If you run a registered NDIS provider, your auditor will ask how you protect participant information. This guide explains what the NDIS Practice Standards actually require of your IT systems — in plain English.
Which Practice Standards touch your IT?
The Core Module’s Governance and Operational Management standard requires providers to manage records and information securely. In practice, auditors look for evidence across four areas: access control, data security, records management and incident response.
- Access control — staff only see the participant records they need; access is revoked when they leave
- Data security — devices are patched, protected and encrypted; MFA is enabled on email and client systems
- Records management — participant records live in a managed system with backups, not personal inboxes or USB drives
- Incident response — you can detect, contain and report a breach under the Privacy Act’s notifiable data breach scheme
What auditors ask to see
Expect requests for your information security policy, evidence of backups and restore tests, a register of who has access to what, and your data breach response plan. If those documents don’t exist, that’s the first gap to close.
Where to start
Begin with an Essential Eight assessment — it covers most of the technical controls auditors expect. Then document what you already do. Most providers are closer to compliant than they think; the evidence is just scattered.
DomainIT specialises in IT support for NDIS providers. Call 03 9122 5224 for an audit-readiness health check.
