Key Takeaways
- There are five NDIS audit types, not two: verification, certification, mid-term, condition and out of cycle. Your registration groups decide which applies, and if your application mixes verification groups with certification groups, the whole application is assessed at certification level.
- Verification is a desk audit of documentation with no site visit. Certification adds an inspection of your sites and interviews with key personnel and participants, defined that way in section 5 of the Provider Registration Rules.
- Certification-pathway providers carry a mid-term audit as a condition of registration. Under section 13B of the Provider Registration Rules it must start no later than 18 months after the registration period begins, and the Commission's guidance has providers engaging an auditor from the 12-month mark.
- Three exemptions from the mid-term audit are written into the Rules: an individual or partnership registered only for early intervention supports for early childhood, a provider registered only for specialist disability accommodation, and a transitioned provider or transitioned RAC provider.
- A corrective action plan is due to your auditor within seven calendar days of written notification. A major non-conformity must be downgraded or closed within three calendar months. A minor non-conformity has eighteen calendar months, then it escalates to a major automatically. These windows are Annex C of the NDIS auditor guidelines, not auditor discretion.
- Stage 2 should start within three months of Stage 1 finishing, and your auditor must give you the Stage 1 findings at least two weeks before Stage 2 starts where a non-conformity was found or is suspected.
- The audit report goes to the Commission within 14 days of a verification audit and 28 days of a certification or mid-term audit.
- The approved quality auditor pool is closed. The Commission is not accepting new applications from would-be auditors, and its list as at 31 July 2026 records both Quality Innovation Performance and Citation Certification as former auditors, leaving 17 firms.
If you are a registered NDIS provider, or applying to be one, your audit type is set by your registration groups rather than by your size. Lower-risk groups take a verification audit, which is a desk review of documents. Higher-risk groups take a certification audit, which adds a site inspection and interviews, plus a mid-term audit 18 months in. This guide covers both pathways end to end and the evidence to have ready for either.
Which NDIS audit applies to you?
The Commission publishes a registration groups table that maps every group to its audit type, and it is the source to use. Secondhand guidance, including the earlier version of this page, has had several groups on the wrong side of the line.
Verification covers the equipment and modification groups (0103, 0105, 0109, 0111, 0112, 0113, 0122, 0123, 0124, 0135), accommodation and tenancy assistance (0101), travel and transport (0108), community nursing care (0114), innovative community participation (0116), household tasks (0120), interpreting and translation (0121), exercise physiology and personal training (0126), plan management (0127), therapeutic supports (0128), specialised driver training (0129), assistance animals (0130), and hearing services (0119, 0134).
Certification covers employment and higher education support (0102), high intensity daily personal activities (0104), assistance in coordinating or managing life stages, transitions and supports (0106), assistance with daily personal activities (0107), specialist positive behaviour support (0110), assistance with daily life tasks in a group or shared living arrangement (0115), development of daily living and life skills (0117), early intervention supports for early childhood (0118), participation in community, social and civic activities (0125), specialist disability accommodation (0131), specialised support coordination (0132), specialised supported employment (0133), group and centre based activities (0136), NDIS digital platform services (0137), and assistance with supported independent living (0138).
Two of those catch people out. Support coordination under 0106 is a certification group, not verification, even though it is often described as the light-touch coordination option. And the two community participation groups sit on opposite sides: 0116 innovative community participation is verification, while 0125 participation in community, social and civic activities is certification.
The mixing rule is in the Commission's own words: if a provider's application includes registration groups associated with both verification and certification audits, they need to complete a certification audit. A provider combining therapeutic supports with personal care cannot take the verification pathway. Check your group selections before you lodge, because the choice sets your cost and your timeline for the next three years. Our registration groups guide walks through the mapping in detail, and the NDIS Compliance Quiz gives you a rapid gap assessment against the groups you hold.
| Audit type | When it applies | What it involves |
|---|---|---|
| Verification | Registration or renewal covering only lower-risk groups | Desk audit of documentation, off site, no interviews |
| Certification | Registration or renewal including any higher-risk group | Stage 1 desk audit, then Stage 2 site inspection and interviews |
| Mid-term | Certification-pathway providers, unless exempt | Governance and operational management standards, plus open corrective actions |
| Condition | Imposed by the Commission during your registration period | Scope set by the condition on your certificate |
| Out of cycle | You apply to change your registration groups or service delivery | Assessment of the added scope |
Two more triggers were added by the 2026 reforms. Section 13BA of the Rules now makes a change in ownership audit a condition of registration for a certification-pathway provider when a change of ownership causes a significant change to the organisation or its governance. That audit must start no later than three months after the change, and the report is due to the Commission within 28 days.
