EDITIONEN·FR·ქართ

Accréditation Sans Frontières

International Accreditation of Healthcare Facilities

ASF Standards · Hospital · Standard 7

Standard 7 — Governance & Management

13 criteria · 10 non-negotiable · 3 core · Version 3.0

Criteria in this standard

7.1

The Board Is Real and Accountable

Non-Negotiable

A governing body exists, with named members and clear, documented authority over safety and quality — not an informal ownership arrangement functioning without real oversight structure.

In plain terms: There is a real governing body with named members and written authority over safety and quality — not just an owner making decisions informally.

Facility category Crisis Transition Small Standard
Applicability Adapted Full Adapted Full

Why this matters

Someone has to be accountable for the whole hospital — not for the surgery department or the finances, but for whether patients are safe. In a hospital without a governing body, that responsibility floats. Decisions about safety compete with decisions about money with no forum to weigh them. A board with named members, terms of reference, minutes, and a standing agenda item on quality and safety creates the forum. It also creates accountability: when something goes wrong, there is a body that should have known, asked, and acted. Ownership is not governance; a sole owner needs a board more, not less.

What good looks like

  • Governance charter names members, terms, and quorum rules in writing.
  • Quality and safety data is reviewed at every meeting, not only annually.
  • Minutes show specific follow-up actions with named owners and deadlines.

Common failure modes

  • Governing body exists on paper only; no minutes can be produced.
  • Meetings occur but only discuss budget and construction, never outcomes.
  • Quality incidents are known to management for months before the board hears of them.

Worked example

In practice
A 110-bed private hospital owned by two physicians.
BeforeThe owners made all decisions between themselves. There was no board, no minutes, no defined responsibility for quality. When a serious incident occurred, no one could say who was accountable for the response. The quality committee reported to the medical director, who reported to the owners informally.
ActionA governing board was constituted with the two owners, the medical director, the nursing director, an external clinical member, and a patient representative. Terms of reference defined its authority over safety and quality. It met quarterly with minutes and a standing safety report (incidents, infections, complaints, audits). The quality committee reported to the board formally.
AfterThe Monitor reviewed the terms of reference, membership, and minutes of three meetings with safety reports and actions. Interviewed the external member who described the board's role. Verified.

If you are starting from zero — do this first

  1. Ask: who is ultimately accountable for patient safety here? If the answer is a person, not a body, that is the gap.
  2. Constitute a board with at least one external member and one patient representative.
  3. Write terms of reference: what the board decides, how often it meets, what it receives.
  4. Put safety and quality first on every agenda, with a written report.
The most common mistake: Having a board that meets only to discuss finances and hears about quality only when something goes badly wrong.

Self-assessment questions

1. Is there a documented governing body with named members and defined terms of office? — A charter or bylaws naming members and terms, not an informal ownership arrangement.
Evidence: Governance charter or bylaws
2. Does the governing body meet on a fixed schedule with minutes retained? — Minutes showing attendance, decisions, and follow-up actions, not just that a meeting occurred.
Evidence: Meeting minutes, last four
3. Does the board formally review quality and safety performance at each meeting, not only financial performance? — A standing quality agenda item with real data discussed, not an afterthought.
Evidence: Quality report presented to governing body

Common reasons for a PARTIAL answer

  • The board meets regularly but the quality agenda item is a formality with no real discussion. — Presence on the agenda doesn't guarantee genuine engagement with the content.
  • Minutes exist but record attendance only, not actual decisions taken. — A record of who was present says nothing about what was actually decided.
  • One board member drives all quality engagement, with others largely passive.

Implementation plan

When What
Week 1 Review recent board minutes for genuine quality discussion versus formality.
Week 2 Add or reinforce a standing quality and safety agenda item with real data presented.
Week 3 Identify the reporting pathway gap between incident/quality data and board-level visibility, if one exists.
Ongoing Track board-level follow-up actions to closure, not just to being raised.

How the Monitor verifies this

Method What Detail
DOCUMENT Charter and minutes review Reviews the governance charter and recent minutes for quorum, attendance, and whether quality data led to tracked follow-up.
ASK Board member interview Asks a governing body member, without the CEO present, to describe the last quality or safety issue the board acted on.
OBSERVE Reporting line check Traces whether incident reports and quality indicators actually reach board level, or stop at management.

Supervisor tips

  • Ask for the last four sets of minutes, not the charter alone. — A polished charter proves nothing about actual practice.
  • Interview a board member alone, not with the CEO present. — If a board member cannot answer without looking to the CEO, oversight is not independent in practice, whatever the bylaws say.

Evidence base

[12] Jha AK, Epstein AM. Hospital governance and the quality of care. Health Aff (Millwood). 2010;29(1):182-187 — hospitals whose boards spent more time on quality performed significantly better on process-of-care measures.

Train your team: H-07 · Governance & Management on GMJ Academy →

This course teaches practical implementation of this standard. Free to enroll. ASF certificate on completion.

7.2

There Is a Written Strategic Plan

Non-Negotiable

A documented plan states the hospital's mission and genuinely guides resourcing decisions — not a one-page mission poster disconnected from how money and staff time actually get allocated.

In plain terms: The hospital has a written strategy that actually guides where money and staff go — not a mission statement on the wall that nobody uses to decide anything.

Facility category Crisis Transition Small Standard
Applicability N/A Full Full Full

Why this matters

Without a strategy, resources follow whoever asks loudest. The surgeon gets the new machine; the ward that needs another nurse gets nothing. A strategic plan states what the hospital is for, what it will prioritise over the next three to five years, and therefore what it will say no to. It becomes real when the budget process references it — when a request is evaluated against the plan. The test is not whether the plan exists but whether anyone can point to a decision it shaped.

What good looks like

  • The plan names the population served, concrete goals, and a resourcing rationale.
  • Front-line staff across departments describe a consistent, recognisable mission.
  • At least one recent resourcing decision is clearly traceable to a stated strategic priority.

Common failure modes

  • The plan is a one-page mission poster with no operational content.
  • Staff across departments give inconsistent or vague descriptions of the hospital's mission.
  • No resourcing decision can be linked back to anything in the written plan.

Worked example

In practice
A 150-bed hospital with a framed mission statement in the lobby.
BeforeThe mission said 'excellence in compassionate care.' There was no strategic plan. Budget was set by adjusting last year's numbers. When the Coordinator asked department heads how resources were allocated, the answer was 'we ask the Director.' No one could name a strategic priority.
ActionThe board ran a half-day planning session and produced a four-page strategy: three priorities for three years (maternal care, infection control, staff retention), with a measurable goal for each. The next budget cycle required every capital request to state which priority it served. Two requests were declined because they served none.
AfterThe Monitor reviewed the strategy, the budget with priority alignment column, and minutes showing a declined request. Asked two department heads the three priorities; both answered. Verified.

If you are starting from zero — do this first

  1. Ask five managers what the hospital's top priority is this year. If you get five answers, there is no strategy.
  2. Hold a half-day session with the board to agree three priorities.
  3. Write them on four pages, each with one measurable goal.
  4. Add a column to the budget request form: 'Which priority does this serve?'
The most common mistake: Confusing a mission statement with a strategy — a mission says why; a strategy says what, when, and therefore what not.

