Skip to main content
Back to blog
Compliance Tips

5 Documents the NDIS Commission Checks First in an SDA Audit

MySDAmanager Team7 min read

When an NDIS auditor arrives, announced or unannounced, they follow a well-established playbook. They are not reviewing every document in your filing cabinet. They are checking specific evidence points that indicate whether your organisation has robust compliance systems or is operating on hope and good intentions.

After working with SDA providers across Australia, we have identified the five documents that auditors consistently request first. Getting these right does not guarantee a clean audit, but getting any of them wrong almost certainly guarantees a finding.

1. Participant consent forms (APP 3)

What auditors look for

A valid, signed consent form for every current participant. The form must comply with Australian Privacy Principle 3 (APP 3), which governs the collection of personal information. For SDA providers, this is particularly sensitive because you are collecting and storing health-related information, NDIS numbers, emergency contacts, and financial details.

What constitutes compliance

  • Consent was obtained before or at the time of information collection
  • The consent form clearly states what information is being collected and why
  • The participant (or their nominee/guardian) has signed and dated the form
  • Consent is current, not expired and not withdrawn
  • For participants with cognitive impairment, an Easy Read version was provided

Common gaps

The most frequent issue is expired consent. Many providers obtain consent at intake and never revisit it. Consent should be renewed annually at minimum, or whenever there is a material change to the information being collected or how it is used. A signed form from three years ago with a previous address is not current consent.

The second most common gap is the absence of Easy Read formats. The NDIS Commission expects providers to make reasonable adjustments to ensure participants understand what they are consenting to.

2. Fire safety statements (FP1500 in NSW)

What auditors look for

Current Annual Fire Safety Statements (FP1500 in NSW, equivalent forms in other states) for every SDA property. These statements certify that all essential fire safety measures in the building have been assessed by a competent fire safety practitioner and are performing to the required standard.

What constitutes compliance

  • An FP1500 (or state equivalent) exists for every property
  • The statement is dated within the last 12 months
  • It covers all essential fire safety measures listed on the fire safety schedule
  • It was prepared by a qualified fire safety practitioner
  • A copy has been prominently displayed in the building

Common gaps

Expired certificates are the number one issue. Fire safety statements are annual, and the renewal date varies by property. When you manage 15 to 20 properties, tracking 15 to 20 different expiry dates manually is a recipe for gaps. A single expired fire safety statement is an immediate non-compliance finding because it directly affects participant safety.

The other common gap is incomplete coverage. The statement must address every measure on the fire safety schedule. If the building has been modified (e.g., new smoke detectors, updated sprinkler systems), the schedule and statement must reflect these changes.

3. Incident register with chain of custody

What auditors look for

A complete incident register showing every recorded incident, with clear timestamps demonstrating compliance with reporting obligations. For NDIS reportable incidents, the auditor will check that the NDIS Commission was notified within 24 hours and that a detailed report was submitted within 5 business days.

What constitutes compliance

  • Every incident has a unique identifier and creation timestamp
  • The register shows who recorded the incident, when, and what actions were taken
  • Reportable incidents have evidence of 24-hour NDIS notification
  • Follow-up actions are documented with completion dates and responsible parties
  • The register is tamper-evident, entries cannot be silently modified or deleted

Common gaps

Chain of custody is where most providers fall down. Auditors do not just want to see that an incident was recorded, they want to see an unbroken timeline from initial report through investigation to resolution. When incidents are recorded in Word documents or spreadsheets, there is no audit trail showing when entries were created or modified.

The 24-hour notification requirement for reportable incidents is another pressure point. If a field worker records an incident on Friday afternoon and the office does not see it until Monday morning, the notification window has already closed.

4. Complaints handling records

What auditors look for

Evidence that your organisation has a documented complaints handling procedure and that it is being followed. The NDIS Practice Standards require providers to acknowledge complaints within 24 hours and work towards resolution within 21 days.

What constitutes compliance

  • A documented complaints procedure accessible to participants and staff
  • Every complaint has a unique reference number and receipt timestamp
  • Evidence of 24-hour acknowledgment (email, letter, or documented phone call)
  • A resolution timeline with documented progress
  • Escalation to the NDIS Commission for complaints involving reportable incidents
  • Outcome letters sent to complainants

Common gaps

The 24-hour acknowledgment requirement catches many providers off-guard. When complaints arrive via email, phone, or the organisation’s website, there must be a system to ensure acknowledgment happens within the window, regardless of when the complaint arrives (weekends, public holidays, after hours).

The other gap is the absence of a documented procedure. It is not enough to handle complaints well in practice. The auditor needs to see a written, version-controlled complaints SOP that staff can reference and that aligns with the NDIS (Complaints Management and Resolution) Rules 2018.

5. Staff screening check clearances

What auditors look for

Current NDIS Worker Screening Check clearances for every staff member who has contact with participants. This includes direct support workers, property managers who visit sites, and any contractors who work in occupied SDA dwellings.

What constitutes compliance

  • Every relevant staff member has a current NDIS Worker Screening Check
  • Clearances are not expired (validity periods vary by state, typically 5 years)
  • The organisation maintains a register of all clearances with expiry dates
  • New staff have clearances before commencing participant-facing work (or are appropriately supervised while pending)
  • Contractors working in SDA dwellings have equivalent screening

Common gaps

Expired clearances for long-serving staff are the most common finding. A staff member hired five years ago may have had their screening check expire without anyone noticing. The screening check register needs proactive monitoring, not just a one-time check at hiring.

Contractor screening is frequently overlooked. When a plumber or electrician enters an occupied SDA dwelling, they are interacting with NDIS participants. The provider has an obligation to ensure appropriate screening is in place.

How to stay audit-ready

The common thread across all five documents is proactive monitoring. None of these compliance requirements are difficult to meet when you have systems that flag gaps before they become findings.

The providers who pass audits cleanly are not the ones with the best filing systems. They are the ones with automated alerts that tell them, 90 days in advance, that a fire safety certificate is about to expire. They are the ones with digital incident registers that timestamp every entry and cannot be silently modified. They are the ones with consent management workflows that trigger renewal reminders before consent lapses.

The tools exist. The question is whether you are using them.

Share this article

Ready to automate your SDA compliance?

Replace spreadsheets with purpose-built software. Properties, participants, compliance, and payments in one system.