Your auditor has just handed you a report with a non-conformance on it, and your stomach has dropped. Registration suddenly feels like it’s hanging by a thread, and the clock is already ticking. Take a breath. What happens over the next few weeks is very much in your control, and it hinges almost entirely on one document: your Corrective Action Plan.
Here’s the good news most providers don’t realise in that first panicked moment. A non-conformance is not a rejection. It’s an invitation to fix something, and the NDIS system is built to give you the chance to do exactly that. Get the Corrective Action Plan right, and the finding closes quietly in the background. Get it wrong, and you’re staring down re-audits, blown deadlines, and in the worst cases, a threat to your registration.
This guide walks you through how to write a Corrective Action Plan that auditors actually accept the first time, why so many plans get bounced back, and what a strong one looks like in practice.
First, You Didn’t Actually “Fail”
Let’s clear up the language, because it matters more than you’d think.
The NDIS Quality and Safeguards Commission doesn’t hand out pass or fail grades the way a school exam does. There is no “fail” stamp. What your Approved Quality Auditor issues instead is a non-conformance (sometimes written “non-conformity”), the formal term for a gap between how you’re operating and what the NDIS Practice Standards require.
That distinction isn’t just semantics. It reframes the whole situation. You haven’t been kicked out of the game; you’ve been shown where your systems fall short of the standard, and you’ve been given a defined process and a defined window to bring them up to scratch. Providers who internalise this stop treating the finding as a catastrophe and start treating it as a project with a deadline. That mindset shift is the first step toward a plan that gets accepted.
Minor vs Major: Know Which One You’re Dealing With
Before you write a single word of your plan, you need to know exactly what kind of non-conformance you’ve received, because it changes your timeline, your workload, and frankly how worried you should be.
Minor Non-Conformance
A minor means there’s a genuine gap, but participants aren’t exposed to serious risk. Typically it looks like one of these:
- A policy that exists but isn’t backed up by the documentation or records to prove it’s actually happening
- A process that’s partly in place but hasn’t been reviewed in a long time
- Evidence that you’re doing the right thing some of the time, but not consistently across the board
Crucially, with a minor, your auditor can still recommend you for certification and registration. You submit your Corrective Action Plan, then you get an extended period to implement the fix properly, and the auditor verifies it at your next scheduled audit.
One trap catches providers off guard: an unresolved minor doesn’t just sit there harmlessly. If you don’t close it out within the allowed window, it can automatically escalate into a major, and once that happens, you can’t have it downgraded back.
Major Non-Conformance
A major is a different animal. It generally means one of three things:
- You can’t demonstrate that you have the processes, systems, or structures needed to meet a required outcome at all
- The gap presents a high risk to participant health, safety, or wellbeing
- You’ve accumulated three or more minor non-conformances within the same module
The consequence is significant: when you receive a major, your auditor cannot recommend you for registration until the issue is closed out entirely, or at least downgraded to a minor. A follow-up review, often called a close-out audit, is required to confirm you’ve genuinely fixed it. Leave a major unresolved past its window, and you’re risking the Commission moving to suspend or revoke your registration.
At a Glance
| Minor Non-Conformance | Major Non-Conformance | |
| What it signals | Documentation gap or partial/inconsistent process | Missing systems, high participant risk, or 3+ minors in one module |
| Can you still be recommended? | Yes, with an accepted plan | No, must be closed out or downgraded first |
| Verification | Checked at your next scheduled audit | Dedicated close-out review (desktop and/or on-site) |
| If left unresolved | Escalates to a major | Registration suspension or revocation |
A note on timeframes: Providers are generally asked to submit their Corrective Action Plan to the auditor within a short, defined window after receiving the finding, commonly cited as around seven calendar days. Resolution periods are typically up to 18 months for minor findings and around 3 months (90 days) for major ones. These figures come from the AQA guidelines and are widely applied, but the exact deadlines can vary slightly between auditors and by the nature of your finding. Always confirm your specific submission and resolution dates in writing with your own auditor the moment the finding is issued. Don’t assume, and don’t rely on an extension being granted; extensions are not automatic.
Why Corrective Action Plans Get Rejected

If you understand why plans fail, writing one that passes becomes much easier. Auditors reject Corrective Action Plans for a handful of predictable reasons, and nearly all of them come down to the same underlying problem: the plan tells the auditor what you say you’ll do, but gives them no confidence it will actually happen or stick.
The usual culprits:
- It’s generic. A plan that could be copied and pasted into any provider’s file is a red flag. Auditors read dozens of these; boilerplate language that doesn’t reference your specific finding, your organisation, and your circumstances signals that you haven’t really engaged with the problem.
- It treats the symptom, not the cause. “We updated the form” is not a corrective action plan. If you fix the immediate instance but leave the underlying system that produced it untouched, the same gap will reappear, and the auditor knows it.
