What should an NDIS audit pack include?
Short answer: there is no mandated audit pack format. A useful pack holds the organisation-level documents an auditor asks for, a sample of complete participant files, and the registers and corrective actions that show the system working. This page gives a checklist and a template you can copy or download without signing up.
Key takeaways
- The NDIS Commission does not set an audit pack format. The approved quality auditor decides what to request and what to sample.
- A pack has three layers: organisation documents, a sample of complete participant files, and registers with evidence of action.
- Each participant file in the sample should stand on its own: current plan, linked notes, incidents with follow-up, risks with review dates.
- The checklist and template below are free, ungated, and need no sign-up.
- Aged care providers work to different standards and reporting rules, so keep a separate pack.
What should an NDIS audit pack include?
An NDIS audit pack should include your organisation-level documents, a sample of complete participant records, and your registers and corrective actions with evidence they were acted on. The auditor decides the exact list, so use this as a starting checklist and confirm it with your approved quality auditor.
| Section | What to include | What it shows |
|---|---|---|
| 1. Organisation | Policies and procedures, governance and structure, worker screening and induction records, training and supervision records | That systems exist and workers are supported |
| 2. Participant files (sample) | Current care and support plan, behaviour support plan where relevant, shift notes for the period, progress reports | That supports match the plan in practice |
| 3. Incidents | Incident records, reportability assessment, notification log, follow-up actions | That incidents are identified, managed and reported |
| 4. Risk | Risk register with controls, owners and review dates, risk assessments in plans | That risks are identified, analysed, prioritised and treated |
| 5. Complaints and feedback | Complaints register with resolution and what was actioned | That feedback is acted on |
| 6. Restrictive practices (if applicable) | Recorded use and the plan authorising it | That use is authorised and reported |
| 7. Corrective actions | Actions raised from incidents, complaints and reviews, with owner, due date and proof of closure | That problems are fixed, not just logged |
The Commission describes a verification audit as a desktop review of documentary evidence, and a certification audit as a desktop stage followed by an onsite stage that can include viewing records and interviewing staff and participants (types of audits). The pack is what lets you answer both quickly.
Free audit pack checklist and template
Copy the table below into your own spreadsheet, or download it as a CSV file. No sign-up is needed. Use reference codes such as P-01 for participants instead of names in anything you share.
| Item | Where it is kept | Owner | Last reviewed | Gap or action |
|---|---|---|---|---|
| Policies and procedures index | ||||
| Worker screening and induction records | ||||
| Training and supervision records | ||||
| Participant file P-01: plan, notes, incidents, risks | ||||
| Participant file P-02: plan, notes, incidents, risks | ||||
| Participant file P-03: plan, notes, incidents, risks | ||||
| Incident register and notification log | ||||
| Risk register with controls and review dates | ||||
| Complaints and feedback register | ||||
| Restrictive practices record (if applicable) | ||||
| Corrective action log with proof of closure |
What do I do when an auditor asks for sample records?
- Confirm the sample. Ask which participants, which period and which record types, in writing.
- Pull whole files, not fragments. For each participant include the plan, the notes for the period, any incidents and the risk entries, so the links are visible.
- Check each file before it leaves. Look for the four gap types in how to handle gaps in audit evidence.
- Do not alter records to fix them. If a file has a gap, supply it as it is with the corrective action beside it.
- Protect identities. Share only what the auditor requested and use reference codes where you can.
Does an aged care audit pack differ?
Yes. Aged care runs under the strengthened Aged Care Quality Standards, seven standards applied from 1 November 2025, and incident reporting runs through the Serious Incident Response Scheme, with Priority 1 incidents due within 24 hours and Priority 2 within 30 days. The same three layers apply, but the evidence maps to different standards. See NoteGate for aged care.
What should audit pack software do?
Whatever tool you use, check that it can export care plans, shift notes, incidents and risks for any period you choose, show each record with its history rather than only its latest version, label anything that is self-reported, and let you remove identities before you share. A pack built only from what was entered, with no quality check on what was entered, will reproduce the gaps already in the records.
The NoteGate audit pack is a workbook for any period up to twelve months, with a sheet per evidence area that appears only where there is data, and participants and workers shown as reference codes. It labels shift times as worker asserted and carries forward corrective actions with their original dates. It does not predict an audit outcome, and your team reviews it and decides what to submit.
Frequently asked questions
Is there an official NDIS audit pack template?
No. The NDIS Commission does not set an audit pack format. The approved quality auditor tells you what to supply, so confirm the list with them.
How many participant files should be in an audit pack?
The auditor decides the sample. Prepare a few complete files across your registration groups, and be ready to produce any file on request.
Can I download a free audit pack checklist?
Yes. The checklist on this page can be copied into a spreadsheet or downloaded as a CSV file without signing up.
Does an audit pack prove I am compliant?
No. It organises your evidence. Compliance is assessed by the approved quality auditor against the NDIS Practice Standards.
Sources
- Types of audits (NDIS Quality and Safeguards Commission, retrieved 28 September 2026)
- NDIS Practice Standards (NDIS Quality and Safeguards Commission, retrieved 28 September 2026)
- What are record keeping requirements (National Disability Insurance Agency, retrieved 25 September 2026)
- Strengthened Aged Care Quality Standards (Aged Care Quality and Safety Commission, retrieved 28 September 2026)
- About reportable incidents (SIRS) (Aged Care Quality and Safety Commission, retrieved 28 September 2026)
Related
Have the pack ready before the audit is booked
Book a 20-minute walkthrough, or choose a plan.
Book a 20-minute walkthroughChoose a plan