Policies & procedures
NDIS Provider Policies and Procedures That Hold Up at Audit
Policies and procedures are one of the most visible parts of an NDIS audit, but the document itself is only half the story — auditors are typically checking whether practice matches the paper. This guide explains what's usually needed and how to make it stick.
Registration Requirements4 min readLast reviewed:
Takes about 60 seconds. No obligation.
Who this guide is for
- Providers drafting policies for the first time
- Businesses that bought a template pack and aren't sure it's enough
- Operations managers preparing for a certification audit
- Providers reviewing documents ahead of renewal
What policies NDIS providers typically need
The exact set of required policies depends on your registration groups and the relevant NDIS Practice Standards modules, but most registered providers need documented approaches to governance, risk management, incident management, complaints handling, privacy and information management, and worker conduct.
Providers delivering higher-risk supports may also need policies on restrictive practices, medication management, or behaviour support, reflecting the additional Practice Standards modules that apply to those registration groups.
Core policy areas most providers need
- Governance and management structure
- Risk management
- Incident management and reportable incidents
- Complaints management and feedback
- Privacy and information management
- Worker recruitment, screening and code of conduct
- Human resource management and training
- Continuity of supports and emergency/disaster management
Why template-only policies fail audits
A common pattern in audit findings is a well-written policy document paired with no evidence it's actually used — no incident register entries matching the stated process, no training records showing staff were inducted on it, or rosters that contradict stated supervision arrangements.
Auditors are typically sampling real records against the policy, not just checking the policy exists. A policy that says 'all incidents are reported within 24 hours' needs an incident log that actually shows that happening.
Policy vs. evidence of implementation
| Policy area | Document alone shows | Implementation evidence auditors look for |
|---|---|---|
| Incident management | A defined process and escalation steps | Incident register entries, reportable incident notifications, follow-up actions |
| Complaints management | A complaints process and timeframes | Complaints log, resolution records, evidence of participant feedback loop |
| Worker code of conduct | Expected standards of behaviour | Signed acknowledgements, induction records, performance records |
| Risk management | A risk framework and register template | Completed risk assessments for actual services delivered |
| Privacy and information management | Stated handling procedures | Access controls, storage arrangements, breach response records |
How to make policies match practice
- 01
Write from actual workflows
Draft policies based on how your team really operates, not an idealised process copied from elsewhere.
- 02
Assign ownership
Name who is responsible for each policy area and for keeping its evidence current.
- 03
Train and record training
Induct staff on relevant policies and keep signed or logged evidence of that training.
- 04
Use the systems day to day
Make sure registers, logs and forms referenced in the policy are actually completed in practice.
- 05
Audit yourself periodically
Spot-check a sample of your own records against the policy before an external auditor does.
Version control makes review cycles credible
Dating and versioning policies, with a documented review date and approver, shows an auditor that your governance is active rather than a one-off exercise from years ago.
Version control and review cycle basics
- 1Give every policy a version number, approval date and next review date
- 2Set a review cycle (commonly annual, or sooner after an incident or regulatory change)
- 3Keep a change log summarising what changed and why between versions
- 4Store superseded versions rather than deleting them, in case of historical queries
- 5Communicate updates to staff and record that communication
Keeping policies current between audits
Policies drift out of date when operations change faster than documentation — new services, new registration groups, new legislation, or lessons learned from an incident. Building a habit of updating policy alongside operational change, rather than only before an audit, keeps the gap between paper and practice smaller.
Tools like Guardian Guard can help schedule review reminders and track which staff have acknowledged the latest version of each policy, reducing reliance on manual tracking.
Frequently asked questions
- Can I buy a template policy pack and use it as-is?
- A template can be a useful starting point, but it generally needs to be adapted to your actual operations and supported by implementation evidence to hold up at audit.
- How many policies does a small provider actually need?
- It depends on your registration groups, but most providers need a core set covering governance, risk, incidents, complaints, privacy and worker conduct at minimum.
- Do sole traders need the same policies as larger organisations?
- Sole traders typically need lighter-weight versions of the same core policy areas, scaled to their size, but the underlying obligations under the Practice Standards still apply.
- How often should policies be reviewed?
- Many providers use an annual review cycle as a baseline, with additional reviews triggered by incidents, complaints or regulatory changes.
- What's the biggest audit finding related to policies?
- A frequent finding is a policy with no matching implementation evidence — the document exists, but records showing it's actually followed are missing or inconsistent.
- Do policies need to be reviewed after registration group changes?
- Yes, adding or changing registration groups often means new Practice Standards apply, which should be reflected in updated or additional policies.
Official sources and further reading
Requirements change. Always confirm the current position with the relevant authority before making decisions.
Ready to move forward?
Get an indicative pathway in about a minute, or start your registration with personalised support for your documents, self-assessment and audit preparation.
NDIS Provider Registration is an independent service and is not affiliated with or endorsed by the NDIA or the NDIS Quality and Safeguards Commission. We provide application preparation and audit preparation support; independent auditor fees are separate and registration decisions are made by the Commission.
