NDIS audits are getting tougher. With the NDIS Commission’s “Crack Down on Fraud” program intensifying and new compliance requirements rolling out, providers who coast on the bare minimum are finding themselves in trouble. The most common reason? NDIS compliance gaps that were entirely preventable.
The frustrating part? Most audit failures aren’t caused by serious misconduct. They’re caused by documentation gaps, process oversights, and compliance blind spots that should have been caught well before an auditor arrived.
After analysing hundreds of NDIS audits, we’ve identified the five NDIS compliance gaps that trip up Australian providers most often. Here’s what they are and how to fix them before your next audit.
Gap 1: Incomplete Worker Screening Records
The problem: Worker screening checks are completed, but the documentation trail is incomplete or inconsistent. Auditors find expired clearances, missing verification dates, or no evidence that checks were completed before workers started delivering services. This is one of the most frequently cited NDIS compliance gaps across the sector.
Why it happens: Most providers complete the checks but rely on manual tracking systems. When staff turnover occurs or admin responsibilities shift, screening records fall through the cracks. A worker might have a valid clearance, but if you can’t prove when it was verified, you have a compliance gap.
How to fix it:
- Centralise all worker screening records in one system
- Set automated alerts for clearances expiring within 90 days
- Document the verification date, not just the clearance date
- Maintain a clear audit trail showing checks were completed before service delivery commenced
- Include screening verification in your onboarding checklist with sign-off requirements
Gap 2: Incident Management That Stops at Reporting
The problem: Incidents are reported to the NDIS Commission as required, but there’s no documented evidence of investigation, root cause analysis, or preventive action. The incident register shows what happened, but not what you did about it.
Why it happens: Providers focus on meeting the 24-hour or 5-day reporting deadlines and breathe a sigh of relief once the notification is submitted. The follow-up investigation gets deprioritised, delayed, or completed verbally without documentation.
How to fix it:
- Create a standardised incident investigation template that captures root cause, contributing factors, and corrective actions
- Set mandatory timeframes for investigation completion (not just initial reporting)
- Document all follow-up actions with dates, responsible persons, and completion status
- Review incident trends quarterly to identify systemic issues
- Link incident learnings to staff training and policy updates
Gap 3: Service Agreements That Don’t Match Service Delivery
The problem: Service agreements exist, but they don’t accurately reflect the services being delivered. Pricing has changed, support types have evolved, or participant goals have shifted, but the agreement hasn’t been updated. Among NDIS compliance gaps, this one catches providers off guard because the original agreement was technically compliant at the time of signing.
Why it happens: Service agreements are often treated as a “set and forget” document created during onboarding. As participant needs change and services adapt, updating the formal agreement falls behind operational reality.
How to fix it:
- Schedule mandatory service agreement reviews at least annually, or whenever NDIS plans are renewed
- Create a change management process that triggers agreement updates when services change
- Ensure pricing in agreements matches current NDIS Price Guide rates
- Document participant consent for any service variations
- Maintain version control showing agreement history and updates
Gap 4: Risk Assessments That Exist But Aren’t Actioned
The problem: Individual risk assessments are completed for participants, but there’s no evidence that identified risks are being actively managed. The assessment identifies a falls risk, but care plans don’t reflect falls prevention strategies.
Why it happens: Risk assessments are often completed as a compliance checkbox during intake. The assessment sits in the participant file, but its findings aren’t translated into practical support strategies or regularly reviewed as circumstances change.
How to fix it:
- Link risk assessments directly to support plans with specific mitigation strategies
- Review risk assessments whenever participant circumstances change significantly
- Document how identified risks are being managed in progress notes
- Train support workers on individual participant risks and required responses
- Include risk status in participant handover processes
Gap 5: Staff Training Records Without Competency Evidence
The problem: Training attendance is recorded, but there’s no evidence of competency assessment or practical application. Staff attended a manual handling workshop, but can they actually demonstrate safe manual handling techniques?
Why it happens: Training is often measured by attendance rather than outcomes. Providers tick the “training completed” box without verifying that staff actually absorbed and can apply the learning. This is especially common with online training modules.
How to fix it:
- Include competency assessments as part of all mandatory training
- Document practical demonstrations or assessments, not just attendance
- Implement refresher training schedules based on competency decay, not just calendar dates
- Link training records to specific NDIS Practice Standards requirements
- Supervisor sign-off on competency demonstration for high-risk skills
The Common Thread Behind These NDIS Compliance Gaps
Notice what these five NDIS compliance gaps have in common? They’re not about whether you’re doing the right thing. They’re about whether you can prove you’re doing the right thing.
Most NDIS providers genuinely care about their participants and deliver quality services. But when auditors arrive, good intentions don’t count. Evidence does.
The providers who pass audits with flying colours aren’t necessarily doing anything different operationally. They’ve just built systems that capture evidence of compliance as a natural byproduct of service delivery, rather than scrambling to reconstruct it before an audit. For a deeper understanding of what auditors are looking for, read our complete guide to NDIS audits.
From Reactive to Proactive: Closing NDIS Compliance Gaps for Good
The traditional approach to NDIS compliance is reactive: prepare intensively before audits, fix issues when they’re found, and hope nothing slips through the cracks in between.
A better approach is continuous compliance monitoring. Instead of discovering NDIS compliance gaps during audits, you identify them the moment they emerge. Instead of scrambling to gather evidence, your documentation is always audit-ready.
This is exactly what NDIS Autonomous Audit Software platforms like Audit Pilot are designed to do. By checking your compliance against all 8 NDIS Core Modules and 28 Practice Standards every single day, gaps are caught in days rather than quarters. To understand the full difference between these approaches, see our guide on autonomous auditing vs traditional audits.
Next Steps
If any of these five NDIS compliance gaps sound familiar, you’re not alone. They’re the most common compliance issues we see across Australian NDIS providers.
The good news? They’re all fixable. Start by auditing your own documentation against these five areas. Better yet, let Audit Pilot do it for you.
Book a demo and we’ll run a preliminary compliance check on your organisation, showing you exactly where your gaps are within 24 hours.