What is the difference between verification and certification?
The difference is written into section 5 of the Provider Registration Rules. Verification is an assessment by an approved quality auditor conducted as a desk audit of your relevant documentation. Certification is a desk audit plus two things: an inspection of the sites, facilities, equipment and services used to deliver supports, and interviews with relevant people including your key personnel and the participants you support.
Verification providers are assessed against the verification module of the NDIS Practice Standards, which covers human resource management, risk management, complaints management and resolution, and incident management. Many are already regulated professionally, through AHPRA or a professional association, so the audit leans on the qualifications and membership evidence set out in the Commission's Qualification and Professional Associations Required Documentation Guide.
Certification providers are assessed against the core module, which covers rights and responsibility for participants, provider governance and operational management, provision of supports, and provision of supports environments. On top of that sit the supplementary modules, and there are now seven of them rather than the four that older guidance lists: high intensity daily personal activities, specialist behaviour support, implementing behaviour support plans, early childhood supports, specialised support coordination, specialist disability accommodation, and supported independent living. The supported independent living module started on 1 July 2026 and is covered in our SIL mandatory registration guide. Our Practice Standards modules guide sets out what each one adds.
One thing that does not scale with size: the Rules require the certification assessment to be proportionate to the size of the provider, the geographical spread and number of locations, and the scope and complexity of the supports. A sole trader and a 40-site organisation are held to the same standards, assessed at a different depth.
The certification audit, stage by stage
Engaging an approved quality auditor
The process starts when you lodge your application through the provider portal. You then engage an approved quality auditor, an independent body approved by the Commission and accredited by JASANZ, the Joint Accreditation Scheme of Australia and New Zealand. You choose your own auditor from the current list; the Commission does not assign one, and it does not set prices.
Lodgement comes first. Your application generates the initial scope of audit, which is the document the auditor prices against. You give the auditor a unique reference number, they associate with your application in the auditors portal, and the final scope is agreed before the audit starts.
A certification audit needs an audit team of at least two auditors. Verification, mid-term and provisional audits need at least one. Where the audit needs particular technical expertise, the team has to include a technical expert, and for a clinical matter that expert must be at least a registered nurse with current AHPRA registration.
Stage 1: the desk audit
Stage 1 is an off-site review of your self-assessment responses and the documents you submitted with the application, your previous audit outcome and corrective actions if you have one, and anything extra the Commission has raised. It can be conducted on site instead, but only for a certification or recertification audit and only where you have agreed to that in writing beforehand.
The documentation usually requested covers your governance framework, risk management plan, quality management system, incident management policy, complaints policy, privacy and confidentiality policy, code of conduct, worker screening register, staff training records, participant service agreements, and current insurance certificates.
Two timing rules protect you here. Where the auditor has found a non-conformity or suspects one is likely, they must give you the Stage 1 findings at least two weeks before Stage 2 starts. Where none is found or suspected, the minimum is one week. And if the audit team decides you are unlikely to be ready for Stage 2, they have to tell you and tell the Commission that Stage 2 is likely to be delayed while you correct the gaps. A delayed Stage 2 is not a failure, it is the system working as designed.
Stage 2: the site audit
Stage 2 should start within three months of Stage 1 finishing. Auditors visit your service locations to test whether what you documented at Stage 1 matches how the organisation runs. It involves interviews with leadership and frontline staff, conversations with participants and their support networks, file reviews, and direct observation of supports being delivered.
Participants are sampled on an opt out basis. You have to tell every participant they are automatically included, and if someone does not want to take part you respect that, document it, and pass it on to the auditor. The Commission publishes participant-facing factsheets for exactly this conversation.
Duration scales with size and complexity, from a few hours for a single-site provider to several days across locations for a provider with multiple accommodation sites and behaviour support registration. What is assessed is implementation, not the existence of a policy. The Commission's own description of the day is blunt about it: auditors want incident reports, complaints records, training logs and supervision notes, not the policy that says those things happen. A policy your staff cannot describe in their own words is a finding.
