
Preparing for an NDIS audit requires more than collecting policies and uploading documents. Providers need to demonstrate that their systems are suitable for their services, workers understand their responsibilities, and compliance processes work in practice.
Quick Answer
An NDIS certification audit assesses whether a provider meets the applicable NDIS Practice Standards. In practice, preparation should cover policies, governance, worker records, participant documentation, risk management, incidents, complaints and evidence that systems are implemented effectively. However, the exact requirements depend on your registration groups, services and audit scope. An Approved Quality Auditor conducts the audit, while the NDIS Commission considers the audit outcome as part of the registration process.
NDIS Audit: What Is a Certification Audit?
An independent Approved Quality Auditor assesses providers against the applicable NDIS Practice Standards. Generally, a certification audit applies to providers delivering higher-risk or more complex NDIS supports and services.
Typically, a certification audit involves two stages. During Stage 1, the auditor conducts a desktop review of information and evidence. Then, during Stage 2, the auditor assesses how the provider implements its policies and procedures in practice. The onsite stage may include reviewing records, visiting sites, interviewing workers and participants, and observing service delivery.
Before you begin preparing, check the current NDIS quality audit process and certification audit guidance from the NDIS Quality and Safeguards Commission.
However, your audit pathway does not simply depend on whether you operate a large or small disability business. Instead, it depends largely on the registration groups, supports and services you intend to deliver. The NDIS Commission provides an Initial scope of audit that identifies the type of audit, registration groups, service delivery types and relevant standards.
For this reason, reviewing your NDIS registration requirements should be one of the first steps in your preparation.
NDIS Audit Preparation: Where Should You Start?
First, start with your audit scope.
Your scope helps identify the registration groups, service delivery types and applicable standards that the auditor needs to assess. Once you understand the scope, you can build an evidence checklist around the requirements that apply to your organisation.
A practical preparation process looks like this:
- First, review your registration groups.
- Next, confirm the applicable audit pathway.
- Then, review the relevant NDIS Practice Standards.
- Match each requirement with supporting evidence.
- After that, identify missing or outdated documents.
- Check whether workers understand the relevant procedures.
- Next, review participant and operational records.
- Test whether your systems work in practice.
- Then, address identified gaps.
- Finally, organise your evidence so workers can locate it easily.
As a result, this approach is usually more useful than simply creating a large folder of policies.
If you need assistance reviewing your documentation, systems and readiness, Providers Consultant can assist with NDIS audit preparation.
NDIS Audit: What Documents Should You Prepare?
However, there is no single document pack that suits every NDIS provider.
Instead, your registration groups, services, workforce and operations determine the evidence you need. Therefore, review the areas below and make sure your documentation reflects your actual organisation.
NDIS Audit Evidence for Governance
For example, governance evidence may include:
- organisational structure
- key personnel information
- roles and responsibilities
- delegations
- conflict-of-interest arrangements
- risk management systems
- quality management processes
- continuous improvement records
- management meeting records
- business continuity arrangements.
Most importantly, your documentation should remain consistent with your actual operations.
For example, your governance documents should show how your organisation actually operates. If a policy says management reviews risks monthly but your records show no reviews, the auditor may identify that gap during the assessment.
NDIS Audit Evidence for Workers
In addition, providers should review worker records carefully.
Depending on your services, check that you have appropriate evidence relating to:
- worker screening
- qualifications
- registrations or professional memberships where applicable
- position descriptions
- employment or engagement arrangements
- induction
- training
- supervision
- competency assessments
- ongoing professional development.
Furthermore, the NDIS Commission provides specific information about worker screening requirements. Providers should therefore review the current requirements relevant to their circumstances.
However, don’t assume that having a worker’s name on a spreadsheet is enough. Instead, keep supporting evidence organised and current.
NDIS Audit: Are Your Policies Actually Being Used?
Unfortunately, this is one of the areas providers can overlook.
However, a policy can look complete while the business operates differently.
For example, your complaints procedure might require every complaint to be recorded in a complaints register. During your internal review, check whether the register exists and whether your team has managed previous complaints according to the procedure.
Similarly, review how your organisation handles:
- incident management
- risk management
- worker training
- participant feedback
- privacy
- emergency management
- medication management, where applicable
- restrictive practices, where applicable.
As a result, support your policies with evidence from your actual operations.
If needed, Providers Consultant can also help providers review their NDIS policies and procedures so the documentation reflects the organisation’s actual services and processes.
Participant Records and Service Delivery Evidence
Similarly, participant documentation should show that your organisation delivers supports appropriately and consistently.
