NDIS Risk Management Plan Template: A Practical Guide for Providers
- Joanne Devine

- Jul 8
- 10 min read
Information current as at 8 July 2026
Risk management is not simply a document completed before an audit. It is an ongoing process of identifying potential harm, assessing its likelihood and consequences, selecting proportionate controls, assigning responsibility and checking whether those controls remain effective.
A structured NDIS risk management plan template can help providers organise this information consistently. However, a template cannot identify every risk, guarantee compliance or replace professional judgement. It must be reviewed and adapted to suit the provider’s services, participants, workers, environment and current obligations.
This guide explains the difference between organisational and participant-specific risk management, what a risk plan should record, how participants should be involved and when a plan needs to be reviewed.
What Risk Management Means in an NDIS Setting
Risk management should support safe, competent and person-centred service delivery.
The NDIS Code of Conduct applies to registered and unregistered NDIS providers, their key personnel and workers. It requires them to respect participants’ rights to self-determination and decision-making, provide supports safely and competently, and act promptly on concerns that may affect the quality or safety of supports.
For registered providers assessed against the NDIS Practice Standards’ core module, the risk-management system should be documented and proportionate to the provider’s size, scale and the complexity of the supports delivered. It should address risks relating to participants, workers, the organisation and the provision of supports.
Risk management is therefore broader than completing a risk matrix. It may involve:
policies and procedures
participant support plans
individual risk assessments
organisational risk registers
incident and complaint records
emergency and continuity planning
worker training and supervision
treatment plans and corrective actions
monitoring and review records
The relevant documents should connect with each other and reflect what the provider actually does.
Organisational Risk Management and Participant Risk Assessments
These areas are related, but they are not the same.
Organisational risk management
Organisational risk management considers risks that may affect participants, workers or the provider as a whole.
For providers assessed against the core module, this may include risks associated with:
incident management
complaints management
financial management
governance
human resources
information and privacy
work health and safety
emergencies and disasters
infection prevention, where relevant
the delivery and continuity of supports
These risks may be recorded in an organisational risk register, governance report, work health and safety system or business continuity plan.
Participant-specific risk assessment
Participant risk assessments focus on risks relevant to an individual participant’s supports, needs, goals, health, environment and circumstances.
The Practice Standards state that, in collaboration with each participant, risk assessments should be undertaken regularly and documented in the participant’s support plan. Strategies should be planned and implemented to address known risks, and their effectiveness should be periodically reviewed.
Participant-specific risks might relate to:
mobility and falls
communication
medication support
eating, drinking or swallowing
health deterioration
community access
transport
environmental hazards
service interruptions
personal care
behaviours that may create a risk of harm
emergency support arrangements
A provider may need both an organisational risk-management system and individual participant risk assessments.
Balance Safety With Participant Choice
Risk management should not automatically remove every activity that carries some risk.
Participants have rights to informed choice, control, independence and dignity of risk. When needed, they should be supported to understand the potential benefits and risks of available options and given sufficient time to consider those options.
A person-centred approach may involve:
explaining risks in an accessible way
asking the participant what matters to them
identifying the benefits of the chosen activity
discussing safer ways to support the choice
offering reasonable alternatives
recording the participant’s views and preferences
involving an advocate or support person where requested
reviewing controls with the participant
A participant’s informed choice should not be described as “non-compliance” simply because it differs from the provider’s preferred option.
Risk documentation should distinguish between:
a known hazard or potential harm
the participant’s informed choice
controls agreed with the participant
risks that require urgent or mandatory action
Access to required supports should not be withdrawn solely because a participant has made a dignity-of-risk choice.
What Should an NDIS Risk Management Plan Record?
The exact format will depend on the type of risk and the provider’s systems. A clear risk record commonly includes the following information.
1. Risk description
Describe the risk clearly and specifically.
Avoid:
Risk of injury.
Prefer:
Risk of the participant falling when moving across the uneven threshold between the kitchen and outdoor area.
A reader should be able to understand what could happen and the circumstances in which it may occur.
2. Who may be affected
Record whether the risk may affect:
the participant
another participant
workers
visitors
members of the public
the provider or organisation
3. Existing controls
Record what is already in place to reduce the risk.
Examples might include:
worker assistance
environmental modifications
visual instructions
mobility equipment
communication supports
staff training
supervision arrangements
emergency contacts
documented health or support instructions
4. Likelihood and consequence
A risk matrix may be used to assess:
how likely the event is to occur
how serious the potential consequence could be
the resulting risk rating
The provider should use its approved rating method consistently. A risk rating supports prioritisation but does not replace participant input, clinical advice, workplace-safety duties or professional judgement.
