
NDIS Record Keeping Requirements: How Long Providers Must Keep Records (7-Year Rule)
Registered NDIS providers must now keep records for seven years. Destroying them is a criminal offence, and payments can be clawed back if you can’t produce one.
Guides, templates and real-world advice for NDIS providers, straight from our compliance team.
If your NDIS audit 2026 date is approaching, you are preparing under a different set of rules than last year. The Australian Government’s Securing the NDIS for Future Generations reforms landed in July 2026, and the compliance standards auditors expect have shifted significantly. New mandatory registration requirements, stricter documentation standards, and expanded audit obligations mean the bar is higher, and the NDIS Quality and Safeguards Commission knows it.
This is the complete NDIS audit 2026 checklist. Not a generic guide you could have found three years ago. The actual things auditors check, updated for where the scheme sits right now, with practical steps to make sure you are ready before the auditor walks in.
Start here at least eight weeks before your audit date.
The NDIS has been through significant reform before, but the 2026 changes are different in scale. Understanding what shifted helps you understand what auditors are now looking for.
From 1 July 2026, all providers delivering Supported Independent Living must be registered with the NDIS Quality and Safeguards Commission. Previously, registration was voluntary for most service types. That changed. If you deliver SIL supports without registration, you are not just at risk of a compliance issue, you risk losing your ability to operate altogether.
This matters for audits because new registrations trigger a Certification audit, not a lighter Verification audit. If you registered in 2026, expect scrutiny at the higher standard.
The 2026 reforms tightened documentation expectations across all registered providers. Auditors now expect traceable, timestamped records, not just policies that exist on paper, but evidence they have been read, signed off, and followed. A policy in a folder is not enough. You need to show it was implemented.
Some providers who previously faced Verification audits now face full Certification audits as registration categories are tightened. If you support participants in higher-risk categories, expect deeper scrutiny of your staff credentials, incident management, and governance records.
The providers who will struggle in NDIS audit 2026 preparations are the ones still managing compliance reactively, pulling everything together in the two weeks before the auditor arrives. That approach was already fragile before 2026. Now it is a liability.
Work through each area below. Give yourself time to identify gaps and fix them, not just locate them.
This is the first thing an auditor checks. Every time. Without exception.
The 2026 risk: auditors are now checking credential status at the time of service delivery, not just at onboarding. A credential that lapsed six months ago while a staff member was actively rostered is a finding — even if it has since been renewed. Document everything.
Incident management is one of the highest-scrutiny areas in any NDIS audit. The Commission cross-references incident data, so inconsistencies get noticed.
One thing auditors flag consistently: incident logs that look too clean. Zero incidents across a full year of service delivery with complex participants will prompt questions. Your records need to reflect reality.
Every active participant needs a complete, current file. Auditors will pull records, and gaps are findings.
Policies are not just documents — they are evidence of your governance. Auditors will check that they exist, that they are current, and that staff have actually read them.
A policy dated 2022 with no review record is a red flag. Under the 2026 documentation requirements, you need to show active governance — not just documentation that once existed.
Training records need to be traceable to the individual. A completion certificate saved in a general folder is not enough — it needs to be linked to the staff member and timestamped.
This area catches providers who deliver good care but run a loose organisation. Auditors look for evidence that leadership is actively managing compliance — not just reacting to it.
When the auditor arrives — or joins remotely — you need to produce everything above, organised by NDIS Practice Standard, with an index so they can find what they need without asking you.
For a remote audit, you will also need a secure way to share read-only access to documents. Emailing 47 files is not a system.
This is where most providers lose hours — or days — they do not have. The organisations that pass quickly are the ones where the evidence pack assembles itself, because compliance was being tracked every day, not just before the audit.
Most NDIS audit failures in 2026 will not be because providers are delivering bad care. They will fail because they cannot prove the care they deliver.
The evidence was not recorded at the time. Or it was recorded somewhere — a notebook, a shared drive, a WhatsApp group — and cannot be located or verified. Or a credential lapsed and nobody noticed until the auditor pointed it out.
The providers who pass first time, with zero findings, are the ones where compliance is not a project they do before an audit. It is how they operate. Credentials tracked automatically. Incidents logged the moment they happen on a phone. Policies read and signed off digitally with a timestamp. By audit day, there is nothing to scramble for — because it was all already done.
That is not an accident. It is a system.
Wholii is built specifically for registered NDIS providers. Every item on this checklist is either tracked in real time or automated inside the platform.
Wholii tracks every credential across your whole team and fires expiry alerts before anything lapses. Your entire team’s credential status is on one dashboard, updated in real time. You see gaps before they become findings.
Staff speak their incident report into their phone. Wholii transcribes it, timestamps it, structures it, and automatically identifies NDIS reportable incidents — complete with a 24-hour countdown timer to the reporting deadline. No one misses the window. Managers are notified immediately. The investigation tracker runs through to sign-off.
NDIS plans, service agreements, support notes, and consent documents are all stored in the participant’s profile — searchable, linked, and current. No digging through folders. No re-entering data.
Staff acknowledge policies digitally from any device. Every sign-off is timestamped and linked to the individual. Training records sit in the staff profile. When an auditor asks for evidence, it is there.
Every action in Wholii is logged automatically — who did what, when, on which participant or document. Your audit trail builds itself every day. When your NDIS audit 2026 date arrives, you are not assembling an evidence pack from scratch. You are exporting what already exists.
The providers who dread audit day are the ones managing all of this across spreadsheets and shared drives. With Wholii, you do not have to.
The best time to prepare for your NDIS audit 2026 is not two weeks before the auditor arrives. It is now, when you have time to find the gaps and fix them — not just find them.
Book a free Wholii demo and see what your compliance looks like when it runs in the background every day. Most providers are set up in under 30 minutes.

Registered NDIS providers must now keep records for seven years. Destroying them is a criminal offence, and payments can be clawed back if you can’t produce one.

From 1 December 2026, NDIS providers have just 90 days to submit a claim — here is what that means for your organisation and what you need to do before the deadline hits.

The NDIS just had its biggest shake-up since launch. Here’s what registered providers need to know, and why compliance matters more now than ever.
