Why Audits Are Won and Lost on Evidence
Talk to anyone who has sat through an NDIS certification audit and you will hear a version of the same story. The support was good. The team cared. The participants were happy. And the auditor kept asking one question in fifteen different ways: show me.
Show me the record of that conversation. Show me when the plan was reviewed. Show me who was told, and when, and what they said back. Show me the note that was written on the day, not the summary someone reconstructed three weeks later from memory.
That is the shape of the whole system. The NDIS Quality and Safeguards Commission does not audit your intentions. It audits your evidence. And in 2026, with increased auditor capacity and a visibly more active enforcement posture, the volume and quality of evidence being asked for has gone up rather than down.
The uncomfortable reframe: if a conversation is not recorded anywhere, then for audit purposes it did not happen. An auditor is not being unreasonable when they say that. They have no other way to distinguish a service that genuinely consulted a participant’s family from one that says it did.
Most providers understand this and act on it — for shift notes. Progress notes get written. Incident forms get filled in. Service agreements get signed and filed. Then the phone rings forty times a day and almost none of it lands anywhere.
What the Rules Actually Require
The record keeping obligations sit across a few places, and it is worth separating them because they have different triggers and different timeframes.
| Obligation | What it means in practice |
|---|---|
| Practice Standard Outcome 2.4 — Information Management | Assessed at every certification and mid-term audit. Records must be accurate, complete, and stored and managed so they are identifiable, accessible to those who need them and protected from those who do not. |
| Contemporaneous records | Made at the time of the event or immediately after it. A note written a fortnight later is not a contemporaneous record, and an auditor can see the timestamp. |
| Seven-year retention | Records, including incident notifications and their supporting documentation, must be kept for a minimum of seven years. |
| Records for participants under 18 | Kept until the person turns 25. Supporting a ten-year-old means that record has a fifteen-year life — longer than most systems you are running today. |
| Incident management system | You must record all incidents, not only reportable ones, including what happened, what was done, and how it was resolved. |
| Complaints management | Complaints must be recorded, actioned and closed out with an audit trail — including complaints made verbally, which is how most of them arrive. |
Read that list again and notice how many of those events typically begin as a phone call. An incident is usually first reported by a support worker ringing the coordinator. A complaint is usually a family member calling, upset. A plan change is usually discussed before it is documented. The written record is downstream of a conversation, and the conversation is the part nobody captures.
The shift auditors have made
The Commission’s emphasis has moved towards outcomes-based evidence rather than documentation compliance alone. That is generally good news — it means a tidy folder of policies nobody follows counts for less than it used to. But it raises the bar on the evidence trail, because demonstrating an outcome means showing the sequence: what the person wanted, what you did, what changed, who was consulted along the way.
The 24-Hour, Five-Day, Seven-Year Drill
Every registered provider should be able to recite this without looking it up, because the clock starts the moment somebody in your organisation becomes aware — usually on a phone call.
24 hrs
To notify the Commission of a reportable incident from the moment you become aware
5 days
Business days to submit the full written report after that initial notification
7 years
Minimum retention for notifications and all supporting documentation
6
Reportable incident categories, including unauthorised restrictive practices
The six categories are death, serious injury, abuse or neglect, unlawful sexual or physical contact, sexual misconduct, and the use of an unauthorised restrictive practice. The first five run on the 24-hour clock; unauthorised restrictive practices are notified on a five-business-day basis.
“When did you become aware?” is the question that decides everything
The 24 hours does not run from when management found out. It runs from when the provider became aware, and a support worker who rang the on-call phone at 9pm on Saturday counts. If that call left no trace — no log, no recording, no timestamped note — you cannot evidence when awareness began, and you are arguing about your own timeline with a regulator. A phone system that logs every call to the on-call number, with time, duration and caller, turns that argument into a record.
The Evidence Gap Nobody Talks About: The Phone
Here is a thought experiment worth running with your leadership team. Pick a participant. Now list every interaction your organisation had about that person in the last month that exists as a record: progress notes, service agreement, plan documents, invoices, emails.
Now list the phone calls. The intake enquiry. The support coordinator ringing to change a booking. The mother who called twice about the same worker. The GP’s receptionist confirming an appointment. The Saturday call from a worker who wasn’t sure about something. The plan manager chasing a claim.
For most services, the second list is longer than the first — and almost entirely undocumented.
The call that was never logged
Someone rang, something was agreed, and it lives in one person’s memory. When that person leaves — and in this sector people do leave — the record leaves with them.
The note written on Friday about Monday
Reconstructed from memory at the end of a busy week. Not contemporaneous, visibly late in the timestamp, and honestly less accurate than the writer believes.
