Could Quality Audits Become Continuous Rather Than Periodic? The Future of Assurance in Adult Social Care

A service can pass a monthly audit on Monday and begin to deteriorate on Tuesday. Medication documentation may become inconsistent, supervision can slip, incidents may start clustering around particular shifts, agency use can increase and people may begin experiencing less continuity long before the next formal audit is due. Periodic assurance remains valuable, but the interval between reviews can become a blind spot.

The emerging question is whether quality assurance can become more continuous without becoming intrusive, bureaucratic or falsely automated. The Quality Assurance Knowledge Hub explores governance, auditing, learning systems and continuous improvement across adult social care. A more continuous model extends that thinking by asking whether providers can detect changes in quality earlier, combine different forms of evidence more intelligently and intervene before isolated weaknesses become service-wide problems.

This is not an argument for abandoning scheduled audits. Nor does it mean every action, conversation or care interaction should be monitored in real time. The stronger model is one in which periodic audits sit within a wider system of quality monitoring, operational intelligence, people’s feedback, workforce information and targeted verification. Formal audit then becomes one part of assurance rather than the only moment at which leaders look closely.

This article focuses on regulated adult social care in England. It examines how continuous assurance could work in practice, how CQC expectations connect with the idea, what governance controls would be required, where technology could help, what evidence should remain human-led and how providers can avoid creating a surveillance culture in the name of quality.

Periodic audits answer an important but limited question

Traditional audits usually ask whether a defined area of practice met an agreed standard at a particular point in time. A medicines audit may review a sample of MAR records. A care-plan audit may test whether assessments and reviews are complete. A health and safety audit may examine checks, incidents and environmental risks. These processes remain essential because they create structured scrutiny and can expose issues that routine operational oversight misses.

The limitation is temporal. An audit provides evidence about what was sampled, when it was sampled and how the reviewer interpreted it. It does not automatically show whether the position was better or worse three weeks earlier, whether a weakness is accelerating or whether an apparently compliant record reflects consistent frontline practice.

This is why mature audit and compliance systems increasingly need to distinguish between a snapshot and a trend. A single missed signature may be an isolated documentation error. Five similar errors across different services, combined with increased medication incidents and reduced competency observations, may indicate a wider control problem.

The central operational challenge is therefore not whether periodic audits should disappear. It is whether providers can reduce the time between a risk emerging and leadership recognising it.

Continuous assurance is not the same as continuous auditing

The distinction matters. Continuous auditing implies that audit activity itself is happening constantly. Continuous assurance is broader. It means that leaders maintain an ongoing view of whether important quality controls remain effective, drawing on multiple sources of information and escalating when patterns change.

Some evidence may be generated automatically. Digital care systems may identify overdue reviews, missed entries, unusual medication patterns or repeated rota changes. Other evidence remains deeply human: observation of practice, conversations with people, supervision, professional judgement, complaints, family feedback and the interpretation of subtle changes in behaviour or wellbeing.

The strongest model brings these sources together rather than privileging whichever system produces the easiest metric. Continuous assurance should therefore combine:

  • routine digital and operational indicators;
  • scheduled and risk-based audits;
  • direct observation and competency validation;
  • people’s experiences, complaints and feedback;
  • incidents, safeguarding concerns and near misses;
  • workforce, continuity and supervision information; and
  • leadership review of trends, exceptions and unresolved actions.

This creates a more dynamic relationship between quality data, KPIs and performance metrics and operational judgement. Data can indicate where leaders should look. It should not be treated as proof that practice is either good or poor without interpretation.

The Quality Dashboard Builder can help providers structure this broader picture by combining indicators across quality, workforce, incidents, outcomes and governance. The value lies not in producing more reporting, but in identifying meaningful variation and ensuring that exceptions generate proportionate review.

Why the interval between audits can hide emerging deterioration

Quality rarely collapses in one dramatic moment. More often, small changes accumulate. A Registered Manager takes on additional responsibilities. Supervision slips. Two experienced workers leave. Agency use rises. New staff are technically inducted but have limited confidence. Documentation becomes shorter. Complaints remain low because families deal directly with familiar staff rather than use formal channels.

