CPD Compliance: Tracking Professional Development Without the Spreadsheet
Call her Priya. She is a physiotherapist in a community rehabilitation unit, fourteen years qualified, and on a Tuesday in early October an email from the HCPC lands with a subject line she has never had to open before. She has been selected for CPD audit. The regulator wants a written profile of how she has met its standards over the past two years, supported by evidence, inside the renewal window.
She is not worried about whether she has done the learning. She has. A two-day manual therapy course in the spring. The monthly journal club. A falls-prevention audit she led on the ward. The problem is what she can prove. The certificate is a PDF somewhere in her personal email. The journal club has no register. The audit write-up sits on a hospital drive she cannot forward. And the departmental CPD spreadsheet was last touched fourteen months ago, by a colleague who has since left.
That is the shape of almost every CPD compliance problem I have seen. Not missing learning. Missing evidence, in the wrong places, held by the wrong people, discovered at the wrong moment.

CPD compliance tracking is the practice of recording every continuing professional development activity against the rules of the professional body that requires it, with the evidence and the reflection that body will ask for, so that any registrant can produce a complete record inside an audit window. It is really a data problem: the UK's nine statutory health regulators alone set nine different rulebooks, and a spreadsheet built for one of them fails the moment a team spans two.
Nine Regulators, Nine Rulebooks
"Keep a CPD log" is unhelpful advice because the log a nurse needs looks nothing like the one a surveyor needs, and neither resembles what a solicitor is asked for. When Karas and colleagues reviewed the UK's statutory health regulators in a 2020 scoping review for BMJ Open, they counted approximately 1.5 million people registered under 32 regulated titles across nine regulators. 81% were required to reflect on their learning, only 35% to use a personal development plan, and 26% had no requirement to learn with peers at all. Eight of the nine regulators checked compliance by auditing a sample of records rather than reviewing everyone.
Outside healthcare the variety widens. Some bodies count hours, some count verifiable units, some set no number and ask for a reflective declaration. Here is what the primary sources actually say for the bodies a mid-sized UK employer is most likely to find on its payroll.
| Body | Who it covers | The requirement | Cycle | How compliance is checked |
|---|---|---|---|---|
| HCPC | 15 professions, including physiotherapists, paramedics and radiographers | Five outcome-based standards, no fixed hours. Standard 1: "maintain a continuous, up-to-date and accurate record" | Two-year renewal | 2.5% of each profession selected at random each renewal; written profile with evidence |
| NMC | Nurses, midwives and nursing associates | 35 hours relevant to scope of practice, at least 20 participatory | Three years | Revalidation. Record must hold method, topic and its relation to practice, dates, hours (including participatory), the part of the Code, and evidence |
| GDC | Dentists and dental care professionals | 100 verifiable hours for dentists, 75 or 50 for DCPs; at least 10 in any two consecutive years; a personal development plan | Five years | Annual CPD statement; records kept five years past the end of the cycle |
| RICS | Chartered surveyors | 20 hours a calendar year, at least 10 structured | Annual: done by 31 December, recorded by 31 January | Recorded in the online member portal |
| ACCA | Chartered certified accountants | 40 units a year: 21 verifiable, 19 non-verifiable | Annual; declaration by 1 January | Annual review of a statistical sample; 28 days to submit; keep records three years |
| IOSH | Technical, Certified and Chartered Members, Chartered Fellows | Minimum 30 hours a year, with a reflective statement per activity | Annual | Random audit or on grade progression; 90 days to comply, then a move to Affiliate |
| Engineering Council (via institutions such as the IET) | EngTech, IEng and CEng registrants | The UK-SPEC CPD Code, which "does not specify a minimum amount of time" | Ongoing | Institutions sample records annually; persistent non-engagement risks removal from the Register |
| SRA | Solicitors with a practising certificate | No minimum hours. Reflect, address learning needs, and "keep an up-to-date record of your learning and development activity" | Annual declaration at renewal | "We regularly ask solicitors to provide evidence to us"; practice can be restricted on competence concerns |
Read that as one data requirement and three things stand out. Hours are only part of it: the NMC counts participatory hours separately, ACCA splits verifiable from non-verifiable, and the GDC checks a two-year minimum inside a five-year total. The fields are prescribed, not suggested: the NMC lists six things every entry must contain. And the clocks are different lengths, starting on different days.
What the Auditor Opens First
Most guides to CPD compliance stop at the hours. The audit rarely starts there. Read what the regulators tell a selected registrant to submit and the first check is whether the record is complete and evidenced; the second is whether the professional can explain what the learning changed.
The HCPC's fifth standard asks the audited registrant to "present a written profile (which must be their own work and supported by evidence) explaining how they have met the Standards for CPD". Its third and fourth standards ask for CPD that "contributed to the quality of their practice and service delivery" and "benefits the service user". A list of course titles satisfies none of that. IOSH asks four questions of every activity: what did I complete, why did I choose it, what did I learn or gain, and how will I use it in my professional practice. Two of ACCA's three verifiability questions are about application and evidence, not attendance.
