Business & Compliance

Audit Your Practice's Documentation in 30 Minutes - 20 Questions Before Any Inspection

Author:

20 yes/no questions that show in 30 minutes whether your practice is ready for a KIF, Sanepid, or UODO inspection - no download required, fully usable right in the article.

Agnieszka has run a physiotherapy practice for four years, and whenever anyone asked "are you ready for an inspection," her answer was always the same: "I think so." Not because she was actually sure -- she'd simply never checked it any other way than by eyeballing it. It wasn't until the practice next door got a KIF site visit and received recommendations about its GDPR records that she sat down and did something she'd never done before: she went through every document she was supposed to have, one by one, and marked what was missing. It took her under half an hour. The result: 13 points out of a possible 20.

The problem for physiotherapy practice owners usually isn't that they don't want their records in order. It's that nobody ever told them exactly how many documents they need to have, or how to check that without waiting for an inspector to knock. This article is exactly that test -- 20 concrete yes/no questions you can tick off while reading, with no file to download, no newsletter signup, no consultation to book. You just read, answer honestly, and by the end you know exactly where you stand. For more on the inspections themselves and typical mistakes, see our article on mistakes during KIF and Sanepid inspections -- this piece is its self-diagnosis companion.

How to use this checklist

The rules are simple. Under each of the five areas you'll find four questions. For each one, mark (mentally or on paper) YES or NO -- without stretching the answer to "sort of" or "I'll get to it eventually." An inspector doesn't accept a stated intention, only a document that actually exists on-site and is up to date. At the end, count your YES answers (out of a maximum of 20) and check the score interpretation below.

This isn't a wish list or a theoretical rundown of regulations. Every question corresponds to one specific document or procedure that a physiotherapy practice genuinely needs -- and one that can be closed with a ready-made template from FizjoReady's packages instead of being written from scratch.

The 20 audit questions -- full checklist

# Question YES NO
Registration and regulations
1Do you have a current RPWDL or CEIDG registration that matches your practice's actual status?
2Do you have written organisational regulations for your practice?
3Is an extract of the regulations displayed somewhere visible to patients?
4Is your liability insurance paid up and currently valid?
Medical records and consent
5Does every patient have a record with an up-to-date, documented therapy plan?
6Do you collect informed consent from patients, including extended consent for higher-risk procedures?
7Do you have authorisations from patients' next of kin to access their medical records?
8Do you keep a register of medical record disclosures?
GDPR
9Do you have a written data protection policy and a record of processing activities (RoPA)?
10Do you have GDPR information clauses for patients?
11Do you have data processing authorisations for staff and data processing agreements with suppliers?
12Do you have a written procedure for reporting data breaches (72 hours)?
Sanitary
13Do you have written disinfection procedures for equipment and treatment tables?
14Do you keep a register of medical waste (BDO)?
15Do you have a current occupational risk assessment (health and safety)?
16Are handwashing instructions displayed by the sink?
HR and monitoring
17Does your staff have written job descriptions?
18Do new employees go through onboarding that includes GDPR documents?
19If you have CCTV, does the monitoring have written rules and information signage?
20If you treat minors, do you have Child Safeguarding Standards in place?

Count your YES answers. The result translates directly into how calmly you can sleep before the next site visit.

What your score means

  • Below 15 out of 20 -- your first inspection will be painful. The gaps are numerous enough that the inspector won't stop at a single recommendation -- you'll likely get a list of failings with a deadline to fix them, and on a repeat finding some of those may no longer result in just a recommendation, but in actual financial consequences.
  • 15-18 points -- good shape, a few gaps to close. This is the most common result among practices that "have something in place" but have never run a systematic review. Closing the remaining gaps is usually a matter of days, not months.
  • 19-20 points -- you're ready. An inspection stops being a stressful event and becomes a formality. It's still worth repeating this test quarterly, though -- documents go stale. Regulations that weren't updated after a price change, a risk assessment from two years ago, or a GDPR consent form missing the latest clause are typical traps even for well-prepared practices.

Which gaps cost the most

Not all 20 points carry equal weight. If you have to choose what to fix first, look at financial and reputational risk, not at what's easiest to do.

GDPR and Child Safeguarding Standards carry the highest risk of penalties. Gaps in GDPR documentation -- no record of processing activities, no data processing agreements, no breach-reporting procedure -- are an area where the data protection authority (UODO) can impose a real financial penalty, not just a recommendation. We describe how such an inspection unfolds step by step in our article on a UODO inspection at a physiotherapy practice. Likewise, missing Child Safeguarding Standards at practices treating minors has been a statutory obligation since 2024, and failing to have them is treated seriously -- details are in our article on Child Safeguarding Standards in physiotherapy.

