Guided tools that build your NDIS policies and procedures from your answers. Created by an NDIS auditor.
Explore the tools →Every provider going through a certification audit is assessed against the Core Module of the NDIS Practice Standards. The following article outlines the document set it requires, including the policies and procedures, the forms and registers that sit under them, and the records that show they are being used.
Treat this as a starting point, not an exhaustive list. The exact documents you need depend on your services, your registration groups and the scope of audit you are given, so use this as the baseline and confirm the specifics against your audit scope and with your own review of the Practice Standards.
If your registration groups include higher-risk supports, you’ll also need documents for one or more supplementary modules on top of the Core Module requirements below (which modules apply depends on your registration groups)
These are the areas your documentation has to cover, not a set of separately titled documents you must hold. An auditor checks whether your policies and procedures address each requirement, they’re not looking at whether you have a document with a specific name. As long as the content is documented somewhere, what you name a policy/procedure doesn’t matter.
Policies and procedures
Your policies state what your organisation does and why, and your procedures state how you do it. The Core Module groups what they need to cover into four areas. Writing them to reflect your actual practice is what the audit is checking for.
Rights and responsibilities:
- Person-Centred Supports. How supports are shaped around each participant’s goals and choices.
- Individual Values and Beliefs. How you respect each participant’s culture, identity and beliefs.
- Privacy and Dignity. How participant information and personal dignity are protected.
- Independence and Informed Choice. How participants are supported to make their own decisions.
- Violence, Abuse, Neglect, Exploitation and Discrimination. How you prevent, identify and respond to harm.
Governance and operational management:
- Governance and Operational Management. Your organisational structure, roles and accountability.
- Risk Management. How risks to participants and the organisation are identified and controlled.
- Quality Management. How you maintain and review the quality of supports.
- Information Management. How records are created, stored, accessed and kept secure.
- Feedback and Complaints Management. How feedback and complaints are received, managed and resolved.
- Incident Management. How incidents are recorded, managed and reported.
- Human Resource Management. How staff are recruited, screened, trained and supervised.
- Business Continuity. How you ensure your participants have access to support without interruption.
- Emergency and Disaster Management. How you plan for, respond to and continue supports through emergencies and disasters.
The provision of supports:
- Access to Supports. How participants start with your service.
- Support Planning. How each participant’s supports are planned and agreed.
- Service Agreements. How the arrangement between you and the participant is set out.
- Responsive Support Provision. How supports are delivered safely and adjusted over time.
- Transitions To or From the Provider. How participants move in and out of your service.
The provision of supports environment:
- Safe Environment. How the places supports are delivered are kept safe.
- Participant Money and Property. How participant funds and belongings are handled.
- Management of Medication. Applies if you administer or assist with medication.
- Mealtime Management. Applies if you support participants with eating and drinking.
- Waste Management. Applies if your supports generate clinical or hazardous waste.
The last three apply only if you deliver that specific supports.
Forms and registers
These are the working documents your policies rely on. Forms are what staff fill in, and registers are the running logs you maintain over time. As with the policies, the auditor is looking for something that does each job, regardless of what you call it.
Forms:
- Service agreement. The signed agreement with each participant. What to include.
- Intake, referral and consent forms. How participants are brought on and what they have agreed to.
- Assessment and support plan. The participant’s goals and how supports meet them.
- Progress notes and reports. The day-to-day record of supports delivered.
- Incident report and investigation forms. Used when something goes wrong.
- Complaint and feedback form. Used to capture what participants raise.
- Risk assessment forms. Individual, home and venue assessments as relevant.
- Emergency and disaster management plan. Your plan for emergencies, kept current and tested. Planning for small providers and how to test it.
- Conflict of interest declaration. Completed by staff and management.
- Internal audit records. Demonstrating you’ve completed audits and are taking action on findings.
Registers:
- Risk register. A live log of identified risks and their controls. How to build one.
- Incident register. Every incident, its management and its outcome. Building the system behind it.
- Complaints and feedback register. Every complaint and how it was resolved.
- Conflict of interest register. Declared conflicts and how they are managed.
- Continuous improvement register. Improvements identified and actioned.
- Document control register. Your document versions and review dates. (Not specifically required, if you have another method of overseeing document control like SharePoint versioning, etc.)
Governance and business documents
These show how the organisation is run and held accountable.
- Business and strategic planning. Your model and services, and the direction and goals you are working towards.
- Financial management policy. Not a named standard, but worth holding to show the organisation is financially well governed.
- Continuous improvement plan. Your planned improvements and how they are tracked.
- Delegation of authority. Who can make which decisions.
- Governance and management meeting records. Evidence that oversight is happening.
- Internal audit schedule. When you plan to complete internal audits throughout the year.
- Insurance certificates. Current public liability, professional indemnity and workers compensation cover.
People and worker records
These show that the people delivering supports are suitable, screened and capable.
- Position descriptions. The role and responsibilities for each position.
- Worker screening records. Current NDIS Worker Screening Checks for relevant roles. How screening works.
- Induction and orientation records. Including completion of the NDIS Worker Orientation Module.
- Training records. What training each worker has completed and when.
- Staff files. Qualifications, references and signed code of conduct for each worker.
Evidence of implementation
The audit team also looks at the evidence that your systems are running.
- Populated registers. Your registers with real entries, not blank templates.
- Training and supervision logs. Records that staff development is actually happening.
- Emergency plan test records. Evidence that your emergency and disaster plan has been tested, not just written.
- Participant records. Files that show the support cycle from intake through to review and transition out.
The audit is checking that these documents reflect what your organisation actually does, not only that they exist. What auditors look for goes into how that assessment works.
Supplementary modules
If you deliver higher-risk supports, you will be assessed against one or more supplementary modules as well, each with it’s own specific documentation requirements in addition to those outlined above.
Check out How To Get Your Policies and Procedures for the main ways providers source and develop their documents.
About the author
Penny Halpin
Penny is an NDIS Lead Auditor who has worked in certification since the first audits in 2018, and was previously a Senior Manager at an Approved Quality Auditor with technical review across thousands of audit reports. She built the Paperbark tools to help providers create documentation that reflects how they actually work.
More about Penny →