What Happens During a Compulsory NDIS Audit? Inside the Process, Stage by Stage
DISABILITY INSIGHTS

What Happens During a Compulsory NDIS Audit? Inside the Process, Stage by Stage

Advertisement Audit Pilot — stop preparing for audits, stay ready. NDIS compliance, autonomously managed 24/7. Audit Pilot — stop preparing for audits, stay ready. NDIS compliance, autonomously managed 24/7.

TL;DR: A compulsory NDIS audit is conducted by an independent approved quality auditor against the NDIS Practice Standards. Lower-risk providers undergo a verification audit (largely a documents check); higher-risk providers undergo certification, which runs in two stages — Stage 1 reviews your policies and systems on paper, Stage 2 is the on-site visit where auditors interview staff and participants, sample participant files, and test whether your documented systems actually operate in practice. Findings are graded as conformities or minor/major non-conformities, and the results go to the NDIS Commission, which makes the final registration decision.

Every registered NDIS provider faces audits — at initial registration, mid-term, and at renewal — and for providers newly captured by the 2026 mandatory registration changes, the first one can feel like a black box. This article explains what actually happens once the audit begins: who turns up, what they look at, who they talk to, and what the grades mean. For the broader compliance context and preparation checklists, see our earlier guide to NDIS audits and compliance checks.

Who conducts the audit — and who pays for it?

NDIS audits are not conducted by the Commission itself but by approved quality auditors — independent auditing bodies approved by the NDIS Commission. You choose your auditor from the approved list, negotiate the price, and pay for it yourself. The auditor's job is to assess your organisation against the NDIS Practice Standards that apply to your registration groups and report the results to the Commission; the Commission — not the auditor — makes the final decision about your registration.

Verification or certification: which audit will you face?

The audit pathway is set by the risk of the supports you deliver, which flows from your registration groups (your "initial scope of audit" document states it):

  • Verification applies to lower-risk supports — for example therapy delivered by professionals with their own regulatory oversight, home modifications, or equipment supply. It is predominantly a desktop exercise: the auditor verifies qualifications, insurances, screening checks and a small set of required policies (complaints, incidents, risk management).
  • Certification applies to higher-risk supports — personal care, daily living assistance, Supported Independent Living, behaviour support and similar. This is the full two-stage process described below, assessed against the Practice Standards' core module plus any supplementary modules your groups trigger (such as high-intensity daily personal activities).

What happens in Stage 1 — the document review?

Stage 1 of a certification audit is a structured review of your organisation on paper, usually conducted remotely. The auditor works through your self-assessment and evidence: governance arrangements, policies and procedures, incident and complaints registers, worker screening records, training records, service agreements and consent documentation. The purpose is to test whether your system is capable of meeting the Practice Standards.

Stage 1 typically ends with a report identifying gaps to fix before Stage 2. Treat this as the gift it is — Stage 1 findings are cheap to fix; the same finding at Stage 2 is a non-conformity on your record.

What happens in Stage 2 — the site visit?

Stage 2 is where the audit becomes real. Auditors come on site (and to service delivery locations where relevant) and test whether the documented system actually operates. Expect them to:

  • Interview key personnel and staff — managers on governance and risk; support workers on what they'd do if a participant fell, how they report incidents, and what the complaints process is. Auditors are checking that frontline practice matches the policy manual.
  • Interview participants (with consent) — participants and, where appropriate, families are asked about their experience: whether they were involved in planning their supports, whether they know how to complain, whether they feel safe. Auditors must obtain consent for participant records they sample and the interviews they conduct.
  • Sample participant files — a selection of files is reviewed end to end: service agreements, support plans, progress notes, incident records, consent forms. Sampling means you cannot "prepare" three good files; any file may be pulled.
  • Inspect records and premises — training matrices, screening clearances, medication management records, restrictive practice authorisations if applicable, and the physical environment where supports are delivered.

Stage 2 typically takes one to several days depending on your size, number of sites and registration groups.

How are findings graded, and what do they mean?

Auditors record each requirement as conforming or as a non-conformity:

  • Minor non-conformity — an isolated lapse that doesn't indicate systemic failure (a gap in one training record, an incomplete register entry). You'll be asked to provide a corrective action plan and evidence of remediation within an agreed timeframe.
  • Major non-conformity — a systemic failure or one creating serious risk to participants (no functioning incident management system, unscreened workers delivering personal care). Majors must usually be remediated and re-verified — sometimes by a follow-up visit — before a positive recommendation can be made.

The auditor's report and recommendation then go to the NDIS Commission, which weighs it in its own suitability assessment. Non-conformities do not automatically sink an application — a credible, evidenced corrective response matters more than a spotless first pass.

What happens after the audit?

For successful applicants, registration is granted (often with conditions) for a set period — but the cycle continues: certification providers face a mid-term audit (a lighter check, roughly at the midpoint of the registration period, that your systems remain in place) and a full renewal audit before registration expires. Providers registering for the first time under the new SIL rules should diarise these from day one — the most common audit failure is simply letting systems drift between audits.

Key Takeaways

  • Audits are done by independent approved quality auditors you engage and pay; the NDIS Commission makes the final registration decision.
  • Lower-risk supports get a verification (desktop) audit; higher-risk supports get two-stage certification.
  • Stage 1 tests your system on paper; Stage 2 tests it in practice — through staff and participant interviews, file sampling and site inspection.
  • Findings are graded minor or major non-conformity; a strong corrective action response usually matters more than a perfect scorecard.
  • The cycle repeats — mid-term and renewal audits — so build compliance into daily operations rather than audit-week heroics.
Need Help Finding a Provider?

We'll match you with trusted, local disability providers — free and fast.

Find a Provider
Advertisement Audit Pilot — stop preparing for audits, stay ready. NDIS compliance, autonomously managed 24/7.