Skip to content
Paperbark NDIS
Open menu

Guided tools that build your NDIS policies and procedures from your answers. Created by an NDIS auditor.

Documentation

How to Write a Risk Register for Your NDIS Business

by Penny Halpin |

A risk register gets talked about often in the context of NDIS audits. But framing it purely as an audit requirement can produce the kind of register that doesn’t serve anyone well: created once, filed away, and then never looked at again.

The providers who get the most out of a risk register treat it as a live record of the things that could go wrong in their business and what they’re doing about them. It’s useful for making operational decisions, onboarding new staff, reviewing insurance, and planning for growth. The audit just happens to be a moment when someone external checks whether you’ve been doing this properly.

This guide covers what belongs in an organisational risk register, what tends to get overlooked, and how to keep it useful over time.

What is an Organisational Risk Register (and What It Isn’t)

Before getting into how to build one, it’s worth being clear about what an organisational risk register actually is, because this is confusing for many providers.

Your organisational risk register captures the risks your business faces in operating as an NDIS provider. This includes things like viability, staff turnover, IT failure, regulatory changes, insurance gaps, and key person dependency. These are the risks that could affect your ability to keep delivering services safely and sustainably.

This is different from:

  • Your risk management policy: describes how your organisation approaches risk management as a system (the principles, the process, and the governance)
  • Individual participant risk assessments: capture risks specific to each participant’s support needs, health, and circumstances. (Side note: Support Coordinators still need risk assessments for their participants.)

All three are part of a complete risk management system, but they serve different purposes and live in different documents. Conflating them, or trying to do all three in one document, can weaken the overall system.

This article focuses on the organisational risk register. It’s the document that most directly evidences the Risk Management standard at both Verification and Certification audits.

Why Auditors Look at Your Risk Register Carefully

The NDIS Practice Standards require that risks are identified, analysed, prioritised, and treated through a documented system that is proportionate to your organisation’s size, scope, and the complexity of the services you deliver.

A sole trader delivering therapeutic supports and a 50-person SIL provider will have genuinely different risk profiles. The risks, ratings, and controls should reflect that. A small household tasks provider with 45 risks lifted from a large organisational template, including items about managing a board of directors, can end up working against you, because it suggests the document hasn’t been read and owned at all.

The same applies the other way. A five-row register for a provider delivering high intensity daily personal activities amongst other supports, where the risk environment is genuinely complex, leaves a lot unexplained.

The goal is a register that clearly belongs to your business.

What Your Risk Register Needs to Include

A well-structured NDIS organisational risk register typically includes the following for each identified risk:

1. Risk description A clear statement of what the risk actually is. Not just “staff” or “compliance”, but something like “Key person dependency: our sole director holds all operational knowledge and client relationships, and we have no documented succession plan.”

The more specific the description, the more credible the register. Vague descriptions suggest a risk has been named but not genuinely considered.

2. Risk category Not a strict necessity, but grouping risks by category makes a register easier to review and helps ensure you’ve covered the main areas. At a minimum, the Risk Management standard for Certification requires that you manage risks in the following areas:

  • incident management;
  • complaints management and resolution;
  • financial management; 
  • governance and operational management;
  • human resource management; 
  • information management; 
  • work health and safety; 
  • emergency and disaster management.

3. Likelihood rating How probable is it that this risk will occur? Is it rare, unlikely, possible, likely, or almost certain? What matters is that the rating reflects consideration, not a default answer of unlikely for every entry.

4. Consequence rating If this risk were to occur, how significant would the impact be? Insignificant, minor, moderate, major, catastrophic? Consider impacts on participants, on your ability to operate, on your workforce, and on your registration.

5. Overall risk rating The combination of likelihood and consequence, usually expressed through a risk matrix. This produces a priority level (typically low, medium, high, or critical) that guides how urgently you need to act.

6. Existing controls What do you already have in place that reduces either the likelihood or the consequence of this risk? Be specific. E.g. “Annual manual handling refresher training documented on each worker’s personnel file”.

7. Residual risk rating After your existing controls, what is the remaining level of risk? This is an important area that many providers miss. The whole point of controls is to reduce risk, so your residual rating should generally be lower than your initial rating. If it isn’t, that signals your controls might not be enough.

8. Further actions required If the residual risk is still higher than acceptable, what additional actions are needed? Who is responsible, and by when? This is how your register can become a live management tool rather than a static document.

9. Review date When will this risk be reviewed? Risks don’t stay static over time, your operating environment changes, new risks emerge, and existing controls become outdated. A register with no review dates (or with review dates that have passed without any updates) tells an auditor the document has been created and filed but not actively maintained.

Risks That Are Easy to Overlook

There are a few gaps that tend to come up repeatedly in NDIS risk registers, because they’re easy to forget when you’re focused on the day-to-day of running a service.

