ProviderQMS

Documents & audits

How to build an NDIS audit evidence register you can actually use

Build an NDIS audit evidence register with clear references, owners, periods and review status. Includes a worked example and retrieval check.

By ProviderQMS · Source review 2026-09-13 · Existing published guide

An evidence register is an index that helps you find and explain the records behind your quality work. It should answer three questions quickly: what does this record help demonstrate, where is the original, and has someone checked that it is suitable?

The register does not need to contain every attachment. In fact, copying full participant records into a general spreadsheet can make access harder to control. A reference to the properly stored original is often more useful than another copy.

This guide gives you a practical structure to build in a spreadsheet or your existing work system. The column names and workflow are suggestions, not a Commission-prescribed template or a guarantee that evidence will be accepted.

Begin with your actual audit scope

Use your current scope of audit and applicable modules to choose the areas your register needs to cover. Do not assume another provider's evidence list fits your registration groups or services. The Commission explains that audit type and scope depend on the supports delivered. NDIS Commission: the quality audit process.

Record the source and date of the scope you are using. If your services or scope change, you can then see which mappings need review.

Separate three things when building a row: the requirement being considered, the provider's process for meeting it, and evidence of what happened. A policy may explain the process. A completed record, observation or relevant account may help establish implementation. Give each item a defined purpose rather than treating a large file collection as proof by volume.

Build a small set of useful columns

Start with these fields. You can combine some on screen, provided their meaning remains clear.

Build a small set of useful columns
Field What belongs here
Evidence ID A stable reference such as EV-024
Requirement or review question The specific matter this evidence helps address
Applicable scope Service, site, module or other relevant boundary
Evidence title A descriptive name rather than “supporting document”
Record type Policy, completed record, review, observation or other source
Period or version Dates covered or the exact document version
Source location A durable link or controlled file reference
Owner Person responsible for maintaining the source
Access arrangement Who may access it and how a review will be arranged
Review status Not checked, checked, gap found or superseded
Review note What was checked, when, by whom and with what limits
Linked action The reference for any missing or unsuitable evidence

Use controlled status choices so a filtered list remains meaningful. Avoid a single “compliant” tick box: it can hide whether someone checked the link, reviewed the content or made a broader assessment.

Write a specific evidence question

“Incident management” is a topic. “Can we trace this sampled incident through assessment, assigned actions and review?” is a question a reviewer can test.

Specific questions help you notice missing links. You may have an incident form and a completed action, but no record connecting the action to the assessment that prompted it. Adding more unrelated incident forms will not fill that gap.

Keep requirement references accurate. Link to the official source, identify the relevant section and distinguish your working question from the regulator's wording. The Practice Standards contain outcomes and indicators used in assessment; your register is a way to organise relevant material around them. NDIS Commission: NDIS Practice Standards.

A fictional three-row register

This example is invented to show the structure. Its titles, references and records do not represent a real provider or a required evidence set.

A fictional three-row register
ID and question Evidence and boundary Review and next step
EV-024: Can a sampled incident be followed through review? Incident DEMO-014, assessment and linked action AC-009; one incident from September Owner checked all three references open. Reviewer still needs to assess the decision and closure evidence.
EV-025: Can workers access the current complaint procedure? Procedure QP-006 version 1.3 and a retrieval check at Example House; September check Two workers found the current version. An old printed copy was also found; action AC-010 remains open.
EV-026: Was the agreed follow-up communicated? Restricted communication record for complaint DEMO-C03; one agreed contact Contact record exists but does not show whether the person's preferred communication method was used. Clarification assigned.

Notice that the register records weaknesses. It does not hide the old copy or label the communication complete merely because there is a dated note.

The row also distinguishes a link check from a content review. A working URL proves that you can open something. It does not prove that the record supports the question being asked.

Keep evidence current without erasing history

For a policy, record the approved version and effective date. For completed records, record the period and the actual record references. For an observation, record when it occurred, its scope and who made it.

Do not replace an old completed form simply because the blank template has changed. The completed form is evidence of a particular event. Link any correction or later action so a reviewer can follow the sequence.

When a source is superseded, preserve the history required by your retention arrangements and label its role. An older procedure may remain relevant to an event that occurred while it was in use. A current procedure may be relevant to the corrective action that followed. Both can matter for different reasons.

Make missing evidence visible

Use “gap found” when a needed record cannot be located or does not answer the review question. Describe the gap precisely: “No record of the promised follow-up found in the approved location as at 13 September” is better than “documentation issue.”

Assign the next step. It might be to search another authorised source, clarify what occurred, correct a process or schedule a genuine check of current practice. Do not recreate a historical record and present it as contemporaneous evidence.

If someone provides a later recollection, label it with its actual creation date and basis. If the event cannot be established, retain that limitation. Honest gaps support better decisions than a register that appears complete because uncertainty has been removed from view.

Use samples with clear boundaries

For your own preparation, select records that help test a real question and state how you chose them. Include known problem cases where relevant; checking only your neatest files tells you little about weaknesses.

Do not present an internal sample as the auditor's final selection. The Commission describes audits as including document review, interviews and observations, depending on the audit. The quality audit process.

Write a short limitation beside each sample: which site, period, service and records were reviewed. If a finding suggests the issue extends beyond that boundary, record a decision about further review. A two-record check cannot support a confident statement about an entire organisation without additional evidence.

Test access before you share the register

Ask an appropriately authorised colleague to follow several references without you navigating for them. Check whether the links require your personal account, point to a local desktop path or open an obsolete copy.

Use the access the reviewer is actually meant to have. Do not solve a permission problem by making a participant folder public. The Core information-management indicators address controlled access and the secure handling of participant records. NDIS Commission: information management.

Keep a sharing note identifying the recipient, authorised purpose and access period where appropriate. Remove access when the review no longer requires it, consistently with your information-handling arrangements.

Maintain the register as work changes

Choose a practical review rhythm and an owner. Review affected rows when a source changes, an action closes, a link moves or the service scope changes. A calendar check can catch broken links, but changes should not wait for that date.

Before marking a row checked, confirm:

  • The question and scope are clear.
  • The original record is retrievable by the right people.
  • Its version or period is stated.
  • The reviewer has recorded what the evidence does and does not show.
  • Any gap has an owner and linked action.
  • Participant information is not copied into unnecessary locations.
  • Earlier versions and decisions remain traceable where required.

Build your first five rows around one process, such as incident follow-up, before importing an entire document library. That small start will expose naming, access and review problems while they are still manageable.

To see an issue, action and supporting history kept together, watch the ProviderQMS walkthrough.

Official sources reviewed 13 September 2026. This register design is an organisational method, not an official audit checklist or a finding of conformity.

Existing published source retained. Original source review: 2026-09-13. Citations appear in the guide above. The new layout does not imply a new regulatory review.