5. Further treatment actions
Where existing controls are insufficient, record additional actions.
Each action should explain:
what will be done
who is responsible
the due date
resources or approval required
how completion will be confirmed
6. Residual risk
Residual risk is the level of risk expected to remain after controls are implemented.
It should not automatically be described as “acceptable” without explaining:
who made that decision
what evidence was considered
whether the participant was involved
what monitoring will continue
when the decision will be reviewed
7. Monitoring arrangements
Explain how the provider will know whether the controls are working.
Monitoring might include:
worker observations
participant feedback
supervision discussions
incident and near-miss data
health-professional advice
equipment checks
file reviews
internal audits
8. Review triggers
Do not rely only on a calendar date.
The plan may need an earlier review when:
the participant’s needs or circumstances change
a participant changes their goals or preferences
an incident or near miss occurs
a control is ineffective
new information becomes available
workers report inconsistent instructions
equipment or the environment changes
a new service or support arrangement begins
there is a disruption to critical supports
the participant requests a review
Participant support plans are expected to be reviewed annually or earlier when needs or circumstances change. The frequency of progress and risk reviews should also be proportionate to the risk, the participant’s functioning and the participant’s wishes.
How to Use an NDIS Risk Management Plan Template
Step 1: Define the purpose and scope
Before completing the template, identify what it is intended to assess.
For example:
one participant
one activity
one environment
one type of support
a broader organisational process
Avoid combining unrelated risks into one vague assessment.
Step 2: Involve the right people
Depending on the situation, this may include:
the participant
the participant’s nominee or advocate
workers who provide the support
supervisors or managers
allied health professionals
health practitioners
other providers
family or informal supports, with consent
The participant should be actively involved wherever possible, and information should be communicated using language and methods they are most likely to understand.
Step 3: Identify the risk and its context
Ask:
What could happen?
When and where could it happen?
Who could be affected?
What may contribute to the risk?
What could make it more or less likely?
What is already working well?
Avoid writing only the name of a condition, diagnosis or behaviour. The assessment should describe the actual risk.
For example, instead of:
Epilepsy risk.
Use:
Risk of injury or delayed medical assistance if the participant experiences a seizure while accessing the community.
Step 4: Assess the existing risk
Consider the risk with current controls already in place.
Record the evidence used, such as:
past incidents
participant feedback
worker observations
professional assessments
environmental checks
equipment instructions
health or support plans
Where evidence is limited, say so rather than presenting an assumption as a confirmed fact.
Step 5: Select proportionate controls
Controls should respond to the actual risk without unnecessarily limiting the participant.
Possible controls may include:
removing or reducing a hazard
changing the environment
using equipment
providing accessible information
adjusting staffing or supervision
establishing clear worker instructions
obtaining professional advice
creating emergency arrangements
providing training
increasing monitoring temporarily
agreeing on a safer alternative with the participant
Use the least intrusive approach that can reasonably address the risk.
Step 6: Assign responsibility
Every action should have a named person or role responsible for completing it.
Avoid:
Staff to monitor.
Prefer:
The service coordinator will review weekly progress notes for reports of dizziness for four weeks and discuss the outcome with the participant by 30 July 2026.
Step 7: Communicate the plan
The plan should be available to the participant and the workers who need it.
For registered providers assessed against the core module, participant support plans should be accessible to the participant and relevant workers and communicated to other people or providers where appropriate and with consent.
Communication may include:
Easy Read information
translated information
visual instructions
verbal explanation
worker handover
induction or refresher training
participant confirmation
acknowledgement that workers have read the plan
Step 8: Monitor and review
A completed form is not the end of the process.
Check:
whether agreed actions were completed
whether controls are being followed
whether they are reducing the risk
whether they create new risks or restrictions
whether the participant remains satisfied with the approach
whether circumstances have changed
Update the plan when required and retain appropriate version-control records.
Worked Example: Community Shopping
The following example is fictional.
Risk identified
The participant may become overwhelmed in crowded shopping environments, leave the worker unexpectedly and become separated from their support.
Participant’s views
The participant wishes to continue shopping in person because choosing products independently is important to them. They prefer morning visits when the centre is quieter.
