NDIS risk register requirements: what the Practice Standards say
The NDIS Practice Standards require a documented risk management system that identifies, analyses, prioritises and treats risks. The core module does not use the words “risk register” or prescribe a format, so a register is best understood as a common way to show the system works. NoteGate builds a risk register from validated notes and incidents, with supervisors reviewing every entry. It supports documentation compliance and does not decide whether a provider’s risk management meets the standards.
Key takeaways
- The core module’s Risk management outcome is that risks to participants, workers and the provider are identified and managed.
- Its indicators say risks are “identified, analysed, prioritised and treated” and that a documented risk management system is in place, proportionate to the size of the provider and the supports it delivers.
- The system should cover incident management, complaints management and resolution, financial management, governance and operational management, human resource management, information management, work health and safety, and emergency and disaster management.
- A register is not named in the module. It is good practice for showing the system in use.
Do NDIS providers need a risk register?
The Practice Standards require a documented risk management system that identifies, analyses, prioritises and treats risk. They do not use the term “risk register”. A register is a common way to keep that documentation, so most providers use one, but the standards state the outcome rather than the format.
The source is the core module, Provider governance and operational management. The indicators are worded as what a provider should be able to demonstrate, and the approved quality auditor assesses that, not software.
What do the Practice Standards say about risk?
| Indicator (core module, Risk management) | What it means for records |
|---|---|
| Risks to the organisation, including risks to participants, financial and work health and safety risks, and risks associated with provision of supports, are identified, analysed, prioritised and treated | Some record of each risk, how it was rated and what was done about it |
| A documented risk management system that effectively manages identified risks is in place, relevant and proportionate to the size and scale of the provider and the scope and complexity of supports | Documentation scaled to the provider, not one fixed form |
| The system covers incident management, complaints management and resolution, financial management, governance and operational management, human resource management, information management, work health and safety, and emergency and disaster management | Risks recorded across these areas, including those that arise from incidents and complaints |
| Supports and services are provided in a way that is consistent with the risk management system | The system is used in practice, which an auditor can test |
The core module also sets a quality management indicator that continuous improvement uses “outcomes, risk related data, evidence-informed practice and feedback”. That is why registers are often linked to corrective actions.
What should a risk register hold as good practice?
This list is our view of good practice and is not stated in the standards. A register that can be read at audit usually shows, for each risk: what the risk is and which participant or area it relates to, its category and rating, the controls already in place and any still planned, an owner, a review date, its status, and the source of the entry, such as the incident or note that raised it.
For providers delivering supported independent living, the SIL Practice Standards safeguarding standard adds an intent that providers and workers evidence the steps taken to manage risks in the home, including between people who live there.
How does NoteGate build a risk register?
In NoteGate, risk signals are extracted from validated shift notes and incident records. They queue for supervisor review and do not enter the register without approval. Each entry carries its source evidence, category, participant link and status. An accepted risk can generate a corrective action with an owner, due date, priority and a resolution evidence requirement. See NDIS risk register software for the detail.
What this does not mean. NoteGate does not decide that a risk is rated correctly or that a provider’s system meets the standards. Every rating and action is reviewed and owned by your supervisors. See NDIS compliance software for the wider picture.
Frequently asked questions
Do NDIS providers need a risk register?
The Practice Standards require a documented risk management system in which risks are identified, analysed, prioritised and treated. They do not use the term risk register. A register is a common way to keep that documentation.
What must an NDIS risk management system cover?
The core module lists incident management, complaints management and resolution, financial management, governance and operational management, human resource management, information management, work health and safety, and emergency and disaster management. Where relevant it also includes infection prevention and control.
Does NoteGate decide whether a risk is rated correctly?
No. NoteGate surfaces risk signals from validated records for a supervisor to review. Every rating, corrective action and pack is reviewed, approved and owned by the provider’s own people.
Sources
- Core module: Provider governance and operational management (NDIS Quality and Safeguards Commission, retrieved 26 September 2026)
- NDIS Practice Standards (NDIS Quality and Safeguards Commission, retrieved 19 September 2026)
- Incident management and reportable incidents (NDIS Quality and Safeguards Commission, retrieved 19 September 2026)
Related
See NoteGate check a note before it is saved
Book a 20-minute walkthrough, or choose a plan.
Book a 20-minute walkthroughChoose a plan