NDIS audit readiness: the provider’s guide
NDIS audit readiness means knowing which audit applies to you, how it runs, what the auditor will ask to see, and whether your records show your practice and not only your policies. The audit is carried out by an approved quality auditor you engage, against the NDIS Practice Standards, under the oversight of the NDIS Commission. A certification audit has a desktop stage and an onsite stage within 3 months.
Key takeaways
- The audit type depends on the risk and complexity of your supports: verification, certification, mid-term, condition or out of cycle.
- A certification audit has Stage 1 (desktop) and Stage 2 (onsite, within 3 months after Stage 1). A mid-term audit falls 18 months into the registration period.
- Auditors ask for real examples and observe whether supports match the participant’s plan. Participants are included in audits unless they opt out.
- Ratings run from 3 to 0. A major non-conformity must be fixed within 3 months.
Which NDIS audit applies to you?
| Audit | Applies to | How it works |
|---|---|---|
| Verification | Providers delivering only lower risk or lower complexity supports | An approved quality auditor completes a desktop review of documentary evidence. The report is submitted up to 14 days after |
| Certification | Providers delivering one or more higher risk or more complex supports | Stage 1 desktop audit, then Stage 2 onsite audit within 3 months. The report is submitted up to 28 days after |
| Mid-term | Providers who initially completed a certification audit | Completed 18 months into the registration period |
| Condition | Any provider the Commission requires to be audited | Can be imposed, for example when minor non-conformities are outstanding or ownership changes |
| Out of cycle | A provider changing its registration | Organised by the provider at any time to support a change application |
The Commission’s initial scope of audit tells you the type you need, and the registration groups table shows which audit each support requires.
What happens on the day?
The Commission describes an opening meeting, then a review of leadership, risk systems, incident management, staff files, participant records and interviews. The focus moves quickly from what policies say to what actually happens. Auditors ask for real examples such as incident reports, complaints records, training logs and supervision notes, sample staff files, interview participants privately, and observe whether supports match the participant’s plan. A closing meeting summarises strengths and any gaps.
How do you prepare?
- Confirm the audit type from your initial scope of audit and registration groups.
- Engage an approved quality auditor. Registration itself is free, but you pay for the audit. The Commission encourages comparing quotes and does not set audit prices.
- Test your records against your own policies. Sample recent participant records against each participant’s plan and goals. Use the NDIS audit checklist for a documentation sample.
- Trace an incident end to end. The Commission describes auditors following a reported incident from the first report through review, actions and notification.
- Organise staff files: screening clearances, qualifications, induction and training and supervision records.
- Tell participants. For a certification audit, participants are automatically included unless they opt out, and you must tell them so.
- Keep records current. The Commission advises keeping records up to date to support audit evidence and decision making.
What happens after the audit?
The auditor gives each Practice Standard and quality indicator a rating from 3 to 0 and submits the report to the Commission. In the Commission’s case study, the provider checked the draft for factual accuracy before it was finalised. A minor non-conformity gives a longer time to fix and the process continues. A major non-conformity must be fixed within 3 months. The Commission says a non-conformity does not mean the provider has failed. See why shift note failures can become audit findings.
Where does NoteGate help?
NoteGate checks shift notes before they are saved, keeps their correction history, and builds an audit pack from daily records. It supports documentation governance. It does not choose your audit type, replace your auditor or determine the outcome. See the NoteGate audit pack and NDIS audit evidence.
Frequently asked questions
Who conducts an NDIS audit?
An independent approved quality auditor that you engage, not the NDIS Commission itself. The Commission oversees the process and approves the auditors.
How long is the gap between certification audit stages?
The Stage 2 onsite audit should take place in the 3 months after the Stage 1 desktop audit is complete.
When is a mid-term audit?
A mid-term audit is completed 18 months into the registration period, for providers who initially completed a certification audit and are registered for higher risk or more complex supports.
How much does an NDIS audit cost?
There is no cost to register with the Commission, but the provider pays an approved quality auditor. The cost depends on the size and scale of the organisation and the number of participants, and the Commission does not set prices.
Are participants involved in the audit?
Yes. Participants are automatically included and may be interviewed or have records reviewed unless they opt out, and you must let them know.
Sources
- Types of audits (NDIS) (NDIS Quality and Safeguards Commission, retrieved 28 September 2026)
- NDIS Practice Standards and Quality Indicators (NDIS Quality and Safeguards Commission, retrieved 28 September 2026)
Related
Have the audit evidence ready before the audit is booked
See how NoteGate builds the audit pack from daily records.
Book a 20-minute walkthroughChoose a plan