Existing controls
Written shopping list
Participant carries a mobile phone
Worker remains within an agreed distance
Quiet shopping times are selected where possible
Further actions
Agree on a meeting point before entering the centre
Confirm how the participant will signal that they need a break
Record an emergency contact
Trial a smaller shopping centre
Review after four outings or earlier if an incident occurs
Monitoring
The worker will record whether breaks were requested, whether the agreed meeting arrangements were used and any feedback provided by the participant.
This example records the participant’s goal, the actual risk, agreed controls and review arrangements. It does not simply prohibit the activity.
Risk Records and Incident Management
A risk assessment does not replace an incident report.
An NDIS incident includes an act, omission, event or circumstance that has caused or could have caused harm to a person with disability. Incidents connected with delivering NDIS supports should be identified, assessed, recorded, managed and resolved while the participant is kept safe, respected and informed.
When an incident or near miss occurs:
address immediate safety and wellbeing
follow the provider’s incident-management procedure
complete required internal records
determine whether escalation or external notification is required
review the relevant risks and controls
record corrective actions
check whether other participants or services may be affected
Registered providers must also notify the NDIS Commission when an incident meets the reportable-incident requirements.
Updating the risk plan may be one action arising from the incident, but it should not replace the separate incident-management process.
Common Risk-Management Mistakes
Using vague descriptions
Participant is a falls risk.
This does not explain where, when or why the risk arises.
Treating a diagnosis as the risk
A diagnosis may inform an assessment, but it does not describe the potential event, consequence or required controls.
Completing the assessment without the participant
Participant views, preferences, strengths and desired outcomes should be included wherever possible.
Copying the same assessment for different participants
Similar risks may require different controls depending on the participant, environment and support arrangements.
Assuming a high-risk rating means the activity must stop
The rating should lead to further discussion, controls and informed decision-making. It should not automatically remove choice.
Recording controls that are not implemented
A plan has limited value if workers are unaware of it, have not been trained or do not have access to required equipment.
Writing “monitor” without explaining how
Monitoring should identify what will be observed, who is responsible, how often it will occur and what will trigger further action.
Waiting for the scheduled review date
Review earlier when circumstances change or there is evidence that controls are not working.
How an NDIS Risk Management Plan Template Can Help
An NDIS risk management plan template may help providers:
use a consistent structure
prompt staff to record key information
assign actions and responsibilities
track review dates
connect risks with treatment actions
record participant involvement
improve communication between authorised workers
identify incomplete or overdue actions
However, the quality of the record depends on the information entered and the actions taken afterward.
A template cannot:
guarantee compliance
replace clinical or professional assessment
decide what level of risk is acceptable
remove the need for participant consultation
replace an incident report
identify every relevant legal obligation
make an ineffective control suitable
Related WorkSmart Templates Resources
The NDIS Risk Management Matrix and Treatment Plan Template provides an editable structure for documenting risks, likelihood, consequences, controls, treatment actions, responsible staff, monitoring and review dates. It is designed as an administrative starting point and should be customised to suit the provider’s circumstances.
The NDIS Risk Management and Support Plan Template provides a broader structure for participant risks, support needs, safeguards, monitoring and review arrangements. It should also be reviewed against the participant’s individual circumstances and the provider’s current obligations.
Final Risk-Management Checklist
Before approving a risk plan, check that:
the risk is described specifically
the participant was involved where possible
the participant’s goals and preferences are recorded
dignity of risk has been considered
existing controls are documented
the rating method has been applied consistently
further actions have responsible people and due dates
monitoring arrangements are clear
workers can access and understand the plan
privacy and consent requirements have been addressed
incident and escalation processes are separate and clear
review dates and early-review triggers are recorded
superseded versions are appropriately managed
Final Thoughts
Effective NDIS risk management is not about eliminating every uncertainty from a participant’s life.
It is about identifying potential harm, supporting informed choice, implementing proportionate controls and checking whether those controls continue to work.
A well-structured risk-management template can make documentation more consistent and easier to review. The value comes from the conversations, decisions, actions and monitoring that sit behind the document.
The most useful final question is:
Does this plan support safety while still respecting the participant’s rights, choices and independence?
Disclaimer
This article provides general administrative and operational information only. It does not constitute legal, regulatory, clinical, work health and safety, audit or professional advice.
Providers should review current NDIS Commission requirements, applicable legislation, registration conditions, participant support needs and professional advice before developing or changing risk-management systems. Templates should be reviewed and customised to suit the provider’s services, participants, workers, environment and current obligations.






