NDIS Record Keeping and Documentation Requirements
Title: NDIS Record
Keeping and Documentation Requirements
Meta Description: A
complete guide to NDIS documentation requirements — service notes, attendance
records, invoices, and how to prepare your records for audit.
Keywords: NDIS
documentation, NDIS record keeping, NDIS service notes, NDIS attendance
records, NDIS audit preparation
NDIS Record Keeping and Documentation Requirements
Introduction
Good documentation is the backbone of NDIS compliance. For
registered providers, records are not optional extras — they are a core
obligation. For participants managing their own funds, they are a practical
necessity.
When an audit occurs, when a complaint is made, or when the
NDIA reviews a plan, documentation is the primary way a provider or participant
can demonstrate that supports were delivered correctly, funds were used
appropriately, and obligations were met.
Despite this, poor record keeping is one of the most common
compliance issues identified by the NDIS Quality and Safeguards Commission.
Many providers have the right intentions but lack the systems to turn those
intentions into reliable, auditable records.
This guide explains what NDIS documentation is required, what
good records look like in practice, and how to build record keeping habits that
hold up under scrutiny.
What Is NDIS Documentation?
NDIS documentation refers to the written records that
providers, participants, plan managers, and support coordinators must keep to
demonstrate compliance with NDIS rules and obligations.
Documentation falls into several broad categories:
Service records
Service records — sometimes called service notes, progress
notes, or case notes — are written accounts of the support delivered in each
session. They record what happened, when, who was involved, and any relevant
observations about the participant's wellbeing or progress toward their goals.
Attendance records
Attendance records confirm that a worker was present with a
participant at a specified time and for a specified duration. They may include
timesheets, sign-in logs, electronic check-ins, or rostering system data.
Attendance records are used to verify that hours billed match hours worked.
Invoices and financial records
Invoices must accurately reflect the service delivered, the
support item number used, the date and duration of the service, the rate
charged, and the total amount. Financial records must also include evidence of
payment, receipts where relevant, and any adjustments or credits applied.
Participant records
Participant records include the service agreement, the
participant's goals and support plan, any assessments or care plans,
communication records, and notes from reviews or meetings. These records form
the foundation of a provider's understanding of the participant's needs and the
basis for the services they deliver.
Worker records
Worker records include employment or contractor agreements,
NDIS Worker Screening clearance evidence, qualifications and training records,
induction documentation, and supervision or performance records.
Governance and policy records
Registered providers must maintain current written policies
covering key areas such as incident management, complaints handling, privacy,
and participant rights. Governance records also include board or management meeting
minutes, risk registers, and evidence of policy reviews.
Why NDIS Documentation Matters
It is a legal and regulatory requirement
Registered providers are required to maintain records as part
of meeting the NDIS Practice Standards. The NDIS Commission can request records
at any time, and failure to produce them — or producing records that are
inaccurate or incomplete — is a compliance breach.
It protects providers during audits and investigations
When an audit or compliance review occurs, documentation is
the primary evidence an auditor or investigator will rely on. A provider who
can produce clear, accurate, and timely records is in a far stronger position
than one who cannot.
It protects participants
Good records support continuity of care. When a worker
changes, when a participant's needs evolve, or when a review is due, detailed
service records ensure that important information is not lost. Records also
protect participants by creating a traceable account of what supports were
provided.
It supports correct payment
Invoices must match the service records that underpin them.
When they do not — because notes are missing, times are inconsistent, or
support items do not align — there is a risk of incorrect payment, repayment
demands, or fraud allegations even when the error was unintentional.
It enables quality improvement
Providers who review their own records regularly can identify
patterns — supports that are not working, participants who are disengaging, or
workers whose documentation needs improvement. Documentation is not just a
compliance tool; it is a quality management tool.
Common Documentation Mistakes
Writing notes in bulk at the end of the week or month
Service notes should be written at or shortly after the time
of the support. Notes written days or weeks later from memory are less
reliable, less detailed, and less credible to an auditor. They are also more
likely to contain errors about dates, times, and what actually occurred.