Self-assessment questions

1. Is there a written strategic plan covering at least a multi-year horizon? — Not an annual budget alone — a plan with genuine forward horizon.
Evidence: Strategic plan document
2. Does the plan include a clear mission statement describing who the hospital serves and how? — Specific enough to guide real decisions, not generic enough to apply to any hospital anywhere.
Evidence: Mission statement text
3. Can a resourcing decision from the last year be traced back to something in the plan? — Tests whether the plan actually influences decisions, not just whether it exists.
Evidence: Example resourcing decision with plan linkage

Common reasons for a PARTIAL answer

  • A plan exists and is well written but was never actually communicated to front-line staff. — Quality of the document doesn't matter if it never reaches the people expected to align with it.
  • The plan states priorities but the annual budget process runs independently of it. — Two parallel processes that don't reference each other produce a plan with no real teeth.
  • Leadership can trace decisions to the plan; front-line staff cannot see the connection.

Implementation plan

When What
Week 1 Review the current plan for specificity and whether recent resourcing decisions reference it.
Week 2 Communicate the plan's core priorities directly to front-line staff, not just leadership.
Week 3 Link the next resourcing or budget decision explicitly and visibly to a stated strategic priority.
Ongoing Revisit the plan on a fixed schedule, not only when it happens to come up.

How the Monitor verifies this

Method What Detail
DOCUMENT Plan and minutes cross-check Reviews the strategic plan against governing body minutes to check for genuine linkage to real decisions.
ASK Front-line staff interview Asks staff from different departments to state the hospital's mission in their own words.
OBSERVE Wall and induction material check Checks whether the mission is genuinely integrated into staff-facing materials, not only leadership documents.

Supervisor tips

  • Ask staff in different departments the same question separately. — Consistency across independent answers reveals genuine organisational alignment.
  • Ask for one specific recent decision and trace its rationale. — A real, traceable example is worth more than a general assurance the plan guides decisions.

Evidence base

[11] Institute for Healthcare Improvement. Framework for effective board governance of health system quality. Boston: IHI; 2018 — identifies strategic alignment between stated mission and resource allocation as a determinant of sustained quality improvement.

Train your team: H-07 · Governance & Management on GMJ Academy →

This course teaches practical implementation of this standard. Free to enroll. ASF certificate on completion.

7.3

Policy Actually Gets Followed

Non-Negotiable

A policy framework exists and staff can describe how it's genuinely applied in practice, not merely confirm that policies are filed and technically available.

In plain terms: Policies exist, and staff can describe how they actually apply them in real situations — not just confirm the binder is on the shelf.

Facility category Crisis Transition Small Standard
Applicability Full Full Full Full

Why this matters

Every hospital has policies. Most sit in binders or on shared drives, written for accreditation, never read. A policy that is not known is not a policy; it is a document. The test is whether a nurse on the ward can say what the hand hygiene policy requires of her, or what the medication policy says to do about a verbal order. If she can, the policy is alive. If she has to look it up, or does not know it exists, the hospital's actual practice is whatever each person decides. The standard asks for evidence of application, not existence.

What good looks like

  • Staff describe specific, genuine application of policy in their actual work.
  • A real adherence-checking mechanism exists, distinct from document filing.
  • Identified gaps between policy and practice trigger a defined, followed response.

Common failure modes

  • Staff can confirm policies exist but cannot describe how they actually apply to daily work.
  • No mechanism exists to verify adherence beyond confirming documents are filed.
  • Known gaps between policy and practice persist without any response.

Worked example

In practice
A 140-bed hospital with 180 policies on a shared drive.
BeforeThe Coordinator asked ten staff to describe three policies relevant to their role. Two could describe one policy. Most did not know where policies were kept. Several policies contradicted current practice; some referred to departments that no longer existed. The last review date on most was five years earlier.
ActionThe policy set was reduced to 40 essential documents, each two pages or less. Each had a named owner and a review date. Every policy was linked to a training or briefing: the ten most critical (hand hygiene, medication, identification, consent, incident reporting) were covered at induction and annual refresher. A monthly 'policy of the month' briefing was added to ward meetings.
AfterThe Monitor asked eight staff to describe two policies relevant to their role; seven could. Reviewed the policy register with owners and dates. Verified.

If you are starting from zero — do this first

  1. Ask five staff to describe one policy they follow daily. Note how many can.
  2. Count your policies. If over 60, most are unread.
  3. Reduce to the essential set, each two pages, each with an owner.
  4. Link every critical policy to a training moment.
The most common mistake: Producing more policies to satisfy an audit when the problem is that existing ones are unknown.

Self-assessment questions

1. Can staff describe how a specific, named policy is actually applied in their daily work? — Not whether they know a policy exists — whether they can describe applying it.
Evidence: N/A — tested directly
2. Is there a mechanism to check policy adherence, not just policy existence? — A policy audit or spot-check process, distinct from simply confirming documents are filed.
Evidence: Policy adherence audit record
3. When a policy-practice gap is found, is there a defined response, not just noting the discrepancy? — Identifying a gap without addressing it provides limited real value.
Evidence: Gap resolution record

Common reasons for a PARTIAL answer

  • Policies are followed for well-established practices but not consistently for newer ones. — Established habit reinforces old policy adherence; new policies need active reinforcement to take hold.
  • An adherence check exists but only samples a small, easily-prepared subset of practice. — A narrow or predictable audit scope can miss where real gaps live.
  • Gaps are identified during audits but corrective action isn't consistently tracked to completion.

Implementation plan

When What
Week 1 Select several key policies and ask a sample of staff to describe their actual application.
Week 2 Establish or reinforce a genuine adherence-checking mechanism, not just document review.
Week 3 Build a tracked resolution process for any policy-practice gap identified.
Ongoing Rotate which policies get checked, avoiding a predictable, easily-prepared audit pattern.

How the Monitor verifies this

Method What Detail
ASK Staff application interview Asks a staff member to describe how they actually apply a specific named policy in their work, not to recite its existence.
DOCUMENT Adherence audit review Checks for evidence of any process verifying policy adherence, beyond confirming documents are filed.
OBSERVE Practice-policy comparison Directly observes a practice area and compares actual behaviour against the stated policy for that area.

Supervisor tips

  • Ask about application, not existence. — "Do you know this policy exists" and "how do you actually apply it" surface very different answers.
  • Pick a policy area to observe directly, not just review on paper. — Direct observation reveals gaps document review alone cannot.

Evidence base

Policy-practice gaps are consistently identified in healthcare quality literature as a distinct failure mode from policy absence — the existence of a written policy is not evidence of its implementation.

Train your team: H-07 · Governance & Management on GMJ Academy →

This course teaches practical implementation of this standard. Free to enroll. ASF certificate on completion.

7.4

Patient Information Stays Private

Non-Negotiable

Confidentiality is protected physically and culturally throughout the facility, not only referenced in a written policy that doesn't translate into actual practice.

In plain terms: Patient information is kept private in practice — no charts left open, no conversations in corridors, no screens visible to visitors — not just in a policy.

Facility category Crisis Transition Small Standard
Applicability Full Full Full Full

Why this matters

Confidentiality is broken by habit, not malice: the chart on the trolley in the corridor, the diagnosis discussed at the nurses' station within earshot of the waiting room, the computer screen facing the door, the whiteboard listing every patient's condition. Each one is a small betrayal that patients notice and remember. In some contexts — HIV, mental illness, pregnancy — a breach can end a marriage, a job, or a life. The policy is the easy part. The hard part is the culture: a hospital where staff automatically lower their voices and close the chart because that is simply what one does.

What good looks like

  • Screens and monitors are consistently positioned away from public view.
  • Clinical conversations happen in genuinely private spaces, doors or curtains actually used.
  • Staff describe specific, habitual privacy practices without needing to reference a policy document.

