Evidencing Risk Management Under the CQC Quality Statements
Risk management under the CQC assessment framework is about more than completing risk assessments. Providers must show how risks are identified, reviewed, controlled and escalated in everyday care. The CQC quality statements for safe and responsive care expect risk controls to be practical, current and understood by staff.
This requires strong evidence and assurance for CQC inspection that connects care records, incidents, audits and management decisions. The CQC compliance knowledge hub for providers supports services to organise risk evidence clearly, while the CQC Evidence Gap Analyzer can help identify where risk-assessment evidence, frontline practice and governance assurance do not yet align.
Why this matters
Risks can change quickly in adult social care. A person’s mobility, cognition, medicines, nutrition, behaviour or environment may alter before the next scheduled review.
Commissioners and inspectors expect providers to evidence active risk management. They want to see how staff recognise change, how managers respond and how controls are checked for effectiveness. This is closely connected with CQC risk, safeguarding and restrictive practice, where the quality of everyday risk decisions matters as much as the existence of formal documentation.
Weak systems often fail because risk assessment becomes periodic rather than continuous. A risk document may still be technically in date while the person’s real-world needs have changed substantially.
A practical framework for risk management evidence
Providers should evidence risk management through assessments, daily observations, incident reports, professional advice, staff briefings, audits and governance review.
The strongest evidence shows the full route from concern to action. It should be clear who identified the risk, what changed, where it was recorded and how improvement was checked.
A useful evidence chain is:
- Signal: what changed or what concern emerged;
- Review: who assessed the significance of that change;
- Decision: what control or support adjustment was agreed;
- Implementation: how staff were informed and practice changed;
- Outcome: what happened after the intervention; and
- Assurance: how managers confirmed the control remained effective.
This approach links day-to-day risk management with quality monitoring systems rather than leaving risk assessment as a separate compliance task.
Operational Example 1: Managing Increased Falls Risk
Step 1: The care worker notices the person is holding furniture while walking, records the observation in the daily care note and alerts the shift leader.
Step 2: The shift leader reviews recent notes and incident records, confirms the change appears repeated and records the concern in the falls monitoring log.
Step 3: The registered manager updates the falls risk assessment, records revised support controls and requests professional advice through the health communication record.
Step 4: The team leader briefs staff on the revised mobility support, records the update in the handover log and checks staff understanding during shift allocation.
Step 5: The deputy manager audits daily records after the change, checks whether controls are followed and records findings in the risk assurance tracker.
What can go wrong is that staff record mobility changes without triggering risk review. Early warning signs include furniture walking, slower transfers, near misses or staff using different support approaches. Escalation involves manager reassessment and professional advice. Consistency is maintained through falls monitoring triggers.
Governance: Falls monitoring logs, risk assessments, handover records and audit findings are reviewed monthly by the registered manager. Action is triggered by repeated near misses, unclear controls, missing staff briefings or evidence that controls are not followed.
Evidence & Outcomes: The baseline issue was delayed review of emerging falls risk. Measurable improvement included faster reassessment and fewer near misses. Evidence sources include care records, audits, feedback and staff practice observations.
Where risks are recurring or difficult to interpret, providers should also connect frontline observations with learning from incidents. Near misses can be as important as actual falls because they often show that an existing control is starting to weaken.
Risk Review Should Follow Change, Not Just the Calendar
Scheduled risk-review dates remain useful, but they should never be the only trigger for reassessment. Strong services define specific events that require earlier review.
These may include:
- falls or near misses;
- hospital admission or discharge;
- new medication;
- deteriorating mobility;
- changes in cognition;
- new behaviour patterns;
- weight loss or reduced intake;
- new safeguarding concerns;
- changes in family or informal support;
- environmental changes;
- new equipment; or
- staff feedback that existing controls are no longer workable.
This helps providers demonstrate risk management and compliance as a live operating process rather than a document-review cycle.
Operational Example 2: Reviewing Risk After a Behaviour Pattern Changes
Step 1: The support worker records repeated evening distress, noting the trigger, environment and staff response in the behaviour monitoring record.
Step 2: The senior support worker compares recent entries, identifies a pattern linked to noise and records findings in the behaviour risk review note.
Step 3: The key worker discusses the pattern with the person or representative, records preferred calming approaches and updates the support plan.