Vague or generic service notes
Notes that simply say 'support provided as per plan' or
'community access' do not meet documentation requirements. A service note
should describe what actually happened during the session — what activities
were undertaken, how the participant engaged, any challenges that arose, and
any relevant observations about the participant's wellbeing or progress.
Timesheets that do not match service notes
If a timesheet records four hours of support but the service
note describes a two-hour session, there is an inconsistency that will be
identified in any serious review. Attendance records and service notes must
align.
Missing or unsigned service agreements
A service agreement is a foundational document in any
provider-participant relationship. Delivering services without a signed service
agreement — or with one that has not been updated when circumstances change —
is a common compliance gap.
Storing records insecurely
Records containing participant information are subject to
privacy obligations. Storing records in unsecured shared drives, on personal
devices, or in unlocked physical filing systems creates both a privacy risk and
a compliance risk. Access should be restricted to those who genuinely need it.
Not retaining records for the required period
Records must be kept for a minimum period after the service
was delivered or the employment relationship ended. Many providers delete
records too soon — often when changing systems or after a participant leaves —
without realising the retention obligation still applies. Always check current
NDIS Commission guidance on required retention periods.
Inconsistent invoice numbering and formatting
Invoices should follow a consistent format and numbering
system. Invoices that are handwritten, inconsistently dated, or missing
required information — such as the provider's ABN, the support item number, or
the participant's NDIS number — create processing problems and raise questions
during review.
Key Requirements and Best Practices
Service notes: what to include
Every service delivery session should be documented with a
service note that covers:
•
The participant's name and NDIS number
•
The date of the session
•
The start and finish time
•
The name of the worker who delivered the support
•
The type of support delivered and the relevant support
item
•
A description of what occurred during the session
•
Any observations relevant to the participant's
wellbeing, safety, or goal progress
•
Any incidents, near misses, or concerns that arose
Notes do not need to be lengthy, but they do need to be
specific. A clear two-paragraph note written promptly is far more valuable than
a half-page note written three days later.
Attendance records: best practice
Attendance records should be generated at the time of the
support — not reconstructed after the fact. Electronic rostering and
timekeeping systems that create timestamped records are the most reliable
approach. Where paper timesheets are used, they should be completed on the day
and countersigned where possible.
Providers should regularly cross-check attendance records
against service notes and invoices. Any discrepancies should be investigated
and resolved before the invoice is submitted.
Invoice requirements
An NDIS-compliant invoice should include:
•
The provider's legal name and ABN
•
The provider's registration number (for registered
providers)
•
The participant's name and NDIS number
•
The date the service was delivered
•
The support item number from the NDIS Support Catalogue
•
A description of the service
•
The quantity (hours or units) and the rate charged
•
The total amount
•
A unique invoice number
Invoices submitted to the NDIA portal for agency-managed
participants must use the correct support item numbers. Incorrect item numbers
can cause payment delays or rejections.
Retention periods
As a general guide, most NDIS provider records should be
retained for a minimum of seven years. However, retention requirements can vary
depending on the type of record, the age of the participant, and the
jurisdiction. Providers should check current NDIS Commission guidance and seek
advice where they are uncertain. When staff leave or participants exit, the
obligation to retain records does not end.
Digital record keeping systems
Purpose-built practice management software can significantly
reduce the administrative burden of NDIS record keeping while improving
accuracy and reliability. Features to look for include timestamped service note
entry, integration with rostering and invoicing, secure cloud storage, access
controls, and audit trail functionality.
Providers who use paper-based systems should have a clear
process for scanning and storing records digitally, along with a backup
procedure to prevent data loss.
Preparing for audit
Providers who maintain records correctly throughout the year
will find audit preparation straightforward. An internal pre-audit checklist
should include:
•
Confirm all worker screening clearances are current and
recorded
•
Verify that service notes exist for all invoiced
sessions within the audit period
•
Check that attendance records align with service notes
and invoices
•
Ensure all participant service agreements are signed
and current
•
Confirm that incident and complaint registers are up to
date
•
Review policies to ensure they reflect current practice
and have been recently reviewed
•
Organise records by participant and by document type so
they can be produced quickly on request
Risks and Warning Signs
The following patterns suggest a provider's documentation
practices may not withstand scrutiny.