The report and the Commission decision
After Stage 2 the auditor drafts the report, shares it with you to check for factual accuracy, has it reviewed by a technical reviewer, and submits it to the Commission through the portal. The deadlines are 14 days after a verification audit and 28 days after a certification or mid-term audit. If the Commission finds the report incomplete, the auditor has two business days to supply more evidence unless another arrangement is made.
The Commission then makes the registration decision under section 73E of the NDIS Act 2013, which requires it to be satisfied that you have been assessed as meeting the applicable standards and that you and your key personnel are suitable. Processing time varies with the size of the organisation and the Commission's workload, so plan for the lag if you are renewing against an expiry date.
A critical risk runs on a separate clock. Auditors must notify the Commission immediately or within 24 hours, and critical risks or other serious matters would normally require an on-site follow-up or re-audit within three calendar months. Where the risk involves criminal acts or child protection concerns, the audit team leader notifies the Commission and the relevant authorities and stops the audit until the Commission says it can restart.
What do NDIS auditors actually look for?
Across both pathways the evidence falls into seven areas. Nothing here is a Commission-published list; it is the shape the requested documentation takes in practice, mapped to the standards it evidences.
| # | Evidence area | What auditors look for |
|---|---|---|
| 1 | Governance and policies | Current, version-numbered policies with review dates and staff acknowledgement records, and evidence they reflect how you actually operate |
| 2 | Worker screening register | Every worker in a risk-assessed role with a current NDIS Worker Screening Check, tracked by issue and expiry date |
| 3 | Incident management | Reportable incidents notified within the statutory timeframes, with investigation, actions taken and preventative measures recorded |
| 4 | Participant records | Signed service agreements, support plans, progress notes, and evidence that participants exercised choice and control |
| 5 | Complaints register | A populated log showing investigation, outcome, and any service changes that followed |
| 6 | Risk register | A live document with identified risks, mitigations and review dates, not a file written once at registration |
| 7 | Insurance and financials | Current public liability, professional indemnity and workers compensation certificates, plus financial sustainability evidence |
Two of those seven carry hard external deadlines that an auditor can check against a date stamp.
Reportable incidents. Death, serious injury, abuse or neglect, unlawful sexual or physical contact or assault, and sexual misconduct must be notified to the Commission within 24 hours of the provider becoming aware. Use of a restrictive practice that is unauthorised in your state or territory, or that is not in line with a behaviour support plan, is 5 business days, unless it resulted in harm, in which case it drops back to 24 hours. The 5 Day Form follows every 24-hour notification and is the only form needed for an unauthorised restrictive practice that caused no immediate harm. Our reportable incident decision tool walks the categories.
Worker screening. NDIS Worker Screening Checks are valid for up to five years from the date of issue. Because the national scheme opened in 2021, the first wave of five-year clearances has been reaching expiry through 2026, and a worker whose clearance lapses while they are in a risk-assessed role is a non-conformity waiting to be written up. Renewal can be lodged up to 90 days before the expiry date, and employers get a notification when a linked worker's check is expiring, though relying on that alone is thin. Our worker screening obligations guide covers the ongoing duties, and the worker screening expiry tool will date the renewals for you.
The 2026 preparation checklist
Here is what to have ready before your auditor arrives, or before you submit the documentation package for a verification audit.
Governance and policies. Confirm every core policy is current, dated and reviewed, with a version number and evidence that staff have acknowledged it. That means your governance framework, risk management plan, quality management system, privacy and confidentiality policy, complaints and feedback policy, incident management policy, and code of conduct. A twelve-month review cycle is the convention rather than a rule in the Standards, but a policy that has not been touched since your last audit is the easiest finding an auditor will write all week. Our NDIS policy templates cover the core module policy areas if you are starting from a blank page, and the policy and procedure guide covers the version control auditors look for.
Worker screening and HR records. Build a register of every worker in a risk-assessed role with their screening status, issue date and expiry date. Add training records showing induction, the NDIS Code of Conduct, and role-specific competencies. For high intensity supports, competency has to map to the specific clinical task, not to a general care qualification. The staff onboarding guide sets out the sequence.
Incident management records. Every reportable incident logged against the 24-hour and 5-business-day clocks, with who was notified, what was done, and what changed afterwards. The most common gap is not the notification, it is the follow-up: the incident is logged, the lesson never lands anywhere.