Common failure modes

  • Screens face waiting areas or corridors, visible to anyone passing.
  • Clinical conversations are regularly audible to other patients.
  • Staff can cite the confidentiality policy but describe no specific practical habits.

Worked example

In practice
A 130-bed hospital with a written confidentiality policy.
BeforeThe Coordinator walked the wards: charts open on trolleys in public corridors; a whiteboard at the nurses' station listing patient names and diagnoses visible from the lift; a doctor discussing a patient's HIV result with a colleague in the waiting area. Computer screens at reception faced the queue. Staff had signed the policy at induction.
ActionWhiteboards were moved behind the station or replaced with initials only. Chart trolleys were fitted with covers. Computer screens were turned and fitted with privacy filters. A 'quiet room' was designated on each ward for sensitive conversations. A 10-minute confidentiality-in-practice briefing with real examples was added to ward meetings. Monthly walk-rounds by the ward manager checked for breaches.
AfterThe Monitor walked three wards: no open charts, no visible diagnoses, screens shielded. Observed a doctor take a family into the quiet room for a difficult conversation. Verified.

If you are starting from zero — do this first

  1. Walk through your hospital as a visitor. What patient information can you see or hear?
  2. Turn every screen away from public view.
  3. Remove diagnoses from any board visible to visitors.
  4. Designate a room on each ward for private conversations.
The most common mistake: Having every staff member sign a confidentiality policy while the whiteboard in the corridor lists every patient's diagnosis.

Self-assessment questions

1. Are screens and monitors positioned so patient information isn't visible to passersby or other patients? — Physical positioning, checked directly, not assumed from a policy statement.
Evidence: Photo audit of screen positioning
2. Are clinical conversations conducted where they can't be overheard by other patients or visitors? — Curtains, closed doors, or private spaces genuinely used, not just available.
Evidence: N/A — tested directly
3. Do staff understand and apply confidentiality practices consistently, not only when reminded? — Tests whether privacy protection is habitual, not situational.
Evidence: N/A — tested directly

Common reasons for a PARTIAL answer

  • Physical privacy is good in some areas but overlooked in others, like corridors or shared bays. — Privacy protection is often strongest where it was deliberately designed and weaker in less-considered spaces.
  • Staff are conscientious about privacy when reminded but inconsistent otherwise. — Habitual practice is a different, more reliable thing than practice prompted by reminder.
  • Curtains or private spaces exist but aren't consistently used under time pressure.

Implementation plan

When What
Week 1 Audit screen positioning and conversation privacy across all patient-facing areas.
Week 2 Reposition screens and reinforce use of private spaces where gaps are found.
Week 3 Brief staff specifically on habitual, not just reminded, confidentiality practice.
Ongoing Spot-check physical privacy periodically, including in less-considered shared spaces.

How the Monitor verifies this

Method What Detail
OBSERVE Physical privacy check Walks through patient-facing areas checking screen positioning, conversation privacy, and general physical confidentiality protection.
OBSERVE Conversation audibility check Checks whether clinical conversations happening in the facility can be overheard from adjacent areas.
ASK Staff practice interview Asks staff to describe specific ways they protect patient confidentiality in their daily work, beyond citing the policy.

Supervisor tips

  • Walk the space as a visitor would, checking what's actually visible or audible. — A staff member's familiar routine can make an obvious privacy gap invisible to them.
  • Ask staff for specific examples of their own privacy practices. — Specific, concrete habits reveal genuine internalisation better than reciting the policy.

Evidence base

Patient confidentiality protection frameworks consistently identify physical environment design and staff behaviour, not policy documentation alone, as the practical determinants of actual privacy protection.

Train your team: H-07 · Governance & Management on GMJ Academy →

This course teaches practical implementation of this standard. Free to enroll. ASF certificate on completion.

7.5

Medical Records Are Complete

Non-Negotiable

Records contain all mandatory elements and are genuinely audited for completeness on a regular basis, not assumed complete because a template exists.

In plain terms: Medical records contain everything they should, and someone regularly audits a sample to check — not just assumes the template makes them complete.

Facility category Crisis Transition Small Standard
Applicability Adapted Full Full Full

Why this matters

The medical record is the only account of what happened to the patient. When it is incomplete, the next clinician does not know the allergy, the court does not know the consent was taken, the audit does not know the antibiotic was given on time. Incompleteness is invisible until the record is needed for something — a complaint, a lawsuit, a readmission — and then it is too late. A regular audit of a random sample against a checklist of mandatory elements is the only way to know the record is working. A template does not guarantee completion; it guarantees that empty fields have names.

What good looks like

  • A specific, defined list of mandatory elements exists for each encounter type.
  • Regular, genuine completeness audits are conducted with documented findings.
  • Identified gaps are tracked to resolution, not left open.

Common failure modes

  • No specific mandatory elements list exists beyond general expectation.
  • No audit process exists, or completeness is assumed rather than checked.
  • Gaps found in past audits remain unresolved with no tracking.

Worked example

In practice
A 150-bed hospital with paper records and a defined admission template.
BeforeNo one audited records. The Coordinator pulled 30 at random against a 15-item checklist (identification, allergies, consent, medication chart, assessment, care plan, discharge summary…). Average completeness: 60%. Consent forms were missing in 8; allergy status was blank in 11. The medical director assumed records were complete 'because the template is good.'
ActionA monthly audit was established: 20 random records against a 15-item checklist, scored by the medical records officer, reported by ward and by clinician. Results went to the quality committee. Wards below 85% received a targeted briefing. The three most-missed items were added to the discharge sign-off.
AfterThe Monitor reviewed six months of audit results: completeness up from 60% to 91%. Reviewed the checklist and the quality committee minutes with actions. Verified.

If you are starting from zero — do this first

  1. Pull 20 records at random and check 15 mandatory items. Score them.
  2. Identify the three most-missed items.
  3. Start a monthly audit with results by ward.
  4. Report the score to the quality committee and ward managers.
The most common mistake: Trusting the template — a template with blank fields is an incomplete record with a nice layout.

Self-assessment questions

1. Is there a defined list of mandatory record elements for each type of encounter? — A specific, checkable list, not a general expectation of thoroughness.
Evidence: Mandatory elements list
2. Are records regularly audited for completeness against that list? — Genuine audit, not assumption of completeness because a template was used.
Evidence: Completeness audit record
3. Are gaps found during audits actually addressed, not just noted? — Identifying an incomplete record without correcting it leaves the underlying risk unresolved.
Evidence: Gap resolution record

Common reasons for a PARTIAL answer

  • Audits happen but only sample a small, non-representative set of records. — A narrow sample can miss where real completeness gaps concentrate.
  • Completeness is checked for structural fields but not for genuine clinical content quality. — A record can be structurally complete while still lacking substantively useful clinical detail.
  • Gaps are found and noted but resolution isn't consistently tracked to closure.

Implementation plan

When What
Week 1 Review the current mandatory elements list and recent audit practice, if any exists.
Week 2 Establish or reinforce a genuine, regular completeness audit process.
Week 3 Build a gap resolution tracker so identified issues are actually closed.
Ongoing Widen the audit sample periodically to avoid a narrow, predictable pattern.

How the Monitor verifies this

Method What Detail
DOCUMENT Mandatory elements definition check Reviews the defined list of mandatory record elements for specificity and completeness.
DOCUMENT Completeness audit review Reviews recent completeness audit records and checks for genuine, regular practice.
DOCUMENT Gap resolution check Checks whether gaps identified in past audits were actually resolved, not just documented as found.

