Guide · audit documents · preparation checklist, not a regulator decision.

Guide 04 · evidence preparation

What documents do I need for an NDIS registration audit?

Short answer: There is no responsible one-size-fits-all folder that can replace a confirmed scope and the auditor's request. The local source says a provider engages an approved quality auditor for a desktop review of required documentary evidence. Your preparation set should therefore connect the confirmed entity, supports and modules to current policies, registers, worker controls, practice records and an evidence index. Treat this as a working checklist, not an exhaustive regulator list.

What the source says

“You need to engage an approved quality auditor to complete a desktop review of the required documentary evidence.”

Source and date: NDIS Quality and Safeguards Commission, “The quality audit process”, accessed 12 August 2026.

The sentence matters because it keeps three roles separate. The approved auditor reviews the required evidence for the agreed audit process. The provider owns the facts, implementation and submission. A preparation consultant may organise and map client material, but a document produced for the provider is not automatically evidence that the control operates.

Start with scope, not documents

Before collecting files, write a scope sheet with the legal or trading entity, current registration status, supports delivered or proposed, modules, sites, operating area, worker count and relevant date. If the provider is SIL, record the SIL role and any high-intensity scope. If the provider uses a platform model, describe the platform functions. Keep unresolved items marked as unsure.

This prevents a common failure mode: a large folder containing policies that do not match the actual service. The index should say which entity owns a file, which support or module it relates to, who owns the control, the version or review date, and what the file demonstrates. If a file is missing, say missing. Do not create a new dated record that suggests an earlier practice existed.

A sensible preparation set

  1. Governance and scope: entity details, role descriptions, scope matrix, policy index, document-control rules and current responsibility assignments.
  2. Rights, privacy and service delivery: the relevant policies, participant-facing information, records controls and a description of how the actual service is delivered. Keep participant-identifying material out of working copies unless it is specifically required through the secure process.
  3. Incidents and complaints: the written workflow, escalation and notification steps, controlled incident and complaint registers, close-out fields and redacted examples where available.
  4. Risk and continuity: the risk register, review cadence, emergency or continuity arrangements, owners and evidence that actions are tracked.
  5. Workers: a worker-screening and HR index showing how screening, expiry or recheck information, induction, training, supervision and competency are tracked. Use a redacted sample.
  6. Evidence organisation: a controlled index with stable IDs, owner, date, status, privacy note, location and a short explanation of the link between each item and the scope.

This list follows the Clearharbour readiness and preparation framework. It is not a statement that every item is required for every provider. The confirmed pathway, modules, provider facts and auditor request control the final evidence boundary.

How to test the folder before sending it

Ask a person who did not build the folder to locate one piece of evidence for each major control. Can they tell which version is current? Can they see who owns the next action? Can they distinguish a template from a completed operational record? Can they see the date, scope and privacy status without opening every file?

Then compare the documents with practice. A policy may say that incidents are escalated, while the register or a redacted example may show whether the fields, owner, dates and close-out steps are actually used. Where the answer is unknown, record the limitation. That is more reliable than renaming a draft “final” and treating it as proof.

Common mistakes

  • Downloading a generic pack and assuming it matches the provider's supports, sites or modules.
  • Presenting a policy index as evidence that workers have been trained or that the workflow is operating.
  • Sending unrestricted participant or worker data when a redacted index or sample would answer the question.

When a written readiness view helps

The free scorecard gives a bounded starting view across policy currency, registers, worker records, incident and complaint practice, evidence organisation, and registration status or pathway fit. It tells you what was reviewed and what was not supplied. It does not replace the auditor's evidence request, a formal audit or the provider's responsibility for accurate records.

Related: verification versus certification and policy versus evidence. Regulatory source access date: 12 August 2026.

Want to know which documents are missing from your own starting set?

Send the free scorecard intake with a policy index or redacted samples where available. The written result will separate missing material from material that was not reviewed.

Start the free scorecard