Published 22 July 2026. Last updated 23 July 2026. By Aaron Price, Founder of Wyzed.
In short: An NDIS audit is an independent assessment of whether your organisation actually does what the NDIS Practice Standards require — carried out by an Approved Quality Auditor, not the Commission itself. Preparing for it is really one job: making sure you can produce evidence on demand. Not "we have a policy for that", but the records that prove it — who did what, when, and how you know. This guide walks through the audit types, how they are scored, exactly what auditors check and ask, a full readiness checklist, a six-week countdown, and the costs, so you walk in able to show your work rather than explain it.
Most providers over-prepare the policies and under-prepare the evidence. An auditor rarely doubts that you have a training policy or an incident process. What they test is whether it is real: can you show them the training was completed, the incident was closed out, the worker's clearance is current? The providers who sail through audits are the ones whose evidence is already assembled, current and easy to retrieve — not scrambled together in the fortnight before.
Quick answer: To prepare for an NDIS audit, gather current, retrievable evidence across governance, policies, incident management, complaints, participant records, worker screening, training records, risk management and continuous improvement. The goal is to show auditors current records that prove your organisation meets the NDIS Practice Standards — not just policies that describe them.
What this guide covers: what an NDIS audit is · the types of audit · how audits are scored · what auditors check and ask · a full readiness checklist · what evidence to prepare · staff training evidence · a six-week countdown · common non-conformities · internal audits · costs · FAQs.
What is an NDIS audit?
An NDIS audit (formally a "quality audit") is how the NDIS Quality and Safeguards Commission checks that a registered — or applying — provider meets the NDIS Practice Standards and the associated Quality Indicators. It is the mechanism that turns "we say we're compliant" into "an independent assessor confirmed it".
Two points trip providers up:
The Commission does not conduct your audit. It is carried out by an Approved Quality Auditor (AQA) — an independent, Commission-approved certification body that you engage and pay directly. The Commission approves the auditors, sets the standards and makes the final registration decision; the AQA does the assessment and reports to the Commission.
An audit is about evidence, not intentions. The Practice Standards describe outcomes. The audit tests whether your day-to-day records demonstrate those outcomes are actually being achieved for real participants and real workers.
Every registered provider is audited to keep its registration, and every new applicant is audited to get it. So this is not a one-off hurdle — it is a recurring cycle you build your operations around.
What are the types of NDIS audit?
Which audit you face depends on the supports you deliver. Lower-risk supports get a lighter verification audit; higher-risk or more complex supports (like Supported Independent Living, personal care or behaviour support) get a more thorough certification audit against the full Practice Standards.
Audit type | Who it applies to | What happens | Typical cost* | Rough timeline |
|---|---|---|---|---|
Verification | Providers of lower-risk supports (e.g. equipment, some therapies) | Desktop review of documents against the Verification Module | ~$900–$1,500 | A few weeks |
Certification (Stage 1 + 2) | Providers of higher-risk / complex supports (SIL, personal care, behaviour support) | Stage 1 desktop document review, then Stage 2 onsite assessment with staff and participant interviews | ~$3,000–$10,000+ | 1–3 months |
Mid-term | Certified providers, roughly halfway through the registration period | Lighter onsite surveillance audit to confirm ongoing conformity | ~$1,000–$4,000 | A few weeks |
Provisional | New providers without an operating history for a support | Modified certification pathway | Varies | Varies |
Condition / out-of-cycle | Providers where the Commission has a compliance concern | Targeted assessment, as directed | Varies | Varies |
Scope extension | Providers adding new registration groups mid-cycle | Additional assessment of the new supports | Varies | Varies |
*Costs are set by the individual Approved Quality Auditor, not the Commission — always get written quotes from more than one AQA. You can find approved auditors through the Commission's Find a registered auditor resources.
Certification is the one to plan hardest for. Stage 1 is a desktop review of your policies, procedures and self-assessment; Stage 2 is the auditor onsite, interviewing your workers and (with consent) your participants, and asking to see evidence in real time. Registration typically runs for three years, with the mid-term audit in between.
How are NDIS audits scored?
There is no simple pass or fail. Against each applicable Practice Standard, the auditor assigns a conformity rating:
3 — Best practice: you exceed the requirement.
2 — Conformity: you meet the requirement. This is the target for every standard.
1 — Minor non-conformity: you largely meet it, but there is a low-risk gap. You will usually be asked for a corrective action plan.
0 — Major non-conformity: you do not meet the requirement and there is a higher risk to participants. You have three months to fix it, and your registration will not progress until it is resolved.
The auditor submits the report to the Commission within set timeframes (14 days for a verification audit, 28 days for certification and mid-term audits). The Commission — not the auditor — then reviews the report and makes the registration decision, and you are notified of the outcome. A single minor non-conformity is normal and manageable; the outcomes that hurt are major non-conformities left unaddressed, because they signal a systemic gap rather than a one-off slip.
Preparing for an audit and short on time? The hardest part of any audit is assembling training and compliance evidence for every worker. If that is the gap, see the best LMS platforms for NDIS providers — the systems built to keep that evidence audit-ready year-round.
