Audit evidence

Position Descriptions and the NDIS Practice Standards: One Held Against Every Role

NDIS Certification asks for a position description held against every position in the service, not every person, naming the skills, knowledge, responsibilities, scope and limitations of each one. A support worker's position description is usually the easy one. Ask for the one covering the person who signs off a restrictive practice authorisation, or the one held by a director, and the folder often runs thin.

Your CRM runs the participant side of the business. This is the workforce side: proof that every position in the service, not just the ones on the roster, has been thought through and written down.

What the Practice Standards actually ask for

The requirement sits under Human Resource Management, part of Provider Governance and Operational Management in the Core Module. In the Commission's own words:

"Skills, knowledge, responsibilities, scope and limitations of each position are identified and documented"

Five things, named against every position in the service: skills, knowledge, responsibilities, scope and limitations. This is one of seven requirements that Certification asks for on top of everything Verification already covers, alongside performance reviews, supervision records and the workforce disruption plan.

It's written about the position, not the person

Read the wording again and notice what it doesn't ask. It doesn't say every worker needs a position description. It says every position does.

That's a real difference, and it's the one most registers get backwards. File a position description per person and you end up with as many documents as you have staff, duplicated across everyone who shares a role, with a gap the moment someone new starts before the paperwork catches up. File it against the role instead, and the question an auditor actually asks becomes answerable directly: does every position in this service have one, not does everyone.

The positions a register usually misses

Support worker, team leader, roster coordinator: most providers have those covered. The gaps tend to sit higher up the chart, not lower.

A director who also authorises restrictive practices holds a position with real scope and real limitations, and it needs documenting the same as any other. So does an on-call after-hours role, or a position created for one specific hire that is, on paper, still a position in its own right.

The indicator doesn't carve out an exception for governance roles. Every position identified and documented means every position, including the ones the organisation chart puts at the top of it.

What has to be on one

Four separate things sit inside "skills, knowledge, responsibilities, scope and limitations," and each is answering a different question. Skills and knowledge: what the role actually requires to do the job, not a generic list lifted from a job ad. Responsibilities: what the position is accountable for. Scope: what the role can decide and act on, on its own. Limitations: what sits outside it, and where a decision has to go instead.

A position description that only lists duties has answered one of the four. Scope and limitations are the two most registers leave out entirely, and they're the two an auditor is most likely to probe, because they're the two that show whether a provider actually knows where a role's authority ends.

How CORA holds the register

CORA files position descriptions in organisation documents, held against a role rather than a person. The role list is drawn from the position titles actually in use across the workforce, so the register answers the indicator's own question directly: does every position in this service have a documented description, not does this one person have theirs.

A position description sits alongside the workforce disruption plan and PPE evidence in the same place, so building out the organisation-level side of an audit means working through one list, not hunting across individual worker files for something that was never a per-worker artefact to begin with. See what sits beside it on the organisation side.

Every claim on this page is written the same way every claim on the site is written: about a named artefact, checkable in a demo. See the standard CORA holds every claim to.

Certification asks for this today. Building it early pays off either way

This indicator sits inside Certification. If you're currently under Verification and moving toward personal care or supported independent living, building the register now means it already exists, dated and complete, by the time Certification asks for it. See the full NDIS audit evidence checklist for how this sits against everything else, whichever audit applies to you.

Common questions

Does every worker need their own position description?

No. The indicator asks for one held against every position in the service, not one per person. Several workers sharing a role share the same position description.

Do director roles need a position description?

Yes. The indicator doesn't exempt governance roles. A director holding a position with real scope, for instance authorising restrictive practices, needs that position documented the same as any other in the service.

Is a position description a Verification requirement or a Certification requirement?

Certification. It's one of seven requirements Certification adds on top of everything Verification already asks a provider to hold.

What has to be in a position description to satisfy the indicator?

At minimum, the skills and knowledge the role requires, what it's responsible for, what it has the scope to decide on its own, and where its limitations sit, the point at which a decision has to go to someone else.