{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Risk Management and Assessment Policy
1. Purpose
The purpose of this policy is to establish a structured approach to identifying, assessing, managing, and mitigating risks in the delivery of domiciliary care services. {{org_field_name}} is committed to ensuring that all risks associated with care provision, staff safety, and organisational operations are systematically managed to maintain high-quality, safe, and effective services.
Risk management is essential to:
- Protect the safety and well-being of service users, staff, and visitors.
- Comply with regulatory requirements under CIW and relevant legislation.
- Ensure effective decision-making in risk-related situations.
- Promote a culture of continuous improvement in service delivery.
2. Scope
This policy applies to:
- All care staff and support workers, who must follow risk management procedures.
- The Registered Manager and Responsible Individual, responsible for ensuring compliance and oversight.
- Service users and their families, ensuring they are aware of risks in home-based care.
- Contractors and external professionals, who must comply with safety procedures when working within service users’ homes.
3. Legal and Regulatory Framework
This policy is based on the legislation and CIW regulations, including:
- The Regulation and Inspection of Social Care (Wales) Act 2016 and associated regulations and statutory guidance.
- The Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017 (as amended), including requirements on governance, suitability of the service, personal plans, safeguarding, health and safety, medicines, record keeping and notifications.
- The Social Services and Well-being (Wales) Act 2014 (including the well-being principle and safeguarding duties).
- The Mental Capacity Act 2005 and Deprivation of Liberty Safeguards (DoLS) where applicable (including best interests decision-making and lawful authority for restrictions).
- The Equality Act 2010 and the organisation’s duty to make reasonable adjustments to ensure equitable access to safe care and support.
- UK GDPR and the Data Protection Act 2018 (confidentiality, lawful processing and information security).
- Health and safety legislation including HSWA 1974, Management of Health and Safety at Work Regulations 1999, Manual Handling Operations Regulations 1992, COSHH 2002, and RIDDOR 2013.
- Relevant professional and practice guidance, including Social Care Wales Codes of Professional Practice and guidance on the professional duty of candour.
4. Risk Management Process
4.1 Identifying Risks
{{org_field_name}} identifies risks in the following key areas:
- Service user risks, including falls, medical conditions, mobility issues, or medication errors.
- Workplace hazards, including lone working, manual handling, and infection control.
- Environmental risks, such as fire hazards, trip hazards, and poor home conditions.
- Data protection and confidentiality risks, ensuring compliance with UK GDPR and the Data Protection Act 2018.
- Business continuity risks, such as staffing shortages, financial risks, and emergencies.
How we manage this efficiently:
- Initial risk assessments are completed before care begins.
- Ongoing risk monitoring is integrated into care reviews.
- Incident reports and staff feedback help identify emerging risks.
4.2 Conducting Risk Assessments
Risk assessments are a systematic evaluation of hazards and their impact on service users, staff, and the organisation.
At {{org_field_name}}, risk assessments include:
- Person-centred risk assessments for each service user, detailing medical needs, mobility, and home environment.
- Workplace risk assessments, ensuring staff safety when delivering care.
- Specific risk assessments for medication administration, lone working, infection control, and safeguarding.
How we manage this efficiently:
- Standardised risk assessment templates ensure consistency.
- Dynamic risk assessments allow staff to make real-time decisions when entering unpredictable situations.
- Risk ratings (low, medium, high) guide decision-making and mitigation efforts.
Risk assessment and management will be person-centred and outcomes-focused and must be undertaken with the individual and, where appropriate, with their representative and other relevant professionals. Risk assessments must consider: the individual’s views, wishes and feelings, the potential impact on their well-being, and any reasonable adjustments needed to enable safe care and support. Where an individual may lack capacity to make specific decisions about risk, staff must follow the Mental Capacity Act 2005 principles and ensure decisions are made in the person’s best interests, with lawful authority in place where restrictions may amount to deprivation of liberty.
4.3 Implementing Risk Control Measures
Once risks are identified and assessed, control measures are put in place to reduce their likelihood and impact.
Common control measures include:
- Personal protective equipment (PPE) for infection control.
- Safe manual handling techniques to prevent injuries.
- Medication management protocols to avoid errors.
- Lone worker safety systems, including regular check-ins.
- Fire safety checks in service users’ homes.
How we manage this efficiently:
- Control measures are recorded in care plans and staff are trained accordingly.
- Regular reviews ensure that measures remain effective.
- Digital risk management systems help track control measures and updates.
