From knowing your regulator to proving you meet it. commvita resolves the right regulator for every jurisdiction, then turns its framework into a live internal audit — evidence commvita already holds, gaps allocated as actions, and an assessor-ready pack at the end.
Regulation management is one traceable line: identity → framework → audit → evidence → action → assurance. Each hop is a real screen you move between.
The Regulatory & Commissioner Engine resolves the correct regulator, inspection framework, background-check scheme, professional register and commissioner per jurisdiction — CQC is England-only; the Crown Dependencies, the other UK nations and every other jurisdiction resolve to their own body, fail-safe (never another jurisdiction's regulator).
The framework name on each jurisdiction card is now clickable — it drills straight into the Compliance Action Hub, where you import that framework and conduct an audit against every requirement.
Every requirement gets a red/amber/green rating and a written finding, stamped with who assessed it. The overall score and RAG recompute as you go.
Each requirement declares whether its evidence is auto (already held in commvita — training %, incidents, DSPT, safeguarding…) or manual (a note you add). Auto-evidence is pulled from the live modules on read.
Turn any gap into a management action assigned to a named member of staff, with a due date, priority and RAG. Owners come from the live staff directory.
Assemble a printable pack — statement, rating, evidence, finding and actions per requirement — and grant read access to named assessor accounts (real users, RBAC-gated).
Per-jurisdiction regulator / framework / background check / professional register / commissioner, with expiry-RAG tracking of the workforce's registrations.
The internal-audit engine: framework import → per-requirement RAG + finding → auto/manual evidence → staff-assigned actions → assessor evidence pack.
A second persisted engine: CQC Single Assessment Framework + Crown Dependency + multi-jurisdiction assessments, element ratings, evidence, CAPA actions, and a guided mock-inspection walkthrough.
This is the honest core of regulation management in commvita — one persisted workflow in the Compliance Action Hub's Audit & Evidence tab. Everything below is API-backed and saved to the database.
Concept screen · illustrative UI of the live workflow| Step | What happens | Status |
|---|---|---|
| Import framework | Instantiates one audit item per requirement from the framework definition. Two frameworks are wired for audit today: CQC (England, 13 requirements) and the Crown Dependency care-standards framework (8 requirements). | ● Live |
| RAG + finding | Rate each requirement red/amber/green with a written finding; the rating is stamped with the assessor and the overall rollup recomputes on every save. | ● Live |
| Auto-evidence (live) | Pulled from real tables on read: mandatory-training % (Learn), incident + incident-action counts (Incident Reporting), safeguarding enquiries, DSPT assertions-met % (IG Hub), clinical-audit count, corporate-risk register, CDSS rules/alerts. | ● Live |
| Auto-evidence (representative) | For some modules the evidence line is a representative summary tagged “seeded module” rather than a live query — meds optimisation, safe-staffing, FFT, RTT, complaints, BAF, personalised care, discharge. | ◎ Part-seeded |
| Manual evidence | For requirements commvita can’t evidence itself (e.g. a board strategy paper), attach a free-text note that persists with the audit item. | ● Live |
| Management actions | Raise an action against a gap, assigned to a real member of staff (owner from the live directory), with due date, priority and a RAG derived from due-date/status. | ● Live |
| Assessor evidence pack | Assemble a printable pack (ref / statement / RAG / evidence / finding / actions), re-computing auto-evidence at pack time; grant pack access to named assessor accounts validated against real users. | ● Live |
Regulation management spans several surfaces at different maturities. Here is the straight answer, so nobody over-claims in front of a regulator.
| Capability | Honest state |
|---|---|
| Internal audit → evidence → actions → pack /compliance-hub | The Audit & Evidence tab is a real, end-to-end persisted workflow for CQC and the Crown Dependency framework. Findings, evidence, staff-assigned actions and the assessor pack all save and reconcile. ● Live |
| Auto-evidence from live modules | Genuinely computed on read for training, incidents, safeguarding, DSPT/IG, clinical audit, corporate risk and CDSS. Roughly the other half of the evidence lines are representative summaries. ● Live ◎ Part-seeded |
| Regulator / register resolution /regulatory-engine | Per-jurisdiction regulator, framework, background-check and professional-register resolution with a proper fail-safe, plus workforce-registration expiry RAG. Configurable per jurisdiction. ● Live |
| Self-assessment & CAPA /regulatory-assessment | A second persisted engine — CQC SAF + Crown Dependency + multi-jurisdiction assessments, element ratings, evidence and CAPA actions all save. Evidence sources are entered by hand (not auto-pulled); the mock-inspection is a guided walkthrough. ● Live ◎ part demonstrated |
| Surface | Honest state |
|---|---|
| Compliance Overview — predicted CQC rating, area bars | Rendered from seeded quality-statement arrays; a compelling picture, but not computed from a live audit. ◎ Demonstrated |
| Action Tracker (the headline tab) | A seeded action list held in the browser session; adds and status changes don’t persist, and “Notify Teams” is illustrative. The live action list lives inside the Audit & Evidence tab. ◎ Demonstrated |
| AI Gap Analysis | Scripted narratives, not a model call — it shows what AI gap analysis would say. ◎ Demonstrated |
| Voluntary Sector register | Seeded partner list; no API yet. ◎ Demonstrated |
The credible roadmap that closes the honest gaps above.
Convert the remaining auto-evidence lines from representative summaries to live queries; add more regulator frameworks beyond CQC and the Crown Dependency set; make the AI Gap Analysis a real model call over the audit’s own findings.
Retire the seeded Action Tracker in favour of the live ComplianceAction list, wire the Teams webhook for real, and persist the Overview from the live audit so the predicted rating is computed, not seeded.