For example, depending on your services, review whether participant records contain appropriate evidence relating to:
- intake
- consent
- service agreements
- participant rights
- risk assessments
- support planning
- service delivery
- communication
- feedback
- incidents
- complaints
- changes to support arrangements.
Most importantly, avoid creating records simply to make an audit folder look complete.
Instead, your records should reflect genuine service delivery, and your organisation should maintain them according to its obligations.
In addition, participant information should be handled securely. Never include confidential information in material prepared for an external audience unless there is an appropriate reason and lawful basis.
Risk Management Checklist
In practice, your risk management system should be active rather than purely documentary.
First, review whether you have identified relevant risks across areas such as:
- participant safety
- worker safety
- service delivery
- emergency situations
- business continuity
- information management
- incidents
- complaints
- subcontractors
- environmental risks.
Next, for each significant risk, consider whether you have documented:
- the risk
- the potential impact
- existing controls
- additional actions
- responsibility
- review dates.
However, if your team has not reviewed the risk register for a long period, the register may not demonstrate effective ongoing risk management.
Therefore, make regular review part of your normal compliance process rather than treating it as an activity you complete only before an audit.
Incident and Complaints Management
Before the audit, carefully review your incident and complaints records.
During this review, ask yourself:
- Are incidents recorded consistently?
- Are serious incidents escalated appropriately?
- Can management identify recurring problems?
- Are complaints followed up?
- Is there evidence of corrective action?
- Have lessons from incidents or complaints resulted in improvements?
Most importantly, consider the final question carefully.
Information from incidents, complaints and feedback should contribute to continuous improvement. Therefore, review the NDIS Commission’s complaints management guidance when you check your current processes.
Continuous Improvement Evidence
Importantly, auditors may look beyond policies to see whether the provider actually monitors and improves its systems.
Auditors may review evidence such as:
- internal reviews
- participant feedback
- worker feedback
- complaint trends
- incident reviews
- management meetings
- corrective actions
- improvement registers
- policy reviews
- changes made following identified problems.
For this reason, a simple improvement register can make this process easier.
For example, you can record the issue, required action, responsible person, due date and outcome in a simple table.
| Issue identified | Action required | Responsible person | Due date | Outcome |
|---|---|---|---|---|
| Training records incomplete | Review worker files | Compliance manager | Set date | Records updated |
| Emergency procedure outdated | Review procedure | Management | Set date | New procedure implemented |
| Participant feedback identified gap | Review process | Operations | Set date | Process improved |
Ultimately, the purpose is not to create paperwork for its own sake. Instead, the register should demonstrate that your organisation identifies issues and responds to them.
Common NDIS Audit Preparation Mistakes
Preparing only policies
Policies are important, but they are only one part of your evidence.
However, auditors may need to see how procedures are implemented through records, registers, worker files and operational evidence.
Using generic templates without customisation
Templates can save time, but you should adapt them to your organisation.
Similarly, a sole trader providing one type of support may have very different systems from a larger provider employing dozens of workers.
Therefore, your documents should reflect your actual business rather than simply copying generic wording.
Leaving preparation until the final week
Unfortunately, last-minute preparation can expose gaps when there is little time to address them.
For this reason, start early enough to review records, identify missing evidence and give workers time to understand their responsibilities.
Ignoring old records
Although current policies are useful, historical records can also demonstrate how systems have operated over time.
Therefore, review relevant records for consistency and completeness.
Forgetting to check worker files
In addition, worker documentation can be easily overlooked when management focuses heavily on policies.
As a result, create a worker-file checklist and review each file against your requirements.
Not testing your systems
Most importantly, test whether your systems work in practice by asking workers practical questions.
For example:
- Where would you report an incident?
- Who do you contact if a participant makes a complaint?
- Where can you find the emergency procedure?
- What should you do if you identify a serious risk?
- How do you protect participant information?
If workers cannot answer basic questions, you may have a training or implementation gap.
What Happens If a Non-Conformity Is Identified?
An audit can identify minor or major non-conformities. The appropriate response depends on the nature of the finding and the applicable requirements.
However, providers should not assume that changing a policy will fix every finding. Instead, identify the underlying problem and address its cause.
Depending on the finding, corrective action may involve:
- changing a process
- updating documentation
- providing additional training
- improving record keeping
- implementing a new control
- reviewing responsibilities
- providing evidence that the organisation has addressed the problem.
The NDIS Commission uses audit ratings that distinguish between conformity, minor non-conformity and major non-conformity. Therefore, providers should understand the significance of any findings and respond within the applicable requirements and timeframes.
