An NDIS risk assessment template is a structured form for recording a risk, who it affects, how likely and how serious it is, the controls that reduce it, who owns those controls and when it will be reviewed. Providers need two versions: one for organisational risk, and one for each participant's support plan.
Most templates circulating online are generic workplace safety forms with the word NDIS added to the header. They fail audit for the same reason every time: they capture hazards but not the specific things the NDIS Practice Standards ask you to demonstrate.
What do the NDIS Practice Standards require for risk management?
Two separate requirements sit in the Core Module, and they are often confused.
The first is organisational. Under Provider Governance and Operational Management, the Risk Management outcome is: "Risks to participants, workers and the provider are identified and managed." Risks must be "identified, analysed, prioritised and treated", and your documented risk management system must be proportionate to your size and scale and to the complexity of the supports you deliver. It has to cover eight named areas, per the NDIS Practice Standards and Quality Indicators:
- incident management
- complaints management and resolution
- financial management
- governance and operational management
- human resource management
- information management
- work health and safety
- emergency and disaster management
Where relevant it must also cover infection prevention and control, and you must hold appropriate insurance including professional indemnity, public liability and accident cover.
The second requirement is participant level, under Support Planning in the Provision of Supports module. In collaboration with each participant, "risk assessments are regularly undertaken, and documented in their support plans", with strategies planned and implemented to treat known risks. Those assessments must consider how much the participant relies on your services for their daily living needs, and how their health and safety would be affected if those services were disrupted.
That last clause is the one small providers most often miss. A solo psychologist seeing a participant fortnightly has a different service-disruption profile to a daily support provider, and the assessment is supposed to say so.
What should an NDIS risk assessment template include?
A template that satisfies both requirements needs these fields. Build it once, use it for organisational and participant risks with a different first column.
- Risk ID and date raised. Sequential numbering so risks can be referenced in incident reports and reviews.
- Risk description. What could happen, in plain language, phrased as an event rather than a topic. "Participant experiences a mental health crisis between scheduled sessions" beats "mental health".
- Who is affected. Participant, worker, other participants, the public, the organisation.
- Existing controls. What is already in place before you rate anything.
- Likelihood and consequence ratings, with a combined risk level, and a residual rating once treatments are in place.
- Additional treatments. The specific actions that will reduce likelihood or consequence.
- Responsible person, a named role rather than "the team", with a target date and review date.
- Participant consultation record for participant-level risks: who was involved, what the participant said, and what they chose.
- Link to related documents. Support plan, behaviour support plan, incident records, emergency plan.
The last two fields are what turn a compliance artefact into something auditors and clinicians can follow.
How do you rate risk with a risk matrix?
A risk matrix multiplies likelihood by consequence to produce a priority. Most providers use a five-by-five grid, though three-by-three is defensible for a small practice as long as you define the terms.
Define each level in words specific to disability supports. Likelihood might run from "almost certain: expected weekly" to "rare: has not occurred in this service". Consequence might run from "negligible: no injury, no service impact" to "catastrophic: death, serious injury, or complete loss of a support the participant depends on daily". Write those definitions into the template: two staff rating the same risk should land in the same cell, and that only happens when the scale is on the page rather than in someone's head.
What does a completed participant risk assessment look like?
The following is an illustrative example for a fictional participant, not a real case.
Risk ID: P-014. Raised: 3 March 2026.
Risk: Participant (psychosocial disability, lives alone, attends weekly therapy) disengages from support after a hospital admission and loses their tenancy.
Existing controls: Weekly sessions with reminder messages; support coordinator holds the housing relationship; participant has consented to contact with their nominated support person.
Likelihood: Possible. Consequence: Major. Risk level: High.
Additional treatments: Documented re-engagement pathway if two consecutive sessions are missed (phone, then written contact, then contact with the nominated support person with consent); warm handover protocol on hospital discharge; tenancy contact details recorded in the support plan.
Responsible person: Lead clinician, with the support coordinator for housing actions. Review date: 3 June 2026, or earlier if an admission occurs. Residual risk: Medium.
Participant consultation: Discussed at the 3 March session. Participant agreed to the contact sequence, declined contact with their sibling, and nominated their support coordinator instead.
What makes this auditable: the participant's own choices are on the record, the review trigger is an event and not just a date, and every treatment names someone.
How does dignity of risk change what you write?
