The NDIS Practice Standards: What you will be assessed against

Last updated: June 2026  ·  Reading time: 5 minutes

Summary

  • The NDIS Practice Standards are the legally mandated quality and safety framework that every registered NDIS provider must meet. They are established under the National Disability Insurance Scheme (Provider Registration and Practice Standards) Rules 2018 and define exactly what your organisation is assessed against at every audit: initial certification, mid-term surveillance, and renewal.
  • Understanding the Practice Standards before you begin building your compliance system is one of the highest-value investments you can make in the registration process.
  • This article explains the full structure of the Practice Standards framework: the Core Module that applies to every certified provider, the Verification Module for lower-risk providers, the supplementary modules for higher-risk and specialist services, and how Quality Indicators translate each standard into concrete evidence requirements.

What are the Practice Standards?

The NDIS Practice Standards are the minimum quality and safety requirements that every registered NDIS provider must meet. They sit alongside the NDIS Code of Conduct as the two primary regulatory instruments governing the behaviour and operations of registered providers.

The standards are established under the National Disability Insurance Scheme (Provider Registration and Practice Standards) Rules 2018, made under the National Disability Insurance Scheme Act 2013. The accompanying National Disability Insurance Scheme (Quality Indicators) Guidelines 2018 specify the quality indicators: the detailed, measurable evidence points auditors use to assess whether each standard is being met. Together, these two instruments define the full assessment framework.

The Practice Standards exist for a specific reason: to ensure that every NDIS participant receives safe, quality supports from a provider with the governance systems, workforce practices, and operational discipline to deliver them consistently. They describe what a well-run registered provider looks like in operational terms.

There are currently 22 standards in the Core Module, organised into four divisions, with further standards in the supplementary modules. Each standard has multiple quality indicators: specific statements of what ‘good’ looks like in operational terms. When an auditor assesses your organisation, they are working through those indicators and asking: is there evidence that this is genuinely happening?

The Module Structure

The Practice Standards are organised into modules. Which modules apply to your organisation depends on your registration pathway and the supports you deliver.

Core module

All providers going through the certification pathway

Full two-stage audit: Stage 1 desktop document review, Stage 2 on-site assessment with staff interviews and participant file review

Verification module

All providers going through the verification pathway (lower-risk supports)

Desktop document review only, no on-site visit

Supplementary modules

Certification providers delivering specific higher-risk or specialist supports (applied in addition to the Core Module)

Assessed as part of the full certification audit; scope depends on which modules apply to your registration groups

SIL Practice Standards

Providers delivering Supported Independent Living (from 1 July 2026)

Assessed in addition to the Core Module for SIL providers; new dedicated standards commenced 1 July 2026

The Core Module is the universal baseline. If you are going through certification, you must meet it regardless of which registration groups you hold or what services you deliver. It is the non-negotiable foundation of registered provider status.

Supplementary modules layer additional requirements on top of the Core Module for providers delivering higher-complexity supports. If your registration groups include High Intensity Daily Personal Activities, Specialist Behaviour Support, Early Childhood Supports, Specialist Disability Accommodation, or Specialist Support Coordination, the relevant supplementary module applies.

The Core Module

The Core Module is organised into four divisions. Divisions 1 and 2 apply to every certification provider. Divisions 3 and 4 apply to providers delivering ongoing direct supports, which includes the majority of community support, SIL, and personal care providers.

Division 1: Rights and Responsibility (Outcomes 1.1-1.5)

Division 1 is the most human-centred of the four divisions. It requires providers to demonstrate that participants are treated as rights-bearing individuals, that their choices and values are actively respected, and that comprehensive safeguards exist to protect them from harm. Every outcome in Division 1 should be visible in your direct service delivery records, not just in your policy documents.

1.1 Person-Centred Supports

Participants receive supports tailored to their individual needs, goals, and circumstances, with active involvement in planning and review. Evidence: Current, co-designed support plans for every participant. Documented participant involvement in plan reviews. Goal review records showing progress tracking. Staff who can describe individual participant needs in interview.