Providers Consultant can provide NDIS compliance support to help organisations review identified gaps and develop practical corrective actions. However, the independent auditor determines audit findings, while the NDIS Commission makes the relevant registration decisions.
What Should You Do After the Certification Audit?
Audit preparation shouldn’t stop when the auditor leaves.
After the audit, registered providers need to maintain their systems and continue meeting applicable obligations.
For example, regularly review:
- worker screening
- training
- incidents
- complaints
- risks
- participant records
- policies
- governance
- continuous improvement
- emergency arrangements.
Depending on your registration and circumstances, further audit activity may also apply. For example, providers that complete a certification audit may need to complete a mid-term audit during their registration period.
Therefore, providers approaching another audit stage should review the Commission’s current audit requirements and consider whether their systems remain effective.
Providers Consultant also offers NDIS audit and compliance support for providers that need assistance maintaining their documentation and compliance systems.
NDIS Certification Audit Checklist
Before your audit, work through this final checklist.
Business and governance
- Registration details are current
- Registration groups have been reviewed
- Key personnel information is current
- Governance responsibilities are clear
- Risk register is current
- Continuous improvement process is active
Policies
- Policies match current operations
- Workers understand the relevant procedures
- Documents have appropriate review dates
- Version control is maintained
- Relevant forms and registers are available
Workers
- Worker screening has been checked
- Qualifications are documented
- Position descriptions are current
- Induction records are complete
- Your organisation keeps training records current
- Competency evidence is available where applicable
- Supervision arrangements are documented
Participants
- Service agreements are maintained
- Consent records are available
- Risk assessments are current
- Participant records are complete
- Feedback is documented
- Your organisation manages complaints appropriately
- Incidents are recorded and reviewed
Compliance systems
- Incident register is current
- Complaints register is current
- Risk register is reviewed
- Improvement register is maintained
- Emergency procedures are current
- Corrective actions are documented
- Evidence is easy to locate
Frequently Asked Questions
How long does NDIS audit preparation take?
There is no single preparation timeframe that suits every provider. For example, a small provider with well-maintained systems may need less preparation than an organisation with multiple registration groups, workers and service locations. Therefore, start early enough to review the applicable standards, check evidence and address gaps before the external audit.
What does an NDIS certification audit check?
A certification audit checks whether the provider conforms with the applicable NDIS Practice Standards and quality indicators. Depending on the scope, the auditor may review governance, workers, participant records, risk management, incidents, complaints, service delivery and other relevant systems. The certification process can also include site visits, interviews and observations.
Do policies need to be customised for an NDIS provider?
Yes, policies should reflect the provider’s actual operations. Although generic templates can provide a starting point, providers should review and adapt them to the organisation’s services, workforce, structure and registration requirements.
What is the difference between verification and certification?
Verification and certification are different audit pathways. Generally, verification applies to lower-risk or lower-complexity supports and services, while certification applies to higher-risk or more complex supports and services. Therefore, the appropriate pathway depends on the registration groups and services being delivered.
Can a consultant guarantee that I will pass my NDIS audit?
No. A consultant can help you prepare documents, review systems and identify potential gaps, but cannot guarantee an audit outcome. Instead, an Approved Quality Auditor independently assesses conformity against the applicable requirements.
What happens if I receive a non-conformity?
You may need to undertake corrective action. However, the response depends on whether the finding is minor or major and the requirements applying to your audit. Therefore, providers should address the underlying problem and retain appropriate evidence of the action taken. The NDIS Commission provides specific timeframes and processes for addressing audit findings.
Do registered providers need ongoing compliance after an audit?
Yes. Passing an audit does not remove the provider’s ongoing responsibilities. Instead, registered providers need to maintain applicable systems, records, worker requirements, incident and complaint processes, risk controls and other obligations throughout their registration period.
Final Thoughts
A strong NDIS audit preparation process is not about creating the biggest folder of documents.
Instead, it is about making sure your policies, workers, records and day-to-day systems tell the same story.
First, start with your audit scope. Then, review the applicable Practice Standards and check your evidence. Next, speak with workers and review participant and operational records. Finally, address identified gaps before the formal assessment.
If you need assistance reviewing your readiness, Providers Consultant’s NDIS audit support can help you work through your documentation and compliance requirements.
Ultimately, the NDIS Commission remains the regulator, while Approved Quality Auditors conduct the independent quality audits. Providers should always check current official guidance because requirements can change.
Disclaimer
This article provides general information only. NDIS requirements may change and can vary according to a provider’s registration groups, services, structure and circumstances. Providers should review current NDIS Commission guidance and obtain appropriate professional advice where required.