Step 4: The registered manager agrees a revised evening support approach, records the decision in the risk assessment and communicates changes through handover.
Step 5: The quality lead reviews behaviour records after implementation, checks whether distress reduced and records outcomes in the governance report.
What can go wrong is that behaviour is managed incident by incident without reviewing triggers. Early warning signs include repeated distress, increased staff anxiety or inconsistent responses. Escalation may involve specialist advice and temporary staffing changes. Consistency is maintained through pattern review and shared guidance.
Governance: Behaviour records, risk reviews, support plan updates and outcome data are audited monthly by the quality lead. Action is triggered by increasing distress, unclear triggers, restrictive responses or no improvement after plan changes.
Evidence & Outcomes: The baseline issue was reactive behaviour risk management. Measurable improvement included reduced evening distress and clearer staff response. Evidence includes care records, audits, feedback and staff practice checks.
This is also where risk management intersects with positive risk-taking and risk enablement. The aim is not to remove all uncertainty, but to understand what support makes participation, choice and everyday life safer without defaulting to unnecessary restriction.
Risk Controls Should Be Proportionate and Least Restrictive
Providers can create regulatory risk by over-controlling as well as under-controlling. Restricting movement, community access, spending, relationships or everyday decisions may appear safer in the short term, but excessive controls can undermine autonomy, quality of life and human rights.
Good risk management therefore asks:
- What is the actual risk?
- How likely and serious is the potential harm?
- What does the person want to do?
- What support could reduce risk without removing the opportunity?
- What would trigger increased support?
- What would justify reducing controls?
- When will the decision be reviewed?
The Positive Risk-Taking Planner can help providers structure this balance between foreseeable harm, proportional safeguards, individual choice and review.
Capacity and Risk Need to Be Kept Distinct
Risk and mental capacity are related but should not be treated as interchangeable. A decision may involve significant risk while the person still has capacity to make it. Conversely, lack of capacity for one particular decision does not justify broad restrictions across unrelated areas of life.
Strong services therefore link specific risk decisions with mental capacity, consent and best-interests decision-making where appropriate, while maintaining clear records of what decision was being considered and why.
Operational Example 3: Controlling Risk During Community Access
Step 1: The key worker reviews the person’s community access goals, identifies road-safety and anxiety risks, and records baseline controls in the risk assessment.
Step 2: The support worker completes planned community support, records routes used, prompts given and the person’s confidence in the daily care record.
Step 3: The team leader reviews community-access notes weekly, identifies progress or new concerns and records findings in the independence review log.
Step 4: The registered manager adjusts the support level where appropriate, records the rationale in the care plan and confirms staff guidance is updated.
Step 5: The deputy manager gathers feedback from the person, records whether confidence improved and adds outcome evidence to the quality audit file.
What can go wrong is that community risk controls either become too restrictive or too loose. Early warning signs include missed prompts, increased anxiety, near misses or staff avoiding activities altogether. Escalation involves reassessment and temporary support changes. Consistency is maintained through weekly independence review.
Governance: Community risk assessments, daily records, independence logs and feedback are reviewed monthly by the deputy manager. Action is triggered by increased anxiety, unsafe practice, reduced access, unclear staff guidance or lack of progress evidence.
Evidence & Outcomes: The baseline issue was unclear evidence that community risk was enabling independence safely. Measurable improvement included increased confidence and clearer support controls. Evidence sources include care records, audits, feedback and staff practice observations.
Where providers are supporting graduated independence, the evidence should show not only whether incidents occurred, but how much support was needed, whether prompts reduced, whether confidence increased and whether restrictions could safely be stepped down. This creates a stronger link between risk management and outcomes-focused and goal-led support.
Risk Controls Must Be Understood by Frontline Staff
A risk assessment is ineffective if staff cannot explain the practical control it contains. During inspection, CQC may compare the written risk plan with staff explanations and observed support.
Providers should therefore be able to evidence that staff know:
- the current risk;
- the early warning signs;
- the expected support approach;
- what staff should not do;
- what triggers escalation;
- who to contact;
- how the control should be recorded; and
- when the plan is due for review.
This links risk management with CQC workforce, training and practice competence. Training completion alone is not enough; staff understanding should be visible in actual practice.
Operational Example 4: Medication Risk Changes After Hospital Discharge
Context: A person returns from hospital with a changed medication regime, including a new PRN medicine and altered administration times.
