NDIS Record Keeping: The Calls Nobody Wrote Down

An NDIS audit is not a test of how well you support people - it is a test of whether you can prove it. Most providers document their shifts carefully and then lose the entire telephone record: the intake call, the family concern, the roster change, the complaint that was fixed. Here is what the rules actually require, and how to stop the phone being the hole in your evidence.

NDIS Providers · Compliance · Record Keeping

NDIS Record Keeping and the Calls Nobody Wrote Down Why Your Audit Evidence Starts on the Phone

An NDIS audit is not a test of how well you support people. It is a test of whether you can prove it. And the single biggest hole in most providers’ evidence is the thing they do most: talk to people on the phone.

📅 ⏱ 14 min read 🇦🇺 Australian owned, Australian hosted, Australian supported
TL;DR

Record keeping is the quiet reason providers fail audits. Not bad support — unprovable support. Under the NDIS Practice Standards, records must be accurate, complete and contemporaneous, kept for a minimum of seven years, and for participants under 18 kept until they turn 25. Reportable incidents run on a 24-hour notification, five-business-day full report clock. Yet the largest single stream of participant contact in most services — the telephone — is usually the least documented thing in the organisation. Nobody types up the call where a mother raised a concern at 7pm, or the roster change agreed verbally on a Friday. This article covers what the rules require, what auditors actually ask for, the Australian law around recording calls (it varies by state and consent matters), how AI transcription makes notes contemporaneous by default, retention and deletion, and a seven-step plan to make your phone a source of evidence rather than a gap in it.

Why Audits Are Won and Lost on Evidence

Talk to anyone who has sat through an NDIS certification audit and you will hear a version of the same story. The support was good. The team cared. The participants were happy. And the auditor kept asking one question in fifteen different ways: show me.

Show me the record of that conversation. Show me when the plan was reviewed. Show me who was told, and when, and what they said back. Show me the note that was written on the day, not the summary someone reconstructed three weeks later from memory.

That is the shape of the whole system. The NDIS Quality and Safeguards Commission does not audit your intentions. It audits your evidence. And in 2026, with increased auditor capacity and a visibly more active enforcement posture, the volume and quality of evidence being asked for has gone up rather than down.

The uncomfortable reframe: if a conversation is not recorded anywhere, then for audit purposes it did not happen. An auditor is not being unreasonable when they say that. They have no other way to distinguish a service that genuinely consulted a participant’s family from one that says it did.

Most providers understand this and act on it — for shift notes. Progress notes get written. Incident forms get filled in. Service agreements get signed and filed. Then the phone rings forty times a day and almost none of it lands anywhere.

What the Rules Actually Require

The record keeping obligations sit across a few places, and it is worth separating them because they have different triggers and different timeframes.

ObligationWhat it means in practice
Practice Standard Outcome 2.4 — Information Management Assessed at every certification and mid-term audit. Records must be accurate, complete, and stored and managed so they are identifiable, accessible to those who need them and protected from those who do not.
Contemporaneous records Made at the time of the event or immediately after it. A note written a fortnight later is not a contemporaneous record, and an auditor can see the timestamp.
Seven-year retention Records, including incident notifications and their supporting documentation, must be kept for a minimum of seven years.
Records for participants under 18 Kept until the person turns 25. Supporting a ten-year-old means that record has a fifteen-year life — longer than most systems you are running today.
Incident management system You must record all incidents, not only reportable ones, including what happened, what was done, and how it was resolved.
Complaints management Complaints must be recorded, actioned and closed out with an audit trail — including complaints made verbally, which is how most of them arrive.

Read that list again and notice how many of those events typically begin as a phone call. An incident is usually first reported by a support worker ringing the coordinator. A complaint is usually a family member calling, upset. A plan change is usually discussed before it is documented. The written record is downstream of a conversation, and the conversation is the part nobody captures.

The shift auditors have made

The Commission’s emphasis has moved towards outcomes-based evidence rather than documentation compliance alone. That is generally good news — it means a tidy folder of policies nobody follows counts for less than it used to. But it raises the bar on the evidence trail, because demonstrating an outcome means showing the sequence: what the person wanted, what you did, what changed, who was consulted along the way.

