How to Prepare Your Participant Files for an NDIS Audit
- Participant files are one of the most important sources of evidence during an NDIS audit.
- Auditors use participant records to assess whether supports are delivered in line with the NDIS Practice Standards and Quality Indicators.
- Strong participant files demonstrate support delivery, participant choice and control, consent, risk management, and ongoing review.
- The NDIS requires providers to maintain complete and accurate records of supports delivered to participants.
- Reviewing participant files before an audit helps identify missing documents, outdated information, and compliance gaps before the auditor does.
What evidence do auditors expect to see in participant files?
Auditors expect participant files to tell a complete story about the participant's experience with your organisation. The file should demonstrate that supports are planned, delivered, reviewed, and documented appropriately.
Under the current NDIS Practice Standards and Quality Indicators, providers are expected to maintain records that support participant outcomes, risk management, governance, and quality service delivery.
A strong participant file typically contains evidence that:
- The participant's needs, goals, and preferences are understood.
- Supports align with agreed arrangements.
- Participant decisions are documented.
- Risks have been identified and managed.
- Reviews occur when circumstances change.
- Information is kept current and confidential.
- Staff record support delivery consistently.
Participant files should contain enough evidence that an auditor can understand what supports are being delivered, why they are being delivered, and how participant outcomes are being monitored.
How do participant files help demonstrate compliance with the NDIS Practice Standards?
Participant files are one of the primary sources of evidence used to demonstrate compliance with the NDIS Practice Standards. During an audit, auditors review participant records to assess whether the provider is meeting the relevant outcomes and quality indicators for their registration groups.
The NDIS Practice Standards set the quality and safety outcomes that registered providers are expected to achieve. Participant files often contain evidence that supports multiple Practice Standards at the same time.

The NDIS Commission assesses evidence against relevant quality indicators, making participant files one of the most important sources of audit evidence. A well-maintained file helps demonstrate not only that supports were delivered, but that participant rights, outcomes, and safety requirements are being met.
What makes a participant file audit-ready?
An audit-ready participant file is complete, current, organised, and easy to follow.
The NDIS Practice Standards require participant information to be accurately recorded, current, and managed through an effective information management system. A file that contains documents but lacks consistency or clear evidence may still create audit concerns.
An audit-ready file should:
- Tell a clear story about the participant's support journey.
- Include current versions of all key documents.
- Show evidence of participant involvement and decision-making.
- Demonstrate how risks are managed.
- Contain complete support records.
- Show reviews and updates when circumstances change.
- Include current consent records.
- Be easy to navigate and review.
A useful test is whether someone unfamiliar with the participant could understand the supports being delivered simply by reviewing the file.
What documents should be included in an NDIS participant file?
An NDIS participant file should contain enough information to demonstrate how supports are planned, delivered, monitored, and reviewed.

The NDIS record-keeping requirements identify service agreements, support logs, case notes, rosters, and invoices as examples of records providers must maintain.
What information must every participant record include?
The NDIS requires providers to maintain complete and accurate records of supports delivered.
According to NDIS record-keeping requirements, records should include:
- Participant name
- Participant NDIS number
- Date support was delivered
- Support type
- Amount, quantity, or hours of support delivered
Providers should also ensure records clearly identify:
- The support worker or practitioner involved
- The support delivered
- Relevant participant outcomes
- Any follow-up actions required
Consistent record keeping helps demonstrate that supports have been delivered appropriately and supports any claims made against NDIS funding.
How do participant consent records affect an NDIS audit?
Participant consent records demonstrate that your organisation respects participant choice, control, privacy, and information rights.
According to NDIS guidance, consent should be:
- Informed
- Voluntary
- Current
- Specific
- Understood and communicated
This means the participant understands what they are agreeing to, chooses to provide consent freely, and understands how their information may be used or shared.
Participants can change or withdraw consent at any time.
Participant files should show:
- When consent was obtained
- What the participant agreed to
- Why information is being collected or shared
- Who information may be shared with
- How consent can be changed or withdrawn
- When consent was reviewed or updated
Under the Information Management quality indicators, providers should obtain participant consent to collect, use, retain, and disclose participant information where appropriate. Consent records within participant files help demonstrate compliance with these requirements and show that participants understand how their information is managed.
Strong consent documentation helps demonstrate participant choice and control while also supporting privacy and information management obligations.
How can participants provide consent?
The NDIS explains that consent can be provided in different ways depending on the participant's preferences and circumstances.
Consent may be:
- Verbal
- Written
- Provided through a consent form
- Communicated through another agreed method
Participant files should clearly document:
- The type of consent provided
- The date consent was obtained
- Any restrictions placed on the consent
- Whether the consent remains current
- Any changes made to the consent
The participant should understand what they are consenting to and how their information may be used. Where consent relates to information sharing, records should clearly identify the parties involved.
How can providers demonstrate participant choice and control?
Participant files should contain evidence that participants are actively involved in decisions about their supports.
According to the NDIS Practice Standards, providers should support participant choice and control throughout service delivery.