Supervisor tips

  • Ask for actual audit records, not a description of the intended process. — Dated findings are the only real evidence a genuine audit occurs.
  • Check whether a past identified gap was actually resolved. — Resolution tracking reveals whether the audit process has real teeth.

Evidence base

Medical record completeness auditing is a recognised quality assurance practice specifically because template existence alone does not guarantee consistent completion in real clinical practice.

Train your team: H-07 · Governance & Management on GMJ Academy →

This course teaches practical implementation of this standard. Free to enroll. ASF certificate on completion.

7.6

Patient Data Is Kept Secure

Non-Negotiable

Health information is protected with defined access controls and a genuine breach response plan, using practical, achievable security measures appropriate to the facility's resources.

In plain terms: Patient data is protected with practical access controls and a plan for what to do if there is a breach — appropriate to the hospital's real situation, not a policy copied from a large corporation.

Facility category Crisis Transition Small Standard
Applicability Adapted Full Full Full

Why this matters

A hospital's records are attractive: identity data, financial data, health data. Breaches happen through lost laptops, shared passwords, unlocked records rooms, and staff looking up patients out of curiosity. The standard does not require enterprise security; it requires the basics done properly: who can access what, how access is granted and removed when someone leaves, where paper records are kept and who has the key, and what happens when a breach is discovered. A breach response plan matters because breaches will happen; the difference is whether the hospital knows within hours or months.

What good looks like

  • Access controls are genuinely role-based and reflect actual staff need.
  • A specific, actionable breach response plan exists and has been reviewed recently.
  • Relevant staff know their role in the breach response process.

Common failure modes

  • Data access is broadly available regardless of staff role.
  • No breach response plan exists, or it exists only as a vague statement of concern.
  • Staff are unaware any breach response process exists.

Worked example

In practice
A 120-bed hospital with an electronic record system and a paper archive.
BeforeAll clinical staff shared two system logins. Departed staff still had accounts. The paper archive was in an unlocked basement room. There was no breach plan. When a USB stick with a patient list was lost, nobody knew who to tell or what to do.
ActionIndividual logins were issued to every user with role-based access. A leaver process removed access on the last day. The archive was locked with a signed key register. A one-page breach response plan named the person to notify, the steps to contain and assess, and the reporting obligations. Two staff completed a half-day data protection course.
AfterThe Monitor reviewed the access list (individual, role-based, no leavers), the archive key register, and the breach plan. Asked a nurse what she would do if she found a patient list in a public area; she named the person to call. Verified.

If you are starting from zero — do this first

  1. Count how many people share a login. Anything above one is a gap.
  2. Check whether staff who left last year still have accounts.
  3. Lock the paper archive and start a key register.
  4. Write a one-page breach plan: who to tell, what to do first.
The most common mistake: Adopting a 40-page data security policy from a large hospital that nobody in a small one can implement — do the basics, and do them properly.

Self-assessment questions

1. Are access controls in place restricting patient data access to staff who need it for their role? — Role-based restriction, not general access available to any staff member.
Evidence: Access control policy and implementation
2. Is there a documented breach response plan, specific and actionable? — Not a general statement of concern — a named process for what happens if a breach occurs.
Evidence: Breach response plan document
3. Have access controls and the breach plan been reviewed or tested recently? — An untested plan or unreviewed control list may not reflect current reality.
Evidence: Review or test record

Common reasons for a PARTIAL answer

  • Access controls exist for electronic records but not consistently for physical files. — Security attention often concentrates on digital systems while physical record access remains loosely controlled.
  • A breach response plan exists but has never been reviewed since it was written. — An unreviewed plan may not reflect current systems, staff, or actual risk.
  • Access controls are correctly configured but not periodically re-reviewed as staff roles change.

Implementation plan

When What
Week 1 Review current access controls against actual staff roles for any over-broad access.
Week 2 Draft or review the breach response plan for specificity and actionable steps.
Week 3 Brief relevant staff on their role in the breach response process.
Ongoing Review access control assignments periodically as staff roles change.

How the Monitor verifies this

Method What Detail
DOCUMENT Access control review Reviews access control policy and checks implementation against actual staff access levels.
DOCUMENT Breach response plan check Reviews the breach response plan for specificity and actionable steps, not general statements.
ASK Staff awareness interview Asks staff whether they know the breach response process and their role in it, if applicable.

Supervisor tips

  • Check physical record access, not only electronic systems. — Security attention often skews toward digital systems while physical files remain loosely controlled.
  • Ask when the breach plan was last reviewed, not just whether it exists. — A plan's age relative to current systems and staff matters as much as its existence.

Evidence base

Health information security frameworks consistently identify access control and incident response planning, rather than technology sophistication alone, as the primary determinants of practical data protection in resource-constrained settings.

Train your team: H-07 · Governance & Management on GMJ Academy →

This course teaches practical implementation of this standard. Free to enroll. ASF certificate on completion.

7.7

Records Are Kept Exactly as Long as Required

Non-Negotiable

A retention policy governs how long records are kept and how they're disposed of, aligned with the specific legal requirement in this facility's jurisdiction, not a generic assumption.

In plain terms: Records are kept for exactly as long as your country's law requires, and destroyed securely after — under a written retention policy that names the legal source.

Facility category Crisis Transition Small Standard
Applicability Adapted Full Full Full

Why this matters

Keep records too briefly and you cannot defend a lawsuit, respond to a complaint, or give a patient their history. Keep them forever and the archive fills a basement, costs money, and breaches privacy law in jurisdictions that mandate deletion. The retention period is not a judgment call; it is a legal requirement that differs by country, record type, and patient age. A written policy that cites the specific law, states the period for each record type, and defines the secure destruction method is the only defensible position. Most hospitals have no such policy and simply keep everything.

What good looks like

  • A specific, written retention policy exists by record type.
  • Retention periods are verified against actual legal requirements, not assumed.
  • Disposal is conducted securely with documented records.

Common failure modes

  • No specific retention policy exists beyond a general assumption.
  • Stated retention periods don't match the actual legal requirement, or were never checked.
  • No evidence of secure, documented disposal exists.

Worked example

In practice
A 140-bed hospital with 25 years of paper records in a basement and no retention policy.
BeforeNobody knew the legal retention period. Records were never destroyed. The basement was full and damp; some records from the 1990s were unreadable. When the Coordinator checked, the national law required 10 years for adult records, 25 years for children, and permanent retention for certain categories — the hospital was both over-retaining most records and had let some required ones decay.
ActionThe Coordinator obtained the legal requirement from the Ministry of Health and wrote a two-page policy: record type, retention period, legal source, destruction method (shredding with certificate), and responsible person. A destruction schedule was created for records beyond retention. Records still within retention were moved to dry storage. A destruction log was started.
AfterThe Monitor reviewed the policy with legal citations, the destruction schedule, the destruction log with certificates, and the improved storage. Verified.

If you are starting from zero — do this first

  1. Find out the legal retention period for medical records in your country — ask the Ministry or a lawyer.
  2. Write it down with the source, by record type.
  3. Identify records past retention and schedule secure destruction.
  4. Check that records within retention are stored where they will survive.
The most common mistake: Keeping everything forever because nobody knows the rule — over-retention is both a cost and a privacy risk.

