NDIS Audit Registers: Risk, Incident, Complaints | NoteGate Skip to content
Audit registers

The registers an auditor asks for, already current.

NoteGate is NDIS, Aged Care and DVA documentation compliance software by AgenticX Australia.

Holding shift notes is not the same as holding a risk register that is owned and reviewed, a complaints register that shows what changed, or a restrictive practices register that matches the plans authorising them. NoteGate keeps all six current as a by-product of normal daily operation.

Australian hosted · AWS Sydney · Participant data is never used to train AI models
Why registers decide audits

An auditor does not test your intentions. They test your records.

Your existing system stores what was submitted. It does not know whether a risk that was identified six months ago was ever assigned to anyone, whether a complaint produced a change in practice, or whether a restrictive practice used on a Tuesday night was authorised in the participant's plan. Those are the questions an audit turns on, and they are answered from registers.

The failure mode is rarely an absent register. It is a register that was built in the fortnight before the audit, where every entry carries a date from the same two weeks and nothing has an owner or a review date. That pattern can be visible to an assessor, and it can undermine the rest of the evidence.

A register that has been maintained continuously reads differently, because it looks like what it is.

The six registers

What each one proves

Each register is exportable to Excel on demand, and maps to the NDIS Practice Standards outcome an assessor will test it against.

2.6 Incident Management

Incident Register

Every reportable and non-reportable incident, with severity, the immediate action taken, and whether it was notified to the Commission.

Shows: incidents are formally recorded rather than left inside a notes feed, and that notification obligations were met on time.
2.5 Feedback and Complaints Management

Feedback and Complaints Register

Complaints, compliments, concerns and suggestions, with how each was resolved and what was done as a result.

Shows: feedback reaches a resolution and changes practice, which is what outcome 2.5 is actually about.
2.2 Risk Management

Risk Register

Identified risks with a scored likelihood and consequence, the controls currently in place, a named owner, and a scheduled review date.

Shows: risks are assessed and owned rather than noted, and that reviews happen on a schedule instead of after an incident.
Module 2A Implementing Behaviour Support Plans

Restrictive Practices Register

Each recorded use of a restrictive practice, the participant it concerned, and the plan authorising it.

Shows: restrictive practice use is visible and traceable to an authorising plan, and that unauthorised use surfaces rather than staying buried.
2.1 Governance and Operational Management

Continuous Improvement Register

Corrective actions with a priority, an owner, a due date, and a record of completion and verification. Actions raised from an incident, a complaint, an audit finding or a risk all appear here.

Shows: the loop closes. This is the register that answers "what changed as a result", including for actions with no parent record.
2.7 Human Resource Management

Worker Screening and Training Register

Worker screening checks and training records with their expiry dates.

Shows: the people delivering supports were cleared and current at the time they delivered them.
From register to audit pack

The audit pack is assembled, not written.

The registers are not a separate reporting exercise. They are the source of the audit pack, which pulls them together with shift note compliance records and incident history into a single workbook, structured the way assessors read.

6
Registers maintained continuously, each exportable to Excel
1
Audit pack, generated on demand for any date range
0
Participant names or NDIS numbers in the auditor-facing export
De-identified by default

Hand it to an auditor without handing over identities.

The audit pack refers to participants and workers by reference codes rather than by name or NDIS number. An assessor can follow a participant across the incident register, the risk register and the shift note record without ever being told who they are.

Where a corrective action was carried forward from an earlier period because it is still open, the pack says so on the row, so a long-standing action is never mistaken for a recent one.

  • Every register exports to Excel on demand
  • Risk Register and Continuous Improvement included as audit pack sheets
  • Participants and workers shown as reference codes
  • Any date range up to twelve months per pack
  • Outstanding corrective actions carried forward and labelled

Works alongside the system you already have

No migration No retraining No change to billing or rostering Australian hosted

NoteGate is a compliance layer, not a replacement for your CRM, your rostering tool, or your scheduling platform. Your team keeps working the way they work now. The registers are maintained from the documentation they are already producing, which is the only way a register stays current in practice: nobody has to remember to update it.

FAQ

Common questions

Which registers does NoteGate maintain?
Six: the Incident Register, the Feedback and Complaints Register, the Risk Register, the Restrictive Practices Register, the Continuous Improvement Register, and the Worker Screening and Training Register. Each one is exportable to Excel, and each one feeds the audit pack.
Do we have to maintain these registers separately from our existing system?
No. NoteGate works alongside whichever documentation platform your team already uses. The registers are maintained from the documentation your team is already producing, so there is no second system to keep current and no migration.
What does an auditor actually do with a register?
An auditor uses a register to test whether a claim about your practice is true. A register that is complete, dated, owned and current is evidence. A register assembled in the fortnight before the audit tends to read as one, because the dates cluster.
Can we export the registers for an auditor?
Yes. Every register exports to Excel, and the Risk Register and Continuous Improvement Register are included as sheets in the audit pack alongside shift note compliance records, incidents, complaints and restrictive practices.
Is participant information exposed in the audit pack?
No. The audit pack refers to participants and workers by reference codes rather than names or NDIS numbers, so it can be handed to an auditor without disclosing identities.
What should a complaints record show for an NDIS audit?
It should show that the complaint was received, acknowledged and resolved through the provider’s complaints system, with dates and outcomes. The core module of the NDIS Practice Standards expects a system that follows procedural fairness and complies with the NDIS (Complaints Management and Resolution) Rules 2018. Auditors ask to see real complaints records. Sources: core module and types of audits, NDIS Commission.
How long must incident records be kept?
Incident records must be kept for 7 years from the day the record is made, and reportable incident records for 7 years from the day the Commission is notified, under the NDIS Incident Management and Reportable Incidents Rules. Other Commonwealth, state or territory laws may add retention requirements. Sources: NDIS (Incident Management and Reportable Incidents) Rules 2018, sections 12 and 25 and Incident Management Systems Detailed Guidance.
Where is the data held?
Australia. Participant data does not leave the provider's control, and is not used to train AI models.

See your registers with your own data in them.

Start with the documentation your team produced this week. Works alongside the system they already use, with no migration and no retraining.

Choose a plan →Book a 20-minute walkthrough →

Questions? Email info@notegate.com.au

Read the guide: what to record and report for restrictive practices

Key takeaways

What NoteGate does not do

NoteGate never writes shift notes or incident reports; workers write those. It supports documentation governance and does not determine compliance.

Related

Audit pack, Incident reporting, Restrictive practices documentation.

Last reviewed 25 September 2026.