A monthly or quarterly audit may eventually identify the consequences, but by then the pattern may be embedded. The advantage of continuous assurance is that several weak signals can be viewed together.

For example, one late supervision record is unlikely to indicate serious risk. A service with falling supervision completion, increased sickness, more rota changes, repeated medication queries and declining family feedback presents a different picture. No individual data point proves deterioration, but the pattern justifies earlier leadership attention.

This connects closely with root cause analysis and thematic learning. Mature assurance asks not simply whether a metric breached a threshold, but whether several indicators may share a common operational cause.

Operational scenario: the service that still looks compliant

A supported living service receives a strong quarterly internal audit. Care plans are current, medication records are complete and training compliance is high. There are no open safeguarding enquiries and the manager has closed all previous improvement actions.

Over the following six weeks, however, several small changes occur. Two experienced support workers leave, the service begins using more agency cover and supervision completion falls. One person’s family reports that unfamiliar staff are asking them repeatedly about communication preferences that should already be known. Another person begins refusing a regular community activity because staffing changes make the routine unpredictable.

No single event triggers a formal quality escalation. The next audit is still six weeks away.

Under a continuous assurance model, the workforce dashboard shows reduced team continuity while the care system records more frequent changes to support notes and several cancelled activities. Family feedback is added to the service quality review. The Registered Manager recognises that formal compliance remains strong but relational continuity is weakening.

The provider does not wait for the next audit. It stabilises agency use around a smaller group of workers, introduces targeted shadowing, checks communication plans through observation and reviews how staff changes are affecting people’s routines. The next formal audit still takes place, but it now verifies whether the intervention worked rather than discovering the problem for the first time.

The distinction is important: continuous assurance has not replaced audit. It has changed the point at which the organisation becomes curious.

CQC assurance increasingly depends on triangulation

CQC does not require providers to operate a continuous auditing model, nor is there a prescribed digital system that demonstrates compliance. The regulatory issue is whether the provider has effective governance arrangements, understands risks, learns from information and can demonstrate that quality is monitored and improved.

Evidence is rarely persuasive in isolation. A provider may present strong audit results, yet people describe inconsistent care. Training completion may appear excellent while staff cannot demonstrate competence. Incident numbers may be low because reporting culture is weak. Conversely, a temporary rise in incident reporting may reflect a stronger learning culture rather than declining care.

This is why CQC evidence and provider assurance increasingly depends on triangulation. Leaders need to connect records, outcomes, workforce information, observations and people’s experiences into a coherent account of how the service is operating.

The CQC Evidence Gap Analyzer can help providers examine whether their evidence is concentrated too heavily in policies, audits or completion reports and identify where additional triangulation may be needed. It should support professional review rather than be treated as evidence that regulatory expectations have automatically been met.

A continuous model potentially strengthens this approach because evidence is considered as it changes. The provider can show not simply that audits occur, but that leaders notice deterioration, intervene, test the effect and adjust again if necessary.

Continuous assurance changes the role of the audit function

If more quality intelligence becomes available between formal audits, internal audit can become more targeted. Instead of spending the same amount of time reviewing every service against an identical timetable, quality teams can direct deeper scrutiny towards areas where intelligence suggests greater uncertainty or risk.

This does not mean high-performing services should never receive formal review. Independent challenge remains important because stable indicators can hide weak culture or inaccurate data. The change is that audit schedules can become partly risk-informed rather than purely calendar-driven.

A mature internal quality review model may therefore include a planned baseline programme plus responsive reviews triggered by emerging evidence. A service with sustained improvement may receive a lighter-touch review focused on verification. A service showing contradictory data may receive a deeper thematic audit.

This can make quality teams more valuable operationally. Their role shifts from identifying historic non-compliance towards helping the organisation understand why performance is changing and whether interventions are genuinely effective.