•
Service notes that are consistently completed days
after the support was delivered
•
Notes that use identical or near-identical language
across different sessions or different participants
•
Invoices submitted for periods where no corresponding
service notes can be located
•
Worker timesheets that are consistently rounded to the
nearest hour regardless of the actual duration of support
•
Participant files where the service agreement has not
been updated despite the participant's needs or plan changing
•
Records stored on individual workers' personal devices
rather than a centralised system
•
No documented process for what happens to records when
a worker leaves the organisation
•
An incident register with very few entries relative to
the number of participants and support hours delivered
•
Policies that reference outdated legislation, old
contact numbers, or processes that staff do not recognise
Any of these should prompt an internal review before they are
identified by an external auditor.
Practical Examples
Example 1: Service notes that do not support the invoice
A registered provider submits an invoice to a plan manager for
20 hours of daily personal care over a two-week period. The plan manager
requests supporting service notes as part of their standard verification
process.
The provider produces notes for 14 of the 20 billed sessions.
Three sessions have notes that simply say 'personal care provided'. Three
sessions have no notes at all.
The plan manager declines to pay for the undocumented sessions
and asks the provider to address the gap before resubmitting. The provider is
also asked to improve note quality for future claims. This is a compliance
issue that could have significant consequences if it persists or is escalated
to the NDIS Commission.
Example 2: Attendance records prevent a fraud allegation
A disability support worker employed by a medium-sized
provider is accused by a participant's family of not turning up for several
scheduled shifts and still being paid. The provider's HR manager reviews the
electronic rostering system, which captures GPS check-ins at the participant's
address.
The records confirm that the worker did attend for all but one
of the disputed shifts, and that the one missed shift was recorded as
unattended and not invoiced. The provider is able to provide this documentation
to the family and to the NDIS Commission contact centre when the family lodges
a complaint.
Without reliable attendance records, the provider would have
had no way to defend the worker or demonstrate that billing was accurate.
Example 3: Audit preparation for a growing provider
A provider that has grown from two to twelve participants over
18 months is approaching their first certification audit since expanding. The
director conducts an internal documentation review and finds significant
inconsistency — some participant files are complete and well-organised, others
are missing signed service agreements, and worker files for three casual
employees have no evidence of NDIS Worker Screening clearances being sighted.
Over eight weeks before the audit, the director works through
a file-by-file checklist. Missing clearances are obtained and recorded, service
agreements are updated and signed, and a standard service note template is
introduced across the organisation.
The audit proceeds and the provider passes with two minor
findings — both administrative — which are resolved within the required
timeframe. The director attributes the positive outcome directly to the
pre-audit internal review.
Frequently Asked Questions
What records must NDIS providers keep?
NDIS providers must keep service records (notes of what
support was delivered and when), attendance records, invoices and financial
records, participant files including service agreements and care plans, worker
records including screening clearances and training evidence, and governance
documents such as policies and incident registers. Registered providers are
assessed against these requirements during audits.
How long must NDIS records be kept?
As a general guide, NDIS provider records should be retained
for a minimum of seven years. Some record types — particularly those involving
children — may have longer retention requirements depending on the
jurisdiction. Providers should confirm current requirements with the NDIS
Commission and seek legal advice if uncertain. The retention obligation does
not end when a participant exits or a worker leaves.
What should a good NDIS service note include?
A good service note includes the participant's name and NDIS
number, the date and time of the support, the name of the worker, the type of
support delivered, a specific description of what occurred during the session,
any observations relevant to the participant's wellbeing or goals, and any
incidents or concerns that arose. Notes should be written promptly and should
be specific to the individual session.
Do unregistered providers need to keep records?
Unregistered providers are not subject to the NDIS Practice
Standards and are not audited by the NDIS Commission. However, they may still
be required to provide records if they work with self-managed participants who
are subject to an NDIA review, or if a complaint is made about their services.
Good record keeping is sound practice regardless of registration status.
Can records be kept digitally?
Yes. Digital records are acceptable and often preferable,
provided they are stored securely, backed up regularly, and accessible only to
authorised staff. Purpose-built practice management software is recommended for
providers managing multiple participants, as it creates reliable audit trails
and reduces the risk of records being lost or altered.
