Compliance · CEO + 2IC
Compliance · CEO + 2IC

Compliance

One system instead of 45 standalone workbooks. Every register DAS keeps, who owns it, whether it is current, and everything open across all of them in a single action queue.

Catalogue B043 Governance Registers Suite v1.0, Board-approved 24 June 2026. 45 registers — 9 kept in this portal, 17 tracked here but held elsewhere, 19 specified but not yet started. 6 Highly Confidential registers are catalogued and never migrated.
Registers overdue
Past their B043 review cadence
Never reviewed
No currency check on record
Not started
19
Specified by policy, no register exists
Open actions
overdue
High / extreme open
Across all live registers
Obligations overdue
due in 30 days

Register currency

B043 §5 categories · cadence from the Suite, currency measured
Register Owner Cadence Currency Entries Open Actions
Governance and Board · 10
Register of Members Public Officer / 2IC Continuous; AGM review
Register of Directors Public Officer / 2IC continuous
Board Resolutions Register Public Officer Per meeting
Common Seal Register Public Officer Per use
Delegations Register CEO On change
Conflict of Interest Register (Board and CEO) provenance Board Chair / Public Officer Per meeting + annual
Conflict of Interest Register (Staff and Volunteers) 2IC Continuous + monthly review Not started
Gifts and Benefits Register 2IC Continuous + quarterly Board review Not started
Quality Improvement Register not in B043 CEO quarterly
Cultural Review Register not in B043 2IC per-event
Risk, safeguarding and incident · 16
Strategic Risk Register CEO Quarterly Board
Key Risk Indicators not in B043 CEO quarterly
Operational Risk Register Operations Manager monthly Not started
Safeguarding Concerns Register CEO Continuous + quarterly Board summary
Child Safety Concerns Register CEO Continuous + quarterly Board summary
Reportable Conduct Register CEO Continuous (permanent retention)
Reportable Incidents Register (NDIS s 73Z) CEO Continuous (permanent retention)
Critical Incident Debrief Log CEO Continuous + annual de-identified Board summary
Whistleblower Disclosures Register CEO (Board Chair where the CEO is the subject) Continuous (permanent retention)
Fraud Risk Register CEO + Treasurer quarterly Not started
WHS Incident Register provenance Operations Manager Continuous + monthly review
Hazard Register Operations Manager Quarterly + on report Not started
Complaints Register provenance CEO Continuous + quarterly Board summary
Privacy Incident and Data Breach Register (NDB) not in B043 2IC On discovery + quarterly Board summary Not started
Feedback Register not in B043 provenance CEO quarterly
Provider Conduct Register not in B043 provenance CEO quarterly
Workforce · 6
Worker Screening Register 2IC Continuous + monthly review
Authorised Driver Register 2IC Continuous + annual review Not started
Training Register provenance 2IC Continuous + monthly review
Volunteer Register 2IC continuous Not started
Flexible Work Register 2IC On approval + annual Not started
Supervision Records Each supervisor; Operations Manager oversight Per session
Operational · 13
Information Asset Register 2IC Annual + on change Not started
Records Disposal Register 2IC Annual sentencing Not started
Approved AI Tools List CEO On approval + annual Not started
Vehicle Register 2IC Continuous + monthly review Not started
Trip Plan Register 2IC Per trip + monthly review Not started
Supplier Register 2IC Continuous + annual review Not started
Supplier Risk Register (modern slavery) 2IC annual Not started
Insurance Register Treasurer / CEO Annual + on policy event
Asset Register (capital and IT) 2IC + Treasurer Annual stocktake + continuous Not started
Donor Register CEO continuous Not started
Sponsorship Register CEO Continuous + annual review Not started
Conflict of Advocacy Log Operations Manager continuous
Community Engagement Log 2IC Per engagement