Automation can identify exceptions, but it cannot judge care quality alone

Digital systems make continuous assurance increasingly feasible because they can identify patterns that would be difficult to detect manually. Electronic care records can highlight overdue reviews. Workforce systems can identify repeated gaps in supervision. Medication systems can flag missing administration records. Scheduling platforms can show continuity deterioration or unusually high reliance on particular workers.

Automation can also reduce the amount of routine checking performed by quality teams. Rather than manually reviewing every record for basic completeness, systems may identify exceptions for human investigation. This creates the possibility of shifting quality capacity from checking whether fields are complete towards interpreting whether practice is safe, person-centred and effective.

However, automation creates its own risks. A system may treat completion as quality, classify an unusual but legitimate practice as an exception or fail to recognise a serious issue because the underlying record appears technically compliant. Poorly configured alerts can also create noise, causing staff to ignore important signals among hundreds of low-value notifications.

This makes digital audit, assurance and compliance a governance issue rather than simply an IT project. Providers need to understand what the system measures, how thresholds are set, who receives alerts, how false positives are managed and what happens when data quality is weak.

The Digital Transformation Readiness Assessment can help organisations examine whether data maturity, workforce capability, information governance and system integration are strong enough to support more automated assurance. Technology becomes useful only when the surrounding operational controls are credible.

The danger of turning quality assurance into surveillance

Continuous visibility can easily become excessive monitoring. If every action taken by care workers is measured, scored and compared without context, assurance can damage trust and create defensive behaviour. Staff may focus on satisfying the system rather than exercising professional judgement.

There is also a risk that technology encourages organisations to measure what is easy rather than what matters. Recording frequency can be measured. Compassion cannot. Login times can be measured. Whether a worker recognised that a person was unusually withdrawn may depend on relationship, observation and experience.

Continuous assurance should therefore be proportionate. Its purpose is to identify organisational risk and support improvement, not to create permanent individual performance surveillance. Where employee-level information is used, providers need clear governance, lawful data processing, transparency and fair interpretation.

The quality culture matters particularly here. If staff believe every exception will result in blame, they may alter recording behaviour or avoid raising concerns. A mature learning-from-incidents approach recognises that useful intelligence depends on people feeling able to report uncertainty, mistakes and near misses.

Continuous assurance becomes counterproductive if it drives risk underground.

People using services should be part of the continuous evidence stream

Quality intelligence should not be dominated by organisational systems. People receiving support often recognise deterioration before performance indicators change. They notice that workers are more rushed, that familiar routines are being missed, that preferred activities are cancelled or that they are repeatedly explaining the same information to new staff.

Traditional feedback systems often collect these experiences periodically through annual surveys, reviews or complaints processes. Continuous assurance creates an opportunity to hear people more regularly without turning every interaction into a questionnaire.

Providers may use a combination of structured conversations, key-worker reviews, family and advocate feedback, accessible digital channels, co-production groups and targeted quality visits. The important issue is whether feedback reaches decision-makers and whether patterns are identified across services.

This makes service-user feedback and co-production part of assurance rather than a parallel engagement activity. If several people describe the same issue, the organisation should be able to connect that experience with staffing, incidents, records and operational context.

The provider should also consider whose voice is least visible. People who communicate non-verbally, people with profound disabilities, those who lack family involvement and people who may fear complaining require different approaches. Continuous assurance is only stronger if it improves visibility for those who are otherwise least likely to appear in formal feedback data.

Operational scenario: feedback reveals what the dashboard missed

A residential service for older people reports strong quality indicators. Medication errors are low, staffing levels remain within planned establishment and scheduled audits are completed on time. The board dashboard shows no significant concerns.

During a quality visit, however, several residents describe evenings as increasingly rushed. They report that staff complete essential personal care but have less time to support preferred routines, conversation and preparation for bed. No formal complaints have been made.

The quality lead compares this feedback with workforce data. Headcount is stable, but sickness has increased and evening shifts are increasingly being covered through additional hours from day staff. Care tasks are being completed, so compliance metrics remain largely unchanged.