The mobile nobody can see
Staff using personal mobiles for participant contact is the single worst pattern in the sector for record keeping. The organisation has no visibility, no log, and no access when the worker resigns.
The verbal complaint
Most complaints are made on the phone by someone who never uses the word “complaint”. If it is not captured and classified, your complaints register understates reality — and auditors know it.
The handover that happened in a corridor
Or on a call between two workers, with no third party and no artefact. Continuity of support depends on it, and there is nothing to point to.
The after-hours call to a diverted number
Diverted to a mobile, answered, dealt with, and invisible to the organisation. The most operationally important calls you take are often the least recorded.
None of this is negligence. It is what happens when the telephone is treated as a utility rather than as part of the record system. The fix is not to ask people to type more. It is to make the phone produce the record itself.
Recording Calls in Australia: The Legal Position
This is the point where providers get nervous, and reasonably so. Recording conversations in Australia is governed by a patchwork: Commonwealth law covers the interception of communications passing over a network, and each state and territory has its own surveillance devices or listening devices legislation covering the recording of private conversations. The rules are not identical between jurisdictions, and if you operate across borders you are subject to more than one of them.
What follows is a practical description of how the sector approaches this. It is not legal advice, and a provider should get its own advice on its own circumstances — particularly if it operates in multiple states.
| Practice | Why it is the standard approach |
|---|---|
| Announce it at the start of every call | A clear automated message saying calls may be recorded, and why. It is the mechanism by which continuing the call becomes informed consent, and it is trivially easy to configure once on a cloud phone system. |
| Give a way to opt out | A caller who does not want to be recorded should be able to say so and have the call continue without it. Pause-and-resume recording controls exist for exactly this. |
| Write it into the service agreement | Participants and their families should learn about recording when they sign up, not when they hear a beep. Explain the purpose: accuracy of records, safeguarding, training. |
| Record purposefully, not universally | Many providers record intake, complaints and the on-call line, and do not record general chatter. Narrower recording is easier to justify, cheaper to store and less intrusive. |
| Pause for payment details | Never keep card numbers in an audio file. Pause the recording, take the detail, resume. |
| Control who can listen | Role-based access, an access log, and a policy that says who may retrieve a recording and for what reason. An unrestricted recording archive is a privacy incident waiting to be written up. |
Handled this way, recording stops being a legal risk and becomes a safeguarding asset. It protects participants when something goes wrong, and it protects workers against allegations that would otherwise be one person’s word against another’s. The mechanics of doing it properly are covered in detail in call recording in Australia: the laws, the benefits and how to set it up.
Contemporaneous by Default: Transcription and Summaries
Here is where the technology has genuinely changed the problem rather than just digitising it.
A recording is evidence, but it is bad evidence to work with. Nobody wants to scrub through eleven minutes of audio to find out what was agreed. What changes the equation is automatic transcription and AI summarisation: the call finishes, and within moments there is a searchable text transcript, a short structured summary of what was discussed, and a list of the actions that came out of it — written into the participant’s record automatically.
Contemporaneous without effort
The note exists within seconds of the call ending, timestamped by the system. That is the definition an auditor is applying, met without anyone remembering to do anything.
Searchable across the whole history
“Find every call where this participant’s transport was discussed.” That question is unanswerable with audio files and trivial with transcripts.
Actions captured, not just words
A summary that ends with the agreed next steps is the difference between a record of a conversation and a record of a decision. Auditors care about decisions.
Time back for the workforce
Support coordinators lose hours a week to write-ups. Removing that is not an efficiency talking point in this sector; it is the difference between a coordinator having capacity for participants and not.
Two cautions, because this technology is oversold elsewhere and providers should hear it straight. First, an AI summary is a draft, not a clinical record — the accountable person should read and confirm it, and your policy should say so. Second, accuracy varies with audio quality, accents and speech differences, which matters enormously in a sector supporting people with communication disabilities. Treat the transcript as an aid to the human record, never as a replacement for a worker’s professional judgement. More on how this works in practice in AI call transcription, summaries and CRM notes.