4.4 Monitoring and Reviewing Risks
Risk management is an ongoing process, requiring regular reviews to ensure that identified risks remain under control.
{{org_field_name}} follows a structured review process, including:
- Routine risk reassessments as and when required, and at least every 3 months, and immediately where there is a significant change in need, circumstances, environment, staffing arrangements, or following any accident, incident, safeguarding concern or near miss.
- Incident reports analysis to identify patterns.
- Staff and service user feedback, ensuring risks are managed effectively.
How we manage this efficiently:
- A central risk register tracks all identified risks and actions taken.
- Lessons learned from past incidents inform future risk management strategies.
- Managers conduct random spot-checks to ensure compliance.
4.5 Emergency and Business Continuity Planning
Risk management includes preparing for emergencies, such as:
- Power outages affecting medical equipment.
- Staff shortages impacting care provision.
- Severe weather conditions preventing visits.
- Major health outbreaks (e.g., flu, COVID-19).
How we manage this efficiently:
- Emergency response plans are in place for all foreseeable risks.
- A backup staffing plan ensures continuity of care.
- Communication protocols ensure rapid response to crises.
4.6 Notifications and escalation to CIW and other agencies
To protect individuals and maintain regulatory compliance, {{org_field_name}} will ensure that notifiable events are identified promptly, escalated appropriately, and reported to Care Inspectorate Wales (CIW) without delay in the required format. Notifications must be made in line with the Regulated Services (Service Providers and Responsible Individuals) (Wales) Regulations 2017 (including Schedule 3 and Schedule 4 requirements).
Notifiable events include:
- Any abuse or allegation of abuse involving the provider and/or staff.
- Serious accident or injury to an individual.
- Outbreak of infectious disease.
- Any event which prevents, or could prevent, the provider from continuing to deliver the service safely (e.g., severe staffing shortfalls, loss of essential utilities impacting safe delivery).
- Certain DoLS-related notifications where applicable.
Notifications will be made using CIW Online (including any agreed delegation arrangements) and failure to notify may place the service in breach of regulatory requirements.
4.7 Duty of candour
{{org_field_name}} will act in an open and transparent way with individuals receiving care and support and, where appropriate, their representatives. When something goes wrong, we will ensure people receive timely information about what happened, the outcome of any review/investigation, and where appropriate an apology. We will promote a culture that supports staff to be open, raise concerns, and learn from incidents, and we will take action to prevent and address any bullying, victimisation or obstruction connected to candour. Our arrangements align with Social Care Wales guidance on the professional duty of candour and the statutory guidance expectations on candour.
5. Responsibilities in Risk Management
- Registered Manager: ensures risk assessments are completed, implemented, reviewed in line with Section 4.4, and embedded into personal plans and daily practice; ensures incidents/near misses are analysed and learning shared; ensures escalation pathways are followed.
- Responsible Individual (RI): ensures effective governance oversight of risk, including monitoring themes and trends from incidents, safeguarding, complaints and whistleblowing; ensures robust arrangements are in place for CIW notifications and duty of candour; seeks assurance that staff competence, staffing levels and operational controls reduce risk so far as reasonably practicable.
- Care Workers: follow risk controls, complete dynamic risk assessments, report changes and incidents immediately, and record actions taken in line with policy and procedures.
- Individuals and/or representatives: are supported to participate in risk discussions and agreed risk management approaches in a way that is accessible and person-centred.
6. Training and Staff Awareness
- All staff receive mandatory risk assessment training.
- Lone working, infection control, and manual handling training are refreshed annually.
- Staff are empowered to identify and report risks proactively.
In addition, training and competency assessment will include (as relevant to role):
- Safeguarding and recognising/escalating allegations or concerns.
- Mental Capacity Act 2005/DoLS awareness (capacity, best interests and lawful authority for restrictions).
- Duty of candour and how to communicate openly when things go wrong.
- Incident reporting and CIW notification requirements (what is notifiable and how to notify via CIW Online).
7. Related Policies
This policy aligns with:
- Health and Safety at Work Policy (DCW16).
- Lone Working and Staff Safety Policy (DCW23).
- Infection Prevention and Control Policy (DCW17).
- Fire Safety and Evacuation Procedures (DCW20).
- Management of Accidents, Incidents, and Near Misses Policy (DCW24).
8. Policy Review
This policy will be reviewed annually or sooner if required due to changes in legislation, business needs, or CIW regulations. The Registered Manager and Responsible Individual are responsible for ensuring its accuracy and implementation.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.