The audit that arrives after you've stopped thinking about audits
Most of the attention in a provider's first year goes to certification: the stage 1 desktop review, the stage 2 site audit, the scramble to have every policy and register ready before the auditor arrives. Once that certificate is issued, it's tempting to treat compliance as a project that's finished rather than a system that keeps running. For providers registered to deliver higher-risk or more complex supports — supported independent living among them — there's a second audit built into the registration period before renewal, and it catches out providers who let their evidence quietly drift after certification: the mid-term audit.
What a mid-term audit actually is
A mid-term audit applies to registered providers who completed a certification audit and are registered to deliver higher-risk or more complex supports, and it's scheduled partway through the registration period rather than at renewal. The NDIS Commission's guidance on the quality audit process sets it out alongside the other audit types a registered provider may encounter — verification, certification, and recertification — as the check that sits inside an active registration period rather than at its start or its renewal.
The specific timing is set as a condition on individual providers' registration, and it commonly appears as a requirement to complete the mid-term audit no later than 18 months after the date of registration — a condition you'll find recorded against your own registration, not a single fixed calendar date that applies to every provider identically. If you're not certain when yours falls due, your registration conditions are the place to check, not an assumption based on when your certificate was issued.
How it differs from a certification or recertification audit
A mid-term audit is a lighter-touch process than the certification audit that got you registered in the first place, but it isn't a lesser one in terms of what it checks. The Commission's guidance confirms a mid-term audit needs at least one auditor, compared with the larger auditor teams typically involved in certification audits for higher-risk supports — but the assessment itself still runs against the full set of NDIS Practice Standards applicable to your registration, not a reduced subset. The difference is in audit team size and process, not in the standard you're being measured against.
Recertification, by contrast, happens at the end of the registration period and effectively re-runs the certification process to renew registration for a further term. The mid-term audit sits between the two: a check-in that confirms your organisation is still operating the way its certification evidence said it would, well before the more comprehensive recertification process begins.
What the auditor is actually assessing
Like certification and recertification audits, a mid-term audit assesses your organisation against the NDIS Practice Standards relevant to your registration groups, and the auditor rates your performance against each applicable standard rather than issuing a single pass or fail. Where the audit identifies a non-conformity, the Commission's guidance describes the provider being asked to provide a corrective action plan describing how the non-conformity will be addressed, with a response required within seven calendar days of that request — a short window that assumes you can already describe the fix, not start diagnosing the problem from scratch. The auditor then submits the audit report to the Commission, with the guidance describing a submission timeframe of up to 28 days after the audit is completed.
None of that process is unfamiliar if you went through certification recently — it's the same rating-and-corrective-action structure. What's different is the state your evidence is likely to be in by the time the mid-term audit arrives, which is where most of the risk in this audit type actually sits.
Why providers get caught out here specifically
Certification evidence is usually assembled under real pressure and real scrutiny — a provider preparing for stage 1 and stage 2 audits tends to have registers, policies, and records in genuinely good order at that specific moment. The mid-term audit lands 18 months later, after the certification pressure has long passed, and a handful of patterns show up repeatedly in providers who find themselves under-prepared for it:
- Registers that were current at certification and haven't been reviewed since. Incident, complaints, and risk registers that were exemplary at stage 2 but haven't had a genuine review cycle in the months since.
- Staff turnover eroding the practice behind the policy. The person who built and understood the certification evidence has moved on, and the process now runs on memory rather than a written, trained-on procedure.
- Worker screening and training records that lapse quietly. Clearances and competencies that were current at certification but haven't been tracked against their actual renewal dates since.
- Continuous improvement treated as a certification artefact rather than a live practice. A continuous improvement register populated once, before the original audit, and not meaningfully added to since.
- No internal check before the mid-term window opens. Providers who assume "we passed certification, we're fine" rather than running their own review against the Practice Standards before the auditor does.
Preparing for the mid-term audit properly
The most reliable preparation isn't a scramble in the weeks before your mid-term audit is due — it's treating your certification evidence as a system to maintain rather than a one-off deliverable. That means registers reviewed on a genuine schedule rather than only when an audit is imminent, worker screening and training tracked against real expiry dates, and a continuous improvement process that actually shows entries added between audits, not just around them. Running an internal review against the Practice Standards a few months ahead of your mid-term window — using the same evidence categories an auditor will check — is the difference between confirming you're ready and discovering a gap when an auditor already has.
How Compliance Care helps
We help registered providers keep the evidence behind their certification genuinely current — registers that are reviewed on a real schedule, worker screening and training tracked against actual expiry dates, and continuous improvement that shows a working system rather than a certification artefact. Our ongoing compliance support is built around exactly this gap: keeping your evidence base audit-ready between the moments when an auditor is actually looking, whichever independent approved quality auditor you've engaged.
If your mid-term audit is approaching and you want an honest read on where your evidence currently stands, our SIL audit checklist is a practical starting point for checking your registers against the Practice Standards today. It's worth reading alongside our NDIS audit preparation guide and our overview of how the registration and certification process works, since the mid-term audit draws on the same evidence base those two posts describe building in the first place.
Book a discovery call and we'll help you map out where your evidence stands ahead of your next audit, whenever it falls due.
Get NDIS compliance updates
Practical guidance on registration, audits and the 2027 wave. No spam, unsubscribe in one click.
