Guided tools that build your NDIS policies and procedures from your answers. Created by an NDIS auditor.
Explore the tools →Support Coordinators are often surprised to receive non-conformities at audit relating to participant risk assessments.
The most common explanation is straightforward: because we don’t provide direct care, individual risk assessments don’t apply.
While understandable, this interpretation doesn’t align with how the NDIS Practice Standards are assessed in audits.
What the Standards actually require
The NDIS Practice Standards require that, in collaboration with each participant:
- Risk assessments are regularly undertaken and documented in support plans
- Appropriate strategies are planned and implemented to manage identified risks
The Standards also states that risk assessments need to include consideration of:
- The degree to which participants rely on the provider’s services to meet their daily living needs
- The extent to which participants’ health and safety would be affected if those services were disrupted
These requirements are not limited to direct care services.
Why this applies to Support Coordination
Although Support Coordinators don’t generally also deliver hands-on supports, the services they provide can be critical to a participant’s wellbeing, continuity of care, and access to essential supports.
From an audit perspective, the key question is not whether you provide direct care, but rather: what risks exist for this participant if your service is disrupted, unavailable, or poorly managed?
If a participant relies heavily on their Support Coordinator to navigate services, manage providers, or respond to changes, the absence of individual risk assessment is difficult to justify.
In practice
In audits, risk assessment gaps for Support Coordination often arise where:
- Participants rely on a single coordinator with no documented backup arrangement
- There is no clear handover process if a coordinator leaves or is unavailable
- Participants have high or complex needs and no documented contingency planning
- Organisational risk registers exist, but individual participant risks have not been considered
Auditors will usually look for evidence that these risks have been identified and that appropriate strategies have been agreed and documented.
It is important to remember that participant risks are separate from your business risks, which you can learn more about in our guide on how to build a risk register for your NDIS business.
What should be included in a Support Coordination risk assessment
Risk assessments for Support Coordination don’t need to be complex, but they should be participant-specific.
Common areas to consider include:
- Reliance on a single coordinator
- Continuity of service arrangements
- Escalation pathways if issues arise
- Impact on the participant if coordination support is interrupted
Where risks are identified, strategies should clearly link back to the participant’s circumstances.
If no risks are identified
If, after completing a risk assessment, you determine that there are no or minimal risks for a participant (which is certainly possible), that outcome should still be documented.
From an audit perspective, a recorded entry stating ‘no risks identified’ demonstrates that the requirement has been considered, and a risk assessment process has been applied.
This is far preferable to having no evidence at all.
What auditors are looking for
Auditors are not expecting Support Coordinators to manage clinical or direct care risks. They will however be looking for confirmation that participant-specific risks have been considered and the reliance on coordination services has been assessed.
A simple, well-documented risk assessment often prevents avoidable non-conformities later.
About the author
Penny Halpin
Penny is an NDIS Lead Auditor who has worked in certification since the first audits in 2018, and was previously a Senior Manager at an Approved Quality Auditor with technical review across thousands of audit reports. She built the Paperbark tools to help providers create documentation that reflects how they actually work.
More about Penny →