EDITIONEN·FR·ქართ

Accréditation Sans Frontières

International Accreditation of Healthcare Facilities

ASF Standards · Ambulatory Clinic · Standard 7

Standard 7 — Governance & Management

10 criteria · 6 non-negotiable · 4 core · Version 3.1

Criteria in this standard

7.1

Leadership Is Real and Accountable

Non-Negotiable

The clinic has clear, named clinical and operational leadership with defined authority over safety and quality — not an informal arrangement functioning without real oversight structure.

In plain terms: The clinic has named clinical and operational leaders with written authority over safety and quality — not just an owner who decides things informally.

Facility category Crisis Transition Small Standard
Applicability Adapted Full Adapted Full

Why this matters

Even a small clinic needs someone accountable for safety who is not only the owner. Clinical leadership decides what care is acceptable; operational leadership makes sure the systems work. When these are one undefined person, or when they are informal, decisions about safety compete with decisions about revenue with no one whose job is to protect the patient. Named leadership with written authority — a clinical lead, a practice manager, defined responsibilities — creates the structure. It need not be elaborate; it needs to exist and be known.

What good looks like

  • A named person holds clear, defined safety and quality authority.
  • This person actively engages with real quality and safety matters.
  • Staff know a specific pathway for raising a safety concern.

Common failure modes

  • No specific person holds this authority; it's informally diffuse.
  • Leadership engagement is limited to administrative matters.
  • Staff are unsure how a safety concern would ever reach leadership.

Worked example

In practice
A 12-room clinic owned by a physician who made all decisions.
BeforeThere was no clinical lead role, no practice manager, no defined responsibilities. Quality issues were raised with the owner if someone thought of it. When a medication error occurred, no one was sure whose job it was to review it. Staff described the structure as 'whoever the doctor tells.'
ActionThe owner designated himself clinical lead and appointed the senior nurse as practice manager, with a one-page terms of reference for each: what they decide, what they review, what they report. A monthly leadership meeting was set with a standing safety item. The medication error was reviewed and an action taken.
AfterThe Monitor reviewed the terms of reference, minutes of four monthly meetings with safety items and actions, and interviewed the practice manager who described her authority. Verified.

If you are starting from zero — do this first

  1. Write down who is responsible for clinical quality and who for operations. If it is the same undefined person, that is the gap.
  2. Give each role a one-page terms of reference.
  3. Set a monthly leadership meeting with safety first on the agenda.
  4. Tell the staff who does what.
The most common mistake: Assuming the owner's involvement is governance — governance is a structure, not a person.

Self-assessment questions

1. Is there a named person with defined authority over clinical safety and quality? — A specific name and defined authority, not an informal arrangement.
Evidence: Leadership structure document
2. Does this person actively review quality and safety matters, not only administrative ones? — Genuine engagement with quality, not administration alone.
Evidence: Quality review record
3. Is there a documented process for raising a safety concern to this leadership? — A specific, known pathway, not an assumption someone would eventually hear about it.
Evidence: Escalation pathway document

Common reasons for a PARTIAL answer

  • A named leader exists but spends most time on clinical duties, with little time for oversight. — A title without real time devoted to the function provides limited real oversight.
  • An escalation pathway exists but has never actually been used or tested. — An untested pathway may not translate smoothly into real use.
  • Leadership reviews quality data but rarely acts visibly on findings.

Implementation plan

When What
Week 1 Confirm and document named leadership and defined authority.
Week 2 Establish a specific, communicated escalation pathway for safety concerns.
Week 3 Build genuine time for quality and safety oversight into leadership's role.
Ongoing Track leadership follow-through on identified issues.
For Micro (solo) Write a single, dated statement naming yourself as the accountable person for safety and quality at this practice, and set a recurring time on your own calendar to actually act on it — this alone satisfies the requirement genuinely.

How the Monitor verifies this

Method What Detail
DOCUMENT Leadership structure review Reviews the named leadership structure and defined authority.
ASK Leadership engagement interview Asks the named leader to describe a recent quality or safety issue they addressed.
OBSERVE Escalation pathway check Checks whether staff know how to raise a safety concern to leadership.

Supervisor tips

  • Ask the named leader for a specific, real example of addressing a safety issue. — A real example reveals genuine engagement versus a title alone.
  • Ask front-line staff how they'd escalate a concern. — Staff-side confirmation reveals whether the pathway genuinely functions.

Evidence base

[35] Jha AK, Epstein AM. Hospital governance and the quality of care. Health Aff (Millwood). 2010;29(1):182-187.

Train your team: AMB-07 · Governance & Management on GMJ Academy →

This course teaches practical implementation of this standard. Free to enroll. ASF certificate on completion.

7.2

Policy Actually Gets Followed

Non-Negotiable

A policy framework exists and staff can describe how it's genuinely applied in practice, not merely confirm that policies are filed and technically available.

In plain terms: Policies exist, and staff can describe how they actually apply them in real situations — not just confirm the binder is on the shelf.

Facility category Crisis Transition Small Standard
Applicability Full Full Full Full

Why this matters

Every clinic has policies. Most sit in binders or on shared drives, written for accreditation, never read. A policy that is not known is not a policy; it is a document. The test is whether a nurse on the treatment area can say what the hand hygiene policy requires of her, or what the medication policy says to do about a verbal order. If she can, the policy is alive. If she has to look it up, or does not know it exists, the clinic's actual practice is whatever each person decides. The standard asks for evidence of application, not existence.

What good looks like

  • Staff describe genuine application of policy in their actual work.
  • A real adherence-checking mechanism exists.
  • Identified gaps trigger a defined, followed response.

