
An audit lasts a few days. The registration period it covers lasts years. In that time your team delivers thousands of shifts, writes thousands of progress notes and makes countless small decisions about participants’ safety, choices and rights. The auditor sees only a sample of that work, but the NDIS Quality and Safeguards Commission can take an interest in any part of it, at any time.
Complaints, reportable incidents and the Commission’s own monitoring can all bring a provider under scrutiny long before the next scheduled audit. Providers who treat compliance as an event tend to scramble twice: once when something goes wrong, and again when the auditor arrives. Those who build it into ordinary operations find both far less stressful.
This guide looks at what compliance means day to day, how the Commission sees your organisation between audits, and a practical routine that keeps you ready.
What Compliance Actually Covers
NDIS compliance is broader than passing an audit against the Practice Standards. For a registered provider, it means meeting several overlapping sets of obligations at the same time:
- the NDIS Code of Conduct, which applies to your organisation and every worker
- the NDIS Practice Standards relevant to your registration groups
- the conditions set out on your certificate of registration
- the NDIS rules on incident management, complaints management, worker screening and, where relevant, behaviour support and restrictive practices.
Some of these reach beyond registered providers. The Commission is clear that registered and unregistered providers alike must follow the Code of Conduct and deliver safe, quality supports. Registration adds the audit, the Practice Standards and a set of formal systems and reporting duties on top.
Compliance is also personal. The Code of Conduct applies to individual workers as well as organisations, and the Commission can take action against a worker, including a banning order, where serious concerns arise. That makes induction and ongoing training part of your compliance system, not an optional extra.
The practical test is simple: could you show someone today, not next month, that each of these obligations is being met? If the answer depends on a document being written or a record being found, there’s a gap.
The Obligations That Run Every Day
Most of what auditors assess is the product of routine work. These are the areas where NDIS provider compliance is won or lost between audits.
- Living the Code of Conduct. Workers must act with respect for participants’ rights, respect privacy, provide supports safely and competently, act with integrity and promptly raise concerns about quality and safety. Staff should be able to explain what the Code means in their own role, not just recite it.
- Managing incidents properly. Registered providers need an incident management system that records, investigates and learns from incidents. Certain reportable incidents, including a participant’s death, serious injury, abuse or neglect, unlawful physical or sexual contact and sexual misconduct, generally must be notified to the Commission within 24 hours. The unauthorised use of a restrictive practice is generally notifiable within five business days, unless it caused harm.
- Handling complaints fairly. A complaints management system should make it easy for participants and families to raise concerns, protect them from any negative consequences and lead to clear outcomes. Every complaint is also an opportunity to find and fix a system weakness.
- Keeping worker screening current. Workers in risk-assessed roles need a valid NDIS Worker Screening clearance, and all workers should complete the NDIS Worker Orientation Module. Track expiry dates centrally rather than relying on individual reminders.
- Using restrictive practices only as authorised. Where participants have behaviour support plans, regulated restrictive practices must be used only as authorised and reported as required. Workers need training in each participant’s plan before they deliver support.
- Notifying changes promptly. Changes to key personnel, ownership, structure or the way you operate may need to be reported to the Commission. Recent amendments to the registration rules shorten some notification timeframes and strengthen requirements around changes of ownership, so check the current rules.
- Staying within your scope and conditions. Deliver only the supports you are registered for, and meet any conditions on your certificate. Scope drift, where services evolve but registration doesn’t, is easy to miss and hard to explain.
How the Commission Sees You Between Audits
It is a common assumption that the Commission only learns about a provider through audit reports. In practice, complaints from participants and families, reportable incident notifications and the Commission’s own monitoring and investigations all give it a view of how you operate.
When it identifies a concern, the Commission has a range of responses. These include compliance notices directing a provider to take specific action, conditions on registration, infringement notices and, in serious cases, suspension or revocation of registration and banning orders. Decisions such as banning orders are published on the Commission’s website, where participants, families and referrers can search them.
If you receive a compliance notice, treat its deadline as fixed. The notice will set out what the Commission believes has gone wrong and what you must do, or stop doing, to fix it. Respond to each point specifically, keep evidence of every action taken and use the notice to test whether the same weakness exists elsewhere in your systems.
The regulatory environment has also tightened. Recent amendments to the NDIS Act increased penalties, extended banning orders to quality auditors and people who facilitate the provision of supports, and strengthened the Commission’s information-gathering powers where participant safety is at risk.
None of this should be read as a reason for alarm. It is a reason for consistency. Providers with sound records, prompt notifications and genuine improvement processes are well placed to respond to any question the Commission asks.
A Routine That Keeps You Audit-Ready
NDIS audit compliance is far easier to maintain than to rebuild. A simple, repeatable routine turns preparation from a pre-audit project into part of normal operations. This is the kind of rhythm we help providers set up.
- Every shift: accurate records. Progress notes should be timely, factual and linked to participant goals. Incidents should be recorded the same day. Good records are the foundation of every other compliance activity.
- Every week: register review. A manager should review new incidents, complaints and feedback, check that reportable incidents were notified on time and assign follow-up actions with owners and due dates.
- Every month: workforce check. Review worker screening clearances, qualifications, first aid and other training due to expire in the next 90 days. Confirm new starters have completed induction and orientation before their first shift.
- Every quarter: internal file audit. Select a sample of participant files and test them against the relevant Practice Standards. Are support plans current? Are risk assessments reviewed? Is consent documented? Record what you find and what you fix.
- Twice a year: policy review. Check policies against current legislation, Commission guidance and the way your team actually works. Use version control and record how staff were told about changes.
- Every finding: corrective action. Log audit findings, complaint outcomes and incident lessons in one continuous improvement register. Close each item with evidence, not just a tick.
- Every year: governance review. Leadership should review the risk register, participant feedback, incident trends and the continuous improvement register, and set priorities for the year ahead. Minute the meeting so the decisions are visible.
Scale the routine to your organisation. A sole trader may combine several steps into a monthly hour of review, while a larger provider will assign each activity to a different role. What matters is that it happens, and that there is a record showing it did. If a step is missed during a busy period, note why and when it will be caught up.
Culture Is What the Auditor Actually Tests

Auditors interview workers, speak with participants and watch how supports are delivered. A policy manual can’t answer those questions on your behalf. When support workers can explain how they would report an incident, what they would do if a participant raised a complaint and where to find a behaviour support plan, the paperwork becomes evidence of something real.
That is why ongoing training, supervision and open conversations about quality matter as much as any document. Keep records of team meetings where incidents and complaints are discussed, supervision sessions and refresher training, because they show an auditor that learning is continuous rather than a one-off induction. Compliance becomes sustainable when it is part of how your team thinks, not something managers do to prepare for an audit.
Practical Support for Registered Providers
Angels Compliance and Training Services is a Perth-based consultancy supporting NDIS and DVA providers across Australia with registration, renewal, audit preparation, policies and procedures, compliance coaching and staff training. We help providers build NDIS compliance into everyday operations through internal audits, practical systems and training that staff can apply on shift.
If you’d like a clearer picture of where your organisation stands, book a free consultation on +61 431 560 453 and we’ll help you plan your next steps.
