NDIS Risk Register Requirements for Providers | NoteGate

NDIS risk register requirements: what the Practice Standards say

By NoteGate Research Team · Published 27 September 2026 · Last reviewed 27 September 2026

The NDIS Practice Standards require a documented risk management system that identifies, analyses, prioritises and treats risks. The core module does not use the words “risk register” or prescribe a format, so a register is best understood as a common way to show the system works. NoteGate builds a risk register from validated notes and incidents, with supervisors reviewing every entry. It supports documentation compliance and does not decide whether a provider’s risk management meets the standards.

Key takeaways

Do NDIS providers need a risk register?

The Practice Standards require a documented risk management system that identifies, analyses, prioritises and treats risk. They do not use the term “risk register”. A register is a common way to keep that documentation, so most providers use one, but the standards state the outcome rather than the format.

The source is the core module, Provider governance and operational management. The indicators are worded as what a provider should be able to demonstrate, and the approved quality auditor assesses that, not software.

What do the Practice Standards say about risk?

Indicator (core module, Risk management)What it means for records
Risks to the organisation, including risks to participants, financial and work health and safety risks, and risks associated with provision of supports, are identified, analysed, prioritised and treatedSome record of each risk, how it was rated and what was done about it
A documented risk management system that effectively manages identified risks is in place, relevant and proportionate to the size and scale of the provider and the scope and complexity of supportsDocumentation scaled to the provider, not one fixed form
The system covers incident management, complaints management and resolution, financial management, governance and operational management, human resource management, information management, work health and safety, and emergency and disaster managementRisks recorded across these areas, including those that arise from incidents and complaints
Supports and services are provided in a way that is consistent with the risk management systemThe system is used in practice, which an auditor can test

The core module also sets a quality management indicator that continuous improvement uses “outcomes, risk related data, evidence-informed practice and feedback”. That is why registers are often linked to corrective actions.

What should a risk register hold as good practice?

This list is our view of good practice and is not stated in the standards. A register that can be read at audit usually shows, for each risk: what the risk is and which participant or area it relates to, its category and rating, the controls already in place and any still planned, an owner, a review date, its status, and the source of the entry, such as the incident or note that raised it.

For providers delivering supported independent living, the SIL Practice Standards safeguarding standard adds an intent that providers and workers evidence the steps taken to manage risks in the home, including between people who live there.

How does NoteGate build a risk register?

In NoteGate, risk signals are extracted from validated shift notes and incident records. They queue for supervisor review and do not enter the register without approval. Each entry carries its source evidence, category, participant link and status. An accepted risk can generate a corrective action with an owner, due date, priority and a resolution evidence requirement. See NDIS risk register software for the detail.

What this does not mean. NoteGate does not decide that a risk is rated correctly or that a provider’s system meets the standards. Every rating and action is reviewed and owned by your supervisors. See NDIS compliance software for the wider picture.

Frequently asked questions

Do NDIS providers need a risk register?

The Practice Standards require a documented risk management system in which risks are identified, analysed, prioritised and treated. They do not use the term risk register. A register is a common way to keep that documentation.

What must an NDIS risk management system cover?

The core module lists incident management, complaints management and resolution, financial management, governance and operational management, human resource management, information management, work health and safety, and emergency and disaster management. Where relevant it also includes infection prevention and control.

Does NoteGate decide whether a risk is rated correctly?

No. NoteGate surfaces risk signals from validated records for a supervisor to review. Every rating, corrective action and pack is reviewed, approved and owned by the provider’s own people.

Sources

Related

See NoteGate check a note before it is saved

Book a 20-minute walkthrough, or choose a plan.

Book a 20-minute walkthroughChoose a plan