- The actions are vague. “Improve staff training” gives the auditor nothing to verify. Compare that to “Deliver a two-hour incident management refresher to all support staff by 15 June, assessed by a written competency quiz.” One is a wish; the other is a commitment.
- There’s no evidence trail. If your plan doesn’t state exactly what documents or records you’ll produce to prove each action is done, the auditor has no way to close the finding.
- It stops at the fix and ignores sustainability. A plan that patches the problem but shows no mechanism for keeping it fixed once the auditor stops watching invites doubt about whether the improvement will last.
Keep these in mind as failure modes to design against. Every section below is aimed at avoiding one of them.
The Anatomy of a Corrective Action Plan That Gets Accepted
At its core, a strong Corrective Action Plan answers four questions clearly and specifically:
- The correction — How will you fix the immediate issue the auditor found?
- The root cause — Why did this happen in the first place?
- The corrective (and preventive) action — What will you change so it can’t happen again?
- Responsibilities and timeframes — Who is doing what, and by when?
To turn those four questions into a document an auditor can act on, structure your plan around the following sections.
1. Non-Conformance Reference
Start by linking your plan directly to the finding. Quote the audit finding number, the specific Practice Standard outcome it relates to, and its classification (minor or major). This tells the auditor immediately that your plan maps to their report.
2. Description of the Finding
Restate the auditor’s finding in your own words, and openly acknowledge the gap. Don’t be defensive or minimise it. Showing that you understand precisely what was found and why it matters sets the tone for everything that follows.
3. Root Cause Analysis
This is the section that separates accepted plans from rejected ones, so give it real attention. The goal is to dig past the surface symptom to the systemic reason the gap existed. (More on how to do this in the next section.)
4. Immediate Corrective Actions
Spell out the specific actions that fix the exact problem the auditor identified. Each one needs a responsible person and a target completion date. This is where you close the immediate gap.
5. Preventive Actions
Now go beyond the immediate fix. What systemic change will stop this type of problem from recurring? Preventive actions are what convince an auditor you’re making a lasting improvement rather than applying a quick patch. Again, assign an owner and a date to each.
6. Evidence of Completion
For every action, list the specific document or record you’ll produce as proof: the updated policy with version control, the training attendance sheet, the completed register, the meeting minutes. This gives the auditor exactly what they need to verify closure.
7. Monitoring and Review
Finish by describing how you’ll keep the improvement alive over time: the recurring review, the register check, the standing agenda item. This demonstrates sustainability, which is the quality auditors most want to see, and the one providers most often forget.
Make every action SMART. Before you commit an action to the plan, test it against five criteria: is it Specific, Measurable, Achievable, Relevant to the root cause, and Time-bound? “Review our documentation” fails almost all five. “Compliance Manager to revise the incident procedure to version 2.0, adding a mandatory root-cause field, by 30 April, evidenced by the updated document with tracked changes” passes all of them and reads like something an auditor can sign off.
Root Cause Analysis: The Part You Can’t Skip
Auditors can tell within seconds when a provider has only addressed a symptom. Writing “we replaced the form” when the real issue is that no one is responsible for keeping forms current will not close a finding. To get to the actual cause, use a structured technique rather than guessing.
The 5 Whys
The simplest and most widely used method. You start with the non-conformance and keep asking “why” until you reach the fundamental cause, usually within about five iterations.
Say your finding is: three of ten support workers don’t have a current NDIS Worker Screening Check on file.
- Why? The checks weren’t obtained before those staff started delivering supports.
- Why? The recruitment process doesn’t include a mandatory screening-verification step before a first shift.
- Why? The recruitment procedure hasn’t been updated since before screening became mandatory in our state.
- Why? There’s no process for reviewing procedures when regulatory requirements change.
- Why? Our document control only schedules time-based annual reviews, with no trigger for regulatory changes.
Root cause: the document-control system lacks any mechanism to review and update procedures when regulations change, so obligations get missed. Notice how different (and how much more fixable) that is from “staff forgot.”
The Fishbone (Ishikawa) Approach
When a finding has several tangled causes, the 5 Whys can be too linear. A fishbone diagram sorts potential causes into categories so you can see the whole picture. For NDIS compliance, useful categories include:
- People — knowledge gaps, turnover, unclear accountability
- Process — missing steps, unclear workflows, inadequate checklists
- Policy — outdated or incomplete documents, poor communication
- Management — insufficient oversight, no monitoring, unclear ownership
- Resources — time pressure, technology gaps, funding constraints
Under each heading, list the specific factors that contributed to your finding. This works especially well for systemic problems that touch several areas at once, such as a failing incident-management system.
