NDIS compliance

NDIS Audit Success: 7 Critical Steps to Certification

Updated 7 September 2026 · first published 18 February 2025 · 5 min read · Compliance Care

Most guides to certification tell you to be organised. That is true and useless. What decides a certification audit is narrower: whether specific evidence can be produced, current and complete, when someone who did not help you build it goes looking for it.

This is written from lead-auditor training in ISO/IEC 17065 — the conformity-assessment standard the NDIS audit scheme is built on — and from doing audit-readiness work with providers. It describes what the audit actually does, and the seven things that decide how it goes.

First, know which audit you are having

Not every provider gets the same assessment. Which one applies is driven by the registration groups you apply for, and it determines almost everything else about your preparation. The Commission sets out the audit types and what triggers them; read that before you read anything else, including the rest of this article.

Certification is the more demanding path. It runs in two stages: a review of your documented system, then an on-site assessment where auditors interview staff, examine records and, with consent, speak to participants. The two stages test different things, and providers who prepare only for the first are the ones caught out.

1. Establish your scope before you build anything

Registration groups pull in modules of the NDIS Practice Standards, and requirements multiply rather than overlap. Applying for a group you do not intend to service is the most common self-inflicted wound in the process — it enlarges your audit scope permanently in exchange for nothing.

Write down the groups, list the modules each pulls in, and let that list define the work. Everything below assumes you have done this.

2. Make the documents consistent, not merely present

Stage one is a review of your documented system, and the failures there are rarely missing policies. They are contradictions: a policy that says reviews happen six-monthly beside a procedure that says annually, an org chart naming a role your position descriptions do not, a complaints policy pointing at a form that no longer exists.

Each document is defensible alone. Read end to end, they describe an organisation that cannot exist. Read your own set in one sitting before an auditor does.

3. Build the evidence trail, not the policy library

A policy states an intention. An audit tests whether the intention happened, and follows a thread: the plan was current, the review occurred when the policy said it would, the incident was recorded and escalated within the timeframe, the worker delivering the support held the screening and training the file claims.

Providers over-invest in the policy set because it is the part you can finish. The evidence trail is the part that is assessed.

4. Treat currency as a separate obligation

Auditors read the gap between a register's last entry and today as a signal about the system, and it is usually the right signal. A risk register accurate in March and untouched since does not evidence a working process — it evidences one that stopped.

Before audit, go through every register and ask when it was last genuinely used. Anything with a long silence needs either a real entry or an honest explanation, and the explanation is better offered than discovered.

5. Prepare people, not scripts

Staff interviews are where policy and practice are compared, and coaching people to recite the policy is actively counterproductive. Auditors ask what you do, then ask for the record of the last time you did it. A confident recitation with nothing behind it is a worse outcome than an honest "I would check with my coordinator" — the second describes a functioning escalation path.

What genuinely helps: making sure every staff member can say what they do when something goes wrong, who they tell, and how fast. Reportable incidents carry hard timeframes — with the exception of unauthorised use of a restrictive practice, they must be notified to the Commission within 24 hours of your organisation becoming aware, per the reportable incidents guidance. If a support worker does not know that clock exists, no policy will save you.

6. Handle participant involvement properly and early

Certification involves speaking with participants, with their consent. This is the step providers leave latest and it is the one with a hard human dependency: consent must be sought properly, without pressure, and it takes time. Rushing it produces exactly the impression you do not want.

7. Sample yourself, the way they will

The highest-value preparation costs nothing. Pick three participants at random — genuinely at random, not the three whose files you know are good — and follow each one all the way through your evidence as an auditor would.

You will find the gaps in about an hour, and they will be the same gaps the audit finds, because the method is the same. Our free NDIS compliance checklist gives you the structure, and names the evidence sampled against each obligation. For SIL providers, the SIL audit-readiness checklist covers the supplementary module as well.

What we do

Gap analysis is step seven done by someone who is not you, which is most of its value — you cannot find the gaps your own filing logic created. Audit preparation is the work of closing them, and policy development is for organisations starting from very little.

If you are unsure how ready you actually are, book a thirty-minute call. It is free, and the answer is sometimes that you are fine and should stop worrying.

Get NDIS compliance updates

Practical guidance on registration, audits and the 2027 wave. No spam, unsubscribe in one click.

Need a hand putting this into practice?

Book a no-obligation discovery call — you’ll leave knowing exactly where you stand.

Book a discovery call

Peace of mind, by design.