How to Escalate a Safeguarding Concern to Police, CQC and Commissioners Without Losing Control of the Case

Safeguarding escalation does not always stop at a local authority referral. In some cases, providers must also consider police involvement, CQC notification duties and commissioner escalation where serious harm, suspected criminal conduct, systemic failure or contractual risk are present.

These cases are operationally demanding because several external routes may open at the same time, each with a different purpose, threshold, timescale and documentation requirement. Providers therefore need a clear framework that defines when each route is triggered, who authorises contact, how records are aligned and how control of the overall case is maintained.

This article explains how providers can manage complex external escalation through disciplined safeguarding incident response, protection and escalation systems, supported by a strong operational understanding of different types of abuse. The aim is to ensure that notifications remain timely, proportionate, defensible and inspection-ready without allowing external correspondence to displace immediate protection of the adult.

For a central source on adult safeguarding prevention, escalation and partnership working, the Adult Safeguarding Knowledge Hub brings together guidance on protecting adults at risk, incident response, multi-agency working and prevention. External escalation should sit within this wider framework rather than being treated as a standalone notification exercise.

Why complex safeguarding cases require several escalation routes

Different external bodies perform different functions. A safeguarding referral, police report, CQC notification and commissioner escalation may all relate to the same incident, but they are not interchangeable.

  • The local authority safeguarding route considers duties relating to an adult with care and support needs who may be experiencing, or at risk of, abuse or neglect.
  • The police route considers suspected criminal conduct, immediate danger, preservation of evidence and criminal investigation.
  • The CQC notification route enables the regulator to receive information about specified events and assess wider regulatory risk.
  • The commissioner route addresses contractual assurance, service continuity, provider performance and risks affecting commissioned people or services.

A serious incident may therefore require several parallel actions. The provider should not assume that notifying one body automatically fulfils its responsibilities to another.

This connects with CQC notifications, statutory reporting and duty of candour, as well as multi-agency safeguarding working. Strong practice depends on understanding each route clearly while maintaining one coherent internal record.

The risks of delayed or poorly coordinated escalation

External escalation can fail even when providers recognise that a case is serious. Common risks include:

  • criminal conduct being managed internally for too long;
  • CQC notification being delayed while managers wait for a safeguarding outcome;
  • commissioners learning of a serious incident from another agency;
  • different accounts being sent to different external bodies;
  • the chronology being updated after rather than before notification;
  • staff restrictions or protection measures lapsing while correspondence continues;
  • unclear ownership once several agencies become involved; and
  • provider leaders assuming that an external investigation has transferred responsibility away from the service.

These weaknesses can undermine trust and expose the adult, other people using the service and staff to continued risk. They can also create avoidable regulatory and contractual concern because inconsistent records may suggest poor governance even where the initial response was broadly appropriate.

Operational Example 1: Deciding Whether the Concern Also Requires Police, CQC or Commissioner Escalation

Step 1: The Designated Safeguarding Lead completes an external escalation screening review within four working hours of threshold confirmation. The review records whether alleged criminal conduct may be present, whether a regulatory notification duty appears to be triggered and whether material contractual or service risk exists.

The screening tool is stored in the restricted safeguarding workspace and submitted for same-day senior review. It should include:

  • the nature of the alleged harm;
  • whether immediate danger remains;
  • whether evidence may need preservation;
  • whether one or several adults may be affected;
  • whether the incident may indicate systemic failure;
  • whether staff restrictions or suspension are required;
  • whether commissioned service continuity is affected; and
  • which external routes may require action.

Step 2: The Registered Manager undertakes an incident-seriousness review within the same working day. The review records injury severity, the number of adults potentially affected, previous related incidents, alleged perpetrator access and whether the concern may be isolated or systemic.

The serious-incident risk matrix is uploaded to the safeguarding decision folder. Immediate escalation should occur where high-severity indicators include:

  • death or serious injury;
  • suspected assault, theft, fraud or sexual offence;
  • ongoing access by an alleged perpetrator;
  • several adults potentially affected;
  • evidence of organisational neglect;
  • repeated incidents previously treated separately; or
  • risk of evidence being lost, altered or destroyed.

