top of page

NDIS Risk Management Plan Template: A Practical Guide for Providers

  • Writer: Joanne Devine
    Joanne Devine
  • Jul 8
  • 10 min read

Information current as at 8 July 2026


Risk management is not simply a document completed before an audit. It is an ongoing process of identifying potential harm, assessing its likelihood and consequences, selecting proportionate controls, assigning responsibility and checking whether those controls remain effective.


A structured NDIS risk management plan template can help providers organise this information consistently. However, a template cannot identify every risk, guarantee compliance or replace professional judgement. It must be reviewed and adapted to suit the provider’s services, participants, workers, environment and current obligations.


This guide explains the difference between organisational and participant-specific risk management, what a risk plan should record, how participants should be involved and when a plan needs to be reviewed.


What Risk Management Means in an NDIS Setting


Risk management should support safe, competent and person-centred service delivery.


The NDIS Code of Conduct applies to registered and unregistered NDIS providers, their key personnel and workers. It requires them to respect participants’ rights to self-determination and decision-making, provide supports safely and competently, and act promptly on concerns that may affect the quality or safety of supports.


For registered providers assessed against the NDIS Practice Standards’ core module, the risk-management system should be documented and proportionate to the provider’s size, scale and the complexity of the supports delivered. It should address risks relating to participants, workers, the organisation and the provision of supports.


Risk management is therefore broader than completing a risk matrix. It may involve:


  • policies and procedures

  • participant support plans

  • individual risk assessments

  • organisational risk registers

  • incident and complaint records

  • emergency and continuity planning

  • worker training and supervision

  • treatment plans and corrective actions

  • monitoring and review records


The relevant documents should connect with each other and reflect what the provider actually does.


NDIS risk management plan infographic showing risk identification, assessment, controls, responsibilities, monitoring and participant-centred review.
NDIS risk management plan infographic showing risk identification, assessment, controls, responsibilities, monitoring and participant-centred review.

Organisational Risk Management and Participant Risk Assessments


These areas are related, but they are not the same.


Organisational risk management


Organisational risk management considers risks that may affect participants, workers or the provider as a whole.


For providers assessed against the core module, this may include risks associated with:


  • incident management

  • complaints management

  • financial management

  • governance

  • human resources

  • information and privacy

  • work health and safety

  • emergencies and disasters

  • infection prevention, where relevant

  • the delivery and continuity of supports


These risks may be recorded in an organisational risk register, governance report, work health and safety system or business continuity plan.


Participant-specific risk assessment


Participant risk assessments focus on risks relevant to an individual participant’s supports, needs, goals, health, environment and circumstances.


The Practice Standards state that, in collaboration with each participant, risk assessments should be undertaken regularly and documented in the participant’s support plan. Strategies should be planned and implemented to address known risks, and their effectiveness should be periodically reviewed.


Participant-specific risks might relate to:


  • mobility and falls

  • communication

  • medication support

  • eating, drinking or swallowing

  • health deterioration

  • community access

  • transport

  • environmental hazards

  • service interruptions

  • personal care

  • behaviours that may create a risk of harm

  • emergency support arrangements


A provider may need both an organisational risk-management system and individual participant risk assessments.


Balance Safety With Participant Choice


Risk management should not automatically remove every activity that carries some risk.


Participants have rights to informed choice, control, independence and dignity of risk. When needed, they should be supported to understand the potential benefits and risks of available options and given sufficient time to consider those options.


A person-centred approach may involve:


  • explaining risks in an accessible way

  • asking the participant what matters to them

  • identifying the benefits of the chosen activity

  • discussing safer ways to support the choice

  • offering reasonable alternatives

  • recording the participant’s views and preferences

  • involving an advocate or support person where requested

  • reviewing controls with the participant


A participant’s informed choice should not be described as “non-compliance” simply because it differs from the provider’s preferred option.


Risk documentation should distinguish between:


  1. a known hazard or potential harm

  2. the participant’s informed choice

  3. controls agreed with the participant

  4. risks that require urgent or mandatory action


Access to required supports should not be withdrawn solely because a participant has made a dignity-of-risk choice.


What Should an NDIS Risk Management Plan Record?


The exact format will depend on the type of risk and the provider’s systems. A clear risk record commonly includes the following information.


1. Risk description


Describe the risk clearly and specifically.


Avoid:

Risk of injury.

Prefer:

Risk of the participant falling when moving across the uneven threshold between the kitchen and outdoor area.

A reader should be able to understand what could happen and the circumstances in which it may occur.


2. Who may be affected


Record whether the risk may affect:


  • the participant

  • another participant

  • workers

  • visitors

  • members of the public

  • the provider or organisation


3. Existing controls


Record what is already in place to reduce the risk.


Examples might include:


  • worker assistance

  • environmental modifications

  • visual instructions

  • mobility equipment

  • communication supports

  • staff training

  • supervision arrangements

  • emergency contacts

  • documented health or support instructions


4. Likelihood and consequence


A risk matrix may be used to assess:


  • how likely the event is to occur

  • how serious the potential consequence could be

  • the resulting risk rating


The provider should use its approved rating method consistently. A risk rating supports prioritisation but does not replace participant input, clinical advice, workplace-safety duties or professional judgement.


