2025-26 APCS audit roadmap showing the two legal periods, three audited statements, evidence workstreams and 31 October deadline.

The Department of Health, Disability and Ageing released the 2025-26 Annual Prudential Compliance Statement (APCS) audit guidance on 23 July 2026. It is not a routine annual refresh. The reporting year straddles the commencement of the Aged Care Act 2024 on 1 November 2025, so auditors must test one twelve-month year against two different legislative frameworks and state an opinion on both. Providers that treat the APCS as a year-end questionnaire risk discovering too late that their source records, board approvals and audit trail were not preserved by legal period.

Key fact: for a standard 30 June reporting year, the complete Aged Care Financial Report — including the APCS and its independent audit opinion — is due by 31 October 2026. The Department says there is no legislative authority to grant an extension.

The deadline sits inside a broader audit workload. The 2025-26 ACFR guidance says the General Purpose Financial Statement and APCS must be audited, and residential aged care providers must also prepare the new externally audited Care Minutes Performance Statement. That makes three audited outputs to coordinate, even though the compliance audit for the APCS must remain separate from the GPFS financial audit. The practical response is to lock scope, evidence ownership and auditor availability now rather than waiting for the Forms Administration portal to become the project plan.

Background: what the APCS did before this transition year

The APCS is the prudential compliance component of the ACFR. It asks providers about refundable deposits, accommodation bonds and entry contributions: how many are held, their value, how they were managed and spent, whether refunds were made on time, and whether the provider complied with the applicable prudential standards. Residential aged care and Multi-Purpose Service providers must complete it. The ACFR guidance is explicit that an APCS is still required even when a provider did not hold bonds during the reporting year.

Under the former framework, the audit centred on Part 5 of the Fees and Payments Principles 2014 (No. 2), inherently including Parts 6 and 7. Auditors tested the old Liquidity, Records, Governance and Disclosure Standards, permitted uses of refundable deposits and bonds, statutory refund timeframes, and accommodation charging obligations. The annual disclosure cycle was therefore built around one stable legal framework for the entire reporting year.

The new Aged Care Act commenced part-way through 2025-26. The Department has therefore required providers to report against whichever prudential framework applied at the time an obligation was in force. The audit remains one engagement across the full year, but the evidence cannot be blended so thoroughly that the auditor loses the ability to determine which law applied on a particular date.

What changed and when: the two-law audit split

The 18-page audit guide divides the reporting year into two periods. For 1 July 2025 to 31 October 2025, the auditor assesses compliance with the Aged Care Act 1997, the Fees and Payments Principles 2014 (No. 2), and the old Prudential Standards. For 1 November 2025 to 30 June 2026, the auditor assesses the Aged Care Act 2024, the Aged Care Rules 2025 and the Aged Care Financial and Prudential Standards 2025.

There is a further commencement nuance. Because the new Act started during a reporting quarter, the guide says providers were not required to comply with the new Liquidity Standard and Investment Standard until 1 January 2026. Audit workpapers therefore need to distinguish at least three operational checkpoints: the old framework to 31 October, the new Act and Rules from 1 November, and the new Liquidity and Investment Standards from 1 January.

An auditor can issue separate findings for the two frameworks or one consolidated report. If a consolidated approach is used, the opinion must still clearly address compliance with each framework during its applicable period. The audit must be performed by a registered company auditor (RCA), or by an auditor approved by the System Governor under section 166-385 of the Aged Care Rules. A provider seeking approval for an alternative auditor should account for the Department's stated 28-day processing period.

The opinion must cover the provider's compliance with Part 5, Part 6 and Part 7 of the old Fees and Payments Principles for the first period, then the Aged Care Financial and Prudential Standards 2025, section 150A of the Aged Care Act 2024, and sections 155-30, 155-35 and 166-360 to 166-385 of the Rules for the second period. An audit report missing required content will be returned for correction and resubmission.

