If you built your assurance model around the Single Assessment Framework, you need to read this before your next board report.
The SAF is being dismantled. It is still the operative framework today — providers are still assessed under it, and CQC’s published guidance still stands. But CQC has formally moved on: two consultations have run, four draft sector-specific replacement frameworks have been published, pilots are running through to October 2026, and implementation is expected “at the end of the year.”
Quality statements are going. Scoring is going. And CQC had already stopped scoring at evidence-category level in December 2024, so this completes a direction of travel rather than starting one.
CQC’s own instruction to providers, published 26 May 2026, is worth quoting exactly:
“We are currently asking for feedback on our draft assessment frameworks, but until we implement the new regulatory approach later this year, please continue to refer to the current published guidance on how we assess quality and performance.”
So: carry on as you are, but do not build anything new on this foundation. (CQC, May 2026 update.)
How we got here
The short version, because the timeline explains the direction of travel.
The SAF was announced in July 2022 and assessments began in December 2023. By July 2024, the Dash interim report had landed and the Secretary of State was saying, in terms, “it’s clear to me CQC is not fit for purpose.” What followed was a sustained rebuild — of which replacing the assessment framework is one visible part.
The important thing for a governance lead is what this pattern implies. CQC did not conclude that it was asking for too much evidence. It concluded that its own machinery for gathering and judging that evidence wasn’t working. The regulator’s capacity problem is not your evidence problem going away.
Meanwhile, the assessment backlog is driving who gets visited
The other half of the May 2026 update is arguably more immediately useful than the framework news, because it tells you something about your own likelihood of being assessed.
CQC says it remains “on track to meet our target to publish reports for at least 9,000 assessments across all sectors by September 2026”, and it has published the criteria it is prioritising by. Aged ratings feature heavily in every sector:
- Adult social care — services never assessed since registration that data flags as very high risk; services registered over a year and not yet assessed; and services with a rating over 6 years old
- Mental health — inadequate ratings not assessed for over 12 months; outstanding ratings over 8 years old; requires improvement over 3 years; good over 5 years
- Primary care and community — services registered a year or more without assessment, and ratings older than 7 years
- Hospitals and specialist care — never-assessed services prioritised by time since registration, plus an “increased focus on services in the independent sector, reflecting the level of unknown or emerging risk, and the increasing volume of NHS-commissioned activity they are delivering”
Two specific programmes are worth knowing about. CQC began a Returning to Good and Outstanding programme in March 2026, running focused assessments of lower-risk NHS GP practices rated good or outstanding whose last report was published between 2017 and 2022 — reviewing, in CQC’s words, “non-clinical quality statements safely and robustly.”
And it is rolling out a lighter-touch approach for adult social care services that are rated good across all five key questions, have a registered manager, have ratings over six years old, show no significant risk in the data, and have no ongoing enforcement. That approach leans on “people’s experiences and outcomes, supported by observation and targeted, risk-based review of records” — with the caveat that “if concerns arise during planning, we will revert to the usual approach.”
The practical read for a provider: if your rating is old and your data profile is clean, you have moved up the queue, not down. A six-year-old “good” is now a reason to visit you, not a reason to leave you alone. And the lighter-touch route is explicitly conditional — it converts to a full assessment the moment anything looks off during planning.
If your last inspection was in the 2017–2022 window, the sensible assumption is that you are in scope this year.
What is not changing
This is the part that matters, and it is the reason we are not telling you to down tools until the new frameworks land.
Every significant reform of the last five years has pushed in the same direction: from periodic demonstration to continuous evidence. That direction has survived a change of framework, a change of leadership, and two consultations.
PSIRF made the point most clearly. The Patient Safety Incident Response Framework replaced the old Serious Incident Framework and deliberately moved away from root cause analysis toward a range of proportionate learning responses — from a same-day huddle through to a full patient safety incident investigation. The unit of account stopped being the investigation report and became the learning. (NHS England.)
That has a consequence people still underestimate: you can no longer evidence your safety culture by pointing at a stack of completed investigations. You have to show that something changed, and that you know whether it worked.
Duty of Candour works the same way — it is a duty that either happened at the time, correctly, or it did not. It cannot be reconstructed later.
