Ask Mandy
Guides  /  NDIS providers
NDIS providers

How to keep NDIS records for an audit

The short answer

To keep NDIS records for an audit, keep a complete file for each participant, a worker file for each staff member, and registers for incidents, complaints and risks. Complaint and incident records must be kept for 7 years. Every service record should show the participant's name and NDIS number, the date, the support type and the hours or quantity delivered.

Sources
NDIS (Provider Registration and Practice Standards) Rules 2018
NDIS (Complaints Management and Resolution) Rules 2018, section 10
NDIS (Incident Management and Reportable Incidents) Rules 2018, section 12
NDIA, What are the record keeping requirements

What records you must keep

Registered providers are assessed against the NDIS Practice Standards in the NDIS (Provider Registration and Practice Standards) Rules 2018, which include an information management standard. Auditors will expect, for each participant, a signed service agreement, consent records, a current support plan, progress or shift notes, and evidence of any risk assessments. For claims, the NDIA requires records that show the participant's name and NDIS number, the date the support was delivered, the amount or hours, and the support type, backed by invoices, rosters or support logs. You also need worker records, including NDIS Worker Screening Check details, qualifications, training and Code of Conduct acknowledgements, and governance documents such as policies and insurance.

How long to keep them

The NDIS (Complaints Management and Resolution) Rules 2018 and the NDIS (Incident Management and Reportable Incidents) Rules 2018 both require records to be kept for 7 years from the day they are made. Most providers apply the same 7 year period to all participant and service records, which also lines up with tax record keeping. Records about children should be kept longer, often until the person is well into adulthood, and state health records laws can add their own periods, so check the requirements in your state. Payment records must be available if the NDIA reviews your claims. When a retention period ends, dispose of records securely.

Storing records safely

Records hold sensitive personal and health information, so the Privacy Act 1988 and the Australian Privacy Principles apply to most providers, alongside the privacy element of the NDIS Code of Conduct. Store records where only authorised staff can see them, use access controls and logs for electronic systems, back up regularly, and have a plan for what happens if a device is lost or a system fails. Paper records should be locked away. Participants have a right to access their own information, so make sure you can find and provide a complete file quickly. A document control register that tracks policy versions also helps auditors follow your system.

Preparing for the audit itself

Auditors usually sample a small number of participant files and worker files and trace them end to end, from the service agreement to the claim. Do your own sample before they arrive. Check that notes are dated, signed and match the hours invoiced, that incidents mentioned in notes appear in the incident register, and that every worker on the roster has a current screening check. Fix gaps and record what you changed. Being able to show a working system, not just a policy on a shelf, is what auditors and the NDIS Quality and Safeguards Commission are looking for.

Ask Mandy this, and thousands more.

Get instant, cited answers on the NDIS, aged care, health and more, in plain English.

Try Ask Mandy
Ask Mandy
Cited by askmandy.app against current legislation. Last reviewed September 2026. Information only, not legal, tax or financial advice. Always check the current source before you act.