The three audited outputs providers must coordinate

  • General Purpose Financial Statement (GPFS). This is the financial statement audit. Its data must reconcile appropriately with the registered provider reporting in the ACFR, but it is not a substitute for the APCS compliance audit.
  • Annual Prudential Compliance Statement. This is a compliance engagement under the applicable Standards on Assurance Engagements, including ASAE 3100. The Department says a single audit report covering both the GPFS and prudential compliance is not acceptable.
  • Care Minutes Performance Statement. New for the 2025-26 ACFR, residential aged care providers must submit an externally audited statement covering care expenses, care minutes and 24/7 RN reporting. For this transition year it covers 1 November 2025 to 30 June 2026, with care-minutes and care-expense data for quarters 3 and 4 and 24/7 RN data for the eight months from November.

The three outputs share source systems and people but have different assurance questions. The GPFS asks whether the financial statements are fairly presented. The APCS asks whether the provider complied with prudential legislation and reported that compliance accurately. The Care Minutes Performance Statement tests care workforce expenses, hours and 24/7 RN data. A single data owner may contribute to all three, but each output needs its own evidence index, review sign-off and final audit deliverable.

Operational impact for providers: six workstreams to open now

  • 1. Freeze a legal-period evidence map. Tag every prudential control and transaction to the date and framework that governed it. At minimum, separate 1 July-31 October, 1 November-31 December, and 1 January-30 June so the delayed Liquidity and Investment Standard commencement is visible.
  • 2. Reconcile the refundable deposit register. Confirm the register contains all information required under the old Records Standard and section 150A of the new Act and Rules. Reconcile opening balances, receipts, deductions, refunds, retention amounts, interest and closing liabilities to the general ledger and resident-level records.
  • 3. Evidence quarterly liquidity governance. The new Liquidity Standard introduces default and evaluated minimum liquidity amounts. Providers should retain the calculations, the chosen method, any Commission notification, evidence that the minimum amount was maintained, and governing-body review and sign-off for each quarter in scope.
  • 4. Validate investment and management strategies. Under the new Investment Standard, all non-government Category 6 providers need an investment management strategy, including providers that do not invest or hold refundable deposits. Keep the approved strategy, objectives, risk controls, responsible-person capability evidence and annual review.
  • 5. Test resident disclosures and refunds. Sample accommodation agreements, seven-day entry disclosures, annual register extracts, information supplied on request, statutory refund dates, and the interest rate applied. The guide expects records and correspondence to provide the evidence; auditors are not expected to contact residents.
  • 6. Reserve signatories and auditors. The ACFR must be signed by a member of the governing body. The Department recommends having at least two signatories available. Book the RCA, confirm the separate audit reports required, and plan backwards from 31 October with time for corrections.

Key numbers and rules the audit evidence must prove

The new guide turns several operational rules into concrete audit tests. For residents entering after 31 October 2025, providers must show that accommodation agreements were entered into before ongoing funded aged care services started. On entry, the resident or representative must receive a copy of the accommodation agreement and a written statement about other available information within seven days. Existing residents with refundable deposits or bonds must receive their register entry and the written information statement annually, within four months after the end of the financial year.

The guide specifies that retention amounts introduced by section 308 of the Aged Care Act 2024 are calculated at 2% per annum on a daily basis, deducted no more than monthly and at least once in each three-month period, and only applied to residents under the post-1 November 2025 accommodation arrangements. Retentions must stop after the resident permanently leaves care.

For overpaid accommodation contributions, the provider must refund the overpayment within 28 days after becoming aware of it. The guide also tells auditors to test whether refundable deposit and bond balances were returned within statutory timeframes and whether base or maximum permissible interest was paid correctly. These are transaction-level obligations: a policy saying refunds are timely is not evidence that each sampled refund was timely.

The maximum accommodation payment amount referenced in the audit guide is $758,627. If a resident was charged more, the provider needs a current Pricing Authority approval for that instance. Providers should also test that room prices were publicly available on My Aged Care and that daily accommodation payments were calculated using the correct maximum permissible interest rate and, where applicable, indexed correctly.