Then there are the windows. ACCA gives a member selected for review 28 days to submit. IOSH gives a non-compliant member up to 90 days before moving them to Affiliate. The GDC expects records kept for five years past the end of a five-year cycle, so a dental nurse may need a certificate from nearly a decade ago. Nobody produces that from a shared inbox.

One more thing the top-ranking guides leave out: the employer's exposure. CPD is an individual obligation, but the consequences land on the organisation. The SRA says it can "restrict your practice if we have concerns about your competence based on the information you provide". The Engineering Council says persistent non-engagement risks removal from the Register. An IOSH Chartered Member moved to Affiliate is no longer a Chartered Member on the tender your firm submitted last week. That is why skills compliance and CPD compliance belong on the same dashboard.
Why the Spreadsheet Fails at Exactly the Wrong Moment
The spreadsheet is not a stupid choice. It is free, everyone can open it, and on the day it is created it holds precisely the columns the team lead thought of. It fails for structural reasons, and it fails at audit rather than in the quiet months before. We covered the general case in CPD tracking software versus traditional record-keeping.
It records hours and loses evidence
A row says "Manual therapy update, 14 hours, March". The certificate that proves it is in an email, on a personal drive, or on a laptop that was reimaged when the person changed roles. The audit asks for both.
It has one owner and no memory
Someone set it up. When that person leaves or gets busy, the file goes stale without anyone noticing, because nothing about a spreadsheet tells you it has stopped being updated. Fourteen months of silence looks identical to fourteen months of compliance.
It has no reflection field, or an unused one
Almost every body in the table asks what the learning changed. A column labelled "notes" is not the same thing, and reflection reconstructed months later from a course title and a date is thin.
It cannot hold two rulebooks at once
A community health team might have HCPC physiotherapists, NMC nurses and an IOSH Chartered Member. Three cycles, three field lists, three definitions of what counts. The spreadsheet has one structure that fits nobody, or three tabs that nobody reconciles.
It does not know the clock is running
A spreadsheet does not know that a dental hygienist is nine months from the end of a two-year window with four verifiable hours logged. It only knows what someone typed into it. The audit letter is the first time anybody looks, and by then the gaps are historical.

Building a CPD Record That Survives an Audit
None of this needs a large project. It needs a record designed from the regulators' requirements backwards, and a habit of capturing evidence when the activity happens. Five steps.
1. Map every registered role to its body, cycle and next deadline
Start with people, not activities. For each person with a registration or membership that carries a CPD obligation, record the body, the grade (IOSH CPD is mandatory only from Technical Member upwards), the cycle length, and the date the current cycle ends. Almost nobody holds this centrally, and it is the data that tells you where the risk sits today. If you already keep a skills matrix, this is a column on it.
2. Define the record as the superset of what your bodies require
Take the strictest field list you face and make it the standard for everyone. The union of the NMC, IOSH and GDC lists gets you there: activity title and type; provider; start and end dates; total and participatory hours; structured or verifiable status; the standard, code or competency it relates to; the evidence file; and a reflective statement. A physiotherapist does not need the NMC Code field, but it costs nothing to leave blank, and one consistent record is far easier to audit than three bespoke ones.
3. Capture evidence on the day, not at renewal
A certificate exists in a findable place for about a week. Attach it to the record the day it arrives, from a phone if that is where the person is: a paramedic, a site engineer or a dental nurse does not sit at a desk, and a process that needs a desk gets deferred. Evidence attached at the point of learning survives ACCA's three years and the GDC's five. Evidence in an inbox does not.
4. Treat reflection as a required field, written the same week
Use IOSH's four questions as the template for everyone, because a paragraph that answers them also satisfies the HCPC's third and fourth standards and ACCA's verifiability test. Two or three sentences per activity is enough, written while the change to practice is still specific.
5. Review quarterly against the clock, and run one mock audit a year
Once a quarter, look at every registrant's position against their own cycle: hours, the participatory or verifiable split, evidence attached, reflection present, months remaining. Once a year, pick two or three people at random and ask for their profile inside 28 days, as ACCA or the HCPC would. The first mock audit is always uncomfortable. The second is routine.

Keep this record linked to, but distinct from, mandatory training: the employer requires fire safety and safeguarding; the body requires CPD to keep the registration.
Where StaffCircle Fits
StaffCircle is a performance and development platform rather than a CPD portal for one body, and that is the point. The employer's problem is a workforce answering to several bodies, and the need to see all of them against one competency framework.
One record per person, against the framework
Each CPD activity sits on the individual's record, linked to the skill or competency it develops, so the entry that satisfies a registration requirement also shows up in a skills gap analysis and a development plan. Nothing is logged twice.
