{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Working with External Providers and Agencies in Home Care Policy
1. Purpose
The purpose of this policy is to establish a structured, transparent, and effective framework for working with external providers and agencies to ensure that service users receive high-quality, safe, and person-centred care. Our home care service collaborates with external providers to enhance the range of services available, ensuring that service users have access to specialist support, medical care, social services, and other essential resources.
This policy supports compliance with the Regulation and Inspection of Social Care (Wales) Act 2016, the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017, as amended, the Social Services and Well-being (Wales) Act 2014, the Data Protection Act 2018, the UK General Data Protection Regulation and the statutory guidance issued under section 29 of the Regulation and Inspection of Social Care (Wales) Act 2016. The service provider and responsible individual remain accountable for compliance with these requirements where any activity, staffing function or element of care and support is provided by an external provider or agency.
Our organisation manages external provider relationships efficiently through clear partnership agreements, service level expectations, robust communication protocols, and continuous monitoring of service quality.
2. Scope
This policy applies to:
- All staff, including care workers, supervisors, and managers, who liaise with external providers.
- Service users and their families, where external support services are engaged.
- External providers and agencies, including but not limited to:
- NHS and primary healthcare providers (GPs, nurses, occupational therapists, physiotherapists).
- Local authority social services and safeguarding teams.
- Private healthcare and therapy services (palliative care, mental health specialists, dementia support groups).
- Community and voluntary sector organisations (charities, advocacy services, befriending schemes).
- Care equipment suppliers and assistive technology providers.
- External recruitment agencies supplying temporary staff.
It covers:
- Selection, vetting, and engagement of external providers.
- Service level agreements and contractual arrangements.
- Collaboration, communication, and coordination of care.
- Quality assurance, monitoring, and compliance checks.
- Safeguarding, confidentiality, and data protection considerations.
2.1 Retained Regulatory Accountability
The engagement of an external provider, contractor, employment agency or individual working under a contract for services does not transfer or reduce the statutory responsibilities of the service provider, responsible individual or registered manager.
The service provider must remain satisfied that:
- all care and support continues to be delivered with sufficient care, competence and skill;
- care and support is consistent with the service’s statement of purpose and the individual’s personal plan;
- individuals remain safe and protected from abuse, neglect and improper treatment;
- sufficient numbers of suitably qualified, trained, skilled, competent and experienced workers are deployed;
- all required records are made, maintained and available to the service;
- concerns, incidents, complaints and safeguarding matters are reported and acted upon; and
- the responsible individual retains effective oversight of the quality, safety and compliance of the service.
No external provider may independently change an individual’s agreed care, support, medicines, risk-management arrangements or personal plan. Any necessary change must be referred to the registered manager or an authorised competent person for assessment, agreement, recording and, where required, consultation with the individual, representative, commissioner or relevant professional.
3. Selecting and Vetting External Providers
3.1 Criteria for Working with External Providers
Before engaging an external provider or agency, we ensure that they:
- Hold every registration, licence, approval or professional registration legally required for the service or activity they will provide. The service must verify the registration directly with the relevant regulator before engagement and at appropriate intervals thereafter. This includes checking CIW registration where the organisation itself provides a regulated service and checking the current professional or Social Care Wales registration of individual workers where their role requires registration.
- Have the capacity to meet each individual’s identified language and communication needs, including Welsh-language needs, communication aids and alternative communication methods recorded in the individual’s personal plan.
- Have demonstrated experience and competence in delivering the required service.
- Adhere to safeguarding and quality standards consistent with our own policies.
- Have adequate insurance and liability cover.
- Comply with GDPR and data protection laws.
We prioritise working with trusted and established organisations to ensure service user safety and service continuity.
3.2 Vetting and Due Diligence Process
To protect service users and ensure compliance, all external providers undergo a robust vetting process, including:
- Reference checks and verification of credentials.
