Skip to content
Paperbark NDIS
Open menu

Guided tools that build your NDIS policies and procedures from your answers. Created by an NDIS auditor.

Documentation

How to Test Your NDIS Emergency Plan

by Penny Halpin |

The NDIS Practice Standards don’t just require you to have an emergency plan, they expect you to demonstrate that the plan actually works.

This means your team knows what to do, that the procedures hold up under pressure, and that you’ve identified gaps before a real emergency forces you to find them the hard way.

The good news is that testing doesn’t have to be complicated or expensive. You don’t need to stage a fake evacuation or simulate a natural disaster. You just need to be deliberate about checking whether your plan does what it’s supposed to do.

If you haven’t actually written your plan yet, our guide on NDIS emergency planning for small providers might be useful.

Why testing matters (beyond passing your audit)

Let’s set the audit aside for a moment – the real reason to test your emergency plan is that untested plans fail.

A plan might look thorough on paper but fall apart in practice. The emergency contact number is out of date, the evacuation procedure assumes a staff member who no longer works for you, the lockdown process doesn’t account for a participant who can’t move quickly. The plan says to call your manager, but nobody has their mobile number saved – whoops.

These aren’t hypothetical problems. The plan might it exist, but the people who would need to use it either haven’t read it, don’t understand it, or would discover critical gaps the moment they tried to follow it.

Testing is how you find those gaps on your terms, not during a real emergency when the stakes are someone’s safety.

What auditors are actually looking for

When auditors assess emergency and disaster management, we’re not expecting providers to have run elaborate simulations. We’re looking for evidence that you’ve done three things:

  1. Checked whether the plan works in practice: not just reviewed the document, but actually thought through or practised what would happen if you needed to use it
  2. Involved the people who would need to use it: whether that’s your staff, your participants, or both
  3. Used what you learned to improve the plan: testing that doesn’t lead to any changes or observations suggests it may not have been done meaningfully

The evidence can be simple, such as a documented record of a tabletop exercise, notes from a scenario walkthrough at a team meeting, or a log entry showing you updated the plan after testing revealed a gap. What matters is that the testing was genuine and that you can show it happened.

Four practical ways to test your emergency plan

1. Tabletop exercises

A tabletop exercise is exactly what it sounds like. You sit down and talk through an emergency scenario step by step. No running around, no props, no disruption to services, instead just a structured conversation about what you’d do.

How to run one:

Pick a realistic scenario. Don’t go with something dramatic and unlikely, choose something that could genuinely happen in your service. This might be a severe storm warning while you’re delivering community access supports., a participant having a seizure during a session, or a fire alarm going off in the building where you run a group activity.

Then walk through it. What’s the first thing you do? Who do you contact? What information do you need and where is it? What do you do with or for the participant? And what happens if your first option isn’t available – the road is blocked, the phone doesn’t connect, the usual meeting point isn’t safe?

For solo operators: You can do this on your own. Set aside 20 minutes, pick a scenario, and genuinely think through your response step by step. Write down what you’d do and note anything that made you pause or where you realised you didn’t have a clear answer.

For small teams: Run it at a team meeting. Present the scenario and let staff talk through the response together, and you’ll quickly find out whether people know the plan, whether they’d do the same things, and where there’s confusion or disagreement. Those conversations are incredibly valuable.

Document it: Record the date, who participated, what scenario you used, what you discussed, and what gaps or improvements you identified. This is your audit evidence.

2. Scenario walkthroughs with participants

Your emergency plan affects your participants directly, and the Practice Standards expect that participants are informed about emergency procedures. Testing is a natural opportunity to check whether that’s actually happened.

This doesn’t need to be formal or intimidating! It can be a conversation during a regular support session:

“I want to make sure we’re both prepared if something unexpected happens while we’re together. If there was a medical emergency during our session, here’s what I’d do… Does that make sense? Is there anything about your situation I should know that would change how I’d respond?”

For participants in shared living or group settings, you might walk through an evacuation route together, or talk through what would happen if there was a power outage overnight.

What you’re checking: Do participants know what to expect? Are there participant-specific needs you haven’t accounted for in your plan? Would your procedures actually work for the people you support, given their communication, mobility, health, and behavioural needs?

Document it: Note that the conversation happened, what you covered, any participant-specific considerations that came up, and any changes you made to the plan as a result.

