Allied Health NDIS Audit Checklist: worksheet
NDIS Practice Standards and Quality Indicators. Edition held: Rules Schedules 1 to 8, Compilation No. 6 (F2026C00527) and Quality Indicators Guidelines Compilation No. 3 (F2026C00528), in force 1 July 2026; checked current on 6 October 2026 (Federal Register: both compilations are the latest version on 6 October 2026).
Under review, not in force: The NDIS Commission's review of the Practice Standards (a proposed quality framework and changes to the standards and how they are assessed) is still being considered; nothing from it is in force.
Standards library: https://compliance.theartofservice.com/frameworks/australia-ndis-practice-standards-and-quality-indicators. Page: https://allied-health-ndis-audit-checklist.theartofservice.com/rules/ndis-practice-standards/core-information-management/
| Ref | Requirement (our statement of the clause) | Evidence an auditor or the regulator asks for | Common gap to check | Held (yes, partly, no, not applicable) | Where it is kept | Owner | Last reviewed | Next review |
|---|---|---|---|---|---|---|---|---|
| Core 12.1 | The provider gets each participant's consent to collect, use and keep their information and to disclose it, including assessments, to other parties, and explains the purpose. Participants are told when information may be disclosed, including without consent where the law requires or authorises it. Source: https://www.legislation.gov.au/F2018L00631/latest/text | Consent to collect and share information forms naming parties and purposes; Privacy notice describing disclosure required or authorised by law; Records of disclosures made and the consent or legal basis for each | Blanket consent with no named parties or purposes; Assessments shared with other providers without consent on file | ☐ yes ☐ partly ☐ no ☐ n/a | ||||
| Core 12.2 | Each participant is told how their information is stored and used, and when and how they can access or correct it and withdraw or change consent they gave earlier. Source: https://www.legislation.gov.au/F2018L00631/latest/text | Privacy statement or handbook explaining access, correction and withdrawal; Register of access or correction requests and responses; Records of consent withdrawals and the actions taken | No process for a participant to see their own file; Withdrawn consent not flagged in the client system | ☐ yes ☐ partly ☐ no ☐ n/a | ||||
| Core 12.3 | The provider keeps an information management system proportionate to its size and scale that records each participant's information accurately and on time. Source: https://www.legislation.gov.au/F2018L00631/latest/text | Client management system or file structure description; Sample of participant files with dated, contemporaneous progress notes; File audit results checking accuracy and timeliness | Progress notes written days after the shift; Duplicate or conflicting records across paper and electronic systems | ☐ yes ☐ partly ☐ no ☐ n/a | ||||
| Core 12.4 | Documents are handled with processes for appropriate use, access, transfer, storage, security, retrieval, retention, destruction and disposal that suit the scope and complexity of the supports delivered. Source: https://www.legislation.gov.au/F2018L00631/latest/text | Records management and retention schedule; System access controls and user access reviews; Secure destruction certificates or disposal log; Data breach response procedure | Shared logins to the client system; Paper files kept in unlocked areas of shared homes | ☐ yes ☐ partly ☐ no ☐ n/a |
Completing this worksheet records what your practice holds and where. It does not make a practice compliant or ready for audit, and it is not legal advice.