CareLedgerPro — Full Governance Framework

Version 1.2 — Last reviewed: June 2026

CareLedgerPro operates a lightweight information-governance framework proportionate to a small UK software provider serving the care sector. This page describes how we manage our own governance responsibilities as a processor. It does not describe your governance framework, which remains your responsibility as Controller. CareLedgerPro acts as a data processor; the registered provider remains the data controller and is responsible for lawful basis, staff training, safeguarding escalation, ICO registration and internal policies.

1. Governance Principles

CareLedgerPro is built around five core governance principles:

  • Transparency — clear, auditable financial records.
  • Accountability — every action linked to a responsible user.
  • Security — encryption, access control and breach‑response workflows.
  • Compliance — alignment with CQC, GDPR, DPA 2018 and MCA 2005.
  • Operational Safety — enforced workflows that reduce risk.

Explore: CQC compliance

2. Financial Governance

CareLedgerPro enforces safe, transparent and auditable financial management.

  • Two‑person verification above configurable thresholds.
  • Mandatory receipts for higher‑risk transactions.
  • Append-only audit logs with recorded corrections; void‑with‑reason enforcement.
  • Per‑client and per‑unit balances with full histories.
  • Weekly reconciliation sign‑off with timestamped managerial approval.
  • Exportable audit logs for safeguarding investigations.
  • Spending‑plan enforcement with warn‑with‑reason prompts.

Explore: financial safeguarding controls

3. Data‑Protection Governance

CareLedgerPro supports GDPR and DPA 2018 compliance through secure data‑handling practices.

  • Encryption in transit (TLS) and at rest.
  • Role‑based access with per‑unit scoping.
  • Audit logging of all access and changes.
  • Password breach‑checking via Have I Been Pwned.
  • Documented retention and deletion schedules.
  • Essential‑only cookies; no advertising or tracking.
  • Clear controller/processor separation.
  • DPO contact details published for rights requests.

Explore: GDPR special‑category handling

4. Safeguarding Governance

CareLedgerPro provides financial‑safeguarding controls aligned with CQC expectations.

  • Discrepancy alerts for petty cash and client balances.
  • Append-only histories for all financial activity.
  • Exportable safeguarding evidence for investigations.
  • Incident logging with full audit trails.
  • Daily email alerts for suspicious spending or missing receipts.

Explore: inspection readiness

5. Mental Capacity Act Governance

CareLedgerPro supports best‑interests decision‑making under the MCA 2005.

  • Per‑client capacity flags.
  • Automatic sign‑on‑behalf enforcement.
  • Recording of authoriser, rationale and supporting evidence.
  • Full audit trail for MCA‑related decisions.

Explore: MCA best‑interests logging

6. Security Governance

CareLedgerPro maintains a secure technical environment suitable for regulated care providers.

  • TLS encryption and encrypted storage.
  • Automated backups with point‑in‑time recovery.
  • High‑availability hosting in UK/EU‑aligned regions.
  • Managed secret storage.
  • Session timeout and re‑authentication for sensitive actions.
  • Documented disaster‑recovery and business‑continuity processes.

Explore: security architecture

7. Access & Accountability Governance

CareLedgerPro enforces strict access control and accountability.

  • Role‑based permissions; staff only see assigned service users.
  • Staff cannot grant their own roles.
  • Every access and change recorded against the responsible user.
  • Administrators required to review access regularly.
  • Session timeout and re‑authentication for sensitive actions.

Explore: access control model

8. Operational Oversight

CareLedgerPro provides real‑time visibility of financial activity across the organisation.

  • Real‑time dashboard showing balances, alerts and recent activity.
  • Organisation‑wide analytics for management reviews.
  • Daily email alerts for risks and outstanding actions.
  • Weekly reconciliation sign‑off workflow.

Explore: reports & analytics

9. Incident‑Response Governance

CareLedgerPro provides an audit‑ready breach‑response workflow aligned with UK GDPR.

  • Detection and logging.
  • Containment and triage.
  • Risk assessment and reportability decision.
  • ICO notification within 72 hours where required.
  • Communication to affected individuals where high risk exists.
  • CSV export for ICO, CQC or internal audits.
  • Post‑incident review and closure.

Explore: breach workflow

10. Complaints & Escalation Governance

CareLedgerPro supports transparent handling of financial concerns.

  • Complaint logging and outcome recording.
  • Escalation routes to provider or DPO.
  • ICO escalation guidance for unresolved concerns.

Explore: complaints workflow

11. Business‑Continuity Governance

CareLedgerPro maintains resilient infrastructure suitable for regulated care environments.

  • Automated backups with point‑in‑time recovery.
  • Documented disaster‑recovery process.
  • High‑availability hosting.
  • In‑region replicas unless continuity requires otherwise.

Explore: business continuity

12. Policy Governance

The following policy documents are available for procurement teams, auditors and regulators:

Explore: policy documentation

13. Provider Responsibilities

CareLedgerPro supports compliance but does not replace the provider’s legal duties. Providers remain responsible for:

  • Lawful basis for processing.
  • Staff training in data protection and safeguarding.
  • Safeguarding escalation procedures.
  • ICO registration and fee payment.
  • Internal financial‑governance policies.

14. Governance Evidence for Inspection

CareLedgerPro provides structured, exportable records suitable for:

  • CQC inspections.
  • Safeguarding investigations.
  • Local‑authority audits.
  • Internal governance reviews.
  • Financial‑management oversight.

Explore: inspection readiness

Disclaimer — This framework summarises features that support governance and compliance. It is not legal advice. The registered provider remains the data controller and is responsible for its own policies, lawful basis, staff training, safeguarding and regulatory obligations.

Not independently certified. Not legal advice. CareLedgerPro provides controls designed to help Controllers meet their obligations under UK GDPR, safeguarding standards, and CQC evidence expectations. Final responsibility for compliance, DPIA completion, DSPT submission, DSAR handling, and record retention rests with the provider.