
Why NDIS Self Assessments Fail at Stage One
This episode breaks down why NDIS self assessments fail when providers write to broad outcomes instead of evidence-based indicators. It also explains a practical three-part formula for answering portal questions with documented processes, operational records, and review evidence that can stand up to audit.
Chapter 1
The Indicator Trap: Why Writing to Outcomes Guarantees Audit Findings
Will, EnableUs Community
You know, when providers sit down to fill out their NDIS registration in the portal, they, they usually think the hard part is just getting the policies written. But then they hit the self assessment section, and, and that's where things can really go off the rails.
Winter, EnableUs Community
Oh, completely. Because people see a big header like Risk Management, and they write this lovely, polished paragraph about how much they care about risk. And then, boom, stage one audit comes around, and they get hit with a minor nonconformity finding right out of the gate.
Will, EnableUs Community
Right! Because according to Veyora's insights on NDIS self assessments, you can't just answer the high level outcome statement. If you look at section 12 of the Quality Indicators Guidelines for Risk Management, that single outcome is actually broken down into six distinct quality indicators. And those indicators cover eight mandatory operational domains.
Winter, EnableUs Community
Eight! Everything from WHS and human resources to financial management, incident management, and emergency and disaster planning. So if you write one general paragraph for the outcome, you've essentially left five or six specific indicators completely unaddressed. The auditor looks at that and sees huge holes in your Practice Standards coverage.
Will, EnableUs Community
Yeah, and it gets worse if you use future tense. I mean, I see this all the time when people panic in the portal. They write things like, uh, policy will be drafted, or internal audit is planned for next quarter. But under Annex B of the Approved Quality Auditors Scheme Guidelines, saying what you intend to do rather than proving what's already operating is a textbook trigger for a finding.
Winter, EnableUs Community
Wait, so even if you genuinely plan to do it next month, writing it in the future tense is logged as missing evidence?
Will, EnableUs Community
Exactly. Annex B explicitly sets out that a minor nonconformity is recorded when a documented process exists without supporting documentation of implementation, or where you can't show review and evaluation. Stage one is a desk review of actual evidence, not good intentions. Overclaiming or promising future work just tells the auditor you aren't ready for stage two, which can delay your whole audit or trigger an application refusal from the Commission.
Winter, EnableUs Community
And, and don't forget how scope selection plays into this! You tick one extra registration group in the portal thinking, oh, we might deliver high intensity supports or behaviour support down the track, and suddenly you've added an entire extra module of quality indicators. Like, if you select high intensity daily personal activities under Module 1, you now have Schedule 2 indicators to self assess against and prove.
Will, EnableUs Community
Uh, yeah! And all of this is happening while the portal clock is ticking down. The Commission deletes your application automatically if it isn't completed within 60 days of starting. That 60 day deadline causes absolute panic if you open the portal before your evidence is actually assembled.
Chapter 2
The Three-Part Formula: Turn Your Portal Application Into a Live Operational Register
Winter, EnableUs Community
So how do you actually write an answer that passes stage one without getting flagged? Is there a set way to structure each indicator response?
Will, EnableUs Community
There is, and it comes down to a strict three part formula for every single quality indicator. Every response needs to name three concrete things. First, the Documented Process, including the exact document ID, version number, and review date. Second, the Operational Record, which is the completed form or log that proves the process actually ran. And third, the Evaluation Review, which proves you actively monitor and evaluate the system.
Winter, EnableUs Community
Okay, let's make that real. What does a weak response look like compared to a strong one using that formula?
Will, EnableUs Community
Right, take Quality Management under section 13 sub two, which requires an internal audit program. A weak response says, quote, we conduct internal audits regularly, end quote. That fails all three parts. A strong response says, quote, Internal audit schedule IA 01 sets four audits per year against Core module divisions. The February 2026 audit report, findings log, and closed actions are attached, and the next scheduled audit is August 2026, end quote.
Winter, EnableUs Community
Wow, yeah! In the second one, you've given them the policy ID, the record showing it ran in February, and the proof of ongoing schedule review. It gives the auditor zero room to doubt that the system exists and works right now.
Will, EnableUs Community
Precisely. And keeping these responses accurate is critical because of what I call the three year audit memory trap. Under the auditor guidelines, recertification and reverification audits require a fresh stage one review where auditors directly compare your new self assessment answers against your previous application.
Winter, EnableUs Community
Ah, so if you claimed a control three years ago that quietly disappeared, or if you had a corrective action plan from a past audit, they'll see it immediately.
Will, EnableUs Community
Exactly. Section 13B of the Rules and Annex C of the Guidelines state that any outcome previously subject to a nonconformity or corrective action plan gets re audited at your mid term or renewal audit. The auditor literally opens your past files to verify that your corrective processes stayed in practice.
Winter, EnableUs Community
Which means you can't treat the self assessment as a one off form that you fill in and forget about once your certificate arrives. You have to treat it like a live control register, sitting right alongside your policy suite, updating version numbers and audit dates as your organisation grows.
Will, EnableUs Community
Spot on. Maintain it as a live document, and when renewal comes around, you're just updating a working system instead of trying to reconstruct three years of history under a deadline.