The NDIS audit checklist: how to prepare with confidence
9 July 2026 · 9 min read
An NDIS audit can feel daunting, but it rewards the same thing every time: being able to show, with evidence, that you do what your policies say you do. This guide breaks down what assessors look for and gives you a checklist to work through well before the auditor arrives.
First, know which audit you're facing
Your audit type depends on the risk level of the supports you deliver:
- Verification audit — for lower-risk, less complex supports. A lighter review, focused on your policies and that your workers meet requirements.
- Certification audit — for higher-risk supports such as Supported Independent Living, personal care and behaviour support. It has two stages: a documentation review (Stage 1) and an on-site assessment (Stage 2) where the auditor talks to staff and participants.
Check your registration groups against the NDIS Commission's requirements so you're preparing for the right level of scrutiny.
What auditors are really checking
Under the NDIS Practice Standards, an auditor is testing whether your organisation is safe, capable and participant-centred — and whether the evidence backs it up. The recurring themes:
- Governance and operational management — clear roles, risk management, continuous improvement.
- Provision of supports — consent, choice and control, and support delivery that matches participant plans.
- Worker requirements — NDIS Worker Screening clearances, orientation, and ongoing training.
- Incident and complaints management — that incidents and complaints are recorded, acted on, and closed out within timeframes.
- Risk and safeguarding — how you identify and manage risks to participants.
Your pre-audit checklist
Work through this in the weeks before your audit:
- Policies and procedures — current, version-controlled, and actually reflecting how you operate. Undated or generic templates are a red flag.
- Worker records — every worker has a valid NDIS Worker Screening clearance, a signed Code of Conduct, orientation, and relevant training recorded with dates.
- Incident register — complete records with the incident, the response, actions taken, and closure. Check nothing is sitting open past its timeframe.
- Complaints register — same discipline: logged, actioned, resolved, with the participant kept informed.
- Participant files — consent, service agreements, plans, and evidence that supports are delivered as agreed and reviewed.
- Risk assessments — current for participants and for the organisation.
- Continuous improvement — a register showing you identify issues and act on them (auditors love to see this).
- Key personnel — details current and notified to the Commission where required.
The gaps that trip providers up
- Policy without practice. The policy exists; the records don't prove it's followed.
- Training you can't evidence. Staff "did the training" but there's no dated record.
- Stale documents. Policies referencing superseded frameworks or old business details.
- Reactive incident management. Incidents logged late, or actions not closed out.
Fixing these is mostly about discipline and records, not grand strategy.
How Support Logic helps
Support Logic is trained on the NDIS Practice Standards, the Code of Conduct and operational guidelines, so your team can get instant, citation-backed answers to "what does the standard actually require here?" — and you can upload your own policies so answers reflect how you work. It won't replace your approved quality auditor, but it makes preparation faster and more consistent. See how it works.
The bottom line
Audits reward organisations that keep clean, current records and can show policy in action. Start early, work the checklist, and close the gap between what your policies say and what your files prove.
This guide is general information, not legal or compliance advice. Always confirm current requirements with the NDIS Commission and your approved quality auditor.
Get practical NDIS guides by email
Simple, practical guidance on compliance, SIL, SCHADS and AI — a few times a month. No spam, unsubscribe anytime.
Frequently asked questions
It depends on the supports you deliver. Lower-risk supports usually require a verification audit — a lighter, desktop-style review of your policies and worker requirements. Higher-risk supports (like Supported Independent Living, behaviour support, or personal care) require a certification audit, which is more in-depth and includes a Stage 1 (documentation) and Stage 2 (on-site, including talking to participants and staff).
Registration runs in cycles (commonly up to three years). Certified providers typically have a mid-term (surveillance) audit partway through the cycle, plus a full re-certification audit before renewal. Your exact dates are set by the NDIS Commission and your approved quality auditor.
Evidence that you meet the relevant NDIS Practice Standards: your policies and procedures, worker screening and training records, incident and complaints management, risk and safeguarding, participant consent and choice, and records that show it all works in practice — not just on paper.
Gaps between policy and practice. You may have a good incident-management policy, but if the records don't show it being followed — reports completed, actions taken, timeframes met — that's where non-conformities arise. Auditors look for the paper trail, not just the policy document.
NDIS AI you don't have to worry about
Support Logic keeps your data onshore, blocks participant identifiers, and gives citation-backed answers — built for Australian NDIS providers.