The 24-Hour, Five-Day, Seven-Year Drill

Every registered provider should be able to recite this without looking it up, because the clock starts the moment somebody in your organisation becomes aware — usually on a phone call.

24 hrs
To notify the Commission of a reportable incident from the moment you become aware
5 days
Business days to submit the full written report after that initial notification
7 years
Minimum retention for notifications and all supporting documentation
6
Reportable incident categories, including unauthorised restrictive practices

The six categories are death, serious injury, abuse or neglect, unlawful sexual or physical contact, sexual misconduct, and the use of an unauthorised restrictive practice. The first five run on the 24-hour clock; unauthorised restrictive practices are notified on a five-business-day basis.

“When did you become aware?” is the question that decides everything

The 24 hours does not run from when management found out. It runs from when the provider became aware, and a support worker who rang the on-call phone at 9pm on Saturday counts. If that call left no trace — no log, no recording, no timestamped note — you cannot evidence when awareness began, and you are arguing about your own timeline with a regulator. A phone system that logs every call to the on-call number, with time, duration and caller, turns that argument into a record.

The Evidence Gap Nobody Talks About: The Phone

Here is a thought experiment worth running with your leadership team. Pick a participant. Now list every interaction your organisation had about that person in the last month that exists as a record: progress notes, service agreement, plan documents, invoices, emails.

Now list the phone calls. The intake enquiry. The support coordinator ringing to change a booking. The mother who called twice about the same worker. The GP’s receptionist confirming an appointment. The Saturday call from a worker who wasn’t sure about something. The plan manager chasing a claim.

For most services, the second list is longer than the first — and almost entirely undocumented.

📞

The call that was never logged

Someone rang, something was agreed, and it lives in one person’s memory. When that person leaves — and in this sector people do leave — the record leaves with them.

🗓️

The note written on Friday about Monday

Reconstructed from memory at the end of a busy week. Not contemporaneous, visibly late in the timestamp, and honestly less accurate than the writer believes.

📵

The mobile nobody can see

Staff using personal mobiles for participant contact is the single worst pattern in the sector for record keeping. The organisation has no visibility, no log, and no access when the worker resigns.

The verbal complaint

Most complaints are made on the phone by someone who never uses the word “complaint”. If it is not captured and classified, your complaints register understates reality — and auditors know it.

🔄

The handover that happened in a corridor

Or on a call between two workers, with no third party and no artefact. Continuity of support depends on it, and there is nothing to point to.

📍

The after-hours call to a diverted number

Diverted to a mobile, answered, dealt with, and invisible to the organisation. The most operationally important calls you take are often the least recorded.

None of this is negligence. It is what happens when the telephone is treated as a utility rather than as part of the record system. The fix is not to ask people to type more. It is to make the phone produce the record itself.

Make Every Call Part of the Record

Call logging, recording where you choose to use it, AI transcription and summaries written straight into your participant record — on an Australian-owned, Australian-hosted platform with Australian support. Talk to a team that understands what an auditor asks for.

Talk to Us Or call directly: 1300 881 662

This is the point where providers get nervous, and reasonably so. Recording conversations in Australia is governed by a patchwork: Commonwealth law covers the interception of communications passing over a network, and each state and territory has its own surveillance devices or listening devices legislation covering the recording of private conversations. The rules are not identical between jurisdictions, and if you operate across borders you are subject to more than one of them.

What follows is a practical description of how the sector approaches this. It is not legal advice, and a provider should get its own advice on its own circumstances — particularly if it operates in multiple states.

PracticeWhy it is the standard approach
Announce it at the start of every call A clear automated message saying calls may be recorded, and why. It is the mechanism by which continuing the call becomes informed consent, and it is trivially easy to configure once on a cloud phone system.
Give a way to opt out A caller who does not want to be recorded should be able to say so and have the call continue without it. Pause-and-resume recording controls exist for exactly this.
Write it into the service agreement Participants and their families should learn about recording when they sign up, not when they hear a beep. Explain the purpose: accuracy of records, safeguarding, training.
Record purposefully, not universally Many providers record intake, complaints and the on-call line, and do not record general chatter. Narrower recording is easier to justify, cheaper to store and less intrusive.
Pause for payment details Never keep card numbers in an audio file. Pause the recording, take the detail, resume.
Control who can listen Role-based access, an access log, and a policy that says who may retrieve a recording and for what reason. An unrestricted recording archive is a privacy incident waiting to be written up.