Step 3: The Operations Director completes a regulatory and contractual impact check within one working day. The review records service-continuity risk, potential breach of registration expectations, impact on other people, staffing implications and commissioner sensitivity.

The external stakeholder impact log should identify:

  • whether the service can continue safely;
  • whether staffing or management arrangements require immediate change;
  • whether the incident may affect more than one location;
  • whether contract outcomes or performance standards are compromised;
  • whether the commissioner needs urgent reassurance; and
  • whether executive-level coordination is required.

Step 4: The Quality Director validates route selection within one working day. The multi-route decision record captures the rationale for police contact, CQC notification and commissioner escalation separately.

The record should show:

  • the trigger for each route;
  • the responsible officer;
  • the expected submission time;
  • the information that may be shared;
  • the person approving the wording;
  • the relationship between each route and the safeguarding referral; and
  • any route considered but not opened, with reasons.

External contact should not be delayed unnecessarily while managers seek perfect certainty. Where immediate police or emergency action is needed, staff should act first and complete governance validation as soon as safely possible.

Step 5: The Quality and Safeguarding Lead audits route-selection decisions weekly. The governance escalation dashboard records:

  • the percentage of serious cases screened on the same day;
  • external routes opened late;
  • decisions later revised;
  • cases where police involvement was considered but not documented;
  • late CQC or commissioner notifications; and
  • recurring areas of manager uncertainty.

Any delayed or revised route decision should lead to corrective action, reflective review and clarification of local procedures.

How effectiveness is evidenced: Improvement is demonstrated through faster same-day screening, fewer retrospective route changes, earlier executive awareness and clearer written rationale for each external contact.

The baseline issue here is route uncertainty. Providers may know that the case is serious but still hesitate over whether police, CQC or commissioners must also be notified. Others may notify too broadly without a clear legal, regulatory or contractual rationale.

Early warning signs include repeated management consultation without closure, serious incidents progressing without external screening and conflicting opinions that are not resolved through a documented decision process.

This links directly to governance decision-making and escalation and CQC risk, safeguarding and restrictive-practice expectations.

Police contact and preservation of evidence

Where suspected criminal conduct, immediate danger or significant evidential risk is present, providers should not allow internal investigation activity to compromise possible police action.

Staff should avoid:

  • conducting detailed interviews beyond immediate safety and factual clarification;
  • asking repeated or leading questions;
  • moving or disposing of potential evidence unnecessarily;
  • allowing the alleged perpetrator continued unsupervised access;
  • sharing sensitive information too widely; and
  • delaying police contact while waiting for a complete internal account.

The provider still needs sufficient information to protect the adult and decide on immediate operational action. However, fact-finding should remain proportionate and should not become an informal criminal investigation.

This supports safeguarding information sharing, confidentiality and disclosure. Information should be accurate, necessary, relevant and shared with the right body for the right purpose.

CQC notification and regulatory evidence

A safeguarding concern may also trigger a CQC notification requirement. Providers should ensure that managers know the difference between notifying the local authority and fulfilling a regulatory notification duty.

Before submission, the provider should confirm:

  • the correct notification category;
  • the date and time of the incident or discovery;
  • the immediate protective action taken;
  • whether police, safeguarding or commissioners are involved;
  • whether staff restrictions or disciplinary processes are active;
  • whether other people may be affected;
  • what service-continuity measures are in place; and
  • who will update CQC if material facts change.

The CQC Evidence Gap Analyzer can help providers identify weaknesses in notification records, chronology, management rationale and evidence of protective action. It is particularly useful where operational decisions were made correctly but the inspection evidence is fragmented across safeguarding, HR, incident and compliance systems.

Commissioner escalation and contractual assurance

Commissioner escalation should be considered where the incident affects commissioned people, service continuity, contract performance, provider stability or confidence in the service.

Commissioners may need assurance about:

  • who has been affected;
  • what immediate protection is active;
  • whether the service remains safe to operate;
  • whether additional people require review;
  • how staffing and leadership are being stabilised;
  • whether contractual reporting requirements have been met;
  • what multi-agency routes are open; and
  • when further updates will be provided.

The Commissioner Evidence Builder can help providers organise a clear assurance narrative for commissioners. It supports consistent reporting of immediate action, service risk, ownership, timescales and outcomes without duplicating the entire safeguarding record.

