← Back to blog

NDIS Audit Checklist for Providers: 90/30/365 Plan

August 10, 2026
NDIS Audit Checklist for Providers: 90/30/365 Plan

Be audit-ready today: have a mapped folder of policies aligned to the NDIS Practice Standards, three months of populated registers, current worker screening records, and a documented 90-day remediation plan. Those four items are what auditors reach for first.

The four non-negotiables on audit day:

  • Policies mapped to NDIS Practice Standards outcomes — every policy in your register must reference the specific outcome it satisfies; auditors cross-check the policy register against the Core Module outcomes list.
  • Several months of populated evidence — participant files, incident registers, complaints logs, and support notes must show real, dated entries; an empty register is an automatic finding.
  • Current worker screening records — NDIS Worker Screening Check clearances, training completion records (including the NDIS Worker Orientation Module), and police checks must be in date and filed in each staff member's folder.
  • A documented 90-day remediation plan — auditors want to see that you identified gaps and acted on them; a written plan with named owners and completion dates signals a functioning governance culture.

Three things to do in the next 24–72 hours:

  1. Pull every policy document and check whether it references an NDIS Practice Standards outcome. Flag any that do not.
  2. Open your incident and complaints registers and count the entries for the last 90 days. If either is blank, that is a gap to fix before anything else.
  3. Print or export your worker screening register and highlight any clearances nearing expiry. Assign a staff member to chase renewals today.

Key Takeaways

Providers who embed compliance into daily operations — not just pre-audit sprints — consistently produce fewer findings and better participant outcomes.

PointDetails
Four audit-day non-negotiablesMapped policies, 3 months of populated registers, current worker screening records, and a written 90-day remediation plan.
Start 90 days outUse a three-phase approach: diagnose (Days 1–30), remediate (Days —), mock audit and verify (Days —).
Six highest-risk areasIncident reporting, worker screening, participant files, restrictive practices, complaint handling, and governance records.
Daily compliance habitA 10-minute Friday register check keeps incidents and complaints current and closes the most common audit gap.
ChampionbusinesscoachingOffers a 90-day NDIS audit preparation coaching program with templates, mock audits, and a results guarantee for Australian providers.

Table of Contents

What does your NDIS audit checklist need to include?

Auditors arrive with a structured evidence framework. The documents below map to the Core Module outcomes and to the NDIS Code of Conduct, which asks providers to embed the Code's eight elements into policies, training, and HR arrangements.

Core document categories:

  • Governance framework (org chart, board/management structure, delegations register)
  • Policy and procedure register (version number, review date, owner on every document)
  • Service agreements linked to individual participant NDIS plans
  • Support plans and participant files (goals, risk assessments, consent forms)
  • Incident and complaints registers with investigation notes and corrective actions
  • Worker files (screening clearances, qualifications, induction records, training logs)
  • Evidence of service delivery (support notes, case notes, invoices, attendance records)
  • Privacy policy, data-security controls, and access-log records

Per the NDIS provider responsibilities guidance, providers must keep accurate records, issue invoices after supports are delivered, and comply with NDIS pricing arrangements. Auditors will sample invoices against support logs to verify this.

DocumentWhere auditors lookMinimum evidence period
Policy registerShared drive or document management systemCurrent version; review date within 12 months
Incident registerCase management or compliance software12 months of entries
Complaints registerSame system as incidents12 months of entries
Worker screening recordsStaff HR filesCurrent clearance; flag renewals 6 months out
Support notes / case notesParticipant files3 months minimum; 12 months preferred
Service agreementsParticipant filesCurrent and signed by participant or nominee
Training recordsStaff HR filesCompletion dates; certificates attached
InvoicesFinance system12 months; matched to support logs

Pro Tip: Organize your audit bundle into labeled folders by audit area (Governance, Participant Files, Worker Files, Incidents, Complaints) before the auditor arrives. Auditors who can navigate your evidence without asking questions tend to find fewer gaps.

What does your NDIS audit checklist need to include? — overview diagram

Which NDIS Practice Standards and audit modules apply to you?

NDIS audits follow a structured framework built around four module categories, and which one applies to your organization determines the scope of evidence you need to prepare.

  • Core Module — applies to most registered providers; covers rights and responsibilities, governance, support planning, and service delivery.
  • Supplementary Modules — apply on top of the Core when you deliver specific support types (e.g., specialist behavior support, early childhood, SDA, high-intensity daily activities).
  • Verification — a desktop-based audit for lower-risk registration groups; requires documented policies and procedures but no on-site interviews.
  • Certification — a full on-site audit for higher-risk supports; includes staff interviews, file reviews, and participant consultations.
Provider typeLikely audit pathwayKey evidence focus
Plan management onlyVerificationFinancial records, invoices, pricing compliance
Support coordinationCertification (Core)Participant files, service agreements, support plans
SDA / SIL providerCertification (Core + Supplementary)Physical environment, behavior support, incident records
Behavior support practitionerCertification (Supplementary)Restrictive practice documentation, training, supervision
Small allied health / therapyVerification or Certification (Core)Qualifications, service agreements, clinical notes

Small providers delivering lower-risk supports face proportionate expectations. A sole trader running plan management will not be assessed against the same evidence volume as a 50-person SIL provider, but the quality bar for what evidence exists is identical.