Common failure modes

  • Staff confirm policies exist but cannot describe how they apply.
  • No mechanism exists to verify adherence beyond filing.
  • Known gaps persist without any response.

Worked example

In practice
A 10-room clinic with 180 policies on a shared drive.
BeforeThe Coordinator asked ten staff to describe three policies relevant to their role. Two could describe one policy. Most did not know where policies were kept. Several policies contradicted current practice; some referred to departments that no longer existed. The last review date on most was five years earlier.
ActionThe policy set was reduced to 40 essential documents, each two pages or less. Each had a named owner and a review date. Every policy was linked to a training or briefing: the ten most critical (hand hygiene, medication, identification, consent, incident reporting) were covered at induction and annual refresher. A monthly 'policy of the month' briefing was added to treatment area meetings.
AfterThe Monitor asked eight staff to describe two policies relevant to their role; seven could. Reviewed the policy register with owners and dates. Verified.

If you are starting from zero — do this first

  1. Ask five staff to describe one policy they follow daily. Note how many can.
  2. Count your policies. If over 60, most are unread.
  3. Reduce to the essential set, each two pages, each with an owner.
  4. Link every critical policy to a training moment.
The most common mistake: Producing more policies to satisfy an audit when the problem is that existing ones are unknown.

Self-assessment questions

1. Can staff describe how a specific, named policy is actually applied in their daily work? — Not whether they know a policy exists — whether they can describe applying it.
Evidence: N/A — tested directly
2. Is there a mechanism to check policy adherence, not just policy existence? — A genuine audit or spot-check process, distinct from confirming documents are filed.
Evidence: Policy adherence audit record
3. When a policy-practice gap is found, is there a defined response? — Identifying a gap without addressing it provides limited real value.
Evidence: Gap resolution record

Common reasons for a PARTIAL answer

  • Policies are followed for established practices but not consistently for newer ones. — Habit reinforces old adherence; new policies need active reinforcement.
  • An adherence check exists but only samples an easily-prepared subset. — A narrow or predictable scope can miss where real gaps live.
  • Gaps are identified but corrective action isn't tracked to completion.

Implementation plan

When What
Week 1 Select key policies and ask a sample of staff to describe actual application.
Week 2 Establish a genuine adherence-checking mechanism.
Week 3 Build a tracked resolution process for identified gaps.
Ongoing Rotate which policies get checked.

How the Monitor verifies this

Method What Detail
ASK Staff application interview Asks staff to describe how they actually apply a specific named policy.
DOCUMENT Adherence audit review Checks for evidence of a process verifying policy adherence.
OBSERVE Practice-policy comparison Observes an area and compares actual behaviour against stated policy.

Supervisor tips

  • Ask about application, not existence. — These surface very different answers.
  • Pick a policy area to observe directly, not just review on paper. — Direct observation reveals gaps document review cannot.

Evidence base

[36] Policy-practice gaps are consistently identified in healthcare quality literature as a distinct failure mode from policy absence.

Train your team: AMB-07 · Governance & Management on GMJ Academy →

This course teaches practical implementation of this standard. Free to enroll. ASF certificate on completion.

7.3

Patient Information Stays Private

Non-Negotiable

Confidentiality is protected physically and culturally throughout the clinic, not only referenced in a written policy that doesn't translate into actual practice.

In plain terms: Patient information is kept private in practice — no charts left open, no conversations in corridors, no screens visible to visitors — not just in a policy.

Facility category Crisis Transition Small Standard
Applicability Full Full Full Full

Why this matters

Confidentiality is broken by habit, not malice: the chart on the trolley in the corridor, the diagnosis discussed at the nurses' station within earshot of the waiting room, the computer screen facing the door, the whiteboard listing every patient's condition. Each one is a small betrayal that patients notice and remember. In some contexts — HIV, mental illness, pregnancy — a breach can end a marriage, a job, or a life. The policy is the easy part. The hard part is the culture: a clinic where staff automatically lower their voices and close the chart because that is simply what one does.

What good looks like

  • Screens are consistently positioned away from public view.
  • Clinical conversations happen in genuinely private spaces.
  • Staff describe habitual privacy practices without prompting.

Common failure modes

  • Screens face waiting areas, visible to anyone passing.
  • Conversations are regularly audible to other patients.
  • Staff can cite policy but describe no specific habits.

Worked example

In practice
A 8-room clinic with a written confidentiality policy.
BeforeThe Coordinator walked the treatment areas: charts open on trolleys in public corridors; a whiteboard at the nurses' station listing patient names and diagnoses visible from the lift; a doctor discussing a patient's HIV result with a colleague in the waiting area. Computer screens at reception faced the queue. Staff had signed the policy at induction.
ActionWhiteboards were moved behind the station or replaced with initials only. Chart trolleys were fitted with covers. Computer screens were turned and fitted with privacy filters. A 'quiet room' was designated on each treatment area for sensitive conversations. A 10-minute confidentiality-in-practice briefing with real examples was added to treatment area meetings. Monthly walk-rounds by the treatment area manager checked for breaches.
AfterThe Monitor walked three treatment areas: no open charts, no visible diagnoses, screens shielded. Observed a doctor take a family into the quiet room for a difficult conversation. Verified.

If you are starting from zero — do this first

  1. Walk through your clinic as a visitor. What patient information can you see or hear?
  2. Turn every screen away from public view.
  3. Remove diagnoses from any board visible to visitors.
  4. Designate a room on each treatment area for private conversations.
The most common mistake: Having every staff member sign a confidentiality policy while the whiteboard in the corridor lists every patient's diagnosis.

