NDIS Audit Preparation: The 2026 Provider Checklist

Updated 12 min readBy the Orangised team

The Short Answer

An NDIS audit checks a registered provider against the NDIS Practice Standards. Lower risk supports get a desk-based verification audit; higher risk supports, now including SIL, get a two-stage certification audit with a site visit, then a mid-term audit within 18 months. Prepare by making policies match practice and keeping incident, complaint, risk and worker screening records current, because auditors sample real files.

On this page
  1. The short version
  2. Certification or verification: which audit you need
  3. The Practice Standards modules
  4. How the audit runs, step by step
  5. 1. Application and self-assessment
  6. 2. Choosing an approved quality auditor
  7. 3. Stage 1: desk audit
  8. 4. Stage 2: site audit
  9. 5. Report and decision
  10. 6. Mid-term, renewal and other audits
  11. Ratings and non-conformities
  12. What auditors ask for, area by area
  13. Indicative costs and timeframes
  14. Common non-conformities
  15. What changed in 2026
  16. A practical checklist
  17. Where software helps, and where it doesn't

The short version

An NDIS audit is an approved quality auditor checking your business against the NDIS Practice Standards. You pay for it, you pick the auditor, and the NDIS Commission makes the registration decision off the back of the auditor's report.

  • Low risk supports get a verification audit. It's a desk review of documents against four standards: risk, complaints, incidents and HR.
  • Higher risk supports get a certification audit. That's two stages: a desk audit, then a site audit with staff and participant interviews.
  • Certification providers also face a mid-term audit that has to start within 18 months of registration.
  • 2026 added new rules. SIL and NDIS digital platform providers must now be registered, SIL has its own Practice Standards module, and two big auditors left the market.

Everything below is sourced to the NDIS Commission or the Federal Register of Legislation unless we say otherwise. This is general information, not legal advice.

Certification or verification: which audit you need

The NDIS (Provider Registration and Practice Standards) Rules 2018 list every class of supports, the standards that apply to it and the assessment method.

Class of supports (Rules wording, some rows grouped)MethodStandards
Assistance with daily personal activitiesCertificationCore module
Participation in community, social and civic activitiesCertificationCore module
Group and centre-based activitiesCertificationCore module
Development of daily living and life skillsCertificationCore module
Assistance in coordinating or managing life stages, transitions and supportsCertificationCore module
High intensity daily personal activitiesCertificationCore and Module 1
Specialist positive behaviour supportCertificationCore and Module 2
Early intervention supports for early childhoodCertificationCore and Module 3
Specialised support coordinationCertificationCore and Module 4
Assistance with supported independent living (new)CertificationCore and Module 5A
Providing an NDIS digital platform service (new)CertificationCore module
Therapeutic supports, household tasks, plan management, community nursingVerificationModule 6: Verification
Assistive products and equipment, home and vehicle modifications, travel/transport arrangementsVerificationModule 6: Verification

Source: Rules, section 20 table. If you deliver supports that use, or may use, a regulated restrictive practice, you also need Module 2A, assessed by certification, whatever your other classes are (Rules, section 20(1)(b)). Government providers are always assessed against the Core module by certification (Rules, section 22).

If even one of your classes needs certification, your audit is a certification audit. A certification audit also satisfies any verification requirement (Rules, section 23).

When you submit your application, the Commission emails you an "Initial scope of audit" document. It confirms your audit type, registration groups, the standards that apply and what to give your auditor (NDIS Commission, Apply for registration). Treat that document as the final word on scope.

The Practice Standards modules

These are the current module names in the compiled Rules in force from 1 July 2026 (Rules, Schedules 1 to 8):

ModuleWhat it covers
Core moduleRights and responsibilities; governance and operational management; provision of supports; support provision environment
Module 1: High intensity daily personal activitiesComplex bowel care, enteral feeding, dysphagia, tracheostomy, catheters, ventilators, injections, wounds
Module 2: Specialist behaviour supportWriting and reviewing behaviour support plans
Module 2A: Implementing behaviour support plansUsing regulated restrictive practices, and monitoring and reporting them
Module 3: Early childhood supportsThe child, the family, inclusion, collaboration, outcomes
Module 4: Specialised support coordinationCoordination, management of supports, conflict of interest
Module 5: Specialist disability accommodationConflict of interest, service agreements, dwelling enrolment, tenancy
Module 5A: Assistance with supported independent livingNew from 1 July 2026: supported decision-making, safeguarding, practice governance, tenancy agreements
Module 6: VerificationRisk, complaints, incidents, human resources