1.2 Individual Values and Beliefs

Providers actively respect and uphold each participant’s cultural identity, language needs, spiritual beliefs, and personal values in day-to-day service delivery. Evidence: Support plans recording cultural and religious preferences. Cultural safety staff training records. Evidence of interpreter or bilingual communication supports where relevant.

1.3 Privacy and Dignity

Participants’ personal information is handled lawfully and with respect. Privacy is upheld in how personal care is delivered, how information is stored, and how participants are discussed within the organisation. Evidence: Signed privacy consent forms for every participant. Privacy policy (current, reviewed). Secure information storage with appropriate access controls. Privacy training records for all staff.

1.4 Independence and Informed Choice

Each participant is supported to make their own decisions, exercise choice and control, and take positive risks. The provider supports informed decision-making and the dignity of risk rather than defaulting to restriction. Evidence: Support plans with decision-making and risk sections co-developed with participants. Signed informed consent records for positive risk-taking. Evidence that participants are supported to access an advocate where they choose. Staff who can articulate the difference between safeguarding and over-restriction.

1.5 Violence, Abuse, Neglect, Exploitation and Discrimination

Comprehensive safeguarding systems prevent, detect, and respond to abuse, neglect, exploitation, and discrimination. Mandatory reporting to the Commission is met within required timeframes. Evidence: Populated incident register (not empty). NDIS Commission reportable incident submission records. Complaints register with evidence of active use. NDIS Worker Screening Checks for all applicable workers, and training records for all staff.

Division 2: Governance and Operational Management (Outcomes 2.1-2.8)

Division 2 shifts from participant-facing practice to organisational systems. These outcomes assess whether your provider has the governance structures, management systems, and operational discipline to sustainably deliver safe and quality supports. New providers frequently underestimate the rigour required here. The NDIS Commission expects a functioning quality management system, not just a folder of policies.

2.1 Governance and Operational Management

The provider has clear, documented governance structures and operational management systems. Leadership demonstrates active oversight of compliance, financial, and regulatory obligations. Evidence: Governance framework or organisational chart with clear accountability lines. Policy register showing all policies with version numbers, approval dates, and review dates. Board or management meeting minutes showing oversight of compliance. Conflicts of interest register. Financial delegations register and evidence of financial review and sustainability.

2.2 Risk Management

The provider identifies, assesses, and manages risks at both strategic and operational level. A functioning risk register is actively maintained and used to inform management decisions. Evidence: Risk management policy (current, approved). Risk register with risks rated by likelihood and consequence, mitigations assigned to responsible persons with due dates, and review history. Meeting minutes showing risk register review as a standing agenda item. Business continuity and emergency management plans.

2.3 Quality Management

The provider has a systematic approach to monitoring and continuously improving the quality of supports. An improvement register captures issues from multiple sources and tracks them to resolution. Evidence: Continuous improvement register showing items, actions, responsible persons, and outcomes. Participant and staff feedback records. Evidence that improvements have been implemented and evaluated. Internal audit or self-assessment records.

2.4 Information Management

The provider manages information accurately, securely, and in compliance with relevant legislation. Documents are version-controlled, records are retained appropriately, and access is controlled. Evidence: Information management policy covering the full information lifecycle. Document control procedure with version control and archival processes. Evidence of secure storage with appropriate access controls. Records retention schedule. Staff training records on information handling.

2.5 Feedback and Complaints Management

Each participant knows how to give feedback or make a complaint and is confident it will be handled fairly and without reprisal. Complaints are recorded, acknowledged, resolved, and used to improve supports. Evidence: Accessible complaints and feedback policy and procedure. A complaints register showing items, actions, responsible persons, outcomes, and timeframes. Evidence that complaints inform continuous improvement. Information for participants on how to complain to the provider and to the NDIS Commission.

2.6 Incident Management

The provider identifies, manages, and learns from incidents, and reports reportable incidents to the NDIS Commission within required timeframes. Evidence: Incident management policy aligned to the NDIS (Incident Management and Reportable Incidents) Rules 2018. A populated incident register (not empty), with investigation, response, and review records. NDIS Commission reportable incident submission records. Evidence that incident trends inform improvement.

