Back to Articles
AI Automation

NDIS Record Keeping Requirements for Australian Providers

NDIS Record Keeping Requirements for Australian Providers

CareVisor

Editorial

14-09-2026
Published 14-09-2026

NDIS record keeping requirements oblige registered providers to keep accurate, complete, and secure records that demonstrate they deliver supports safely and to the NDIS Practice Standards. This includes participant files, service agreements, progress notes, incident and complaints records, worker screening, and financial records. Most records must be kept for at least seven years, stored securely under the Australian Privacy Principles, and be retrievable on request.

Record-keeping is the least glamorous part of running an NDIS business and the fastest way to fail an audit. Not because providers deliver poor care, but because they can't produce the evidence that proves good care happened.

An auditor doesn't take your word for it. They ask to see the record. This guide covers exactly what records NDIS providers must keep, how long to keep them, how they must be stored, and what auditors check, so your record-keeping proves your compliance instead of exposing gaps.

What are NDIS record keeping requirements?

NDIS record keeping requirements are the obligations, set under the NDIS Practice Standards and the NDIS rules, for providers to create and keep records that show they meet their responsibilities.

NDIS record keeping requirements mean providers must keep accurate, complete, secure, and retrievable records that demonstrate compliance with the NDIS Practice Standards, covering participants, staff, incidents, finances, and service delivery.

The purpose is accountability. Records prove that supports were delivered as agreed, incidents were handled correctly, staff were screened and qualified, and money was claimed properly. No record means no proof, and at audit, no proof means a finding.

What records must NDIS providers keep?

Here's the full picture. A compliant provider keeps records across six areas.

Record category

What it includes

Participant records

Service agreements, consents, plans, goals, reviews

Service delivery

Progress notes, shift records, support delivered

Incidents and complaints

Incident register, SIRS notifications, complaints handling

Staff records

Worker screening, qualifications, training, inductions

Financial records

Claims, invoices, payroll, SCHADS calculations

Governance

Policies, procedures, continuous improvement log

Each category links to a deeper guide: service agreements, progress notes, incident reporting and SIRS compliance, worker screening and staff credential tracking, and SCHADS payroll. The participant file checklist covers the participant side in full.

Six categories of NDIS records providers must keep, from participant files to financial records.

How long must NDIS records be kept?

This is the question providers search most, and the answer is mostly consistent.

Short answer: NDIS providers must keep most records for at least seven years from the date the record was made. Records involving a participant who was under 18 at the time may need to be kept longer, and some records have specific retention rules.

The seven-year benchmark covers most records, but note:

  • Incident records: at least seven years from the date of the incident.

  • Records involving children: may need to be retained until the person reaches a certain age, often longer than seven years.

  • Financial and employment records: governed by their own laws (Fair Work, ATO) as well as NDIS rules, so keep them for the longest applicable period.

Key point: When retention periods differ across regimes, keep the record for the longest one. It's never a compliance problem to keep a record too long; it's a serious one to destroy it too early.

A quick clarification, because searches mix these up: the NDIS seven-year rule is separate from the ATO's record-keeping rules for tax. Both may apply to a provider, but they're different obligations. Don't assume meeting one covers the other.

How must NDIS records be stored?

Keeping records isn't enough; they must be stored properly. The requirements:

  • Secure. Protected against unauthorised access, under the Australian Privacy Principles.

  • Confidential. Participant information handled per privacy law.

  • Backed up. Protected against loss, damage, or corruption.

  • Retrievable. Able to be produced for the NDIS Commission on request, within a reasonable time.

  • Tamper-evident. Ideally with an audit trail showing who changed what and when.

Short answer: NDIS records must be stored securely and confidentially under the Australian Privacy Principles, backed up against loss, and retrievable on request. Records that can be edited without a trace are a compliance weakness.

That last point matters more than providers realise. A record an auditor can't trust, because it could have been altered, is barely a record. This is exactly where paper files and editable spreadsheets fall short, and where a system with a time-stamped audit trail proves its worth.

What happens if you don't keep proper NDIS records?

The consequences are real and escalate.

  1. Audit findings. Missing or incomplete records are among the most common non-conformities.

  2. Corrective actions. You'll be required to fix the gaps and prove it, adding cost and time.

  3. Claiming problems. Unable to evidence delivered supports, you may face payment issues or repayment demands.

  4. Registration risk. Systemic record-keeping failures can lead to conditions on your registration.

  5. Participant safety risk. Poor records mean poor continuity of care, which is the real harm behind the paperwork.

Key point: Most record-keeping failures aren't about missing dramatic documents. They're about gaps, incident records without investigations, participant files without current agreements, shifts without progress notes, that accumulate quietly until an auditor finds them.