Auditors must take the Quality Indicators Guidelines into account when they assess you (Rules, section 24). Those indicators are the closest thing to the auditor's checklist, and they were updated on 1 July 2026 to add the SIL indicators (Quality Indicators Guidelines, Compilation 3). Read them before you write a single policy.

How the audit runs, step by step

1. Application and self-assessment

You apply in the Commission's Applications Portal: registration groups, a self-assessment against the Practice Standards with evidence, and suitability questions about you and your key personnel. Finish within 60 days or it gets deleted (NDIS Commission, Apply for registration).

Write the self-assessment yourself. The Commission says responses must be specific to your organisation, "not a direct copy of purchased documents". If they're not, it can refuse the application or impose a condition requiring a fresh certification audit (NDIS Commission, Apply for registration).

Get key personnel and risk-assessed workers screened first: the Commission checks their clearances during the application (Apply for registration).

2. Choosing an approved quality auditor

Only approved quality auditors can do the audit, and they are not part of the Commission. Auditors give free, no-obligation quotes, and the Commission recommends getting more than one (NDIS Commission, The quality audit process).

Fewer auditors are taking work. QIP stopped NDIS verification and certification audits on 30 April 2026 (QIP). Citation Certification wound up all NDIS audit activity on 30 June 2026 (Citation Certification). Book early.

3. Stage 1: desk audit

Stage 1 is an off-site review of your self-assessment, your documents and any past audit findings. A verification audit is Stage 1 activity only (Approved Quality Auditors Scheme Guidelines, sections 12 to 14).

The auditor must send you the Stage 1 findings at least one week before Stage 2, or two weeks if they suspect a non-conformity. If you're clearly not ready, they tell the Commission Stage 2 will be delayed (AQA Guidelines, section 14).

4. Stage 2: site audit

Stage 2 should start within three months of Stage 1 finishing (AQA Guidelines, section 14(3)). Expect an opening meeting, governance interviews, staff file sampling, private participant interviews, observation of supports, and a walk through at least one incident from report to close (NDIS Commission, The quality audit process).

Sampling rules worth knowing (AQA Guidelines, Annex B):

  • Opt-out. You must tell every participant they are automatically in the audit. If someone opts out, record it and tell the auditor.
  • Sample size. For certification, at least the square root of your participant count, rounded up. 32 participants means 6 files and 6 interviews.
  • No cherry-picking. You can't pre-select the workers, participants or files.
  • Problems grow the sample. Each non-conformity found adds to it, to test for a system failure.

5. Report and decision

The auditor sends the report to the Commission within 14 days of a verification audit and 28 days of a certification or mid-term audit (NDIS Commission, The quality audit process). The Commission then assesses your suitability and decides. Registered providers are "generally registered for three years" (NDIS Commission, About registration).

New providers with no participants yet get a provisional audit, and may need a further Stage 2 once they start delivering (AQA Guidelines, section 27).

6. Mid-term, renewal and other audits

  • Mid-term audit. Certification providers must start one no later than 18 months into the registration period. It covers the Core module's governance and operational management standards, anything that needed a corrective action plan, and anything else the Commission names (Rules, section 13B). The Commission suggests engaging your auditor at 12 months (NDIS Commission, The quality audit process). Individuals or partnerships whose only certification class is early childhood, SDA-only providers and transitioned providers are exempt.
  • Renewal. You can start any time in the 6 months before expiry. Start before expiry and your registration stays valid until the decision. Start after and it has lapsed (NDIS Commission, Renew your registration).
  • Condition and out of cycle audits. The Commission can order an audit at any time, and you can request one to add registration groups (NDIS Commission, The quality audit process).

