Policies are evidence, not decoration

Auditors don’t count policies. They test whether what you say you do matches what you actually do. A 300-page pack you’ve never read is a liability; twenty documents you follow is a pass.

The core set for a verification-module provider

Rights and responsibilities; privacy and dignity; incident management (including reportable incidents); complaints and feedback; risk management; human resource management including screening and training; continuity of supports; governance and operational management; emergency and disaster management; a Code of Conduct acknowledgement; and a service agreement template.

Add for certification

Module-specific procedures for the supports you deliver — medication, mealtime management, behaviour support implementation, restrictive practices reporting — plus clinical governance where relevant.

Registers you must actually keep

Incident register, complaints register, worker screening and training register, risk register, and a continuous improvement log. These are what the auditor opens first.

Want it built for you? The NDIS Audit & Compliance is a fixed-price, ready-to-run version of everything in this article. Book a 20-minute call — no pitch, honest answer.

General information only, not legal or financial advice. Requirements change; confirm with the regulator or a qualified professional.