If you're looking to become a registered NDIS provider — or you're already registered and approaching your renewal — understanding the audit process is the single most important step you can take. This article breaks down exactly what an NDIS audit involves, what auditors look for, and how to prepare without drowning in paperwork.
What Is an NDIS Audit and Why Does It Exist
An NDIS audit is a formal assessment carried out by an approved quality auditor to determine whether an NDIS provider meets the requirements set out in the NDIS Practice Standards. These standards exist to protect participants — the people living with disability who rely on NDIS-funded services every day. The audit process is administered under the framework of the National Disability Insurance Scheme, Australia's landmark social support system for people with permanent and significant disability.
The NDIS Quality and Safeguards Commission oversees provider registration and requires all registered providers to demonstrate they have the right policies, procedures, governance structures, and operational practices in place before they can deliver funded supports. The audit is how that demonstration happens — it's an independent verification that your organisation is genuinely equipped to deliver safe, high-quality services.
Audits aren't just a bureaucratic hurdle. They serve a real protective purpose:
- They ensure participant safety by confirming providers have proper risk management and incident response processes.
- They maintain sector accountability so that only qualified, compliant providers operate within the scheme.
- They build participant trust by signalling that a provider has met a recognised standard of quality.
For new providers, passing an audit is the gateway to registration. For existing providers, it's an ongoing requirement that keeps your registration active. Either way, knowing what an audit actually involves — and preparing your documentation accordingly — makes the difference between a smooth process and a stressful one.
The Two Types of NDIS Audits Explained
Not all NDIS audits are the same. The NDIS Commission recognises two distinct audit types, and which one applies to your organisation depends on the registration groups you hold — in other words, the specific supports and services you are approved to deliver.
- Verification Audit: This is the lighter-touch option, designed for providers delivering lower-risk supports such as assistance with daily tasks, community participation, or transport. A Verification audit is primarily a document review — an approved quality auditor checks that your policies, procedures and key governance documents are in place and meet the relevant NDIS Practice Standards. There are no on-site visits or staff interviews involved, which makes having well-prepared paperwork absolutely critical to passing.
- Certification Audit: This is the more comprehensive audit type, required for providers delivering higher-risk or more complex supports — including specialised disability accommodation, early childhood supports, behaviour support, or any service involving significant risk to participants. A Certification audit involves both a desktop document review and an on-site assessment, including interviews with staff, participants, and management. Auditors examine not just whether your documents exist, but whether your organisation genuinely operates in line with them.
Most new providers registering to deliver complex supports will need to complete a Certification audit from the outset. It is also the audit type that catches providers most off guard — because the documentation requirements are substantial, covering everything from governance frameworks and risk management to staff training records and incident response procedures.
The document pack available through NDIS University is built specifically for the Certification audit pathway. Every policy, procedure and template included is structured to align with the NDIS Practice Standards that Certification auditors assess against — so you are not starting from a blank page when the stakes are highest.
What Happens During the NDIS Audit Process
Understanding the steps involved in an NDIS audit helps you know exactly what to prepare for — and where gaps in your documentation are most likely to be exposed. While the specific sequence can vary slightly depending on your audit type and registered auditor, the process generally follows a consistent structure.
- Stage 1 — Document Review: Your auditor begins by examining your written policies, procedures, and governance documents. This is where many providers struggle. The auditor is checking whether your documentation aligns with the relevant NDIS Practice Standards and whether it reflects how your organisation actually operates.
- Stage 2 — On-Site or Remote Assessment: For Certification audits, auditors go deeper. They conduct interviews with staff and management, observe service delivery where applicable, and speak with participants or their representatives. They are looking for evidence that your written policies are genuinely embedded in your day-to-day practice.
- Stage 3 — Evidence Gathering: Throughout the audit, your auditor collects supporting evidence — completed forms, incident reports, training records, meeting minutes, and complaint logs. Every claim your documentation makes needs to be backed by real, traceable records.
- Stage 4 — Findings and Corrective Actions: Once the assessment is complete, the auditor produces a report outlining conformance and any non-conformances identified. Minor issues may be resolved through corrective action plans, while major non-conformances can delay or prevent registration approval.
The most common reason providers hit trouble at audit is not a lack of good intentions — it is incomplete or misaligned documentation. Policies that do not match actual practice, missing templates, or poorly structured procedures can all trigger non-conformances that set your registration timeline back significantly.
Having a complete, professionally structured document pack before your audit begins puts you in the strongest possible position from Stage 1 onwards.