Handled this way, recording stops being a legal risk and becomes a safeguarding asset. It protects participants when something goes wrong, and it protects workers against allegations that would otherwise be one person’s word against another’s. The mechanics of doing it properly are covered in detail in call recording in Australia: the laws, the benefits and how to set it up.

Contemporaneous by Default: Transcription and Summaries

Here is where the technology has genuinely changed the problem rather than just digitising it.

A recording is evidence, but it is bad evidence to work with. Nobody wants to scrub through eleven minutes of audio to find out what was agreed. What changes the equation is automatic transcription and AI summarisation: the call finishes, and within moments there is a searchable text transcript, a short structured summary of what was discussed, and a list of the actions that came out of it — written into the participant’s record automatically.

⏱️

Contemporaneous without effort

The note exists within seconds of the call ending, timestamped by the system. That is the definition an auditor is applying, met without anyone remembering to do anything.

🔍

Searchable across the whole history

“Find every call where this participant’s transport was discussed.” That question is unanswerable with audio files and trivial with transcripts.

Actions captured, not just words

A summary that ends with the agreed next steps is the difference between a record of a conversation and a record of a decision. Auditors care about decisions.

🧑💻

Time back for the workforce

Support coordinators lose hours a week to write-ups. Removing that is not an efficiency talking point in this sector; it is the difference between a coordinator having capacity for participants and not.

Two cautions, because this technology is oversold elsewhere and providers should hear it straight. First, an AI summary is a draft, not a clinical record — the accountable person should read and confirm it, and your policy should say so. Second, accuracy varies with audio quality, accents and speech differences, which matters enormously in a sector supporting people with communication disabilities. Treat the transcript as an aid to the human record, never as a replacement for a worker’s professional judgement. More on how this works in practice in AI call transcription, summaries and CRM notes.

Retention, Access Control and Deletion

Seven years is a long time in software. Fifteen years — the practical life of a record for a participant supported at age ten — is longer than most platforms you use will exist in their current form. Retention is therefore an architecture question, not a filing question.

Question to answer nowWhy it bites later
Where does the data physically live? If your phone platform is a reseller badge on an overseas cloud, participant conversations may be stored offshore. That is a Privacy Act question and a procurement question, and it is much easier to answer before you sign. See where your calls actually live.
Can you export everything if you leave? Recordings, transcripts and call logs in an open format, not a vendor viewer. A provider that cannot export its own records has outsourced its compliance obligation to a company with no obligation.
Who can listen, and is that logged? Access to a participant’s recordings should be role-based and auditable. “Everyone in the office can play any call” will be written up.
What is the deletion rule, and does it run automatically? Keeping everything forever is not caution, it is risk accumulation. Set retention per record type, apply the under-18 rule where it applies, and let the system enforce it.
What happens on a participant access request? People have a right to their own information. Being able to produce a participant’s call history and transcripts quickly is both a legal obligation and a trust-building act.

Dignity, Privacy and the Participant’s Rights

It would be a mistake to treat all of this purely as compliance engineering. The Practice Standards begin with participant rights for a reason, and record keeping sits inside that, not beside it.

A participant has a right to know what is recorded about them, to see it, to correct it, and to have it held securely and no longer than necessary. A family member ringing to raise a concern is not generating audit evidence; they are trusting you with something difficult. The systems should serve that relationship rather than the other way round.

A useful test for any record keeping decision

Would you be comfortable explaining this practice, in plain language, to the participant it concerns? If recording the on-call line makes sense because it protects both the person and the worker, that explains itself easily. If a practice only makes sense as protection for the organisation, it will not survive that conversation — and it probably should not.

There is also a quality dimension that gets lost in compliance talk. Recordings and transcripts of real calls are the best training material a service will ever have. Reviewing how an intake call was handled, or how a distressed family member was spoken to, improves practice in a way that no policy document can. Used well — with the team’s knowledge, and for coaching rather than surveillance — it lifts the standard of the conversations themselves. That is the approach set out in AI call scoring and quality assurance.