How to build a realistic 30/90/365-day audit preparation plan

Starting 90 days out with a three-phase approach — diagnose, remediate, verify — is the most effective way to reduce non-conformances and walk into the audit with confidence.

Role assignments for small providers: If you do not have a dedicated compliance officer, the CEO or owner takes the diagnostic and verification phases. Assign admin staff to document control and register maintenance. Team leaders own worker file completeness for their direct reports.

For the 365-day ongoing cycle, a monthly 30-minute governance meeting reviewing the incident register, complaints log, and any policy due for review is enough to stay continuously compliant without heavy overhead.

What causes non-conformances? The six high-risk audit areas

The NDIS Commission's compliance and enforcement approach is proportionate but firm. These six areas generate the most findings across Australian providers.

  • Incident reporting and reportable incidents — late notifications, missing investigation notes, or corrective actions not documented. Auditors check the date of the incident against the date of notification.
  • Worker screening gaps — expired clearances, missing NDIS Worker Orientation Module certificates, or contractors treated as exempt when they are not.
  • Incomplete participant files — service agreements not signed, support plans not updated after a participant's goals change, or risk assessments missing.
  • Restrictive practices — any unauthorized restrictive practice without a behavior support plan, or a plan that has not been reviewed within required timeframes.
  • Poor complaint handling — complaints logged but no investigation documented, or no evidence the participant was informed of the outcome.
  • Governance and record-keeping — policies with no review date, an org chart that does not match actual staffing, or no evidence of a governance meeting in the last 12 months.

Pro Tip: Date-stamp every entry in your incident and complaints registers at the time of the event, not when you write it up later. Auditors compare entry timestamps to notification timestamps. A gap of several days with no explanation is a finding waiting to happen.

How to keep records that actually stand up in an audit

The minimum evidence standard is: contemporaneous, dated, author-identified, and version-controlled. A support note written three weeks after the session does not meet that standard.

TemplateKey fieldsStorage requirement
Support noteDate, time, participant ID, support delivered, author, signatureParticipant file; access-restricted
Incident reportDate/time, description, immediate action, reportable assessment, notification dateIncident register; version-controlled
Corrective action logFinding, root cause, action, owner, due date, completion dateGovernance folder
Training recordStaff name, training title, date completed, certificate referenceStaff HR file
Policy sign-off sheetPolicy name, version, staff name, date signedPolicy register

Access controls matter as much as the records themselves. Auditors will ask who can edit your incident register and whether there is an audit trail. Cloud-based systems with role-based permissions and automatic version history satisfy this requirement. For systemized document control, every document needs a version number, a review date, and a named owner before it goes into the register.

Worker screening, training, and supervision: what auditors check

Required checks for every worker (employees, contractors, and volunteers in risk-assessed roles):

  • NDIS Worker Screening Check clearance (mandatory for risk-assessed roles)
  • Working With Children Check where the provider delivers supports to participants under 18
  • Qualification verification for regulated roles (e.g., registered nurses, behavior support practitioners)
  • NDIS Worker Orientation Module completion certificate
Check typeExpiryRenewal trigger
NDIS Worker Screening Check5 yearsFlag at 5 years; initiate renewal 6 months before expiry
Working With Children CheckVaries by stateMonitor per state rules; flag 6 months out
NDIS Worker Orientation ModuleNo expiry; one-timeConfirm completion at induction
First aid certificate3 years (CPR annually)Flag at 3 years

Contractors and volunteers carry the same evidence requirements as employees for risk-assessed roles. A common audit finding is a provider who has robust employee records but no screening evidence for their regular contractors. Supervision records — meeting notes, observation logs, or sign-off on support plans — must also sit in each worker's file.

Managing incidents, reportable incidents, and complaints

Auditors expect a complete incident register, evidence of timely reportable-incident notifications, and documented investigations with corrective actions. The flow is: identify the incident, take immediate action, assess whether it is reportable, notify the NDIS Commission within 24 hours if it is, investigate, and close with a corrective action.

Reportable incidents include unexpected death, serious injury, abuse, neglect, unlawful sexual contact, and unauthorized restrictive practices. The 24-hour notification window is a hard deadline auditors check against the incident date in your register.