Participant records. Service agreement, support plan, progress notes and evidence of choice and control for each participant. Auditors are looking for supports tailored to the individual rather than a template with a name at the top. Our service agreement requirements checklist covers what has to be in the agreement itself.
Complaints and risk registers. A complaints log showing how each item was investigated, the outcome, and any service change that followed. If you have had no complaints, document how you seek participant feedback instead, because an empty register with no explanation reads as a register nobody uses. The risk register needs identified risks, mitigations, review dates and evidence of monitoring; the risk register guide covers the structure auditors expect.
Insurance and financial records. Current certificates for public liability, professional indemnity and workers compensation, plus the financial evidence that shows you can keep operating.
Organising all of it is half the job. Whether you use folders on a shared drive or a compliance platform, the auditor has to find things quickly, and the evidence pack guide covers how to structure it by criterion.
Five non-conformities that come up again and again
1. Policies that do not match operations. The most common finding is not a missing policy, it is a policy that describes an organisation you no longer are. If you have grown, moved, or added support types since the last review, the document needs to catch up.
2. Gaps in worker screening records. One worker in a risk-assessed role with an expired or missing check is a non-conformity. Track renewals centrally with reminders well ahead of expiry, not in the month it falls due.
3. Incomplete incident records. Auditors trace an incident from first report to closure: initial report, internal review, actions taken, notification obligations. Where the trail stops halfway, the finding follows.
4. Weak complaints evidence. An empty complaints register combined with no evidence of feedback-seeking invites the auditor to test whether participants know how to complain. They ask participants directly, so this one is checked against the participant's answer, not yours.
5. A risk register nobody has opened. A register written at registration and never revised shows no monitoring. Reviews, new risks identified over time, and evidence the mitigations work are what turn it into a live system.
What happens if you get a non-conformity?
Non-conformities are rated on a four-point scale, and the timeframes attached to them come from Annex C of the NDIS auditor guidelines, a legislative instrument. They are not your auditor's discretion, and they are not negotiable.
| Rating | Meaning | What has to happen |
|---|---|---|
| 3 | Conforms with elements of best practice | Nothing |
| 2 | Conforms with the NDIS Practice Standards | Nothing |
| 1 | Minor non-conformity | Corrective action plan within 7 calendar days; closed out within 18 calendar months at the mid-term or recertification audit, whichever comes first, or it escalates to a major |
| 0 | Major non-conformity | Corrective action plan within 7 calendar days; downgraded or closed within 3 calendar months; a rating of 0 precludes a recommendation for certification |
Three consequences follow from that table. Three minor non-conformities within the same module may constitute a major non-conformity in their own right, so a scatter of small findings in one area is not the safe outcome it looks like. A minor that escalates to a major cannot be downgraded back, and if the escalated major is not closed within three calendar months the certification decision is automatically suspended. And a major that gets downgraded to a minor has twelve calendar months from the date of the original finding, not eighteen, which leaves nine months once the first three are spent.
For a major non-conformity your auditor does a desktop review of the implemented corrective actions within three calendar months of receiving your plan, with an on-site follow-up if needed. Where you have raised corrective actions, the relevant Practice Standards outcomes get audited again at your mid-term or recertification audit to confirm the plan turned into practice.
The framing matters. Auditors are testing whether your systems work and whether you respond when something goes wrong. A provider who had an incident, managed it and recorded what changed reads better than a provider claiming nothing has ever gone wrong.
Mid-term audits: the 18-month condition
Certification-pathway providers have a third audit obligation between initial registration and renewal. Section 13B of the Provider Registration Rules makes it a condition of registration: the audit must be carried out by an approved quality auditor using certification, and it must start no later than 18 months after the beginning of the registration period, unless the Commissioner allows longer.
The Commission's guidance splits that into two markers. At 12 months you engage an auditor from the approved list, confirm scope and timing, review the standards you will be assessed against, and gather the evidence. At 18 months the audit is finalised and your auditor submits the report.
Scope is narrower than a full certification audit. It assesses the standards in Part 3 of Schedule 1 to the Rules, which is provider governance and operational management, plus any standard where a previous assessment identified a need for a corrective action plan, plus any standard the Commissioner specifies in a written notice. It is conducted on site and involves document review, staff interviews and participant interviews. Findings carry the same Annex C consequences as findings at a full audit.