Self-assessment questions

1. Are screens and monitors positioned so patient information isn't visible to others? — Physical positioning, checked directly.
Evidence: Photo audit of screen positioning
2. Are clinical conversations conducted where they can't be overheard? — Doors or private spaces genuinely used, not just available.
Evidence: N/A — tested directly
3. Do staff apply confidentiality practices consistently, not only when reminded? — Habitual, not situational.
Evidence: N/A — tested directly

Common reasons for a PARTIAL answer

  • Physical privacy is good in exam rooms but overlooked at the reception counter. — Privacy protection is often strongest where it was deliberately designed.
  • Staff are conscientious when reminded but inconsistent otherwise. — Habitual practice is more reliable than reminded practice.
  • A private space exists but isn't consistently used under time pressure.

Implementation plan

When What
Week 1 Audit screen positioning and conversation privacy across all patient-facing areas.
Week 2 Reposition screens and reinforce private space use where gaps are found.
Week 3 Brief staff on habitual, not just reminded, confidentiality practice.
Ongoing Spot-check physical privacy periodically.

How the Monitor verifies this

Method What Detail
OBSERVE Physical privacy check Walks through patient-facing areas checking screen positioning and conversation privacy.
OBSERVE Conversation audibility check Checks whether conversations can be overheard from adjacent areas.
ASK Staff practice interview Asks staff to describe specific privacy practices.

Supervisor tips

  • Walk the space as a visitor would. — A familiar routine can make an obvious privacy gap invisible to staff.
  • Ask staff for specific examples of their own privacy practices. — Specific habits reveal genuine internalisation better than reciting policy.

Evidence base

[37] Patient confidentiality protection frameworks consistently identify physical environment design and staff behaviour, not policy documentation alone, as the practical determinants of actual privacy protection.

Train your team: AMB-07 · Governance & Management on GMJ Academy →

This course teaches practical implementation of this standard. Free to enroll. ASF certificate on completion.

7.4

Medical Records Are Complete and Secure

Non-Negotiable

Records contain all mandatory elements, are regularly audited for completeness, and are protected by access controls and a genuine breach response plan.

In plain terms: Medical records are complete (audited regularly), and protected by access controls and a breach plan.

Facility category Crisis Transition Small Standard
Applicability Adapted Full Full Full

Why this matters

This combines two hospital criteria (7.5 and 7.6) for the clinic setting. Records must contain the mandatory elements — identification, history, examination, diagnosis, plan, consent where relevant — and a monthly audit of a sample is the only way to know they do. Records must also be secure: individual logins, locked paper storage, and a one-page plan for what to do when a breach happens. A clinic with a shared computer login and an unlocked filing cabinet has neither.

What good looks like

  • Regular, genuine completeness audits are conducted.
  • Access controls are genuinely role-based.
  • A specific, actionable breach response plan exists.

Common failure modes

  • No audit process exists, or completeness is assumed.
  • Data access is broadly available regardless of role.
  • No breach response plan exists beyond vague concern.

Worked example

In practice
A 10-room clinic with an electronic record system and a paper archive.
BeforeAll staff used one login. The paper archive was in an unlocked cupboard in a corridor. No one audited records. The Coordinator pulled 20 records: 8 lacked a documented plan; 5 lacked examination findings; 3 had no allergy status. There was no breach plan.
ActionIndividual logins were created with role-based access. The archive was moved to a locked room with a key register. A monthly audit of 15 records against a 10-item checklist was started, with results shared with clinicians. A one-page breach plan was written. Two staff completed a data protection briefing.
AfterThe Monitor reviewed four months of audits (completeness up from 62% to 90%), the access list, the key register, and the breach plan. Verified.

If you are starting from zero — do this first

  1. Count shared logins. Any above zero is a gap.
  2. Lock the paper records and start a key register.
  3. Pull 15 records and check 10 mandatory items.
  4. Write a one-page breach plan.
The most common mistake: Trusting the electronic template to make records complete while everyone logs in as 'admin.'

Self-assessment questions

1. Is there a defined list of mandatory record elements, audited regularly? — A specific, checkable list and genuine audit, not assumed completeness.
Evidence: Mandatory elements list and audit record
2. Are access controls in place restricting data access to staff who need it for their role? — Role-based restriction, not general access available to anyone.
Evidence: Access control policy and implementation
3. Is there a documented, specific breach response plan? — A named process, not a general statement of concern.
Evidence: Breach response plan document

Common reasons for a PARTIAL answer

  • Audits happen but only sample a small, unrepresentative set of records. — A narrow sample can miss where real gaps concentrate.
  • Access controls exist for electronic records but not physical files. — Security attention often concentrates on digital systems.
  • A breach plan exists but has never been reviewed since written.

Implementation plan

When What
Week 1 Review the mandatory elements list and recent audit practice.
Week 2 Establish a genuine, regular completeness audit.
Week 3 Review access controls against actual staff roles.
Ongoing Review the breach response plan periodically.

How the Monitor verifies this

Method What Detail
DOCUMENT Completeness audit review Reviews audit records for genuine, regular practice.
DOCUMENT Access control review Reviews access control policy against actual staff access levels.
DOCUMENT Breach response plan check Reviews the plan for specificity and actionable steps.

Supervisor tips

  • Ask for actual audit records, not a description of intended process. — Dated findings are the only real evidence.
  • Check physical record access, not only electronic systems. — Security attention often skews toward digital systems while physical files remain loosely controlled.

