Audit evidence

The NDIS Credential Register: Every Ticket, Check and Licence, With the Date It Lapses

An NDIS credential register holds every ticket, check and licence a worker carries, with who issued it, when, and when it lapses. A First Aid ticket lapses two months before your next audit, and nobody catches it until the assessor asks to see it. That's the failure an NDIS credential register exists to stop, and most providers end up building one anyway, after the fact, out of a folder of scanned certificates and a spreadsheet somebody half trusts.

CORA's credential register holds every ticket, check and licence your workforce carries, on the worker's own record, before an audit is the reason you go looking for it. One row per credential: the name, the category, who issued it, the date it was issued, and the date it lapses. That's workforce evidence, not paperwork for its own sake.

What does an NDIS credential register need to hold?

Every credential in CORA carries the same five pieces of information: what it is, what category it sits in, who issued it, the date it was issued, and the date it expires, where it has one. Some credentials genuinely never lapse. Most do, and the register is built around the date that matters most, the one an assessor checks first.

Category is yours to name. First Aid, Manual Handling, the NDIS Worker Screening Check, a qualification, a licence to drive the organisation's vehicle, whatever your workforce actually holds, in your own words, because a real workforce holds credentials no fixed dropdown would have anticipated.

Column What it shows
Worker name Every credential sits on the worker's own record
Credential name and category Named in your own words, First Aid, worker screening, a licence, a qualification
Issued by The RTO, agency or authority that issued it, not CORA
Date issued Read straight off the uploaded certificate where CORA can
Expiry date, where it applies Some credentials never lapse. Where one does, this is the date the warning windows count down to
Warning window Set by the provider at 7, 14, 30, 60 or 90 days before expiry

The artefacts an auditor asks for by name

The requirement sits under Human Resource Management, in Provider Governance and Operational Management, in the Core Module. In the Commission's own words:

"Records of worker pre-employment checks, qualifications and experience are maintained."

Two of the artefacts an auditor asks for by name, under that one requirement, are the NDIS Worker Screening Check clearance and the worker's qualifications and experience for the role. Both live in CORA's credential register, with their own issue and expiry dates, alongside every other ticket your workforce holds.

Proof of identity and the right to work sit a short walk away, in the worker's own document vault. This page is about what expires. Screening, qualifications and everything else with a renewal date on it belong here.

Who can add, update and remove a record

A worker adds their own certificate the moment they earn it, straight from their phone. If a renewal arrives, or they uploaded the wrong file the first time, they update that same record themselves rather than starting a new one.

Removing a record from the register is an admin action. Correcting evidence and removing evidence are different acts, and the register stays reliable because the second one carries a second person's judgement.

You upload it, CORA holds it

Every claim on this page is written the same way every claim on this site is written: about what CORA actually holds, checkable in a demo. You upload it, CORA holds it, and every download is logged, a full record of who opened a worker's certificate and when, one that nobody, not even an admin, can edit or delete afterwards.

See the standard we hold every claim on the site to. The credential register is one part of CORA's HR software for NDIS providers, alongside the worker file, policy acknowledgements and supervision. Setting up a new starter's credentials by hand for now? Grab the free support worker onboarding checklist, no email required.

How do I chase expired credentials across a team?

Finding out that twenty-nine tickets have lapsed across your workforce is the easy half of the job. The hard half used to be chasing twenty-nine people individually, one email at a time, trying to remember who you'd already nagged.

Filter the register to what you actually care about: everyone expired, everyone expiring this month, one credential type, or a search across names, certificates and issuers. Then send a reminder to everybody sitting inside that filter, in one action.

Before anything sends, CORA shows you exactly who's about to be emailed and why. A record with no expiry date is left out, because there's nothing to remind anyone about. Anyone already reminded in the last week is named and held back, so two different reasons to chase the same person never turn into two emails on the same morning. Each person still gets one email, listing everything of theirs that's due, never one email per record.

That's what makes the register a tool rather than a report. A report tells you what's wrong. This lets you act on all of it, from the same screen, without opening a mail client.

The full picture of how CORA paces every reminder it sends, the automated jobs, the quiet windows, the weekly digest, lives on automated training reminders for NDIS providers.

Can I import our existing credential spreadsheet?

A provider switching to CORA rarely starts with an empty register. Credentials and in-person training records import in bulk from a spreadsheet you already keep, and they land as the same kind of record CORA builds from a fresh upload, so a certificate from 2022 sits next to one uploaded this morning with no visible seam. See how bringing your spreadsheet across actually works.

Does CORA read certificate expiry dates automatically?

Yes. Upload a photo or a PDF of the certificate itself and CORA reads the name, the issuer, the issue date and the expiry straight off it, then asks you to confirm what it found before anything is saved. See exactly how CORA reads a certificate, and why it refuses to guess an expiry.

Common questions

What does an NDIS credential register need to hold?

At minimum, the worker's name, what the credential is, who issued it, when it was issued, and when it expires if it does. The NDIS Worker Screening Check clearance and a worker's qualifications and experience for the role are two specific artefacts an assessor asks for by name.

Is a credential register the same as a training register?

They answer different questions. A credential register tracks externally issued tickets, checks and licences and their expiry dates. A training register tracks courses a worker completed inside your own training system. CORA keeps in-person training records in the credential register too, alongside tickets and checks, distinguished only by category.

Can a support worker upload their own certificate?

Yes. A worker can add a certificate to their own record and update it themselves the moment a renewal arrives. Removing a record from the register is kept as an admin action.

What warning windows can I set before a credential expires?

7, 14, 30, 60 or 90 days, set by the provider. CORA holds every worker to the same window per credential type and sends a weekly digest rather than a flood of single-credential emails.