NDIS Verification vs Certification Audit: Which Audit Do You Need?
Compliance
7 August 2026
NDIS Verification vs Certification Audit: Explore the differences between them, which one your organisation needs & how to properly prepare.
Registering as an NDIS provider means one thing is unavoidable: an audit. But not all audits are the same, and which type applies to your organisation is determined entirely by the supports you're registering to deliver.
Understanding the difference between an NDIS verification audit and an NDIS certification audit upfront can save you months of misdirected preparation, unnecessary cost, and real stress. Here's what you need to know.
Key Insights
Your audit type is set by your registration groups, not by your size, experience, or preference
Verification audits are desktop-only document reviews for lower-risk supports
Certification audits involve two stages, including an on-site visit, for higher-risk or complex supports
If even one of your registration groups requires certification, your entire application goes through the certification pathway
SIL providers must be registered by 1 July 2026, and SIL requires a certification audit
What Determines Your Audit Type?
The NDIS Practice Standards are broken down into modules: a core module that applies to all registered providers delivering higher-risk supports and services, supplementary modules that apply depending on the types of supports being delivered, and a verification module that applies to all registered providers delivering lower-risk supports and services.
Which audit type applies to your organisation is determined entirely by the registration groups you select when applying to the NDIS Commission. When you submit your application, the Commission assigns an audit pathway based on those groups. You'll receive an Initial Scope of Audit document confirming which pathway applies.
A verification audit is required for providers delivering lower-risk or lower-complexity supports and services. A certification audit is required for providers delivering more complex or higher-risk supports and services.
For a full breakdown of which modules apply to each registration group, the NDIS Commission publishes the Registration Requirements by Supports and Services document. This is the authoritative source to cross-reference against your intended supports.
What is an NDIS Verification Audit?
An NDIS verification audit is a desktop review. There is no on-site visit, no participant interviews, and no observation of your service delivery. The auditor assesses whether your organisation's documentation demonstrates that you meet the relevant Practice Standards outcomes.
Auditors review key areas including insurance policies (such as public liability and professional indemnity), qualifications and experience of staff and key personnel, and policies and procedures for risk management, incidents, and complaint handling.
Verification typically applies to supports with lower direct participant contact, such as assistive technology, home modifications, vehicle modifications, therapeutic supports, and community nursing care. Allied health providers registering under group 0128 (Therapeutic Supports), for example, need AHPRA registration, professional indemnity insurance, and incident management and complaints policies.
The required documentation for verification audits is listed in the Commission's Verification Module Required Documentation Guide, updated May 2025.
What is an NDIS Certification Audit?
An NDIS certification audit applies to providers delivering higher-risk or complex supports, such as personal care, daily activities, supported independent living, specialist behaviour support, and others where participants depend on a provider for their day-to-day safety and wellbeing.
The certification audit process runs in two stages. Stage 1 is a documentation review (similar to a verification audit) that assesses policies, procedures, and your self-assessment. Stage 2 is an on-site assessment in which the auditor visits your service, reviews records and files, and interviews a sample of key personnel, staff, and participants to confirm that policies are understood and consistently applied in practice.
If you register for even one support type that triggers certification, your entire application goes through the certification pathway. This catches many providers off guard, particularly those adding a new high-risk registration group to an existing lower-risk registration.
You can read a full module-by-module breakdown of what the certification pathway involves in our NDIS Practice Standards module walkthrough.
Quick Comparison: NDIS Certification Audit vs Verification Audit
Verification audit | Certification audit | |
Risk level | Lower-risk, lower-complexity supports | Higher-risk, complex supports |
Audit method | Desktop document review only | Stage 1 (desktop) + Stage 2 (on-site) |
On-site visit? | No | Yes |
Participant interviews? | No | Yes |
Practice Standards | Verification Module | Core Module + supplementary modules |
Timeline | Generally shorter | 8–16 weeks typical |
Triggered by | Verification-only registration groups | Any certification registration group |
For a deeper dive into how the two pathways sit alongside each other, see our dedicated verification versus certification audit explainer.
Can Your Audit Type Change?
Yes, but only by changing your registration groups. If you initially registered under verification-only groups and subsequently wish to add a certification-required group, you must apply to vary your registration and undergo a certification audit for the new scope. Your existing verification registration does not convert automatically. Conversely, if you hold certification registration and choose to surrender certain certification-required groups at renewal (retaining only verification groups), your renewal audit may be a verification audit.
So if your organisation is growing and adding new support types, it's worth understanding this trigger early. Our NDIS SIL registration guide specifically covers this for providers moving into supported independent living.
A Note on the 1 July 2026 SIL Deadline
This is urgent for a specific group of providers. From 1 July 2026, all providers of Supported Independent Living (group 0115) and platform-based providers must be registered with the NDIS Commission. This obligation was created by the NDIS Amendment (Integrity and Safeguarding) Act 2026, which passed Parliament on 31 March 2026. Delivering SIL without registration after that date is a criminal offence carrying a maximum of 5 years imprisonment for an individual. SIL registration requires a certification audit.
Audit wait times of 8–16 weeks are realistic. Providers who haven't started the process are already working against the clock.
Preparing For Either Audit Type
The core principle is the same regardless of pathway: your documentation needs to reflect how your organisation actually operates, not just what looks good on paper.
For practical preparation, our NDIS audit checklist outlines the key documentation requirements for both pathways. If you're going through this for the first time, our first NDIS audit walkthrough is a good starting point. And if you want everything in one place, the NDIS audit guide covers the process end-to-end.
Not sure where your preparation currently stands? Check your audit readiness score to see exactly where your gaps are before an auditor does.
Written by

James Driscoll
Writer
Community Manager for Willow , heywillow.ai. Helping healthcare, aged care, and NDIS providers ditch the compliance spreadsheets for AI-powered intelligence.
Latest Articles & Guides
Stay informed with the latest guides and news.
Ready to Move From Reactive to Continuous Compliance?
See how Willow supports structured governance, real-time monitoring, and audit-ready operations.



