Audit
NDIS Human Resources Policy: What Auditors Look For
NDIS auditors assess your human resources policy against the Practice Standards by checking worker screening compliance, documented recruitment procedures, training and competency records, supervision frameworks, and performance management processes. A compliant HR policy must demonstrate how your organisation recruits, retains, and manages a workforce capable of delivering safe, high-quality supports.
Why Your HR Policy Is a Priority Audit Item
When an approved quality auditor arrives at your organisation — whether for initial registration, re-registration, or a mid-term audit — your human resources policy sits near the top of the document request list. This is not administrative box-ticking. The NDIS Quality and Safeguards Commission treats workforce governance as a direct safeguard for participants. An inadequate HR policy signals systemic risk, not just paperwork gaps.
Under the NDIS Practice Standards, providers must demonstrate that their workforce is appropriately screened, trained, supervised, and supported. The strengthened 2026 framework places even greater weight on evidence — auditors are trained to look past policy statements and into the systems and records that prove those statements are lived reality.
The Six Areas Auditors Examine in an HR Policy
1. Worker Screening and Pre-Employment Checks
Auditors will verify that your HR policy explicitly requires — and your records prove — compliance with the NDIS Worker Screening requirements. This means:
- A current NDIS Worker Screening Check (or equivalent state/territory check) for all workers in risk-assessed roles before they commence unsupervised work with participants.
- A documented process for checking and recording clearance status, including expiry dates and renewal triggers.
- A clear policy position on what happens when a worker's clearance is pending, lapses, or is excluded — including immediate stand-down procedures.
- Reference to the NDIS Code of Conduct obligations that apply to all workers and contractors, not just employees.
A common non-conformance is policies that require checks at commencement but contain no mechanism for ongoing monitoring. Auditors will ask: how does your organisation know if a clearance is revoked between renewal cycles?
2. Recruitment and Selection Procedures
Your policy must describe a structured, values-based recruitment process. Auditors are looking for:
- Position descriptions that specify required qualifications, experience, and personal attributes aligned to the NDIS Code of Conduct.
- Interview and reference-checking frameworks that probe for attitudes toward participant rights, dignity, and safety.
- Documentation requirements — what records are created and retained for each recruitment decision.
- Probationary review processes with defined competency benchmarks.
Under the strengthened standards, auditors pay particular attention to whether organisations have embedded the NDIS Practice Standards' expectations around person-centred practice into their recruitment criteria — not simply assumed workers will absorb these values on the job.
3. Induction, Training, and Competency Development
A policy that says "all workers complete induction" without specifying content, timeframes, or sign-off mechanisms will attract a finding. Auditors expect to see:
- A structured induction programme covering the NDIS Code of Conduct, mandatory reporting obligations, the organisation's incident management procedure, complaint handling, and participant rights.
- Mandatory and role-specific training modules with completion timelines (e.g., restrictive practices training for workers in services where PBS plans are in place).
- Evidence of ongoing professional development — not a once-per-year checkbox, but a system that responds to identified competency gaps and emerging Practice Standard requirements.
- Records accessible to the auditor: individual training logs, sign-off sheets, or learning management system reports.
Refresher training on reportable incidents, abuse and neglect recognition, and restrictive practices is scrutinised particularly closely because these are the domains most directly linked to participant harm.
4. Supervision and Performance Management
Auditors distinguish between an organisation that monitors worker performance and one that genuinely supports worker development. Your policy should describe:
- Regular, documented supervision sessions — the frequency will depend on worker experience and role complexity, but the policy must set minimum expectations.
- A performance appraisal cycle linked to the organisation's quality objectives and the NDIS Practice Standards.
- A clear, fair, and documented disciplinary process, including how the organisation responds to Code of Conduct breaches or substantiated complaints involving a worker.
- A process for immediate response when a worker is the subject of an allegation — including interim management measures that protect participants without prejudging the outcome.
5. Workforce Wellbeing and Support
The 2026 strengthened framework places increased emphasis on provider obligations to support worker wellbeing as a condition of safe service delivery. Auditors will look for:
- Access to Employee Assistance Programme (EAP) or equivalent psychological support.
- Workload management policies that do not create conditions for worker burnout and associated participant risk.
- Mechanisms for workers to raise concerns about workplace safety, service quality, or management decisions without fear of reprisal — a whistleblower-adjacent provision aligned to the Code of Conduct.
6. Contractor and Agency Worker Management
Many providers assume their HR policy only covers direct employees. This is a significant non-conformance. The NDIS Practice Standards and Worker Screening requirements apply to the workforce broadly — including contractors and labour-hire workers. Your policy must address:
- How contractor screening compliance is verified before engagement.
- How contractors are inducted into your organisation's policies, particularly around incident reporting and participant rights.
- Contractual clauses requiring contractors to comply with the NDIS Code of Conduct.
