
NDIS audit compliance is a major part of running a safe and successful disability service in Australia. As a provider, you have a duty to make sure your staff are fit to work with vulnerable people. When an auditor visits your business, they will look closely at how you vet your team. They want to see proof that you follow the law and the NDIS Practice Standards.
Failing an audit can lead to serious problems for your business. It can result in fines or the loss of your registration. Most audit failures happen because of poor record-keeping rather than a lack of actual screening. This guide will help you understand how to organize your staff screening to meet all requirements. RefHub is here to support you in making your recruitment process as strong as possible.
Disability sector hiring involves more than just finding the right person for the job. You must also follow a strict legal framework. This framework protects participants from harm. Every person you hire must undergo a series of identity and safety checks before they start work.
In Australia, the NDIS Quality and Safeguards Commission sets these rules. You must have a written policy that explains how you screen new workers. This policy should cover:
By having clear rules, you show auditors that you take safety seriously. You can find more helpful information in our HR resources section to help you build these policies.
The most important part of screening is the background checks. You cannot rely on a resume alone. Auditors will check if you have the following documents for your staff:
Make sure you do not let a worker start their duties until these checks are finished. Auditors will look for any gaps between the start date and the date the check was approved.
An audit trail is a set of records that shows the history of an action. For staff screening, your audit trail must show every step you took from the moment you met a candidate. If a document exists but you cannot find it quickly, the auditor might mark it as a non-compliance.
To create a good audit trail, you should record:
Using a spreadsheet or a digital system can help you track these details. You should also keep notes of any conversations you had during reference checks. This shows the auditor that you did your due diligence.

One of the easiest ways to pass an NDIS audit is to have organized files. Each staff member should have a dedicated file. You can keep these as physical folders or digital files. A well-organized file should contain:
When an auditor asks to see a file, you should be able to produce it immediately. If your files are messy, the auditor may look deeper into other parts of your business. Keeping things tidy shows that you are a professional and compliant provider.
Not every role in your business needs the same level of screening. However, most roles in the disability sector are "risk-assessed." A risk-assessed role is one that involves:
You must keep a list of all risk-assessed roles in your company. For every person in these roles, a valid NDIS Worker Screening Check is mandatory. You must also link these workers to your organization in the NDIS Commission portal. If a worker leaves your company, you must unlink them. Auditors will check your portal list against your actual staff list to see if they match.
When you know an audit is coming, do not panic. Use the time to review your records. You should perform a "mock audit" on your own files. Pick five staff files at random and check if every required document is there.
Check for:
If you find a mistake, fix it before the auditor arrives. It is better to find the error yourself than to have the auditor find it. Be honest with the auditor if you are still waiting for a document. Showing that you have a system to track missing items is better than having no system at all.
Meeting NDIS audit compliance for staff screening is about being organized and proactive. By performing thorough background checks and keeping a detailed audit trail, you protect both your participants and your business. Remember that screening is not a one-time task. It is an ongoing process that requires constant attention.
RefHub is dedicated to helping Australian providers stay compliant. By following the steps in this guide, you can face your next audit with confidence. Clear records and a commitment to safety are the best tools you have to succeed in the disability sector.
The NDIS Worker Screening Database is a national tool. It allows providers to check the status of a worker’s screening. You must use this database to verify that your staff have a "clear" status before they work in risk-assessed roles. It also helps you link workers to your business so you get notified if their status changes.
The NDIS Worker Screening Check is usually valid for five years. However, other checks like police checks or Working with Children Checks may have different expiry dates depending on your state. You should check the expiry dates of all documents at least once every six months to stay compliant.
In some states, a worker might be able to start under supervision while their check is being processed. However, this is very risky. Most auditors prefer that workers do not start until they have a full clearance. You must check the specific rules for your state and the NDIS Commission guidelines before allowing a worker to start early.
If a record is missing, the auditor will likely give you a "non-conformity." You will then have a certain amount of time to find the record or fix the problem. If the issue is serious, like a worker having no screening at all, it could lead to a major non-conformity. This might require a follow-up audit or legal action from the NDIS Commission.