Self-assessment questions

1. Does a written retention policy exist, specifying how long different record types are kept? — Specific durations by record type, not a vague general statement.
Evidence: Retention policy document
2. Is the retention period aligned with the actual legal requirement in this jurisdiction? — Verified against the real legal requirement, not assumed or copied from another context.
Evidence: Legal requirement reference
3. Is disposal of records past their retention period conducted securely and documented? — Disposal that protects confidentiality even as the record is destroyed.
Evidence: Disposal record

Common reasons for a PARTIAL answer

  • A policy exists but was written years ago and never checked against a legal requirement update. — Legal requirements can change, and a policy set once can quietly become outdated.
  • Retention periods are correct for most record types but a specific category was overlooked. — Comprehensive-looking policies can still miss a specific record type with different legal requirements.
  • Disposal happens but isn't consistently documented.

Implementation plan

When What
Week 1 Review the current retention policy against the actual legal requirement for this jurisdiction.
Week 2 Correct any misalignment found and update the policy accordingly.
Week 3 Establish a documented, secure disposal process for records past retention.
Ongoing Recheck legal requirement alignment periodically, as regulations can change.

How the Monitor verifies this

Method What Detail
DOCUMENT Retention policy review Reviews the retention policy for specificity by record type.
DOCUMENT Legal alignment check Checks whether the stated retention periods align with the actual legal requirement in this jurisdiction.
DOCUMENT Disposal record review Reviews records of secure disposal for any record past its retention period.

Supervisor tips

  • Ask for the specific legal citation the retention period is based on. — A specific reference, or its absence, reveals whether this was genuinely checked or assumed.
  • Check disposal documentation, not just the retention policy itself. — A correct policy on paper doesn't guarantee correct, documented execution.

Evidence base

Health record retention requirements vary by jurisdiction and are legally defined precisely because both premature destruction and indefinite retention carry distinct, documented risks.

Train your team: H-07 · Governance & Management on GMJ Academy →

This course teaches practical implementation of this standard. Free to enroll. ASF certificate on completion.

7.8

Incidents Are Actually Reported

Non-Negotiable

An accessible incident reporting system exists and staff genuinely use it — measured by real reporting volume and pattern, not merely by the system's technical availability.

In plain terms: Staff actually report incidents — near-misses as well as harm — and the hospital can show it from the number and pattern of reports, not just the existence of a form.

Facility category Crisis Transition Small Standard
Applicability Full Full Full Full

Why this matters

A hospital that reports few incidents is not a safe hospital; it is a hospital where staff have stopped reporting. Incident reports are the raw material of learning: the near-miss today is the death next month if the cause is not found. Staff stop reporting when reports go nowhere, when they are blamed, when the form takes 20 minutes, or when nothing ever changes. The measure of a working system is volume and pattern: reports rising as trust builds, near-misses outnumbering harm events, every ward reporting. A form on the intranet with three reports a month is not a system.

What good looks like

  • Reporting volume reflects genuine, ongoing use across staff levels, not just management.
  • Staff describe genuine confidence they can report without punitive consequence.
  • The reporting system is accessible directly at the point of work.

Common failure modes

  • Reporting volume is minimal or has dropped sharply with no clear explanation.
  • Staff describe fear of blame or consequence as a reason they hesitate to report.
  • The reporting system exists but is difficult to access in practice.

Worked example

In practice
A 150-bed hospital with an incident form that generated 40 reports a year.
BeforeThe form was four pages and required the reporter's name and manager's signature. Reports went to the medical director and stayed there. Staff described a colleague who had reported a medication error and been disciplined. Ward nurses estimated they saw 'several' near-misses a week; none were reported.
ActionThe form was reduced to one page with an anonymous option. A no-blame policy was written and signed by the Director. Reports went to a quality officer who acknowledged each within 48 hours, with the reporter told what was done. Monthly ward feedback showed what was learned. Near-miss reporting was actively encouraged with a 'good catch' recognition.
AfterThe Monitor reviewed the log: 340 reports in the year, 60% near-misses, every ward reporting, average acknowledgement time 1.5 days. Interviewed three nurses who had reported and received feedback. Verified.

If you are starting from zero — do this first

  1. Count last year's incident reports. Divide by beds. Under 2 per bed per year means under-reporting.
  2. Ask five nurses when they last saw a near-miss and whether they reported it.
  3. Cut the form to one page and allow anonymous reports.
  4. Acknowledge every report within 48 hours and tell the reporter what happened.
The most common mistake: Interpreting a low incident count as a safe hospital — it is almost always a silent one.

Self-assessment questions

1. Is the incident reporting system genuinely accessible to all staff, not just management? — Accessible in practice, at the point of work, not buried in an administrative system.
Evidence: Reporting system access description
2. Does actual reporting volume suggest genuine use, not just technical availability? — A system that exists but receives almost no reports over time suggests a use problem, not a safety-perfect facility.
Evidence: Reporting volume data over time
3. Do staff believe they can report without fear of punitive consequence? — Genuine psychological safety, not just a stated non-punitive policy.
Evidence: N/A — tested directly

Common reasons for a PARTIAL answer

  • Reporting happens for minor incidents but staff hesitate to report anything involving their own error. — Psychological safety often varies by perceived personal exposure, not uniformly across incident types.
  • Senior staff report reliably; junior staff report far less. — Hierarchy can create very different real experiences of psychological safety within the same facility.
  • A non-punitive policy exists on paper but staff describe a past incident where reporting led to real consequences.

Implementation plan

When What
Week 1 Review reporting volume trends and identify any concerning drop or pattern.
Week 2 Interview a cross-section of staff, including junior staff, about their actual confidence in reporting.
Week 3 Address any specific past incident or perception undermining psychological safety directly and visibly.
Ongoing Track reporting volume as an ongoing indicator, investigating any significant drop.

How the Monitor verifies this

Method What Detail
DOCUMENT Reporting volume review Reviews incident reporting volume and pattern over time for evidence of genuine, ongoing use.
ASK Psychological safety interview Asks front-line staff directly whether they feel safe reporting an incident, including one they caused themselves.
OBSERVE System accessibility check Checks how genuinely accessible the reporting mechanism is at the actual point of work, not just in principle.

Supervisor tips

  • Ask junior staff specifically, not only senior staff. — Hierarchy can create very different real experiences within the same facility.
  • Ask about reporting one's own error specifically, not just witnessing someone else's. — Self-reporting confidence is usually the harder, more revealing test of genuine psychological safety.

Evidence base

Incident reporting culture, specifically the psychological safety staff feel around reporting without fear of punitive consequence, is consistently identified as the primary determinant of reporting volume, more so than system accessibility alone.

Train your team: H-07 · Governance & Management on GMJ Academy →

This course teaches practical implementation of this standard. Free to enroll. ASF certificate on completion.

7.9

Serious Incidents Get Properly Investigated

Non-Negotiable

Root cause analysis is genuinely used for serious incidents, with a resulting, tracked action plan — not a brief note explaining what happened without examining why it happened.

In plain terms: Serious incidents get a proper root cause analysis with a tracked action plan — not a short note saying what happened and moving on.

Facility category Crisis Transition Small Standard
Applicability Adapted Full Full Full

Why this matters

When a patient dies from an error, the question is not 'who did it' but 'why did the system let it happen.' Root cause analysis asks that question systematically: what were the contributing factors — staffing, equipment, communication, training, environment — and what change would prevent recurrence. A brief incident note that records the facts and blames the individual learns nothing; the same error recurs with a different nurse. An RCA produces actions with owners and dates, and those actions are tracked to completion. That is how the hospital gets safer.

What good looks like

  • A structured RCA methodology is genuinely applied to serious incidents.
  • RCAs consistently result in specific, documented action plans.
  • Action items are tracked and demonstrably completed, not left open.