Rather than dismissing the issue because staffing ratios are technically met, the provider reviews workload, dependency, call-bell patterns, sickness and staff feedback. The analysis shows that evening capacity has become fragile even though total staffing remains adequate.

The rota is redesigned, one vacancy is recruited specifically around evening availability and managers introduce short-term observation of evening routines. Resident feedback is repeated six weeks later.

The improvement is verified not because an audit score rises, but because residents describe greater choice and less rushing while call-bell delays and overtime reduce. Continuous assurance has added lived experience to the organisation’s interpretation of workforce data.

Registered Managers need fewer disconnected audits and better intelligence

Registered Managers often receive assurance requirements from multiple directions. Medicines audits, care-plan reviews, infection-control checks, health and safety inspections, supervision monitoring, incident analysis, safeguarding reviews and commissioner reporting may all operate separately.

The risk is that managers spend substantial time proving oversight without gaining a coherent view of their service. Continuous assurance should reduce fragmentation rather than add another reporting layer.

The stronger approach is to identify a limited number of critical controls and risks, then make it easier for managers to see when those controls are weakening. Routine information should be drawn from existing systems wherever possible. Manual reporting should be reserved for areas requiring judgement or context.

This connects with Registered Manager support. Managers need the authority and organisational backing to act on emerging risks. A dashboard that shows deteriorating continuity is of limited value if the manager cannot influence recruitment, restrict new admissions or obtain support from senior operations.

Continuous assurance therefore depends as much on organisational decision-making as on data availability.

Governance needs to define who acts when an indicator changes

One of the weaknesses of many assurance systems is that they generate information without defining responsibility. Reports identify overdue actions or negative trends, but ownership remains unclear. A continuous model would magnify that problem if alerts and indicators increase without corresponding decision rights.

Governance should therefore establish what happens when a threshold is breached. Some issues can be managed within the service. Others require regional, clinical, quality or executive escalation. Serious safeguarding concerns still require appropriate statutory and organisational responses; they should never be reduced to a dashboard exception.

Leadership teams should be clear about:

  • which indicators trigger local review;
  • which combinations of evidence require escalation;
  • who can commission a targeted audit;
  • when an issue enters the organisational risk register;
  • who owns corrective action and timescales; and
  • what evidence is required before an issue is considered resolved.

The Governance Maturity Assessment can help leadership teams test whether risk ownership, delegated authority and assurance lines are sufficiently clear. Continuous information becomes valuable only where the organisation can convert it into timely decisions.

This strengthens decision-making and escalation by connecting evidence with explicit responsibility rather than assuming managers will interpret every warning consistently.

Board assurance should shift from completion towards control effectiveness

Boards and trustees often receive high-level assurance such as audit completion percentages, policy compliance and numbers of overdue actions. These measures remain useful, but they do not necessarily show whether controls are effective.

A provider may complete 100% of scheduled audits while repeatedly identifying the same weaknesses. Another may report very few overdue actions because issues are closed once paperwork is updated rather than when practice changes. Continuous assurance creates an opportunity to move board attention towards whether risks are reducing and improvement is being sustained.

Stronger board evidence might include service-level variation, recurrence of audit findings, time taken to resolve high-risk exceptions, links between workforce pressure and quality indicators, people’s experience trends and evidence that corrective actions remain effective several months later.

This is the distinction between reporting activity and providing assurance. Strong quality assurance, governance and board oversight should help leaders understand whether organisational controls are working under normal operational pressure, not merely whether they have been performed.

Boards should also challenge the quality of the data itself. If digital information increasingly influences assurance, leadership needs confidence that definitions are consistent, missing data is visible and automated reporting has not obscured local context.

Commissioners may increasingly expect more dynamic assurance

Local authority and NHS commissioners already receive significant amounts of provider performance information, but contract monitoring is often retrospective. Data is submitted monthly or quarterly, discussed at review meetings and acted upon after variation has already occurred.

A more mature model could support earlier conversations. Providers might identify emerging continuity pressure, increasing agency dependence or repeated quality exceptions before contractual thresholds are formally breached. Commissioners could then distinguish between organisations that understand and manage risk proactively and those that disclose problems only after performance has deteriorated.

