Allied Health NDIS Audit Checklist
Practice StandardsNDIS Practice Standards and Quality Indicatorsndis-practice-standards--core-information-management
Requirement

Core module: Information management

The Core module outcome information management: every quality indicator the NDIS Practice Standards set for it (Core 12.1 to Core 12.4), what an auditor asks to see under each, the common gaps, and a free worksheet to fill in.

Clause

NDIS Practice Standards Core 12.1 to Core 12.4

Regulator

NDIS Quality and Safeguards Commission

Edition held

Rules Schedules 1 to 8, Compilation No. 6 (F2026C00527) and Quality Indicators Guidelines Compilation No. 3 (F2026C00528), in force 1 July 2026

Checked current

6 October 2026, Federal Register: both compilations are the latest version on 6 October 2026

Who it applies to

Registered NDIS providers audited by certification: registered for early childhood supports, specialist behaviour support, implementing behaviour support plans or regulated restrictive practices, or specialised support coordination. An individual or partnership whose only certification requirement is early childhood supports meets only Core clause 7 (freedom from abuse) and Module 3 (Rules s 20(4) and (5)).

Under review, not in force

The NDIS Commission's review of the Practice Standards (a proposed quality framework and changes to the standards and how they are assessed) is still being considered; nothing from it is in force.

Core 12.1Information management: informed consent to collect, use and disclose informationsource
Requirement, our statement of the clause

The provider gets each participant's consent to collect, use and keep their information and to disclose it, including assessments, to other parties, and explains the purpose. Participants are told when information may be disclosed, including without consent where the law requires or authorises it.

Evidence that typically shows this
  • Consent to collect and share information forms naming parties and purposes
  • Privacy notice describing disclosure required or authorised by law
  • Records of disclosures made and the consent or legal basis for each
Common gap to check
  • Blanket consent with no named parties or purposes
  • Assessments shared with other providers without consent on file
Core 12.2Information management: participants told about storage, access, correction and withdrawalsource
Requirement, our statement of the clause

Each participant is told how their information is stored and used, and when and how they can access or correct it and withdraw or change consent they gave earlier.

Evidence that typically shows this
  • Privacy statement or handbook explaining access, correction and withdrawal
  • Register of access or correction requests and responses
  • Records of consent withdrawals and the actions taken
Common gap to check
  • No process for a participant to see their own file
  • Withdrawn consent not flagged in the client system
Core 12.3Information management: proportionate system recording accurate, timely informationsource
Requirement, our statement of the clause

The provider keeps an information management system proportionate to its size and scale that records each participant's information accurately and on time.

Evidence that typically shows this
  • Client management system or file structure description
  • Sample of participant files with dated, contemporaneous progress notes
  • File audit results checking accuracy and timeliness
Common gap to check
  • Progress notes written days after the shift
  • Duplicate or conflicting records across paper and electronic systems
Core 12.4Information management: secure handling through to retention and destructionsource
Requirement, our statement of the clause

Documents are handled with processes for appropriate use, access, transfer, storage, security, retrieval, retention, destruction and disposal that suit the scope and complexity of the supports delivered.

Evidence that typically shows this
  • Records management and retention schedule
  • System access controls and user access reviews
  • Secure destruction certificates or disposal log
  • Data breach response procedure
Common gap to check
  • Shared logins to the client system
  • Paper files kept in unlocked areas of shared homes
Worksheet: what your practice holds, and where
RefHeld (yes, partly, no, not applicable)Where it is keptOwnerLast reviewedNext review
Core 12.1
Core 12.2
Core 12.3
Core 12.4

Completing this worksheet records what your practice holds and where. It does not make a practice compliant or ready for audit, and it is not legal advice.

Related requirements

NDIS Practice Standards and Quality Indicators

The same topic in other instruments (privacy and records)

See every requirement for your practiceSee the specimen practice