Common failure modes

  • Serious incidents receive only a brief note, no structured systemic analysis.
  • RCAs identify findings but produce no specific action plan.
  • Action items remain open indefinitely with no completion tracking.

Worked example

In practice
A 160-bed hospital where serious incidents were reviewed by the medical director.
BeforeA wrong-drug death was investigated with a half-page note: 'Nurse X administered the wrong medication. Nurse X has been counselled.' No system factors were examined. Six months later, a near-identical error occurred with a different nurse. Nobody had asked why two similar drugs were stored side by side, why the double-check was not done, or why the ward was two nurses short that night.
ActionAn RCA process was adopted: a trained team of three (not including the involved staff's manager) conducts a structured investigation within 30 days using a recognised method — timeline, contributory factors, root causes, actions with owners and dates. Actions are tracked at the quality committee until closed. The involved staff are supported, not blamed, unless there is reckless conduct.
AfterThe Monitor reviewed three completed RCAs with contributory factor analysis and action plans; all actions had owners, dates, and closure evidence. The look-alike drug storage issue identified in one RCA had been fixed hospital-wide. Verified.

If you are starting from zero — do this first

  1. Pull your last three serious incident investigations. Do they identify system causes or just name a person?
  2. Train three people in a recognised RCA method (a two-day course).
  3. Define 'serious incident' and the 30-day RCA requirement in writing.
  4. Track every RCA action at the quality committee until closed.
The most common mistake: Investigating to find who was at fault rather than why the system allowed it — the person changes; the system stays the same.

Self-assessment questions

1. Is a structured root cause analysis method used for serious incidents, not just a brief incident note? — A defined methodology examining systemic factors, not a one-paragraph summary.
Evidence: RCA methodology and completed sample
2. Does the RCA result in a specific, tracked action plan? — Findings without a resulting plan don't translate into prevention.
Evidence: Action plan document
3. Are action plan items tracked to completion, not left open indefinitely? — An action item that's never closed provides no real protection against recurrence.
Evidence: Action plan completion tracking

Common reasons for a PARTIAL answer

  • RCA is conducted for the most severe incidents but not consistently applied to moderately serious ones. — A narrower-than-intended threshold for triggering RCA can leave real systemic issues unexamined.
  • Action plans are written but implementation isn't consistently tracked to actual completion. — A good plan on paper doesn't guarantee the underlying system issue actually got fixed.
  • RCA identifies contributing factors but stops short of genuinely systemic root causes.

Implementation plan

When What
Week 1 Review recent serious incidents for evidence of genuine RCA versus brief incident notes.
Week 2 Ensure RCA methodology is applied consistently against a clear, defined severity threshold.
Week 3 Build a tracked action plan process ensuring RCA findings translate into completed changes.
Ongoing Audit action plan completion rates periodically.

How the Monitor verifies this

Method What Detail
DOCUMENT RCA methodology and sample review Reviews the RCA methodology used and checks a sample of completed analyses for genuine systemic examination.
DOCUMENT Action plan review Reviews whether RCAs result in specific, documented action plans, not just findings.
DOCUMENT Completion tracking check Checks whether action plan items are tracked to actual completion.

Supervisor tips

  • Ask for a completed RCA example, not a description of the methodology. — A real example reveals whether the analysis goes genuinely systemic or stays surface-level.
  • Check whether action items from past RCAs were actually completed. — Completion tracking is where good analysis either translates into real prevention or doesn't.

Evidence base

Root cause analysis methodology is a well-established patient safety practice specifically because surface-level incident review, without deeper systemic examination, is consistently associated with recurrence of preventable events.

Train your team: H-07 · Governance & Management on GMJ Academy →

This course teaches practical implementation of this standard. Free to enroll. ASF certificate on completion.

7.10

Safety Culture Is Actually Measured

Non-Negotiable

A validated survey measures whether staff genuinely feel safe raising concerns, conducted regularly and acted on, not assumed from the absence of complaints.

In plain terms: The hospital measures whether staff feel safe to raise concerns — with a validated survey, regularly — and acts on what it finds.

Facility category Crisis Transition Small Standard
Applicability N/A Full Adapted Full

Why this matters

Safety culture is the difference between a nurse who says 'I think you've got the wrong patient' and one who says nothing because the surgeon shouts. It cannot be assumed from the absence of complaints; silence is the symptom. A validated survey — the AHRQ Hospital Survey on Patient Safety Culture, SAQ, or equivalent — asks staff anonymously: do you feel able to speak up? Are errors held against you? Does management act on safety concerns? The results, by unit, show where the culture is broken. Then the hard part: doing something visible about it.

What good looks like

  • A validated safety culture survey is administered on a regular, defined schedule.
  • Results are reviewed with genuine analysis, not filed without examination.
  • Staff can point to a visible change that resulted from a past survey.

Common failure modes

  • No structured survey exists, or an internally improvised, unvalidated tool is used.
  • Surveys were conducted once, historically, with no regular schedule since.
  • Staff report survey results disappear with no visible follow-up.

Worked example

In practice
A 140-bed hospital that had never surveyed staff on safety culture.
BeforeManagement believed the culture was good because there were few complaints. The Coordinator ran the AHRQ survey anonymously: 45% of staff said they felt errors would be held against them; 38% said they would not feel safe raising a concern about a senior doctor. Two units scored far below the rest.
ActionResults were shared openly with all staff. The two low-scoring units received focused attention: their leadership was coached, a 'speaking up' champion was appointed, and the Director attended their meetings. A hospital-wide 'just culture' policy was written and explained. The survey was repeated at 12 months.
AfterThe Monitor reviewed both survey rounds: 'errors held against you' down from 45% to 22%; the two low-scoring units improved most. Reviewed the action plan and the just culture policy. Verified.

If you are starting from zero — do this first

  1. Run a validated safety culture survey — the AHRQ tool is free and translated into many languages.
  2. Make it anonymous and share the results with everyone.
  3. Identify your two lowest-scoring units and focus there.
  4. Repeat annually and show the trend.
The most common mistake: Assuming the culture is safe because nobody complains — the absence of complaints is what an unsafe culture produces.

Self-assessment questions

1. Is a validated safety culture survey conducted, not an informal or ad hoc check? — A recognised, validated tool, not an internally improvised questionnaire.
Evidence: Survey tool and administration record
2. Is the survey conducted regularly, on a defined schedule? — A single historical survey doesn't reflect current culture.
Evidence: Survey schedule and history
3. Are survey results reviewed and acted on, with visible follow-up? — Measurement without action provides no real improvement.
Evidence: Results review and action record

Common reasons for a PARTIAL answer

  • A survey is conducted but response rates are low, undermining result reliability. — Low participation can reflect the same trust issues the survey is trying to measure.
  • Results are reviewed by leadership but not communicated back to staff. — A closed feedback loop, invisible to staff, doesn't build the trust genuine improvement requires.
  • Action is taken on some findings but not others, without a clear rationale communicated.

Implementation plan

When What
Week 1 Review the current survey tool for validation and the administration schedule for regularity.
Week 2 If response rates are low, investigate why and address barriers to participation.
Week 3 Establish a process to communicate results and planned actions back to staff.
Ongoing Track whether survey-driven actions are visible and completed, and repeat on schedule.

How the Monitor verifies this

Method What Detail
DOCUMENT Survey tool and history review Reviews the survey tool used for validation and checks the administration schedule for regularity.
DOCUMENT Results and action review Reviews survey results and checks for evidence of genuine follow-up action, not just data collection.
ASK Staff perception interview Asks staff whether they believe survey results actually lead to visible change.