2.7 Human Resource Management

The provider manages the full workforce lifecycle: recruitment, induction, supervision, training, performance, and separation. All workers in risk-assessed roles hold current NDIS Worker Screening Checks. Evidence: NDIS Worker Screening Check records for every applicable worker. Recruitment and selection documentation. Structured induction records covering the NDIS Code of Conduct, Practice Standards, and key policies. Regular supervision records. Staff training register and professional development records.

2.8 Continuity of Supports

Each participant has access to timely and appropriate supports without unplanned interruption. The provider plans for continuity, including during emergencies, disasters, and workforce shortages. Evidence: Business continuity and emergency or disaster management plans. Backup and contingency arrangements for critical supports. Evidence that continuity plans are tested and reviewed. Records showing supports continued without unplanned gaps.

Division 3: Provision of Supports (Outcomes 3.1-3.5)

Division 3 applies to providers delivering ongoing or episodic direct supports to participants. It covers the full cycle of service delivery, from initial assessment and planning through to how supports are delivered and reviewed. This division is where the auditor most directly assesses whether your operational practice matches your documented systems.

3.1 Access to Supports

Each participant accesses the most appropriate supports that meet their needs, goals, and preferences, with entry criteria and any costs clearly defined and communicated. Evidence: Documented access and entry or exit criteria, information provided to participants in accessible formats, and records showing how participants are matched to appropriate supports.

3.2 Support Planning

Each participant is actively involved in developing a support plan that reflects their needs and goals, and the plan is reviewed regularly. Evidence: Current, co-designed support plans for every participant, records of participant involvement in planning and review, and plans linked to each participant’s NDIS plan goals.

3.3 Service Agreements with Participants

Each participant has a clear understanding of the supports they have chosen and how they will be provided, set out in a collaboratively developed service agreement. Evidence: Signed service agreements specifying supports, conditions, and costs, evidence the agreement was developed with the participant, and agreed arrangements for emergencies or disasters where relevant.

3.4 Responsive Support Provision

Each participant accesses responsive, timely, competent, and appropriate supports that meet their needs and goals. Evidence: Progress notes and service delivery records, records of participant involvement in selecting workers including preferred gender for personal care, and evidence that workers understand each participant’s needs and preferences.

3.5 Transitions to or From a Provider

Each participant experiences a planned and coordinated transition to or from the provider. Evidence: Transition plans developed with the participant, records of risks identified and managed during transition, and documented transition processes that are reviewed and communicated.

Division 4: Support Provision Environment (Outcomes 4.1-4.4)

Division 4 applies to providers delivering supports in a physical environment they control, such as supported independent living, residential, or centre-based settings. It assesses the safety and management of the environment in which supports are delivered. This division is assessed on-site during Stage 2 of the certification audit.

4.1 Safe Environment

Each participant accesses supports in a safe environment that is appropriate to their needs. Evidence: Current safety checks, maintenance records, and accessibility assessments, records showing workers are identifiable to participants, and evidence of work with participants and other providers to manage environmental risks.

4.2 Participant Money and Property

Each participant’s money and property are secure, and each participant is supported to make decisions about how their money and property are used. Evidence: Policy and procedures for handling participant money and property, records of participant consent and authorisation, reconciliation records, and safeguards against misuse.

4.3 Management of Medication

Each participant requiring medication is confident their provider administers, stores, and monitors medication safely and works to prevent errors. Evidence: Medication management policy, medication administration records (MARs), staff medication competency assessments, and secure, identifiable storage accessed only by trained workers.

4.4 Management of Waste

Each participant, worker, and other person in the support environment is protected from harm from exposure to waste or infectious or hazardous substances generated during support delivery. Evidence: Policies and procedures for safe storage, handling, and disposal of waste that comply with legislation and local health requirements, records of incidents involving hazardous substances, an emergency plan for such incidents, and worker training on safe handling and PPE.

From 1 July 2026, new dedicated SIL Practice Standards took effect, introducing additional obligations for SIL providers layered on top of the Core Module requirements. If you deliver SIL, review the current SIL Practice Standards published on the NDIS Commission’s website before building your documentation framework.

