Registered NDIS providers go through a Practice Standards audit, verification for lower-risk registration groups, certification for higher-risk ones, to keep their registration current. The Practice Standards themselves are written broadly, but auditors ultimately want the same thing: evidence that participant information is actually being handled the way your policies say it is. Here's what that means in practice for IT and data.
It's Evidence, Not Just Policy
A written information management policy is the starting point, not the finish line. Auditors look for evidence that the policy reflects what actually happens: access logs, incident records, a real backup and continuity history, and staff who can describe how they handle participant records day to day without reciting a document they were handed once during induction. A policy nobody can demonstrate in practice is one of the more common findings in a Practice Standards audit.
What Auditors Typically Look For
- Access control evidence. Can you show that only staff involved in a participant's support can access their records, and that access is removed when a staff member or contractor leaves or changes role? A list of who currently has access isn't enough on its own, auditors want to see that access is actually reviewed on a schedule.
- Individual accountability. Shared logins make it impossible to demonstrate who accessed a given record, which directly undermines the audit trail auditors expect to see.
- Incident records. A documented history of how information-related incidents, a lost device, a misdirected email, an access anomaly, were identified, actioned, and closed out. An organisation with zero recorded incidents over several years often reads as under-reporting rather than a genuinely clean record.
- Business continuity evidence. Not just a written plan, but proof it's been tested: a documented backup restore test, or a record of how a system outage was actually handled without disrupting participant support.
- Staff awareness. Auditors frequently interview frontline staff directly. If a support worker can't explain, in their own words, what to do if they suspect a privacy breach, that gap shows up regardless of how well-written the policy document is.
Two Separate Reporting Obligations, Often Confused
Registered providers sit under two different incident reporting regimes, and audits sometimes surface confusion about which applies when. The Notifiable Data Breaches scheme under the Privacy Act covers breaches of personal information generally, reported to the OAIC when the breach is likely to cause serious harm. NDIS reportable incidents are a separate scheme entirely, reported to the NDIS Quality and Safeguards Commission, and cover a broader category of events affecting participants, some of which have nothing to do with data at all. A single incident, a lost device containing participant records, for example, can trigger obligations under both schemes simultaneously. Knowing which applies, and being able to show you know, is something auditors specifically probe for.
Where IT Providers Usually Fall Short
A generalist IT provider can keep systems running without ever building the audit trail a Practice Standards review actually requires. Individual accountability, access reviews on a schedule, tested continuity plans, and documented incident handling all need to be set up deliberately, they don't happen automatically just because good IT support is in place. For the broader technical picture, including care management systems, mobile device management, and network segmentation, see our guide to IT support for Perth aged care and NDIS providers.
Preparing Well Ahead of an Audit
The organisations that go into a Practice Standards audit comfortably are the ones treating access reviews, incident logging, and continuity testing as routine operations, not a scramble in the weeks before an auditor is booked in. If you're not confident your evidence trail would hold up today, that's the gap worth closing first, well before a registration renewal is on the calendar.
Frequently Asked Questions
Does an NDIS audit actually inspect our IT systems directly?
Auditors don't typically run technical penetration tests, but they do ask for evidence: records showing access is controlled and reviewed, incident logs, backup and continuity documentation, and staff who can describe how information is actually kept secure day to day. A policy that doesn't match what staff can demonstrate in practice is a common audit finding.
What's the difference between a Notifiable Data Breach and an NDIS reportable incident?
They're separate schemes with separate obligations. The Notifiable Data Breaches scheme under the Privacy Act covers breaches of personal information generally, reported to the OAIC. NDIS reportable incidents, reported to the NDIS Quality and Safeguards Commission, cover a broader set of events affecting participants, including some that don't involve data at all. A registered provider may need to report the same incident to both bodies.
How far in advance should we prepare for an audit?
Ideally months, not weeks. Access reviews, incident logs, and continuity testing all need a track record behind them, not evidence created the week before the audit. A rushed preparation is usually visible to an experienced auditor.
Do smaller NDIS providers get an easier audit?
Verification (self-assessed) audits for lower-risk registration groups are less intensive than certification audits, but the underlying expectation, that you can demonstrate secure, appropriate handling of participant information, doesn't disappear just because the provider is small.
We help Perth NDIS providers build the access, incident, and continuity evidence a Practice Standards audit expects to see.
Aged Care & NDIS IT →Audit coming up and not sure your IT evidence would hold up?
Call 0433 087 091 for a free, no-obligation review of your current access controls and incident records.
Book a Free ConsultationFor related reading, see IT Support for Aged Care in Perth and The Notifiable Data Breaches Scheme.
This article explains general obligations under the NDIS Practice Standards and related reporting schemes as a starting point only. It is not legal or compliance advice. Confirm current requirements with the NDIS Quality and Safeguards Commission or a qualified compliance adviser before relying on it for registration purposes.