How to prepare for an NDIS provider audit by building evidence daily, not before the auditor arrives
Short answer: audit readiness is a by-product of good daily documentation, not a project you start when you receive an audit date. Check notes when they are written, link them to care plan goals, triage incidents the day they occur and track corrective actions to closure, so the audit pack is assembled from records that already exist.
Key takeaways
- Audit readiness is a by-product of good daily documentation, not a separate project you start when you receive an audit date.
- Auditors review records such as shift notes, incident records, care plans, risk registers and behaviour support documentation against the NDIS Practice Standards. Every record must stand on its own.
- The most common failure modes are vague shift notes, outdated care plans, risks without controls or review dates, and incidents never triaged for reportability.
- A continuous evidence-building process removes the last-minute scramble: check notes at the point of writing, link them to care plan goals, triage incidents immediately and track corrective actions.
- Purpose-built documentation compliance software such as NoteGate can enforce these habits through pre-save validation and a linked evidence trail.
Treat audit evidence as daily work, not an event
Most providers only think about audit evidence in the weeks before an auditor arrives. By then the work is archaeological: sifting through months of shift notes, chasing missing incident reports and updating care plans that should have been reviewed already. The result is stress, overtime and evidence that looks like it was produced for the auditor rather than for the participant.
The alternative is to build audit evidence as a by-product of everyday work. When shift notes are checked for quality at the point of writing, incidents are triaged the day they occur and care plan reviews happen on schedule, the evidence trail already exists. Preparing for an audit then means assembling records that are already linked, not reconstructing them.
Verification and certification audits assess different things
NDIS quality audits fall into two main categories. A verification audit is a desktop review of documentary evidence by an approved quality auditor. A certification audit, which applies to higher-risk registration groups such as supported independent living, has a Stage 1 desktop audit and a Stage 2 onsite audit, where the auditor views records, interviews staff and participants and makes observations.
In both cases the auditor samples. Any record could be the one selected, and the Commission notes an auditor may trace a reported incident through your records. A single vague shift note, an incident without follow-up or a care plan with no evidence of participant involvement can become a non-conformity. A non-conformity is not a failure, but it does have to be fixed. The test is whether your documentation shows the Practice Standards are met in practice, not just on paper.
What auditors look for in each record type
| Record type | What the auditor checks against the Practice Standards |
|---|---|
| Shift notes | Specific, objective, linked to care plan goals, written close to the time of service delivery |
| Incident records | Timely recording, triage against reportable incident obligations, evidence of immediate response and follow-up actions |
| Care plans | Current, reviewed at required intervals, reflect participant goals, evidence of participant and family involvement |
| Risk registers | Identified risks with controls, responsible persons, review dates and evidence of periodic review |
| Behaviour support plans | Developed by a registered behaviour support practitioner, implemented by trained staff, restrictive practice use recorded and reported, linked to shift notes showing implementation |
The most common reasons providers receive non-conformities
- Vague shift notes. Notes that say “participant had a good day” or “all tasks completed” give no evidence of what support was delivered or how it related to the participant’s goals.
- Outdated care plans. A care plan not reviewed since it was written, or that does not reflect current goals and circumstances, signals a gap between documented and actual practice.
- Risks without controls or review dates. A register that lists hazards but not the controls in place, who is responsible or when the risk was last reviewed fails to show active risk management.
- Incidents not triaged for reportability. Providers must identify whether an incident is reportable to the NDIS Commission. When incidents are recorded without this step, an auditor cannot see that the provider met its obligations.
- Evidence assembled late. When documentation is created or updated in the weeks before an audit, timestamps and version history can make this visible, and it weakens the evidence.
How to build evidence continuously instead of retrospectively
- Check notes at the point of writing. Every shift note should be checked before it is saved. Does it name the support delivered? Does it reference the relevant care plan goal? Is it specific and objective? The check can be manual (a team leader reviewing notes daily) or automated through documentation compliance software.
- Link notes to care plan goals and behaviour support plans. Each note should be traceable to the goal or plan it supports. This is the chain auditors follow: care plan goal, then shift note showing delivery, then outcome review.
- Maintain a live risk register. Risks should have named controls, responsible persons and scheduled review dates. When a review is due, complete and record it rather than deferring it.
- Triage every incident for reportability. At the point of recording, assess whether the incident meets the NDIS Commission’s reportable incident criteria, and document the reasoning.
- Track corrective actions and review dates. When an incident, complaint or internal review identifies an issue, record the corrective action, responsible person, due date and completion evidence, and track it to closure.
Assembling an audit pack from records that are already linked
When evidence is built continuously, preparing an audit pack is a retrieval task, not a creation task. The provider pulls a sample of participant records and confirms each one contains linked shift notes, a current care plan, incident records with triage and follow-up, and risk entries with review evidence. Gaps are visible immediately because the links either exist or they do not.
This is where purpose-built documentation compliance software such as NoteGate fits. NoteGate checks shift notes, incident records and care plans against the relevant standards before they are saved, and returns precise corrections when a record falls short. Prompts are drawn from the participant’s care plan and behaviour support plan, and notes, incidents, risks, corrective actions and reviews link into one evidence trail. Audit packs become a by-product of daily documentation rather than a separate project. Workers still write their own records, and providers retain all clinical and governance decisions.
A checklist for 90, 30 and 7 days before an audit
| Timeframe | Action |
|---|---|
| 90 days | Confirm all care plans have been reviewed within their required cycle. Identify overdue risk reviews. Sample shift notes for specificity and goal linkage. Check incident triage records are complete. |
| 30 days | Run a mock audit: pull a sample of participant files across each registration group. Check each file for linked notes, a current care plan, incident records with follow-up and behaviour support plan implementation evidence. Close the gaps. |
| 7 days | Assemble the audit pack. Confirm staff who may be interviewed can describe how they document support, report incidents and implement care plans and behaviour support plans. Make sure policies match actual practice. |
Audit readiness is a daily habit, not a deadline
Providers who build evidence as staff work, rather than assembling it before an auditor arrives, give themselves fewer surprises and put less pressure on staff. The process is straightforward: check documentation at the point of creation, link records to goals and plans, triage incidents immediately and track corrective actions to closure. Tools like NoteGate automate the checks that make this sustainable, so the audit pack already exists when the audit date is confirmed.
Frequently asked questions
How many participant files will an auditor sample?
It depends on the provider’s size, services and registration groups, and the approved quality auditor decides the sample. Assume any file could be selected and prepare accordingly.
Do shift notes need to reference care plan goals explicitly?
The Practice Standards expect supports to be delivered in line with the participant’s plan. Notes that name the specific goal or outcome being supported give the clearest evidence of this. A note that describes the activity without the goal leaves the auditor to infer the connection.
What if an incident was not triaged for reportability at the time?
Triage it as soon as the gap is found and, if it is reportable, notify the NDIS Commission. Documenting the late identification honestly is better than leaving the gap unaddressed.
Can NoteGate be used alongside an existing CRM or rostering system?
Yes. NoteGate is a standalone documentation compliance layer and does not replace scheduling, billing or claiming systems. Connectors to existing platforms are in development; contact NoteGate to confirm options for your stack.
Sources
- Types of audits (NDIS Quality and Safeguards Commission, retrieved 28 September 2026)
- NDIS Practice Standards and Quality Indicators (NDIS Quality and Safeguards Commission, retrieved 28 September 2026)
- Reportable incidents (NDIS Quality and Safeguards Commission, retrieved 25 September 2026)
Related
Build audit evidence as staff work
Book a 20-minute walkthrough, or choose a plan.
Book a 20-minute walkthroughChoose a plan