How we work

The whole engagement, disclosed.

Most compliance consultants will not tell you what actually happens after you sign. Here is ours end to end — what we do, what we need from you, what you walk away owning, and the parts that are genuinely hard work.

We are a young practice. We cannot show you a wall of client logos or a review score, and we are not going to invent one. What we can show you is the method — in enough detail that you could hold us to it, or take it to another consultant and ask them to match it.

Read it with an eye on the “what we need from you” columns. Every engagement that goes badly goes badly there first.

Before anything is signed

Scope, quote, conflict check.

Nothing is billable until you have a scope and a fixed figure in writing. The discovery call is a working session, not a sales call — we map where your service actually is against what registration or your next audit requires.

What we do

  • Run the discovery call and map your service mix, sites, participant profile and registration status.
  • Produce a written scope and a fixed price for a defined outcome — not an hourly meter.
  • Run a pre-engagement conflict check and record the outcome in writing before you sign. If we know of any actual, potential or perceived conflict, you are told about it before signature, not after.
  • Issue the engagement letter, which incorporates our Statement of Impartiality and names every deliverable.

What we need from you

  • Tell us the awkward parts. An undisclosed site or an open incident does not disappear because it was left out of the scoping call — it just moves the surprise to audit day.
  • Read the engagement letter, take advice on it if you want to, and sign it.

What you end up holding

  • Written scope and fixed quote
  • Signed engagement letter
  • Conflict-check record

Week one

Document Discovery and the gap register.

Week one is deliberately front-loaded. By the end of it you know exactly what you are missing — which is usually the first time anyone has told you in a list you can act on.

What we do

  • Hold the kick-off session with your nominated decision-maker and compliance lead.
  • Send the evidence request — a specific list of documents, registers, rosters and records, not a vague ask.
  • Run Document Discovery to produce the canonical document list for your service mix, reviewed against the published NDIS Practice Standards.
  • Read what you already hold, and assess each item as present, out of date, or present but never approved.
  • Publish the gap register: every gap, with an owner and a target closure date.

What we need from you

  • Nominate one decision-maker with authority to approve documents, and one day-to-day contact.
  • Give us access to what you already hold — including the drafts you are not proud of. Those are more useful than a clean slate.
  • Turn requests around inside the agreed window (we work to five business days unless we agree otherwise).

What you end up holding

  • Canonical document list for your service mix
  • Gap analysis against what you already hold
  • Gap register with owners and closure dates

The build

Documents populated to your operation, not downloaded.

This is the bulk of the engagement. A SIL registration set typically runs to roughly forty policies, procedures and registers — and the difference between a set that survives audit and one that does not is whether it describes what your service actually does.

What we do

  • Populate the policies, procedures and registers your service mix requires, tailored to how you actually operate — sites, shift patterns, participant profile, state overlays.
  • Build the risk register from your operational profile, and the incident, complaints and feedback workflows.
  • Set up the worker certification register and the monitoring behind it, so screening checks and training expiries surface before they lapse rather than after.
  • Run checkpoint reviews against the gap register so you can always see what is closed, what is in flight and what is waiting on you.
  • Draft with AI assistance where it helps, and put every draft through human review before it reaches you. We say so plainly because you are entitled to know — and because an unreviewed generated policy is exactly the kind of document that falls over under audit questions.

What we need from you

  • Review and approve. We do not sign documents on your behalf and would not want to — approval is a governance act, and it is yours.
  • Correct us when a procedure describes something your team does not actually do. Every one of those caught here is a finding avoided later.
  • Close your own gap-register items — the ones only you can do: appoint the person, run the drill, hold the meeting, sign the record.
  • Tell us if the business changes. A new site, service type or registration group changes what an audit looks at, and a scope variation has to be agreed in writing by both of us.

What you end up holding

  • Populated policies, procedures and registers
  • Risk register
  • Incident, complaints and feedback workflows
  • Worker certification register with expiry monitoring

The run-up to audit

The readiness review, then handover.

Before you present anything, we test it — against the evidence-pack expectations published by the approved quality auditor you have chosen, and against the indicators the audit will actually be scored on.

What we do

  • Run the pre-audit readiness review against your chosen auditor's published evidence-pack expectations.
  • Walk the evidence the way it will be asked for — indicator, document, record, date — and flag anything that reads well but cannot be evidenced.
  • Hold the handover session with your nominated compliance lead, so the knowledge stays in your organisation and not in ours.
  • Confirm every gap-register item is closed, or explicitly accepted by you as an open risk you are carrying into the audit with your eyes open.

What we need from you

  • Select and engage the approved quality auditor yourself, from the JAS-ANZ-accredited list, and pay them directly. We do not choose for you.
  • Make your team available for the readiness review — including the people who work the shifts, not only the people who write the documents.
  • Own what you present. You are responsible for the truthfulness, completeness and currency of everything submitted to the auditor and the Commission, whatever role we played in preparing it.

What you end up holding

  • Pre-audit readiness review findings
  • Handover session with your compliance lead
  • Full document set, owned by you outright

After the audit

Keeping it true between audits.

Registration is a point in time; evidence is not. The set that passed goes stale the moment a worker's screening lapses or a procedure stops matching practice — which is the single most common reason a mid-term audit goes badly.

