Built for Australian NDIS Providers: automated expiry tracking, mobile SMS signing, and audit logs.Try Free
NDIS Practice Standards Core Module Ready

NDIS 7-Year Audit Readiness Checklist & Scorecard

Assess your agreement execution, evidentiary records, and retention practices against 10 mandatory standards. Identify compliance vulnerabilities before your auditor does.

Audit Readiness Score
50%(5 of 10 verified)
Critical Audit Risk

Significant compliance gaps detected. High probability of non-conformities or billing clawbacks in an audit.

|
#1

Executed Prior to Service Delivery

Practice Standard 1.2: Human Rights & Consent

The service agreement was signed by both parties before the first billable hour of support commenced.

Audit Risk: Billing services delivered before agreement execution risks full payment clawbacks during NDIA review.
Remediation: Ensure your intake workflow sends digital agreements with SMS signing links immediately upon enquiry.
#2

Current NDIS Price Limit Alignment

Practice Standard 2.3: Support Planning

Support item codes, hourly rates, and travel allowances strictly match current NDIS Price Limits.

Audit Risk: Billing even $1.00 above the gazetted cap constitutes a serious breach and triggers mandatory refunds.
Remediation: Include an automatic clause stating rates adjust automatically in line with annual NDIA price updates.
#3

Compliant 7-Day Cancellation Clause

Practice Standard 2.4: Service Agreements

Cancellation policy explicitly reflects the NDIS 7-day short-notice threshold and 100% claim limits.

Audit Risk: Unlawful cancellation clauses (such as 14-day notice or charging beyond 100%) are routinely flagged by auditors.
Remediation: Update your service agreement to state clearly that short notice applies only to cancellations inside 7 days.
#4

Supported Decision-Making & Easy-Read Option

Practice Standard 1.1: Person-Centred Supports

Terms are documented in plain English, and supported decision-making assistance was offered to the participant.

Audit Risk: Auditors evaluate whether participants understood what they signed, particularly around fee structures.
Remediation: Keep summary bullet points of key obligations at the top of your agreement or provide an Easy Read appendix.
#5

Verified Representative Capacity (Where Applicable)

NDIS Act 2013 (Part 2: Nominees & Guardians)

Where signed by a nominee, guardian, or advocate, the legal basis of authority is captured and recorded.

Audit Risk: Agreements signed by informal family members without formal authority can be disputed in family disagreements.
Remediation: Capture the representative role (Plan Nominee, Appointed Guardian, or Formal Advocate) during intake.
#6

Executed Copy Delivered Within 5 Days

Practice Standard 2.4: Service Agreements

A completed copy of the signed agreement was provided to the participant or representative within 5 business days.

Audit Risk: Failing to deliver completed copies undermines informed consent and violates Quality Standards.
Remediation: Use an automated platform that instantly emails the final executed PDF and completion certificate to all signers.
#7

Cryptographic Tamper-Evident Audit Certificate

Electronic Transactions Act 1999 (Cth) s 10

Signature record includes verified IP address, UTC timestamp, mobile/email verification, and document hash.

Audit Risk: Pasted signature images without audit metadata have weak evidentiary weight if disputed by plan managers.
Remediation: Retain an audit certificate containing SHA-256 hashes and timestamped signing telemetry for every document.
#8

Australian Sovereign Cloud Data Storage

Privacy Act 1988 (Cth) & Australian Privacy Principles

All participant health notes, NDIS numbers, and signed agreements are hosted within Australian borders.

Audit Risk: Storing sensitive participant health records on unvetted offshore servers can breach the Privacy Act.
Remediation: Verify your software vendor stores data exclusively in Australian data centres (e.g. Sydney or Melbourne).
#9

7-Year Mandatory Record Retention Guarantee

Practice Standard 2.2: Information Management

Agreements and evidentiary certificates are retained in a searchable archive for a minimum of 7 years.

Audit Risk: NDIS Commission audits review agreements dating back several years. Missing historical files cause major findings.
Remediation: Ensure your document repository maintains permanent archives that survive staff turnover and device resets.
#10

Mandatory Complaints & Incident Referral Details

Practice Standard 1.4: Complaints Management

Agreement includes provider internal dispute procedures and direct contact details for the NDIS Commission.

Audit Risk: Omitting NDIS Quality and Safeguards Commission contact details is an automatic non-conformity in core audits.
Remediation: Include the NDIS Commission contact line (1800 035 544) in the standard complaints clause of your agreement.

How to Assemble an Auditor-Proof NDIS Evidence Pack in 3 Steps

1

Export Agreement PDFs

Download the complete, fully executed PDF with all signed schedules, terms of support, and payment arrangements intact.

2

Attach Completion Certificates

Verify every agreement includes cryptographic proof: timestamped audit events, verified IP addresses, and email confirmation tokens.

3

Store in Sovereign Cloud

Ensure records remain securely archived in an Australian-hosted database for 7 years, protected from local device losses.

Frequently Asked Questions: NDIS Audit Compliance

Guidance on navigating NDIS Commission audits and maintaining compliant document repositories.

Automate 100% of your NDIS audit trail compliance

Fair Enough generates tamper-evident completion certificates with full telemetry, automated 7-year storage, and instant audit evidence exports for every signed agreement.

Start Your Free 14-Day Provider Trial