Support approach: The provider treats the medication change as a live risk event rather than waiting for the next scheduled care-plan review.
Step 1: The senior on duty reconciles discharge information against the existing MAR and identifies changes requiring clarification.
Step 2: The registered manager ensures the medication risk assessment and support plan are updated before the revised regime is delivered routinely.
Step 3: Competent staff are briefed on the new timings, PRN rationale and escalation route, with any uncertainty resolved through pharmacy, GP or clinical contact.
Step 4: The first administrations are checked through enhanced oversight and any omission, refusal or side-effect concern is recorded and escalated.
Step 5: The manager reviews the first week of medication records and related care notes to confirm that the new control is embedded safely.
What can go wrong: Staff may continue following the old regime, rely on incomplete discharge paperwork or misunderstand when PRN medication should be used.
Early warning signs: Conflicting MAR entries, repeated staff queries, unexplained omissions, increased sedation, pain or distress.
Escalation and response: Uncertainty is escalated before administration rather than resolved informally by staff. Any adverse effect or clinically significant concern follows the agreed health escalation route.
Consistency and governance: Medication changes are linked with care-plan review, staff briefing, competency assurance and short-term audit.
Evidence & Outcomes: Effective controls are demonstrated through accurate administration, fewer discrepancies, timely escalation and clear audit evidence showing that the changed risk was understood and managed.
Risk Management Should Use Incidents and Near Misses as Intelligence
Incidents should not be treated as isolated events if they show a control may be failing. Near misses are particularly important because they reveal weaknesses before significant harm occurs.
Providers should review:
- repeat incident themes;
- near misses;
- time and location patterns;
- staff involved;
- changes in dependency;
- environmental factors;
- communication failures;
- control failures; and
- whether previous actions were effective.
This connects directly with root cause analysis and thematic learning and learning, incidents and continuous improvement.
Do Not Confuse Activity With Assurance
Providers may be able to show that risk assessments were updated, staff were briefed and audits were completed. Those activities matter, but assurance requires evidence that the risk actually became better controlled.
For example:
- Did falls reduce?
- Did distress reduce?
- Did community access increase safely?
- Did medication discrepancies reduce?
- Did staff confidence improve?
- Were restrictive controls reduced?
- Did complaints decrease?
- Did people report feeling safer and more independent?
The Quality Dashboard Builder can help providers bring together risk indicators, incidents, audits, feedback and outcome measures so leaders can see whether risk controls are producing sustained improvement rather than simply generating completed actions.
Risk Dashboards Should Show Deterioration Before Harm Escalates
A useful governance dashboard should not focus only on serious incidents. It should also make emerging deterioration visible.
Relevant indicators may include:
- falls and near misses;
- medication errors and omissions;
- safeguarding concerns;
- behaviour incidents;
- restrictive interventions;
- weight loss or nutritional decline;
- pressure damage;
- hospital transfers;
- complaints;
- missed care;
- staff-reported concerns;
- overdue risk reviews;
- repeat incidents despite action; and
- controls that remain temporary beyond their intended review date.
This strengthens quality data, KPIs and performance metrics and makes risk visible through governance before a serious event forces attention.
Operational Example 5: Safeguarding Risk Emerges Through Financial Changes
Context: A support worker notices that a person who usually manages small purchases confidently has begun running out of money earlier in the week and appears reluctant to discuss recent spending.
Support approach: The provider treats the change as a potential vulnerability signal rather than assuming poor budgeting.
Step 1: The worker records the factual observation and informs the senior without making allegations.
Step 2: The senior reviews recent financial-support records, notes any unexplained changes and checks whether the person wants private support to discuss the issue.
Step 3: Where concern remains, the registered manager reviews capacity, consent, financial-risk controls and whether a safeguarding threshold may be met.
Step 4: Any protective action is designed proportionately so the person retains as much control over their money as possible while the concern is investigated.
Step 5: The case is reviewed through safeguarding and governance processes to determine whether there is an isolated issue, exploitation risk or a wider pattern.
What can go wrong: Staff may either ignore subtle warning signs or respond by taking over the person’s finances unnecessarily.
Early warning signs: unexplained withdrawals, sudden lack of money, increased contact from particular individuals, anxiety about spending or changes in usual financial behaviour.