Dignity of risk is the participant's right to choose to take some risk in engaging in life. It is not a reason to leave a risk unassessed. The Practice Standards state that access to supports required by a participant will not be withdrawn or denied solely on the basis of a dignity of risk choice they have made.
Practically, your template records the choice rather than overrides it. Where a participant makes a decision you have assessed as risky, document the conversation, the information you gave them, the alternatives offered, the decision they made, and the controls you both agreed to. That record is what turns a risky choice into a supported decision.
How often should an NDIS risk assessment be reviewed?
The standards require periodic reviews of the effectiveness of risk management strategies with each participant, so that risks are being adequately addressed and changes are made when required. Support plans must be reviewed annually or earlier, in collaboration with the participant, as their needs or circumstances change.
Annual is the floor, not the target. Set review triggers as well as dates: after any incident, after a hospital admission or significant change in health, when a support is added or withdrawn, and when a plan is reassessed. A template with a "review triggered by" field gets reviewed. One with only a date gets reviewed once a year, in a hurry, the week before an audit.
How does risk assessment connect to incident reporting?
Risk management and incident management are the same system viewed from opposite ends of an event, which is why the standards list incident management as one of the eight areas your risk system must cover.
For registered providers, a reportable incident must be notified to the NDIS Commission within 24 hours of key personnel becoming aware of it, with a five business day window applying to the use of a restrictive practice that is unauthorised or not in accordance with a behaviour support plan. Records of reportable incidents must be kept for seven years from the date of notification. See the Commission's reportable incidents guidance for current forms and definitions.
Wire the two together: every incident should ask whether an existing risk assessment predicted it, and every risk review should read the incidents logged since the last one. That loop is what an auditor is looking for when they ask how you know your controls work.
Requirements are also moving. Supported independent living providers must be registered and follow new SIL Practice Standards from 1 July 2026. If that is your service type, check your risk documentation against the new standards rather than the version you were last audited on.
How do you build the template in Word?
Word remains the practical choice for a first version. Set the page to A4 landscape so the rating and treatment columns fit, and build the register as a single table, one row per risk, with the fields above as columns. Put the likelihood and consequence definitions on page one, use Word's dropdown content controls (Developer tab, then Drop-Down List Content Control) for the rating fields so people select rather than type, and add a version number to the header.
The honest limitation: a Word register is a snapshot. It does not remind anyone that a review is due, it does not link a risk to the participant's notes, and the copy on someone's desktop is rarely the current one. Once you have more than a handful of participants, the register belongs in the same system as your clinical documentation, where review dates surface as tasks and a risk sits alongside the notes that evidence it. PractaLuma is AI-native practice management software for Australian mental-health practices, and keeping risk, support plans and clinical notes in one record is the point of doing it there. Plans are on the pricing section of our homepage.
What are the most common mistakes?
- Rating the risk without listing existing controls, which inflates every score and hides what is actually protecting the participant.
- Copying a generic workplace safety register that covers slips and trips but never touches service disruption, disengagement, medication, restrictive practices or safeguarding.
- Treatments with no owner, written in the passive voice: "will be monitored".
- No participant voice, which fails the collaboration requirement in Support Planning regardless of how good the clinical reasoning is.
- A register that never changes, which tells an auditor it is not being used.
Frequently asked questions
Do unregistered NDIS providers need a risk assessment template? The Practice Standards apply to registered providers, and audits test them. Unregistered providers still hold duties under the NDIS Code of Conduct, work health and safety law and their professional obligations, so a documented risk process remains the sensible baseline.
Is one register enough, or do I need one per participant? Both. Keep a single organisational register covering the eight areas named in the standards, plus a participant-level assessment in each support plan. They use the same fields and feed each other.
Where do risk assessments have to be stored? Participant risk assessments belong in the support plan, which sits with the participant's records, and your clinical documentation should reference them so the connection is visible. See our guides to the NDIS support plan template, writing NDIS goals and progress notes for how those documents fit together.
How long do I keep risk and incident records? Records of reportable incidents must be kept for seven years from the date of notification to the NDIS Commission. State and territory health records law may impose its own retention periods on clinical records, so check the rules for your jurisdiction and apply the longer one.
Should the participant see their own risk assessment? Yes. It is developed in collaboration with them and documented in their support plan, so it should not contain anything they have not been told.
