Policy Management

NDIS Policy Gap Analysis: How to Find What's Missing Before Your Audit

AuditCore Team· NDIS Compliance10 May 20266 min read

A policy gap analysis finds the policies you need but don't have — before an auditor does. Here is how to run one and what AuditCore's AI finds automatically.

A policy gap analysis compares your existing policy library against the full set of policies required by the NDIS Practice Standards. It identifies what you have, what you are missing, and what needs updating. AuditCore runs this analysis automatically against your policy register and produces a gap report you can act on immediately.

How to Run a Manual Policy Gap Analysis

  1. 1List every policy your organisation currently has — including version, review date, and approval status
  2. 2Map each policy to the NDIS Practice Standard indicator it supports
  3. 3Compare your list against the complete list of required NDIS policies
  4. 4Identify policies that are missing entirely
  5. 5Identify policies that exist but are outdated, unapproved, or not in use
  6. 6Prioritise gaps by risk — policies linked to serious incidents or audit findings first

The Most Commonly Missing Policies

AuditCore's Policy Library maps your existing policies against every NDIS Practice Standard requirement — instantly showing which policies are missing, outdated, or incomplete.

Run a Policy Gap Analysis

After running gap analyses for NDIS providers across Australia, AuditCore consistently finds the same policies missing in organisations that have not completed a systematic review:

  • Business Continuity and Continuity of Supports Policy
  • Whistle-blower Protection Policy
  • LGBTQIA+ Inclusive Practice Policy
  • Mealtime Management Policy (for providers who need it)
  • Behaviour Support Policy (for providers delivering behaviour support)
  • Document Control Policy
  • Cultural Safety Policy

Policies That Exist But Are Not Compliant

Having a policy is not enough if it does not reflect current requirements. The most common issues AuditCore finds in existing policies:

  • References to repealed legislation or outdated NDIS Commission documents
  • Complaints procedures that do not align with NDIS Commission timeframes
  • Incident management policies that predate the Reportable Incidents Rules
  • Privacy policies that do not address digital data and cloud storage
  • Worker screening policies that do not reference the NDIS Worker Screening Act 2020

Every policy gap identified automatically creates a CI Register item — tracking the gap through to resolution with owner assignment and a due date.

See the CI Register

How AuditCore Runs the Gap Analysis

AuditCore maintains a master list of all policies required for NDIS registration — mapped to each Practice Standard indicator. When you upload or create policies in the platform, they are matched against this master list. The gap analysis dashboard shows you which required policies are present, which are missing, which are overdue for review, and which have currency issues. Before your audit, you run the gap analysis report and get a prioritised list of actions to take.

Ready to simplify NDIS compliance?

AuditCore automates incident management, internal audits, and compliance tracking for Australian NDIS providers.

Book a Free Demo →