Escalation and response: The concern is escalated according to risk and safeguarding thresholds, with consent and capacity considered explicitly.
Consistency and governance: Financial-risk decisions are recorded, reviewed and linked with mental capacity, consent and safeguarding decision-making.
Evidence & Outcomes: Strong evidence demonstrates whether the person remained protected from exploitation while retaining appropriate choice and control.
Risk Escalation Thresholds Must Be Clear
Frontline staff should not have to guess which changes require immediate escalation and which can wait for routine review.
Services should define examples of escalation triggers such as:
- serious or unexplained injury;
- repeated near misses;
- sudden deterioration;
- new safeguarding indicators;
- risk controls no longer being workable;
- staff disagreement about safe practice;
- new restrictive measures;
- medication-related concerns;
- equipment failure;
- significant changes in behaviour or cognition;
- professional advice conflicting with current support plans; or
- risk increasing beyond the provider’s existing capability.
This links with decision-making and escalation and supports greater consistency across shifts and services.
Risk Decisions Need Named Ownership
Risk can drift when everyone is aware of the concern but nobody owns the next action. Strong systems assign responsibility clearly.
Depending on the issue, ownership may sit with:
- frontline staff for immediate observation and reporting;
- shift leaders for initial review;
- registered managers for assessment and operational control;
- clinical professionals for specialist advice;
- safeguarding leads for protection decisions;
- quality leads for thematic oversight; or
- senior leadership for provider-level risk.
The provider should be able to show who was responsible, what they were expected to do and by when.
Risk Registers Should Reflect Operational Reality
Significant service-level risks should move beyond individual care records where they indicate a wider organisational issue.
Examples include:
- repeated falls across one service;
- persistent medication errors;
- unsafe staffing;
- repeated equipment failure;
- multiple safeguarding concerns with the same theme;
- poor environmental conditions;
- systemic documentation problems; or
- weak escalation practice.
These risks may need to appear within service or corporate risk registers and connect with internal controls and assurance frameworks.
Operational Example 6: Environmental Risk Is Escalated Beyond One Person
Context: Several residents experience minor trips in the same corridor over a three-week period. Individual risk assessments are updated, but the pattern continues.
Support approach: The registered manager reframes the issue from individual falls risk to a service-level environmental concern.
Step 1: Incident locations and times are mapped.
Step 2: The corridor environment is reviewed for lighting, flooring, clutter and equipment placement.
Step 3: The issue is added to the service risk register with named actions and target dates.
Step 4: Environmental controls are implemented and staff are briefed.
Step 5: Incident rates are monitored against the previous baseline before the risk is considered for closure.
How effectiveness is evidenced: Trip incidents reduce and repeat environmental concerns no longer appear in audits or resident feedback.
This is a good example of why quality assurance, governance and board oversight should connect individual incidents with wider organisational patterns.
Commissioner Expectation
Commissioners expect risk management evidence to show proportionate controls, clear ownership and timely review. They want assurance that providers protect people without unnecessarily limiting choice, independence or wellbeing.
They are also likely to expect evidence that changing needs, incidents, feedback and professional advice lead to practical reassessment rather than being filed without changing delivery.
Strong commissioner assurance may include:
- current risk assessments;
- clear escalation thresholds;
- evidence of review after incidents or changing need;
- links between risks and support-plan changes;
- proportionate use of enhanced staffing;
- evidence that restrictive controls are reviewed;
- outcome measures showing whether risk reduced;
- professional involvement where needed; and
- governance evidence showing that recurring risks are escalated appropriately.
The Commissioner Evidence Builder can help providers organise risk, action and outcome evidence into a clearer contract-monitoring and assurance narrative, particularly where commissioners need to understand why support levels, controls or costs have changed.
Commissioners Need to Understand Both Safety and Enablement
Commissioner confidence is not necessarily strengthened by a provider removing every conceivable risk. In many services, good support requires people to develop skills, access their communities, make choices and experience ordinary levels of uncertainty.
Providers should therefore be able to explain:
- what the person wants to achieve;
- what foreseeable risk exists;
- what proportionate safeguards are in place;
- why more restrictive options were not chosen;
- what indicators would trigger increased support;
- what evidence would allow support to reduce; and
- how the person has been involved in the decision.
This helps demonstrate that positive risk-taking is governed rather than improvised.
