Guides3 min read

What an NDIS audit actually looks at

An NDIS certification audit is not a document check. It is an evidence check, and most of the evidence is about people. Here is what the auditor asks for and why.

The Accorda Team · 22 September 2026

Illustration of a stack of approved documents linked to a chain of timestamped records, one under a magnifying glass

An NDIS audit is run by an approved quality auditor, not by the NDIS Quality and Safeguards Commission itself, against the NDIS Practice Standards. Registered providers are audited when they register and at renewal, and the Commission can ask for one in between. What follows is a plain-English account of what the auditor is actually testing. Timing, scope and the modules that apply to your registration groups are set by the Commission, so confirm your own situation with them.

It is an evidence check, not a document check

The single most common misunderstanding is that an audit checks whether you have policies. It does, but only as the first step. The Practice Standards are written as outcomes ("each participant accesses supports that respect their rights") with quality indicators underneath, and the auditor's job is to find evidence that the outcome is being achieved in practice.

That is why the expectation has shifted from "do you have a policy?" to "can you prove it was current, acknowledged and followed?" A policy that nobody has read is a document, not a control. Evidence that it was followed usually lives in records: sign-offs, training records, incident and complaint registers, and the notes in participant files.

The two stages

A certification audit has a desktop stage and a site stage.

Desktop. The auditor reviews your documents before anyone visits: policies and procedures, your self-assessment, registers, and samples of records. This is where gaps in the paperwork surface, and where a version-controlled policy library earns its keep, because the auditor will ask which version was in force on a given date.

On site. The auditor interviews staff and participants, observes practice where appropriate, and samples records against what people tell them. The classic finding is a mismatch: the policy says one thing, a support worker describes another, and the participant file shows a third. Interviews are not a formality. Auditors talk to participants and families, and "would you know how to raise a concern?" is a standard question.

What the auditor asks for on the day

Providers rarely fail because they do nothing. They fail because they cannot produce the record when asked. The list below is what an auditor asks for in the first hour, and what a provider should be able to hand over without an all-nighter.

  • Current policies, with the version history, and evidence of who approved them
  • Staff acknowledgements: who has signed which policy, and when
  • Training records, including what is current, what is expiring and what is overdue
  • Worker screening clearances and other credentials, with expiry dates and a renewal history
  • The incident register, including which incidents were assessed as reportable and the corrective actions taken
  • The complaints register, with the response and outcome recorded for each complaint
  • The risk register
  • Evidence of internal audit or self-assessment, with findings turned into actions

Each of these is a per-person or per-event record. That is why spreadsheets and shared drives struggle: the evidence is scattered, it is not dated in a way anyone can defend, and assembling it under pressure is where providers come unstuck.

Findings, and what happens next

Findings are graded. A minor non-conformity is a gap that does not put participants at risk and can be closed with a corrective action; a major one is a systemic failure or a risk to participants, and it has to be resolved before certification. The auditor reports to the Commission, which makes the registration decision.

The practical point is that findings are not surprises if you have looked first. An internal audit against the same standards, done in plain English with the evidence spelled out, surfaces the same gaps on your own timetable.

Where to start

If you are preparing for a first audit, or a renewal after a period of growth, three things pay off quickly:

  1. Get the policy library under version control, with the current version obvious and prior versions kept.
  2. Record acknowledgements per person, so the answer to "did staff know this?" is a dated record.
  3. Run a self-assessment against the Practice Standards before the auditor does, and turn each gap into an action with an owner.

Our free Compliance Readiness Check is a four-minute version of that self-assessment, with a readiness band across nine compliance domains. Accorda itself is built to keep the records above current as your team works, so the audit evidence pack is one click rather than a week. Neither replaces advice about your own registration; for that, check with the NDIS Commission.

Start today

See your compliance audit-ready in one place

Try Accorda free for 14 days. Every feature, no credit card, no auto-charge.