WHEN POLICY MEETS PRACTICE | PART TWO
How quality assurance and quality improvement audits keep policies alive and patients safe
Written by Robert Colon-Torres
Compliance owns the policy, QA verifies it is followed, and QI proves it works. When the three operate as one feedback loop, policies stay alive, and the rest of the organization follows.
Previously, in Part 1: The Cost of an Unchecked Policy
Harm is common and often preventable. Workarounds signal where policy and practice have come apart, and left unchecked they become normal. Regulators now ask whether compliance programs work in practice, and courts may treat a health system's own policies as evidence of the standard of care.
Part 1 made the case that the gap between policy and practice is costly. This concluding part asks why the gap opens and how to close it. The answer is this month's theme: compliance and CQI working hand in hand.
Why good policies break down: five kinds of ambiguity
Gurses and colleagues studied why ICU teams struggled to follow evidence-based infection prevention guidelines. The problem was rarely indifference. It was that the guidelines left too much unclear. They identified five kinds of “systems ambiguity,”[1] each of which points to a specific audit question.
Ambiguity | What it looks like on the floor | What the audit should ask |
Task | Staff aren't sure which steps are required | Can staff describe the required steps without looking them up? |
Expectation | The standard is vague (“as appropriate,” “regularly”) | Is the expected result measurable, and do staff know the target? |
Responsibility | No one is sure who owns a step or makes the call | Is a named role accountable for each step? |
Method | The process is complex and the environment demanding | Do workflow, equipment, and staffing make the right way the easy way? |
Exception | It's unclear when deviation is allowed | Are exceptions defined, and documented when used? |
Ambiguity is only half the story. Jens Rasmussen's dynamic safety model describes every organization as operating inside a “safety envelope” bounded by economic failure, unacceptable workload, and unacceptable performance. Cost pressure and workload pressure combine to push operations steadily toward the performance boundary, where harm occurs. Cook and Rasmussen called a system running at that edge “going solid”: it has lost its slack, so problems in one unit cascade into others.[2] This is why rewriting an ambiguous policy for a chronically understaffed unit rarely works. Audits must look at the conditions around the policy, not just the policy itself.
Proof that the partnership works
The Michigan Keystone ICU project remains one of the clearest demonstrations of what happens when clear policy, measurement, and culture work together. More than 100 ICUs adopted a short checklist of five evidence-based practices for central line insertion. Nurses were explicitly empowered to stop a procedure if a step was missed. Infection rates were measured and fed back to each unit. The median rate of catheter-related bloodstream infections fell from 2.7 per 1,000 catheter-days to zero within the first three months, and the gains were sustained over 18 months.[3]
Keystone eliminated all five ambiguities at once: clear tasks, a measurable target, named responsibility, a simplified method, and defined authority to intervene. It also shows that audit and feedback works best as part of a broader system, not as a standalone report. A Cochrane review of 140 randomized trials found that audit and feedback produced a median 4.3 percent absolute improvement in compliance with desired practice. That gain is modest but meaningful, and it was largest when baseline performance was low, feedback came from a supervisor or respected colleague, was repeated, was delivered both verbally and in writing, and included explicit targets and an action plan.[4]
A working model for compliance and CQI
Function | Core question | Owns |
Compliance | Is the expectation clear, required, and enforced? | Policy, training, corrective action, board reporting |
Quality assurance | Are we doing what the policy says? | Adherence audits, sampling, findings |
Quality improvement | Is it producing the result we want? | Outcome measures, PDSA cycles, redesign |
- Write the policy with the people who will follow it. Frontline input surfaces task and method ambiguity before approval and builds belief that the policy is valid.
- Build the audit in from the start. Every policy should define its measure, sample, frequency, threshold, and owner. New and revised policies warrant closer review until they are stable.
- Measure adherence and outcomes together. High adherence with poor outcomes means the policy needs redesign, not harder enforcement.
- Pair numbers with voices. Data shows where the gap is; rounding, interviews, and staff surveys explain why.
- Close the loop. A failing policy should be revised and re-audited, or retired. Leaving it unchanged guarantees drift and, as Heastie showed in Part 1, can be used against you.
- Report upward and bring in outside eyes. Route results to your compliance committee and board, as OIG guidance expects, and use periodic external audits to catch blind spots.[5]
Inspiring others to follow your lead
Keystone's results did not come from the checklist alone; they came from changing who felt ownership of safety. Compliance leaders can create that same shift. Share the data with the people who generate it, and make unit-level results visible. The Cochrane evidence suggests the messenger matters: feedback lands best when it comes from a supervisor or trusted colleague, not an anonymous report. Invite frontline staff to draft and test policies, then tell them what changed because of their input. Respond to errors with a just culture lens, so staff report problems instead of hiding them. Recognize improvement publicly and name the teams responsible. And model the behavior yourself: when compliance audits its own processes and acts on what it finds, others take auditing seriously too.
Leadership in compliance is rarely about authority. It is about making the right way the easy way, and checking until it is.
Closing the series
Part 1 showed that preventable harm remains common and that unchecked policies carry clinical, financial, regulatory, and legal risk. Part 2 showed that the gap can be closed when compliance, QA, and QI operate as one feedback loop: clear policies, built-in audits, honest feedback, and a culture that treats every finding as a chance to improve. That is what compliance and CQI working hand in hand looks like, and it is how we lead others to follow.
About the Author
Robert Colon-Torres is a healthcare compliance executive with roughly 25 years of experience, most recently as a chief compliance officer for federally qualified health centers in California. He holds a degree in health law from Loyola University Chicago.
References
1.Gurses AP, et al. Systems ambiguity and guideline compliance. Qual Saf Health Care. 2008;17(5):351–359.
2.Cook R, Rasmussen J. “Going solid”: a model of system dynamics and consequences for patient safety. Qual Saf Health Care. 2005;14(2):130–134.
3.Pronovost P, et al. An intervention to decrease catheter-related bloodstream infections in the ICU. N Engl J Med. 2006;355(26):2725–2732.
4.Ivers N, et al. Audit and feedback: effects on professional practice and healthcare outcomes. Cochrane Database Syst Rev. 2012;(6):CD000259.
5.HHS Office of Inspector General. General Compliance Program Guidance. November 2023
Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved
