Skip to content
Paperbark NDIS
Open menu

Guided tools that build your NDIS policies and procedures from your answers. Created by an NDIS auditor.

Systems and Processes

Governance for Small NDIS Providers

by Penny Halpin |

Governance refers to the arrangements that determine how decisions get made in your organisation, who is accountable for them, and how you know your service is doing what you say it does. It sits above day to day management, so where management runs the service, governance sets the direction, holds management to account, and carries responsibility when something goes wrong.

The NDIS Core Module, which you'll be audited against if you're on the Certification pathway, sets a governance outcome that's proportionate. Each participant's support is to be overseen by governance and operational management systems relevant to the size and scale of the provider, as well as the scope and complexity of the supports delivered.

In short, as a small provider you aren't expected to have the same arrangements as a large one, but you do need something.

Governance without a board

Whoever holds ultimate responsibility for the organisation is the governing body, whether that's a board of six, two directors, or one person operating on their own.

If you're a one person business, you're the governing body and management at the same time, and the requirements apply to you.

What the standard asks for

IndicatorWhat it can look like at a small scale
People with disability have opportunities to contribute to governance and to input into policy and processesStructured participant feedback that reaches decisions, rather than only a complaints form. Ask participants about your processes, record what they said, and record what changed
A defined structure to meet financial, legislative, regulatory and contractual responsibilities, and to monitor and respond to quality and safeguarding mattersWritten down: who decides what, what gets reviewed, how often, and how a quality or safeguarding issue reaches the person accountable
The skills and knowledge needed to govern effectively are identified, and relevant training addresses any gapsA skills assessment of yourself or your board, and a record of the training taken to close the gaps
Strategic and business planning considers legislative requirements, organisational risks, NDIS requirements, participant and worker needs, and the wider environmentA strategic plan that addresses each of these, and gets reviewed rather than written once
The performance of management is monitored, including responses to individual issues, to drive continuous improvementA review of how management is performing. Where you are management, an external perspective is worth seeking
The provider is managed by a suitably qualified or experienced person with clearly defined responsibility, authority and accountabilityA position description for the management role, held on file, including your own
A documented system of delegated responsibility and authority to another suitable person in the absence of the usual position holderA named person, in writing, with what they're authorised to decide
Perceived and actual conflicts of interest are proactively managed and documented, including through policiesA conflict of interest policy, a register with entries in it, and a way of raising them

Governing yourself

Monitoring the performance of management and delegating authority in your absence become trickier when you're the only person in the organisation.

Monitoring your own performance. Self-review can still be credible if it's structured, scheduled and written down, and if it uses evidence rather than impression. Set the questions in advance, hold yourself to a date, and record the answer. Consider engaging a mentor, a peer in another service, or an accountant or advisor for part of this, to provide perspectives other than your own.

Delegation. If you're unwell or unavailable at short notice, someone needs to be able to act. Decide who that is, tell them, and write down what they're authorised to decide. It's a governance indicator, and it also gives your continuity of supports arrangements something to rest on.

Governance and the Verification pathway

You won't be audited against the governance indicators if you're in the Verification pathway but the questions are still worth asking.

Deciding who is accountable for what, reviewing whether your service is working, planning beyond the next month, and managing conflicts of interest will all help to make your business stronger.

Governance obligations outside the NDIS

The NDIS Practice Standards aren't the only source of governance duties, and the standards don't cover everything that applies to your organisation.

If you operate through a company, directors have duties under the Corporations Act 2001, including duties of care and diligence, good faith, and not trading while insolvent. These apply to the sole director of a small company as well.

If you're incorporated as a charity, the ACNC Governance Standards apply, including requirements about responsible persons and financial management.

Work health and safety law places duties on officers of a business, which includes people who make or participate in decisions affecting a substantial part of it.

These sit alongside your NDIS obligations, it's not an either/or. Get advice from an accountant or a lawyer on what applies to your structure.

What good practice looks like at a small scale

  • A written statement of who decides what, including where your authority ends
  • A regular governance review, scheduled and recorded, separate from operational catch-ups
  • A set of things you look at every time: incidents, complaints, feedback, finances, worker matters, risks
  • A strategic plan you revisit rather than file
  • A skills gap assessment for whoever governs, with training recorded against it
  • A named delegate with documented authority
  • A conflict of interest register with entries in it
  • Evidence that participants have contributed to governance decisions, with a record of anything that changed
  • A decision log recording what you decided and why

Common oversights

Governance treated as a document rather than an activity. A governance policy on file, with no record of any governance taking place.

Nothing separating governance from operations. Everything discussed in the same conversation, with no point at which someone steps back and reviews the service as a whole.

Participant input that goes nowhere. Feedback collected and filed, with no record of a decision changing as a result.

No delegate named. This is a significant operational risk if you're a one-person business and are suddenly unavailable at short notice.

No conflicts of interest identified. Small providers do have conflicts, particularly where family members work in the business or where you refer to services you have an interest in.

Strategic plans written for the audit. A plan produced once, never reviewed, and describing a business that has since changed.

Paperbark's Certification Toolkit helps you build your governance and operational management policy and procedure, including delegations and conflict of interest, from your answers about how your organisation actually makes decisions.

About the author

Penny Halpin

Penny is an NDIS Lead Auditor who has worked in certification since the first audits in 2018, and was previously a Senior Manager at an Approved Quality Auditor with technical review across thousands of audit reports. She built the Paperbark tools to help providers create documentation that reflects how they actually work.

More about Penny →