The Verification Module

Providers going through the verification pathway are assessed against the Verification Module, not the Core Module. The Verification Module covers four outcomes that mirror the Core Module’s themes but at a lighter level of evidence, reflecting the lower risk profile of the supports in the verification pathway.

Rights and Responsibilities

Participants receive safe, quality supports that uphold their rights. Evidence is primarily documentation-based: participant rights policy, privacy policy, consent processes.

Governance and Operational Management

The provider has appropriate governance structures, management systems, and operational processes. Evidence: Governance documentation, risk management policy, quality management framework.

Provision of Supports

Supports are delivered by appropriately qualified and screened workers. Evidence: Worker qualifications and screening records, service agreements, support plans where applicable.

Support Provision Environment

The environment in which supports are delivered is safe and appropriate. Evidence: Safety checks, equipment records, emergency procedures.

The verification audit is a desktop document review. There is no on-site visit, no staff interviews, and no participant file review. The AQA assesses your documentation package against the four Verification Module outcomes and returns findings. If your documentation is complete, accurate, and genuinely reflects how your organisation operates, verification should be a straightforward process.

One important note: the verification module does not assess fewer things because the standards are lower. It assesses fewer things because the supports are lower risk. For the outcomes it does cover, the expectation is the same: your systems must genuinely work, not just exist on paper.

Supplementary modules

If your registration groups include higher-complexity or specialist supports, one or more supplementary modules will apply in addition to the Core Module. Each supplementary module adds specific evidence requirements that reflect the additional risks and clinical or specialist demands of those support types.

High Intensity Daily Personal Activities (HIDPA)

Providers of Group 0104 (complex personal care including enteral feeding, tracheostomy management, subcutaneous injections, ventilator support)

Evidence of worker clinical competencies for each HIDPA category. Specific competency assessment and supervision records beyond standard workforce requirements.

Specialist Behaviour Support

Providers delivering Group 0110 (positive behaviour support), including providers implementing plans involving restrictive practices

Behaviour Support Plans for each participant. State/territory restrictive practice authorisation records. Monthly Commission reporting for providers implementing restrictive practices. PBS practitioner registration.

Early Childhood Supports

Providers of Group 0118 (early intervention supports for children under 9)

Evidence of multidisciplinary team practice. Child-safe environment standards. Family and carer involvement in planning. Transition planning to school-age supports.

Specialist Support Coordination

Providers of Group 0132 (specialised support coordination for complex or crisis situations)

Evidence of complex case management capabilities. Specialist qualifications of support coordinators. Crisis response planning and records.

Specialist Disability Accommodation (SDA)

Providers of Group 0131 (specialist housing for participants with extreme functional impairment)

SDA design category documentation. Tenancy agreements and participant rights documentation specific to SDA. Dwelling maintenance and safety records. SDA enrolment records.

Supported Independent Living (SIL): NEW from 1 July 2026

Providers of Group 0115 (residential support in shared or individual accommodation)

New SIL-specific standards covering participant wellbeing, household environment, and transitions. Review the Commission’s current SIL Practice Standards document for full requirements.

How Quality Indicators Work as Evidence Requirements

Every standard in the Practice Standards framework has associated Quality Indicators, set out in the National Disability Insurance Scheme (Quality Indicators) Guidelines 2018. Quality Indicators are the operational translation of each standard: they describe, in specific and measurable terms, what ‘meeting the standard’ actually looks like in practice.

Quality Indicators matter for one practical reason: they are what auditors work through. When an auditor assesses your organisation against Standard 2.7 (Human Resource Management), they are not just checking whether you have an HR policy. They are checking the Quality Indicators for that standard, which include (among others): whether all workers hold current NDIS Worker Screening Checks, whether induction records exist for every staff member, whether supervision is documented at a regular cadence, and whether training needs are identified and met.

The Quality Indicators Guidelines are a public document published by the NDIS Commission. Reading the indicators for the standards that apply to your organisation, before you write a single policy, is the most important compliance preparation step most providers skip. If you understand what the indicators require, you know exactly what your policies and systems need to produce as evidence.

The three-part evidence test

The three-part evidence test underpins how auditors assess every standard.