Key person dependency Particularly common for sole traders and small businesses. If you are the only person who knows how to operate your business (the only one with system access, client relationships, and operational knowledge), what happens if you’re ill, injured, or otherwise unavailable? This is a genuine and significant risk for many NDIS providers.

Regulatory and policy change The NDIS is a scheme under significant and ongoing reform. Changes to Practice Standards, pricing arrangements, registration requirements, or government policy can seriously affect your business. Providers who don’t document this risk and their approach to monitoring and responding to changes are leaving an obvious gap.

Worker screening lapses NDIS Worker Screening clearances expire. If your system for tracking expiry dates isn’t robust, a clearance can lapse without anyone noticing, which is both a compliance breach and a genuine participant safety risk. Many providers don’t have this risk explicitly documented in their register.

Data breach and privacy You hold sensitive information about participants, such as health conditions, support needs, and financial details. A data breach or privacy incident is a real and increasingly common risk.

Subcontractor and third-party risks If you engage subcontractors or work with other providers in delivering supports, their conduct reflects on you. The risks associated with those relationships (e.g. screening, competency, and conduct) should be somewhere in your risk framework.

Underinsurance Insurance requirements change, business circumstances change, and coverage that was adequate when you first registered may no longer be.

What a Well-Maintained Register Tends to Look Like

There are a few things that tend to distinguish a register that clearly belongs to a real, operating business from one that’s been downloaded and filed away.

The risks reflect your actual service context. A speech pathologist’s register should look different to a SIL provider’s. The risks, ratings, and controls should make sense for what you actually do.

The controls are specific. Generic controls like “training provided” or “policies in place” aren’t useful. Real controls name the specific mechanism: who does what, how often, and how it’s evidenced.

The review history is visible. A register that’s been actively maintained tends to show signs of that, like risks added or removed over time, ratings updated, completed actions noted, and new review dates set. A register where every row carries the same creation date and nothing has changed since is harder to point to as a living document.

It’s proportionate. Five risks for a high-intensity provider looks under-done. Eighty risks for a sole trader cleaner looks copied. The right number is the number that genuinely reflects your operating environment (and if that’s truly eighty, definitely document them!).

It connects to your other systems. Risks related to incidents should reference your incident management process. Risks related to workforce should reference your HR procedures. A risk register that exists in isolation from the rest of your quality system is harder to defend at audit.

How Often Do You Need to Review It?

At minimum, your risk register should be reviewed annually.

You should also review it when:

  • A significant incident occurs that wasn’t captured as a risk
  • Your business circumstances change materially (e.g. new service type, new location, or change in staff)
  • A new regulatory or policy change affects your operating environment
  • A near-miss or complaint reveals a risk gap

The review doesn’t need to be a lengthy exercise. A structured run-through of each row is generally sufficient, e.g. are the controls still current? Has the rating changed? Are actions completed? Document that you completed the review, when, and whether any changes were made (even if the answer is “no changes required”).

Free Tool: Build Your Risk Register

Rather than starting from a generic template and deleting what doesn’t apply, our free Risk Register Builder guides you through questions about your specific service context (e.g. the types of supports you deliver, your team structure, and your operating environment) and generates a draft risk register that actually reflects your business. No sign-up required.

Frequently Asked Questions

Is a risk register required for Verification providers?

Yes. Risk management is one of the four standards assessed in the Verification Module, and a documented risk register is a key piece of evidence auditors look for. The depth and complexity of the register should be proportionate to your business size and service type (i.e. a sole trader providing therapeutic supports doesn’t need the same document as a large provider) but you should definitely have one.

Can I use the same risk register for both my organisational risks and participant-specific risks?

It’s generally cleaner to keep them separate. Organisational risks and participant-specific risks serve different purposes, are often maintained by different people, and are reviewed in different contexts. Combining them can produce a document that does neither job well. Your organisational register covers business-level risks; participant risk assessments sit in each participant’s file.

What format does a risk register need to be in?

There’s no prescribed format, so whatever works best for you! A well-structured spreadsheet works for most providers. What matters is that the content is there (risk description, ratings, controls, residual rating, review information). A simple, honest, well-maintained spreadsheet is far preferable to a polished template with placeholder risks.

How many risks should be in my register?

There’s no required number. The right answer is however many genuinely apply to your business.

What happens if my risk register has gaps at audit?

Gaps in your risk register, or a register that clearly hasn’t been maintained, might result in a non-conformance against the Risk Management standard. It doesn’t mean you’ve ‘failed’ your audit, but it will require a corrective action plan and may delay your registration outcome. Getting the register right before your audit is less stressful than correcting it under time pressure afterwards.

About the author

Penny Halpin

Penny is an NDIS Lead Auditor who has worked in certification since the first audits in 2018, and was previously a Senior Manager at an Approved Quality Auditor with technical review across thousands of audit reports. She built the Paperbark tools to help providers create documentation that reflects how they actually work.

More about Penny →