Supervisor tips

  • Ask staff directly whether they believe the survey leads to real change. — Staff perception of genuine impact is the real test, not survey administration alone.
  • Check response rates, not just that a survey was sent. — Low participation can itself be a safety culture signal worth investigating.

Evidence base

Safety culture surveys are a recognised patient safety measurement practice specifically because staff silence is an ambiguous signal that can indicate either genuine safety or suppressed concern, and only direct measurement distinguishes between them.

Train your team: H-07 · Governance & Management on GMJ Academy →

This course teaches practical implementation of this standard. Free to enroll. ASF certificate on completion.

7.11

Patient Experience Is Measured Continuously, Not Only After Discharge

Core

Patient experience is measured through structured, ongoing feedback during the course of care — not only through the post-discharge complaint channel required elsewhere in this document, which by definition only captures concerns raised after the fact.

In plain terms: Patient experience is measured during the stay — not only after discharge or through complaints — so problems can be fixed while the patient is still there.

Facility category Crisis Transition Small Standard
Applicability N/A Full Adapted Full

Why this matters

A complaint after discharge tells you what went wrong last month. A question at the bedside on day two tells you what is going wrong now — and lets you fix it for this patient. Continuous measurement — a short daily question, a mid-stay check, a real-time feedback point — catches the cold food, the unanswered call bell, the doctor who did not explain. It also changes staff behaviour: when patients are asked every day whether they were treated with respect, staff treat them with respect. The post-discharge survey remains useful, but as one source among several, not the only one.

What good looks like

  • Structured feedback is collected systematically during the stay, not only after discharge.
  • Collection reaches a broad, representative sample of patients, not just self-selected volunteers.
  • Real examples exist of improvements made in response to collected feedback.

Common failure modes

  • No feedback mechanism exists beyond the post-discharge complaint channel.
  • Feedback relies entirely on patients who happen to volunteer it, unsystematically.
  • Feedback is collected but no evidence exists it has ever informed a real change.

Worked example

In practice
A 130-bed hospital with a post-discharge survey returned by 8% of patients.
BeforeThe only measure was a paper survey mailed after discharge, low response, results reviewed annually. No one asked patients during the stay. The Coordinator interviewed 20 inpatients: 12 had a concern they had not raised because 'no one asked.'
ActionA three-question bedside check was introduced on day two and every three days after: 'Are you being treated with respect? Do you understand your care? Is there anything we can do better today?' Done by the ward manager or a volunteer, recorded, and any concern actioned same day. A tablet at the ward exit offered a two-minute feedback form. Results by ward were reported monthly.
AfterThe Monitor reviewed three months of bedside check data with same-day actions logged. Interviewed five inpatients: all had been asked about their experience within the last three days. Verified.

If you are starting from zero — do this first

  1. Ask ten inpatients today: 'Is there anything we could be doing better?' Note what you hear.
  2. Introduce a three-question check on day two of every stay.
  3. Record the answers and act on concerns the same day.
  4. Report results by ward monthly.
The most common mistake: Relying on a post-discharge survey with a low response rate as the only measure of patient experience.

Self-assessment questions

1. Is patient experience measured through structured feedback during the stay, not only after discharge? — Real-time or near-real-time feedback, distinct from the post-discharge complaint channel.
Evidence: Ongoing experience measurement tool
2. Is feedback collected broadly, not only from patients who happen to volunteer it? — A systematic approach, not reliance on the small subset of patients naturally inclined to give feedback.
Evidence: Feedback collection method
3. Is collected feedback actually reviewed and used to inform real improvements? — Genuine responsiveness, not data collected and left unexamined.
Evidence: Feedback review and action record

Common reasons for a PARTIAL answer

  • Feedback is collected but response rates are low, limiting how representative the picture actually is. — Low participation can mean the loudest or most engaged voices dominate, not a representative signal.
  • Feedback is reviewed by leadership but rarely translated into a visible, communicated change. — A closed feedback loop that doesn't visibly act on input can erode patient willingness to participate over time.
  • Collection happens for inpatient stays but not for shorter outpatient or day-procedure visits.

Implementation plan

When What
Week 1 Review current patient experience measurement, if any, for systematic reach versus self-selected feedback.
Week 2 Establish or strengthen a structured, ongoing feedback mechanism during the stay.
Week 3 Build a defined review process ensuring feedback actually informs improvement decisions.
Ongoing Track response rates and periodically communicate real changes made in response to feedback.

How the Monitor verifies this

Method What Detail
DOCUMENT Measurement tool review Reviews the ongoing patient experience measurement tool and collection method for genuine, systematic reach.
DOCUMENT Response rate check Reviews response rates and collection consistency, not reliance on self-selected volunteer feedback alone.
ASK Feedback action interview Asks staff for a specific example of a real improvement made in response to collected experience feedback.

Supervisor tips

  • Ask for a specific, real example of a change made from feedback. — A real example reveals genuine responsiveness better than a description of the collection process.
  • Check response rates, not just that a feedback mechanism exists. — Low participation can undermine how representative the collected picture actually is.

Evidence base

Ongoing patient experience measurement, distinct from post-discharge complaint mechanisms, is an established quality improvement practice in international hospital accreditation frameworks, providing earlier and more representative signal than complaint-based feedback alone.

Train your team: H-07 · Governance & Management on GMJ Academy →

This course teaches practical implementation of this standard. Free to enroll. ASF certificate on completion.

7.12

A Real Ethics Consultation Process Exists

Core

Staff facing a genuine ethical dilemma in patient care have access to a real, usable ethics consultation process — a committee, a named resource, or an external arrangement — not left to resolve difficult cases alone or through informal corridor conversations.

In plain terms: When staff face a genuine ethical dilemma — withdrawing treatment, a patient refusing life-saving care, a family in conflict — there is someone they can actually consult.

Facility category Crisis Transition Small Standard
Applicability Adapted Full Adapted Full

Why this matters

Should we continue ventilating a patient with no prospect of recovery when the family insists? Can we override a competent patient's refusal of a blood transfusion? What do we do when parents disagree about their child's treatment? These are not clinical questions and they are not legal questions; they are ethical ones, and clinicians facing them alone at 2am make worse decisions than clinicians with somewhere to turn. An ethics consultation process — a committee, a trained individual, an external advisor — gives staff a structured way to think through the dilemma. It does not need to be elaborate; it needs to exist and be reachable.

What good looks like

  • A real, structured ethics consultation resource exists and is accessible.
  • Staff can describe specifically and confidently how they would access it.
  • Real usage exists, or a credible explanation for why the need hasn't yet arisen.

Common failure modes

  • No real consultation resource exists beyond a general policy statement about ethical principles.
  • Staff are unaware of how to access any such resource.
  • The process, if it exists, has never been used and nobody can explain why.

Worked example

In practice
A 150-bed hospital with an ICU and no ethics resource.
BeforeEthical dilemmas were resolved by whoever was most senior. An ICU nurse described a case where a patient's daughter demanded continued ventilation the team believed was futile; the consultant decided alone, the team was divided, and the nurse said 'I still don't know if we did the right thing.' There was no forum for the discussion.
ActionA small ethics consultation group was formed: a senior physician, a senior nurse, a chaplain, and an external ethicist from the university, available by phone within 24 hours. A one-page process described how to request a consultation and what to expect. Consultations were documented in the patient record. The group met quarterly to review cases and learn.
AfterThe Monitor reviewed the process, the contact list, and records of four consultations in six months. Interviewed the ICU nurse who described using the process and feeling supported. Verified.

