Governance Is Not Compliance: Why the Difference Matters More Than Your Policy Folder Suggests

Ask most independent providers what "good governance" looks like and you'll get a description of good compliance instead: policies up to date, DSPT submitted, statutory notifications sent on time, CQC evidence portfolio populated. All of that matters. None of it is governance.

Compliance answers one question: are we meeting the minimum standard set by someone outside the organisation? Governance answers a different one: are we making good decisions, for the right reasons, in a way we could defend to a regulator, a coroner, or a patient's family if we had to? A service can be fully compliant and still be badly governed. It's a more common combination than most boards would like to admit.

What compliance actually covers

Compliance is the floor. It's the set of external requirements — CQC fundamental standards, DSPT, statutory notifications, mandatory training completion rates — that exist whether or not your organisation has thought about them at all. You can outsource most of compliance. You can automate parts of it. A well-run compliance function tells you where you stand against a fixed external checklist, and that's genuinely valuable: it catches the gaps that would otherwise surface during an inspection instead of before one.

But compliance, by design, doesn't ask whether the checklist is the right one for your organisation's actual risks. It doesn't ask why an incident happened, only whether it was reported within the required timeframe. It doesn't ask whether your board understood the decision it signed off, only whether the sign-off exists on file.

What governance adds

Governance is the judgment layer sitting above compliance. It's the structure through which decisions get made, tested, and owned — who decided, on what evidence, weighed against what risk, with what oversight afterward. A governance framework asks compliance's questions and then a harder set on top: did we understand what we were agreeing to, did the right people have visibility before the decision was made rather than after, and can we show our reasoning, not just our paperwork, if we're asked to account for it later.


This is the distinction that shows up hardest in an incident. A provider with strong compliance and weak governance will have the notification on file, the policy referenced, the training record complete — and still struggle to explain why the decision that led to the incident was made, because no one owned it as a decision at the time. It just happened, inside a compliant system, without anyone particularly deciding it should.

Where this shows up in practice

Three places we see the gap most often with providers:

Risk registers that log risks without anyone owning the decision about what to do with them. A risk sitting at "amber" for eighteen months with no board discussion isn't a governance failure of documentation — the documentation is fine. It's a failure of someone actually deciding what amber means and what happens next.

Board minutes that record attendance and agenda items but not reasoning. If a board approved a change in staffing ratios, the minute that matters isn't "the board approved the proposal." It's what evidence was weighed, what alternative was considered and rejected, and why. That's the record that protects the organisation later — and it's the record most boards don't actually keep, because it takes longer to write and nobody's checklist requires it.

Assurance that flows one way. Compliance tells the board what's been done. Governance requires the board to test it — to ask the operational team a question they weren't expecting, rather than accepting the report as read. A board that only ever receives assurance, and never probes it, isn't governing. It's rubber-stamping with good intentions.

The practical fix

You don't fix this by adding more policies — that's compliance thinking applied to a governance problem, and it tends to make the folder thicker without making the decisions better. The fix is structural:

Separate the reporting question from the decision question on your board agenda. "Here's our compliance status" and "here's a decision we need to make, here's the evidence, here's what we're weighing" should be different agenda items with different expectations of the room.

Require reasoning in the minute, not just the outcome. One sentence on what was considered and why is usually enough. It's the habit that matters, not the length.

Build in genuine challenge. If every paper that reaches the board gets approved without a substantive question, that's worth noticing in itself — not because approval is wrong, but because it suggests the board isn't yet doing the second half of its job.

Compliance keeps you registered. Governance is what you'd actually want standing behind you if something went wrong and someone asked why the decision was made the way it was.

August regulatory round-up

A short one this month, but two dates worth having on your radar:

DSPT transition deadline — 14 August 2026. The Health Research Authority has confirmed that 2024/25 Data Security and Protection Toolkit assurances will only be accepted for CAG applications, amendments or annual reviews submitted before 14 August. After that date, only 2025/26 submissions will be accepted. If your DSPT renewal has slipped, this is the practical deadline that bites — not the toolkit's own nominal submission date.

CQC's sector-specific assessment framework — expected this summer. CQC has confirmed it's on track to publish the replacement for the single assessment framework this summer, with separate frameworks for adult social care, hospitals, primary care and mental health, ahead of implementation planned for the end of 2026. The single assessment framework remains in force for inspections in the meantime, so nothing changes operationally yet — but providers should expect the published framework text to set the shape of what changes later this year, and it's worth reading closely as soon as it lands rather than waiting for guidance to catch up.

We're tracking both, along with the Health Bill's progress through report stage, in this month's full regulatory briefing for Harbour and Deep Water subscribers.

Next
Next

Chapter 1: Why "Good" Is Harder Than "Compliant"