Call her Priya. She is a physiotherapist in a community rehabilitation unit, fourteen years qualified, and on a Tuesday in early October an email from the HCPC lands with a subject line she has never had to open before. She has been selected for CPD audit. The regulator wants a written profile of how she has met its standards over the past two years, supported by evidence, inside the renewal window.

She is not worried about whether she has done the learning. She has. A two-day manual therapy course in the spring. The monthly journal club. A falls-prevention audit she led on the ward. The problem is what she can prove. The certificate is a PDF somewhere in her personal email. The journal club has no register. The audit write-up sits on a hospital drive she cannot forward. And the departmental CPD spreadsheet was last touched fourteen months ago, by a colleague who has since left.

That is the shape of almost every CPD compliance problem I have seen. Not missing learning. Missing evidence, in the wrong places, held by the wrong people, discovered at the wrong moment.

A physiotherapist at a clinic desk at the end of the day, holding a folder of paper course certificates beside an open laptop
The learning was done. The evidence is in four places, and one of them is a colleague who left.

CPD compliance tracking is the practice of recording every continuing professional development activity against the rules of the professional body that requires it, with the evidence and the reflection that body will ask for, so that any registrant can produce a complete record inside an audit window. It is really a data problem: the UK's nine statutory health regulators alone set nine different rulebooks, and a spreadsheet built for one of them fails the moment a team spans two.

Nine Regulators, Nine Rulebooks

"Keep a CPD log" is unhelpful advice because the log a nurse needs looks nothing like the one a surveyor needs, and neither resembles what a solicitor is asked for. When Karas and colleagues reviewed the UK's statutory health regulators in a 2020 scoping review for BMJ Open, they counted approximately 1.5 million people registered under 32 regulated titles across nine regulators. 81% were required to reflect on their learning, only 35% to use a personal development plan, and 26% had no requirement to learn with peers at all. Eight of the nine regulators checked compliance by auditing a sample of records rather than reviewing everyone.

Outside healthcare the variety widens. Some bodies count hours, some count verifiable units, some set no number and ask for a reflective declaration. Here is what the primary sources actually say for the bodies a mid-sized UK employer is most likely to find on its payroll.

BodyWho it coversThe requirementCycleHow compliance is checked
HCPC15 professions, including physiotherapists, paramedics and radiographersFive outcome-based standards, no fixed hours. Standard 1: "maintain a continuous, up-to-date and accurate record"Two-year renewal2.5% of each profession selected at random each renewal; written profile with evidence
NMCNurses, midwives and nursing associates35 hours relevant to scope of practice, at least 20 participatoryThree yearsRevalidation. Record must hold method, topic and its relation to practice, dates, hours (including participatory), the part of the Code, and evidence
GDCDentists and dental care professionals100 verifiable hours for dentists, 75 or 50 for DCPs; at least 10 in any two consecutive years; a personal development planFive yearsAnnual CPD statement; records kept five years past the end of the cycle
RICSChartered surveyors20 hours a calendar year, at least 10 structuredAnnual: done by 31 December, recorded by 31 JanuaryRecorded in the online member portal
ACCAChartered certified accountants40 units a year: 21 verifiable, 19 non-verifiableAnnual; declaration by 1 JanuaryAnnual review of a statistical sample; 28 days to submit; keep records three years
IOSHTechnical, Certified and Chartered Members, Chartered FellowsMinimum 30 hours a year, with a reflective statement per activityAnnualRandom audit or on grade progression; 90 days to comply, then a move to Affiliate
Engineering Council (via institutions such as the IET)EngTech, IEng and CEng registrantsThe UK-SPEC CPD Code, which "does not specify a minimum amount of time"OngoingInstitutions sample records annually; persistent non-engagement risks removal from the Register
SRASolicitors with a practising certificateNo minimum hours. Reflect, address learning needs, and "keep an up-to-date record of your learning and development activity"Annual declaration at renewal"We regularly ask solicitors to provide evidence to us"; practice can be restricted on competence concerns

Read that as one data requirement and three things stand out. Hours are only part of it: the NMC counts participatory hours separately, ACCA splits verifiable from non-verifiable, and the GDC checks a two-year minimum inside a five-year total. The fields are prescribed, not suggested: the NMC lists six things every entry must contain. And the clocks are different lengths, starting on different days.

What the Auditor Opens First

Most guides to CPD compliance stop at the hours. The audit rarely starts there. Read what the regulators tell a selected registrant to submit and the first check is whether the record is complete and evidenced; the second is whether the professional can explain what the learning changed.

The HCPC's fifth standard asks the audited registrant to "present a written profile (which must be their own work and supported by evidence) explaining how they have met the Standards for CPD". Its third and fourth standards ask for CPD that "contributed to the quality of their practice and service delivery" and "benefits the service user". A list of course titles satisfies none of that. IOSH asks four questions of every activity: what did I complete, why did I choose it, what did I learn or gain, and how will I use it in my professional practice. Two of ACCA's three verifiability questions are about application and evidence, not attendance.

