Audit, Documents, and Evidence
Stay audit ready all year, not just audit week.
Audit Centre scores your readiness continuously, generates audit evidence from live records, maps it to the NDIS Practice Standards, and shares it with auditors through a secure, time-boxed portal.
Before you begin
The Audit Centre keeps your organisation audit ready all year, not just in audit week. Before you start, it helps to have:
- Staff, client, site and organisation documents uploaded into Documents.
- An Owner or Admin who can decide which document types are enforced.
- A clear picture of which audit or review is coming up, if one is scheduled.
Recommended setup order
The Audit Centre opens on the Readiness tab. We recommend working through it in this order.
1 Run your readiness checks
Open the Readiness tab and select Run readiness check. BondiByte scores your organisation across six domains: worker compliance, participant records, service delivery, incidents, document control and corrective actions.
Every issue comes with a plain-language explanation of how to fix it, and the score updates as records change. Critical issues cap the overall score until they are resolved, and the cap is shown with the reason.
Use the Fix these first panel to clear the highest-impact items, and the scope filter to view readiness for a single site, participant or worker.
A green score all year beats a scramble the month before an audit.
2 Tune your compliance checks
The Checks tab lists every automatic check behind the readiness score. Each check can be turned on or off for your organisation.
Turning a check off stops it being evaluated and it no longer counts towards your readiness score, so only disable checks that genuinely do not apply to your operation.
3 Choose what is enforced, and where
Open Settings in the Audit Centre. Each document type has two separate switches, and both start turned off:
- Enforce for compliance chasing: the document counts in readiness checks, appears on each staff member's My Compliance checklist, and staff are reminded to keep it current.
- Enforce for rostering: Smart Rostering will not assign a staff member who is missing this document. Use this only for documents that genuinely must block a shift.
Rostering enforcement is deliberately opt-in. Nothing blocks shift assignment until you switch it on for a document type. Site pages show organisation-enforced items greyed out with a link back to these settings.
4 Turn on compliance chasing
The Chase staff about compliance documents switch controls reminder automation. Choose a schedule preset:
- Recommended: reminders at 60, 30, 14 and 7 days before a document expires.
- Gentle: one reminder 30 days out, then weekly.
- Custom: pick your own first reminder and repeat interval.
Two optional digests are available: a Monday summary to each staff member with open items, and a Friday summary to managers for items open seven days or more. All three sections in Settings save together with the single Save changes button.
5 Let the Prepare audit wizard build your evidence
The Prepare audit tab generates audit evidence from your live records instead of you assembling it by hand. It can produce:
- Worker compliance register (CSV)
- Participant records register (CSV)
- Incident register (CSV)
- Policy and document register (CSV)
- Service delivery reconciliation (CSV)
- Audit readiness report (PDF)
Each generated file carries a SHA-256 hash so auditors can verify integrity. Regenerating a document supersedes the earlier unshared draft, so you always share the latest version.
6 Create an audit session
Create a session for the specific audit. Each session is a dedicated workspace for evidence, auditor access and audit communication.
Set the access window when you create it: auditor portal access opens at the start time, and access is automatically revoked at the end time. If you add an auditor before the window opens, their login details are emailed automatically the moment it does.
7 Organise and upload evidence
Group evidence into Evidence Groups such as Organisation, Operations, Workforce and Participants so auditors can navigate it easily.
Upload any additional files the session needs. Each file has two controls: Show this file to the auditor, and Allow auditor download. A file without download permission is view only in the portal.
8 Map evidence to the NDIS Practice Standards
The By Standard tab maps your evidence against the NDIS Practice Standards: the Core Module outcomes plus any supplementary modules that apply to your registration, such as High Intensity Daily Personal Activities or Specialist Behaviour Support.
Use Auto-map suggested evidence to link matching evidence automatically, then review coverage. The tab shows overall coverage, outcomes evidenced, and gaps to close, with quality indicators under each outcome.
Auditors see the same view in their portal, grouped by standard, which makes their review dramatically faster.
The standards content in BondiByte is a paraphrased working reference. Confirm authoritative requirements with the NDIS Quality and Safeguards Commission.
9 Share evidence and the evidence pack
Evidence moves through clear states: draft, shared with the auditor, or revoked. Use Share with auditor to release an item and Stop sharing to pull it back.
You can also download the full evidence pack: a ZIP of every shared file plus a manifest listing each item with its SHA-256 hash.
Auditors only ever see evidence you have shared. Drafts stay internal.
10 Invite auditors
Invite auditors with the secure Auditor Invite. Auditor access is separate from staff accounts and scoped to the session's shared evidence only.
You can require auditors to verify with a one-time email code before entering the portal, and PDF downloads can carry a watermark.
Use Preview portal to see exactly what the auditor will see before they do. Preview never sends anything.
11 Work through requests, samples and findings
Auditors can request more evidence from inside the portal. You are notified immediately, and you respond by sharing further evidence or replying in the Requests tab.
Samples give auditors a reproducible selection of records to review. Findings let auditors raise observations; you respond in the workspace and can attach corrective actions with owners and due dates.
12 Review access and close the audit
Review auditor activity in the Access Log, confirm access end dates, and revoke any access that is no longer needed.
Access expires automatically at the end of the window, and the auditor receives a reminder seven days before expiry. Closing the audit captures a snapshot of the session for your records.
