Allied Health NDIS Audit Checklist
Practice StandardsNDIS Practice Standards and Quality Indicatorsndis-practice-standards--core-risk-management
Requirement

Core module: Risk management

The Core module outcome risk management: every quality indicator the NDIS Practice Standards set for it (Core 10.1 to Core 10.6), what an auditor asks to see under each, the common gaps, and a free worksheet to fill in.

Clause

NDIS Practice Standards Core 10.1 to Core 10.6

Regulator

NDIS Quality and Safeguards Commission

Edition held

Rules Schedules 1 to 8, Compilation No. 6 (F2026C00527) and Quality Indicators Guidelines Compilation No. 3 (F2026C00528), in force 1 July 2026

Checked current

6 October 2026, Federal Register: both compilations are the latest version on 6 October 2026

Who it applies to

Registered NDIS providers audited by certification: registered for early childhood supports, specialist behaviour support, implementing behaviour support plans or regulated restrictive practices, or specialised support coordination. An individual or partnership whose only certification requirement is early childhood supports meets only Core clause 7 (freedom from abuse) and Module 3 (Rules s 20(4) and (5)).

Under review, not in force

The NDIS Commission's review of the Practice Standards (a proposed quality framework and changes to the standards and how they are assessed) is still being considered; nothing from it is in force.

Core 10.1Risk management: organisational and participant risks identified and treatedsource
Requirement, our statement of the clause

Risks to the organisation, including risks to participants, financial and work health and safety risks, and risks from providing supports, are identified, analysed, prioritised and treated.

Evidence that typically shows this
  • Risk register rating likelihood and consequence with treatments and owners
  • Participant risk assessments linked to the organisational register
  • Work health and safety hazard register
Common gap to check
  • Register lists risks but no treatments or owners
  • Participant-level risks not considered at organisational level
Core 10.2Risk management: documented, proportionate risk management systemsource
Requirement, our statement of the clause

A documented risk management system is in place that effectively manages identified risks and is relevant and proportionate to the provider's size and scale and the scope and complexity of its supports.

Evidence that typically shows this
  • Risk management policy and framework document
  • Records of periodic risk register review and sign-off
  • Risk reports to the governing body
Common gap to check
  • Generic purchased template not adapted to the provider's supports
  • No evidence the system has been reviewed
Core 10.3Risk management: system covers the eight required areassource
Requirement, our statement of the clause

The risk management system covers each of: incident management; complaints management and resolution; financial management; governance and operational management; human resource management; information management; work health and safety; and emergency and disaster management.

Evidence that typically shows this
  • Risk register or framework mapped to all eight areas
  • Policies for each area cross-referenced from the risk framework
  • Most recent review of each area's risks
Common gap to check
  • Emergency and disaster or information management risks missing from the register
  • Financial management risks not assessed in a small provider
Core 10.4Risk management: infection and outbreak prevention and controlsource
Requirement, our statement of the clause

Where relevant to its supports, the provider's risk management system includes measures to prevent and control infection and outbreaks.

Evidence that typically shows this
  • Infection prevention and control policy and outbreak management plan
  • PPE stock and supply records
  • Records of outbreak response or exercises
Common gap to check
  • Outbreak plan written during a past pandemic and never updated
  • No PPE stock plan for home-based supports
Core 10.5Risk management: supports delivered consistently with the risk systemsource
Requirement, our statement of the clause

Supports and services are actually delivered in line with the risk management system, so the controls written in it are followed in practice.

Evidence that typically shows this
  • Spot check or supervision records verifying risk controls on shift
  • Participant files showing risk plan actions carried out
  • Internal audit findings on risk controls
Common gap to check
  • Risk controls on paper not followed by casual or agency workers
  • Participant risk plans not available to workers on shift
Core 10.6Risk management: appropriate insurance heldsource
Requirement, our statement of the clause

The provider holds appropriate insurance, including professional indemnity, public liability and accident insurance, for the supports it delivers.

Evidence that typically shows this
  • Current certificates of currency for professional indemnity, public liability and accident or workers compensation cover
  • Insurance schedule showing the covered activities match registered supports
  • Renewal tracking records
Common gap to check
  • Policy lapsed or excludes some registered supports
  • Sole traders relying on a subcontractor's insurance
Worksheet: what your practice holds, and where
RefHeld (yes, partly, no, not applicable)Where it is keptOwnerLast reviewedNext review
Core 10.1
Core 10.2
Core 10.3
Core 10.4
Core 10.5
Core 10.6

Completing this worksheet records what your practice holds and where. It does not make a practice compliant or ready for audit, and it is not legal advice.

Related requirements

NDIS Practice Standards and Quality Indicators

The same topic in other instruments (risk and insurance)

See every requirement for your practiceSee the specimen practice