Policies, quality and risk
How this manual is kept current and used, the self-audit, quality improvement, risk management and insurance.
Version 1 · approved 23 Sept 2026 by Sam Nguyen
This manual
This manual covers how the pharmacy operates, how it is governed and every service it provides.
Legal requirement VPA Standard 1.4.1 · VPA Guidelines G1.4.1
Approving the manual
It should be approved by the licensee, or someone they delegate, before it is used. Each policy shows when it was approved and by whom.
Regulator guidance VPA Guidelines G1.4.2
Keeping it current
Each policy should be reviewed at least every two years, and sooner after a change in how a service is delivered, an incident, a complaint or a near miss, or a change in the law or the standards. Only the current version should be in use. Earlier versions are kept, clearly marked as superseded, for reference.
Regulator guidance VPA Standard 1.4.2 · VPA Guidelines G1.4.2
Knowing and following the procedures
Every staff member should know where to find the current procedures for their role and be able to read them at any time. New staff should be taken through the relevant procedures at induction, and this should be recorded. The licensee should make sure that compliance with procedures is watched and recorded, and that lapses are dealt with promptly. Day-to-day, the pharmacist in charge does this for them.
Regulator guidance VPA Standard 1.4.3 · VPA Guidelines G1.4.3
The VPA self-audit
The pharmacy should complete the VPA self-audit twice a year while services are new, and for high-risk areas, and at least once a year once they are established. The licensee should review every finding, and each problem should become an action with a person responsible and a due date.
Regulator guidance VPA self-audit form (Introduction)
Improving the service
Feedback, incidents, audits and spot checks should be used to find ways to make services safer and better. Each improvement should be documented — what was found, what will change, who will do it, by when, and whether it worked.
Regulator guidance VPA Standard 1.5.1 · VPA Guidelines G1.5.1 · VPA self-audit 1.5.1
Risk management
A risk register should list the main risks for each service the pharmacy provides — professional, legal, financial and reputational — and what is done to reduce each one. It should be reviewed regularly — here, at least once a year and after any serious incident — and staff should be told about the risks relevant to their work. Where ours is kept: not yet recorded.
Regulator guidance VPA Standard 1.5.3 · VPA Guidelines G1.5.3 · VPA self-audit 1.5.3
Business continuity
There should be a plan for keeping patients safe and staying within the law if something disrupts the pharmacy — a power or IT outage, a flood or fire, or the loss of key staff — including an emergency procedure. Where it's kept, alongside the risk register: not yet recorded.
Regulator guidance VPA Guidelines G1.5.3
Insurance
The pharmacy should hold public liability and other appropriate business insurance. Every pharmacist working here should be covered by professional indemnity insurance that meets the Board's standard — their own, or the pharmacy's.
Regulator guidance VPA Guidelines G1.5.3 · PBA Guidelines on the safe provision of pharmacy services s1 (from 1 Oct 2026)
Checks that go with this policy
- Risk register review — Yearly
- VPA self-audit — Every 6 months
PharmPolicy supports compliance. It is not legal advice, and it does not replace the licensee's own judgement or obligations under the Pharmacy Regulation Act 2010 and other laws.