What decides which audit you need?
The NDIS Quality and Safeguards Commission links each registration group to an audit type. The registration groups in your application or renewal determine whether you complete a verification audit or a certification audit. You do not choose the audit type yourself, and an auditor cannot change it.
The rule that catches many new providers is the mixed application. If even one registration group in your application requires certification, the whole application goes through a certification audit. That is one reason scope matters so much: adding a single higher-risk support can change the cost, effort and evidence required across your entire registration.
After you lodge an application through the Commission portal you receive an initial scope of audit, which confirms the audit type and the standards and modules that apply to you. Check it carefully before you engage an auditor. NDIS rules continue to change through reform, so always confirm the current registration group and audit requirements against the Commission's own guidance.
What is a verification audit?
A verification audit applies to providers who only deliver lower-risk or lower-complexity supports. The Commission describes it as a lighter-touch, desktop audit: you engage an NDIS-approved quality auditor, who reviews the required documentary evidence rather than visiting your sites or interviewing participants.
Verification audits are assessed against the NDIS Practice Standards Verification Module. The Commission publishes a required documentation guide for this module, and in general terms the auditor looks for evidence in four areas.
- Relevant qualifications, expertise and experience for the supports you deliver
- Incident management processes and policies
- Complaints management processes and policies
- Risk management processes and policies, including appropriate insurance
What evidence does a verification audit look for?
In practice, documentation relates to the people delivering supports and the systems around them. The Commission's guidance refers to evidence such as identity, professional qualifications, experience, ongoing professional development, worker screening, insurances and completion of the NDIS worker orientation module, along with systems for human resources, work health and safety, incidents and complaints.
Evidence should be proportionate. The Commission asks approved quality auditors to consider the risk and complexity of the supports delivered and the size and scale of the organisation. A sole trader is not expected to produce the same volume of evidence as a national provider with a large workforce, but every document should be current, accurate and genuinely used.
What is a certification audit?
A certification audit applies to providers who deliver one or more higher-risk or more complex supports. It is a more detailed process that assesses you against the NDIS Practice Standards: the core module, plus any supplementary modules relevant to the supports you deliver.
The core module covers rights and responsibilities for participants, provider governance and operational management, provision of supports, and the support provision environment. Supplementary modules include high intensity daily personal activities, specialist behaviour support, implementing behaviour support plans, early childhood supports, specialised support coordination, specialist disability accommodation and supported independent living, depending on your scope.
How does a certification audit work?
Certification audits are completed in two stages. The Commission's guidance describes the second stage as taking place within three months of the first.
- Stage 1: a review of your documentation, such as policies, procedures and governance records, to check your systems are designed to meet the applicable standards
- Stage 2: an onsite assessment of whether those systems work in practice, which may include viewing records, visiting sites, interviewing staff and participants, and observing supports
What happens after the audit?
The auditor reports findings, including any non-conformities, to you and the Commission. The Commission then considers the audit outcome, along with the suitability of your organisation and key personnel, before making a registration decision. No consultant or auditor can guarantee that decision.
Registration generally runs on a three-year cycle. Providers who completed a certification audit also complete a mid-term audit around 18 months into their registration period, focusing on provider governance and operational management, plus any standard that previously needed a corrective action plan and any others the Commission requires. This is why certification providers benefit most from evidence that is produced by everyday work rather than assembled just before an audit.
How should you prepare for either audit?
Whichever audit applies, preparation follows the same principles. The difference is depth: certification auditors test whether your systems operate in practice, so they will look for live records and talk to your people.
- Confirm your scope first and only include registration groups you can deliver and evidence now
- Read your initial scope of audit and list every standard and module it names
- Map each requirement to a policy, a working process, a current record and a named owner
- Check worker screening, orientation, training and supervision records for every relevant worker
- Make sure key personnel can explain your policies in their own words
- Engage an NDIS-approved quality auditor early and ask them what they will need from you
Frequently asked questions
Can I choose a verification audit to save time and cost?
No. Your registration groups determine the audit type. If any group in your application requires certification, the whole application goes through a certification audit.
Do verification providers have a mid-term audit?
The Commission's guidance describes the mid-term audit as applying to providers who completed a certification audit. Confirm your own obligations in your certificate of registration and current Commission guidance.
Who conducts NDIS audits?
Audits are carried out by NDIS-approved quality auditors, which you engage and pay directly. Auditors are independent of the Commission and of any consultant who helped you prepare.
If I add a higher-risk support later, will my audit type change?
It can. Audit type follows your registration groups, so adding a group linked to certification can bring in certification requirements. Check the Commission's guidance on changing your registration before you expand your scope.
Sources
- NDIS Commission: The quality audit process
- NDIS Commission: Registration groups or classes of support
- NDIS Commission: Verification Module required documentation
- NDIS Commission: NDIS Practice Standards
This article is general information, not legal advice or an eligibility decision. Requirements change, so always confirm against current NDIS Commission guidance.