What Auditors Actually Ask For: A Practical Document Checklist
| Document | What the Auditor Is Checking |
|---|---|
| HR Policy (master document) | Currency, approval date, version control, CEO/Board endorsement |
| Worker Screening Register | All risk-assessed roles listed; clearance numbers, issue dates, expiry dates recorded |
| Induction Checklist (signed) | Evidence each worker completed mandatory modules before unsupervised participant contact |
| Training Records | Individual logs showing ongoing training aligned to role requirements |
| Supervision Records | Dated notes demonstrating regular, structured supervision has occurred |
| Position Descriptions | Qualification requirements, NDIS Code of Conduct reference, key responsibilities |
| Contractor Agreements | Code of Conduct obligations, screening clause, incident reporting requirements |
The Most Common Non-Conformances
Based on the types of audit findings the NDIS Commission's audit framework is designed to catch, the most frequently observed HR policy non-conformances include:
- Out-of-date policies — HR policies last reviewed before the Practice Standards were strengthened, with no reference to current worker screening obligations.
- Missing scope clauses — policies that apply only to "employees" and do not cover contractors, agency staff, or volunteers in participant-facing roles.
- No stand-down procedure — the policy describes screening requirements but does not specify what happens if a worker's clearance is revoked mid-employment.
- Training policy not linked to records — a beautifully written training section, but no corresponding records system to prove completion.
- Supervision policy without frequency standards — policies that say supervision "will occur regularly" without defining what regular means in practice.
- No mechanism for allegation management — the policy does not address interim management steps when a worker is accused of a Code of Conduct breach.
Policy Template Excerpt: Worker Screening Clause
The following is an example of how a compliant worker screening clause might read within an HR policy:
5.2 NDIS Worker Screening
All workers engaged by [Organisation Name] in roles assessed as involving more than incidental contact with NDIS participants must hold a valid NDIS Worker Screening Check (or recognised equivalent) prior to commencing unsupervised work with participants. The People and Culture team maintains a Worker Screening Register, which is reviewed no less than monthly. Where a clearance is pending, the worker must be directly supervised at all times. Where a clearance expires or is withdrawn, the worker is stood down from participant-facing duties immediately, pending resolution. Contractors and labour-hire workers are subject to the same requirements; verification of clearance status is obtained in writing prior to engagement commencement.
Preparing for Your Next Audit
The most audit-ready HR policies are written for two audiences simultaneously: the worker who needs to understand their obligations, and the auditor who needs to verify the organisation is meeting the NDIS Practice Standards. This means plain language, clear scope, version control, and a direct link between every policy statement and a corresponding record system.
If you are building or overhauling your HR policy ahead of registration or re-registration, ndiscompliant.com.au offers a 136-document SIL compliance kit that includes a pre-built HR policy, worker screening register template, induction checklist, and supervision record forms — all aligned to the current Practice Standards framework.
Above all, treat your HR policy as a living document. The NDIS Commission expects providers to review and update policies in response to regulatory changes, internal incidents, and audit findings. A policy that has not been touched in several years is itself a red flag.
Important: This article provides general guidance about NDIS compliance requirements. It is not legal or professional advice. Requirements may change as the NDIS Commission updates its policies and Practice Standards. Always verify current requirements with the NDIS Quality and Safeguards Commission or a registered NDIS consultant before making compliance decisions.
Frequently asked questions
Does an NDIS HR policy need to cover volunteers and contractors, or just employees?
Yes. The NDIS Worker Screening requirements and Code of Conduct obligations apply to the broader workforce, including contractors, agency staff, and volunteers in risk-assessed roles. Your HR policy must explicitly include these groups and describe how their screening and induction compliance is managed.
How often should an NDIS HR policy be reviewed?
The NDIS Practice Standards require policies to be current and fit for purpose. Most providers review their HR policy annually at minimum, and also following significant regulatory changes, audit findings, or critical incidents. The strengthened 2026 framework is a clear trigger for an immediate review if your policy predates it.
What happens if an auditor finds our HR policy is non-conformant?
A non-conformance against the Practice Standards can result in a corrective action requirement, a condition on your registration, or in serious cases a referral to the NDIS Commission for compliance action. Minor non-conformances typically require a corrective action plan with a defined timeframe for resolution.
Do we need to keep training records as separate documents from the HR policy?
Yes. The HR policy describes the training framework; the training records prove it is being implemented. Auditors will request both. Individual training logs, induction checklists, and competency sign-off forms must be retained and retrievable per worker.
Is there a specific format the NDIS Commission requires for HR policies?
No prescribed format exists, but the policy must demonstrably address the workforce-related requirements in the NDIS Practice Standards and reference the Code of Conduct. Policies should include version control, an approval date, a review schedule, and a clearly defined scope.
What is a 'risk-assessed role' for NDIS Worker Screening purposes?
A risk-assessed role is one in which a worker is likely to have more than incidental contact with NDIS participants. This includes direct support workers, supervisors of direct support workers, and others whose work brings them into regular contact with participants. The NDIS Commission's worker screening guidance describes this in detail.
Keep reading
Free: the SIL Readiness Pack
A checklist and a sample policy page, sent as a download. No sequence.