Your First NDIS Audit: A New Provider's Day-by-Day Walkthrough

Compliance

7 August 2026

Going through your first NDIS audit? This guide covers audit types, NDIS audit questions, timelines & where new providers most often get caught out.

The NDIS audit questions you'll face aren't secret. The process isn't a trap, but for a new provider, it can still feel deeply unclear. Like preparing for an exam when no one's told you the subject.

This guide covers exactly what happens before, during, and after your first audit, so you can move through it with confidence.


Key Takeaways 

  • Your audit type (verification or certification) is determined by your registration groups, not by you

  • Auditors assess your systems in practice, not just your policies on paper

  • The most common failure point is the gap between what documents say and what staff actually do

  • NDIS audit questions vary but consistently test governance, worker screening, incident management, and participant rights

  • From preparation to registration decision, expect 3–12 months total

First: Which Audit Are You Getting?

Before anything else, you need to know whether you're facing a verification or certification audit. The NDIS Commission's Initial Scope of Audit document tells you which type applies. Verification is for low-risk, low-complexity supports, while certification is for higher-risk services. 

Certification audits run in two stages. Stage 1 is an initial evaluation of your organisation's management system; essentially a readiness check where auditors review your business on paper to see if you're set up to meet the NDIS Practice Standards. Stage 2 moves to direct assessment: interviews, evidence sampling, and observed practice. 

Knowing your audit type early shapes your documentation requirements, your timeline, and the level of preparation your team needs.

The Days Before: What You Need to Have Ready

Think of your audit preparation in three layers.

Layer 1: Policies that match your registration groups

Template-based documentation that doesn't reflect your actual operations is something auditors spot immediately. The language is generic, the procedures don't match the service model, and staff can't explain them. The NDIS Commission has explicitly warned against this. 

Your policies need to describe your service, not a hypothetical one.

Layer 2: Evidence that your systems work

Auditors will want to see documentary evidence that your policies meet the relevant Practice Standards, proof of current worker screening checks and qualifications, evidence of a functional complaints and incident management system, and a continuous improvement register showing documented actions. Even if you're a new provider with no incidents yet, the system must exist.

An empty register isn't a red flag by itself. A missing register is.

Layer 3: Workers who can explain what they do

This is where many new providers get caught out. A provider may have excellent policies, but staff cannot explain them in interviews. That disconnect creates compliance risk. 

Brief your team on your incident reporting process, complaints handling, and participant rights before the audit date. Auditors will ask.

Use our NDIS audit checklist to work through documentation requirements registration group by registration group, and cross-check your readiness against the NDIS Practice Standards checklist before you engage an auditor.

The NDIS Audit Questions You Should Expect

For participants, auditors typically ask questions such as: How often do you discuss your support needs with your provider? Are you happy with the supports provided? How does your provider consider your needs and preferences? What do you do if you are unhappy about your support? 

For your organisation's key personnel and staff, the NDIS audit questions focus on systems and real-world application:

  • How do you identify and assess the needs of participants?

  • What happens when a participant makes a complaint?

  • How do you manage risks in service delivery?

  • What training have you completed, and where are the records?

  • How do you ensure participant rights are upheld day to day?

Auditors ask questions to test your systems. A common example: "What training have you received in privacy and confidentiality?" Having a signed training record on file lets you answer that question with evidence, not assurance. 

For providers delivering higher-risk supports, your leadership team will also be interviewed. If they can't articulate how governance, risk management, and quality systems work in practice, it raises serious concerns about organisational capability. 

During the Audit: What the Process Looks Like

During an audit, auditors evaluate how well your organisation operates. They review your daily practices, procedures, and the overall quality of your services. Depending on your audit type, this may involve desktop document review only (verification) or a combination of document review, staff interviews, and participant conversations (certification). 

If an auditor speaks with participants, they will let them know that everything they say is confidential, check that they're still happy to chat, and ask simple questions about their experience with your service.

The audit isn't adversarial. Auditors aren't looking for a reason to reject you. They're trying to determine whether your organisation can deliver safe, quality supports.

After the Audit: Non-Conformities and What Happens Next

The outcome of the audit is an audit report with a rating for how well you comply with each NDIS Practice Standard and quality indicator. If you receive a major non-conformity rating in any area, you have three months to fix the issue. Your registration won't progress until you've addressed it and successfully completed the quality audit. 

Minor non-conformities don't stop registration, but they do require a corrective action plan.

When the audit is complete, the auditor may ask you to fix any issues identified, then submits a recommendation to the NDIS Commission. The Commission considers that recommendation and assesses your suitability as a provider, including your key personnel. They may ask for additional information before making a final decision.

After the audit is complete, the Commission's review and registration decision typically takes 4 to 8 weeks, though complex applications can take longer. 

For providers registered under higher-risk groups, the process doesn't stop there. Certified providers are required to complete an initial audit, a mid-term audit within 18 months of registration approval, and a recertification audit every three years. 

If you're preparing to offer SIL supports specifically, our NDIS SIL registration guide covers the additional requirements that apply from July 2026 onward.

Where New Providers Most Often Struggle

The same issues appear across audit cycles:

  • Incident management gaps. Your reportable incidents workflow needs to be documented, understood by staff, and actively used. An untested system is a liability. Our reportable incidents workflow guide walks through what that system needs to cover.

  • Worker screening lapses. Auditors fail providers when workers don't have valid NDIS Worker Screening Checks or when checks have expired without renewal. Track screening expiry dates and set reminders at least 60 days before renewal is due. 

  • Support plans that are too vague. Generic goals don't satisfy the Practice Standards. Plans need measurable outcomes tied to each participant's specific situation.

How Long Will This Take?

NDIS registration typically takes between three and six months from application submission to approval, though the timeline varies depending on your level of preparation, the type of audit required, and the Commission's review period. Certification audits for new providers can run longer. 

The single biggest variable is how ready your documentation is before you engage an auditor. Gaps that lead to non-conformances can add weeks or months. Starting the process well-prepared consistently produces shorter, smoother timelines.

If you want a structured view of where you stand right now, check your audit readiness score. It takes a few minutes and gives you a clear picture of what's in good shape and what needs attention before you approach an auditor. For the complete process overview, our NDIS audit guide covers everything from application through to renewal.

Written by

James Driscoll

Writer

Community Manager for Willow , heywillow.ai. Helping healthcare, aged care, and NDIS providers ditch the compliance spreadsheets for AI-powered intelligence.

Latest Articles & Guides

Stay informed with the latest guides and news.

Ready to Move From Reactive to Continuous Compliance?

See how Willow supports structured governance, real-time monitoring, and audit-ready operations.