Operational Example 2: Making External Notifications Without Duplicating or Distorting the Case Record

Step 1: The Designated Safeguarding Lead submits the safeguarding referral and any police contact within the required timeframe once the threshold is met. The external-notification submission record captures:

  • the date and time of contact;
  • the receiving officer, team or reference number;
  • the reason for escalation;
  • the immediate risk and protective action;
  • what information was shared;
  • what follow-up was requested; and
  • whether receipt was confirmed.

Step 2: The Registered Manager prepares the CQC notification where required. The regulatory-notification checklist records the incident type, current protective measures, other agency involvement, service impact and any information that remains unconfirmed.

The manager checks the notification against the live safeguarding chronology before submission. Facts, allegations and professional judgements should be clearly distinguished.

Step 3: The Contracts or Commissioning Lead notifies commissioners where contractual thresholds are met. The commissioner escalation record captures:

  • the commissioner contact;
  • the date and time of notification;
  • the concise incident summary;
  • the immediate protection plan;
  • service-continuity arrangements;
  • known regulatory or police involvement;
  • the date of the next update; and
  • any specific assurance requested.

The wording should align with the safeguarding and CQC records while remaining proportionate to the commissioner’s role.

Step 4: The Safeguarding Administrator updates the core chronology immediately after each notification. The chronology records:

  • the route opened;
  • the exact time of submission;
  • the person making contact;
  • the recipient or reference number;
  • the information sent;
  • the response received; and
  • the next action or deadline.

The chronology remains the master sequence for the case. Separate records may support each route, but they should not create competing versions of events.

Step 5: The Quality and Safeguarding Lead audits notification quality within one working day of submission. The audit checks:

  • timeliness against internal and external requirements;
  • consistency of dates and material facts;
  • alignment of risk descriptions;
  • whether immediate protection is described consistently;
  • whether allegations are clearly identified as allegations;
  • whether corrections are required; and
  • whether all notifications are reflected in the chronology.

Any inconsistency should be corrected promptly and transparently rather than left to create later confusion.

How effectiveness is evidenced: Improvement is demonstrated through timely notification, fewer corrections, consistent descriptions across external routes and a complete master chronology.

The baseline issue at this stage is fragmented communication. Providers may make the correct notifications but use different wording, dates or descriptions across police, CQC and commissioner routes.

This links with CQC digital records, data and information governance and internal controls and assurance frameworks. One controlled chronology and clear approval process reduce the risk of contradictory external accounts.

Keeping the Adult’s Protection Central During External Escalation

External notification can create a large volume of correspondence, requests and meetings. Providers must ensure that the adult’s immediate safety, wishes and day-to-day support remain central while these processes develop.

Live protection may include:

  • removing or restricting alleged perpetrator access;
  • changing staffing or management arrangements;
  • providing additional welfare contact;
  • reviewing accommodation, transport or community access;
  • protecting financial, medication or communication arrangements;
  • arranging advocacy or trusted-person involvement;
  • updating risk assessments and support plans; and
  • confirming what the adult wants from the safeguarding process.

This reflects Making Safeguarding Personal. A technically correct notification process is not enough if the adult feels excluded, uninformed or less safe as the case progresses.

Operational Example 3: Keeping Control After Multiple External Escalations Have Opened

Step 1: The Operations Director opens a multi-agency control plan within four working hours of the final external notification. The plan records:

  • all open external routes;
  • the purpose of each route;
  • provider action owners;
  • external contact names and reference numbers;
  • live protection measures;
  • service-continuity controls;
  • review deadlines; and
  • issues requiring executive decision.

The plan is stored in the governance reporting system and reviewed at the end of the working day to confirm that every action has an owner and deadline.

Step 2: The Registered Manager updates the live protection and continuity tracker daily. The tracker records:

  • staff restrictions still in force;
  • welfare contact completed with the adult;
  • changes to staffing, accommodation or routines;
  • service-continuity adjustments;
  • new risks identified;
  • actions completed or overdue; and
  • whether any protection measure has lapsed.

Any lapse in protection should be escalated immediately. External agency involvement does not remove the provider’s responsibility to maintain safe operational controls.