The Three Things Every Auditor Looks For: Policies, Records, Outcomes

Meeting a Practice Standard requires evidence of the following three things:

1. A documented system (policy or procedure) that describes how your organisation manages this area.
2. Evidence of implementation (registers, forms, records, meeting minutes) that shows the system is being used.
3. Demonstrated outcomes (participant files, interview responses, data, improvement records) that show the system is producing the right results.

Missing any one of the three creates a non-conformance finding. A perfect policy with no supporting records is a finding. A register with entries but no policy backing it is a finding. Records of activity that produced no discernible improvement is a finding.
An NDIS-compliant system is built on the operational systems you run, and the documentation is the evidence that those systems work.

The practical implication of the three-part test is that you need to approach each Practice Standard with three questions:

  • What documented system (policy or procedure) do I need to have in place?
  • What operational records will my system generate as evidence that it is working?
  • What outcomes will those records demonstrate to an auditor?

A policy that is well-written but never implemented will fail the second test. A register that is populated but whose entries are never reviewed, responded to, or used for improvement will fail the third. Providers who approach compliance from this three-part frame consistently produce audit-ready systems. Those who approach it as a documentation exercise consistently find themselves with non-conformances.

How the standards are changing

The NDIS Practice Standards are not static. The NDIS Commission is currently undertaking a comprehensive review of the Practice Standards framework, led by KPMG through a national consultation process. The review is examining whether the current structure adequately reflects participant-centred outcomes, whether the evidence requirements are appropriately calibrated, and whether the framework should be restructured around new domains.

The four proposed new Core Practice Domains under the review are: Individual Rights; Provider Leadership; Safe Support Practice; and Effective and Impactful Support. These are directional signals, not final decisions. The review is ongoing and final changes have not been confirmed at the time of writing.

What is already in force: new dedicated SIL Practice Standards took effect from 1 July 2026. If you deliver SIL, the Commission’s current SIL Practice Standards document is required reading before your next audit.

Your obligation as a registered provider is to maintain compliance with the current standards, not the standards that applied when you registered. When the Commission updates the standards, you must review your compliance system and update your documentation accordingly. Providers who build their compliance systems with this ongoing-update reality in mind will find the transition to new standards manageable. Providers who treat their documentation as set-and-forget will not.

For a full picture of the 2026 regulatory reform agenda and what is coming next, see Article 2.2: NDIS regulatory reform 2026, what every registered provider needs to know.

Using the standards as your compliance blueprint

The most efficient way to build your compliance system is to work directly from the Practice Standards and Quality Indicators, not from a generic policy template. Here is what that looks like in practice:

  • Start with the Quality Indicators for every standard that applies to your registration groups. Read them. Understand what each one requires as evidence.
  • For each indicator, identify whether you have an existing documented system that produces that evidence. If yes, review it for currency and completeness. If no, you need to build it.
  • Build your policies around the indicators, not the other way around. A policy written to satisfy a specific Quality Indicator will produce evidence that auditors are looking for. A generic policy downloaded from the internet may or may not.
  • Design your operational records (registers, forms, file structures) to capture the evidence the indicators require as a byproduct of doing your work, not as a separate compliance exercise.
  • Before your audit, conduct a self-assessment against the Quality Indicators. For each indicator, ask: do I have evidence that we do this? Not ‘do we have a policy that says we do this’, but ‘do I have records that show we do this?’

This approach takes more upfront thinking than purchasing a policy pack. It also produces a compliance system that works and that you understand. After more than 1,500 audits, the providers who are most audit-ready are almost always the ones who built their systems around the standards from the beginning, rather than the ones who purchased documentation and hoped it covered everything.

TrustBook maps your registration groups to their Practice Standard requirements automatically

For each standard that applies to your organisation, TrustBook shows you the Quality Indicators, the evidence required, and whether your current documentation covers them. It removes the guesswork from building a compliant system and tells you exactly where your gaps are before an auditor finds them.

Prefer expert guidance from a former NDIS auditor?

AuditHub’s advisors can review your registration group scope, identify the applicable standards, and help you build a documentation framework designed to pass, first time.