Continuous evidence was the whole premise of the SAF, and there is no indication it is what CQC objected to about its own framework.
So the honest reading is this. The scaffolding is being replaced. The bar has not moved.
What to actually do while the frameworks are in flux
Do not rewrite your evidence model around quality statements. If your policies, your board reports or your internal audit schedule are structured around the 34 quality statements, that structure has a shelf life measured in months. Map your evidence to the underlying regulations and to your own risks instead — those are stable, and they survive framework changes.
Do not stop collecting. The temptation during a regulatory transition is to pause and wait for clarity. That is exactly wrong. Whatever the new frameworks ask for, they will ask you to evidence things that happened during the transition period. Evidence you didn’t capture in 2026 cannot be recreated in 2027.
Keep it dated, owned and signed. This is the format-independent core. Every assurance framework of the last decade has wanted to know what you found, when, who owned it, what you did, and whether it worked. No consultation is going to remove that.
Watch the sector-specific split. Four draft frameworks means CQC is moving away from one-size-fits-all. If you operate across sectors, the assumption that a single internal assurance model serves all your registrations may not survive.
Check how old your rating is, and act accordingly. This is the cheapest piece of preparation available and almost nobody does it. Look up your published rating date. If it falls into one of the ageing bands above, treat assessment as likely within the year and work backwards from that — rather than waiting for the new framework to be published and then starting.
Do not wait for the pilots to conclude. The organisations that will struggle are the ones treating this transition as a reason to defer. CQC has been explicit that the current guidance still applies. “We were waiting for the new framework” is not a defence for a gap in evidence during 2026.
Where AI fits — and where it does not
Since this sits inside our AI in healthcare compliance cluster, the honest position on tooling.
The good fit is continuous evidence mapping. The work that kills governance teams is not judgement — it is keeping a live picture of what evidence exists, what has gone stale, what is unowned, and what changed since the last board meeting. That is genuinely well suited to automation, and it is the difference between an inspection-week scramble and a permanent state of readiness.
The bad fit is investigation. Be careful here, because vendors are selling hard into it.
First, anyone pitching you “AI-powered root cause analysis” is selling against national policy. PSIRF deliberately moved away from RCA as the default method. A product built around generating RCA reports faster is optimising a thing the framework de-emphasised.
Second, and more seriously: there is no published evidence base for LLM use in patient-safety incident investigation. Claims in this space extrapolate from IT operations incident management or from general summarisation benchmarks. Neither transfers well. Incident narratives are the least structured, most incomplete inputs in the entire clinical record, and the dominant failure mode of AI summarisation is omission — silently dropping the contributory factor nobody wrote down clearly.
Then consider where that output goes: Duty of Candour conversations, LFPSE records, CQC notifications, coroners’ inquests. A confident, fluent, causally-wrong narrative is unusually damaging in exactly those settings.
Third, there is a measurement problem underneath all of it. Analysis of 429 AI-related medical device reports published in npj Digital Medicine found that 34.5% contained insufficient information to determine whether AI had contributed at all. Frontline reporters, the authors noted, “may not have insight on whether AI/ML are contributing to the safety issue they are observing given that these algorithms are at work ‘behind the scenes’.”
Which means: the absence of reported AI incidents in your organisation is not evidence that AI is causing no harm. Your incident reporting system, as currently designed, probably cannot see it.
The uncomfortable summary
The framework you are being assessed against is going to change within months. The evidence you need has not changed and will not change. And the tooling being sold to help you produce it is furthest ahead in precisely the area — investigation — where the evidence base is thinnest and the consequence of a confident error is highest.
None of that is an argument for standing still. It is an argument for putting your automation where the work is genuinely repetitive and the failure mode is visible, and keeping named human judgement on everything that ends up in front of a regulator, a family, or a coroner.
If you are evaluating tooling in this space, our twelve questions to ask any healthcare AI vendor are derived from documented failure modes rather than a procurement template. For the wider picture, see our guide to AI in healthcare compliance. And if you’re specifically assessing incident platforms, our PSIRF software buyer’s guide covers the six capabilities worth testing.
This article describes the position as at July 2026, during an active CQC consultation and pilot period. We will update it when the new frameworks are implemented.
