RAI Consultancy Ltd · UK-wideEmail
RAI Consultancy
Audit

Assurance that will withstand external scrutiny.

An independent line of sight for boards, trustees and general counsel: how your organisation actually behaves against how it says it behaves, and against what the law and regulators require, including pre-inspection readiness for CQC and Ofsted.

A

What it is

A rigorous, evidence-based audit of a defined area of organisational conduct: existing policies mapped against current legislation and sector best practice; regulatory audits and readiness for inspection, including CQC and Ofsted pre-inspection audits; operational process audits testing compliance with your own SOPs and brand or contractual service level agreements; and GDPR / UK data protection compliance. Delivered to the evidential standard of an internal inquiry.

When you'd instruct us

  • A regulator, CQC/Ofsted inspection or ICO enquiry is imminent and internal assurance is not enough.
  • You need policies benchmarked against current legislation, statutory guidance and sector best practice.
  • Operations are drifting from SOPs, contractual SLAs or brand standards and the board needs independent evidence.
  • A serious incident, data breach or complaint has occurred and you need an independent post-incident review.
  • Insurers or acquirers are seeking third-party comfort on your controls.

What you receive

  • A written audit report with findings, evidence log and prioritised recommendations against legislation, regulator expectations and internal standards.
  • A briefing to the board or audit committee.
  • Optional remediation tracking, policy re-drafting and implementation support after the report is delivered.

Typical engagement

Timeframes are agreed at instruction based on the scope of the work and its urgency. Fees are fixed and confidentiality arrangements are confirmed at the outset.

Anonymised example

Ahead of a high-stakes statutory area inspection, we carried out an independent audit of a randomly selected sample of child safeguarding cases to test regulatory readiness. A rigorous review of the case materials surfaced critical service delivery failures and points of non-compliance with statutory policy. We identified the root causes, delivered strategic recommendations to rectify them before the formal inspection began, and fed the findings into multi-agency panel reviews, establishing best-practice benchmarks and embedding the learning across all partner organisations.

Illustrative UK cases

Publicly reported matters that illustrate the kind of exposure this discipline addresses. RAI Consultancy Ltd has no involvement in these cases; they are cited from reputable UK media and regulators for context only.

  • Holland Park School: Ofsted 'Inadequate' after governance failures

    2022

    Ofsted downgraded Holland Park School in Kensington from 'Outstanding' to 'Inadequate' after a governor-commissioned review uncovered a 'culture of fear and favouritism', with staff using public humiliation and shouting as behaviour management, and serious safeguarding failures identified. The case shows why an independent pre-inspection audit against the Ofsted framework is often the best way to surface control and culture gaps before a regulator does.

    Read source: BBC News

    Citation & disclaimer: publicly reported by BBC News (2022). Cited as an illustrative example only. RAI Consultancy Ltd has no involvement in this matter.

  • Swiss Cottage Care Home: CQC 'Inadequate' for failing to protect residents

    2023

    The Care Quality Commission rated Swiss Cottage Care Home in Leighton Buzzard 'Inadequate' for the second time, finding that residents were not adequately protected from abuse and improper treatment, including a failure to report an allegation of abuse to the relevant authorities. A textbook example of the safeguarding and reporting gaps that a CQC pre-inspection audit is designed to identify before they become a regulator's finding.

    Read source: BBC News / CQC

    Citation & disclaimer: publicly reported by BBC News / CQC (2023). Cited as an illustrative example only. RAI Consultancy Ltd has no involvement in this matter.

  • British Airways: £20m ICO fine for GDPR failings

    2020

    The Information Commissioner's Office fined British Airways £20 million after a 2018 cyber attack compromised the personal and financial data of more than 400,000 customers, finding BA had failed to put adequate security measures in place, one of the largest UK GDPR enforcement penalties issued to date.

    Read source: BBC News

    Citation & disclaimer: publicly reported by BBC News (2020). Cited as an illustrative example only. RAI Consultancy Ltd has no involvement in this matter.

  • Starling Bank: £29m FCA fine for financial crime control failures

    2024

    The Financial Conduct Authority fined Starling Bank £29 million for 'shockingly lax' financial crime controls, finding the bank had repeatedly breached a regulatory requirement not to open accounts for high-risk customers and failed to maintain adequate sanctions screening as it scaled from 43,000 to 3.6 million customers.

    Read source: FCA / The Guardian

    Citation & disclaimer: publicly reported by FCA / The Guardian (2024). Cited as an illustrative example only. RAI Consultancy Ltd has no involvement in this matter.

Confidential · Privileged · UK-wide

Speak to the principal.