What happens if a provider cannot produce records during an
audit?
If a provider cannot produce records requested by an auditor,
the auditor will note the absence as a finding. Depending on the significance
of the missing records, this may result in non-compliance with the NDIS
Practice Standards. The NDIS Commission may then require corrective action,
impose conditions on registration, or take further regulatory steps. Inability
to produce records is taken seriously because it may indicate that services
were not delivered as claimed.
Do participants need to keep records?
Self-managed participants are responsible for keeping records
of how their NDIS funds were spent, including invoices and receipts. The NDIA
can audit self-managed plans and request evidence of spending. Participants who
cannot produce records to support their claims may be required to repay amounts
that cannot be verified. Plan-managed participants rely on their plan manager
to maintain financial records.
Future Trends in NDIS Documentation
Increased use of digital practice management platforms
The shift toward digital record keeping is accelerating across
the NDIS sector. Purpose-built platforms that integrate rostering, service
notes, invoicing, and incident reporting are becoming standard for providers of
all sizes. Providers still relying on paper-based or manual systems face
growing administrative risk as expectations around documentation quality
increase.
Real-time documentation expectations
There is growing regulatory interest in whether service notes
are created at the time of support delivery or retrospectively. Some digital
systems now capture the time a note was created alongside the time of the
session, creating a natural audit trail. Providers should expect scrutiny of
note-creation timestamps to become more common in future audits.
Stronger requirements for self-managed participants
As the NDIA increases oversight of self-managed plans,
participants who self-manage are likely to face clearer and more consistently
enforced documentation requirements. The expectation that self-managed
participants retain invoices, receipts, and service records is likely to become
more formalised.
Integration of documentation with outcomes measurement
Future compliance frameworks may require providers to
demonstrate not just that services were delivered and documented, but that they
contributed to measurable participant outcomes. This would require service
notes to capture goal progress, not just service activity. Providers who build
outcome-oriented documentation habits now will be well placed as these
expectations evolve.
Final Thoughts
NDIS documentation is not bureaucratic box-ticking. It is the
written record of the support a person received — a record that protects
participants, supports providers, and enables the scheme to function with
integrity.
The providers who find documentation burdensome are often
those who treat it as separate from service delivery. The providers who do it
well tend to see it as part of the service itself — a professional record of
the work done and the difference it made.
Building strong documentation habits does not require complex
systems or large teams. It requires consistency, clarity, and a commitment to
recording what actually happened at the time it happened.
If your current documentation practices would not hold up to
an audit, now is the time to address them — not when an auditor is already at
the door. An internal review, a clear template, and a modest investment in
digital tools can make a significant difference.
For guidance on specific documentation requirements, always
refer to the NDIS Practice Standards, the NDIS Commission's evidence guides,
and any relevant guidance from your state or territory authority.
Suggested Internal Links
Consider linking this article to the following related content
on your website:
Related NDIS Articles
•
The Complete Guide to NDIS Compliance for Providers —
obligations, registration, and ongoing requirements
•
The Complete Guide to NDIS Audits — what auditors look
for and how to prepare
•
The Complete Guide to NDIS Fraud Prevention — how poor
documentation enables fraud
•
NDIS Incident Reporting — timeframes, templates, and
what must be recorded
Supporting Topics
•
NDIS Service Agreements — what must be included and
when to update them
•
NDIS Worker Screening — what clearances are required
and how to record them
•
Complaints Management for NDIS Providers — how to
document and respond to complaints
•
NDIS Privacy Obligations — how to store and protect
participant information
Relevant Guides
•
How to Write a Good NDIS Service Note — a practical
guide for support workers
•
NDIS Invoice Requirements — what must appear on every
invoice
•
Choosing a Practice Management System for NDIS
Providers
•
Preparing for an NDIS Certification Audit — a
documentation checklist
Disclaimer:
This article provides general information only. NDIS documentation requirements
and retention periods are subject to change. Always refer to current guidance
from the NDIS Quality and Safeguards Commission (www.ndiscommission.gov.au) and
the NDIA (www.ndis.gov.au) for the most up-to-date requirements.
Comments
Post a Comment