Allied Health NDIS Audit Checklist
Psychology CodePsychology Board Code of conduct for psychologistspsychology-code-of-conduct--7-1-risk-management
Requirement

Risk management

Psychology Board Code of conduct for psychologists 7.1, stated plainly and cited to the edition held, with the evidence an auditor or the regulator asks for, the common gaps, and a free worksheet to fill in.

Clause

Psychology Board Code of conduct 7.1

Regulator

Psychology Board of Australia

Edition held

Code of conduct for psychologists, effective 1 December 2025 (advance copy published November 2024; PDF dated 13 November 2025)

Checked current

6 October 2026, our build record of the held copy: current on the Psychology Board site as read 6 October 2026

Who it applies to

Registered psychologists (general, provisional and endorsed), from 1 December 2025. Never occupational therapists or physiotherapists, who follow the shared Code of conduct.

7.1Risk managementsource
Requirement, our statement of the clause

Effective risk management means the psychologist: (a) applies Principles 2 and 3 on cultural safety and culturally reflective practice; (b) understands governance and their own obligations in the work setting (the ACSQHC Australian Open Disclosure Framework is noted for accredited organisations); (c) joins in any available systems for quality assurance and improvement; (d) where no local systems exist, develops and runs processes to identify and reduce risk of harm to clients and to respond to harmful events; (e) takes part, where required, in surveillance and monitoring of harmful events, reporting them to the appropriate authority where suitable; (f) when in a leadership or management role, makes sure there are ways for people to voice concerns about risks to clients or anyone else; (g) works to reduce error and improve safety for clients and others in the work setting and the wider system; (h) backs colleagues and practitioners who raise safety concerns that are objectively valid; (i) takes reasonable steps to deal with any reason to think client safety may be compromised; and (j) considers whether a client seriously threatens other people and, on a reasonable belief that they do, takes reasonable steps to deal with it consistently with the Privacy Act and any other applicable law.

Evidence that typically shows this
  • Practice risk register and risk management procedure (for sole practitioners without organisational systems)
  • Client risk assessments and safety plans, reviewed at set intervals
  • Incident and near-miss log with reporting to the relevant authority where required
  • Record of the reasoning and steps taken when a client was judged a serious threat to others, including any disclosure made under the Privacy Act
  • Participation in audits or quality improvement activities
Common gap to check
  • Sole practice with no risk or incident process at all
  • Threat to a third party recorded with no action taken or reasoning given
  • Risk assessments done at intake only
Worksheet: what your practice holds, and where
RefHeld (yes, partly, no, not applicable)Where it is keptOwnerLast reviewedNext review
7.1

Completing this worksheet records what your practice holds and where. It does not make a practice compliant or ready for audit, and it is not legal advice.

Related requirements

See every requirement for your practiceSee the specimen practice