5. Further treatment actions


Where existing controls are insufficient, record additional actions.


Each action should explain:


  • what will be done

  • who is responsible

  • the due date

  • resources or approval required

  • how completion will be confirmed


6. Residual risk


Residual risk is the level of risk expected to remain after controls are implemented.


It should not automatically be described as “acceptable” without explaining:


  • who made that decision

  • what evidence was considered

  • whether the participant was involved

  • what monitoring will continue

  • when the decision will be reviewed


7. Monitoring arrangements


Explain how the provider will know whether the controls are working.


Monitoring might include:


  • worker observations

  • participant feedback

  • supervision discussions

  • incident and near-miss data

  • health-professional advice

  • equipment checks

  • file reviews

  • internal audits


8. Review triggers


Do not rely only on a calendar date.


The plan may need an earlier review when:


  • the participant’s needs or circumstances change

  • a participant changes their goals or preferences

  • an incident or near miss occurs

  • a control is ineffective

  • new information becomes available

  • workers report inconsistent instructions

  • equipment or the environment changes

  • a new service or support arrangement begins

  • there is a disruption to critical supports

  • the participant requests a review


Participant support plans are expected to be reviewed annually or earlier when needs or circumstances change. The frequency of progress and risk reviews should also be proportionate to the risk, the participant’s functioning and the participant’s wishes.


NDIS risk management plan displayed beside a laptop, showing risk identification, controls, responsibilities, monitoring and participant-centred review.
NDIS risk management plan displayed beside a laptop, showing risk identification, controls, responsibilities, monitoring and participant-centred review.

How to Use an NDIS Risk Management Plan Template


Step 1: Define the purpose and scope


Before completing the template, identify what it is intended to assess.


For example:


  • one participant

  • one activity

  • one environment

  • one type of support

  • a broader organisational process


Avoid combining unrelated risks into one vague assessment.


Step 2: Involve the right people


Depending on the situation, this may include:


  • the participant

  • the participant’s nominee or advocate

  • workers who provide the support

  • supervisors or managers

  • allied health professionals

  • health practitioners

  • other providers

  • family or informal supports, with consent


The participant should be actively involved wherever possible, and information should be communicated using language and methods they are most likely to understand.


Step 3: Identify the risk and its context


Ask:


  • What could happen?

  • When and where could it happen?

  • Who could be affected?

  • What may contribute to the risk?

  • What could make it more or less likely?

  • What is already working well?


Avoid writing only the name of a condition, diagnosis or behaviour. The assessment should describe the actual risk.


For example, instead of:

Epilepsy risk.

Use:

Risk of injury or delayed medical assistance if the participant experiences a seizure while accessing the community.

Step 4: Assess the existing risk


Consider the risk with current controls already in place.


Record the evidence used, such as:


  • past incidents

  • participant feedback

  • worker observations

  • professional assessments

  • environmental checks

  • equipment instructions

  • health or support plans


Where evidence is limited, say so rather than presenting an assumption as a confirmed fact.


Step 5: Select proportionate controls


Controls should respond to the actual risk without unnecessarily limiting the participant.


Possible controls may include:


  • removing or reducing a hazard

  • changing the environment

  • using equipment

  • providing accessible information

  • adjusting staffing or supervision

  • establishing clear worker instructions

  • obtaining professional advice

  • creating emergency arrangements

  • providing training

  • increasing monitoring temporarily

  • agreeing on a safer alternative with the participant


Use the least intrusive approach that can reasonably address the risk.


Step 6: Assign responsibility


Every action should have a named person or role responsible for completing it.


Avoid:

Staff to monitor.

Prefer:

The service coordinator will review weekly progress notes for reports of dizziness for four weeks and discuss the outcome with the participant by 30 July 2026.

Step 7: Communicate the plan


The plan should be available to the participant and the workers who need it.


For registered providers assessed against the core module, participant support plans should be accessible to the participant and relevant workers and communicated to other people or providers where appropriate and with consent.


Communication may include:


  • Easy Read information

  • translated information

  • visual instructions

  • verbal explanation

  • worker handover

  • induction or refresher training

  • participant confirmation

  • acknowledgement that workers have read the plan


Step 8: Monitor and review


A completed form is not the end of the process.


Check:


  • whether agreed actions were completed

  • whether controls are being followed

  • whether they are reducing the risk

  • whether they create new risks or restrictions

  • whether the participant remains satisfied with the approach

  • whether circumstances have changed


Update the plan when required and retain appropriate version-control records.


Worked Example: Community Shopping


The following example is fictional.


Risk identified

The participant may become overwhelmed in crowded shopping environments, leave the worker unexpectedly and become separated from their support.

Participant’s views

The participant wishes to continue shopping in person because choosing products independently is important to them. They prefer morning visits when the centre is quieter.