Evidence may include:
- Signed service agreements
- Consent records
- Goal-setting discussions
- Support reviews
- Meeting notes
- Feedback records
- Requests for changes to supports
- Participant preferences
- Records of participant decisions
Participant files should show that participants have opportunities to make informed decisions and that those decisions influence the supports they receive.
Auditors often review participant files for evidence that participant preferences have been identified, documented, and respected.
How should providers manage participant information?
Participant information must be accurate, current, confidential, and accessible to appropriate people.
The Information Management Practice Standard requires providers to ensure participant information is identifiable, accurately recorded, current, confidential, and accessible where appropriate. Participant files should demonstrate that these requirements are consistently applied across the organisation.
Participants should understand:
- Why information is collected
- How information is used
- How information is stored
- Who information may be shared with
- How they can access their information
- How they can correct inaccurate information
The quality indicators published by the NDIS Commission also require providers to maintain an information management system that records participant information accurately and in a timely manner.
Providers should maintain systems that ensure:
- Information is updated promptly
- Records remain accurate
- Documents are stored securely
- Access is restricted appropriately
- Information can be retrieved when required
- Privacy obligations are met
Strong information management practices support compliance across multiple NDIS Practice Standards and help reduce audit risk.
How should participant files be organised?
Participant files should be organised so information can be located quickly during an audit.
A well-structured file demonstrates effective information management and makes it easier for auditors to review evidence.
A common file structure includes the following sections.
Participant Information
- Participant profile
- Contact details
- Emergency contacts
- Communication preferences
- Relevant medical or support information
Agreements and Consents
- Service agreements
- Consent forms
- Privacy acknowledgements
- Information-sharing permissions
Planning Documents
- Support plans
- Goal plans
- Risk assessments
- Risk management plans
Service Delivery Records
- Support logs
- Progress notes
- Case notes
- Rosters where applicable
Monitoring and Review
- Support reviews
- Goal reviews
- Incident records
- Complaints
- Feedback records
Organised files help providers prepare for audits more efficiently and demonstrate good governance practices.
How should providers prepare participant files before an NDIS audit?
Providers should review participant files before an audit to ensure records are complete, current, and consistent.
A structured review process helps identify gaps before the auditor does.
1. Check participant information is current
Review:
- Personal details
- Support arrangements
- Goals and preferences
- Communication requirements
- Risk information
- Emergency contacts
Outdated information may indicate that participant needs are not being monitored effectively.
2. Review support delivery records
Support records should clearly show what support was delivered and how it relates to participant needs and goals.
Review:
- Support logs
- Progress notes
- Case notes
- Rosters where applicable
Ensure records are complete, accurate, and consistent across the file.
3. Review service agreements and consent records
Check that:
- Service agreements reflect current supports
- Participant agreements remain relevant
- Consent records are current
- Information-sharing arrangements are documented
- Participant decisions are recorded
The NDIA strongly recommends service agreements between providers and participants. Written service agreements are required for Specialist Disability Accommodation (SDA).
4. Review risk management documentation
Review:
- Risk assessments
- Risk management plans
- Incident records
- Escalation procedures
- Follow-up actions
Risk management documentation helps demonstrate compliance with the NDIS Practice Standards and shows how participant safety is managed.
5. Review review and communication records
Review:
- Support reviews
- Goal reviews
- Participant feedback
- Complaints
- Important communications
These records help demonstrate continuous monitoring, participant involvement, and service improvement.
6. Check for consistency across documents
One of the most common audit issues is inconsistent information across participant files.
Review whether:
- Goals align with support plans
- Progress notes align with supports delivered
- Risk information is consistent across documents
- Participant details are current throughout the file
- Consent arrangements match current practices
Consistency helps demonstrate that records are actively maintained and accurately reflect service delivery.
What should good progress notes include?
Progress notes are often one of the most important pieces of audit evidence because they demonstrate how supports are delivered on a day-to-day basis.
According to NDIS record-keeping guidance, case notes should describe activities completed and explain how those activities relate to participant goals and funded supports.
Good progress notes generally include:
- Date and time of support
- Name of the worker providing support
- Support delivered
- Activities completed
- Participant response
- Progress towards goals
- Risks or concerns identified
- Follow-up actions required
Progress notes also help demonstrate compliance with the Provision of Supports and Individual Outcomes requirements within the NDIS Practice Standards. Strong records show how supports were delivered, how participant goals are being progressed, and whether support strategies remain effective.
Avoid:
- One-line entries
- Generic statements
- Personal opinions
- Copy-and-paste notes
- Missing dates or participant details
- Records that do not explain what support was delivered
Progress notes should provide a clear and accurate record of the support delivered and any outcomes achieved.
What participant file issues commonly cause audit findings?
Participant file issues often arise when records are incomplete, inconsistent, or outdated.
Common issues include:
- Missing service agreements
- Missing consent records
- Progress notes that do not link to participant goals
- Incomplete support logs
- Outdated participant information
- Missing risk assessments
- Missing review records
- Inconsistent information across documents
- Missing evidence of support delivery
- Incomplete incident documentation
- Poorly organised files
The NDIS requires providers to maintain complete and accurate records. Missing or inconsistent documentation can make it difficult to demonstrate compliance during an audit.
