← All guides
19 September 2026

NDIS Core Module Self-Assessment: Check Your Evidence Before an Audit

NDIS Core Module Self-Assessment: Check Your Evidence Before an Audit

An NDIS Core Module self-assessment is a structured walk through every quality indicator in the four Core Module divisions, recording whether evidence exists, partly exists or does not exist. You do it before an auditor does it for you, so gaps are found and fixed on your timetable rather than written up as non-conformities. The output is an action list, not a score.

This guide is general information current at September 2026 for providers assessed by certification audit against the Core Module. Confirm your position with the NDIS Quality and Safeguards Commission and your approved quality auditor, working from the current NDIS Practice Standards and Quality Indicators.

The Commission's online registration application asks for a self-assessment against the applicable NDIS Practice Standards, with evidence to support your comments (see how to become a registered NDIS provider).

The four Core Module divisions

The Core Module in the NDIS (Provider Registration and Practice Standards) Rules 2018 has four divisions, each made up of outcome statements and quality indicators. Auditors request evidence at indicator level, so that is how a self-assessment works.

Rights and responsibilities

Person-centred supports, individual values and beliefs, privacy and dignity, independence and informed choice, and preventing violence, abuse, neglect, exploitation and discrimination. Examples: workers understand each participant's legal and human rights and apply them in daily practice; each participant's right to take reasonable risks in their own decisions is supported.

Governance and operational management

The largest division: governance, risk, quality, information management, feedback and complaints, incident management, human resources, continuity of supports, and emergency and disaster management. Examples: the quality system includes a documented program of internal audits; worker pre-employment checks, qualifications and screening status are recorded and kept current.

Provision of supports

Access to supports, support planning, service agreements, responsive support provision and transitions to or from the provider. Examples: support plans are developed with the participant and reviewed at least annually or when needs change; each participant with a written service agreement receives a copy and is helped to understand it.

Provision of supports environment

Safe environment, participant money and property, management of medication and mealtime management. Examples: workers who deliver supports directly hold current first aid training; medication records identify each participant's medication and dose and are kept up to date. The medication and mealtime indicators apply where you deliver those supports.

Yes, Partial or No: how to score honestly

The temptation is to tick Yes because the policy is written. Resist it.

Yes means both that the document exists and that there is evidence it is used. A complaints policy scores Yes when there is also a complaints register with entries (or a dated nil return), a record that workers were trained in it, and a service agreement or handbook that tells participants how to complain.

Partial means the document exists but the implementation evidence is thin, out of date or missing. A policy with no register, no training record and no completed form is Partial at best.

No means nothing is in place, or what exists does not address the indicator. Finding a No early is the point of the exercise.

Two habits keep scoring honest: have someone other than the document's author assess it where you can, and record the evidence you actually looked at. If you cannot name the file, it is not a Yes.

What counts as evidence

Auditors assess practice, not intentions. The evidence categories that recur against almost every indicator:

  • Registers: complaints, incidents, risks, training, worker screening, conflicts of interest, continuous improvement, and a master document register showing version and review status. Auditors also look for a documented record retention and disposal process behind those registers.
  • Completed forms: intake forms, signed service agreements, consent records, incident reports, conflict of interest declarations, medication charts.
  • Training records: induction checklists, competency assessments, first aid and infection control certificates.
  • Meeting minutes: governance meetings, risk reviews, complaint and incident trend reviews.
  • Incident and complaint records showing what happened, what was done and what changed as a result.
  • Participant files: support plans with review dates, risk assessments, progress notes, mealtime or medication plans where relevant.
  • Version-controlled documents with an approval block, a review date and a change history.
  • Audit and review records: internal audit checklists, previous self-assessments, corrective action registers with closed items.

A gap in evidence often reveals a gap in practice. If nobody can find the supervision records, ask whether supervision happens.