Regulator / Inspector Expectation
Inspectors expect risk assessments to match daily care and staff explanations. They may compare formal risk documents with incidents, care notes, observations, staff interviews and people's experiences.
Strong evidence shows that risk is actively managed and reviewed. Weak evidence appears when assessments exist but are outdated, generic, contradictory or not followed in practice.
Inspectors may explore:
- how staff identify changing risk;
- who is authorised to update controls;
- how quickly significant changes are reviewed;
- whether staff understand escalation routes;
- how incidents and near misses affect risk planning;
- whether restrictions are proportionate;
- whether capacity and consent are considered correctly;
- how managers know controls are being followed;
- how risk information is communicated between shifts; and
- how recurring themes reach provider governance.
This sits directly within CQC inspection and on-site assessment and wider CQC governance, leadership and provider oversight.
Inspection Readiness Means Being Able to Follow One Risk Through the System
A useful test is whether an inspector could select one person's risk and follow the evidence from first concern through to governance.
For example:
- A care worker notices increasing instability when walking.
- The daily record captures the change.
- The shift lead identifies a repeated pattern.
- The risk assessment is reviewed.
- Professional advice is requested.
- Staff are briefed on the revised support approach.
- Practice is observed or audited.
- Near misses reduce.
- The improvement is discussed through governance.
Where that chain is visible, the provider has strong CQC evidence and assurance.
Where it is fragmented, the CQC Evidence Gap Analyzer can help identify which part of the evidence chain is missing.
Risk Audits Should Test Practice, Not Just Document Completion
A risk audit should not simply ask whether every person has a signed assessment. It should test whether those assessments remain meaningful.
Useful audit questions include:
- Is the assessment current?
- Does it reflect recent incidents and changes?
- Does the support plan match it?
- Can staff explain the controls?
- Are those controls actually being followed?
- Are escalation thresholds clear?
- Has the person or representative been involved appropriately?
- Are restrictions reviewed?
- Is there evidence that controls work?
- Are recurring risks escalated into governance?
This strengthens audit and compliance by shifting assurance from document presence to operational effectiveness.
Operational Example 7: Audit Finds Risk Assessments Are Current but Practice Is Inconsistent
Context: A provider's audit shows 100% of risk assessments are within review date. However, spot checks identify that staff are using different approaches when supporting one person with transfers.
Support approach: The quality lead treats this as an assurance failure despite full documentation compliance.
Step 1: The person's current assessment and moving-and-handling guidance are reviewed.
Step 2: Staff are observed during support and asked to explain the expected approach.
Step 3: The review identifies that handover and competency reinforcement have been inconsistent.
Step 4: Staff receive targeted re-briefing and observed competency checks.
Step 5: Repeat spot checks confirm whether practice is now consistent before the action is closed.
Evidence & Outcomes: The provider demonstrates that risk assurance does not stop at a completed form. The measurable outcome is consistent practice across staff and safer transfers.
Risk Improvement Actions Need Closure Criteria
Actions such as “review risk assessment”, “retrain staff” or “monitor incidents” are too vague to demonstrate improvement on their own.
Stronger actions specify:
- what must change;
- who owns the action;
- when it must happen;
- what evidence will prove completion;
- what outcome will demonstrate effectiveness; and
- what happens if the control does not work.
This links with quality improvement plans and action tracking.
Governance Should Distinguish Individual Risk From Systemic Risk
Not every individual risk belongs on a corporate dashboard. However, leaders should recognise when several individual concerns reveal a wider service problem.
Systemic signals may include:
- repeated falls across several people;
- similar medication errors in different services;
- multiple incidents during the same staffing period;
- repeated restrictive responses;
- common documentation weaknesses;
- recurring safeguarding themes;
- staff uncertainty about the same escalation process; or
- repeated failures to implement professional advice.
These themes should move into organisational quality assurance and governance rather than remaining scattered across individual case files.
Quality Dashboards Should Support Risk Prioritisation
Leaders need a way to see which risks require attention now, which are improving and which remain unresolved.
A useful dashboard may show:
- high-severity risks;
- overdue reviews;
- repeat incidents;
- near-miss trends;
- safeguarding concerns;
- restrictive-practice use;
- actions overdue;
- professional recommendations not yet implemented;
- risk-related complaints;
- services with increasing incident frequency; and
- risks where controls have not reduced harm.
