Audits6 min read

How to Assemble Your Audit Evidence Pack Without the Last-Minute Scramble

Auditors don't want to hear that you do the right thing — they want to see it. Here's what goes in an audit evidence pack, and how to keep it ready all year instead of rebuilding it the night before.

The Accorda Team · 7 August 2026

A floating white audit evidence pack card on a pale teal watercolour background, showing a checklist of policies, sign-offs, incident records and credentials with green "ready" ticks and one amber item.

Most providers know their audit date weeks, sometimes months, in advance. And yet the fortnight before still tends to look the same: someone digging through shared drives for the current version of a policy, someone else emailing team leaders to ask who signed off on what, a folder of incident records that lives half in one system and half in a filing cabinet. The work gets done — but it gets done at the worst possible time, under the most pressure, when a single missing document feels like a crisis.

It doesn't have to be that way. The scramble isn't caused by the audit. It's caused by leaving the evidence scattered until the audit forces you to gather it. Pull it together as you go, and the week before an audit becomes a review rather than a rebuild.

Here's what auditors actually ask for, what belongs in an evidence pack, and how to keep one ready year-round.

Auditors want the record, not the reassurance

The single most useful thing to understand about an audit is this: assessors are not there to hear that you do the right thing. They're there to see the evidence that you did.

That distinction runs through how audits are structured. In aged care, the Aged Care Quality and Safety Commission opens an audit by asking the provider to complete and submit an Audit Evidence Collection Tool with key documentation, before assessors review it and meet with leadership. Where a site visit follows, assessors don't just read documents — they gather evidence through, in the Commission's own description, "interviews with older people and their representatives", "interviews with staff", "observations" and "file reviews."

Assessors aren't looking for a good answer in the meeting. They're looking for a record that was already true before they arrived.

NDIS registered providers face the same logic through a different door. Registration is assessed against the NDIS Practice Standards by an approved quality auditor. A certification audit runs in two stages — a document and desk review of your policies, procedures and self-assessment, followed by an on-site stage where the auditor tests what's actually happening through worker and participant interviews, observation and record reviews. Verification audits, for lower-risk supports, are lighter and largely document-based. Either way, the questions come back to evidence.

So an "evidence pack" isn't bureaucratic busywork. It's simply you assembling, on your own terms and in your own time, the same material an assessor is going to ask for anyway.

What actually goes in the pack

The exact contents depend on your sector, your registration groups or service types, and the standards you're audited against. But across NDIS and aged care providers, the same categories come up again and again:

  • Current policies and procedures — and, crucially, proof they're the current version, not last year's. Auditors expect documents that are tailored to your service, in date, and actually in use.

  • Staff sign-offs and training records — evidence that the people delivering care have read the policies that govern their work, understand the Code of Conduct, and hold the training their role requires.

  • Incident records — reports, triage decisions, actions taken, and where relevant the reportable-incident notifications you made and when. Assessors will want to see not just that incidents were logged, but that they were handled and followed through.

  • Complaints and feedback records — how concerns were received, responded to, and used to improve.

  • Worker screening and credentials — current clearances, registrations and licences for the people who need them, with the dates that prove they were valid at the time, not just today.

  • Governance evidence — how your leadership oversees quality and safety: risk management, continuous improvement, meeting records.

None of this is exotic. Every provider already has most of it. The problem is almost never that the evidence doesn't exist. It's that it's scattered, and that some of it can't be quickly proven to be current.

The two things that make the pack slow

When assembling an evidence pack turns into a fortnight of stress, it's usually for one of two reasons.

The first is finding it. Policies live in one place, sign-offs in another, incident records in a third, credential expiry dates in a spreadsheet someone updates when they remember. Assembling the pack means a treasure hunt across systems and people, and the pieces most likely to be missing are the ones that prove a document is current — the version history, the date a staff member actually signed, the point at which a clearance was verified.

The second is proving it's real. An assessor doesn't only want the document; they want confidence the record wasn't tidied up the week before they arrived. A policy with no version history, a training log with no dates, notes that could have been written at any time — these raise questions even when nothing is wrong. Evidence is most persuasive when it's contemporaneous: recorded at the time, in a form that can't be quietly backdated.

Solve those two problems — keep everything in one place, and keep it dated and tamper-evident — and the pack more or less assembles itself.

Build the pack all year, not the night before

The providers who don't scramble aren't the ones with more staff or bigger budgets. They're the ones who treat evidence as something captured continuously, not manufactured on demand. A few habits make the difference:

  • Keep one source of truth for policies, sign-offs, incidents and credentials, so there's no treasure hunt when the audit initiation email lands.

  • Capture the date on everything — when a policy version went live, when each staff member signed it, when a clearance was verified and when it expires — so "current" is provable, not asserted.

  • Log incidents and their follow-through in the same place, so the record shows the full loop, not just the initial report.

  • Watch expiry dates ahead of time, so a lapsed screening check or licence never becomes the gap an auditor finds first.

  • Review, don't rebuild. When the evidence is already assembled and current, audit prep becomes a quick check that everything's in order — the work of an afternoon, not a fortnight.

Where Accorda fits

This is exactly the problem Accorda is built to take off your plate. It keeps your policies, staff sign-offs, incident records and credentials in one place, each with the dates and version history that make "current" something you can prove rather than promise. Records are tamper-evident, so the evidence stands up as contemporaneous. And when the audit comes, a one-click audit evidence pack pulls the relevant material together for you — no treasure hunt, no rebuild.

To be honest about what that does and doesn't do: Accorda doesn't sit your audit, and no tool can guarantee an outcome. What it does is make sure that when an assessor asks for evidence, the answer is "here it is" — organised, in date, and provable — instead of a fortnight of digging. You do the work of good care all year. Accorda makes it easy to show.

If your last audit prep felt like a scramble, the fix isn't to try harder next time — it's to stop letting the evidence scatter in the first place. See how Accorda keeps your audit evidence ready year-round.

Sources

Disclaimer

Disclaimer This article is general information only, current as at August 2026, and is not legal or compliance advice. Regulatory requirements can change.

Start today

See your compliance audit-ready in one place

Try Accorda free for 14 days. Every feature, no credit card, no auto-charge.