What does CQC expect when a clinic uses AI?
Short answer
CQC has no AI-specific regulation. It judges AI tools against the rules that already apply, chiefly Regulation 17 (good governance). For GP services, mythbuster 109 lists what inspectors look for: evidence-based procurement, clinical risk management under DCB0160, a clinical safety officer, data protection, human oversight of outputs, staff training and ongoing monitoring.
Regulation 17 is the anchor
Regulation 17 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 requires registered providers to keep an accurate, complete and contemporaneous record for each person, and to operate systems that assess, monitor and improve the quality and safety of the service. An AI scribe or receptionist is part of those systems. Inspectors will not ask whether you use AI. They will ask whether you can show it is governed: chosen on evidence, risk-assessed, overseen by people, and monitored.
What GP mythbuster 109 asks for
CQC's GP mythbuster 109, 'Use of artificial intelligence (AI) in GP services', is the clearest statement of what inspectors check. In summary:
- Procurement against standards: evidence that tools meet DCB0160, DTAC and MHRA registration where it applies. Tools from an NHS procurement list still need checking against their intended purpose.
- Clinical risk management: under DCB0160, confirm the developer complies with DCB0129 and carry out your own clinical risk assessment. See DCB0129 and DCB0160.
- Named roles: a clinical safety officer with current professional registration and digital clinical safety training, and a named digital lead for AI governance.
- A hazard log and documented risk assessments covering AI tools.
- Human oversight: evidence that AI is a support tool and not a replacement for human oversight, from audits, incident logs or quality improvement work.
- Learning from errors: a way to report and investigate errors, including to the developer and through the MHRA Yellow Card scheme.
- Data protection: records of how suppliers handle data, including DPIAs and DSPT.
- Telling patients: people should know you are using AI and be able to object. See patient consent and transparency.
- Training, access and bias: trained staff, a non-digital route to care, and assurance that bias against particular groups is mitigated.
Not a GP practice? Use it anyway
Mythbuster 109 is written for GP services, but it is the most specific published statement of how CQC thinks about AI governance. For other CQC-registered clinics it is a sensible checklist to work through before inspection. Many physiotherapy and therapy practices are not CQC-registered at all. For them, Regulation 17's record standard is still the benchmark that professional bodies and insurers expect.
What to have on file
- A short AI policy naming which tools touch patient records, who approved them and why.
- Your DPIA and the vendor's DPA. See DPIA for clinic AI.
- The vendor's clinical safety evidence (DCB0129) and your hazard log.
- Your consent and patient information wording, and the privacy notice.
- Evidence of review: documentation audits, incidents logged and acted on, staff training records.
What Motics does
- AI-generated outputs (clinical notes, codes, letter drafts) are drafts. A clinician reviews and approves them before use. Motics assists; it does not decide.
- Motics Scribe Agent is a Class I medical device under UK MDR. Our DCB 0129 clinical safety case is available on request to support your DCB0160 work.
- Motics has been assessed against the NHS Digital Technology Assessment Criteria. Assessment evidence and clinical safety documentation are on our Trust Centre.
- Every data access event is logged with who, what, when and from where, and audit logs are available to your compliance team.
- Audit Agent reviews clinical documentation against your standards across every note rather than a sample, which supports the 'assess and monitor' duty in Regulation 17.
Full detail on our security and compliance page and the Trust Centre. Ask any vendor, including us, to put these answers in writing.
Primary sources
- CQC: GP mythbuster 109, Use of artificial intelligence (AI) in GP services
- CQC: Regulation 17, Good governance
- CQC: Artificial intelligence in health and social care, CQC's role, expectations and plans
- NHS England: DCB0160 Clinical Risk Management, its application in the deployment and use of health IT systems
Practical orientation for UK clinics, not legal advice. For your own circumstances, take advice from your data protection officer, indemnity provider or a solicitor.