3. Practical checks

Some parts of your emergency plan can be tested without running a full scenario, but you need to check whether the practical elements are in place and working.

Things to check:

  • Are emergency contact numbers current and accessible? Could you find them quickly under pressure?
  • Do you have first aid supplies, and are they stocked and in date?
  • If your plan references specific equipment (torch, phone charger, emergency kit in your car), is it actually there?
  • If you have evacuation routes or meeting points, are they still accessible and appropriate?
  • Can you access participant emergency information (e.g health conditions, emergency contacts, specific needs) quickly if you need it? What if your phone or system is down?
  • If your plan relies on contacting a specific person as a backup (a colleague, a manager, a family member), do they know that’s their role? Do they have the information they’d need?

These checks take minutes but they catch the kind of practical failures that make a plan useless in a real emergency.

Document it: Keep a simple log: what you checked, when, and whether anything needed updating.

4. Post-incident reviews

If you’ve actually experienced an emergency or a near-miss, even a minor one, that’s the most valuable test your plan will ever get. What happened? Did you follow the plan? Did it work? What would you do differently?

This doesn’t have to be a formal investigation. For a one-person provider, it might be sitting down after the event and honestly reflecting on how the response went. For a team, it’s could be a debrief conversation.

The key questions:

  • Did the plan cover this situation, or did we have to improvise?
  • Was the response effective? Were participants safe throughout?
  • Did everyone involved know what to do?
  • Were there any gaps, e.g. missing information, unavailable contacts, unclear procedures?
  • What should we change in the plan based on this experience?

Document it: Record the incident (this connects to your incident management process), what you learned about the emergency plan’s effectiveness, and what changes you made as a result. This shows the plan is genuinely being used and improved.

How often should you test?

There’s no magic number prescribed in the Practice Standards, but here’s a practical approach:

At minimum, annually. Run at least one tabletop exercise or scenario walkthrough each year. If you’re a sole trader, this might be a 20-minute exercise you schedule alongside your annual plan review. For a team, build it into a team meeting once a year.

After any real incident or near-miss. If your plan was activated, even partially, do a post-incident review. This is both the most valuable form of testing and the easiest to justify to an auditor.

When something significant changes. Including new participants with different needs, new service locations, new staff who haven’t been through the plan. Any of these should trigger at least a targeted review and walkthrough of the affected parts of your plan.

When you onboard new staff or participants. Walking a new staff member through emergency procedures is a form of testing. You’ll quickly find out whether the plan is clear enough for someone who hasn’t seen it before. Same with participant conversations at the start of services.

A note on what testing is not

Reviewing the document is not testing. Reading through your plan and confirming it still looks right is a review, not a test. Reviews are important, and you need to do them, but they don’t check whether the plan works in practice.

Updating the date on the front page is not testing. The plan has a ‘reviewed’ date that’s been updated, but nothing else has changed and there’s no record of how it was reviewed or tested.

Ticking a box on a checklist is not testing. If your annual review process is a checklist that says ’emergency plan reviewed – yes/no’ with no detail, that doesn’t really demonstrate meaningful testing. What scenario did you consider? What did you find? What changed?

Testing means engaging with the question: if this emergency happened right now, would this plan actually protect my participants?

Bringing it all together

Here’s a simple testing schedule that would satisfy most auditors and more importantly would actually make your emergency plan more reliable:

Annually: Run one tabletop exercise using a realistic scenario. Review and update the plan based on what you find. Document the exercise, findings, and any changes made.

Ongoing: Check practical elements (contacts, supplies, equipment, access to participant information) periodically. Have emergency conversations with new participants at the start of services. Walk new staff through the plan as part of induction.

As needed: Conduct post-incident reviews after any emergency or near-miss. Update and re-test affected procedures when significant changes occur.

Keep your documentation simple, e.g. a log or register that records the date, the type of test, who was involved, what was found, and what was changed is enough. You don’t need a separate report for every exercise, you just need to be able to show a clear trail of genuine testing over time.

The whole point is to find the gaps before a real emergency finds them for you.

About the author

Penny Halpin

Penny is an NDIS Lead Auditor who has worked in certification since the first audits in 2018, and was previously a Senior Manager at an Approved Quality Auditor with technical review across thousands of audit reports. She built the Paperbark tools to help providers create documentation that reflects how they actually work.

More about Penny →