For a lot of providers, the NDIS Practice Standards first appear as a PDF that feels like a wall — parts, outcomes, quality indicators, clause after clause. It's easy to read that document and feel like compliance is a test written in another language.
It isn't. Strip away the structure and the Practice Standards are a description of what good, safe support actually looks like — the things a well-run provider already tries to do every day. The work isn't becoming a different organisation to pass an audit. It's being able to show that what you already do lines up with the standard. And the most reliable way to know whether it does is to check yourself against it, calmly and on your own terms, before an external auditor does it for you.
Here's what the Standards ask, which audit applies to you, and how an internal audit closes the gap between "we do this" and "we can prove it."
What the NDIS Practice Standards actually are
The NDIS Practice Standards are the national quality and safety framework for registered NDIS providers. They set out the quality standards a provider has to meet when delivering supports and services to participants, and they give participants a clear picture of the quality of service they should expect. They're enforced by the NDIS Quality and Safeguards Commission, and they sit alongside the NDIS Code of Conduct, which sets the expectations for how workers and providers behave.
The important thing to understand is that for a registered provider, meeting the Standards isn't optional or aspirational. It's a condition of registration. Providers have to be able to demonstrate their compliance through external audit by an approved quality auditor — at registration, and again at renewal.
How the Standards are structured
The Standards are built as modules, which is what lets them apply fairly to a solo allied health clinic and a large disability service alike.
The core module applies to all registered providers delivering higher-risk supports. It covers the foundations: participant rights and responsibilities, provider governance and operational management, the provision of supports, and the support environment.
Supplementary modules apply on top of the core module depending on the specific supports you deliver — for example high-intensity daily personal activities, specialist behaviour support, or early childhood supports.
The verification module applies to providers delivering lower-risk supports, and sets a lighter bar focused on areas such as complaints management, incident management, risk management and human resource management.
Which modules apply to you decides your audit pathway, and the requirements are proportionate to your size, scale and the type of supports you deliver.
The audit that decides your registration
There are two pathways, and knowing which one is yours changes everything about how you prepare.
A verification audit is the lighter, largely document-based pathway for lower-risk supports. An allied health clinic delivering therapy through AHPRA-registered practitioners will often sit here.
A certification audit is the fuller pathway for higher-risk supports. It runs in two stages — a document and desk review, then an on-site stage where the auditor tests what's really happening through interviews with workers and participants, observation, and record reviews. Certification runs on a three-year cycle, with a mid-term audit in between to confirm you're still meeting the Standards.
Either way, the auditor isn't there to hear that you do the right thing. They're there to see the evidence that you do — documented policies mapped to the Standards, incident and complaints systems, risk management, worker screening and credential controls, and records that back all of it up.
The part most providers miss: the Standards expect you to audit yourself
Here's a detail that's easy to skip past. Inside the core module's governance and quality management requirements, the Standards expect a registered provider to run a documented program of internal audits, proportionate to the provider. In other words, self-checking against the framework isn't just a good idea you might get around to. A version of it is written into the standard your external auditor assesses you against.
Doing the right thing and being able to show it are two different things. An internal audit is where you find the gap between them — while you still have time to close it.
That reframes internal audit from "extra work" to "the work the Standards already ask for." Run it well and you get two things at once: you satisfy an expectation the auditor will look for, and you find your weak spots months before anyone official does.
How Accorda's Internal Audit works
This is exactly what Accorda's Internal Audit feature is built for — a calm, structured way to walk the standard, item by item, and see where you stand.
It starts with a checklist that faithfully encodes the NDIS Practice Standards Core Module — its four sections, twenty-four outcomes and the underlying quality indicators — paraphrased in plain English and traceable back to the Commission's published source. You're not auditing against a generic template; you're auditing against the actual framework.
From there:
Scan for gaps first. Before you work through a single item, an optional AI gap scan compares the standard's requirements against your own policy library and flags the areas most likely to need attention — so you know where to look first. It's advisory only: it points, it never judges, and it never decides whether you're compliant.
Work through each requirement. You mark each item compliant, non-compliant or not applicable, with notes. As you go, Accorda tracks your progress and works out an overall readiness verdict — from compliant through substantially compliant to action required — with a running count of what's compliant and what isn't.
Find your evidence. For any item, an AI evidence finder searches your own policies and surfaces the passages that actually support that requirement, each with the real quote from your document and a one-line reason. You decide what counts; nothing is invented and nothing is attached without you.
Turn findings into actions. A non-compliant item can become a tracked corrective action against the audit, so a gap you found doesn't quietly get forgotten — it gets owned, worked and closed.
Produce a report. When you're done, Accorda generates a branded audit report — your sections, your findings, your readiness verdict — with an optional AI-written executive summary that states the result factually and plainly.
Being honest about what it is
An internal audit in Accorda is a dress rehearsal, not the performance. It does not certify you, it does not pass your audit, and it is not a substitute for the approved quality auditor — only the Commission's process can register you. The AI is advisory throughout: it helps you find gaps and evidence faster, but a human makes every compliance call, and the report's own summary is careful never to imply you're certified or guaranteed to pass.
What it does do is take the fear out of the framework. Instead of meeting the Practice Standards for the first time across a table from your auditor, you meet them on a quiet afternoon, in your own system, with time to fix what needs fixing. That's the whole point of auditing yourself first — and it's the internal audit program the Standards were already asking you to run.
If you'd like to see where you stand against the NDIS Practice Standards, take a look at how Accorda's Internal Audit works.
Sources
Disclaimer
Disclaimer This article is general information only, current as at August 2026, and is not legal or compliance advice. Regulatory requirements can change.