Evidence base

[38] Health information security frameworks consistently identify access control and incident response planning, rather than technology sophistication alone, as the primary determinants of practical data protection in resource-constrained settings.

Train your team: AMB-07 · Governance & Management on GMJ Academy →

This course teaches practical implementation of this standard. Free to enroll. ASF certificate on completion.

7.5

Incidents Are Actually Reported

Non-Negotiable

An accessible incident reporting system exists and staff genuinely use it — measured by real reporting volume and pattern, not merely by the system's technical availability.

In plain terms: Staff actually report incidents — near-misses as well as harm — and the clinic can show it from the number and pattern of reports, not just the existence of a form.

Facility category Crisis Transition Small Standard
Applicability Full Full Full Full

Why this matters

A clinic that reports few incidents is not a safe clinic; it is a clinic where staff have stopped reporting. Incident reports are the raw material of learning: the near-miss today is the death next month if the cause is not found. Staff stop reporting when reports go nowhere, when they are blamed, when the form takes 20 minutes, or when nothing ever changes. The measure of a working system is volume and pattern: reports rising as trust builds, near-misses outnumbering harm events, every treatment area reporting. A form on the intranet with three reports a month is not a system.

What good looks like

  • Reporting volume reflects genuine, ongoing use.
  • Staff describe genuine confidence in reporting without punitive consequence.
  • The system is accessible at the point of work.

Common failure modes

  • Reporting volume is minimal or has dropped sharply with no explanation.
  • Staff describe fear of blame as a reason they hesitate to report.
  • The system is difficult to access in practice.

Worked example

In practice
A 14-room clinic with an incident form that generated 40 reports a year.
BeforeThe form was four pages and required the reporter's name and manager's signature. Reports went to the medical director and stayed there. Staff described a colleague who had reported a medication error and been disciplined. Ward nurses estimated they saw 'several' near-misses a week; none were reported.
ActionThe form was reduced to one page with an anonymous option. A no-blame policy was written and signed by the Director. Reports went to a quality officer who acknowledged each within 48 hours, with the reporter told what was done. Monthly treatment area feedback showed what was learned. Near-miss reporting was actively encouraged with a 'good catch' recognition.
AfterThe Monitor reviewed the log: 340 reports in the year, 60% near-misses, every treatment area reporting, average acknowledgement time 1.5 days. Interviewed three nurses who had reported and received feedback. Verified.

If you are starting from zero — do this first

  1. Count last year's incident reports. Divide by beds. Under 2 per bed per year means under-reporting.
  2. Ask five nurses when they last saw a near-miss and whether they reported it.
  3. Cut the form to one page and allow anonymous reports.
  4. Acknowledge every report within 48 hours and tell the reporter what happened.
The most common mistake: Interpreting a low incident count as a safe clinic — it is almost always a silent one.

Self-assessment questions

1. Is the incident reporting system genuinely accessible to all staff? — Accessible at the point of work, not buried in an administrative system.
Evidence: Reporting system access description
2. Does actual reporting volume suggest genuine use? — A system receiving almost no reports over time suggests a use problem, not perfect safety.
Evidence: Reporting volume data over time
3. Do staff believe they can report without fear of punitive consequence? — Genuine psychological safety, not just a stated non-punitive policy.
Evidence: N/A — tested directly

Common reasons for a PARTIAL answer

  • Reporting happens for minor incidents but staff hesitate to report their own errors. — Psychological safety often varies by perceived personal exposure.
  • Senior staff report reliably; junior staff report far less. — Hierarchy can create very different real experiences within the same clinic.
  • A non-punitive policy exists but staff recall a past incident where reporting led to consequences.

Implementation plan

When What
Week 1 Review reporting volume trends for concerning patterns.
Week 2 Interview a cross-section of staff, including junior staff, about reporting confidence.
Week 3 Address any specific past incident undermining psychological safety.
Ongoing Track reporting volume, investigating any significant drop.

How the Monitor verifies this

Method What Detail
DOCUMENT Reporting volume review Reviews reporting volume and pattern over time for genuine use.
ASK Psychological safety interview Asks staff directly whether they feel safe reporting an incident, including one they caused.
OBSERVE System accessibility check Checks how accessible the reporting mechanism is at the actual point of work.

Supervisor tips

  • Ask junior staff specifically, not only senior staff. — Hierarchy can create very different real experiences.
  • Ask about reporting one's own error specifically. — Self-reporting confidence is usually the harder, more revealing test.

Evidence base

[39] Incident reporting culture, specifically the psychological safety staff feel around reporting without fear of punitive consequence, is consistently identified as the primary determinant of reporting volume, more so than system accessibility alone.

Train your team: AMB-07 · Governance & Management on GMJ Academy →

This course teaches practical implementation of this standard. Free to enroll. ASF certificate on completion.

7.6

Staff Scope of Practice Is Verified

Core

Every clinical staff member's actual duties are matched to their verified scope of practice and licence category, not assumed appropriate because they've been performing the role for some time.

In plain terms: Every clinical staff member's actual duties match what their licence allows — checked, not assumed because they have been doing it for years.

Facility category Crisis Transition Small Standard
Applicability Adapted Full Full Full

Why this matters

The nurse who has been prescribing 'under the doctor's authority' for a decade, the health assistant who does injections, the receptionist who triages — each may be working outside their legal scope of practice, exposing the patient to unqualified care and the clinic to liability. Scope creep is gradual and invisible; nobody decided it, it just happened. The standard asks for a deliberate check: for each clinical role, what does the licence permit, what does the person actually do, and do they match? Where they do not, either the duty changes or the qualification is obtained.