Seven Steps to a Phone Record That Survives an Audit

A practical sequence. Most providers can work through this in a few weeks.

StepWhat to doWhat it fixes
1. Get participant contact off personal mobiles Give every worker a business identity on their own device through an app, so calls go out from the organisation’s number and are logged centrally. The single biggest invisible-record problem in the sector, and the hardest to explain to an auditor.
2. Number the functions, not just the people Separate published numbers for intake, on-call, complaints and general enquiries, each with its own routing and reporting. Makes the call log meaningful. “Eleven calls to the complaints line last month” is evidence; a mixed call log is noise.
3. Write the recording policy before switching recording on Scope, announcement wording, opt-out handling, access rules, retention periods, and the deletion schedule. Get advice on the jurisdictions you operate in. Turns recording from a liability into a defensible, documented control.
4. Turn on transcription and summaries Automatic transcript and structured summary for every recorded call, pushed into the participant record with the timestamp intact. Contemporaneous notes without relying on anyone’s memory or goodwill at 6pm.
5. Connect the phone to the system of record Integrate with your client management, CRM or rostering platform so call activity attaches to the participant automatically rather than being retyped. Ends double entry, and ends the gap where a call is logged in one system and invisible in the other.
6. Make the on-call line a real service A single after-hours number with a rota, escalation, voicemail-to-text and a complete log — not a manager’s personal mobile. Establishes exactly when the organisation became aware of something. That is the 24-hour clock.
7. Rehearse the audit questions Once a quarter, pick a participant at random and produce the full contact history in ten minutes. If you cannot, you have found your gap before the auditor did. Turns compliance from an annual panic into a routine that quietly improves.

Seven Mistakes That Cost Providers at Audit

📱

1. Personal mobiles for participant contact

No log, no continuity, no organisational access, and a privacy exposure when the phone is lost or the worker leaves.

📝

2. Batch-writing notes at the end of the week

Visibly non-contemporaneous, and less accurate than the writer thinks. Timestamps do not lie.

🗂️

3. Records in five places

Rostering here, notes there, emails in Outlook, calls nowhere. Producing a single participant history becomes a half-day archaeology project.

♻️

4. No deletion schedule at all

Keeping everything forever looks careful and is actually the opposite: more data, more exposure, more to produce in a breach.

🌏

5. Not knowing where the data is stored

“It’s in the cloud” is not an answer to a question about participant information. Know the jurisdiction and be able to say it.

🚪

6. Unrestricted access to recordings

If anyone in the office can listen to any call about any participant, that is a finding, and fairly it should be.

📥

7. Verbal complaints that never reach the register

A complaints register with two entries in a year does not tell an auditor you have no complaints. It tells them you are not capturing them.

Every one of those has the same root cause: the phone was never treated as part of the record system. Fix that and most of the list resolves itself — which is a much better position than trying to fix seven separate documentation habits across a workforce that is already stretched.