Sanitary and formal gaps usually end with just a recommendation. Missing handwashing instructions by the sink, or an outdated BDO waste register, are failings that the sanitary inspectorate most often notes with a deadline for correction, without immediate financial consequences -- provided they don't recur at the next visit. That doesn't mean you can ignore them, but it's worth setting the order of fixing gaps deliberately: GDPR and legally risky documents first, then sanitary and formal order.

[SP] Example -- Solo practice: After scoring 13/20 on her test, Agnieszka first closed her GDPR gaps -- she was missing her record of processing activities and a breach-reporting procedure. Only after that did she deal with the handwashing signage and update her risk assessment. Two weeks later she repeated the test and scored 19/20.

[GR] Example -- Group practice: At a practice with four therapists, each person filled in the 20-question test separately for their own workstation -- and it turned out only two of the four had signed data processing authorisations. The owner introduced a rule that a new employee doesn't start seeing patients until their full HR and GDPR paperwork is in place.

What has to be on display, and what patients never see

Some of the 20 documents are public-facing -- they must be visible to patients in the waiting room or treatment room. Others are internal and a patient will never see them, but an inspector will. Confusing the two categories is a common mistake: practices display their regulations but forget the GDPR information clause, or the other way around -- they have everything filed away, but nothing is displayed where it should be. We've put together the full list of what must be displayed at a physiotherapy practice in our article on what must be displayed at a physiotherapy practice.

How the gaps map onto FizjoReady's packages

Once you've counted your points, the natural question is: "okay, but how do I close this quickly?" The answer depends on exactly which questions on the checklist came back NO.

  • The FUNDAMENT package covers the basics: organisational regulations, patient consent templates, basic sanitary procedures, and staff job descriptions. That's your answer to questions 2, 3, 5, 6, 13, and 17.
  • The TARCZA package adds complete GDPR documentation -- a data protection policy, a record of processing activities, information clauses, authorisations, and a breach-reporting procedure -- plus inspection checklists and monitoring procedures. That covers questions 7-12, 16, 18, and 19.
  • The PREMIUM package is a full audit tailored to your specific practice, including risks unique to your situation (e.g. treating minors and Child Safeguarding Standards, CCTV, multiple staff members) -- recommended if your score is below 15 and you want certainty that nothing has been missed.

If you want to start with the document solo practices most often lack -- organisational regulations -- you'll find a ready template and implementation guide in our article on organisational regulations for a physiotherapy practice. We've covered the full GDPR documentation package step by step in our article on complete GDPR documentation for a physiotherapy practice.

Frequently asked questions

Does this checklist replace a professional audit?

Not fully, but for most solo and small-team practices it's a sufficient starting point. The 20-question test shows you where the gaps are, but it doesn't assess the quality of each individual document -- whether your regulations match current law, or whether your GDPR clause has every required element. If your score is low, or the documents you do have are old (two or three years out of date), it's worth considering a full audit as part of the PREMIUM package.

How often should I repeat this audit?

Once a quarter is a reasonable rhythm for most practices. Documents go stale -- staff turnover, pricing changes, new data-processing suppliers, and regulations themselves (like the Child Safeguarding Standards) get updated. The test takes 30 minutes, so the cost of repeating it is negligible compared to the risk a neglected document carries.

Does a low score mean I'll get fined at my next inspection?

Not necessarily. Most inspections, even with substantial gaps, end with a recommendation and a deadline for correction rather than an immediate financial penalty -- we cover this in more detail in our article on mistakes during KIF and Sanepid inspections. The exception is serious GDPR violations, where the data protection authority (UODO) has the right to impose a fine without a prior recommendation if the breach is severe or involves sensitive data.

Do I need all 20 documents if I run a one-person practice?

Almost all of them -- yes. The only questions that might not apply to you are number 19 (monitoring, if you don't have CCTV) and number 20 (Child Safeguarding Standards, if you don't treat patients under 18). The remaining 18 points apply to every physiotherapy practice, regardless of size.

CTA: You already know your score -- now it's time to close the gaps. Whether you're missing your regulations, a complete GDPR package, or need a full audit tailored to your practice, FizjoReady's packages include ready-made templates and procedures for every one of these 20 checklist points. See FizjoReady packages →

Related articles:
- Mistakes during KIF and Sanepid inspections -- how to avoid them
- Organisational regulations for a physiotherapy practice -- ready template
- Complete GDPR documentation for a physiotherapy practice
- A UODO inspection at a physiotherapy practice
- Child Safeguarding Standards in physiotherapy
- What must be displayed at a physiotherapy practice

Newsletter

Regulatory changes and practical tips for physiotherapy practices. No spam.