What good looks like

  • Duties are specifically matched against verified scope for every staff member.
  • This comparison is repeated periodically, not only at hiring.
  • A defined correction process exists and is used when a mismatch is found.

Common failure modes

  • No specific comparison exists beyond assumed appropriateness.
  • Comparison happens only once, at hiring.
  • No process exists to correct an identified mismatch.

Worked example

In practice
A 14-room clinic with two doctors, four nurses, two health assistants, and three receptionists.
BeforeA health assistant with no clinical qualification was giving vaccinations and taking blood. A nurse was issuing repeat prescriptions in the doctor's name. Receptionists were deciding which patients were 'urgent.' None of this had been decided; it had accumulated. Nobody had compared duties to licences.
ActionThe practice manager listed every clinical task and who performed it, then checked each against the national scope of practice for that role. Three mismatches were found. The health assistant was moved off clinical tasks pending training; the nurse's prescribing was stopped and a proper delegated-prescribing arrangement set up; a triage protocol with nurse oversight replaced receptionist judgment. The review was scheduled annually.
AfterThe Monitor reviewed the task-to-scope matrix, the corrected assignments, and the annual review date. Interviewed the health assistant who confirmed her current duties. Verified.

If you are starting from zero — do this first

  1. List every clinical task done in the clinic and who does it.
  2. For each role, find the national scope of practice.
  3. Compare. Note every mismatch.
  4. Fix each: change the duty or obtain the qualification.
The most common mistake: Assuming that because someone has always done a task, they are permitted to.

Self-assessment questions

1. Is each staff member's actual duties matched against their verified licence category and scope? — A specific comparison, not an assumption that current duties are appropriate.
Evidence: Scope of practice review record
2. Is this comparison repeated periodically, not only done once at hiring? — Duties can expand gradually over time without a formal decision ever being made.
Evidence: Periodic review schedule
3. Is there a defined process if a mismatch is found? — Identifying a mismatch without correcting it provides no real protection.
Evidence: Correction process record

Common reasons for a PARTIAL answer

  • Comparison happens for physicians but less consistently for support clinical staff. — Attention often concentrates on the most visible role.
  • A mismatch was identified once but never actually corrected. — Identification without correction leaves the underlying risk in place.
  • Duties have gradually expanded informally without anyone reviewing scope.

Implementation plan

When What
Week 1 Review current duties against verified scope for all clinical staff.
Week 2 Correct any mismatch found.
Week 3 Establish a periodic review schedule.
Ongoing Repeat scope reviews on the defined schedule.

How the Monitor verifies this

Method What Detail
DOCUMENT Scope comparison review Reviews evidence that actual duties are compared against verified scope.
DOCUMENT Periodic review schedule check Checks whether this comparison is repeated periodically.
ASK Correction process interview Asks what happens if a mismatch between duties and scope is found.

Supervisor tips

  • Ask a staff member to describe their actual daily duties in detail. — A detailed description can reveal drift a job title alone wouldn't show.
  • Check non-physician clinical staff specifically. — Scope drift often goes unnoticed longest in less closely supervised roles.

Evidence base

[40] Scope-of-practice verification, distinct from initial credential checking, is an established governance requirement in healthcare workforce quality frameworks internationally.

Train your team: AMB-07 · Governance & Management on GMJ Academy →

This course teaches practical implementation of this standard. Free to enroll. ASF certificate on completion.

7.7

Leadership Reviews Overall Performance at Planned Intervals

Non-Negotiable

Clinic leadership formally reviews overall quality and safety performance at a defined, regular interval — not only in reaction to an individual incident — covering trends, not single events.

In plain terms: Leadership sits down at a set interval — quarterly at least — to look at quality and safety trends across the whole clinic, not just the last incident.

Facility category Crisis Transition Small Standard
Applicability Adapted Full Adapted Full

Why this matters

Reacting to incidents is necessary but insufficient. A clinic that only reviews quality when something goes wrong never sees the pattern: the referrals that are slowly taking longer, the complaints that cluster around one clinician, the infection rate that has crept up. A planned review — quarterly, with data — looks at trends: incidents, complaints, referral times, audit results, patient feedback, staff turnover. It asks: what is changing, and what should we do about it? This is the difference between managing a clinic and firefighting in one.

What good looks like

  • Reviews happen at a genuine, defined, regular interval.
  • Reviews cover trends and patterns across time.
  • Reviews lead to documented decisions or actions.

Common failure modes

  • No planned review exists beyond reacting to individual incidents.
  • Reviews, if they happen, only list individual events without trend analysis.
  • Reviews produce discussion but no documented follow-through.

Worked example

In practice
A 12-room clinic where quality was discussed only when a problem arose.
BeforeNo scheduled review existed. Incidents were discussed when they happened. Complaints, audit results, and referral data were not collected in any form that could be reviewed. The clinical lead could not say whether the clinic was getting safer or less safe.
ActionA quarterly quality review was scheduled: a one-page dashboard of incidents, complaints, referral confirmation rate, record audit score, patient feedback score, and staff turnover. Each item has a trend arrow. The review produces two or three actions with owners. Minutes are kept.
AfterThe Monitor reviewed three quarterly dashboards and minutes with actions closed. The dashboard showed complaints trending down and referral confirmation trending up. Verified.

