UK compliance hubInspection and patients

What does CQC expect when a clinic uses AI?

Short answer

CQC has no AI-specific regulation. It judges AI tools against the rules that already apply, chiefly Regulation 17 (good governance). For GP services, mythbuster 109 lists what inspectors look for: evidence-based procurement, clinical risk management under DCB0160, a clinical safety officer, data protection, human oversight of outputs, staff training and ongoing monitoring.

Regulation 17 is the anchor

Regulation 17 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 requires registered providers to keep an accurate, complete and contemporaneous record for each person, and to operate systems that assess, monitor and improve the quality and safety of the service. An AI scribe or receptionist is part of those systems. Inspectors will not ask whether you use AI. They will ask whether you can show it is governed: chosen on evidence, risk-assessed, overseen by people, and monitored.

What GP mythbuster 109 asks for

CQC's GP mythbuster 109, 'Use of artificial intelligence (AI) in GP services', is the clearest statement of what inspectors check. In summary:

  • Procurement against standards: evidence that tools meet DCB0160, DTAC and MHRA registration where it applies. Tools from an NHS procurement list still need checking against their intended purpose.
  • Clinical risk management: under DCB0160, confirm the developer complies with DCB0129 and carry out your own clinical risk assessment. See DCB0129 and DCB0160.
  • Named roles: a clinical safety officer with current professional registration and digital clinical safety training, and a named digital lead for AI governance.
  • A hazard log and documented risk assessments covering AI tools.
  • Human oversight: evidence that AI is a support tool and not a replacement for human oversight, from audits, incident logs or quality improvement work.
  • Learning from errors: a way to report and investigate errors, including to the developer and through the MHRA Yellow Card scheme.
  • Data protection: records of how suppliers handle data, including DPIAs and DSPT.
  • Telling patients: people should know you are using AI and be able to object. See patient consent and transparency.
  • Training, access and bias: trained staff, a non-digital route to care, and assurance that bias against particular groups is mitigated.

Not a GP practice? Use it anyway

Mythbuster 109 is written for GP services, but it is the most specific published statement of how CQC thinks about AI governance. For other CQC-registered clinics it is a sensible checklist to work through before inspection. Many physiotherapy and therapy practices are not CQC-registered at all. For them, Regulation 17's record standard is still the benchmark that professional bodies and insurers expect.

What to have on file

  • A short AI policy naming which tools touch patient records, who approved them and why.
  • Your DPIA and the vendor's DPA. See DPIA for clinic AI.
  • The vendor's clinical safety evidence (DCB0129) and your hazard log.
  • Your consent and patient information wording, and the privacy notice.
  • Evidence of review: documentation audits, incidents logged and acted on, staff training records.

What Motics does

  • AI-generated outputs (clinical notes, codes, letter drafts) are drafts. A clinician reviews and approves them before use. Motics assists; it does not decide.
  • Motics Scribe Agent is a Class I medical device under UK MDR. Our DCB 0129 clinical safety case is available on request to support your DCB0160 work.
  • Motics has been assessed against the NHS Digital Technology Assessment Criteria. Assessment evidence and clinical safety documentation are on our Trust Centre.
  • Every data access event is logged with who, what, when and from where, and audit logs are available to your compliance team.
  • Audit Agent reviews clinical documentation against your standards across every note rather than a sample, which supports the 'assess and monitor' duty in Regulation 17.

Full detail on our security and compliance page and the Trust Centre. Ask any vendor, including us, to put these answers in writing.

Primary sources

  1. CQC: GP mythbuster 109, Use of artificial intelligence (AI) in GP services
  2. CQC: Regulation 17, Good governance
  3. CQC: Artificial intelligence in health and social care, CQC's role, expectations and plans
  4. NHS England: DCB0160 Clinical Risk Management, its application in the deployment and use of health IT systems

Practical orientation for UK clinics, not legal advice. For your own circumstances, take advice from your data protection officer, indemnity provider or a solicitor.

FAQ

Common questions

Yes. CQC does not prohibit AI tools. It says it encourages innovative technology, including AI, where it benefits people, and it assesses AI through the regulations that already apply. What it expects to see is governance: evidence-based procurement, risk assessment, human oversight and monitoring.

No. Mythbusters are CQC guidance that explain how inspectors interpret the regulations. The legal requirements are the regulations themselves, chiefly Regulation 17. In practice, mythbuster 109 tells you what evidence an inspector will look for when you use AI in a GP service.

It is written for GP services, so it does not apply directly. If your clinic is CQC-registered, it is still the best available checklist for AI governance. If you are not CQC-registered, Regulation 17 does not apply to you, but the same record-keeping standards are what professional bodies and insurers expect.

CQC's mythbuster describes a senior clinician with current professional registration and practitioner-level training in digital clinical safety. In a small clinic this is usually the clinical lead or owner. Their job is to own the hazard log and the clinical risk assessment for each AI tool.

Mythbuster 109 points to audits, incident logs and quality improvement work. Practical examples: a sample or full documentation audit showing clinicians correct AI drafts, a log of AI-related incidents and what changed, and a written rule that no AI output is filed without clinician approval.

CQC's mythbuster says the type of consent depends on the technology. For AI scribes used for individual care, implied consent may be appropriate, but you must tell people you are using them and give them the option to object. Many clinics also ask in person at the start of each session.

No. The clinician who files a note is responsible for it whoever drafted the first version, and the registered provider is responsible for the systems around it. That is why clinician review of every AI output is a governance requirement, not a nice-to-have.

Running a compliance review?

We work with clinic owners, compliance leads and DPOs. Bring your DPIA or vendor questionnaire and we will come prepared.