Step 3: The Safeguarding Administrator updates the chronology within one working day of every external development. This includes police contact outcomes, commissioner requests, CQC follow-up and safeguarding meeting decisions.

The chronology should be reviewed before each internal case meeting or multi-agency discussion so all participants work from the same sequence of events.

Step 4: The Executive Lead reviews every live multi-route case at least every seventy-two hours while serious risk remains open. The executive safeguarding oversight dashboard records:

  • unresolved protection risks;
  • provider actions still open;
  • overdue external responses;
  • staffing or service-continuity concerns;
  • regulatory or contractual deadlines;
  • changes in the adult’s desired outcome; and
  • decisions requiring senior authority.

Where serious risk remains unresolved beyond agreed timescales, the executive lead should escalate the matter, challenge delay and consider whether stronger interim protection is required.

Step 5: The Quality and Safeguarding Lead completes a cross-route learning review within five working days of case stabilisation or closure. The review considers:

  • the timeliness of each route;
  • the consistency of information sent;
  • whether live protection remained effective;
  • whether provider actions were completed;
  • whether external responses were coordinated;
  • what the adult experienced;
  • what should change in future cases; and
  • whether organisation-wide improvement is required.

How effectiveness is evidenced: Improvement is demonstrated through stronger action closure, fewer chronology gaps, more reliable protection and clearer coordination across police, CQC, commissioner and safeguarding routes.

The baseline issue here is loss of control after multiple agencies become involved. Providers may open all the correct routes but allow action ownership, chronology quality or protection oversight to weaken because responsibility begins to feel shared externally.

Early warning signs include actions without owners, chronology gaps, repeated requests for the same information and serious risk remaining open several days after escalation.

Multi-Agency Working Without Losing Provider Accountability

Multi-agency working is essential in serious safeguarding cases, but shared involvement does not mean shared ambiguity. The provider should remain clear about which actions it owns and which actions sit with external partners.

A multi-agency control plan should distinguish:

  • provider protection and continuity actions;
  • local authority safeguarding actions;
  • police investigation activity;
  • CQC regulatory requests;
  • commissioner assurance requirements;
  • HR or disciplinary processes;
  • clinical or legal advice; and
  • actions dependent on the adult’s consent or preferred outcome.

This supports effective multi-agency safeguarding working. Strong partnership working depends on clarity, not the assumption that another body is managing the whole case.

Information Sharing Across Several External Routes

Different external bodies may require different levels of detail. Providers should share enough information to support the purpose of each route without circulating unnecessary or poorly controlled personal information.

Good practice includes:

  • sharing verified facts separately from allegations or opinion;
  • recording the lawful and operational reason for disclosure;
  • limiting information to what is relevant for the recipient;
  • using secure communication channels;
  • recording exactly what was sent and when;
  • avoiding uncontrolled forwarding of full case records;
  • protecting witness, whistleblower and adult confidentiality; and
  • correcting material inaccuracies promptly.

This aligns with safeguarding information sharing, confidentiality and disclosure. The master chronology should show each disclosure clearly enough for later audit.

Staff Restrictions, Allegations and Safe Employment Practice

Where the concern relates to a staff member, provider action may include suspension, redeployment, increased supervision, restricted duties or removal from direct contact while facts are established.

Decisions should be proportionate and should consider:

  • the seriousness of the allegation;
  • the risk of further harm;
  • access to adults or evidence;
  • the worker’s role and authority;
  • whether alternative safe duties are possible;
  • police or safeguarding advice;
  • employment-law and HR requirements; and
  • the need to avoid prejudicing external investigation.

This connects with safeguarding allegations against staff and safe employment practice. External notification should not replace immediate employment and operational risk management.

Using Governance Dashboards Without Reducing the Case to Data

Dashboards can help leaders track serious multi-route cases, overdue actions and recurring escalation failures. They should not replace case review or remove the adult’s circumstances from view.

The Quality Dashboard Builder can support indicators such as:

  • serious cases screened on the same day;
  • police, CQC or commissioner routes opened late;
  • notifications requiring correction;
  • live protection actions overdue;
  • chronology gaps;
  • cases open beyond expected timescales;
  • repeat themes across services;
  • staff restrictions not reviewed on time; and
  • post-case learning actions outstanding.