Then there are the windows. ACCA gives a member selected for review 28 days to submit. IOSH gives a non-compliant member up to 90 days before moving them to Affiliate. The GDC expects records kept for five years past the end of a five-year cycle, so a dental nurse may need a certificate from nearly a decade ago. Nobody produces that from a shared inbox.

Two engineers at a meeting table working through a printed technical drawing together
Learning with peers: the hours regulators increasingly want counted separately, and the ones a spreadsheet never captures.

One more thing the top-ranking guides leave out: the employer's exposure. CPD is an individual obligation, but the consequences land on the organisation. The SRA says it can "restrict your practice if we have concerns about your competence based on the information you provide". The Engineering Council says persistent non-engagement risks removal from the Register. An IOSH Chartered Member moved to Affiliate is no longer a Chartered Member on the tender your firm submitted last week. That is why skills compliance and CPD compliance belong on the same dashboard.

Why the Spreadsheet Fails at Exactly the Wrong Moment

The spreadsheet is not a stupid choice. It is free, everyone can open it, and on the day it is created it holds precisely the columns the team lead thought of. It fails for structural reasons, and it fails at audit rather than in the quiet months before. We covered the general case in CPD tracking software versus traditional record-keeping.

It records hours and loses evidence

A row says "Manual therapy update, 14 hours, March". The certificate that proves it is in an email, on a personal drive, or on a laptop that was reimaged when the person changed roles. The audit asks for both.

It has one owner and no memory

Someone set it up. When that person leaves or gets busy, the file goes stale without anyone noticing, because nothing about a spreadsheet tells you it has stopped being updated. Fourteen months of silence looks identical to fourteen months of compliance.

It has no reflection field, or an unused one

Almost every body in the table asks what the learning changed. A column labelled "notes" is not the same thing, and reflection reconstructed months later from a course title and a date is thin.

It cannot hold two rulebooks at once

A community health team might have HCPC physiotherapists, NMC nurses and an IOSH Chartered Member. Three cycles, three field lists, three definitions of what counts. The spreadsheet has one structure that fits nobody, or three tabs that nobody reconciles.

It does not know the clock is running

A spreadsheet does not know that a dental hygienist is nine months from the end of a two-year window with four verifiable hours logged. It only knows what someone typed into it. The audit letter is the first time anybody looks, and by then the gaps are historical.

Comparison of a shared CPD spreadsheet with a CPD record system designed from regulator requirements

Building a CPD Record That Survives an Audit

None of this needs a large project. It needs a record designed from the regulators' requirements backwards, and a habit of capturing evidence when the activity happens. Five steps.

1. Map every registered role to its body, cycle and next deadline

Start with people, not activities. For each person with a registration or membership that carries a CPD obligation, record the body, the grade (IOSH CPD is mandatory only from Technical Member upwards), the cycle length, and the date the current cycle ends. Almost nobody holds this centrally, and it is the data that tells you where the risk sits today. If you already keep a skills matrix, this is a column on it.

2. Define the record as the superset of what your bodies require

Take the strictest field list you face and make it the standard for everyone. The union of the NMC, IOSH and GDC lists gets you there: activity title and type; provider; start and end dates; total and participatory hours; structured or verifiable status; the standard, code or competency it relates to; the evidence file; and a reflective statement. A physiotherapist does not need the NMC Code field, but it costs nothing to leave blank, and one consistent record is far easier to audit than three bespoke ones.

3. Capture evidence on the day, not at renewal

A certificate exists in a findable place for about a week. Attach it to the record the day it arrives, from a phone if that is where the person is: a paramedic, a site engineer or a dental nurse does not sit at a desk, and a process that needs a desk gets deferred. Evidence attached at the point of learning survives ACCA's three years and the GDC's five. Evidence in an inbox does not.

4. Treat reflection as a required field, written the same week

Use IOSH's four questions as the template for everyone, because a paragraph that answers them also satisfies the HCPC's third and fourth standards and ACCA's verifiability test. Two or three sentences per activity is enough, written while the change to practice is still specific.

5. Review quarterly against the clock, and run one mock audit a year

Once a quarter, look at every registrant's position against their own cycle: hours, the participatory or verifiable split, evidence attached, reflection present, months remaining. Once a year, pick two or three people at random and ask for their profile inside 28 days, as ACCA or the HCPC would. The first mock audit is always uncomfortable. The second is routine.

Five-step process for building a CPD record that survives a professional body audit

Keep this record linked to, but distinct from, mandatory training: the employer requires fire safety and safeguarding; the body requires CPD to keep the registration.

Where StaffCircle Fits

StaffCircle is a performance and development platform rather than a CPD portal for one body, and that is the point. The employer's problem is a workforce answering to several bodies, and the need to see all of them against one competency framework.

One record per person, against the framework

Each CPD activity sits on the individual's record, linked to the skill or competency it develops, so the entry that satisfies a registration requirement also shows up in a skills gap analysis and a development plan. Nothing is logged twice.