Common audit fail points for incidents:

  • Notification date recorded but no evidence of submission to the Commission's portal
  • Investigation notes missing or written as a single sentence
  • Corrective action listed but no completion date or evidence the action was taken
  • Complaints handled informally with no register entry

Pro Tip: When assembling your audit bundle for incidents, include the register entry, the Commission notification confirmation (a portal reference number or email), the investigation summary, and the corrective action log entry as a single linked set. Auditors who can trace the full lifecycle of an incident in under two minutes rarely raise a finding on process.

How to run a self-assessment before your official audit

Run a documented mock audit at least 30 days before certification, using a scoring tool with a named remediation owner for every fail. The LexisNexis NDIS compliance checklist provides a structured "Yes / Don't know / Needs work" format across participant supports, governance, worker rules, and complaints — a practical starting point for your self-assessment.

Scoring categories:

  1. Pass — evidence is complete, current, and correctly filed.
  2. Minor non-conformance — evidence exists but has a gap (e.g., policy not reviewed in 18 months instead of 12).
  3. Major non-conformance — evidence is missing or the control does not exist.

Top eight mock-audit fail points and quick fixes:

  1. Policies with no review date — add a review date and owner to every document header today.
  2. Incident register with gaps in the investigation column — write up outstanding investigations before the mock audit.
  3. Worker files missing NDIS Worker Orientation Module certificates — email staff for screenshots of completion today.
  4. Service agreements not signed by the participant or their nominee — contact participants and get wet or digital signatures.
  5. No evidence of a governance or management meeting in the last 12 months — hold one, minute it, and file the minutes.
  6. Corrective actions listed with no completion evidence — close out open actions and document the outcome.
  7. Support notes written in bulk rather than contemporaneously — brief staff on the standard before the official audit.
  8. Complaints register empty — confirm with staff that informal complaints are being logged; if not, run a 30-minute training session.

For staff interview prep, brief your team on three things: where the policies are stored, how to report an incident, and what the Code of Conduct requires of them. Auditors ask these questions directly.

What to do if you receive a compliance notice or adverse finding

Immediate steps on receipt of a notice:

  1. Acknowledge receipt in writing to the NDIS Commission within the stated timeframe.
  2. Secure all relevant evidence — do not alter or delete any records.
  3. Identify and stop any ongoing risk to participants immediately.
  4. Notify affected participants if the finding relates to their supports, and document that notification.
  5. Assign a named owner to the corrective action plan within 24 hours.

Drafting your corrective action plan:

  • State the finding verbatim from the notice.
  • Identify the root cause (not just the symptom).
  • List each corrective action with a named owner and a completion date.
  • Include a monitoring step to verify the action worked.
  • Submit the plan within the Commission's stated deadline and keep a copy with the submission confirmation.

The Commission's compliance and enforcement framework includes a range of tools from education and compliance notices through to banning orders. Providers who respond promptly with a credible corrective action plan typically resolve findings at the notice level without escalation. Keep every piece of correspondence with the Commission in a dedicated compliance folder, dated and filed in order.

Why compliance culture beats a last-minute checklist every time

Most providers treat audit preparation as a sprint. The ones who rarely get findings treat it as a Tuesday.

The difference is not a better checklist. It is whether your team knows where the policies are, logs incidents the same day they happen, and treats a signed service agreement as a standard part of onboarding rather than a box to tick before the auditor arrives. Compliance embedded in daily operations improves participant outcomes as a direct side effect — not as a compliance goal, but because the habits that satisfy auditors (clear records, prompt incident response, regular supervision) are also the habits that make support delivery safer and more consistent.

One practical tip: schedule a 10-minute end-of-week register check every Friday. One person, five minutes on the incident log, five minutes on the complaints log. If both are current and complete, you are done. That single habit closes the most common audit gap before it opens.

Providers who want structured support building these habits can work with Championbusinesscoaching's NDIS coaching program, which is designed specifically for Australian providers navigating compliance and growth simultaneously.

Championbusinesscoaching helps NDIS providers get audit-ready faster

Audit preparation is one of the most time-consuming compliance tasks a small provider faces, and most of the stress comes from not knowing what "good enough" looks like until the auditor tells you it is not.

Championbusinesscoaching

Championbusinesscoaching works with Australian NDIS providers through a structured 90-day audit preparation coaching program that covers gap analysis, policy templates, mock audits, and staff briefing guides. The program is built for small-to-medium providers who need practical results without a full-time compliance team. Rated 5 stars on Google, the coaching is backed by a 90-day guarantee: results or your session is free. If you want to walk into your next audit with a complete evidence folder and a team that knows what to say, book a free consultation and get a clear action plan within the first session.

Sources

These are the primary official sources referenced throughout this article. Each one is worth bookmarking.