Retention, Access Control and Deletion
Seven years is a long time in software. Fifteen years — the practical life of a record for a participant supported at age ten — is longer than most platforms you use will exist in their current form. Retention is therefore an architecture question, not a filing question.
| Question to answer now | Why it bites later |
|---|---|
| Where does the data physically live? | If your phone platform is a reseller badge on an overseas cloud, participant conversations may be stored offshore. That is a Privacy Act question and a procurement question, and it is much easier to answer before you sign. See where your calls actually live. |
| Can you export everything if you leave? | Recordings, transcripts and call logs in an open format, not a vendor viewer. A provider that cannot export its own records has outsourced its compliance obligation to a company with no obligation. |
| Who can listen, and is that logged? | Access to a participant’s recordings should be role-based and auditable. “Everyone in the office can play any call” will be written up. |
| What is the deletion rule, and does it run automatically? | Keeping everything forever is not caution, it is risk accumulation. Set retention per record type, apply the under-18 rule where it applies, and let the system enforce it. |
| What happens on a participant access request? | People have a right to their own information. Being able to produce a participant’s call history and transcripts quickly is both a legal obligation and a trust-building act. |
Dignity, Privacy and the Participant’s Rights
It would be a mistake to treat all of this purely as compliance engineering. The Practice Standards begin with participant rights for a reason, and record keeping sits inside that, not beside it.
A participant has a right to know what is recorded about them, to see it, to correct it, and to have it held securely and no longer than necessary. A family member ringing to raise a concern is not generating audit evidence; they are trusting you with something difficult. The systems should serve that relationship rather than the other way round.
A useful test for any record keeping decision
Would you be comfortable explaining this practice, in plain language, to the participant it concerns? If recording the on-call line makes sense because it protects both the person and the worker, that explains itself easily. If a practice only makes sense as protection for the organisation, it will not survive that conversation — and it probably should not.
There is also a quality dimension that gets lost in compliance talk. Recordings and transcripts of real calls are the best training material a service will ever have. Reviewing how an intake call was handled, or how a distressed family member was spoken to, improves practice in a way that no policy document can. Used well — with the team’s knowledge, and for coaching rather than surveillance — it lifts the standard of the conversations themselves. That is the approach set out in AI call scoring and quality assurance.
Seven Steps to a Phone Record That Survives an Audit
A practical sequence. Most providers can work through this in a few weeks.
| Step | What to do | What it fixes |
|---|---|---|
| 1. Get participant contact off personal mobiles | Give every worker a business identity on their own device through an app, so calls go out from the organisation’s number and are logged centrally. | The single biggest invisible-record problem in the sector, and the hardest to explain to an auditor. |
| 2. Number the functions, not just the people | Separate published numbers for intake, on-call, complaints and general enquiries, each with its own routing and reporting. | Makes the call log meaningful. “Eleven calls to the complaints line last month” is evidence; a mixed call log is noise. |
| 3. Write the recording policy before switching recording on | Scope, announcement wording, opt-out handling, access rules, retention periods, and the deletion schedule. Get advice on the jurisdictions you operate in. | Turns recording from a liability into a defensible, documented control. |
| 4. Turn on transcription and summaries | Automatic transcript and structured summary for every recorded call, pushed into the participant record with the timestamp intact. | Contemporaneous notes without relying on anyone’s memory or goodwill at 6pm. |
| 5. Connect the phone to the system of record | Integrate with your client management, CRM or rostering platform so call activity attaches to the participant automatically rather than being retyped. | Ends double entry, and ends the gap where a call is logged in one system and invisible in the other. |
| 6. Make the on-call line a real service | A single after-hours number with a rota, escalation, voicemail-to-text and a complete log — not a manager’s personal mobile. | Establishes exactly when the organisation became aware of something. That is the 24-hour clock. |
| 7. Rehearse the audit questions | Once a quarter, pick a participant at random and produce the full contact history in ten minutes. If you cannot, you have found your gap before the auditor did. | Turns compliance from an annual panic into a routine that quietly improves. |
Seven Mistakes That Cost Providers at Audit
1. Personal mobiles for participant contact
No log, no continuity, no organisational access, and a privacy exposure when the phone is lost or the worker leaves.
2. Batch-writing notes at the end of the week
Visibly non-contemporaneous, and less accurate than the writer thinks. Timestamps do not lie.
3. Records in five places
Rostering here, notes there, emails in Outlook, calls nowhere. Producing a single participant history becomes a half-day archaeology project.
4. No deletion schedule at all
Keeping everything forever looks careful and is actually the opposite: more data, more exposure, more to produce in a breach.
5. Not knowing where the data is stored
“It’s in the cloud” is not an answer to a question about participant information. Know the jurisdiction and be able to say it.
6. Unrestricted access to recordings
If anyone in the office can listen to any call about any participant, that is a finding, and fairly it should be.
7. Verbal complaints that never reach the register
A complaints register with two entries in a year does not tell an auditor you have no complaints. It tells them you are not capturing them.
Every one of those has the same root cause: the phone was never treated as part of the record system. Fix that and most of the list resolves itself — which is a much better position than trying to fix seven separate documentation habits across a workforce that is already stretched.