, likely external notification or removal from assignment;
- Level 4 — Critical: death, life-threatening harm, widespread risk, major criminal allegation, major data breach or substantial business disruption requiring immediate executive oversight.
The internal level does not determine whether an event is legally reportable. Statutory thresholds must be assessed separately.
21. Suitability, Assignment Information and Future Supply
Following an incident, {{org_field_name}} will review whether:
- the agency obtained sufficient information from the client about the position, location, hours, risks, experience, training and qualifications required;
- the worker had the qualifications, experience, training and authorisations required for the role;
- any legal or professional requirement prevented the worker from undertaking the work;
- the worker received sufficient assignment information and site induction;
- the client disclosed relevant health and safety risks;
- the worker was asked to perform tasks outside their competence or agreed assignment;
- additional checks, training, supervision or restrictions are required before future supply.
The agency will not continue to supply a worker to a role where it knows or has reasonable grounds to believe that the worker is unsuitable, lacks a required qualification or presents an unmanaged risk.
Any restriction on future supply will be documented, proportionate, reviewed and communicated only to persons who need the information for a lawful purpose.
22. Concerns About a Client Organisation
Where an incident indicates unsafe staffing, abuse, neglect, unlawful practice, inadequate supervision, obstruction of reporting or another serious concern about a client, {{org_field_name}} will:
- escalate the concern to an appropriate senior person within the client organisation;
- consider a safeguarding or regulatory referral where necessary;
- assess the safety of all workers supplied to that client;
- consider pausing or terminating supply;
- document the concern, action taken and outcome;
- support workers who raise genuine concerns;
- ensure that commercial considerations do not override safety or legal obligations.
23. Policy Review
This policy will be formally reviewed at least annually and sooner where:
an enforcement body, safeguarding authority, insurer or professional regulator recommends a change.
legislation, statutory guidance or regulatory requirements change;
a serious incident identifies a weakness in the policy;
an audit identifies non-compliance;
there is a material change in the services, worker-engagement model or client base of {{org_field_name}};
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.