- Written evidence that every external or agency worker who may have regular contact with individuals satisfies the fitness requirements applicable to the role. Before the worker begins work, the service must obtain or verify:
- proof of identity and the person’s right to work;
- a full employment history, including a satisfactory written explanation of any gaps;
- relevant qualifications, skills, competence and experience;
- satisfactory references, including verification of the references;
- information concerning the person’s health and ability to perform the intrinsic functions of the role, subject to reasonable adjustments;
- a current enhanced DBS certificate, including the appropriate barred-list information where the role is eligible;
- the outcome of a DBS Update Service check, where applicable;
- current registration with Social Care Wales or another professional regulator where registration is required; and
- any other information required by Schedule 1 to the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017.
- Where the worker is registered with the DBS Update Service, the service provider must ensure that the worker’s certificate status is checked at least annually. Where the worker is not registered with the Update Service, a new DBS certificate must be obtained within three years of the previous certificate and at least every three years thereafter.
- The service must retain evidence demonstrating that the agency completed the required checks. A verbal assurance or a general statement that the agency has undertaken checks is not sufficient.
- The service provider must assess the reliability and robustness of the agency’s recruitment and vetting arrangements and must not deploy a worker until the required evidence has been received and reviewed by an authorised person.
- Review of policies and procedures, ensuring alignment with CIW standards.
- A signed agreement outlining service expectations, roles, and responsibilities.
If an external provider fails to meet required standards, we will not proceed with the engagement and will seek alternative options.
4. Service Agreements and Contractual Arrangements
4.1 Formalising Agreements with External Providers
All external provider relationships must be documented through:
- Service Level Agreements (SLAs) or contracts, outlining:
- Scope of services to be provided.
- Roles and responsibilities of each party.
- Response times and service delivery expectations.
- Safeguarding and incident reporting requirements.
- A requirement for the external provider to notify the registered manager immediately of any accident, incident, error, omission, safeguarding concern, allegation, complaint, data breach, missed visit, late visit, medicines incident or other event affecting an individual’s safety or well-being.
- A requirement for the external provider to provide the service promptly with all information and records required to assess the incident, protect individuals, investigate the matter, respond to a complaint or safeguarding process, and make any statutory notification or referral.
- A requirement for the external provider to co-operate with CIW, safeguarding authorities, commissioners, the police, the Disclosure and Barring Service, Social Care Wales and other professional regulators where legally required.
- The service provider’s right to audit the provider’s relevant records, worker files, training evidence, registration status, DBS evidence, incident records and service-performance information.
- A prohibition on subcontracting any care or support activity without the service provider’s prior written approval and completion of equivalent due-diligence checks.
- Clear arrangements for continuity of care, emergency cover, missed or delayed visits, staff absence and termination of the agreement.
- Clear arrangements for returning or securely disposing of personal information and service records when the contract ends.
- Confidentiality and data sharing agreements.
- Where the external provider processes personal data on behalf of the service provider, a legally compliant written data-processing contract must be in place before processing begins. The contract must define the subject matter, duration, nature and purpose of the processing, the categories of personal data and data subjects, confidentiality requirements, security arrangements, assistance with data-subject rights and breaches, restrictions on sub-processors, deletion or return of data and the service provider’s audit rights.
- A designated point of contact within both organisations to facilitate communication and coordination.
4.2 Managing External Agency Staff
Where an external agency provides temporary or contract staff, the service provider must:
- verify and retain evidence that the worker satisfies all applicable fitness, DBS, registration, qualification and competency requirements before the worker is deployed;
- confirm the worker’s identity when they first attend the service and check that the person attending is the person whose records were supplied;
- provide an introduction before the worker undertakes unsupervised duties;
- ensure that the introduction covers the statement of purpose, the worker’s role and limits of authority, safeguarding, whistleblowing, complaints, medicines, incident reporting, emergency arrangements, data protection, confidentiality, lone working, record keeping, duty of candour and management and supervision arrangements;
- ensure that the worker has read and understood the personal plan, risk assessments, communication needs and any relevant healthcare or behavioural support instructions for each individual they support;
- assess and record the worker’s competence before permitting them to undertake specialised, delegated healthcare, medicines, moving and handling or other higher-risk activities;
- identify the manager or competent person responsible for directing, supporting and monitoring the worker;
- provide appropriate supervision and monitor the worker’s performance;
- ensure that use of temporary or agency workers does not prevent individuals receiving reasonable continuity of care;
- ensure replacement workers are familiar with the individuals they support and are introduced to individuals wherever practicable; and
- immediately remove the worker from duties where their fitness, conduct, competence, registration or practice may place an individual at risk.