A four week self-assessment plan for a small provider

  1. Week 1: inventory and set-up. Open the four Core Module checklists, decide who assesses and who reviews, and build or update your master document register so you know which documents exist and their version and review date. Note any supplementary modules that also apply; each needs its own pass.
  2. Week 2: governance and rights. Work through Governance and operational management, then Rights and responsibilities. Policies usually exist here; registers and training records often do not. Pull a sample of worker files and check screening, induction, training and supervision against what the policies require.
  3. Week 3: supports and environment. Work through Provision of supports and Provision of supports environment using real participant files. Pick two or three participants and trace intake, service agreement, support plan, risk assessment, progress notes and, where relevant, medication and mealtime records. Walk your home visit or site safety process against the safe environment indicators.
  4. Week 4: actions and sign-off. Consolidate every Partial and No into an action list, assign owners and dates, sign off the assessment and schedule the follow-up review. File the completed checklists; they are themselves evidence for the quality management indicators.

Turning gaps into an action list

Every Partial or No should produce a line in a corrective actions register. A usable entry has four parts:

  • Owner: a named person, not a role. In a sole director business that is often you, which is fine if the date is realistic.
  • Due date: far enough before your audit to generate evidence, not just write a document. A training register needs training to have happened.
  • Evidence to be produced: the specific artefact that changes the score. For example: complaints register created, this year's two complaints entered, workers briefed at the October team meeting, attendance recorded.
  • Link to the continuous improvement register: transfer each action so it sits alongside improvements from complaints, incidents and internal audits. Auditors look for one system that closes the loop.

Close each action with a date and where the evidence sits. The next self-assessment starts from these records.

Certification versus verification

Providers registering for higher-risk or more complex registration groups, including supported independent living from 1 July 2026, are assessed by certification audit against the Core Module and any applicable supplementary modules. Certification is a two-stage audit: the auditor reviews documents, then tests whether practice matches them through participant files and conversations with workers and participants.

Sole traders and providers delivering lower-risk registration groups are generally assessed by verification, a document review against the verification module rather than the full Core Module. Use the Sole-Trader Verification Self-Assessment Checklist instead, and see our NDIS verification audit guide. The Commission confirms your pathway after you apply, based on the registration groups you select.

Templates that support a Core Module self-assessment

MRSS publishes four NDIS Core Standards Self-Assessment Checklists, one per division: Governance and Operations (CORE-01-13), Rights and Responsibilities (CORE-02-11), Provision of Supports (CORE-03-11) and Support Environment (CORE-06-10). Each lists the indicators, the Core Library documents that sit against them (for example CORE-01-01 Corporate Governance Policy), a Yes, No or Partial column, an actions column, a corrective actions register and a sign-off block. They work alongside the NDIS Audit Preparation Checklist, the Master Document Register for the inventory step, the Internal Audit Schedule and Checklist for the ongoing program, and the Continuous Improvement Register for tracking actions.

All of these are in the NDIS Provider Core Library (230 documents, $599) and sold individually at $24.99, as editable Word files with a version control table and approval block. They are a starting point that must be customised to your services and implemented; the evidence behind every Yes comes from your practice, and audit outcomes depend on what your auditor finds in your records.

Frequently asked questions

How often should an NDIS provider complete a Core Module self-assessment?

There is no set legal frequency. Good practice is at least once a year and again before any scheduled audit, including registration renewal. Many providers align it with their internal audit schedule so each division is checked annually and the results feed the continuous improvement register. Check current Commission guidance and your registration conditions.

Is a self-assessment required for NDIS registration?

The Commission's online registration application includes a self-assessment against the NDIS Practice Standards that apply to the supports you deliver, with evidence to support your comments. A structured Core Module self-assessment done beforehand makes that step faster and more accurate. Check the current Commission guidance for what the application and renewal process asks of you.

What is the difference between a self-assessment and an internal audit?

A self-assessment is a point-in-time review of every indicator, usually annual or pre-audit, that records the status of your evidence. An internal audit is a scheduled program that samples specific areas through the year. The Core Module expects a documented internal audit program; the self-assessment checks that it, and everything else, exists and works.

Sources: NDIS Practice Standards and Quality Indicators (NDIS Quality and Safeguards Commission); National Disability Insurance Scheme (Provider Registration and Practice Standards) Rules 2018; NDIS Quality and Safeguards Commission guidance on applying for registration and the quality audit process, accessed September 2026.

These templates are general information, not legal advice. No template pack can guarantee registration or audit outcomes.