Guide · registers · controlled fields, owners and review dates.

Guide 09 · controlled registers

What registers does a small NDIS provider need to maintain?

Short answer: Start with controlled incident, complaint and risk registers, then link them to worker-screening and HR tracking and an evidence index. There is no useful answer that is only a list of file names. Each register needs a clear owner, required fields, review cadence, escalation or notification prompt, close-out status and a link to the evidence that supports the entry. The final scope depends on the provider's actual supports, modules, sites and operating model.

The smallest useful register set

Incident register: capture the event identifier, date, affected service or site, immediate action, escalation or notification question, owner, status, review date, close-out and learning. Use a minimum-necessary description and avoid unnecessary participant details in working copies.

Complaint register: record the complaint identifier, date received, channel, issue, owner, acknowledgement or response step, escalation, investigation, outcome as a factual record, close-out and learning or improvement action. Do not use “closed” as a substitute for explaining what was done.

Risk register: describe the risk, affected scope, current controls, rating method, owner, treatment action, due date, review date and status. A risk register should make a decision visible; it is not a static list of worries.

Worker-control matrix: this is not a substitute for an incident, complaint or risk register. It makes screening, expiry or recheck information, induction, training, competency and supervision fields visible for the worker population.

Evidence index: stable IDs, title, owner, date, version or status, privacy treatment, location and the link to the policy, control or scope item being demonstrated. It makes the set discoverable without treating the folder name as proof.

Why “we have a spreadsheet” is not enough

A spreadsheet may be a perfectly workable tool. The question is whether it is controlled and usable. Can someone tell who owns an open item? Is the review date visible? Does the entry show what was escalated and why? Is the close-out supported by a record? Can the provider distinguish an old draft from the current register? If the answer is no, the register may exist while the control remains partial.

Informal email lists and notes can be useful intake material, but they should be classified honestly. Move them into the controlled structure only when the provider can preserve the original facts and record the source, date and owner. Do not rewrite history to make the new register look older than it is.

The useful test is not whether the register looks tidy on the day it is opened. It is whether the next person can understand what happened, what remains open and what decision is due without asking the original author to reconstruct the story. That is why ownership, dates and review evidence matter as much as the column headings.

What to do this week

  1. Choose one owner for each register and one backup or escalation route.
  2. Write the required fields before importing old records. Include status, due date, review date and close-out.
  3. Set a review cadence that fits the provider's operating week. Record the review even when there are no new items.
  4. Link each register to the relevant policy and evidence index. Give the files stable names and a privacy note.
  5. Test one redacted example from receipt through close-out. Record the missing field rather than inventing it.

Common mistakes

  • Keeping incidents, complaints and risks in one undifferentiated list with no different workflow fields.
  • Allowing an open action to sit without an owner, due date or next review.
  • Using an empty template as if it proves the provider has operated the control.

When a written readiness view helps

The free scorecard includes registers as one of six dimensions. It can distinguish a current controlled set, a partial structure, no available material or an uncertain position. It does not create a regulator's required list or decide whether your entries are accepted. It gives you a written starting point for the next owner and action.

Related: policy versus evidence and audit documents. This guide is operational information, not legal advice; last verified 12 August 2026.

Want the register gaps written down before they become a folder hunt?

Use the free scorecard with a redacted register sample or a clear NONE or UNSURE answer. The written result will show the control fields, ownership and review limits that need attention.

Start the free scorecard