If you are starting from zero — do this first

  1. Pick six numbers that describe your clinic's quality: incidents, complaints, referral confirmations, audit score, feedback score, turnover.
  2. Put them on one page with last quarter's figure beside this quarter's.
  3. Schedule a quarterly meeting to review it.
  4. Produce two actions from each meeting.
The most common mistake: Reviewing individual incidents thoroughly while never looking at the trend across all of them.

Self-assessment questions

1. Does leadership review overall quality and safety performance at a defined, regular interval? — A specific, planned interval, not only when something goes wrong.
Evidence: Management review schedule and minutes
2. Does the review cover trends and patterns, not only a list of individual incidents? — Trend analysis reveals patterns a single-incident view misses entirely.
Evidence: Trend analysis documentation
3. Does the review lead to documented decisions or actions, not just discussion? — Review without resulting action provides limited real value.
Evidence: Review outcome and action record

Common reasons for a PARTIAL answer

  • A review happens but only when leadership happens to have time, not on a fixed schedule. — An irregular pattern risks the review being deprioritised indefinitely during busy periods.
  • Trends are informally noticed but never formally analysed or documented. — Undocumented pattern recognition is hard to distinguish from coincidence.
  • Decisions are made during review but not tracked to completion afterward.

Implementation plan

When What
Week 1 Establish a specific, regular interval for a genuine performance review.
Week 2 Build a simple trend-analysis method covering incidents, complaints, and quality data together.
Week 3 Define how review decisions will be tracked to completion.
Ongoing Hold the review on schedule and track action completion.
For Micro (solo) Block a specific, recurring date on your own calendar — quarterly is reasonable — and use that time to read back through the last quarter's incidents, complaints, and near-misses as a reviewer would, not as you experienced them in the moment.

How the Monitor verifies this

Method What Detail
DOCUMENT Review schedule and minutes review Reviews evidence of a genuine, planned-interval management review, not only reactive incident discussion.
DOCUMENT Trend coverage check Checks whether reviews cover trends and patterns, not only individual events.
ASK Outcome interview Asks leadership for a specific example of a decision or action resulting from a review.

Supervisor tips

  • Ask for the actual review schedule and minutes, not a description of intended practice. — Dated records are the only real evidence of a consistent, planned process.
  • Ask for a specific example of a decision that came from a review, not an incident. — This distinguishes genuine systematic review from incident-reactive management alone.

Evidence base

[41] International Organization for Standardization. ISO 9001:2015 — Quality management systems — Requirements. 5th ed. Geneva: ISO; 2015 — Clause 9.3 requires management review of the quality management system's performance at planned intervals, distinct from reactive incident response.

Train your team: AMB-07 · Governance & Management on GMJ Academy →

This course teaches practical implementation of this standard. Free to enroll. ASF certificate on completion.

7.8

Quality Objectives Are Set, Specific, and Tracked

Core

The clinic sets specific, measurable quality objectives for the coming period, and tracks progress against them — not a general aspiration to "provide good care" with no way to know if it's actually happening.

In plain terms: The clinic has written, measurable quality goals for the year — 'reduce missed referrals to under 5%' — and tracks whether it is hitting them.

Facility category Crisis Transition Small Standard
Applicability Adapted Full Adapted Full

Why this matters

'Provide excellent care' is an aspiration. 'Reduce time-to-result-communication to under 48 hours by December' is an objective. The difference is that the second can be measured, and therefore managed. Quality objectives force the clinic to decide what matters most this year, put a number on it, and check progress. Three to five objectives are enough; more dilutes attention. Each needs a baseline, a target, a date, and an owner. At year end, the clinic knows what it achieved — and what it did not.

What good looks like

  • Objectives are specific and genuinely measurable.
  • Progress is actively tracked, not assumed.
  • Relevant staff know the current objectives.

Common failure modes

  • Objectives, if stated, are general aspirations with no measurable target.
  • No tracking exists beyond a general sense of how things are going.
  • Staff are unaware any specific objectives exist.

Worked example

In practice
A 14-room clinic with a mission statement and no objectives.
BeforeThe clinic's stated goal was 'quality patient-centred care.' Nobody could say what that meant in numbers. When asked what had improved in the last year, the answer was 'we're always improving.' No baseline data existed for anything.
ActionAt the quarterly review (7.7), the leadership set three objectives for the year: referral confirmation rate from 65% to 90%; abnormal result communication within 24 hours from unknown to 95%; hand hygiene compliance from 40% to 75%. Each had an owner and a monthly measure. Progress went on the dashboard.
AfterThe Monitor reviewed the objectives, baselines, monthly tracking, and the year-end review: two of three achieved, the third at 68% with a revised plan. Verified.

If you are starting from zero — do this first

  1. Write down three things you would most like to improve this year.
  2. For each, measure where you are now — that is the baseline.
  3. Set a target number and a date.
  4. Assign an owner and check monthly.
The most common mistake: Setting objectives without baselines — you cannot know you improved if you don't know where you started.

Self-assessment questions

1. Are there specific, measurable quality objectives set for the coming period? — A specific, numeric or otherwise measurable target, not a general aspiration.
Evidence: Quality objectives document
2. Is progress against these objectives actually tracked? — Tracked progress, not an assumption things are improving.
Evidence: Progress tracking record
3. Are objectives communicated to relevant staff, not held only by leadership? — Staff who don't know the objective can't meaningfully contribute to it.
Evidence: N/A — tested directly

Common reasons for a PARTIAL answer

  • Objectives are set but not revisited until the following year. — Infrequent revisiting limits the ability to course-correct during the period.
  • Objectives are measurable but tracking happens informally without documentation. — Undocumented tracking is hard to distinguish from not tracking at all.
  • Leadership knows the objectives but they were never communicated to front-line staff.

