CareLedgerPro — Full Governance Framework
Version 1.2 — Last reviewed: June 2026
CareLedgerPro operates a lightweight information-governance framework proportionate to a small UK software provider serving the care sector. This page describes how we manage our own governance responsibilities as a processor. It does not describe your governance framework, which remains your responsibility as Controller. CareLedgerPro acts as a data processor; the registered provider remains the data controller and is responsible for lawful basis, staff training, safeguarding escalation, ICO registration and internal policies.
1. Governance Principles
CareLedgerPro is built around five core governance principles:
- Transparency — clear, auditable financial records.
- Accountability — every action linked to a responsible user.
- Security — encryption, access control and breach‑response workflows.
- Compliance — alignment with CQC, GDPR, DPA 2018 and MCA 2005.
- Operational Safety — enforced workflows that reduce risk.
2. Financial Governance
CareLedgerPro enforces safe, transparent and auditable financial management.
- Two‑person verification above configurable thresholds.
- Mandatory receipts for higher‑risk transactions.
- Append-only audit logs with recorded corrections; void‑with‑reason enforcement.
- Per‑client and per‑unit balances with full histories.
- Weekly reconciliation sign‑off with timestamped managerial approval.
- Exportable audit logs for safeguarding investigations.
- Spending‑plan enforcement with warn‑with‑reason prompts.
3. Data‑Protection Governance
CareLedgerPro supports GDPR and DPA 2018 compliance through secure data‑handling practices.
- Encryption in transit (TLS) and at rest.
- Role‑based access with per‑unit scoping.
- Audit logging of all access and changes.
- Password breach‑checking via Have I Been Pwned.
- Documented retention and deletion schedules.
- Essential‑only cookies; no advertising or tracking.
- Clear controller/processor separation.
- DPO contact details published for rights requests.
4. Safeguarding Governance
CareLedgerPro provides financial‑safeguarding controls aligned with CQC expectations.
- Discrepancy alerts for petty cash and client balances.
- Append-only histories for all financial activity.
- Exportable safeguarding evidence for investigations.
- Incident logging with full audit trails.
- Daily email alerts for suspicious spending or missing receipts.
5. Mental Capacity Act Governance
CareLedgerPro supports best‑interests decision‑making under the MCA 2005.
- Per‑client capacity flags.
- Automatic sign‑on‑behalf enforcement.
- Recording of authoriser, rationale and supporting evidence.
- Full audit trail for MCA‑related decisions.
6. Security Governance
CareLedgerPro maintains a secure technical environment suitable for regulated care providers.
- TLS encryption and encrypted storage.
- Automated backups with point‑in‑time recovery.
- High‑availability hosting in UK/EU‑aligned regions.
- Managed secret storage.
- Session timeout and re‑authentication for sensitive actions.
- Documented disaster‑recovery and business‑continuity processes.
7. Access & Accountability Governance
CareLedgerPro enforces strict access control and accountability.
- Role‑based permissions; staff only see assigned service users.
- Staff cannot grant their own roles.
- Every access and change recorded against the responsible user.
- Administrators required to review access regularly.
- Session timeout and re‑authentication for sensitive actions.
8. Operational Oversight
CareLedgerPro provides real‑time visibility of financial activity across the organisation.
- Real‑time dashboard showing balances, alerts and recent activity.
- Organisation‑wide analytics for management reviews.
- Daily email alerts for risks and outstanding actions.
- Weekly reconciliation sign‑off workflow.
9. Incident‑Response Governance
CareLedgerPro provides an audit‑ready breach‑response workflow aligned with UK GDPR.
- Detection and logging.
- Containment and triage.
- Risk assessment and reportability decision.
- ICO notification within 72 hours where required.
- Communication to affected individuals where high risk exists.
- CSV export for ICO, CQC or internal audits.
- Post‑incident review and closure.
10. Complaints & Escalation Governance
CareLedgerPro supports transparent handling of financial concerns.
- Complaint logging and outcome recording.
- Escalation routes to provider or DPO.
- ICO escalation guidance for unresolved concerns.
11. Business‑Continuity Governance
CareLedgerPro maintains resilient infrastructure suitable for regulated care environments.
- Automated backups with point‑in‑time recovery.
- Documented disaster‑recovery process.
- High‑availability hosting.
- In‑region replicas unless continuity requires otherwise.
12. Policy Governance
The following policy documents are available for procurement teams, auditors and regulators:
13. Provider Responsibilities
CareLedgerPro supports compliance but does not replace the provider’s legal duties. Providers remain responsible for:
- Lawful basis for processing.
- Staff training in data protection and safeguarding.
- Safeguarding escalation procedures.
- ICO registration and fee payment.
- Internal financial‑governance policies.
14. Governance Evidence for Inspection
CareLedgerPro provides structured, exportable records suitable for:
- CQC inspections.
- Safeguarding investigations.
- Local‑authority audits.
- Internal governance reviews.
- Financial‑management oversight.
Disclaimer — This framework summarises features that support governance and compliance. It is not legal advice. The registered provider remains the data controller and is responsible for its own policies, lawful basis, staff training, safeguarding and regulatory obligations.
Not independently certified. Not legal advice. CareLedgerPro provides controls designed to help Controllers meet their obligations under UK GDPR, safeguarding standards, and CQC evidence expectations. Final responsibility for compliance, DPIA completion, DSPT submission, DSAR handling, and record retention rests with the provider.