A 30-day workflow to reach auditor-ready status

  • Days 1-5 — scope and owners. Confirm which ACFR forms apply to each program, nominate owners for the GPFS, APCS and Care Minutes Performance Statement, appoint the governing-body signatories, and agree the RCA timetable. Document the two legal periods and the 1 January standard commencement inside the audit plan.
  • Days 6-10 — extract and reconcile. Export the refundable deposit register, general ledger accounts, resident agreements, refund transactions, liquidity calculations, investment records and disclosure correspondence. Reconcile totals and investigate every unexplained variance before sending data to the auditor.
  • Days 11-15 — control testing. Sample resident entries, accommodation charges, retention deductions, refunds, annual disclosures and board approvals. Record each exception with the date, affected framework, value, root cause and remediation status.
  • Days 16-20 — strategy and governance pack. Assemble the Liquidity Management Strategy, Investment Management Strategy, financial and prudential management system, quarterly minimum-liquidity approvals, delegations and evidence that responsible staff had appropriate skills and oversight.
  • Days 21-25 — dry-run the APCS. Complete a draft APCS using the Department's 2025-26 resources. Cross-reference every response to an evidence file. Give the auditor the draft APCS, reconciliation workbook and exception log early enough to refine the sampling plan.
  • Days 26-30 — governing-body review. Present the compliance position, unresolved exceptions and remediation plan to the governing body. Confirm the final signatory, the audit-report wording, upload responsibilities and a submission date comfortably before 31 October.
Do not merge the assurance reports. The Department says the APCS compliance audit is separate from the GPFS financial audit. Build one coordinated timetable, but obtain distinct reports that answer the distinct assurance questions.

Common failure modes to test before the auditor does

Blended-period evidence. A provider supplies one annual policy, one year-end liquidity calculation and one consolidated exception list. The auditor cannot determine what control operated under the old law, what changed on 1 November, or whether the new Liquidity and Investment Standards were operating from 1 January.

Missing governing-body approval. The finance team calculated the quarterly minimum liquidity amount, but there is no evidence that the governing body reviewed and signed it off. The calculation may be numerically correct while the governance obligation remains unsupported.

One audit report for everything. The provider asks the financial statement auditor to mention prudential compliance in the GPFS report. The ACFR guidance expressly says one report covering both the GPFS and prudential compliance is not acceptable.

Policies without resident-level transactions. The provider has a compliant refunds policy but cannot produce the departure date, statutory deadline, payment date, balance, base interest and maximum permissible interest calculations for sampled residents. The audit tests actual performance, not just policy design.

Late remediation discovered after 31 October. The Department says there is no legislative authority for an extension. The ACQSC can consider formal compliance action for late reporting and uses reporting performance as part of the provider's wider risk profile. The safe plan includes time for an audit query, a corrected schedule and a governing-body re-sign.

How NovoCove supports this

NovoCove supports the workforce evidence layer that feeds aged care compliance and assurance. It centralises staff certifications and training expiry, covers aged care credentials including AHPRA registration and NDIS Worker Screening, applies automatic alerts through a 7-tier expiry cadence, and gives each service a RAG compliance view. Daily ComplianceSnapshot records preserve the trend so leaders can see whether workforce credential risk improved or deteriorated before the reporting date.

For multi-site providers, the multi-tenant architecture and tenant-scoped audit logging help keep service records separated and traceable. That is useful when workforce evidence contributes to the Care Minutes Performance Statement or when an auditor samples training and credential records supporting a compliance control.

NovoCove does not replace the provider's finance system, refundable deposit register, Liquidity Management Strategy, Investment Management Strategy, audit workpapers or Forms Administration submission. It also does not provide the independent audit opinion. Its role is narrower and concrete: keep staff credential and training evidence current, surface expiry risk early, and give leaders an auditable workforce data layer that can be supplied alongside the financial and prudential evidence maintained elsewhere.

Official sources and further reading

This guide is general information and is not legal advice.

Build the workforce evidence layer before your 31 October submission

NovoCove centralises staff credentials and training expiry, applies automatic 7-tier alerts, and gives each service a RAG view of workforce compliance. It complements — but does not replace — your finance system, refundable deposit register, audit workpapers or Forms Administration submission.

Book a demo