How to Prepare for an NDIS Audit (And Actually Pass)

An NDIS audit is one of the most stressful moments in a registered provider’s calendar. The stakes are high, fail it and you could lose your registration entirely. But here’s what most providers don’t realise: the majority of audit failures aren’t caused by poor service delivery. They’re caused by poor documentation.

If you’re preparing for an upcoming audit (or you want to avoid being caught off guard), this guide walks you through exactly what the process looks like, what auditors are checking, and the practical steps you can take to give yourself the best possible chance of passing.


What Is an NDIS Audit?

All registered NDIS providers must undergo regular audits conducted by an Approved Quality Auditor (AQA) appointed by the NDIS Quality and Safeguards Commission. These audits assess whether your organisation is meeting the NDIS Practice Standards: the quality benchmarks all registered providers must comply with.

There are two types of audits:

Certification Audit

Required for providers delivering higher-risk supports, including:
– Specialist Disability Accommodation (SDA)
– Support Coordination
– Supported Independent Living (SIL)
– Early Childhood supports
– Behaviour support

Certification audits are more rigorous. They involve a desktop review of your documentation and an on-site assessment, including interviews with participants and staff.

Verification Audit

Required for providers delivering lower-risk supports such as assistive technology, home modifications, or plan management. These are desktop-only reviews of your documentation, no on-site component.

Both audit types assess your compliance with the NDIS Practice Standards relevant to the supports you deliver.


When Does Your Audit Happen?

Your first audit must be completed before your initial registration is approved. After that:
– Certification providers are audited every 3 years, with a mid-term review at the 18-month mark
– Verification providers are audited every 3 years at renewal

The NDIS Commission does not give you much lead time. Registrations are typically scheduled to expire, and audit windows can sneak up on providers who aren’t tracking their renewal dates. Put a reminder in your calendar at least 6 months before your registration expiry date.


What Are Auditors Actually Looking For?

Auditors assess you against the NDIS Practice Standards, which cover four core modules:

  1. Rights and Responsibilities: Do participants understand their rights? Is informed consent documented?
  2. Governance and Operational Management: Do you have proper policies, risk management, and financial oversight?
  3. The Support Provision Environment: Is your workplace safe? Are incidents managed correctly?
  4. Support Provision: Are supports delivered effectively and in line with each participant’s plan?

Higher-risk providers are also assessed against supplementary modules specific to their support types (e.g., behaviour support, SIL, early childhood).

Here’s the thing auditors see constantly: providers who deliver genuinely great support but have almost no paper trail to prove it. In an audit, if it isn’t documented, it didn’t happen.


The 8 Areas Where Providers Most Commonly Fail

Understanding where providers fall short is the best preparation you can do.

1. Outdated or Missing Policies and Procedures

Your policies need to reflect current legislation and NDIS Commission guidelines. A policy last updated in 2023 that references superseded rules is a red flag. Auditors will check policy dates and cross-reference them against current requirements.

2. Incomplete Worker Screening Records

Every worker delivering NDIS supports must hold a current NDIS Worker Screening Check (or an equivalent state-based check where applicable). Auditors will ask for a register of all workers and verify screening currency. A single unscreened worker can put your entire registration at risk.

3. No Evidence of Participant Consent

Informed consent isn’t just a tick-box. Auditors want to see that participants were given real information, had time to consider it, and that their consent was recorded, particularly for behaviour support, restrictive practices, and personal care.

4. Poor Incident Management Records

Do you have a formal incident register? Are incidents being categorised correctly (reportable vs. non-reportable)? Are outcomes documented? Many providers log incidents but never close them out with actions taken and lessons learned. Auditors will check the full lifecycle of your incidents.

5. No Evidence of Worker Training

You need to be able to show that all staff have completed required training, and that you have records to prove it. Certificates, completion dates, training registers. Without these, auditors assume it didn’t happen.

6. Complaints Register Issues

Not just whether you have a complaints register, but whether it’s being used and whether complaints are being resolved and followed up. An empty register over several years raises eyebrows. It suggests participants aren’t aware they can complain, not that everything is perfect.

7. Risk Management Plans That Are Generic

Copying a generic risk management template and putting your logo on it won’t cut it. Auditors want to see that your risk assessment reflects your specific service environment, participant cohort, and operational context.

8. Participant Files Missing Key Documentation

Support plans, goal reviews, communication of plan changes, evidence of participant involvement in their own planning, these all need to be in individual participant files, up to date, and accessible.


Your NDIS Audit Preparation Checklist

Start working through this at least 3 months before your audit date:

Governance & Documentation
– [ ] All policies and procedures reviewed and updated to current year
– [ ] Organisational chart and key personnel details current
– [ ] Risk management framework reviewed and tailored to your organisation
– [ ] Business continuity plan in place

Worker Management
– [ ] Worker Screening Check register up to date (check expiry dates)
– [ ] Training register complete (mandatory + role-specific training)
– [ ] Employment contracts, position descriptions, and performance review records accessible
– [ ] Supervision records documented

Participant Records
– [ ] Support plans in place for all current participants
– [ ] Consent records signed and dated
– [ ] Progress notes up to date
– [ ] Complaints received documented and resolved

Incident Management
– [ ] Incident register current and complete
– [ ] All reportable incidents reported to the NDIS Commission within required timeframes
– [ ] Post-incident reviews documented
– [ ] Staff aware of incident reporting obligations

Complaints Handling
– [ ] Complaints register active and accessible
– [ ] Participants informed of how to make a complaint (including to the NDIS Commission)
– [ ] Complaints resolved and outcomes documented


What Happens During the Audit?

Desktop review: Your AQA will request a set of documents, policies, procedures, worker records, participant files, incident registers, complaints records. These are typically submitted via a secure portal before the on-site component.

On-site assessment (certification only): Auditors will visit your premises, interview staff, and if appropriate, speak with participants or their nominees. They’ll be assessing whether what’s in your documents reflects what’s actually happening in your organisation.

Audit report: After the assessment, your AQA submits a report to the NDIS Commission. The Commission then makes the final decision on your registration.

If non-conformities are identified, you’ll typically be given an opportunity to provide a corrective action response before the Commission makes its final determination.


What to Do If You’re Not Ready

If your audit date is approaching and you know your documentation isn’t where it needs to be, don’t panic, but do act fast.

Prioritise in this order:
1. Worker Screening compliance (this is non-negotiable and fast to fix)
2. Policy and procedure currency
3. Participant consent records
4. Incident and complaints registers

If you genuinely don’t have time to get everything in order yourself, working with a registered NDIS compliance specialist can significantly reduce your risk. HPA has helped hundreds of providers get audit-ready, from initial registration through to renewal, with a 100% approval track record.


Final Thought

Audits don’t have to be terrifying. Providers who pass consistently aren’t the ones delivering perfect services, they’re the ones who’ve built good systems and keep their records current. Start early, work through the checklist methodically, and treat the audit as a checkpoint rather than a threat.


Need help getting audit-ready? Contact the HPA team, we’ve supported providers through hundreds of NDIS audits and can help you prepare with confidence.

Need help? Ask NADO
Chat Icon
NADO โ€“ Your Health Provider Assist Consultant ๐Ÿ’ฌ ร—
0
0
Your Cart
Your cart is emptyReturn to Shop