
Your first NDIS certification audit: what actually happens
If you're a newly registered or newly registering SIL provider, "the audit" can feel like a single, vague, high-stakes event. In practice it's a defined, two-stage process run by an independent auditor, and knowing the shape of it in advance is most of what reduces the stress. This guide walks through what a certification audit actually involves, stage by stage, and what genuinely helps you prepare.
From the auditor's chair
In practice, the Stage 1 desk audit rarely fails on missing documents — it fails on documents that don't match each other. I have seen a provider submit a well-written incident policy alongside an incident register whose entries used different categories entirely, and the auditor's follow-up went straight to the gap rather than the policy. Consistency across the set is what gets assessed, not the quality of any single file.
Certification audit vs verification audit
Not every NDIS provider goes through the same audit pathway. Providers delivering higher-risk or more complex supports — Supported Independent Living among them — go through a certification audit rather than the lighter-touch verification pathway used for lower-risk supports. The NDIS Quality and Safeguards Commission's guidance on audit types sets out which pathway applies to which registration groups — worth checking against your own registration groups before you assume which one you're in for.
Stage 1: the desktop review
A certification audit runs in two stages. Stage 1 is a documentation review: your chosen approved quality auditor examines your policies, procedures, and self-assessment against the NDIS Practice Standards modules relevant to your registration groups, and identifies where the paper trail has gaps before anyone sets foot on site. Per the Commission's quality audit process guidance, this stage is about readiness — it tells you, and the auditor, whether you're actually prepared to move to Stage 2.
Stage 2: interviews, site visits, and evidence in practice
Stage 2 is where documentation meets day-to-day practice. It typically runs over at least a day and includes interviews with leadership and frontline staff, conversations with participants (who are included in the audit sample unless they choose to opt out), direct observation of your service environment, and file reviews of participant records and incident documentation. The Commission's guidance requires Stage 2 to commence within three months of Stage 1 being completed — so the gap between stages is a working window, not a long pause.
This is the stage where policies that exist only on paper get found out. Staff need to be able to explain, in their own words, how they follow your incident, complaints, and safeguarding procedures — not recite them, but describe how they actually use them.
If the audit finds a non-conformity
Audit outcomes are rated against each Practice Standard and quality indicator. Where the auditor identifies a major non-conformity, the Commission's guidance gives the provider a defined window — three months to implement corrective action before registration can proceed on that basis. A non-conformity isn't the end of the process; it's a documented, time-bound expectation to close a specific gap.
Who conducts the audit — and why independence matters
Certification audits are carried out by an approved quality auditor — an independent, third-party auditing body from the Commission's own list, which you select and engage yourself. See the Commission's find-an-auditor guidance for the current list. That independence is the point: the auditor's job is to test your actual practice against the Practice Standards, and only your organisation's real evidence, systems, and people determine the outcome — not any relationship with a consultant, and not us.
Preparing in practice: what actually reduces audit stress
The providers who find Stage 2 straightforward tend to have done the same handful of things well in advance:
- Documentation that matches practice. Policies should describe what your team actually does, not a generic template — auditors notice the gap quickly, and it shows up across incident management, complaints handling, participant consent, and governance records alike.
- A genuine gap analysis before the audit notice arrives. Reviewing your own evidence against the Practice Standards ahead of time, rather than waiting for the auditor to find the gaps, is what turns Stage 1 from a source of surprises into a formality.
- Risk registers and incident logs that are living documents. Auditors expect to see risks linked to mitigation actions, incident trends actually reviewed, and corrective actions followed through — not a file created the week before the audit.
- Staff who can speak to their responsibilities. Interviews are a standard part of Stage 2 — if frontline staff can't explain how they apply your policies day to day, that's a governance signal even when the paperwork itself is in order.
Common gaps that trip up first-time certification audits
Across newly certifying providers, the same avoidable gaps recur: policies with no evidence they've been implemented, documentation that's out of date or in the wrong version, no internal review process ahead of the external one, and staff who haven't been briefed on what an interview actually involves. None of these require expensive fixes — they require starting the preparation early enough that fixing them isn't a scramble.
How Compliance Care helps you prepare
We build genuine competence against the NDIS Practice Standards — preparing your evidence, policies, people, and systems so that whichever independent auditor reviews your organisation finds practice that reflects real quality, not a rehearsed version of it. Our audit preparation services are built around this two-stage process specifically, and our gap analysis and pre-audit reviews are designed to surface the same gaps a Stage 1 review would — before Stage 1 does.
If you're newly registered and building your evidence base from scratch, our SIL audit checklist is a practical starting point, and our guide to the certification process and step-by-step audit checklist cover the wider registration journey. For ongoing support once you're certified, see ongoing compliance support.
Ready to talk through where you stand before your Stage 1 review? Book a discovery call and we'll help you map what's left to do.
Get NDIS compliance updates
Practical guidance on registration, audits and the 2027 wave. No spam, unsubscribe in one click.
