Skip to content

What auditors actually ask for

3 min read Dallo

A provider gathering evidence for an audit review

An audit is not a test of whether you are a good provider. It is a test of whether you can prove it, on a particular day, from records that already exist.

That distinction is the whole thing. Providers who fail audits are rarely delivering poor support. They are delivering good support and keeping poor records of it.

What is actually being checked

An auditor works from the standards that apply to your registration and asks, for each one, the same two questions.

Is there a documented way you do this? And is there evidence that the documented way is what actually happened?

Everything else follows from those two. A policy with no records behind it fails the second question. Records that contradict the policy fail both.

The records that get asked for

Your policies and procedures, as they were then

Not the current version. The version that was in force when the thing happened. If you cannot tell an auditor which version applied in March, and show it, then your document history is a gap.

The incident record

What happened, when it was reported, who was told, what you did, what changed as a result. Incomplete incident records are the single most reliable way to turn a routine audit into a difficult one, because they suggest the system exists on paper only.

Complaints and what came of them

Same shape as incidents. A complaints register with entries and no outcomes is worse than no register at all: it proves you knew and shows nothing happened.

Worker screening, qualifications and training

Current, for every worker, with dates. This is the one that catches good providers out. Everyone had the right checks when they were hired. The question is whether they are current now, and whether you can show that without ringing anyone.

Signed, current, matching the supports actually delivered. If the agreement says one thing and the roster says another, that is a finding.

Your own review of yourself

Continuous improvement, internal audits, whatever your policy says you do. If you wrote that you review something quarterly, an auditor will ask to see four of them.

What most providers cannot find in time

Three things, over and over.

Which version was current. The policy has been updated three times and there is one file. Nobody can say what it said in March.

Expiry dates. A screening check that lapsed two months ago, caught by the auditor rather than by you, is a much worse conversation than one you had already flagged and were fixing.

The link between the document and the event. You have the incident form and the policy. What you cannot show is that the form was completed the way the policy requires, within the time the policy sets.

The fix is boring

Keep versions. Keep dates. Keep the record at the moment the thing happens rather than reconstructing it later.

The providers who find audits uneventful are not the ones with the best policies. They are the ones whose evidence is a by-product of doing the work, so when someone asks for March, March is simply there.

If assembling your evidence pack takes a fortnight of nights and weekends, the problem is not the audit. It is that the record only exists when someone goes and builds it.

Filed under

  • Audits
  • Evidence

Read next

All writing
A provider reviewing their business on a laptop

What is R-Commerce?

Buying and selling in industries where the licence is the business, not an afterthought.