What do NDIS auditors check — and ask?
This is where preparation pays off. Auditors do not want to hear that you have a process; they want to see the evidence that proves it works. In our experience supporting providers through Stage 2 audits, the difference between a smooth audit and a stressful one is almost never knowledge — it is retrieval. The providers who breeze through can pull up any worker's training record or any incident's close-out on the spot; the ones who struggle spend the day reconstructing evidence that existed all along but was never assembled.
"The providers that handle audits best are rarely the ones with the most policies. They're the ones that can retrieve evidence quickly — training records, incident trails, clearances and corrective actions — without scrambling on the day." — Aaron Price, Founder of Wyzed
The most useful way to prepare is to run through the questions they ask and make sure the record that answers each one is ready to retrieve.
Here is the pattern that separates a strong audit from a stressful one — the question, and the evidence that answers it cleanly:
"How do you know your workers are trained for the specific needs of the people they support?"
Strong answer: a training register showing each worker's completed modules, mapped to the relevant Practice Standard and their role, with completion dates and current refresher status — exportable on the spot. Weak answer: "We run inductions," with no per-worker record of who completed what, or when.
"Show me how one incident was managed from report through to resolution."
Strong answer: an incident register with the full trail — report, actions taken, notifications made, and close-out — for a real incident. Weak answer: a blank incident policy and a verbal "we'd escalate it."
"How do you know this worker's police check and first aid are current?"
Strong answer: a licence and qualification register with expiry dates and alerts, showing nothing has lapsed. Weak answer: a folder of certificates no one has checked the dates on.
"How do participants raise concerns, and how do you act on them?"
Strong answer: a complaints and feedback register showing concerns received, actions taken and improvements made. Weak answer: "They can always call us."
The theme is consistent: a register beats a policy. Policies tell the auditor what you intend; registers prove you did it. If you can retrieve the right record in under a minute for any question above, you are audit-ready.
Your NDIS audit checklist
Organise your evidence into these categories before the auditor arrives. Treat each as a folder you can produce on demand.
Governance and risk
- Current governance and risk-management policies
- A live risk register (business, operational and participant risk)
- Continuous improvement register showing issues raised and acted on
Policies and procedures - Policies that reflect what you actually do (not a generic template)
- Procedures and practice guides workers can point to
- Version control showing they are current and reviewed
Registers
- Incident register (with the full report-to-close-out trail)
- Complaints and feedback register
- Restrictive practices register, if applicable
Participant documentation
- Consent, service agreements and support plans
- Evidence that supports are delivered in line with each plan
Staff and workforce - Worker screening clearances, current and tracked (NDIS Worker Screening)
- Qualifications and licences with expiry tracking
- Training records — completed, mapped to standards, and evidenced (see the next section)
Restrictive practices (if you deliver relevant supports)
- Behaviour support plans and authorisation records
- Reporting of any use of a regulated restrictive practice
Financial and operational
- Insurance currency
- Financial sustainability evidence, where required for your audit type
What evidence do you need for an NDIS audit?
If you want a single list to work from, these are the records auditors most often ask to see. Have each one current and retrievable:
Training completion records (per worker, mapped to standards)
Worker screening checks
Qualifications and licence expiry records
Incident register
Complaints and feedback register
Risk register
Continuous improvement register
Participant support plans
Consent records
Service agreements
Policy and procedure review history
Insurance certificates
The common thread: every item is a record that proves an outcome, not a policy that describes an intention. If you can produce each of these on demand, you are audit-ready.
Staff training evidence: the most-missed non-conformity
One of the most common non-conformities is not "we don't train our staff" — it is "training was completed but not documented." Providers do the training and then can't prove it at audit, which reads to an assessor exactly like it never happened.
A training record that stands up at audit isn't a spreadsheet of names. For every worker it should show:
What they completed — the specific module or course
Mapped to which requirement — the Practice Standard or role obligation it satisfies
When — the completion date
Evidence of understanding — an assessment or acknowledgement, not just a tick
Refresher status — when it is next due, and whether it has lapsed
Who verified it — a clear, retrievable source of truth
Assembling that by hand across a whole workforce is where providers lose the most time before an audit — and where records go stale between audits. This is exactly the job a purpose-built NDIS learning system does: assign training by role, chase what's overdue, track expiries, and produce the completion evidence in one export. Providers on Wyzed have supported 700+ NDIS audits with no non-conformities related to training. If staff-training evidence is your weak point, that is the part to systematise first.
For a step-by-step walkthrough — how to get every worker compliant before the audit, and how to pull the exact training reports auditors ask for — see our guide on how to get your NDIS staff audit-ready.
A six-week countdown to audit day
If your audit is booked, work backwards.
Weeks 6–5 — Gap analysis. Self-assess against each applicable Practice Standard. Mark every requirement as "evidenced", "partial" or "missing". The missing and partial items are your work list.
Weeks 4–3 — Assemble evidence. Pull every register, plan and record into its category folder. Close the gaps: chase overdue training, update lapsed policies, complete any missing acknowledgements.
Week 2 — Mock audit. Have someone play the auditor and ask the questions above. Time how long it takes to retrieve each record. Anything over a minute is a risk.
