Audit Process
The NDIS Provider Audit Process Explained
Once the NDIS Commission issues an Initial Scope of Audit, a provider needs to engage an approved quality auditor to complete an independent audit before registration can be finalised. This guide walks through how that process generally unfolds.
Audits & Practice Standards4 min readLast reviewed:
Takes about 60 seconds. No obligation.
Who this guide is for
- Providers who have received their Initial Scope of Audit and need to engage an auditor
- Providers preparing for their first stage 1 and stage 2 audit
- Operations managers coordinating staff and participant interviews for an audit
- Providers wanting to understand what a non-conformity means and how it's resolved
Where the audit fits in the registration journey
After a provider applies to the NDIS Commission and nominates registration groups, the Commission issues an Initial Scope of Audit that sets out which standards apply and whether a verification or certification-style audit is required.
From there, the provider engages an approved quality auditor — a business independently approved by the Commission to conduct audits — to carry out the assessment.
The auditor's findings are reported back to the Commission, which then completes its own suitability assessment and makes the final registration decision.
Engaging an approved quality auditor
- 01
Confirm your Initial Scope of Audit
Know which modules and standards apply before you contact auditors, so you can describe your needs accurately.
- 02
Approach one or more approved auditors
The NDIS Commission publishes a register of approved quality auditors; providers are free to approach any of them for a quote.
- 03
Compare scope, cost and timing
Auditor fees and availability vary and are set independently by each auditor — we never quote these on your behalf.
- 04
Confirm the audit type and schedule dates
Agree whether the audit will be a verification-style review or a certification audit, and lock in dates for each stage.
- 05
Submit your self-assessment and evidence ahead of time
Most auditors expect your self-assessment and supporting documents before the on-site or interview stage begins.
Typical audit stages at a glance
| Stage | General focus | What providers usually do |
|---|---|---|
| Stage 1 (desktop/document review) | Policies, procedures, self-assessment and key records | Supply organised, current documents mapped to each standard |
| Stage 2 (site or detailed assessment) | Interviews, sampling of files, observation of practice | Make staff and, where applicable, participants available; have records ready to produce quickly |
| Reporting | Auditor documents findings and any non-conformities | Review the draft findings and prepare responses |
| Corrective action | Provider addresses any non-conformities raised | Submit evidence that issues have been fixed within the auditor's timeframe |
Sampling, interviews and what auditors look for
Auditors typically don't review every single file; instead, they sample a selection of participant files, incident records, HR files and other documents to test whether practice is consistent across the organisation, not just in a few showcase examples.
Interviews with staff — and, depending on the audit type, with participants or their families — are used to check that what's written in policy is actually understood and practised day to day.
Consistency matters more than perfection: an auditor is generally more reassured by evidence of a genuine, imperfect system that's actively managed than by a flawless-looking but untested set of documents.
Non-conformities and corrective actions
A non-conformity is a finding that a standard has not been fully met, and audits can raise minor or major non-conformities depending on the seriousness and pattern of the issue.
Providers are usually given a defined period to submit a corrective action plan and evidence that the issue has been addressed, rather than automatically failing the audit outright.
How non-conformities are categorised and resolved is ultimately a matter for the approved auditor and the NDIS Commission's own guidance, so always follow the specific instructions given in your audit report.
Documents an audit commonly draws on
- Self-assessment against the applicable Practice Standards
- Policies and procedures relevant to the registration groups sought
- Sample participant files, service agreements and support plans
- Incident, complaints and feedback registers
- Worker screening, qualification and training records
- Governance records such as meeting minutes and organisational charts
After the audit: the auditor's report
Once the audit is complete, the auditor prepares a report summarising their findings, including any non-conformities and how they were or will be addressed, and submits it to the NDIS Commission.
The Commission then conducts its own suitability assessment, considering the audit report alongside other information, before making the final decision on registration and the registration groups approved.
Providers should keep a copy of the final audit report and corrective action evidence, as this forms part of the record the Commission and any future auditor may refer back to.
Frequently asked questions
- How do I find an approved quality auditor?
- The NDIS Commission publishes a register of approved quality auditors on its website, and providers can approach any listed auditor for a quote.
- Do you conduct audits yourselves?
- No. We are not an approved auditor — we provide application and audit preparation support so you're ready when you engage an independent approved auditor.
- What's the difference between stage 1 and stage 2?
- Stage 1 generally focuses on reviewing documents and your self-assessment, while stage 2 typically involves interviews, sampling and, where relevant, on-site or direct observation.
- What happens if a non-conformity is found?
- Providers are typically given an opportunity to submit a corrective action plan and evidence addressing the issue within a timeframe set by the auditor, rather than automatically failing.
- How much does an audit cost?
- Audit fees are set independently by each approved quality auditor and vary based on scope and complexity, so we recommend requesting quotes directly from auditors rather than relying on a fixed figure.
- Does passing the audit guarantee registration?
- No outcome can be guaranteed. The audit report feeds into the NDIS Commission's own suitability assessment, which makes the final registration decision.
Official sources and further reading
Requirements change. Always confirm the current position with the relevant authority before making decisions.
Ready to move forward?
Get an indicative pathway in about a minute, or start your registration with personalised support for your documents, self-assessment and audit preparation.
NDIS Provider Registration is an independent service and is not affiliated with or endorsed by the NDIA or the NDIS Quality and Safeguards Commission. We provide application preparation and audit preparation support; independent auditor fees are separate and registration decisions are made by the Commission.