Ratings and non-conformities

Every standard and quality indicator gets a rating (NDIS Commission, The quality audit process):

RatingMeaning
3Conforms with elements of best practice
2Conforms with NDIS Practice Standards
1Minor non-conformity
0Major non-conformity

The clock rules are tight (AQA Guidelines, Annex C):

  • You must give the auditor a corrective action plan within 7 calendar days of written notice of any non-conformity.
  • A major must be downgraded or closed within 3 calendar months. At a mid-term or recertification audit, missing that deadline means automatic suspension of the auditor's certification decision.
  • A minor must be closed by the mid-term or recertification audit (whichever comes first) and within 18 calendar months, or it escalates to a major.
  • A major can't lead to certification, but a minor can, if you show an acceptable corrective plan first (AQA Guidelines, section 16).

What auditors ask for, area by area

The Commission says auditors want to see real examples, such as incident reports, complaints records, training logs and supervision notes, not just the policy (NDIS Commission, The quality audit process). Here's what the rules and indicators point to.

AreaWhat the rules requireEvidence to have ready
GovernanceDefined structure, oversight of quality and safeguarding, conflicts managed (QI 11)Org chart, minutes showing quality and risk discussed, conflict register
RiskRisks identified, analysed and treated; a documented system; insurance (QI 12)Risk register with review dates, participant risk assessments, insurance certificates
QualityInternal audit program, continuous improvement (QI 13)Internal audit results, improvement register with owners
IncidentsReportable incidents notified within 24 hours or 5 business days; records kept 7 years (Incident Rules, sections 12, 20, 21)Incident register, investigations, notifications, trend reviews
ComplaintsParticipants told how to complain, including externally; records kept 7 years (Complaints Rules, section 10)Complaints register with outcomes, participant information pack
Worker screeningLists of risk-assessed roles and the workers in them, with clearance details, showing who held each role on any day in the past 7 years (Worker Screening Rules, sections 17 to 21)Roles list, screening register with expiry dates
Training and HRPre-employment checks, the NDIS worker orientation module, training, supervision (QI 17)Staff files, training matrix, supervision notes
Participant recordsConsent to use information; support plans and risk assessments reviewed at least annually (QI 14 and 20)Consents, service agreements, current plans, shift notes
Medication (where relevant)Records identify each participant's medication and dosage (QI 26)Medication logs, medication incidents, competency records
EmergenciesPlans made with participants, tested and trained (QI 18A)Emergency plans, drill records
Restrictive practicesMonthly reports on use; plans reviewed at least every 12 months (Restrictive Practices Rules, sections 14 and 22)Plans, authorisations, monthly reports, use records
SIL (Module 5A)Supported decision-making, safeguarding between co-residents, separate service and tenancy agreements (QI 72B to 72E)Decision records, safeguarding reviews, both agreements

The Commission's own audit case study shows the auditor tracing one incident from first report through internal review, actions and notification, then checking restrictive practices were properly authorised (NDIS Commission, The quality audit process). Pick a real incident and do that trace yourself before they do.

Indicative costs and timeframes

There is no fee to register with the Commission. You pay the auditor, and the Commission "doesn't set prices for audit services". Cost depends on your size and participant numbers (NDIS Commission, The quality audit process).

We couldn't find any official figures. These ranges are indicative, from industry sources that don't publish their method, and they disagree:

AuditProvider Plus (January 2026)LMS Compliance (October 2025)
Verification$900 to $1,800$900 to $1,500
Certification$2,800 to $12,000 or more$3,000 to $5,000
Mid-term$1,000 to $6,000not given

Sources: Provider Plus, LMS Compliance Services.

The timeframes that are set in the rules or by the Commission:

StepTimeframe
Finish the online applicationWithin 60 days of starting
Stage 2 after Stage 1Should start within 3 months
Stage 1 findings sent to youAt least 1 or 2 weeks before Stage 2
Audit report to the Commission14 days (verification), 28 days (certification, mid-term)
Corrective action plan7 calendar days from written notice
Close a major non-conformity3 calendar months
Mid-term audit startsNo later than 18 months into registration
Renewal windowUp to 6 months before expiry
Change of ownership audit (certification)Starts within 3 months of the change

Sources: as cited in the sections above, plus Rules, section 13BA. The Commission gives no total processing time; it depends on your size and supports (Apply for registration).

