NDIS Policies and Procedures: What You Actually Need
Ask ten NDIS consultants what policies you need and you will get ten different lists and ten different invoices. The honest answer is that the list depends on your registration groups, your delivery model and whether you employ staff. This guide explains how the NDIS Practice Standards drive your document requirements, what a sensible core set looks like, and what auditors actually look for beyond the paperwork.
This article is general information, not legal advice. Check requirements against the NDIS Practice Standards for your registration groups.
Policies follow the Practice Standards, not the other way round
The NDIS Practice Standards are the benchmark that registered providers are audited against. They are organised as a core module plus supplementary modules that apply depending on what you deliver:
- Core module: rights of participants, governance and operational management, the provision of supports, and the support provision environment
- Supplementary modules: for example high intensity daily personal activities, specialist behaviour support, implementing behaviour support plans, early childhood supports, specialist disability accommodation, and the new supported independent living module that applies to registered SIL providers from 1 July 2026.
Your Initial Scope of Audit tells you which standards apply to you. Every policy you write should map back to a standard or a real operational need. If a document does not do either, it is shelf-ware.
The core document set most providers need
For a small provider heading for certification against the core module, a workable library usually covers:
- Governance and compliance: corporate governance, risk management, continuous improvement, document control, compliance calendar, delegations
- Participant rights and safeguarding: rights and dignity, privacy, advocacy, safeguarding, easy-read participant materials
- Service delivery: intake and eligibility, service agreements, support planning, participant money and property, exit and transition
- Incidents and complaints: incident management including reportable incidents, complaints and feedback management, with registers for both
- Workforce: recruitment and screening, induction, training and competency records, supervision, performance, code of conduct
- Work health and safety: WHS policy, home visit and lone worker safety, infection prevention, emergency and disaster management
- Medication and health supports (if you deliver them): medication administration built on the 6 Rights, plus high intensity support procedures where applicable
- Information management: records management, data breach response, information security.
Sole traders need a leaner set. If you have no employees, you do not need an HR manual, a board charter or a supervision framework. You do still need the participant-facing, safety, privacy, incident and complaint documents that apply to the work you actually do. Our Independent Support Worker Verification Pack is built specifically for that situation.
What auditors look for (it is not just the documents)
A folder of polished policies proves very little on its own. Auditors check that your policies are implemented, and implementation leaves evidence:
- completed registers: incidents, complaints, risks, conflicts of interest, continuous improvement
- training records showing workers actually read and understood the policies
- version control and review dates showing documents are maintained, not bought and forgotten
- records of practice: service agreements signed, support plans reviewed, incidents managed the way your policy says they will be.
This is why "policies alone are not evidence of compliance" is the position we take across everything we sell. Documents give you the framework; your day-to-day records prove it works.
Buying templates versus writing from scratch
Writing a full library from scratch takes hundreds of hours and it is easy to miss requirements. Templates solve the structure problem cheaply, with two conditions. First, they must be current: NDIS requirements changed significantly through 2024 to 2026, and documents citing outdated legislation or old pricing arrangements will hurt you at audit. Second, they must be customised: the Commission has warned that applications relying on uncustomised purchased policies can be refused, so whatever you buy, from us or anyone else, plan to spend real time making it match how you actually operate.
How the MRSS library is organised
Every document in our library is mapped to its Practice Standards module, uses consistent formatting and version-control blocks, and comes in editable Word format with placeholder fields for your business details. The NDIS Provider Core Library covers the core module set (229 documents). Add-on modules cover high intensity supports and behaviour support and restrictive practices, and the Complete Library includes everything (330 documents). All are priced for small providers, not enterprise budgets.
Frequently asked questions
What are the NDIS Practice Standards?
They are the quality benchmark registered providers are assessed against at audit, made up of a core module and supplementary modules with quality indicators for each. Which modules apply depends on your registration groups.
Do unregistered providers need policies?
Unregistered providers are not audited against the Practice Standards, but they must comply with the NDIS Code of Conduct, and good practice still requires service agreements, privacy, incident and complaint handling, and proper records. Participants and plan managers increasingly ask to see these documents before engaging you.
How many policies do I need for NDIS registration?
There is no official number. What matters is covering every Practice Standard in your audit scope with documents you actually implement. A sole trader might operate well with a few dozen documents; a provider delivering high intensity supports needs substantially more.
Sources: NDIS Quality and Safeguards Commission, The quality audit process and Apply for registration, accessed August 2026.
These templates are general information, not legal advice. No template pack can guarantee registration or audit outcomes.