Internal assurance resource

Internal Assurance Calendar

A practical annual rhythm for checking whether the systems behind safe, quality services are current, complete and working in practice.

This is different from the regulatory calendar. It is your organisation’s own internal program of file reviews, training checks, HR audits, practice reviews, risk checks and governance assurance.

A sensible operating rhythm

Monthly

Incidents, complaints, safeguarding, critical workforce expiries, training exceptions, key service records and corrective actions.

Quarterly

HR files, CRM/client files, supervision, risk controls, compliance registers, governance records and selected practice audits.

Six-monthly

Emergency readiness, business continuity, deeper practice reviews and selected system controls.

Annually

Whole-of-system policy cycle, governance effectiveness, financial controls, provider due diligence, strategic risk and assurance-plan reset.

What should be in it?

Audit the things that tell you whether practice is actually under control.

The exact frequency should be proportionate to risk, service type, regulatory obligations, incidents and organisational size. The purpose is not to create more administration. It is to establish a repeatable assurance cycle so important controls are tested before a regulator, auditor or serious incident exposes the gap.

Client, participant and consumer records

Monthly or quarterly
  • CRM and client file completeness
  • Consent, service agreements and plans
  • Case notes and progress records
  • Risk, safeguarding and escalation records
  • Exit, transition and referral documentation

Workforce and HR files

Quarterly
  • Personnel file completeness
  • Qualifications and role requirements
  • Worker screening and checks
  • Employment documentation and position descriptions
  • Performance and probation records

Training, competency and supervision

Monthly or quarterly
  • Mandatory training completion
  • Role-specific competency evidence
  • Expired and upcoming learning requirements
  • Supervision and reflective-practice records
  • Capability gaps and remedial actions

Incidents, complaints and safeguarding

Monthly
  • Incident and complaint trends
  • Reporting timeliness and escalation
  • Corrective actions and closure
  • Restrictive-practice or safeguarding themes
  • Evidence that learning changed practice

WHS and risk controls

Monthly or quarterly
  • Hazard and incident trends
  • Psychosocial hazards
  • Critical control effectiveness
  • Risk register updates
  • Outstanding corrective actions

Policy and procedure review

Scheduled across the year
  • Policies due for review
  • Legislative and regulatory changes
  • Forms, tools and procedures aligned to policy
  • Version control and approval
  • Implementation and workforce communication

Governance and compliance records

Quarterly
  • Delegations and authorities
  • Conflicts and declarations
  • Registers and statutory records
  • Committee and Board actions
  • Compliance obligations and overdue actions

Service quality and practice

Quarterly or risk-based
  • Observed practice against expectations
  • Service-user experience and feedback
  • Practice supervision and coaching
  • Quality indicators and outcome measures
  • Improvement actions and effectiveness review

Finance, procurement and provider controls

Quarterly or annual
  • Financial delegations and approvals
  • Provider and subcontractor due diligence
  • Procurement controls
  • Fraud and conflict controls
  • Contract and insurance currency

Emergency, continuity and information systems

Six-monthly or annual
  • Emergency and evacuation testing
  • Business continuity exercises
  • Cybersecurity and access controls
  • Privacy and records management
  • System recovery and critical contact information

For each assurance activity, record more than “completed”.

What was sampled or tested
What was found
Who owns the action
When effectiveness will be re-checked

That creates an evidence trail from review → finding → action → re-test → governance assurance.

Build the calendar around your actual services and risks.

A multi-service provider should not use the same assurance schedule as a small single-service organisation. The Hub can help establish a proportionate annual plan.

Talk to Rachel