Evidence attached, cycle tracked
Certificates, attendance confirmations and reflective notes attach to the activity itself, with an expiry or cycle-end date, so the record and its proof never separate and the platform can surface who is approaching a deadline.
Captured from a phone, on shift
Because the platform is mobile-first, a clinician or engineer can log an activity, photograph a certificate and write a reflection at the end of the day it happened, rather than reconstructing it at renewal.
Reporting across bodies, not one at a time
Managers and compliance leads see hours, evidence status and cycle position across the team regardless of which body each person answers to, which turns the annual scramble into a quarterly check. Our list of must-have CPD tracking features is a fair checklist if you are comparing tools, and the employee development page shows where the CPD record sits.
Final Thoughts
Priya passed her audit, in this telling, because a colleague remembered that the course provider re-issues certificates on request, and because the ward manager dug the falls audit out of the shared drive. That is not a system. That is luck and a good team, and it cost her eleven evenings.
The organisations that stop dreading CPD audits are not the ones whose people do the most learning. They are the ones whose records were designed from the regulators' requirements backwards, whose evidence was attached the week it was earned, and whose reflection was written while it still meant something. Book a demo to see how StaffCircle keeps CPD evidence, competencies and development in one record.
FAQ
What is CPD compliance tracking?
CPD compliance tracking is recording every continuing professional development activity against the rules of the professional body that requires it: the hours or units, the split that body cares about (participatory, verifiable or structured), the evidence, and a reflective statement, so a registrant can produce a complete record inside an audit window.
How many CPD hours do UK professionals need each year?
It depends on the body. RICS requires 20 hours a calendar year, at least 10 structured. IOSH requires a minimum of 30 hours a year from Technical Member grade upwards. ACCA requires 40 units a year, 21 verifiable. The NMC requires 35 hours over three years, at least 20 participatory. The GDC requires 100 verifiable hours over five years for dentists. The HCPC, the SRA and the Engineering Council set no minimum hours and use outcome-based standards instead.
What does a CPD audit involve?
Most UK bodies audit a sample rather than everyone. The HCPC randomly selects 2.5% of each profession at each renewal and asks for a written profile supported by evidence. ACCA reviews a statistical sample annually and gives members 28 days to submit records. IOSH audits at random or on progression to a new grade and expects a reflective statement for every activity. The auditor checks that the record is complete, evidenced and reflected on, not just that hours were logged.
What should a CPD record include?
Use the superset of what your bodies require. Taking the NMC, IOSH and GDC lists together: activity title and type, provider, start and end dates, total and participatory hours, structured or verifiable status, the standard, code or competency it relates to, the evidence file, and a reflective statement covering what you learned and how you will apply it. Fields a body does not need can be left blank.
How long do you need to keep CPD evidence?
It varies. ACCA tells members to keep CPD records for three years, longer for statutory auditors. The GDC requires records to be retained for five years from the end of the five-year cycle, which can mean producing a certificate nearly a decade after the course. Where no period is given, keep evidence for the current cycle plus the previous one, and attach it to the record at the time so the question never arises.
What is the difference between verifiable and non-verifiable CPD?
Verifiable CPD is learning you can evidence and explain. ACCA's test is three questions: was the activity relevant to your career, can you explain how you applied the learning in the workplace, and can you provide evidence that you undertook it. Non-verifiable CPD is relevant learning, such as reading, that you cannot evidence in the same way. RICS draws a similar line between structured and unstructured learning.
What is participatory learning in NMC revalidation?
The NMC requires 35 hours of CPD in each three-year cycle, at least 20 of them participatory. Participatory learning involves interaction with one or more other professionals, such as a course, a workshop, a peer discussion or clinical supervision, rather than solo activity like reading. Participatory hours must be recorded separately, which is one reason a single hours column is not enough for a nursing team.
Does mandatory training count as CPD?
Sometimes. Mandatory training is what the employer requires for the role, such as fire safety or safeguarding; CPD is what the professional body requires to keep a registration. Where a mandatory course is relevant to the person's scope of practice and they can evidence what they learned and applied, many bodies will accept it. Repeating the same annual e-learning module with no new learning rarely meets the relevance and reflection tests.
What happens if you fail a CPD audit?
It depends on the body. IOSH gives a non-compliant member up to 90 days to reach compliance, then moves them to Affiliate Member status. The Engineering Council says registrants who persistently fail to respond to CPD record requests risk removal from the Register. The SRA says it can restrict a solicitor's practice where it has competence concerns. In every case the right to practise under the title is what is at risk.
How do you write a CPD reflective statement?
Use IOSH's four questions as a template regardless of body: what activity did I complete, why did I choose it, what did I learn or gain, and how will I use this learning in my professional practice. Two or three specific sentences written in the same week as the activity is enough, and also satisfies the HCPC's practice-quality standards and ACCA's verifiability test.
See StaffCircle in action
Book a personalised demo and see how StaffCircle drives performance, engagement and development.