Preparing participant records for an NDIS audit
NDIS providers are audited by an approved quality auditor against the NDIS Practice Standards. A verification audit is a desktop review of documents for lower risk supports. A certification audit has a desktop stage and an onsite stage where the auditor looks at how policies work in practice, including participant records.
Key takeaways
- The type of audit depends on the risk and complexity of the supports delivered, as set out in the provider’s registration groups.
- A certification audit has Stage 1 (desktop) and Stage 2 (onsite), with Stage 2 due within 3 months of Stage 1.
- Auditors want real examples such as incident reports, complaints records and participant records, not only policies.
- A non-conformity does not mean the provider has failed; it needs correcting within a set timeframe.
What types of NDIS audit are there?
The NDIS Commission describes several audit types. A verification audit is for low risk, low complexity supports. A certification audit is for higher risk supports. A mid-term audit applies to providers who initially completed a certification audit and is completed 18 months into the registration period. The Commission can require a condition audit, and an out of cycle audit may be needed when a provider changes the supports it delivers.
| Audit | For | How it works |
|---|---|---|
| Verification | Lower risk, lower complexity supports | An approved quality auditor completes a desktop review of required documentary evidence |
| Certification | One or more higher risk or more complex supports | Stage 1 desktop audit, then Stage 2 onsite audit within 3 months |
| Mid-term | Providers who initially completed a certification audit | Completed 18 months into the registration period |
What do auditors look at in participant records?
The Commission describes an auditor reviewing leadership, risk systems, incident management, staff files, participant records and interviews. The focus moves quickly from what policies say to what actually happens. Auditors ask to see real examples, such as incident reports, complaints records, training logs and supervision notes, and they also observe whether supports match the participant’s plan.
How should a provider prepare its participant documentation?
- Confirm which registration groups and audit type apply, using the Commission’s registration requirements.
- Sample recent participant records and check each against the participant’s plan and goals: could someone who has never met the participant see what was delivered and why?
- Check that incidents are recorded consistently, with dates, times, actions and when the provider became aware.
- Check that the information management system keeps records accurate, current and confidential, as the core module outcome requires.
- Correct weak or copied notes going forward, and keep a record of the correction process.
- Tell participants that they are enrolled in the audit interviews unless they opt out, as the Commission requires for certification audits.
What happens if the auditor raises a non-conformity?
The Commission says a non-conformity does not mean the provider has failed. It means something needs to be corrected or strengthened, and the provider is given a timeframe to address it.
Where does NoteGate fit?
NoteGate checks shift notes before they are saved and keeps the validation and correction history, so the participant records an auditor samples have already been checked. It supports documentation governance and does not determine the outcome of an audit. See the NDIS audit documentation checklist and the audit pack.
Frequently asked questions
Who conducts an NDIS audit?
An independent approved quality auditor, not the NDIS Commission itself. The Commission oversees the process and approves the auditors.
Does the provider choose the auditor?
Yes. The Commission encourages providers to get quotes from several approved quality auditors. It does not set audit prices.
Do auditors speak to support workers as well as read records?
Yes. The Commission says a quality audit may include worker interviews, participant interviews, site visits and a review of documents. Auditors also sample staff files and ask to see real examples, so records should show what workers actually did, not only what a policy says.
How do auditors test an incident record?
The Commission’s certification audit case study describes auditors tracing a reported incident from the initial report through internal review, actions taken and notification obligations, then cross-checking the records against policy. A complete incident record, with dates, actions and when the provider became aware, supports that trace.
Sources
- Types of audits (NDIS Quality and Safeguards Commission, retrieved 19 September 2026)
- Core module: Provider governance and operational management (NDIS Quality and Safeguards Commission, retrieved 19 September 2026)
- NDIS Practice Standards (NDIS Quality and Safeguards Commission, retrieved 19 September 2026)
Related
See NoteGate check a note before it is saved
Book a 20-minute walkthrough, or choose a plan.
Book a 20-minute walkthroughChoose a plan