NDIS Practice Standards · Core Module
NDIS Compliance Checklist for Providers
25 checks, organised by the four divisions of the NDIS Practice Standards Core Module — because that is how the Standards are written and how an auditor’s scope is built. Each check names the evidence that proves it, not just the obligation.
Reviewed by an ISO 17065 Lead Auditor.
Prefer a printable copy? We’ll email you the PDF →
How to use it
Work down each division and mark a check only where you could produce the evidence today — not where you believe the practice is sound. The gap between those two answers is almost exactly the list of findings an audit would raise.
Auditors triangulate: for any requirement they want the policy that says what you do, the record showing it was done on real dates for real participants, and a worker who describes doing it. A check is only genuinely met when all three exist.
1 — Rights and responsibilities
How participants are treated, and whether they can show it. Auditors test this division mostly through participant files and worker interviews rather than through policy documents, because it is the division where a gap between the written and the actual is most visible.
2 — Provider governance and operational management
The division that most often produces non-conformities, because it is the one providers treat as administrative. It is where the auditor establishes whether anyone is actually accountable for the rest of the checklist.
3 — Provision of supports
The delivery layer. Evidence here is overwhelmingly file-based, and it is sampled — so consistency across files matters more than perfection in one.
4 — Provision of supports environment
The physical and clinical safety layer. Much of it is verified by observation on the day, so it is the division least amenable to preparation on paper.
Where providers most often fall short
The same five gaps come up again and again, and none is an obscure clause. All five sit in governance and operational management, and all five come from a process that is written down but not run day to day.
- An incident management system that exists on paper onlyThe policy exists; the register does not show every incident logged, actioned and closed the way the policy says. Reportable incidents add a hard clock: most must be notified to the Commission within 24 hours of the provider becoming aware, so the policy has to say who checks for that trigger, and when. Commission guidance on reportable incidents
- Worker screening gaps in risk-assessed rolesRarely an unscreened team. Usually a role never formally identified as risk-assessed, a casual or contractor who missed onboarding, or a clearance that lapsed unnoticed. Clearances last up to five years, which is long enough to lose track of expiry dates without a dated register. Worker screening for registered providers
- Complaints handled inconsistentlyA complaints policy but no register, or a register whose entries stop partway with no resolution recorded. The fix is closing the loop on every entry: what was raised, what was done, and whether the person was told the outcome. Core Module: governance and operational management
- Continuous improvement treated as a once-off taskAn improvement register populated once, around the last audit, and untouched since. A pattern in the incident or complaints register should create an improvement entry, and that entry should show what changed. Core Module: governance and operational management
- Risk management that lives in a document, not a routineA risk register not reviewed since it was written, or risks never linked to the incident, complaints and screening evidence that would show whether they are being managed. NDIS Practice Standards
If you have an audit booked
This checklist asks whether your obligations are covered. An audit asks a narrower and later question — whether your evidence survives being sampled. For that, the SIL audit checklist sets out what Stage 1 and Stage 2 test, and our audit preparation service covers the gap analysis and mock audit. If you are not registered yet, start with registration.
Frequently asked
- What is on an NDIS compliance checklist?
- At minimum, every division of the NDIS Practice Standards Core Module that applies to your registration groups: rights and responsibilities, provider governance and operational management, provision of supports, and the supports environment. Modules beyond the Core apply depending on the supports you deliver. A checklist that is not organised around the applicable standards will leave gaps precisely where the audit looks.
- Does this checklist apply to unregistered providers?
- The Practice Standards bind registered providers. Unregistered providers are still bound by the NDIS Code of Conduct, and any provider intending to register — or required to — is best served by working to the Standards now, because the evidence an audit samples has to accumulate over time and cannot be produced retrospectively.
- How is this different from an audit checklist?
- This one is about whether the obligations are covered. An audit checklist is about whether your evidence survives being sampled by an auditor — a narrower and later question. If you have an audit booked, the SIL audit checklist covers what a Stage 1 and Stage 2 audit tests.
- What are the most common NDIS compliance mistakes?
- Five gaps recur, all in governance and operational management: an incident system that exists on paper but not in the register, worker screening gaps in risk-assessed roles, complaints without recorded resolutions, a continuous improvement register that stopped moving after the last audit, and a risk register that is never reviewed. Each is a process not being run, rather than a missing policy.
- How often should we work through it?
- Annually as an internal audit, and again before any external audit. The continuous improvement register is where the output belongs — an internal audit that produces no recorded actions is not evidence of improvement, and auditors read it that way.
Want the printable version?
We'll email you this checklist as a PDF you can take into a team meeting or an internal audit — plus practical compliance updates, roughly fortnightly. Unsubscribe in one click.