Evidence attached, cycle tracked

Certificates, attendance confirmations and reflective notes attach to the activity itself, with an expiry or cycle-end date, so the record and its proof never separate and the platform can surface who is approaching a deadline.

Captured from a phone, on shift

Because the platform is mobile-first, a clinician or engineer can log an activity, photograph a certificate and write a reflection at the end of the day it happened, rather than reconstructing it at renewal.

Reporting across bodies, not one at a time

Managers and compliance leads see hours, evidence status and cycle position across the team regardless of which body each person answers to, which turns the annual scramble into a quarterly check. Our list of must-have CPD tracking features is a fair checklist if you are comparing tools, and the employee development page shows where the CPD record sits.

Final Thoughts

Priya passed her audit, in this telling, because a colleague remembered that the course provider re-issues certificates on request, and because the ward manager dug the falls audit out of the shared drive. That is not a system. That is luck and a good team, and it cost her eleven evenings.

The organisations that stop dreading CPD audits are not the ones whose people do the most learning. They are the ones whose records were designed from the regulators' requirements backwards, whose evidence was attached the week it was earned, and whose reflection was written while it still meant something. Book a demo to see how StaffCircle keeps CPD evidence, competencies and development in one record.

FAQ

What is CPD compliance tracking?

CPD compliance tracking is recording every continuing professional development activity against the rules of the professional body that requires it: the hours or units, the split that body cares about (participatory, verifiable or structured), the evidence, and a reflective statement, so a registrant can produce a complete record inside an audit window.

How many CPD hours do UK professionals need each year?

It depends on the body. RICS requires 20 hours a calendar year, at least 10 structured. IOSH requires a minimum of 30 hours a year from Technical Member grade upwards. ACCA requires 40 units a year, 21 verifiable. The NMC requires 35 hours over three years, at least 20 participatory. The GDC requires 100 verifiable hours over five years for dentists. The HCPC, the SRA and the Engineering Council set no minimum hours and use outcome-based standards instead.

What does a CPD audit involve?

Most UK bodies audit a sample rather than everyone. The HCPC randomly selects 2.5% of each profession at each renewal and asks for a written profile supported by evidence. ACCA reviews a statistical sample annually and gives members 28 days to submit records. IOSH audits at random or on progression to a new grade and expects a reflective statement for every activity. The auditor checks that the record is complete, evidenced and reflected on, not just that hours were logged.

What should a CPD record include?

Use the superset of what your bodies require. Taking the NMC, IOSH and GDC lists together: activity title and type, provider, start and end dates, total and participatory hours, structured or verifiable status, the standard, code or competency it relates to, the evidence file, and a reflective statement covering what you learned and how you will apply it. Fields a body does not need can be left blank.

How long do you need to keep CPD evidence?

It varies. ACCA tells members to keep CPD records for three years, longer for statutory auditors. The GDC requires records to be retained for five years from the end of the five-year cycle, which can mean producing a certificate nearly a decade after the course. Where no period is given, keep evidence for the current cycle plus the previous one, and attach it to the record at the time so the question never arises.

What is the difference between verifiable and non-verifiable CPD?

Verifiable CPD is learning you can evidence and explain. ACCA's test is three questions: was the activity relevant to your career, can you explain how you applied the learning in the workplace, and can you provide evidence that you undertook it. Non-verifiable CPD is relevant learning, such as reading, that you cannot evidence in the same way. RICS draws a similar line between structured and unstructured learning.

What is participatory learning in NMC revalidation?

The NMC requires 35 hours of CPD in each three-year cycle, at least 20 of them participatory. Participatory learning involves interaction with one or more other professionals, such as a course, a workshop, a peer discussion or clinical supervision, rather than solo activity like reading. Participatory hours must be recorded separately, which is one reason a single hours column is not enough for a nursing team.

Does mandatory training count as CPD?

Sometimes. Mandatory training is what the employer requires for the role, such as fire safety or safeguarding; CPD is what the professional body requires to keep a registration. Where a mandatory course is relevant to the person's scope of practice and they can evidence what they learned and applied, many bodies will accept it. Repeating the same annual e-learning module with no new learning rarely meets the relevance and reflection tests.

What happens if you fail a CPD audit?

It depends on the body. IOSH gives a non-compliant member up to 90 days to reach compliance, then moves them to Affiliate Member status. The Engineering Council says registrants who persistently fail to respond to CPD record requests risk removal from the Register. The SRA says it can restrict a solicitor's practice where it has competence concerns. In every case the right to practise under the title is what is at risk.

How do you write a CPD reflective statement?

Use IOSH's four questions as a template regardless of body: what activity did I complete, why did I choose it, what did I learn or gain, and how will I use this learning in my professional practice. Two or three specific sentences written in the same week as the activity is enough, and also satisfies the HCPC's practice-quality standards and ACCA's verifiability test.


About the author

Mark Seemann is the CEO and Founder of StaffCircle, the AI performance management platform for mid-sized organisations. He writes about performance management, employee development and the practical use of AI in HR. Connect with Mark on .