13 Understand staff ratings
The Ratings tab gives managers a read-only view per staff member across cancellation, swaps, non-completion, shift notes, clock accuracy and documents, blended into an overall score from the metrics that apply.
In Settings, the Show staff ratings in mobile app switch is off by default. When you turn it on, each staff member sees only their own rating in the mobile app under My ratings: never a ranking, an average, or anyone else's numbers.
14 Know what happens if capacity runs out
Audit Centre automation, including the Prepare audit generators, evidence packs and closure snapshots, uses Automation Capacity. If your monthly capacity is exhausted, new processing pauses and the screen explains why.
Nothing is lost when this happens: existing audits, evidence, packs and history remain fully viewable, and paused work resumes when capacity is available or expanded.
The Audit Centre automation switch in Account Settings under Automation and Capacity Controls governs this whole area. Turning it off keeps everything viewable but stops new processing.
Understanding the Audit Centre
Readiness Score
A live score built from automatic checks over your operational records, broken down by domain, with plain-language fixes for every issue. Critical issues cap the score until resolved, and the cap is always shown with its reason.
Prepare Audit Wizard
A guided generator that builds audit evidence from live records: compliance and incident registers, a policy register, a service delivery reconciliation, and a readiness report. Every file carries a SHA-256 integrity hash.
Evidence Pack
A downloadable ZIP of every shared evidence file plus a manifest listing each item with its hash, so an auditor can verify nothing was altered.
Practice Standards Mapping
The By Standard view that links evidence to NDIS Practice Standards outcomes across the Core Module and any supplementary modules, showing coverage and gaps. A working reference, not an authoritative statement of requirements.
Enforce for compliance chasing
A per-document-type switch that makes the document count in readiness checks, appear on staff My Compliance checklists, and be chased by reminders. Off by default.
Enforce for rostering
A separate per-document-type switch that stops Smart Rostering assigning staff who are missing the document. Off by default, so nothing blocks shifts until you choose it.
Audit Session
A dedicated workspace used to organise and manage documents, evidence and auditor access for a specific audit, with a defined access window.
Access Window
The start and end times of auditor portal access. Login details are emailed when the window opens, and access is automatically revoked when it ends.
Evidence Group
A category used to organise audit evidence into logical sections (e.g. Organisation, Operations, Workforce, Participants), making documentation easier to review.
Auditor Invite
A secure invitation that provides auditors with limited, session-specific access to shared evidence. Separate from staff accounts, with optional one-time email code verification and watermarked PDF downloads.
Evidence Request
A request from an auditor asking for additional documentation during the audit. You are notified immediately and respond directly in the Audit Centre.
Sample
A reproducible selection of records (for example staff files or shifts) generated for an audit session so auditors can review a fair slice of your operations.
Finding
An auditor-raised observation or non-conformity on an audit session. You respond in the workspace and can attach corrective actions with owners and due dates.
Access Log
A record of auditor activity, showing when evidence has been viewed or accessed during the audit.
My Compliance
The staff portal and app screen where each staff member sees the documents they must hold, their right-to-work status, and what needs renewing, with self-service uploads.
Ratings
A manager-side, read-only view of per-staff reliability metrics. Staff only ever see their own rating in the mobile app, and only if the organisation turns that on.
Audit Centre automation
The master switch for audit processing: preparation runs, registers, evidence packs, snapshots and reminders. Off keeps everything viewable but stops new processing. Uses Automation Capacity when on.
Complaints Register
A simple register of complaints with acknowledgement and resolution tracking. Feeds the readiness checks and gives auditors the register they usually ask for.
Best practice
- Keep the readiness score green all year rather than fixing everything the month before an audit.
- Let the Prepare audit wizard generate registers instead of assembling spreadsheets by hand.
- Map evidence to the Practice Standards before the audit so gaps surface while there is still time to close them.
- Turn on rostering enforcement only for document types that truly must block a shift, and only once staff documents are up to date.
- Let staff clear their own compliance items from My Compliance instead of chasing them by email.
- Share only the evidence required for the specific audit, and use the evidence pack when an auditor wants files with verifiable integrity.
- Invite auditors using secure Auditor Invites rather than standard workspace accounts, and preview the portal before they arrive.
- Review auditor access regularly and let the access window expire it automatically.
Common mistakes to avoid
- Assuming organised evidence guarantees compliance or a successful audit outcome.
- Turning on Enforce for rostering across many document types at once and blocking shifts unexpectedly.
- Inviting auditors before your documentation has been reviewed and shared.
- Uploading documents without sharing them to the relevant audit session.
- Sharing broader workspace access instead of using scoped Auditor Invites.
- Disabling readiness checks to lift the score instead of fixing the underlying records.
What to do next
Related guides
Documents
Upload and manage documents linked to staff, clients, sites, or organisation areas: document types, expiry dates, renewal reminders, compliance checks, certificates and licences, and audit evidence readiness.
Automation and NotificationsEmail Notifications
Understand platform-managed email: sender profiles, your Reply-To settings, workflow notifications, email readiness, and troubleshooting checks.
Security, Roles, and AccessRoles and Access
Understand Owner, Admin, Manager, Staff, Staff Portal access, auditor access, and platform administration separation.
Need help applying this setup path?
Book a BondiByte demo and we can walk through the right setup order for your provider.