Skip to content
Paperbark NDIS
Open menu

Guided tools that build your NDIS policies and procedures from your answers. Created by an NDIS auditor.

Profession Guides

What Policies Does a Counsellor Need for NDIS Registration?

by Penny Halpin |

Related: NDIS Registration for Counsellors

Policies and procedures are the documents that describe how your service operates, and if you undergo the registration process, they're the main thing your auditor reviews at a Verification audit. A policy sets out your position, a procedure sets out the steps you follow, and the forms and registers behind them help you maintain evidence that your procedures were followed.

The Verification module covers four specific standards that you'll need to cover with your policies and procedures.

StandardWhat you need
Human Resource ManagementA policy covering qualifications, records and training, plus your worker file: identity, right to work, professional body membership, qualifications, Worker Screening Check, Worker Orientation Module certificate, supervision and CPD records, and infection control and PPE training with refreshers
Incident ManagementA policy and procedure meeting the NDIS (Incident Management and Reportable Incidents) Rules 2018, an incident form, and a register
Complaints ManagementA policy and procedure meeting the NDIS (Complaints Management and Resolution) Rules 2018, a form, a register, and information for participants including how to complain to the Commission
Risk ManagementA documented risk management system covering work health and safety, your insurances, emergency and disaster planning, risk assessments considering participant reliance on your service, and infection control standard precautions

If a policy pack you're looking at buying includes governance, participant money and property, medication management or restrictive practices, those belong to the Core Module and a Certification audit. You don't need them if you're only registering for 0128 Therapeutic Supports.

Incident policies and procedures for Counsellors

The NDIS Incident Management Rules define an incident as an act, omission, event or circumstance that happens in connection with providing supports and has, or could have, caused harm to a person with disability.

If you're writing your own policies and proecdures, it's worth working through your work and considering what you may experience that would be considered an incident under the NDIS. Work out where this line sits for you and clearly include it in your procedure. Potential incidents that counsellors may need to record include:

  • A participant discloses abuse, neglect or exploitation, whether by a family member, a support worker or another provider
  • A participant expresses suicidal ideation or discloses self-harm
  • A mandatory reporting obligation is triggered
  • A confidentiality breach, such as an email to the wrong recipient, or notes visible to someone else during a telehealth session
  • A participant leaves a session in acute distress
  • An allegation about your conduct or a boundary concern
  • A participant discloses financial exploitation
  • A safety concern during a telehealth session where you don't know where the participant is

Once you're registered, the reportable incidents obligations apply to you, which is a narrower set of more serious incidents with notification timeframes to the Commission. Our guide on reportable incidents covers which incidents those are.

Risks worth having in a counselling risk register

A generic risk register might include participant transport and community access hazards, which tells an auditor nothing about how you're delivering your counselling supports. So make sure you develop a risk register that reflects the risks actually faced by you, your business, and participants. This may include:

  • Confidentiality and information sharing across support coordinators, plan managers, therapy teams and the NDIA
  • Professional boundaries and dual relationships, particularly in small communities
  • Supporting a participant in acute distress or expressing suicidal ideation
  • Mandatory reporting decisions
  • Vicarious trauma and practitioner wellbeing
  • Working alone, if you do home or community visits
  • Scope of practice, and knowing when to refer
  • Business continuity when you're the only practitioner
  • Technology and platform failure, if you deliver by telehealth

The Verification standard also asks you to consider how much a participant relies on your service and what would happen if it were disrupted. An unplanned break in therapy can matter more than an unplanned break in a cleaning service, so consider this seriously and document a plan.

Managing complaints

It's likely that you already have a complaints process if you're already working as a counsellor, but if you're registering with the NDIS you need to make sure your documents are updated to meet the requirements of the NDIS Complaints Rules.

The NDIS requires a complaints process a participant can use with you directly, plus information telling them they can go to the NDIS Commission instead. You may have separate avenues for complaints that you need to include as part of any professional memberships you have. There's no need to have two separate complaints policies, and adding in the relevant NDIS information to your existing documentation is fine.

Updating your existing documents

The following aren't Verification indicators, and you won't be assessed against them at your audit. However, you may already have existing policies in place for these areas, and it's worth making some updates to include information relevant to delivering counselling as an NDIS provider.

Your confidentiality policy. An NDIS participant may have a support coordinator wanting updates, a plan manager seeing your invoices, and a plan review where your notes become evidence. Set out what you share, with whom, and on what basis, and make sure you explain this to all participants.

Your information privacy/consent form. Consent to treatment isn't consent to collect, use, retain and disclose information. Name who information can go to, how the participant accesses or corrects it, and how they withdraw consent.

Your fee agreement. An NDIS service agreement should cover the supports to be provided, price guide rates, cancellation terms, whether the participant is agency-managed, plan-managed or self-managed, and what happens if their plan changes.

Your session notes. Progress notes should ideally show movement against the goals in the participant's plan.

These become audit requirements if you later add a registration group that moves you to Certification, where privacy and dignity, information management, service agreements and support planning are all Core Module standards.

Privacy law applies regardless of turnover

Small businesses turning over $3 million or less are generally exempt from the Privacy Act 1988, and health service providers are one of the exceptions. The OAIC states that small businesses which are health service providers are covered by the Act, and a counselling practice generally holds health information and provides a health service.

Several states and territories add their own health records legislation covering retention periods and client access rights, such as Victoria's Health Records Act 2001.

This sits outside the NDIS Practice Standards, and it's why your privacy and consent documents matter whether or not an auditor asks for them. Confirm your position with your professional body or a lawyer.

Our free toolkit

Paperbark's Verification Toolkit is free and helps you build the four Verification policies and their supporting forms and registers, directly from your answers about how your practice actually runs.


Meta description: What a counsellor is assessed against at NDIS Verification, what counts as an incident in a counselling practice, and what belongs in your risk register.

About the author

Penny Halpin

Penny is an NDIS Lead Auditor who has worked in certification since the first audits in 2018, and was previously a Senior Manager at an Approved Quality Auditor with technical review across thousands of audit reports. She built the Paperbark tools to help providers create documentation that reflects how they actually work.

More about Penny →