Implementation plan

When What
Week 1 Review current quality objectives, if any, for genuine specificity and measurability.
Week 2 Set or refine specific, measurable objectives for the coming period.
Week 3 Communicate objectives to relevant staff and establish a tracking method.
Ongoing Track progress and revisit objectives at defined intervals.
For Micro (solo) Write one or two specific, measurable objectives for the coming period, even though you're the only person who will track them — for example, a specific target for test-result turnaround time or patient complaint response time.

How the Monitor verifies this

Method What Detail
DOCUMENT Objectives specificity review Reviews whether objectives are genuinely specific and measurable, not general aspirations.
DOCUMENT Progress tracking review Reviews evidence of actual tracked progress against objectives.
ASK Staff awareness interview Asks relevant staff whether they know the clinic's current quality objectives.

Supervisor tips

  • Ask for the actual objectives, with numbers or specific targets, not a general statement. — Specificity is what distinguishes a real objective from an aspiration.
  • Ask a front-line staff member if they know the current objective. — This reveals whether objectives genuinely reach beyond leadership.

Evidence base

[42] International Organization for Standardization. ISO 9001:2015 — Quality management systems — Requirements. 5th ed. Geneva: ISO; 2015 — Clause 6.2 requires quality objectives that are measurable, monitored, and communicated, distinct from general quality aspirations.

Train your team: AMB-07 · Governance & Management on GMJ Academy →

This course teaches practical implementation of this standard. Free to enroll. ASF certificate on completion.

7.9

A Continual Improvement Process Exists, Not Only Reaction to Individual Incidents

Core

The clinic has a defined process for identifying and acting on improvement opportunities generally, separate from and in addition to responding to specific incidents as they occur.

In plain terms: The clinic looks for ways to improve on its own initiative — audits, patient feedback, staff ideas — not only in response to something going wrong.

Facility category Crisis Transition Small Standard
Applicability N/A Full Adapted Full

Why this matters

Incident response fixes what broke. Continual improvement finds what could be better before it breaks. The mechanisms are simple: a regular audit cycle (records, hand hygiene, prescribing), a patient feedback loop, a way for staff to suggest changes, and a routine of picking one thing to improve each quarter. The clinic that does this gets better steadily; the clinic that only responds to incidents stays the same between incidents. The standard asks for evidence of a process — not just good intentions — and of at least one improvement that did not originate from an incident.

What good looks like

  • A defined, proactive improvement process exists, distinct from incident response.
  • A real, recent example of proactive improvement can be shown.
  • Staff know a specific channel for suggesting improvements.

Common failure modes

  • No improvement happens outside of reacting to specific incidents.
  • No recent example of proactive improvement exists.
  • Staff have no known way to suggest an improvement idea.

Worked example

In practice
A 12-room clinic that responded well to incidents but had no improvement programme.
BeforeEvery improvement in the clinic's history had followed an incident or a complaint. No audits were done proactively. Staff suggestions were made verbally and forgotten. The clinic was not getting worse — but it was not getting better either.
ActionA simple improvement cycle was set up: an annual audit calendar (one topic per month); a staff suggestion form reviewed at team meetings; one improvement project per quarter chosen from audit findings, feedback, or suggestions — with a before and after measure. The first project, from a staff suggestion, reorganised the treatment room and cut preparation time per procedure by 30%.
AfterThe Monitor reviewed the audit calendar, four completed audits, the suggestion log, and two completed improvement projects with before/after data. Verified.

If you are starting from zero — do this first

  1. Write an audit calendar: twelve topics, one per month.
  2. Put a suggestion form where staff can reach it and review it at team meetings.
  3. Pick one improvement project this quarter — measure before and after.
  4. Track it on your dashboard.
The most common mistake: Confusing good incident response with continual improvement — the first is reactive; the second finds what the incidents haven't revealed yet.

Self-assessment questions

1. Is there a defined process for identifying improvement opportunities, separate from incident response? — A proactive process, not only reaction to something having gone wrong.
Evidence: Continual improvement process document
2. Have any improvements been made through this process recently, not only through incident-driven correction? — A real, recent example distinguishes genuine practice from a policy on paper.
Evidence: Recent improvement example
3. Are staff able to suggest improvement ideas through a known channel? — Front-line staff often see improvement opportunities leadership doesn't.
Evidence: Staff suggestion channel

Common reasons for a PARTIAL answer

  • A suggestion channel exists but has never actually been used. — An unused channel may not be genuinely known or trusted by staff.
  • Improvement happens but is driven entirely by leadership, without staff input. — Front-line perspective often surfaces different opportunities than leadership sees.
  • A process exists on paper but the clinic cannot point to a real recent example.

Implementation plan

When What
Week 1 Review current practice for any proactive, non-incident-driven improvement activity.
Week 2 Establish a specific staff suggestion channel if none exists.
Week 3 Define a process for evaluating and acting on improvement suggestions.
Ongoing Track and document real examples of proactive improvement.
For Micro (solo) Use patient feedback specifically as your improvement input channel — actively ask a few patients each month what could have gone better, and keep a simple, dated log of ideas this surfaces and what you actually changed as a result.

How the Monitor verifies this

Method What Detail
DOCUMENT Improvement process review Reviews the defined process for identifying improvement opportunities separate from incidents.
DOCUMENT Recent example review Reviews for a real, recent example of proactive, non-incident-driven improvement.
ASK Staff suggestion channel interview Asks staff whether they know how to suggest an improvement idea.