Specified but not started

19 registers
Register Required by Owner Board-reported
Conflict of Interest Register (Staff and Volunteers) B034 Conflict of Interest Policy Staff and Volunteers 2IC
Gifts and Benefits Register B038 2IC Quarterly
Operational Risk Register R001 Risk Management Framework Operations Manager
Fraud Risk Register B030 CEO + Treasurer Quarterly
Hazard Register W001 Work Health and Safety Policy Operations Manager
Authorised Driver Register B032 2IC
Volunteer Register B033 2IC
Flexible Work Register B039 2IC
Information Asset Register B029 2IC
Records Disposal Register B029 2IC
Approved AI Tools List IT002 CEO
Vehicle Register B032 2IC
Trip Plan Register B032 2IC
Supplier Register B017 2IC
Supplier Risk Register (modern slavery) B040 2IC
Asset Register (capital and IT) B004 2IC + Treasurer
Donor Register B007 CEO
Sponsorship Register B014 CEO
Privacy Incident and Data Breach Register (NDB) Privacy Act 1988 Pt IIIC (Notifiable Data Breaches) / B029 2IC Quarterly

These are not portal gaps — they are registers a Board-approved policy says DAS keeps, with no artefact behind them anywhere in SharePoint or the audit pack. The ones marked Quarterly are additionally owed to the Board every three months under B043 §9.

Entries needing provenance confirmation

6 registers

These registers were populated or substantially back-filled during the 21–23 July 2026 audit-preparation window. Back-filling a proper register from email, IVO and memory is legitimate. Presenting those rows with the same authority as contemporaneous ones is not — so they carry a standing banner until Scott confirms the source.

Conflict of Interest Register (Board and CEO)

The 22 Jul snapshot had only the CEO row populated, with the Board rows as bracketed placeholders. Director declarations were filled in on 22 Jul 2026 at 19:13. Confirm each director actually made the declaration recorded against their name before this is relied on.

WHS Incident Register

RESOLVED 27 Jul 2026 (Lukas): this register stands; the conflicting document goes. The 22 Jul snapshot of evidence folder 20 held a signed CEO nil declaration — "no incidents 2021–2026" — which cannot be true alongside these dated entries. ⚠ Withdraw it properly: mark it SUPERSEDED with a dated note saying why, and keep it on file. Do NOT delete it. Quietly removing a signed record from an audit pack is the same failure that made the duplicate Internal Audit Records a problem — the fix for a wrong signed document is a visible correction, not a disappearance. Entries below remain a 23 Jul back-fill of unconfirmed provenance until Scott confirms their source.

Complaints Register

Entries carry dates from Mar 2024 onward, but the workbook was populated on 23 Jul 2026 during audit preparation — the 22 Jul snapshot of the same file held three nil returns and no individual complaints. Treat these rows as a back-fill of unverified provenance until Scott confirms the source, and do not cite the 2024–25 entries as contemporaneous records.

Training Register

The workbook describes itself as a working copy "reproduced in the Audit folder from the SharePoint master" on 22 Jul 2026. It is honest about its own gaps — nine cells are explicitly marked [VERIFY] with the instruction "date to be confirmed by staff (do not invent)" — but it has never been maintained at the monthly cadence B042 sets. Treat it as a starting inventory, not a maintained record, until the VERIFY cells are closed out with staff.

Feedback Register

Same workbook and same 23 Jul 2026 back-fill as the Complaints Register. Provenance unconfirmed for the pre-2026 rows.

Provider Conduct Register

Created 23 Jul 2026 in the same workbook as the incident register, during audit preparation. Provenance of the pre-2026 rows unconfirmed; where a matter was reported to the NDIS Commission there should be a Commission reference to verify against.

Catalogue notes

Discrepancies found transcribing B043 v1.0 §5
  • B043 v1.0 §16 states the Catalogue covers 38 registers (8 governance + 12 risk + 6 workforce + 12 operational). §5.4 actually lists 13 operational registers, so §5 contains 39. One-line correction at the next Suite review.
  • Five registers DAS demonstrably keeps are absent from B043 v1.0 §5: Quality Improvement, Feedback, Provider Conduct, Key Risk Indicators, Cultural Review. All five have a live file or system behind them.
  • B043 §5 does not state where any register physically lives. `externalLocation` here fills that in for the ones that could be traced; the blanks are themselves a finding.
  • Complaints and Feedback are owned by this system, not by the IVO-style CRM, and the two are deliberately not joined. The only link is `ivo_ref`, a participant record number carried on the compliance row — a pointer for a human, not a database relationship.
  • The same boundary sent the Privacy Incident register here from the advocacy CRM (28 Aug 2026). Complaints, feedback and privacy breaches are registers about DAS; systemic issues and the No Wrong Door waitlist are derived from casework and stay in the CRM. The test is whose conduct the row records, not who typed it.