Compliance
One system instead of 45 standalone workbooks. Every register DAS keeps, who owns it, whether it is current, and everything open across all of them in a single action queue.
Register currency
B043 §5 categories · cadence from the Suite, currency measured| Register | Owner | Cadence | Currency | Entries | Open | Actions |
|---|---|---|---|---|---|---|
| Governance and Board · 10 | ||||||
| Register of Members | Public Officer / 2IC | Continuous; AGM review | — | — | — | — |
| Register of Directors | Public Officer / 2IC | continuous | — | — | — | — |
| Board Resolutions Register | Public Officer | Per meeting | — | — | — | — |
| Common Seal Register | Public Officer | Per use | — | — | — | — |
| Delegations Register | CEO | On change | — | — | — | — |
| Conflict of Interest Register (Board and CEO) provenance | Board Chair / Public Officer | Per meeting + annual | — | — | — | — |
| Conflict of Interest Register (Staff and Volunteers) | 2IC | Continuous + monthly review | Not started | — | — | — |
| Gifts and Benefits Register | 2IC | Continuous + quarterly Board review | Not started | — | — | — |
| Quality Improvement Register not in B043 | CEO | quarterly | — | — | — | — |
| Cultural Review Register not in B043 | 2IC | per-event | — | — | — | — |
| Risk, safeguarding and incident · 16 | ||||||
| Strategic Risk Register | CEO | Quarterly Board | — | — | — | — |
| Key Risk Indicators not in B043 | CEO | quarterly | — | — | — | — |
| Operational Risk Register | Operations Manager | monthly | Not started | — | — | — |
| Safeguarding Concerns Register | CEO | Continuous + quarterly Board summary | — | — | — | — |
| Child Safety Concerns Register | CEO | Continuous + quarterly Board summary | — | — | — | — |
| Reportable Conduct Register | CEO | Continuous (permanent retention) | — | — | — | — |
| Reportable Incidents Register (NDIS s 73Z) | CEO | Continuous (permanent retention) | — | — | — | — |
| Critical Incident Debrief Log | CEO | Continuous + annual de-identified Board summary | — | — | — | — |
| Whistleblower Disclosures Register | CEO (Board Chair where the CEO is the subject) | Continuous (permanent retention) | — | — | — | — |
| Fraud Risk Register | CEO + Treasurer | quarterly | Not started | — | — | — |
| WHS Incident Register provenance | Operations Manager | Continuous + monthly review | — | — | — | — |
| Hazard Register | Operations Manager | Quarterly + on report | Not started | — | — | — |
| Complaints Register provenance | CEO | Continuous + quarterly Board summary | — | — | — | — |
| Privacy Incident and Data Breach Register (NDB) not in B043 | 2IC | On discovery + quarterly Board summary | Not started | — | — | — |
| Feedback Register not in B043 provenance | CEO | quarterly | — | — | — | — |
| Provider Conduct Register not in B043 provenance | CEO | quarterly | — | — | — | — |
| Workforce · 6 | ||||||
| Worker Screening Register | 2IC | Continuous + monthly review | — | — | — | — |
| Authorised Driver Register | 2IC | Continuous + annual review | Not started | — | — | — |
| Training Register provenance | 2IC | Continuous + monthly review | — | — | — | — |
| Volunteer Register | 2IC | continuous | Not started | — | — | — |
| Flexible Work Register | 2IC | On approval + annual | Not started | — | — | — |
| Supervision Records | Each supervisor; Operations Manager oversight | Per session | — | — | — | — |
| Operational · 13 | ||||||
| Information Asset Register | 2IC | Annual + on change | Not started | — | — | — |
| Records Disposal Register | 2IC | Annual sentencing | Not started | — | — | — |
| Approved AI Tools List | CEO | On approval + annual | Not started | — | — | — |
| Vehicle Register | 2IC | Continuous + monthly review | Not started | — | — | — |
| Trip Plan Register | 2IC | Per trip + monthly review | Not started | — | — | — |
| Supplier Register | 2IC | Continuous + annual review | Not started | — | — | — |
| Supplier Risk Register (modern slavery) | 2IC | annual | Not started | — | — | — |
| Insurance Register | Treasurer / CEO | Annual + on policy event | — | — | — | — |
| Asset Register (capital and IT) | 2IC + Treasurer | Annual stocktake + continuous | Not started | — | — | — |
| Donor Register | CEO | continuous | Not started | — | — | — |
| Sponsorship Register | CEO | Continuous + annual review | Not started | — | — | — |
| Conflict of Advocacy Log | Operations Manager | continuous | — | — | — | — |
| Community Engagement Log | 2IC | Per engagement | — | — | — | — |
Specified but not started
19 registers| Register | Required by | Owner | Board-reported |
|---|---|---|---|
| Conflict of Interest Register (Staff and Volunteers) | B034 Conflict of Interest Policy Staff and Volunteers | 2IC | — |
| Gifts and Benefits Register | B038 | 2IC | Quarterly |
| Operational Risk Register | R001 Risk Management Framework | Operations Manager | — |
