NDIS compliance

Top 5 Mistakes NDIS Providers Make in Compliance (And How to Avoid Them)

Updated 3 August 2026 · first published 13 February 2025 · 2 min read · Compliance Care

The findings that keep turning up at audit

Ask any approved quality auditor which non-conformities they see most often, and the list is short and repetitive. It isn't exotic clauses buried deep in a supplementary module — it's a small set of Core Module basics that providers write a policy for once and then don't actually run day to day. That gap between the document and the practice is where most audit findings live.

This isn't a checklist to memorise. It's the five places evidence most commonly falls short against the NDIS Practice Standards, why each one trips providers up, and what closing the gap actually looks like in practice.

What a non-conformity actually is

The NDIS Practice Standards set out a Core Module — covering Rights & Responsibilities, Governance & Operational Management, Provision of Supports, and the Support Environment — plus supplementary modules for specific support types. Approved quality auditors assess your organisation against the quality indicators published for each outcome; a non-conformity is a gap between what an indicator requires and what your evidence actually shows, as set out on the NDIS Commission's Practice Standards page. It's an independent, evidence-based finding — the auditor doesn't set the bar, the published indicators do, and only your organisation's actual practice determines whether you meet it.

The five areas below are all Governance & Operational Management outcomes. They come up often for a simple reason: they depend on staff actually following a process every day, not just on a document existing.

1. An incident management system that exists on paper only

Most providers have an incident management policy. Far fewer can show, on request, that every incident in the last six months was logged, actioned, and closed out the way the policy describes. The NDIS Commission's incident management guidance is specific: your written procedures need to cover how incidents are identified and recorded, how they're reported, how support is provided to the person affected, how that person is involved in resolving it, and when a corrective action is triggered.

The most common failure isn't the policy — it's the register. If your incident log has gaps, no follow-up notes, or no link back to a corrective action, that's the evidence gap an auditor will find. Reportable incidents carry a hard timeframe on top of this: except for unauthorised use of a restrictive practice, they must be notified to the NDIS Commission within 24 hours of your organisation becoming aware of them, per the Commission's reportable incidents guidance. A policy that doesn't say who checks for that 24-hour trigger, and when, is a gap waiting to be found.

2. Worker screening gaps in risk-assessed roles

Registered providers are required to identify which roles in their organisation are risk-assessed, keep a written record of them, and make sure the people filling those roles hold a current NDIS Worker Screening clearance — set out in the Commission's worker screening guidance for registered providers. Clearances are valid for up to five years, which is exactly long enough for a provider to lose track of which ones are approaching expiry.

The finding auditors raise here is rarely "we didn't screen anyone" — it's a role that was never formally identified as risk-assessed in the first place, a contractor or casual who slipped through onboarding, or a clearance that lapsed without anyone noticing. A current, dated register of risk-assessed roles and clearance expiry dates is the evidence that closes this gap before it becomes a finding.

3. Complaints and feedback handled inconsistently

The Core Module's feedback and complaints management standard, described on the Commission's governance and operational management page, expects a system that's genuinely accessible to participants, workers trained in how to use it, and a supportive environment for anyone who raises a concern. In practice, many providers can show a complaints policy but not a complaints register — or a register with entries that stop partway through, with no record of resolution or follow-up with the person who complained.

The fix isn't a longer policy. It's closing the loop on every entry: what was raised, what was done, and whether the person was told the outcome.

4. Continuous improvement treated as a once-off task

The same governance standard expects continuous improvement to be genuinely continuous — regular review of policies and procedures, participant input on how well your systems are working, and feedback that actually changes practice rather than sitting in a register nobody revisits. A common pattern auditors see is a continuous improvement register that was populated once, around the last audit, and hasn't moved since.

Continuous improvement done well links directly back to your incident and complaints registers: a pattern in either one should generate an entry in your improvement register, and that entry should show what changed as a result.

5. Risk management that lives in a document, not a routine

Governance and operational management also expects risk to be actively managed, not just documented once at registration. Where this becomes a finding is usually a risk register that hasn't been reviewed since it was written, or risks that were identified but never linked to the incident, complaints, or worker screening evidence that would show whether they're actually being managed.

Auditors are looking for one thing across all five of these areas: does your evidence show a system running, or a document that was written and then left alone?

Closing the gap before your audit, not during it

Every one of these five areas is fixable without drama — but it takes an honest look at your actual registers and records, not just your policies, and it takes time you don't want to find out you're short of the week before your audit. A structured pre-audit review against the current quality indicators, well ahead of your audit date, is the difference between finding these gaps yourself and having an auditor find them for you. Our SIL audit-readiness checklist is a practical starting point if you want to check your own evidence against these five areas today.

For a deeper walkthrough of what auditors actually look for and how to structure your evidence ahead of time, see our NDIS audit preparation guide and step-by-step compliance audit checklist.

How Compliance Care can help

We help providers build genuine competence against the NDIS Practice Standards — preparing your registers, evidence, and everyday practice so that whichever independent auditor reviews your organisation, what they find reflects the real quality of your operation. Our audit preparation services are built around exactly the five areas above, and our gap analysis and pre-audit reviews give you an honest read on where your evidence actually stands before an auditor does.

Book a discovery call and we'll help you map which of these five areas needs attention first.

Get NDIS compliance updates

Practical guidance on registration, audits and the 2027 wave. No spam, unsubscribe in one click.

Need a hand putting this into practice?

Book a no-obligation discovery call — you’ll leave knowing exactly where you stand.

Book a discovery call

Peace of mind, by design.