NDIS Audit Checklist

How to Prepare for Certification and Verification Audits

Preparing for an NDIS audit can feel overwhelming for many providers.

Whether you are undergoing your first NDIS certification audit or preparing for a verification audit, the process requires clear documentation, structured evidence, and strong alignment with the NDIS Practice Standards.

Auditors expect providers to demonstrate that their systems, policies, and operational practices meet the regulatory requirements set by the NDIS Quality and Safeguards Commission.

This guide provides a comprehensive NDIS audit checklist to help providers prepare for audits with confidence.

In this guide you will learn:

What an NDIS audit involves

The difference between certification and verification audits

The documentation auditors typically review

Common compliance gaps providers encounter

A practical checklist to prepare for your audit

Download

Fill out the form and receive your free NDIS Audit Checklist

What is an NDIS Audit?

An NDIS audit is an independent assessment conducted to determine whether a provider complies with the NDIS Practice Standards and regulatory requirements established by the NDIS Quality and Safeguards Commission.

Audits are required for providers seeking to become registered NDIS providers and for organisations renewing their registration.

The purpose of the audit process is to ensure that providers:

Deliver safe and high-quality services

Maintain effective governance and risk management systems

Protect participant rights and wellbeing

Operate in accordance with NDIS regulatory standards

During an audit, auditors review policies, procedures, operational records, and other evidence demonstrating that the provider meets the relevant Practice Standards.

NDIS Certification vs Verification Audits

NDIS providers may be required to undergo either a certification audit or a verification audit, depending on the types of services they deliver.

Audit Type

Audit Type

Who Requires It

Who Requires It

Scope

Scope

Certification Audit

Certification Audit

Providers delivering higher-risk supports

Providers delivering higher-risk supports

Full NDIS Practice Standards

Full NDIS Practice Standards

Verification Audit

Verification Audit

Providers delivering lower-risk supports

Providers delivering lower-risk supports

Core module only

Core module only

Certification audits typically involve a more comprehensive assessment because they apply to services that involve greater participant risk.

Verification audits are generally shorter and focus on core operational compliance.

Understanding which audit applies to your organisation is an important first step in preparing for NDIS compliance.

NDIS Audit Preparation Checklist

Preparing for an NDIS audit requires documentation across multiple operational areas.

The checklist below outlines key areas that auditors typically review when assessing compliance with the NDIS Practice Standards.

Governance and Management

Auditors expect providers to demonstrate clear governance and oversight of their operations.

Providers should ensure they have documentation covering:

Organisational governance structure

Leadership roles and responsibilities

Risk management framework

Quality management systems

Continuous improvement processes

Board and leadership oversight of quality and compliance should be clearly documented.

Policies and Procedures

Policies must align with the NDIS Practice Standards and reflect how services are delivered in practice.

Auditors typically review documentation such as:

Participant safeguarding policies

Complaints and feedback management procedures

Incident management policies

Risk management procedures

Privacy and confidentiality policies

Policies should be regularly reviewed and accessible to staff.

Workforce Compliance

Providers must demonstrate that their workforce is appropriately trained and supported.

Key documentation includes:

Worker screening checks

Staff training records

Employee role descriptions

Supervision and performance management documentation

Induction training processes

Auditors often review evidence showing that staff understand the policies relevant to their roles.

Incident Management

Incident management systems are a critical part of NDIS compliance.

Providers should maintain clear records of:

Incident reporting procedures

Incident investigation processes

Incident registers

Corrective actions and follow-up activities

The organisation must demonstrate that incidents are reviewed and addressed appropriately.

Restrictive Practices

Providers supporting participants with behaviour support plans must comply with strict requirements regarding restrictive practices.

Auditors may review:

Behaviour support plans

Authorisation documentation for restrictive practices

Monitoring and review processes

Reporting procedures

Clear documentation is essential to demonstrate compliance in this area.

Participant Documentation

Participant records should demonstrate that services are delivered in accordance with the NDIS Practice Standards.

Examples include:

Participant service agreements

Consent documentation

Participant care records

Support plans and goals

Service delivery documentation

Records should be accurate, complete, and securely stored.

Common NDIS Audit Non-Conformities

During audits, providers often receive non-conformities when documentation or operational practices do not fully meet regulatory expectations.

Common issues include:

Missing or incomplete staff training records

Inconsistent incident documentation

Policies that do not align with NDIS Practice Standards

Limited evidence of governance oversight

Gaps in restrictive practices documentation

Addressing these areas before an audit significantly improves the likelihood of a successful outcome.

Understanding the NDIS Compliance Framework

The NDIS regulatory system follows a structured compliance framework used by auditors when assessing providers.

This framework typically follows a hierarchy:

Framework

Standard

Requirement

Evidence

Assessment

Action

Providers must be able to demonstrate that their policies, operational processes, and documentation align with each relevant requirement within the NDIS Practice Standards.

Maintaining structured evidence and clear documentation makes it significantly easier to demonstrate compliance during audits.

How Compliance Software Helps With NDIS Audits

Many providers manage compliance using spreadsheets and manual documentation systems.

As organisations grow, these approaches can become difficult to manage.

Dedicated compliance platforms help providers:

Centralise policies and documentation

Map evidence to NDIS Practice Standards

Track compliance status across requirements

Monitor remediation actions

Generate audit evidence packs

This allows providers to move from reactive audit preparation to continuous compliance monitoring.

Learn more about how structured compliance platforms work on our NDIS Compliance Software page.

Related Compliance Resources

You may also find these resources helpful:

NDIS Compliance Software

ACQS 2025 Explained

Aged Care Compliance Software

Healthcare Compliance Frameworks

Frequently asked questions

Frequently asked questions

Find answers to common questions about Willow and how it can benefit your business

Find answers to common questions about Willow and how it can benefit your business

How long does an NDIS audit take?

Certification audits often take several days depending on the size of the organisation and the number of service registrations.

Verification audits are typically shorter and focus on core operational requirements.

What happens if a provider fails an NDIS audit?

If a provider receives non-conformities during an audit, they are usually required to implement corrective actions within a specified timeframe.

Evidence must then be provided demonstrating that the issues have been resolved.

How often do NDIS audits occur?

NDIS providers typically undergo audits during initial registration and periodically during renewal of their registration.

Audit frequency can vary depending on the type of services delivered.

What documents do auditors request?

Auditors commonly review:

  • Policies and procedures

  • Staff training records

  • Incident registers

  • Participant records

  • Governance documentation

  • Quality improvement plans

Providers should maintain clear and accessible documentation across these areas.

How long does an NDIS audit take?

Certification audits often take several days depending on the size of the organisation and the number of service registrations.

Verification audits are typically shorter and focus on core operational requirements.

What happens if a provider fails an NDIS audit?

If a provider receives non-conformities during an audit, they are usually required to implement corrective actions within a specified timeframe.

Evidence must then be provided demonstrating that the issues have been resolved.

How often do NDIS audits occur?

NDIS providers typically undergo audits during initial registration and periodically during renewal of their registration.

Audit frequency can vary depending on the type of services delivered.

What documents do auditors request?

Auditors commonly review:

  • Policies and procedures

  • Staff training records

  • Incident registers

  • Participant records

  • Governance documentation

  • Quality improvement plans

Providers should maintain clear and accessible documentation across these areas.

Download the NDIS Audit Preparation Checklist

Preparing for an NDIS audit is much easier with a structured checklist.

Download our NDIS Audit Preparation Checklist to ensure your organisation is ready for certification or verification audits.

The checklist covers:

Governance preparation

Compliance documentation

Workforce requirements

Incident management processes

Participant record management