Where an external worker may no longer be fit to work, may have harmed or placed an individual at risk, or is alleged to have committed serious misconduct, the service must take immediate and proportionate action to protect individuals. This may include removing the worker from duties, notifying the supplying agency, preserving evidence, commencing safeguarding and disciplinary or contractual procedures, and making any required referral to the Disclosure and Barring Service, Social Care Wales, another professional regulator, the police, the local authority and CIW. Requesting replacement staff or further training must not be used as an alternative to a mandatory safeguarding, regulatory or barring referral.
5. Collaboration, Communication, and Coordinated Care
5.1 Effective Multi-Agency Working
To ensure seamless care delivery, we promote strong collaboration and communication with external providers by:
- Holding regular meetings and case reviews with multi-disciplinary teams.
- Using secure communication channels to share relevant service user information.
- Ensuring that all external professionals understand the service user’s care plan, needs, and preferences.
- Recording within the individual’s personal plan the respective roles and responsibilities of the service, external providers and relevant professionals, including who is authorised to make decisions, provide advice, undertake delegated activities and respond to a deterioration or emergency.
- Ensuring that any advice, assessment, treatment instruction or change communicated by an external professional is promptly recorded, reviewed by an appropriately competent person and incorporated into the individual’s personal plan where necessary.
- Ensuring that delegated healthcare activities are accepted only where there is a clear written delegation, the activity is within the service’s statement of purpose, the worker has been trained and assessed as competent, appropriate monitoring is in place and the delegating professional retains the accountability required by their professional standards.
- Escalating concerns without delay where information from different professionals conflicts, responsibilities are unclear or the individual’s assessed needs are no longer being met.
5.2 Information Sharing, Confidentiality and Data Protection
Personal information must be shared only where there is an identified and lawful purpose. Before routine information sharing begins, the service must determine and document:
- the respective data-protection roles of the organisations;
- the lawful basis under Article 6 of the UK GDPR;
- the applicable condition under Article 9 where special-category information is involved;
- what information is necessary and proportionate to share;
- who is authorised to receive it;
- how it will be transferred, accessed, retained and securely disposed of; and
- how individuals will be given appropriate privacy information.
Consent must not be treated as the only lawful basis for sharing personal information. Consent will be obtained where consent is the appropriate lawful basis or where required by the common-law duty of confidentiality. Information may be shared without consent where another lawful basis applies, including where sharing is necessary to meet a legal obligation, protect vital interests, provide direct care, prevent or detect crime, or safeguard an adult or child at risk.
Where an individual lacks capacity to make a specific information-sharing decision, staff must act in accordance with the Mental Capacity Act 2005, including its statutory principles and best-interests requirements.
Staff must not delay necessary and proportionate information sharing where delay could expose an individual or another person to abuse, neglect, improper treatment or serious harm.
Only information that is adequate, relevant and limited to what is necessary may be shared. Information must be accurate, up to date, transferred securely and recorded in the individual’s records, including the purpose of the disclosure, the information disclosed, the recipient, the lawful basis and the person authorising the disclosure.
Routine information-sharing arrangements must be supported by an appropriate data-sharing agreement. Where an external organisation acts as a processor on behalf of the service provider, a compliant written data-processing contract must be in place.
6. Quality Assurance and Monitoring of External Providers
6.1 Ongoing Performance Monitoring
To maintain high-quality service standards, external providers will be subject to:
- Regular audits and reviews of their performance and compliance.
