Back to the requirement

Allied Health NDIS Audit Checklist: worksheet

Core module: Information management

NDIS Practice Standards and Quality Indicators. Edition held: Rules Schedules 1 to 8, Compilation No. 6 (F2026C00527) and Quality Indicators Guidelines Compilation No. 3 (F2026C00528), in force 1 July 2026; checked current on 6 October 2026 (Federal Register: both compilations are the latest version on 6 October 2026).

Under review, not in force: The NDIS Commission's review of the Practice Standards (a proposed quality framework and changes to the standards and how they are assessed) is still being considered; nothing from it is in force.

Standards library: https://compliance.theartofservice.com/frameworks/australia-ndis-practice-standards-and-quality-indicators. Page: https://allied-health-ndis-audit-checklist.theartofservice.com/rules/ndis-practice-standards/core-information-management/

RefRequirement (our statement of the clause)Evidence an auditor or the regulator asks forCommon gap to checkHeld (yes, partly, no, not applicable)Where it is keptOwnerLast reviewedNext review
Core 12.1The provider gets each participant's consent to collect, use and keep their information and to disclose it, including assessments, to other parties, and explains the purpose. Participants are told when information may be disclosed, including without consent where the law requires or authorises it.
Source: https://www.legislation.gov.au/F2018L00631/latest/text
Consent to collect and share information forms naming parties and purposes; Privacy notice describing disclosure required or authorised by law; Records of disclosures made and the consent or legal basis for eachBlanket consent with no named parties or purposes; Assessments shared with other providers without consent on file☐ yes
☐ partly
☐ no
☐ n/a
Core 12.2Each participant is told how their information is stored and used, and when and how they can access or correct it and withdraw or change consent they gave earlier.
Source: https://www.legislation.gov.au/F2018L00631/latest/text
Privacy statement or handbook explaining access, correction and withdrawal; Register of access or correction requests and responses; Records of consent withdrawals and the actions takenNo process for a participant to see their own file; Withdrawn consent not flagged in the client system☐ yes
☐ partly
☐ no
☐ n/a
Core 12.3The provider keeps an information management system proportionate to its size and scale that records each participant's information accurately and on time.
Source: https://www.legislation.gov.au/F2018L00631/latest/text
Client management system or file structure description; Sample of participant files with dated, contemporaneous progress notes; File audit results checking accuracy and timelinessProgress notes written days after the shift; Duplicate or conflicting records across paper and electronic systems☐ yes
☐ partly
☐ no
☐ n/a
Core 12.4Documents are handled with processes for appropriate use, access, transfer, storage, security, retrieval, retention, destruction and disposal that suit the scope and complexity of the supports delivered.
Source: https://www.legislation.gov.au/F2018L00631/latest/text
Records management and retention schedule; System access controls and user access reviews; Secure destruction certificates or disposal log; Data breach response procedureShared logins to the client system; Paper files kept in unlocked areas of shared homes☐ yes
☐ partly
☐ no
☐ n/a

Completing this worksheet records what your practice holds and where. It does not make a practice compliant or ready for audit, and it is not legal advice.