Which One Should You Use?
| Your situation | Best technique |
| A single, clear cause | 5 Whys — fast and direct |
| Several contributing factors | Fishbone — captures the complexity |
| A recurring finding | Both — 5 Whys for depth, fishbone for breadth |
| A systemic failure across multiple areas | Fishbone — surfaces cross-cutting themes |
The Evidence Rule: Prove It, Don’t Promise It
A Corrective Action Plan states what you will do. What closes the finding is proof that you did it. Your plan must name the evidence you’ll produce for each action, and the auditor will check it before signing anything off.
Evidence auditors accept includes:
- Updated documents — revised policies, procedures, and forms with clear version control showing the date of change
- Training records — attendance sheets, training materials, competency-assessment results, signed acknowledgements
- Operational records — completed incident reports, supervision notes, participant feedback
- Meeting minutes — records of team or management meetings where the corrective actions were discussed
- Registers — updated entries in your worker-screening, training, or continuous-improvement registers
- System screenshots — for electronic systems, images showing the updated process or completed task
Evidence must be genuine and contemporaneous. It has to be created at the time the action was actually taken, not backdated to look good. Auditors are experienced at spotting documents that were fabricated after the fact, mismatched version histories, records that all appear on the same day, and training “delivered” the week before the deadline. Falsifying evidence isn’t a shortcut; it’s an integrity breach that can turn a manageable non-conformance into a refusal of registration. Do the work, then document the work.
A Worked Example: Incomplete Training Records
To pull it all together, here’s how a plan might read for a common minor finding.
The finding — NC-03 (Minor). NDIS Practice Standards, Human Resource Management outcome. Of ten staff files reviewed, four contained no evidence of training in the organisation’s incident-management procedure. The training register does not track individual completion.
Root cause (5 Whys). Training was delivered verbally in team meetings but never formally recorded → because there was no standard record template → because the training procedure doesn’t specify how training must be documented → because the HR policy states what training is required but not how it’s evidenced. Root cause: the HR policy and training procedure set no documentation standard, and no template exists to capture attendance and competency.
The action table.
| Action | Type | Responsible | Due | Evidence |
| Deliver an incident-management refresher to all support staff, with a written competency quiz | Corrective | Team Leader | 30 April | Attendance list, completed quizzes, training materials |
| Complete the missing training records for the four identified staff | Corrective | HR Officer | 30 April | Updated staff files |
| Create a standard training-record template (date, topic, trainer, attendees, competency outcome, signatures) | Preventive | HR Officer | 15 April | Completed template with version control |
| Update the HR policy to specify training-documentation requirements | Preventive | Compliance Manager | 30 April | Updated policy (v2.0) with tracked changes |
| Introduce a centralised training register tracking each staff member individually | Preventive | HR Officer | 15 April | Populated register |
| Add a quarterly training-compliance check to the management meeting agenda | Monitoring | Director | Ongoing (first review May) | Meeting minutes |
Notice what this plan does: it fixes the four specific files (correction), rebuilds the system that let them slip (prevention), names a real person and date for every line, states the exact evidence, and builds in an ongoing check so the fix doesn’t quietly lapse. That is what “accepted the first time” looks like.
Give the Auditor Every Reason to Say Yes
One last piece of practical advice that costs nothing and saves enormous stress: talk to your auditor early. Auditors are not trying to trip you up most are happy to give feedback on your proposed approach before you invest weeks implementing it. A quick check that your plan is heading in the right direction is far cheaper than discovering at verification that you built the wrong fix. If anything in the finding is unclear, ask. A plan written against a misunderstanding of the finding is a plan destined for rejection.
The Best Corrective Action Plan Is the One You Never Have to Write
Everything above will help you recover from a non-conformance. But the providers who sail through audits aren’t the ones with flawless recovery plans; they’re the ones who rarely trigger findings in the first place, because they treat compliance as ongoing work rather than a scramble before the auditor arrives.
That means running your own gap analysis against the Practice Standards before your audit, conducting internal audits the way an external auditor would, making sure your documentation genuinely reflects how your team operates instead of what an off-the-shelf template claims, and keeping your evidence organised so proof of compliance is easy to find. Do that consistently, and the non-conformance you’re writing a plan for today becomes the last one you have to deal with.
Need a Hand Getting It Right?
Writing a Corrective Action Plan that closes a finding the first time is a skill, and when your registration is on the line, it’s not the moment to guess. At Angels Compliance and Training Services, we help NDIS providers respond to non-conformances, build audit-ready compliance systems, and train their teams so the gaps don’t reappear. Whether you’re recovering from an audit finding, preparing for your first certification, navigating registration, or looking to buy or sell an NDIS business, our team can help you move forward with confidence.
Get in touch with Angels Compliance and Training Services to turn your audit finding into a closed chapter.
This article provides general guidance about NDIS compliance and is not legal or professional advice. NDIS Commission requirements, timeframes, and Practice Standards can change, and specific deadlines may vary between auditors. Always confirm current requirements and your own audit timeframes directly with your Approved Quality Auditor or the NDIS Quality and Safeguards Commission before making compliance decisions.