This does not mean commissioners should demand unrestricted access to live provider systems. Information-sharing needs to remain proportionate, contractually clear and consistent with data-protection responsibilities. Providers also need space to manage routine operational variation without every internal exception becoming a contract escalation.

The stronger opportunity is to improve the quality of regulatory and commissioner alignment. Internal assurance, CQC evidence and contract monitoring should not become three entirely separate industries of reporting. Where possible, common evidence should support several legitimate assurance purposes while retaining appropriate context.

The Commissioner Evidence Builder can help providers structure performance, quality and improvement evidence for commissioner conversations. Its value is greatest where it turns internal intelligence into a coherent account of risks, actions and outcomes rather than simply increasing reporting volume.

Continuous assurance should detect drift, not eliminate professional judgement

One of the strongest uses of continuous assurance is detecting gradual drift. Practice may move slowly away from agreed standards without anyone making an explicit decision to change. Staff shortcuts become normal, documentation becomes less meaningful, supervision becomes administrative and temporary workarounds become permanent.

Digital data can expose some of this. Repeated late entries, increasing exceptions or persistent action-plan delays may indicate control fatigue. But cultural drift is often visible first through observation and conversation.

Quality teams therefore still need to visit services, speak with people, observe practice and challenge what has become normal. Continuous assurance should make those human reviews more intelligently targeted, not remove them.

This aligns with embedding learning into day-to-day practice. Improvement becomes credible when policy, supervision, coaching, observation and service design change together. A metric can show that something moved; human review is usually needed to establish why.

Continuous auditing of safeguarding would require particular caution

Safeguarding generates some of the most important quality intelligence in adult social care, but it cannot be reduced to automated pattern recognition. A rise in safeguarding referrals may indicate deteriorating practice, increased risk or simply a healthier reporting culture. A fall may indicate improvement or under-reporting.

Systems can help identify repeated themes, locations, individuals or types of incident, but professional and statutory judgement remains essential. Serious concerns need immediate protection, appropriate escalation and liaison with local authority safeguarding processes where thresholds are met.

Continuous assurance may nevertheless strengthen prevention. Providers can connect safeguarding concerns with staffing, complaints, incidents, supervision and quality findings to identify emerging organisational vulnerabilities earlier.

This is where safeguarding audit, assurance and board oversight becomes particularly important. Governance should test not only whether referrals were made appropriately, but whether themes are understood and whether preventive action has changed the underlying conditions.

Audit actions should remain open until improvement is evidenced

A common weakness in periodic audit systems is premature closure. An audit identifies a problem, an action is created, paperwork is updated and the action is marked complete. The organisation has evidence that something was done, but not necessarily that practice improved.

Continuous assurance creates the possibility of a stronger closure standard. Actions can remain under monitoring until subsequent evidence shows that the risk has reduced. This may include a follow-up audit, observation, trend data, feedback from people or evidence that incidents have not recurred.

This turns quality improvement plans and action tracking into a learning mechanism rather than an administrative closure process.

A mature provider might differentiate between implementation and effectiveness. Installing a new medication protocol is implementation. Demonstrating fewer administration errors, stronger staff competence and consistent practice over time is effectiveness. Both matter, but they are not the same evidence.

Operational scenario: repeated audit findings that never quite disappear

A domiciliary care branch repeatedly receives minor findings about late care-note completion. Each month the issue is added to the action plan, staff are reminded of expectations and the action is closed when completion rates temporarily improve.

Over six months, the same issue returns four times. No individual episode appears serious enough to trigger wider intervention.

A continuous assurance review combines documentation timing with rota data and travel information. It shows that late recording is concentrated in workers covering a particular geographic route. Those workers regularly finish calls late because travel assumptions between visits are unrealistic. Notes are then completed retrospectively after shifts.

The issue is not primarily poor staff compliance. It is a rota-design problem.

The branch adjusts travel allocations, reviews visit sequencing and tests whether the change affects punctuality and recording quality. The action remains open for eight weeks while the provider monitors both measures.