What we do

  • Where you continue with us, track reviews, expiries and obligations so they surface before they bite, and update documents as the rules change.
  • Where a finding does land, work the recovery: root-cause analysis per finding, a corrective action plan with an evidence map, and support to re-present.
  • Where you do not continue with us, you keep everything anyway — the documents are yours, and you can export your data from the platform at any time, free.

What we need from you

  • Actually run the system. This is the part no consultant can do for you, and it is where audit outcomes are really decided.
  • Tell us when something changes, rather than at the next audit.

The boundaries

What we don’t do — and won’t.

These are binding commitments recorded in our Statement of Impartiality and written into every engagement letter we sign, not marketing positioning.

We do not audit you
Compliance Care is not a JAS-ANZ-accredited approved quality auditor and does not perform Stage 1, Stage 2, mid-term or recertification audits.
We do not choose the auditor
We do not refer, rank or recommend approved quality auditors, and we take no fee from one in connection with a client. You select from the JAS-ANZ-accredited list and engage them directly.
You are quarantined, permanently
Every client is entered on our client-quarantine register on the day the engagement starts. That permanently excludes you from any audit our principal might personally conduct in the future. It never lapses.
We do not speak to the Commission for you
Representations to the NDIS Quality and Safeguards Commission are yours to make and yours to stand behind.
This is not legal advice
We build compliance systems against the Practice Standards. Where you need legal or financial advice, get it — and we will say so when we think you should.

The credential, in full

Lead Auditor credential under ISO/IEC 17065

ISO/IEC 17065:2012 is the international standard Conformity assessment — Requirements for bodies certifying products, processes and services. It is the standard the JAS-ANZ-accredited approved quality auditors who conduct NDIS certification audits operate under. Our principal holds a Lead Auditor credential in it.

Held by
Gaurav Nirwani, Director, AAR GEE PTY LTD (ABN 56 682 972 685) trading as Compliance Care.
Standard
ISO/IEC 17065:2012 — conformity assessment. Supported by lead-auditor competence in ISO 9001 (quality), ISO 45001 (work health & safety), ISO 14001 (environment) and ISO/IEC 42001 (AI management), plus PMP and ITIL.
Scope
Competence in how conformity against a standard is assessed and evidenced. It is a competence credential held by an individual — it is not an accreditation of Compliance Care as a certification body.
Verify
A copy of the certificate is provided on request — email info@compliancecare.com.au. We would rather say that than publish an identifier we have not put in front of you.

What it means for your audit

  • We read the NDIS Practice Standards the way a conformity assessment reads them — as indicators that have to be evidenced, not as topics to have a policy about.
  • Your evidence is built to the bar a certification audit is actually run at, so a finding is less likely to be the first time you hear about a gap.
  • When an auditor asks “show me”, the answer is a document, a record and a date — not an explanation.

What it does not mean

  • It gives us no influence over any audit outcome, and no relationship with the auditor you appoint or with the NDIS Quality and Safeguards Commission.
  • Compliance Care is not an approved quality auditor and does not perform Stage 1, Stage 2, mid-term or recertification audits.
  • We do not refer, rank or recommend auditors, and we accept no fee from an auditor in connection with a client.
  • Every client is entered permanently on our client-quarantine register, which excludes them for good from any audit our principal might personally conduct in the future.

These are binding commitments, not preferences. They are set out in our Statement of Impartiality and written into every engagement letter we sign.

Questions

The practical ones.

How long does an engagement take?
Weeks rather than months for a registration or audit-preparation sprint, but the honest answer depends on your starting point and how fast evidence comes back. The timeline, start date and milestones are written into your engagement letter before work begins, and client delay extends it by the period of the delay — we say that up front rather than discovering it halfway through.
How much of my team's time will this take?
More than you would like and less than doing it yourself. Expect a named decision-maker who can approve documents, a day-to-day contact who can find records, and real availability during week one and the readiness review. A page that told you this was effortless would be selling you something.
How is it invoiced?
Against milestones, not hours: half on signature and the balance staged across a mid-engagement milestone and delivery, with invoices payable within fourteen days. The figure is fixed in the engagement letter before any work starts, and only changes by a variation both of us sign.
How do gap findings get tracked to closure?
Through a single gap register, from week one to handover. Every gap has an owner — us or you — and a target closure date, and it is reviewed at every checkpoint. Nothing closes because it was forgotten; it closes because someone did it or you consciously accepted the risk.
Do you use AI?
Yes, for drafting and analysis, and every draft is reviewed by a human with the competence to review it before it reaches you. We do not use your personal information to train or fine-tune models. The full position is published in our Trust Center.
Who owns the documents at the end?
You do. Your populated policies, procedures and registers are yours outright, with a perpetual licence to keep using our underlying methodology inside them for your own operations. There is no hostage-taking if you stop working with us.

We also stand behind the work financially — see the Audit-Readiness Guarantee, or book a discovery call and we’ll scope yours.

See the method applied to your service.

Book a no-obligation discovery call — you'll leave with a scope, a fixed figure and a realistic timeline.

Book a discovery call

Peace of mind, by design.