Supervisor tips

  • Ask for a real, recent example that wasn't triggered by an incident. — This is the clearest test of whether improvement is genuinely proactive.
  • Ask a front-line staff member how they'd suggest an improvement idea. — A confident, specific answer reveals whether the channel is genuinely known.

Evidence base

[43] International Organization for Standardization. ISO 9001:2015 — Quality management systems — Requirements. 5th ed. Geneva: ISO; 2015 — Clause 10.3 requires continual improvement of the quality management system's suitability, adequacy, and effectiveness, as a distinct requirement from corrective action on nonconformities.

Train your team: AMB-07 · Governance & Management on GMJ Academy →

This course teaches practical implementation of this standard. Free to enroll. ASF certificate on completion.

7.10

Patient Feedback Has an Independent Channel, Not Just an Internal One

Core

Patients and families have a genuine, independent channel to raise concerns, praise, and ideas — one that reaches a body outside the clinic’s own management, not only an internal suggestion box or feedback form the clinic itself reviews and answers.

In plain terms: Patients can tell someone who isn’t the clinic itself when something’s wrong, or right — not just fill in a form the clinic reads and files away.

Facility category Crisis Transition Small Standard
Applicability Adapted Full Adapted Full

Why this matters

A patient who’s unhappy with a clinic they still depend on for care rarely says so honestly on the clinic’s own form. The polite answer goes in the box; the real story goes to a review site or social media instead, later and angrier, after the clinic has lost the chance to fix it quietly. An independent channel, reaching a body with no stake in the outcome, is structurally more likely to surface a real problem while it’s still small. ASF’s Patient Voice service provides exactly this: a QR code, a neutral intermediary, and, for clinics that want it, a real patient council that meets regularly and reviews what patients are actually saying.

What good looks like

  • An independent channel exists, genuinely reaching a body outside the clinic’s own management.
  • Concerns raised through it are genuinely acknowledged and answered, not left unaddressed.
  • Patterns in what patients raise genuinely inform real changes at the clinic.

Common failure modes

  • The only feedback channel is an internal form the clinic itself reviews and answers.
  • An independent channel exists on paper but nothing reaches the clinic from it in practice.
  • Feedback is collected but never closes the loop with the person who raised it.

Worked example

In practice
A 13-staff ambulatory clinic whose only feedback mechanism was a paper suggestion box at reception.
BeforeThe suggestion box was checked irregularly. Patients who raised a real concern rarely heard back. A long wait-time pattern on Tuesdays went unreported for months because no one wanted to complain to the receptionist who’d see the complaint.
ActionA QR code was placed at reception and in each exam room, linking to ASF’s Patient Voice channel. Feedback now goes directly to ASF, not through the clinic first. ASF acknowledges within two working days and closes every case in writing.
AfterIn the first quarter, five patients used the channel; two flagged the same Tuesday wait-time issue, and the clinic adjusted scheduling within the month — instead of the pattern going unreported indefinitely. The Monitor reviewed the case log. Verified.

If you are starting from zero — do this first

  1. Read the Patient Voice page to see the full mechanism.
  2. Place the QR code at reception and in every exam room.
  3. Tell staff the channel exists and that it doesn’t come back through them first.
  4. Check in three months whether anything has actually come through it.
The most common mistake: Treating an internal suggestion box the staff themselves check as equivalent to an independent channel.

Self-assessment questions

1. Do patients have a channel that reaches a body genuinely independent of the clinic’s own management? — A real external channel, not an internal form the clinic reviews itself.
Evidence: Feedback channel documentation
2. Are concerns raised through it genuinely acknowledged and answered, not left to sit? — Real, timely responses, not silence after submission.
Evidence: Case log or response record
3. Do patterns in what patients raise genuinely inform real changes at the clinic? — Evidence of at least one real change traceable to patient feedback.
Evidence: N/A — tested directly

Common reasons for a PARTIAL answer

  • A feedback channel exists but patients aren’t told it’s independent of the clinic. — If patients don’t know it reaches someone other than the clinic, it won’t be used honestly.
  • Feedback is collected but responses are inconsistent or slow. — A channel that doesn’t close the loop trains patients to stop using it.
  • The channel is new and hasn’t yet generated evidence of a real change resulting from it.

Implementation plan

When What
Week 1 Set up the Patient Voice QR code and review how it works.
Week 2 Place it at reception and in every exam room.
Week 3 Tell staff it exists and that it bypasses them by design.
Ongoing Review what comes through it and confirm at least one real change traceable to it each year.

How the Monitor verifies this

Method What Detail
DOCUMENT Channel review Confirms an independent channel exists and is visibly accessible to patients.
DOCUMENT Response record review Reviews whether concerns raised are genuinely acknowledged and answered.
INTERVIEW Patient awareness check Asks patients directly whether they know the channel exists and that it’s independent.

Supervisor tips

  • Ask a patient, not staff, whether they know how to reach someone outside the clinic with a concern. — This reveals whether the channel is genuinely known, not just technically present.
  • Ask to see one real case that came through the channel and what changed because of it. — A specific, real example reveals genuine use, not a channel that exists only on paper.

Evidence base

Independent, external feedback channels are structurally more likely to surface an honest concern than a channel reviewed by the same organisation being reported on — the same reasoning that underlies independent ombuds and patient-advocacy practice in healthcare systems worldwide.

ASF training courses on GMJ Academy →

Foundation courses A-00 to A-03 are live. Criterion-specific modules are being developed and will link here when published.

© 2026 Accréditation Sans Frontières · PHIG · Sheni Network