Common non-conformities

The Commission doesn't publish a ranked list. Its case study ends with a minor non-conformity for incomplete documentation and an improvement opportunity on participants' awareness of complaints (NDIS Commission, The quality audit process). Industry write-ups keep naming the same problems (FlowLogic; LMS Compliance Services):

  • Policies that don't match practice.
  • Worker screening gaps for people in risk-assessed roles.
  • Incident logs with holes: no follow-up, no trend review.
  • Complaints with no paper trail to an outcome.
  • Risk registers untouched since the last audit.
  • Staff files missing qualifications or induction records.

Watch screening this year in particular. The first NDIS worker screening checks were issued from February 2021 and started expiring from February 2026, because clearances last up to 5 years (NDIS Commission, Worker screening; Renewal cycle FAQs).

What changed in 2026

Confirmed:

  • SIL must be registered. From 1 July 2026 you must be registered to provide assistance with supported independent living, assessed by certification against the Core module and the new Module 5A (Amendment Rules F2026L00802). The new registration group is 0138 (NDIS Commission, SIL mandatory registration).
  • SIL transition. Registered providers already holding the shared living class must meet Module 5A from 1 July 2026 while the Commission decides whether to add SIL to their registration. Unregistered providers already delivering SIL had to apply before 1 October 2026 to keep going until a decision; those that didn't had to be registered from 1 October 2026 (Amendment Rules, transitional section 32). The Commission says delivering SIL unregistered carries a maximum penalty of 2 years' imprisonment, 120 penalty units, or both (NDIS Commission, SIL mandatory registration).
  • Digital platforms must be registered and certified against the Core module. Extra conditions on checking and displaying worker screening, banning orders and credentials apply from 1 January 2027 (Amendment Rules F2026L00802).
  • Change of ownership. Notice is due by the earlier of when you know the change will happen or when a necessary step occurs. Certification providers whose governance changes significantly must start a change of ownership audit within 3 months (Rules, sections 13A and 13BA).
  • Stronger Commission powers. The NDIS Amendment (Integrity and Safeguarding) Act 2026 received Royal Assent on 8 April 2026 and expands the Commission's powers to detect, prevent and respond to breaches (NDIA, Integrity and safeguarding).

Not decided yet:

  • The wider Practice Standards review. Public consultation, run with KPMG, closed on 14 November 2025, and it asked about a new NDIS Quality Framework. As at September 2026 the Commission says it is "considering feedback" for next steps (NDIS Commission, Practice Standards reform). For now, the Core module and other modules still apply as written. Ignore anyone selling "the new standards" as law.

A practical checklist

WhenDo this
6 months outConfirm your classes and modules, read their Quality Indicators, get two or more auditor quotes and book dates.
4 to 6 months outDo your own gap check against every indicator. Rewrite any policy that doesn't match what staff actually do.
3 to 4 months outClean up the worker screening register: every risk-assessed role listed, every clearance number, outcome and expiry date current.
3 months outCheck every staff file: qualifications, induction, orientation module, training, supervision.
3 months outUpdate the risk, incident, complaints and continuous improvement registers. Close or progress old items, and record trend reviews.
2 months outCheck participant files: consents, service agreements, support plans and risk assessments reviewed in the last 12 months.
2 months outIf you use restrictive practices, match every use to an authorised plan and a monthly report.
1 month outTell every participant they're in the audit and can opt out. Brief staff. Trace one incident end to end.
After the auditSend your corrective action plan within 7 days. Diary 3 months for majors and your mid-term date for minors.

Where software helps, and where it doesn't

No system passes an audit for you. What helps is having the evidence in one place with dates on it, instead of chasing it across inboxes the week before Stage 2. Orangised keeps the incident, ABC, client and organisational risk, continuous improvement and feedback registers together. It sends admins reminders before staff checks and risk reviews fall due, and your auditor can get a read-only login, set up by Orangised support, to go through the registers, risk assessments, participant records and documents.

Sources

General information for NDIS providers, not legal or financial advice. Rules change: check the source before you act, and if something here is out of date, tell us.

Less Reading Rules. More Running Your Business.

Book a demo and we'll show you how Orangised keeps the NDIS paperwork in check while you get on with the work.