| Fraud Risk Register | B030 | CEO + Treasurer | Quarterly |
| Hazard Register | W001 Work Health and Safety Policy | Operations Manager | — |
| Authorised Driver Register | B032 | 2IC | — |
| Volunteer Register | B033 | 2IC | — |
| Flexible Work Register | B039 | 2IC | — |
| Information Asset Register | B029 | 2IC | — |
| Records Disposal Register | B029 | 2IC | — |
| Approved AI Tools List | IT002 | CEO | — |
| Vehicle Register | B032 | 2IC | — |
| Trip Plan Register | B032 | 2IC | — |
| Supplier Register | B017 | 2IC | — |
| Supplier Risk Register (modern slavery) | B040 | 2IC | — |
| Asset Register (capital and IT) | B004 | 2IC + Treasurer | — |
| Donor Register | B007 | CEO | — |
| Sponsorship Register | B014 | CEO | — |
| Privacy Incident and Data Breach Register (NDB) | Privacy Act 1988 Pt IIIC (Notifiable Data Breaches) / B029 | 2IC | Quarterly |
These are not portal gaps — they are registers a Board-approved policy says DAS keeps, with no artefact behind them anywhere in SharePoint or the audit pack. The ones marked Quarterly are additionally owed to the Board every three months under B043 §9.
Entries needing provenance confirmation
6 registersThese registers were populated or substantially back-filled during the 21–23 July 2026 audit-preparation window. Back-filling a proper register from email, IVO and memory is legitimate. Presenting those rows with the same authority as contemporaneous ones is not — so they carry a standing banner until Scott confirms the source.
The 22 Jul snapshot had only the CEO row populated, with the Board rows as bracketed placeholders. Director declarations were filled in on 22 Jul 2026 at 19:13. Confirm each director actually made the declaration recorded against their name before this is relied on.
RESOLVED 27 Jul 2026 (Lukas): this register stands; the conflicting document goes. The 22 Jul snapshot of evidence folder 20 held a signed CEO nil declaration — "no incidents 2021–2026" — which cannot be true alongside these dated entries. ⚠ Withdraw it properly: mark it SUPERSEDED with a dated note saying why, and keep it on file. Do NOT delete it. Quietly removing a signed record from an audit pack is the same failure that made the duplicate Internal Audit Records a problem — the fix for a wrong signed document is a visible correction, not a disappearance. Entries below remain a 23 Jul back-fill of unconfirmed provenance until Scott confirms their source.
Entries carry dates from Mar 2024 onward, but the workbook was populated on 23 Jul 2026 during audit preparation — the 22 Jul snapshot of the same file held three nil returns and no individual complaints. Treat these rows as a back-fill of unverified provenance until Scott confirms the source, and do not cite the 2024–25 entries as contemporaneous records.
The workbook describes itself as a working copy "reproduced in the Audit folder from the SharePoint master" on 22 Jul 2026. It is honest about its own gaps — nine cells are explicitly marked [VERIFY] with the instruction "date to be confirmed by staff (do not invent)" — but it has never been maintained at the monthly cadence B042 sets. Treat it as a starting inventory, not a maintained record, until the VERIFY cells are closed out with staff.
Same workbook and same 23 Jul 2026 back-fill as the Complaints Register. Provenance unconfirmed for the pre-2026 rows.
Created 23 Jul 2026 in the same workbook as the incident register, during audit preparation. Provenance of the pre-2026 rows unconfirmed; where a matter was reported to the NDIS Commission there should be a Commission reference to verify against.
Catalogue notes
Discrepancies found transcribing B043 v1.0 §5- B043 v1.0 §16 states the Catalogue covers 38 registers (8 governance + 12 risk + 6 workforce + 12 operational). §5.4 actually lists 13 operational registers, so §5 contains 39. One-line correction at the next Suite review.
- Five registers DAS demonstrably keeps are absent from B043 v1.0 §5: Quality Improvement, Feedback, Provider Conduct, Key Risk Indicators, Cultural Review. All five have a live file or system behind them.
- B043 §5 does not state where any register physically lives. `externalLocation` here fills that in for the ones that could be traced; the blanks are themselves a finding.
- Complaints and Feedback are owned by this system, not by the IVO-style CRM, and the two are deliberately not joined. The only link is `ivo_ref`, a participant record number carried on the compliance row — a pointer for a human, not a database relationship.
- The same boundary sent the Privacy Incident register here from the advocacy CRM (28 Aug 2026). Complaints, feedback and privacy breaches are registers about DAS; systemic issues and the No Wrong Door waitlist are derived from casework and stay in the CRM. The test is whose conduct the row records, not who typed it.