The Quality Dashboard Builder can support providers to structure these indicators into a clearer governance view.
Board Oversight Should Focus on Material Risk and Control Effectiveness
Boards and senior leadership teams do not need every individual assessment, but they should understand material risks that could affect safety, regulatory compliance or service continuity.
Useful board-level questions include:
- Which risk themes are increasing?
- Which controls are repeatedly failing?
- Where are incidents recurring despite previous action?
- Which services have the highest unresolved risks?
- Are restrictions increasing?
- Are professional recommendations implemented on time?
- Are there recurring staffing or competency contributors?
- What risks have moved onto corporate registers?
- What improvement has been sustained?
The Governance Maturity Assessment can help providers test whether risk information is being escalated effectively from frontline practice through management, executive and board oversight.
Common Weaknesses in CQC Risk Management Evidence
- Risk assessments reviewed by date rather than when needs change.
- Staff observations recorded without triggering reassessment.
- Generic controls that do not explain what staff should actually do.
- Different staff using different approaches.
- Incidents reviewed individually without thematic analysis.
- Near misses not treated as risk intelligence.
- Risk controls becoming unnecessarily restrictive.
- Capacity being treated as a blanket status rather than decision-specific.
- Professional advice not translated into support-plan changes.
- Staff briefings not evidenced.
- Actions closed because paperwork is complete rather than because outcomes improved.
- Individual risks not escalated when they reveal systemic problems.
- Governance dashboards counting incidents without testing control effectiveness.
- People's feedback not used to challenge risk decisions.
Thinking Like a CQC Inspector
A useful question for providers is:
“If an inspector identifies one current risk today, can we show how we know it is understood, controlled, reviewed and producing the intended outcome?”
A credible answer should connect:
- the assessment;
- the person's goals and wishes;
- daily records;
- staff knowledge;
- incidents and near misses;
- professional input;
- audit findings;
- management decisions; and
- outcomes.
Thinking Like a Registered Manager
The management question should not simply be, “Are our risk assessments up to date?”
It should be:
“How do I know our current controls are still the right controls, staff are actually using them and people are safer without being unnecessarily restricted?”
That shift in thinking turns risk management from compliance paperwork into a genuine quality-control system.
Key Takeaway for Providers
Evidencing risk management under the CQC quality statements requires providers to demonstrate a continuous process: risks are identified early, assessed proportionately, translated into practical support, understood by staff, escalated where necessary and reviewed against real outcomes.
The strongest services do not treat the absence of incidents as proof that risk management is effective. They also examine near misses, people's feedback, staff confidence, changing needs and whether controls remain proportionate.
Risk management becomes inspection-ready when the provider can show a reliable line from change → assessment → control → practice → outcome → governance.
Conclusion
Evidencing risk management under the CQC assessment framework requires much more than maintaining current risk-assessment forms. Providers need to show how risks are recognised and controlled in real care situations, how frontline observations trigger timely review and how leaders determine whether controls remain effective.
Governance provides the structure for this assurance. Risk assessments, incident analysis, monitoring logs, handover records, audits, feedback and quality dashboards allow leaders to understand whether risk is changing and whether intervention is working.
Outcomes should demonstrate more than the absence of serious harm. Strong evidence can show fewer near misses, lower distress, safer independence, reduced restriction, improved confidence and better consistency in staff practice.
Consistency is maintained through clear triggers, named ownership, staff briefings, escalation routes and routine governance challenge. Where evidence gaps remain, the CQC Evidence Gap Analyzer can help identify weaknesses in the assurance chain, while the Positive Risk-Taking Planner can support proportionate decisions where safety, independence and choice need to be balanced carefully.
When these elements are embedded properly, risk management evidence does more than support inspection readiness. It demonstrates that the provider understands changing need, learns from warning signs and can protect people while continuing to support meaningful choice, independence and quality of life.
Latest from the knowledge hub
- Reykjavík and Rural Iceland: Can a Small Country Deliver Equitable Long-Term Care Across a Dispersed Population?
- Iceland’s Ageing Population: What Demographic Change Means for Long-Term Care and Community Support
- How Is Long-Term Care Funded in Iceland? Public Financing, Municipal Responsibilities and Household Contributions
- Who Is Responsible for Long-Term Care in Iceland? National Government, Municipalities and Service Providers