Week 1 — Logistics. Confirm which staff the auditor will interview, brief them (honesty, not scripts), arrange a quiet interview space, and make sure the people who own the evidence are available on the day.
Audit day. Show your work. When asked, retrieve the record rather than describing the intent.
Common non-conformities to avoid
The patterns that catch providers out are predictable:
Training completed but not documented — no per-worker, per-standard record.
Policies that don't reflect practice — a polished document that describes something you don't actually do.
Evidence fragmented across systems — records spread over email, spreadsheets and folders, so nothing can be produced quickly.
Lapsed clearances or qualifications — a worker screening check or first aid certificate that expired unnoticed.
Incident trails that stop halfway — reported but no documented resolution.
Continuous improvement on paper only — a register with no evidence anything was actually changed.
Every one of these is an evidence problem, not a knowledge problem — which is good news, because evidence is fixable before the auditor arrives.
Running an internal (mock) audit
The best predictor of a clean external audit is a habit of internal ones. An internal audit is simply you assessing yourself against the Practice Standards before anyone else does.
How often: at least annually, and always 4–6 weeks before a scheduled external audit.
What to do: work through each standard, ask "what evidence proves this?", and try to retrieve it. Log every gap.
What a good one finds: the lapsed clearance, the undocumented training, the policy that no longer matches practice — while you still have time to fix them.
If you want a repeatable structure, use the checklist categories above as your internal-audit template and score each one honestly.
How much does an NDIS audit cost?
The Commission does not set or publish audit fees — each Approved Quality Auditor prices its own work, so costs vary with your size, the supports you deliver and the auditor. The figures below are not official; they are aggregated from provider-reported experience, so treat them as indicative only:
Verification audit: ~$900–$1,500
Certification audit (Stage 1 + 2): ~$3,000–$10,000+, scaling with size and complexity
Mid-term audit: ~$1,000–$4,000
Always get written quotes from more than one approved auditor, and confirm exactly what is included (travel, re-assessment of any non-conformities, report fees). The bigger cost of an audit is usually the internal time spent preparing — which is why keeping evidence audit-ready year-round works out cheaper than a scramble every cycle.
Choosing the system to keep you audit-ready? Start with the best LMS for NDIS providers, and see how Wyzed compares head-to-head in Wyzed vs eTrainU.
Frequently asked questions
What is an NDIS audit?
An NDIS audit is an independent assessment of whether a provider meets the NDIS Practice Standards, carried out by an Approved Quality Auditor approved by the NDIS Quality and Safeguards Commission. It checks that your records prove the required outcomes are being met for participants and workers.
What is the difference between a verification and certification audit?
Verification is a lighter desktop review for providers of lower-risk supports. Certification is a fuller two-stage audit (desktop plus onsite interviews) for providers of higher-risk or complex supports such as Supported Independent Living, personal care or behaviour support.
How much does an NDIS audit cost?
Fees are set by each Approved Quality Auditor, not the Commission. Verification audits typically run around $900–$1,500 and certification audits from roughly $3,000 to $10,000+, depending on your size and complexity. Get written quotes from more than one auditor.
What happens if you fail an NDIS audit?
There is no simple fail. Each standard gets a conformity rating; a major non-conformity (0) must be rectified, usually within about three months, before registration is confirmed. Minor non-conformities are addressed through a corrective action plan.
How often are NDIS providers audited?
Registration typically lasts three years. Certified providers also have a lighter mid-term audit roughly halfway through, plus any out-of-cycle audits the Commission directs if a compliance concern arises.
What documents do I need for an NDIS audit?
Current policies and procedures, participant support plans and consents, incident and complaints registers, worker screening and qualification records, training completion records, a risk register and continuous improvement evidence — all current and quick to retrieve.
Who conducts NDIS audits?
Independent Approved Quality Auditors, approved and overseen by the NDIS Quality and Safeguards Commission. The Commission itself does not perform the audit, but it approves the auditors and makes the final registration decision.
How do I get my staff training audit-ready?
Keep a per-worker training record showing what each worker completed, which standard it maps to, the completion date, evidence of understanding and refresher status. An NDIS-specific learning system keeps this current automatically and exports it as audit evidence.
About the author
Aaron Price is the founder of Wyzed, the LMS purpose-built for NDIS providers. He has worked with more than 300 Australian disability service providers on making staff training simple, customisable and audit-ready, and writes about NDIS compliance, workforce training and choosing the right tools for the sector. Connect with Aaron on LinkedIn.
Sources
NDIS Quality and Safeguards Commission. "The quality audit process / Types of audits." ndiscommission.gov.au
NDIS Quality and Safeguards Commission. "NDIS Practice Standards." ndiscommission.gov.au
NDIS Quality and Safeguards Commission. "Worker screening." ndiscommission.gov.au
NDIS Quality and Safeguards Commission. "Quality audits and finding a registered auditor." ndiscommission.gov.au
Australian Government. "National Disability Insurance Scheme (Approved Quality Auditors Scheme) Guidelines 2018" — Annex B (the conformity rating scale). legislation.gov.au



