Common NDIS documentation errors that attract audit scrutiny
The NDIS Commission does not publish a ranked list of common documentation errors, so this guide starts from the other end: the requirements a record has to meet. An error attracts scrutiny when the record cannot show what a rule or Practice Standard asks it to show. The eight errors below are each tied to the source that makes them testable.
Key takeaways
- An auditor tests records against the Practice Standards’ quality indicators and asks to see real examples, not only policies.
- Most documentation errors are testable because a source states a requirement: the NDIA record keeping page, the core module, the Incident Management Rules and the Restrictive Practices Rules.
- Timeframes for reportable incidents run from when the provider becomes aware, so a record with no awareness time is hard to defend.
- Where a point is NoteGate’s view rather than a rule, this guide says so.
Which NDIS documentation errors attract audit scrutiny?
| Error | Requirement it relates to |
|---|---|
| 1. A note that does not show what support was delivered or how it relates to goals | The NDIA describes case notes as outlining the activities a participant engaged in and how they relate to the support item and goals |
| 2. Missing identifying details: participant, dates, hours or quantity, support type | NDIA record keeping page lists these as minimum details. It also says failing to provide complete and accurate records in a review may mean funds have to be repaid |
| 3. Records that are not accurate or timely | Core module, Information management: a system that records participant information “in an accurate and timely manner” |
| 4. An incident record with no time of awareness | Commission reportable incident timeframes are counted from when the provider became aware |
| 5. A restrictive practice record missing required content | Restrictive Practices and Behaviour Support Rules 2018, section 15: description of the use, the behaviour that led to it, times, people involved and witnesses, actions taken, less restrictive options tried first |
| 6. Records not kept for the stated period | Incident, reportable incident and restrictive practice records: 7 years under the Rules |
| 7. Support plan risk assessments or reviews that are not documented | Core module, Support planning: risk assessments documented in support plans, and each plan reviewed annually or earlier |
| 8. Policies that exist but records that do not show them in use | The Commission says an audit’s focus moves from what policies say to what actually happens |
How do auditors test for these errors?
The Commission describes auditors tracing a reported incident from the initial report through internal review, actions taken and notification obligations, cross-checking records against policy. It also describes sampling staff files and observing whether supports match the participant’s plan. Documentation errors show up when the trail breaks: a note with no time, an incident with no awareness date, a plan with no review.
Which of these are rules and which are practice?
Errors 2, 4, 5 and 6 rest on stated obligations or timeframes. Errors 1, 3 and 7 rest on guidance and indicators that an auditor judges, and error 8 describes how audits are run. Copying the same note across shifts, recording a feeling instead of behaviour, or writing notes in a batch at the end of the day are not named in a rule. They are patterns NoteGate treats as risks to the accuracy and timeliness indicator. See the 12 shift note failure modes for worked examples.
How can a provider find these errors before an audit?
Sample recent records and test each against the table: could someone who was not there see what was delivered, when, and for which goal? Then check the incident file: is there an awareness time on every record? NoteGate checks shift notes before they are saved and keeps the correction history, which addresses errors 1 to 3 at the point of writing. It does not review incident timeliness for you or decide whether you meet a standard. See the NDIS audit checklist for a pre-audit sample.
Frequently asked questions
What are the most common NDIS documentation errors?
The Commission does not publish a ranked list. Errors that are easiest for an auditor to test are notes that do not show what was delivered or how it relates to goals, missing identifying details, records that are not accurate or timely, incident records with no awareness time, and incomplete restrictive practice records.
What must an NDIS incident record include?
The Commission expects a provider’s incident management system to record the details and evidence of each incident. Reportable incident timeframes run from when the provider became aware, so the awareness time should be recorded.
What must a restrictive practice record include?
Under section 15 of the Restrictive Practices and Behaviour Support Rules 2018 it includes a description of the use and why it was used, the behaviour that led to it, when and where it started and ended, the people involved and witnesses, the actions taken, and the less restrictive options considered or used first. It must be kept for 7 years.
Can incomplete records cost a provider money?
The NDIA record keeping page says that failing to provide complete and accurate records during a review may result in funds having to be repaid.
Sources
- Types of audits (NDIS) (NDIS Quality and Safeguards Commission, retrieved 28 September 2026)
- Core module: Provider governance and operational management (NDIS Quality and Safeguards Commission, retrieved 28 September 2026)
- Core module: Provision of supports (NDIS Quality and Safeguards Commission, retrieved 28 September 2026)
- What are the record keeping requirements (NDIS) (NDIA, retrieved 25 September 2026)
- NDIS (Incident Management and Reportable Incidents) Rules 2018, sections 12 and 25 (Federal Register of Legislation, retrieved 25 September 2026)
- NDIS (Restrictive Practices and Behaviour Support) Rules 2018, section 15 Record keeping (Federal Register of Legislation, retrieved 25 September 2026)
- Reportable incidents (NDIS Quality and Safeguards Commission, retrieved 25 September 2026)
Related
Stop weak notes at the point of writing
See how NoteGate checks a note against the participant’s requirements before it is saved.
Book a 20-minute walkthroughChoose a plan