Data should be accompanied by narrative explaining current risk, the adult’s desired outcome and unresolved barriers. A low number of notifications does not necessarily demonstrate strong practice if serious concerns are being under-recognised.

Governance and Board Oversight

Senior leaders and boards need enough information to understand the seriousness, systemic implications and organisational learning arising from external escalation cases.

Board or committee scrutiny should consider:

  • whether all required routes were opened on time;
  • whether the service remained safe;
  • whether other adults or services may be affected;
  • whether the concern indicates cultural or systemic failure;
  • whether staff and leadership actions were proportionate;
  • whether commissioner and regulatory confidence has been affected;
  • whether learning has been implemented; and
  • whether unresolved risk requires further executive action.

The Governance Maturity Assessment can help providers evaluate whether serious safeguarding escalation reaches the right level of scrutiny, whether challenge is sufficiently robust and whether learning is translated into organisation-wide improvement.

This aligns with safeguarding audit, assurance and board oversight and quality assurance, governance and board oversight.

Commissioner Expectation

Commissioners expect providers to recognise when serious safeguarding concerns create wider regulatory, service or contractual risk and to escalate transparently without losing operational control.

They are likely to look for evidence that:

  • serious cases are screened promptly;
  • commissioner notification thresholds are understood;
  • information is accurate and aligned with other routes;
  • service continuity remains safe;
  • other commissioned people are reviewed where necessary;
  • provider actions remain active throughout external involvement;
  • updates are supplied at agreed intervals; and
  • learning is incorporated into contract assurance.

The Commissioner Evidence Builder can help providers present a clear line from concern to protection, notification, continuity action and outcome.

Regulator and Inspector Expectation

Inspectors expect providers to understand that serious safeguarding concerns may require parallel escalation to local authorities, police, CQC and commissioners. They will also expect a clear rationale for each route, strong chronology control, prompt notification and evidence that the provider maintained oversight of risk while external scrutiny was underway.

Inspection-ready evidence may include:

  • external escalation screening tools;
  • serious-incident risk matrices;
  • police, safeguarding, CQC and commissioner submission records;
  • the master safeguarding chronology;
  • staff restriction and protection decisions;
  • multi-agency control plans;
  • daily protection and continuity trackers;
  • executive oversight dashboards;
  • audit findings and corrected inconsistencies;
  • evidence of the adult’s involvement; and
  • post-case learning and completed improvement actions.

The CQC Evidence Gap Analyzer can help providers test whether the full evidence trail is inspection-ready rather than fragmented across safeguarding, HR, compliance, operations and commissioner systems.

Common Weaknesses in External Safeguarding Escalation

  • Referral treated as completion: the provider assumes the local authority referral fulfils all external duties.
  • Police contact delayed: suspected criminal conduct is explored internally for too long.
  • CQC notification uncertainty: managers wait for an investigation outcome before considering regulatory reporting.
  • Commissioners informed late: contractual confidence is damaged by delayed disclosure.
  • Contradictory records: different routes receive different dates, descriptions or risk levels.
  • No master chronology: external contacts create competing case records.
  • Protection displaced by correspondence: operational safeguards weaken while managers focus on agency responses.
  • Ownership becomes unclear: staff assume an external agency has taken control of provider actions.
  • Information shared too widely: confidentiality and evidential integrity are weakened.
  • Case closure without learning: recurring route-selection or notification problems are not addressed.

Conclusion

Escalating a safeguarding concern to police, CQC and commissioners is not simply a communication exercise. It is a governance test requiring providers to distinguish each route clearly, notify the correct body on time and maintain one controlled case record despite multiple external demands.

Strong providers screen serious cases promptly, separate the purpose of each notification, align all external accounts with a master chronology and preserve live protection throughout the process. They remain responsible for staffing, continuity, restrictions, welfare contact and internal action even after several agencies become involved.

Delivery links directly to governance because screening tools, notification records, chronology sheets, multi-agency control plans and executive dashboards create one auditable external-escalation pathway. Outcomes are evidenced through faster route selection, fewer inconsistent notifications, stronger action closure and better multi-agency coordination.

Consistency is demonstrated when every serious case uses the same route-screening criteria, chronology standards and oversight triggers. That is what makes complex safeguarding escalation credible, measurable and inspection-ready.