Existing controls


  • Written shopping list

  • Participant carries a mobile phone

  • Worker remains within an agreed distance

  • Quiet shopping times are selected where possible


Further actions


  • Agree on a meeting point before entering the centre

  • Confirm how the participant will signal that they need a break

  • Record an emergency contact

  • Trial a smaller shopping centre

  • Review after four outings or earlier if an incident occurs


Monitoring

The worker will record whether breaks were requested, whether the agreed meeting arrangements were used and any feedback provided by the participant.

This example records the participant’s goal, the actual risk, agreed controls and review arrangements. It does not simply prohibit the activity.


Risk Records and Incident Management


A risk assessment does not replace an incident report.


An NDIS incident includes an act, omission, event or circumstance that has caused or could have caused harm to a person with disability. Incidents connected with delivering NDIS supports should be identified, assessed, recorded, managed and resolved while the participant is kept safe, respected and informed.


When an incident or near miss occurs:


  1. address immediate safety and wellbeing

  2. follow the provider’s incident-management procedure

  3. complete required internal records

  4. determine whether escalation or external notification is required

  5. review the relevant risks and controls

  6. record corrective actions

  7. check whether other participants or services may be affected


Registered providers must also notify the NDIS Commission when an incident meets the reportable-incident requirements.


Updating the risk plan may be one action arising from the incident, but it should not replace the separate incident-management process.


NDIS risk management workspace showing a risk assessment matrix, control checklist, review dashboard and person-centred monitoring tools.
NDIS risk management workspace showing a risk assessment matrix, control checklist, review dashboard and person-centred monitoring tools.

Common Risk-Management Mistakes


Using vague descriptions

Participant is a falls risk.

This does not explain where, when or why the risk arises.


Treating a diagnosis as the risk

A diagnosis may inform an assessment, but it does not describe the potential event, consequence or required controls.


Completing the assessment without the participant

Participant views, preferences, strengths and desired outcomes should be included wherever possible.


Copying the same assessment for different participants

Similar risks may require different controls depending on the participant, environment and support arrangements.


Assuming a high-risk rating means the activity must stop

The rating should lead to further discussion, controls and informed decision-making. It should not automatically remove choice.


Recording controls that are not implemented

A plan has limited value if workers are unaware of it, have not been trained or do not have access to required equipment.


Writing “monitor” without explaining how

Monitoring should identify what will be observed, who is responsible, how often it will occur and what will trigger further action.


Waiting for the scheduled review date

Review earlier when circumstances change or there is evidence that controls are not working.


How an NDIS Risk Management Plan Template Can Help


An NDIS risk management plan template may help providers:


  • use a consistent structure

  • prompt staff to record key information

  • assign actions and responsibilities

  • track review dates

  • connect risks with treatment actions

  • record participant involvement

  • improve communication between authorised workers

  • identify incomplete or overdue actions


However, the quality of the record depends on the information entered and the actions taken afterward.


A template cannot:


  • guarantee compliance

  • replace clinical or professional assessment

  • decide what level of risk is acceptable

  • remove the need for participant consultation

  • replace an incident report

  • identify every relevant legal obligation

  • make an ineffective control suitable


Related WorkSmart Templates Resources


The NDIS Risk Management Matrix and Treatment Plan Template provides an editable structure for documenting risks, likelihood, consequences, controls, treatment actions, responsible staff, monitoring and review dates. It is designed as an administrative starting point and should be customised to suit the provider’s circumstances.


The NDIS Risk Management and Support Plan Template provides a broader structure for participant risks, support needs, safeguards, monitoring and review arrangements. It should also be reviewed against the participant’s individual circumstances and the provider’s current obligations.


Final Risk-Management Checklist


Before approving a risk plan, check that:


  • the risk is described specifically

  • the participant was involved where possible

  • the participant’s goals and preferences are recorded

  • dignity of risk has been considered

  • existing controls are documented

  • the rating method has been applied consistently

  • further actions have responsible people and due dates

  • monitoring arrangements are clear

  • workers can access and understand the plan

  • privacy and consent requirements have been addressed

  • incident and escalation processes are separate and clear

  • review dates and early-review triggers are recorded

  • superseded versions are appropriately managed


Final Thoughts


Effective NDIS risk management is not about eliminating every uncertainty from a participant’s life.


It is about identifying potential harm, supporting informed choice, implementing proportionate controls and checking whether those controls continue to work.


A well-structured risk-management template can make documentation more consistent and easier to review. The value comes from the conversations, decisions, actions and monitoring that sit behind the document.


The most useful final question is:

Does this plan support safety while still respecting the participant’s rights, choices and independence?

Disclaimer


This article provides general administrative and operational information only. It does not constitute legal, regulatory, clinical, work health and safety, audit or professional advice.


Providers should review current NDIS Commission requirements, applicable legislation, registration conditions, participant support needs and professional advice before developing or changing risk-management systems. Templates should be reviewed and customised to suit the provider’s services, participants, workers, environment and current obligations.


bottom of page