Late recording falls and staff report less pressure. The finding is then closed because the underlying cause has changed, not simply because employees were reminded again.

This is the kind of improvement continuous assurance can enable: repeated audit findings become data about system design rather than recurring evidence of individual failure.

AI may support future assurance, but its role should remain bounded

Artificial intelligence could eventually help quality teams identify combinations of indicators that humans might overlook. It may assist with thematic analysis of large volumes of incident reports, identify repeated concerns across services or highlight unusual variation in workforce and quality data.

These uses are emerging rather than standard practice. They also raise significant questions about transparency, bias, data quality and accountability. An AI model may identify a pattern without being able to explain the operational context. Historical data may reproduce old assumptions. Generated summaries may omit nuance or overstate certainty.

Any use of AI in assurance should therefore retain human accountability. The technology may suggest where to investigate; it should not determine that a worker, manager or service is unsafe without professional review.

This makes AI and automation in care relevant to governance as much as innovation. Leaders need to understand how outputs are generated, what data is used, where human verification occurs and how inaccurate conclusions can be challenged.

The future is likely to be a hybrid assurance model

The most plausible future is neither wholly periodic nor wholly continuous. Adult social care providers are more likely to develop hybrid systems.

Formal audits will remain important for structured independent scrutiny. Continuous indicators will provide earlier warning. Targeted reviews will examine unusual patterns. People’s feedback and observation will test whether digital data reflects lived experience. Governance forums will focus more heavily on exceptions, trends and repeated failure.

The balance will vary by provider size and service model. A small supported living organisation may use a simple monthly dashboard and frequent manager observation. A national provider may integrate multiple digital systems and use automated exception reporting. Both can operate mature assurance if controls are proportionate and decisions remain clear.

What matters is not the sophistication of the platform. It is whether the assurance architecture identifies risk early enough, produces useful challenge and leads to demonstrable improvement.

Building continuous assurance without increasing bureaucracy

Providers should resist the temptation to respond by creating dozens of new indicators. More data can make assurance weaker if leaders cannot distinguish signal from noise.

A proportionate model begins with the risks that matter most. What could significantly affect safety, rights, continuity or quality of life? Which controls should show early signs of deterioration? Which data already exists? Where is human observation indispensable?

Existing systems should be integrated before additional reporting is created. If scheduling, care records, incident systems and workforce platforms already generate useful information, quality teams should draw from those sources rather than asking managers to enter the same data elsewhere.

The organisation can then establish thresholds, exception routes and review rhythms. Some information may require daily attention, some weekly and some monthly. Continuous assurance does not mean every metric is watched continuously.

Over time, providers can test which indicators genuinely predicted problems and remove those that created noise. This connects directly with continuous improvement: the assurance system itself should learn.

Conclusion

Periodic quality audits will remain an important part of adult social care assurance, but they are unlikely to be sufficient on their own for increasingly complex, digitally enabled services. A quarterly audit can confirm what was sampled on the day. It cannot by itself provide continuous visibility of changing workforce pressure, emerging practice drift, deteriorating continuity or the early signals contained in people’s experiences.

The stronger direction is a hybrid model in which scheduled audits are supported by operational data, digital exceptions, direct observation, workforce intelligence, feedback, incidents and targeted human review. The purpose is not permanent surveillance and it is not to automate judgement. It is to reduce the delay between deterioration beginning and the organisation becoming aware of it.

For providers in England, the governance challenge is as important as the technology. Leaders need clear thresholds, reliable data, defined responsibilities and evidence that corrective actions genuinely improve practice. Registered Managers need usable intelligence rather than additional reporting, boards need visibility of control effectiveness rather than completion percentages and people drawing on care and support need to remain central to the interpretation of quality.

The future of quality standards and assurance frameworks is therefore unlikely to be the disappearance of the audit. It is the development of an assurance system that learns continuously, intervenes proportionately and uses formal audit as one powerful source of evidence within a much wider understanding of how care is actually being experienced.