Many audit findings relate not to the absence of policies, but to the absence of evidence showing those policies are being followed.
What questions should you ask during an internal participant file audit?
Before an external audit, providers should conduct their own file review.
Review each participant file and ask:
- Is the participant information current?
- Is there a current service agreement?
- Are consent records complete?
- Are support notes up to date?
- Do case notes link to participant goals?
- Are risks documented and reviewed?
- Are incidents recorded appropriately?
- Have support reviews been completed?
- Is there evidence of participant involvement?
- Are participant preferences documented?
- Are files organised and easy to navigate?
- Could an auditor easily follow the participant's support journey?
If the answer to any of these questions is no, further review may be required.
What should providers do if participant files are missing documents?
Providers should identify and address missing documents before the audit where possible.
A practical approach is to:
- Identify the missing document.
- Determine why it is missing.
- Obtain updated information where appropriate.
- Record corrective actions taken.
- Review other participant files for similar issues.
- Update internal systems to prevent the issue recurring.
Do not create records retrospectively that inaccurately represent past events.
Instead, document the issue, record the corrective action taken, and ensure future records meet the required standard.
For more on what happens when gaps like these turn into audit findings, see our guide: What Happens If You “Fail” an NDIS Audit? (Non-Conformities Explained).
What is an NDIS participant file audit checklist?
Use this checklist before your audit.
Participant Information
☐ Participant details are current
☐ Participant goals are documented
☐ Communication needs are recorded
☐ Emergency information is available
☐ Important support needs are documented
Supports evidence for: Information Management, Individual Outcomes
Agreements and Consent
☐ Service agreement is current
☐ Consent records are complete
☐ Information-sharing permissions are documented
☐ Participant decisions are recorded
☐ Consent reviews are documented where applicable
Supports evidence for: Rights and Responsibilities, Information Management
Support Delivery Evidence
☐ Support logs are complete
☐ Progress notes are current
☐ Case notes link to participant goals
☐ Records match supports delivered
☐ Reviews are documented
☐ Participant outcomes are recorded where applicable
Supports evidence for: Provision of Supports, Individual Outcomes
Risk and Safety
☐ Risk assessments are current
☐ Risk management plans are documented
☐ Incident records are complete
☐ Follow-up actions are recorded
☐ Risk reviews are documented
Supports evidence for: Risk Management
Information Management
☐ Information is stored securely
☐ Access is restricted appropriately
☐ Records are accurate and current
☐ Participants can access or correct information if required
☐ Privacy obligations are being met
Supports evidence for: Information Management, Governance and Operational Management
Keeping every participant file this organised, across every client and every Practice Standard area, is a lot to manage manually. Our PQM Pro tool, built by our team of former NDIS auditors, helps you keep participant records complete and current so nothing gets missed between reviews.
How often should NDIS providers review participant files?
Participant files should be reviewed regularly rather than only when an audit is scheduled.
Regular reviews help identify:
- Missing documentation
- Outdated information
- Incomplete support records
- Consent issues
- Risk management gaps
- Information management issues
The Practice Standards framework emphasises maintaining accurate and current information as part of ongoing quality and compliance processes.
Regular file reviews can also help providers identify trends, improve record-keeping practices, and reduce audit preparation workloads.
Conclusion
Participant files are one of the most important sources of evidence during an NDIS audit. They help demonstrate how supports are delivered, how participant rights are protected, how risks are managed, and how providers meet the NDIS Practice Standards.
Well-maintained participant files do more than support audit outcomes. They help providers deliver consistent, person-centred supports, maintain accurate records, and continuously improve service quality.
By reviewing participant files regularly and ensuring records are complete, current, and organised, providers can approach audits with greater confidence and reduce the risk of avoidable findings.
If you need help, our NDIS consultants have supported providers through thousands of audits since 2018. In a free consultation, our team can explain the process, ask you about your situation and guide you on the next best step forward. Book a call today.
Need help with the NDIS?
Fill in the form below to get started.
FAQs
The NDIS requires providers to maintain complete and accurate records of supports delivered. Depending on the support type, this may include service agreements, support logs, case notes, invoices, rosters, consent records, risk documentation, and review records.
Yes. Progress notes and case notes are commonly used as evidence that supports were delivered and that activities align with participant goals and funded supports.
The NDIA strongly recommends service agreements between providers and participants. Written service agreements are required for Specialist Disability Accommodation (SDA).
Consent records demonstrate that participants understand and agree to how their information is collected, used, stored, and shared. They also help demonstrate compliance with Information Management requirements under the NDIS Practice Standards.
Missing records can create gaps in audit evidence and make it harder to demonstrate compliance. Providers should review files before an audit to identify and address missing documentation.
Yes. Electronic records can be used provided they are accurate, secure, accessible, and maintained through appropriate information management processes.
The most important requirement is maintaining complete, accurate, and current records that demonstrate supports delivered, participant outcomes, participant choice and control, and compliance with the NDIS Practice Standards.







Understand exactly why registration takes 6–12+ months



.webp)