- Feedback from service users and families to assess satisfaction.
- Incident reporting and complaints investigations, ensuring quick resolution of concerns.
- Auditing compliance with worker fitness, DBS, registration, training, competency, safeguarding, information governance, record keeping, continuity of care, missed-visit reporting and contractual notification requirements. Audit findings, required actions, responsible persons and completion dates must be recorded and followed through to completion.
- Annual contract and service reviews, making improvements where necessary.
If an external provider fails to meet a legal, regulatory, contractual or safety requirement, the service must:
- take immediate action to protect individuals and maintain continuity of care;
- assess whether the failure constitutes a safeguarding concern, notifiable event, data breach, contractual breach or fitness-to-practise concern;
- record the concern, investigation, risk assessment, actions and outcome;
- issue a time-limited corrective action plan where continued engagement is safe and lawful;
- monitor completion and verify that the required improvement has occurred;
- suspend or terminate the arrangement where the risk cannot be safely managed or required improvements are not achieved; and
- make all required notifications and referrals.
7. Safeguarding, Complaints, and Incident Reporting
7.1 Safeguarding Responsibilities
External providers and agency workers must comply with the service’s Safeguarding Adults from Abuse and Improper Treatment Policy, the Wales Safeguarding Procedures and applicable local safeguarding arrangements.
Any allegation, disclosure, evidence or suspicion of abuse, neglect or improper treatment must be reported immediately to the registered manager or safeguarding lead. Reporting internally does not replace the requirement to take immediate action or make an external safeguarding referral.
On receiving a safeguarding concern, the service must:
- take immediate action to secure the safety and well-being of the individual and any other person who may be at risk;
- obtain urgent medical assistance or contact the police where required;
- preserve evidence and avoid action that may compromise a police or safeguarding investigation;
- make an appropriate referral to the relevant local authority safeguarding team and any other relevant agency;
- notify the responsible individual;
- consider whether a CIW notification is required;
- consider whether a referral to the DBS, Social Care Wales or another professional regulator is required;
- record the evidence or substance of the allegation, immediate protective action, decisions, referrals, notifications and outcome; and
- ensure that the individual and, where appropriate, their representative are informed and supported in a manner suited to their communication needs.
Where the concern relates to an external or agency worker, the worker must not continue to undertake duties that could place individuals at risk while the concern is assessed. The supplying organisation must be informed only in a manner that does not compromise immediate safety, evidence preservation or the instructions of the police or safeguarding authority.
The registered manager and responsible individual must monitor all safeguarding referrals and outcomes and ensure that required improvements are implemented.
7.2 Statutory Notifications and Referrals
The registered manager must immediately inform the responsible individual of any event involving an external provider or agency worker that may require a statutory notification or referral.
The responsible individual must ensure that CIW is notified, through CIW Online, of events specified in the Regulations and within the applicable statutory timescale. Where authority to submit a notification has been delegated to an authorised online assistant, the responsible individual remains accountable for ensuring that the notification is accurate, complete and submitted.
Events must be assessed individually and may include:
- an allegation or incident of abuse, neglect or improper treatment;
- serious injury or an event significantly affecting an individual’s safety or well-being;
- police involvement concerning the service or a person working in it;
- a serious medicines, treatment or care error;
- a prolonged or serious disruption to the regulated service;
- an event affecting the fitness of a person working in the service; or
- any other event listed in the applicable notification schedules to the Regulations.
The service must also make referrals to the DBS, Social Care Wales or another professional regulator whenever the relevant statutory or professional referral criteria are met. A notification to one organisation does not replace a separate notification or referral required by another organisation.
7.3 Complaints and Dispute Resolution
A complaint concerning care or support provided through an external provider or agency must be accepted and managed under the service provider’s own complaints policy. The complainant must not be required to pursue the external provider before the service accepts or investigates the complaint.