Frequently Asked Questions

How long does an NDIS provider have to keep records?
The baseline is a minimum of seven years, and that covers participant records, incident notifications and the supporting documentation behind them. There is a longer rule that catches a lot of providers out: where you support a participant who is under 18, their records must be kept until they turn 25. Supporting a ten-year-old therefore creates a record with a fifteen-year life, which is longer than most software platforms survive in their current form. That has a practical consequence worth thinking about before you choose systems - you need to be confident you can export your records in an open, readable format and carry them to whatever you use next, because the obligation follows the provider, not the vendor. It is also why an automated retention and deletion schedule is worth setting up properly: keeping everything forever is not caution, it is accumulating risk and cost, while deleting something early is a compliance failure.
What does contemporaneous actually mean for record keeping?
It means the record was created at the time of the event or immediately after it, rather than reconstructed later from memory. This is assessed under Practice Standard Outcome 2.4 on information management, and auditors can see timestamps, so a batch of notes all written on a Friday afternoon about events across the week is visible for exactly what it is. The reason the standard exists is accuracy rather than bureaucracy: human memory of a specific conversation degrades quickly, and details that matter later - who said what, what was agreed, what time somebody was informed - are the first things to go. The practical implication for the telephone is significant, because calls are the interactions least likely to be written up promptly. Automatic call logging with transcription and a structured summary produces a timestamped note within seconds of the call ending, which meets the definition without depending on anyone remembering to do anything at the end of a long day.
What are the reporting timeframes for a reportable incident?
A registered provider must submit an initial notification to the NDIS Quality and Safeguards Commission within 24 hours of becoming aware of a reportable incident, and then a full written report within five business days of that notification. Unauthorised restrictive practices sit on a five-business-day notification timeframe rather than 24 hours. The six reportable categories are death, serious injury, abuse or neglect, unlawful sexual or physical contact, sexual misconduct, and the use of an unauthorised restrictive practice. All notifications and supporting documentation must be kept for at least seven years. The detail that catches providers out is the phrase becoming aware, because awareness usually starts with a phone call from a support worker rather than an email to management. If that call is not logged with a time, you have no way to evidence when the clock started, and you end up arguing about your own timeline with the regulator.
Is it legal to record phone calls with participants and families?
Recording is governed by a patchwork of laws in Australia: Commonwealth legislation covers the interception of communications passing over a network, and each state and territory has its own surveillance devices or listening devices legislation covering the recording of private conversations. The rules are not identical across jurisdictions, so a provider operating across state borders is subject to more than one of them, and every provider should get its own legal advice rather than relying on a general article. What the sector does in practice is straightforward and defensible: play a clear automated announcement at the start of every call saying that calls may be recorded and why, allow a caller who objects to continue without recording, describe the practice in service agreements so people learn about it at sign-up, restrict who can access recordings, and pause recording before any payment details are taken. Recording narrowly and purposefully - intake, complaints and the on-call line, for instance - is easier to justify than recording everything.
Can AI notes replace a support worker's written record?
No, and a provider should be explicit about that in policy. An AI transcript and summary is an excellent aid: it captures what was said, produces a timestamped and searchable record within seconds, and pulls out the actions agreed. But it is a draft that the accountable person should read and confirm, not a professional record in itself. Two limits matter especially in disability services. Transcription accuracy varies with audio quality, accents, background noise and speech differences, which is a serious consideration in a sector supporting people with communication disabilities, and an inaccurate transcript treated as gospel is worse than no transcript. And a summary captures content, not clinical or professional judgement - the worker's assessment of how somebody presented, what concerned them and what they intend to do about it is the part that matters most at audit and the part no model produces. Use the technology to remove the typing, not the thinking.
Our staff use their own mobiles to call participants. Is that a problem?
It is the most common record keeping weakness in the sector and the hardest one to explain to an auditor. When participant contact happens on a personal mobile, the organisation has no call log, no recording, no transcript and no way to reconstruct what was discussed. The number belongs to the worker rather than the service, so continuity breaks the moment they are on leave or resign, and participants may keep ringing a phone that nobody answers on the organisation's behalf. There are privacy exposures in both directions: participant details sit in a personal device outside your control, and the worker's private number is now in the community. The fix does not require buying anyone a handset. A cloud phone system puts a business identity on the worker's own device through an app, so outbound calls display the organisation's number, every call is logged centrally, recordings and transcripts flow into the participant record, and the worker keeps their private number private.
What is the fastest way to close the gap before our next audit?
Run a rehearsal. Pick a participant at random and give yourself ten minutes to produce their complete contact history for the last six months - every call in and out, who from, when, what was discussed and what came of it. Most providers discover in that exercise that shift notes are strong and telephone contact is close to invisible, which tells you precisely where to spend your effort. From there the highest-value moves in order are: get participant contact off personal mobiles and onto the organisation's phone system so it is logged; give intake, complaints and the on-call line their own numbers so the log is meaningful; write the recording policy before switching recording on; and turn on transcription so notes become contemporaneous by default. Those four steps are achievable in a few weeks and they address the majority of what an auditor will ask about under information management, incident management and complaints.

What to Read Next

Your next reads

Uniden Voice Over Cloud logo

Australia’s smartest AI-powered cloud phone system — Australian owned, Australian hosted, Australian supported. unidenvoice.com | 1300 881 662