What policies and documents do you need for an NDIS audit?
If you're preparing for an NDIS audit, the question underneath all the stress is usually a simple one: exactly which documents do I need to have ready? Here's the complete, plain-English answer — the core policies an auditor expects, the records that sit beside them, and how to present everything so audit day is calm rather than a scramble.
The short answer
Most new and small providers go through a verification audit — the lighter of the two audit types (more on the difference below). For that, you need two things working together: a set of written policies that show how you run a safe, accountable service, and the records that prove you actually follow them.
At minimum, auditors expect to see these six core policies:
- Incident Management — how you identify, record, respond to and report incidents.
- Privacy & Confidentiality — how you collect, store, use and protect personal information.
- Complaints Management — how participants raise concerns and how you resolve them.
- Code of Conduct — the standards of behaviour you and your workers commit to.
- Work Health & Safety (WHS) — how you keep workers and participants safe.
- Risk Management — how you identify and control risks across your service.
The six core policies, and what each should show
Incident management policy
Defines what counts as an incident, what makes one reportable, who does what when one happens, and the timeframes for notifying the NDIS Commission. The auditor wants to see that a worker would know exactly what to do in the moment — not just that a policy exists.
Privacy and confidentiality policy
Sets out what personal information you collect, why, how you store and secure it, who can access it, and how participants can see or correct their own information. It should reflect the Australian Privacy Principles and how they apply to your supports.
Complaints management policy
Explains, in plain language, how a participant can complain, how you'll handle it fairly and promptly, and that they can go to the NDIS Commission directly at any time. Pair it with a complaints register so nothing is lost.
Code of conduct
States the standards of behaviour you and your workers hold to — aligned with the NDIS Code of Conduct. It's the document that signals your culture, and auditors expect your workers to actually know it.
Work health and safety (WHS) policy
Covers how you keep both workers and participants safe — hazard identification, safe work practices, and what happens when something goes wrong. Even a sole trader needs this; it scales up as you employ staff.
Risk management policy
Describes how you spot, assess and control risks — to participants, workers and the business — and how you review them over time. It's the backbone the other policies hang off, so it's worth getting genuinely clear.
The records that sit alongside your policies
A policy says what you will do; records prove you did it. Auditors look for that link — so alongside the six policies, have these ready:
- Service agreements and consent records for your participants.
- Progress notes and service records.
- Incident records — and evidence you reviewed and acted on them.
- A complaints register with outcomes recorded.
- Worker screening checks, orientation and training records.
- Risk assessments and how you manage the risks you've identified.
- Continuous improvement records — what you've changed, and why.
Verification vs certification audit — which applies to you?
There are two audit types, and which one you face depends on the supports you deliver. A verification audit is the lighter pathway, for lower-risk, less complex supports — the six-policy set above is its backbone. A certification audit is the fuller, more involved pathway for higher-risk or complex supports (such as Supported Independent Living or specialist behaviour support), and it adds further requirements on top.
Which one applies isn't your choice — it's determined by your registration groups. Always confirm your specific pathway with the NDIS Quality and Safeguards Commission before you prepare.
How to walk in audit-ready
- Map each required policy and record to exactly where it lives.
- Find the gaps — anything you can't point to evidence for yet.
- Close gaps with real practice, not just a new file in a folder.
- Make every policy read consistently — same business name, ABN, version number and review dates throughout.
- Do a dry run: pick a standard at random and try to produce the evidence in under two minutes.
For the preparation process in more depth — the mindset, the evidence register and what happens on the day — see our companion guide, Getting ready for an NDIS audit.
Get all six core policies, audit-readyGenerate the six core policies auditors expect — Incident Management, Privacy, Complaints, Code of Conduct, WHS and Risk Management — each filled with your business name, ABN and NDIS details, so they read as one consistent organisation. Preview free; $5 per document, or subscribe for unlimited — and we never store your data.Open the generator →The exact standards you're audited against depend on your supports and registration type, so treat this as general information to help you prepare. The authoritative sources are always the NDIS Quality and Safeguards Commission and your approved auditor.
The NDIS Provider Starter Checklist
Every document and setup step a new provider needs, in one printable checklist. Pop in your email and it's yours.