The service provider must:
- acknowledge, record, investigate and respond to the complaint in accordance with its complaints procedure;
- ensure the external provider supplies relevant records and co-operates with the investigation;
- keep the complainant informed;
- provide information about advocacy and how the complaint may be escalated;
- assess whether the complaint also raises safeguarding, duty-of-candour, data-protection, contractual, CIW-notification or professional-referral issues;
- record the outcome and any remedial action;
- review whether the complaint identifies wider risks or required service improvements; and
- ensure that making a complaint does not adversely affect the care or treatment of the individual.
The external provider’s complaints procedure may be used in parallel where appropriate, but it does not replace the service provider’s responsibility to investigate complaints about the regulated service.
Where serious or repeated non-compliance is identified, the service must suspend or terminate the arrangement where necessary to protect individuals and maintain continuity of care.
7.4 Duty of Candour
Where an incident, error or omission involving an external provider or agency worker has caused, or may have caused, harm or distress, the service provider must act openly and transparently with the individual and any representative.
The service must:
- explain what is known about what happened in a clear and accessible manner;
- provide information about the immediate action taken to protect the individual;
- provide appropriate updates concerning the investigation and its outcome;
- offer an appropriate apology;
- explain what action will be taken to prevent recurrence; and
- maintain a record of the communication.
The service must not delay compliance with its duty of candour solely because the external provider is undertaking a separate investigation or has not accepted responsibility.
8. Staff Training and Responsibilities
All staff involved in liaising with external providers must:
- Undergo training on multi-agency working, safeguarding, and partnership management.
- Follow proper procedures for escalating concerns and sharing information.
- Understand that concerns involving an external provider must be reported through the service’s own safeguarding, incident, whistleblowing and complaints procedures and must not be left solely for the external organisation to address.
- Verify a worker’s identity and authorisation before permitting access to an individual, their home, medicines, records, keys, equipment or personal information.
- Record relevant communications, professional advice, changes, incidents, missed services and concerns promptly, accurately and in the individual’s records.
- Escalate immediately any instruction from an external provider that conflicts with the individual’s personal plan, assessed needs, legal rights, safety or expressed wishes.
- Co-operate with safeguarding enquiries, complaint investigations, audits and regulatory inspections.
- Ensure service users receive consistent and coordinated care from all providers involved.
Failure to comply with this policy may result in disciplinary action, in line with the Disciplinary and Grievance Policy (DCW31).
9. Related Policies
This policy should be read alongside:
- Safeguarding Adults from Abuse and Improper Treatment Policy (DCW13).
- Confidentiality and Data Protection (GDPR) Policy (DCW34).
- Risk Management and Assessment Policy (DCW18).
- Whistleblowing (Speaking Up) Policy (DCW29).
10. Policy Review
This policy will be reviewed annually or sooner if required due to regulatory changes, CIW inspections, or organisational improvements. The service provider is responsible for ensuring that the service is delivered in accordance with this policy. The registered manager is responsible for its day-to-day implementation, for maintaining the external-provider register and associated compliance evidence, and for escalating significant concerns. The responsible individual is responsible for maintaining effective oversight, reviewing evidence of compliance, ensuring that required notifications are made and confirming that identified improvements are completed.
Appendix 1 – External Provider and Agency Compliance Register
The registered manager must maintain an up-to-date register for each external provider and employment agency. The register must contain, where applicable:
- provider or agency name and address;
- service supplied;
- contract owner and operational contact;
- regulatory registration and date checked;
- professional registrations and dates checked;
- insurance details and expiry dates;
- data-protection role and agreement;
- contract commencement, review and expiry dates;
- due-diligence approval date;
- worker fitness and Schedule 1 evidence;
- DBS certificate or Update Service evidence and next review date;
- Social Care Wales or professional registration evidence;
- induction and competency records;
- safeguarding, complaint and incident-reporting arrangements;
- audit dates, findings and action plans;
- complaints, incidents, safeguarding concerns and statutory notifications;
- performance concerns and corrective action;
- contract suspension or termination decisions; and
- the name and signature of the person completing and approving each review.
Records must be retained securely and made available to the responsible individual and CIW when required.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.