Guide · NDIS compliance

What evidence do the NDIS Practice Standards actually require?

Updated 28 July 2026 Ricardo Santos · AI Systems Engineer 9 min read
The short answer

The Practice Standards are assessed against quality indicators, and an auditor tests those indicators by asking for evidence that something happened, not evidence that you intended it to. A policy saying incidents are reviewed within five days is not evidence. A record showing that this incident was reviewed on that date by that person is.

The distinction decides most audit outcomes. Providers rarely fail because they lack policies. They fail because the policy exists and the evidence that it was followed does not.

Two audit pathways, two different burdens

Which audit you face depends on the registration groups you hold. Roughly 60% of registered providers sit on the verification pathway, which applies to lower-risk supports and is largely document-based: policies, insurance, worker screening records, key operational documents.

Certification applies to higher-risk supports, including supported independent living, specialist disability accommodation, early childhood supports and behaviour support. It adds on-site assessment, staff interviews and participant feedback, and it typically runs on a three-year cycle with a mid-term review.

Changed this month

From 1 July 2026, supported independent living providers and NDIS digital platform providers must undergo audit and register with the Commission in order to keep delivering supports. If that is you and it has not started, that is the immediate priority, ahead of anything on this page.

The four kinds of evidence, weakest to strongest

1. Documented policy

The weakest form, and the one providers over-invest in. A policy establishes what you say you do. It carries almost no weight on its own, because an auditor's question is never "do you have a policy" for long.

2. Records that the policy was applied

Incident forms completed, reviews signed, training attended, plans lodged. This is where most providers are adequate but inconsistent, and inconsistency is what gets sampled.

3. Records with attribution and timing

The same records, carrying who did it and when, in a form that cannot be back-dated without leaving a trace. This is the level at which evidence starts being persuasive rather than merely present.

4. Evidence generated as a by-product of the work

Records that exist because the work happened, not because someone remembered to record that the work happened. This is the only level that survives a busy quarter, and it is a system design property rather than a training problem.

Where providers are usually exposed

  • Supervision. It happens, and it is not evidenced. Reconstructing it after an auditor asks is the classic scramble.
  • Worker screening currency. Screening was checked at onboarding and never re-checked against expiry.
  • Policy review cycles. The policy exists and was last reviewed four years ago, which the version history makes obvious.
  • Restrictive practice authorisation. Authorisation lapses on its own schedule, independent of the plan it sits inside.
  • Participant feedback and complaints. Captured informally, so there is no record that the loop was closed.
The question that separates ready from not

Not "do we do this", but "if an auditor picked a random participant and a random month, could we show what happened without anyone reconstructing it". If the honest answer is no, the gap is evidence capture, not process.

Why this is a systems problem

Every failure above shares a shape: the work was done and the evidence was a separate act that someone had to remember. Any approach that adds a second administrative task to a clinical or support workflow decays, because the second task is the one that gets dropped when the week gets hard.

The alternative is to derive compliance state from the work itself. When a practitioner records a session, the supervision evidence, the timestamp and the attribution come with it. Nobody maintains a compliance record, because the compliance record is a view over what already happened. That is a build decision, and it is the one that determines whether you are audit-ready in year three or scrambling.

Common questions

Is a policy enough to satisfy a Practice Standard?

Rarely. Policies establish intent. Quality indicators are assessed on evidence that the intent was carried out, so a policy without corresponding records is usually treated as a gap rather than as compliance.

How far back will an auditor look?

It depends on the audit type and your registration groups, but expect sampling across the period since your last audit rather than a review of recent months only. Evidence that only exists for the last quarter is a visible pattern.

Do we need software to pass an audit?

No. Plenty of small providers pass on well-run manual processes. Software becomes worth considering when the volume of evidence exceeds what anyone can reliably maintain by hand, or when the same evidence has to be assembled repeatedly.

What changed on 1 July 2026?

Supported independent living providers and NDIS digital platform providers now need to undergo audit and register with the NDIS Commission in order to continue delivering supports.

This guide is general information about how Australian regulatory obligations apply in practice. It is not legal advice, and requirements vary by registration group, jurisdiction and the supports you deliver.

Related

Carrying an obligation your software does not represent?

Two weeks inside your workflow produces a build plan, an accuracy baseline and a risk register. You keep all three either way.

Start a conversation