Who Conducts NDIS Audits and How Auditors Are Chosen
NDIS audits are not conducted by the NDIS Commission itself. Instead, the Commission maintains a register of approved third-party audit bodies — known as approved quality auditors — who are accredited to assess providers against the NDIS Practice Standards. These are independent organisations that have met strict criteria set by the NDIS Commission to carry out both Certification and Verification audits.
As an NDIS provider, you are responsible for selecting and engaging your own approved auditor from the Commission's register. This might seem straightforward, but there are a few important things to understand about the process:
- You choose your auditor — Providers select an approved quality auditor directly. You can compare auditors based on availability, experience in your service type, and pricing.
- Auditors must be approved by the NDIS Commission — Not just any consultant or compliance professional can conduct an NDIS audit. Only those on the official register are recognised.
- The auditor assesses your documentation and practices — For Certification audits, this includes a desktop review of your policies and procedures and an on-site assessment of how your organisation actually operates.
- Auditors submit findings to the Commission — The auditor does not grant registration themselves. They report their findings, and the NDIS Commission makes the final registration decision.
Understanding who auditors are — and what they are looking for — helps you prepare more strategically. Auditors are trained to identify gaps between your written documentation and your real-world practice, which is why having well-structured, compliant policies from the outset matters so much. If you want to learn more about how the audit process works in practice, the NDIS University blog covers it in detail. And if you have questions about getting started, you can always contact the team directly.
How to Prepare Your Organisation for an NDIS Audit
Preparing for an NDIS audit doesn't have to be overwhelming — but it does require a structured, proactive approach. Auditors will scrutinise your documentation, your systems, and your day-to-day practices, so getting organised well in advance is essential.
Here are the key steps to get your organisation audit-ready:
- Conduct a gap analysis. Review the NDIS Practice Standards relevant to your registration group and honestly assess where your current policies, procedures, and evidence fall short. Identifying gaps early gives you time to address them before your auditor does.
- Build a complete document library. Every required policy and procedure must be documented, current, and accessible. This includes governance frameworks, risk management plans, incident management procedures, staff induction records, and participant rights documentation — among many others.
- Train your staff. Your team needs to understand your policies and be able to speak to them confidently. Auditors often interview workers directly, so make sure everyone knows your processes — not just where to find them on a shared drive.
- Gather evidence of practice. Policies alone aren't enough. Auditors want to see that your organisation lives its documentation. Collect evidence such as completed forms, meeting minutes, training records, and complaint logs.
- Organise your documentation systematically. A well-structured document management system shows auditors your organisation is professionally run. Group documents by category — governance, risk, staff, operations — so nothing gets missed.
One of the biggest challenges providers face is simply building compliant documentation from scratch. It's time-consuming, technically demanding, and easy to get wrong. That's exactly why a ready-made document pack — like the one available here at NDIS University — can be a genuine game-changer. Starting from a professionally structured foundation means you spend less time writing policies and more time preparing your team and your evidence.
What Happens After the Audit Is Complete
Once your NDIS audit is finished, the auditing body reviews all findings and prepares a formal audit report. What happens next depends on the outcome of that review.
- Successful outcome: If you meet the relevant NDIS Practice Standards, the auditor submits a recommendation to the NDIS Commission to grant or renew your registration. The Commission then processes your application and, if satisfied, issues your certificate of registration.
- Non-conformities identified: If the auditor finds areas where your organisation does not fully meet the standards, you will receive a list of non-conformities. Minor issues typically come with a corrective action period — you will need to provide evidence of remediation before registration is confirmed. Major non-conformities may delay or prevent registration until they are resolved.
- Ongoing surveillance: Certification audits are not a one-off event. Registered providers are subject to ongoing surveillance audits during their registration period and must undergo a full renewal audit before their registration expires — typically every three years.
It is important to treat the audit outcome as a starting point, not a finish line. Any corrective actions should be addressed promptly and thoroughly documented. Maintaining your policies, procedures, and staff records in good order between audits means you are never scrambling at the last minute.
If you received non-conformity findings related to your documentation, that is a strong signal that your policies and procedures need strengthening before your next audit cycle begins.
Understanding what an NDIS audit involves — from the types of audits and the standards assessed, through to what auditors look for and what follows after the process — puts you in a far stronger position as a provider. Whether you are registering for the first time or approaching a renewal, having professionally prepared, standards-aligned documentation in place from the outset is one of the most effective steps you can take to move through the audit process with confidence.
Ready to get audit-ready without the paperwork?
Get the Certification Pack — $649