Policies & procedures

NDIS Provider Policies and Procedures That Hold Up at Audit

Policies and procedures are one of the most visible parts of an NDIS audit, but the document itself is only half the story — auditors are typically checking whether practice matches the paper. This guide explains what's usually needed and how to make it stick.

Registration Requirements4 min readLast reviewed:

Takes about 60 seconds. No obligation.

Who this guide is for

  • Providers drafting policies for the first time
  • Businesses that bought a template pack and aren't sure it's enough
  • Operations managers preparing for a certification audit
  • Providers reviewing documents ahead of renewal

What policies NDIS providers typically need

The exact set of required policies depends on your registration groups and the relevant NDIS Practice Standards modules, but most registered providers need documented approaches to governance, risk management, incident management, complaints handling, privacy and information management, and worker conduct.

Providers delivering higher-risk supports may also need policies on restrictive practices, medication management, or behaviour support, reflecting the additional Practice Standards modules that apply to those registration groups.

Core policy areas most providers need

  • Governance and management structure
  • Risk management
  • Incident management and reportable incidents
  • Complaints management and feedback
  • Privacy and information management
  • Worker recruitment, screening and code of conduct
  • Human resource management and training
  • Continuity of supports and emergency/disaster management

Why template-only policies fail audits

A common pattern in audit findings is a well-written policy document paired with no evidence it's actually used — no incident register entries matching the stated process, no training records showing staff were inducted on it, or rosters that contradict stated supervision arrangements.

Auditors are typically sampling real records against the policy, not just checking the policy exists. A policy that says 'all incidents are reported within 24 hours' needs an incident log that actually shows that happening.

Policy vs. evidence of implementation

Policy areaDocument alone showsImplementation evidence auditors look for
Incident managementA defined process and escalation stepsIncident register entries, reportable incident notifications, follow-up actions
Complaints managementA complaints process and timeframesComplaints log, resolution records, evidence of participant feedback loop
Worker code of conductExpected standards of behaviourSigned acknowledgements, induction records, performance records
Risk managementA risk framework and register templateCompleted risk assessments for actual services delivered
Privacy and information managementStated handling proceduresAccess controls, storage arrangements, breach response records

How to make policies match practice

  1. 01

    Write from actual workflows

    Draft policies based on how your team really operates, not an idealised process copied from elsewhere.

  2. 02

    Assign ownership

    Name who is responsible for each policy area and for keeping its evidence current.

  3. 03

    Train and record training

    Induct staff on relevant policies and keep signed or logged evidence of that training.

  4. 04

    Use the systems day to day

    Make sure registers, logs and forms referenced in the policy are actually completed in practice.

  5. 05

    Audit yourself periodically

    Spot-check a sample of your own records against the policy before an external auditor does.

Version control makes review cycles credible

Dating and versioning policies, with a documented review date and approver, shows an auditor that your governance is active rather than a one-off exercise from years ago.

Version control and review cycle basics

  1. 1Give every policy a version number, approval date and next review date
  2. 2Set a review cycle (commonly annual, or sooner after an incident or regulatory change)
  3. 3Keep a change log summarising what changed and why between versions
  4. 4Store superseded versions rather than deleting them, in case of historical queries
  5. 5Communicate updates to staff and record that communication

Keeping policies current between audits

Policies drift out of date when operations change faster than documentation — new services, new registration groups, new legislation, or lessons learned from an incident. Building a habit of updating policy alongside operational change, rather than only before an audit, keeps the gap between paper and practice smaller.

Tools like Guardian Guard can help schedule review reminders and track which staff have acknowledged the latest version of each policy, reducing reliance on manual tracking.

Frequently asked questions

Can I buy a template policy pack and use it as-is?
A template can be a useful starting point, but it generally needs to be adapted to your actual operations and supported by implementation evidence to hold up at audit.
How many policies does a small provider actually need?
It depends on your registration groups, but most providers need a core set covering governance, risk, incidents, complaints, privacy and worker conduct at minimum.
Do sole traders need the same policies as larger organisations?
Sole traders typically need lighter-weight versions of the same core policy areas, scaled to their size, but the underlying obligations under the Practice Standards still apply.
How often should policies be reviewed?
Many providers use an annual review cycle as a baseline, with additional reviews triggered by incidents, complaints or regulatory changes.
What's the biggest audit finding related to policies?
A frequent finding is a policy with no matching implementation evidence — the document exists, but records showing it's actually followed are missing or inconsistent.
Do policies need to be reviewed after registration group changes?
Yes, adding or changing registration groups often means new Practice Standards apply, which should be reflected in updated or additional policies.

Official sources and further reading

Requirements change. Always confirm the current position with the relevant authority before making decisions.

Ready to move forward?

Get an indicative pathway in about a minute, or start your registration with personalised support for your documents, self-assessment and audit preparation.

NDIS Provider Registration is an independent service and is not affiliated with or endorsed by the NDIA or the NDIS Quality and Safeguards Commission. We provide application preparation and audit preparation support; independent auditor fees are separate and registration decisions are made by the Commission.

Not sure what you need?

About 60 seconds. No obligation.

Check now