Key takeaways

  • NDIS providers must keep accurate, complete, secure, retrievable records across participants, staff, incidents, finances, and governance.

  • Most records must be kept at least seven years; records involving children may need longer.

  • Records must be stored securely under the Australian Privacy Principles, backed up, and retrievable on request.

  • When retention periods differ across regimes, keep records for the longest applicable period.

  • Poor record keeping is a leading cause of audit findings and a genuine participant safety risk.

How to keep NDIS records audit-ready at scale

One participant, one folder, is manageable. Fifty participants, a team of staff, daily shifts, and incidents across a year is where record keeping breaks down, and where it's usually done in a mix of spreadsheets, shared drives, and inboxes.

That fragmentation is the problem. When records live in four places, no one can produce a complete, current, tamper-evident set on demand, which is exactly what an audit requires.

A workable record-keeping system needs:

  1. One source of truth. Every record type in one place, linked to the participant, staff member, or incident it belongs to.

  2. Retention tracking. So records are kept the full required period and not destroyed early.

  3. Secure, privacy-compliant storage. Meeting the Australian Privacy Principles by default.

  4. A time-stamped audit trail. Proving records weren't altered.

  5. Instant retrieval. Any record produced in seconds when the Commission asks.

This is the principle behind an operating system rather than a filing cabinet. CareVisor keeps participant records, progress notes, incidents, worker screening, service agreements, and financial records in one platform, each time-stamped, retention-tracked, and retrievable in seconds. When an auditor asks for any record, it's one search away, complete and dated. See how it connects on our NDIS service provider platform page, or the wider best NDIS compliance software guide. For how records get sampled, our what NDIS auditors check and how to prepare for an NDIS audit guides apply directly.

Frequently asked questions

What are the record keeping requirements for NDIS providers?
NDIS providers must keep accurate, complete, secure, and retrievable records demonstrating compliance with the NDIS Practice Standards. This covers participant files, service agreements, progress notes, incident and complaints records, worker screening, staff credentials, and financial records.

How long must NDIS records be kept?
Most NDIS records must be kept for at least seven years from the date the record was made. Records involving a participant who was under 18 may need to be kept longer, and financial or employment records may have their own longer retention periods.

How must NDIS records be stored?
NDIS records must be stored securely and confidentially under the Australian Privacy Principles, backed up against loss, and retrievable for the NDIS Commission on request. Ideally, they have a time-stamped audit trail showing who changed what and when.

What records must NDIS providers keep for seven years?
Participant records, service agreements, progress notes, incident records, complaints, worker screening, staff credentials, and financial records should generally be kept for at least seven years, longer where children are involved or other laws require it.

What happens if an NDIS provider doesn't keep proper records?
Poor record-keeping leads to audit findings, corrective actions, potential claiming and repayment problems, and in serious or systemic cases, conditions on registration. It's also a participant safety risk through poor continuity of care.

Is NDIS record keeping the same as ATO record keeping?
No. The NDIS record-keeping rules under the Practice Standards are separate from the ATO's tax record-keeping rules. Both may apply to a provider, so keep records for the longest applicable period across all regimes.

NDIS record-keeping requirements come down to one test: when an auditor asks for any record, can you produce it, complete, current, and provably unaltered, in seconds? The providers who pass audits comfortably aren't keeping more records. They're keeping them in one place, securely, with a trail, so nothing has to be reconstructed.

Get record-keeping right, and it stops being your biggest audit risk and becomes your strongest evidence.

See record keeping done right. Start a free CareVisor trial and see how providers keep every record type in one secure, retention-tracked, instantly retrievable place, so your next audit is a confirmation, not a document hunt.

Start your free 7-day trial →

About CareVisor

CareVisor is the audit-ready operating system for Australian NDIS providers, built in Sydney by NDIS operators who have prepared for and passed Quality and Safeguards Commission audits firsthand. Participant records, progress notes, incident reporting, service agreements, worker screening, claiming, and SCHADS payroll live in one platform, mapped to the NDIS Practice Standards, with secure storage and a time-stamped audit trail captured by default. Learn more about us or start your free trial at carevisor.com.au.

TAGS

NDIS record keeping requirementsNDIS documentation requirementsNDIS records retention periodNDIS provider complianceNDIS Practice StandardsNDIS participant recordsNDIS audit evidenceAustralian Privacy Principles NDISNDIS document storageNDIS provider record checklist