If you are starting from zero — do this first

  1. Ask three senior clinicians about the last ethical dilemma they faced and who they consulted.
  2. Identify three or four people who could form a consultation group.
  3. Write a one-page process: how to request, response time, documentation.
  4. Tell all clinical staff it exists.
The most common mistake: Assuming ethical dilemmas are resolved by seniority — the senior person is as uncertain as everyone else, just more alone.

Self-assessment questions

1. Is there a real, accessible ethics consultation process — committee, named resource, or external arrangement? — An actual, usable resource, not a theoretical statement that ethical principles matter.
Evidence: Ethics consultation process description
2. Do staff know how to access it, not just that it exists somewhere in policy? — Practical, known accessibility — staff can describe how they'd actually use it.
Evidence: N/A — tested directly
3. Has the process actually been used for a real case, or does it exist only theoretically? — Genuine use is the real test of whether this is a functioning resource or a document nobody has needed to open.
Evidence: Usage record, or honest absence of one

Common reasons for a PARTIAL answer

  • A resource exists but is only accessible during business hours, leaving urgent after-hours dilemmas unsupported. — Ethical dilemmas don't confine themselves to convenient hours, and a resource that assumes they will has a real coverage gap.
  • Senior staff know how to access consultation; junior staff facing the same dilemmas often don't. — Awareness concentrated at senior levels doesn't help staff who most need support in the moment.
  • A committee exists on paper but hasn't convened or been consulted in a very long time.

Implementation plan

When What
Week 1 Review current access to ethics consultation, if any, for real structure versus policy statement.
Week 2 Establish or reinforce a genuinely accessible process, including after-hours coverage.
Week 3 Brief all clinical staff, not only senior staff, on how to access it.
Ongoing Review whether the process is genuinely being used when needed, not just theoretically available.

How the Monitor verifies this

Method What Detail
DOCUMENT Process existence and structure review Reviews the ethics consultation process for a real, defined structure, not just a policy statement of principles.
ASK Staff access interview Asks clinical staff how they would actually access ethics consultation for a difficult case.
DOCUMENT Usage history check Checks for any real, documented instance of the process being used, or an honest account of why it hasn't been.

Supervisor tips

  • Ask a junior staff member how they'd access ethics support, not a department head. — This reveals whether awareness genuinely reaches the staff most likely to face difficult cases directly.
  • Ask about after-hours access specifically. — A resource available only during business hours has a real, common gap worth checking directly.

Evidence base

Access to clinical ethics consultation is an established structural requirement in major international hospital accreditation and governance frameworks, recognising that individual clinicians should not be left to resolve genuine ethical complexity without institutional support.

Train your team: H-07 · Governance & Management on GMJ Academy →

This course teaches practical implementation of this standard. Free to enroll. ASF certificate on completion.

7.13

Patients and Families Have a Real Voice in Governance

Core

At least one patient or family representative has a genuine, structured role in quality review or governance discussions — not a governance and quality structure that is entirely staff and board-facing, with patient input arriving only indirectly through complaints or surveys.

In plain terms: At least one patient or family representative sits in quality or governance meetings with a real role — not a token seat with no voice.

Facility category Crisis Transition Small Standard
Applicability N/A Full Adapted Full

Why this matters

Clinicians and managers see the hospital from inside. A patient sees it from the bed, the waiting room, the car park. Every quality committee that has added a patient representative reports the same thing: they raise issues nobody on the inside had noticed. The representative must be genuine: attending regularly, receiving the same papers, able to put items on the agenda, and listened to. A name on the membership list who is never invited, or who is present but silent because the meeting is in jargon, does not meet the standard.

What good looks like

  • A patient or family representative holds a genuine, structured role in quality review or governance.
  • The representative genuinely participates in discussion, not just attends.
  • A specific, real example exists of their input shaping an actual decision.

Common failure modes

  • No structured patient or family role exists beyond survey and complaint data reaching staff indirectly.
  • A representative attends but does not genuinely participate in discussion.
  • No example exists of patient or family input ever shaping a real decision.

Worked example

In practice
A 140-bed hospital whose quality committee was entirely clinical and management staff.
BeforeNo patient voice in any governance structure. The quality committee discussed patient experience data without any patient present. When asked, the chair said 'we hadn't thought about it' and worried a patient 'wouldn't understand the clinical issues.'
ActionTwo patient representatives were recruited — one from a recent discharge, one from a community group — with a one-hour orientation. They joined the quality committee with full papers and agenda rights. The chair was asked to explain jargon. Their first meeting raised the issue of night-time noise on wards, which nobody had discussed; a noise-reduction action followed.
AfterThe Monitor reviewed minutes of four meetings showing the representatives present and contributing, including two agenda items they raised. Interviewed one representative who described being heard. Verified.

If you are starting from zero — do this first

  1. Look at your quality committee membership. Is there a patient?
  2. Recruit two — a recent patient and a community member.
  3. Give them the same papers and agenda rights as everyone else.
  4. Ask the chair to explain jargon and invite their view on every item.
The most common mistake: Appointing a patient representative and then never sending them the papers or inviting them to speak.

Self-assessment questions

1. Does at least one patient or family representative have a genuine, structured role in quality review or governance discussions? — An actual seat or defined role, not indirect input filtered through staff-collected feedback alone.
Evidence: Governance or quality committee structure showing patient/family role
2. Is this representative genuinely included in discussion, not present only as an observer? — Real participation, not token attendance without a voice in the discussion.
Evidence: N/A — tested directly
3. Can the facility point to a specific instance where patient or family input shaped a real decision? — Concrete evidence of influence, not just presence.
Evidence: Example of patient/family input shaping a decision

Common reasons for a PARTIAL answer

  • A representative role exists but the position has been vacant for some time without being filled. — A defined role that isn't actually occupied provides no real, current voice.
  • The representative attends but discussions move quickly in technical or clinical language that limits genuine participation. — Presence without genuine accessibility to the discussion doesn't provide real influence.
  • Patient input shapes minor operational decisions but rarely reaches larger strategic or safety discussions.

Implementation plan

When What
Week 1 Review current governance and quality review structure for any existing patient or family voice.
Week 2 Recruit or confirm a patient or family representative for a genuine, structured role.
Week 3 Brief the representative and the governance team on genuine participation expectations, not passive attendance.
Ongoing Track and document specific instances where patient or family input has shaped decisions.

How the Monitor verifies this

Method What Detail
DOCUMENT Governance structure review Reviews the governance and quality review structure for a genuine, defined patient or family representative role.
OBSERVE Meeting participation check Where possible, observes or reviews minutes of a governance or quality meeting for genuine representative participation, not passive attendance.
ASK Influence example interview Asks staff and the representative, if available, for a specific example of patient or family input shaping a real decision.

Supervisor tips

  • Ask for a specific, real example of influence, not a description of the role's existence. — A concrete instance reveals whether this is genuine participation or a symbolic seat.
  • Check whether the role is currently filled, not just defined in principle. — A vacant position provides no real, current voice regardless of how it's written into governance structure.

Evidence base

Patient and family engagement in governance and quality structures, distinct from feedback mechanisms alone, is an established element of patient-centred care frameworks in international hospital accreditation and governance literature.

Train your team: H-07 · Governance & Management on GMJ Academy →

This course teaches practical implementation of this standard. Free to enroll. ASF certificate on completion.

© 2026 Accréditation Sans Frontières · PHIG · Sheni Network