Three exemptions are written into section 13B(7). The mid-term audit does not apply to an individual or partnership whose only certification-level class of supports is early intervention supports for early childhood, to a provider registered only for specialist disability accommodation, or to a transitioned provider or transitioned RAC provider. Verification-pathway providers never had the obligation in the first place.
Missing the date is a breach of a condition of registration, which exposes you to compliance action up to suspension.
What your certificate of registration says
A successful application results in a certificate of registration issued under section 73E of the NDIS Act. The Act sets out what it must specify: what you are registered in relation to (managing funding for supports, providing supports under plans, providing supports under the Chapter 2 arrangements, or providing supports to people with disability outside the NDIS), the classes of supports or services you are registered to provide, the class of persons where relevant, any conditions the Commissioner has imposed under section 73G, the period for which the registration is in force, and anything else the Commissioner determines.
Registered providers are generally registered for three years, and the audit program in the auditor guidelines works to a three-year initial cycle beginning on the registration approval date. Conditions imposed by the Commissioner can cover the types of quality audits you must undergo and their timing, which is where a condition audit comes from. Conditions appear on the certificate and on the publicly accessible NDIS Provider Register.
Renewal runs on a six-month window. You can start the renewal process any time in the six months before your expiry date, and the recertification audit is planned to occur no earlier than six months before the renewal date. Section 73K of the Act does the useful work here: if you apply within that six-month window, your registration continues in force until the Commissioner decides your application. Start after the expiry date and the registration has lapsed, you have no valid registration while the application runs, and you complete a full new application and audit process.
Choosing an approved quality auditor
Only bodies approved by the Commission can conduct NDIS Practice Standards audits. JASANZ manages and administers the scheme on the Commission's behalf: it accredits auditors, monitors them with scheduled and unscheduled surveillance, and oversees compliance with the accreditation manual, the auditor guidelines and the auditors code of conduct.
The pool is closed. The Commission is not currently accepting new applications to become an approved quality auditor, a decision taken after the independent review of the NDIS, the Disability Royal Commission, and the work of the NDIS Provider and Worker Registration Taskforce. It says the decision will keep being reviewed as part of the broader reform program during 2026, and any restart will be published on its own page and on the JASANZ website.
Two firms have left. The Commission's Find an auditor page, last updated 31 July 2026, records Quality Innovation Performance Limited as an approved quality auditor from 2019 to 2026 and Citation Certification as an approved quality auditor from 2020 to 2026. Both now sit in the notes section rather than the active list, leaving 17 firms, all operating Australia-wide (the current names are in the FAQ below).
Fewer firms and a closed pool means booking earlier than you would have two years ago. Approach several at once rather than one at a time, ask specifically about experience with the supplementary modules your registration groups trigger, and get written timelines alongside the quote. Quotes are free and no-obligation, and the code of conduct requires auditors to accept that you are free to select and change your auditor. Staying with the same auditor across an audit cycle has an upside the Commission itself points to: they know your service, so feedback and progress tracking get sharper. If you are unhappy with how an audit was run, raise it with the auditor first, then with the firm that employed or contracted them, then with JASANZ.
What does an NDIS audit cost?
There is no cost to register with the NDIS Commission. You pay for the audit, and the Commission does not set or publish prices, so the ranges below are ClinicComply's own estimates from provider-reported quotes rather than published figures.
Verification audits generally run $3,000 to $6,000, certification audits $8,000 to $20,000 or more, and mid-term audits $4,000 to $10,000, all scaling with the number of sites, the complexity of the supports, and the modules in scope. The NDIS audit cost estimator gives you a tailored range in about a minute, which is a useful sanity check before you approach auditors for formal quotes.
Budget for preparation separately: gap analysis, policy work, staff training, and whatever system holds the evidence. Providers who spend more on preparation than on the audit are usually the ones who pass it cleanly.
Working backwards from your audit date
If your audit is three months out or less, the sequence below is the one that works.
Three to two months out. Gap-analyse against every applicable Practice Standard. Find policies that are missing or that no longer describe the organisation, check every worker's screening status against its expiry date, and read one incident end to end the way an auditor would.
Two to one month out. Close what you found: update the policies, renew expired screening checks, complete the missing documentation. Then run a mock audit, or have someone outside the compliance function walk your evidence and ask "can you show me".
Final two weeks. Organise the evidence so it maps to criteria rather than to your folder habits. Brief staff on what to expect, especially if interviews are in scope. Confirm participants have been told they are automatically included and that any opt-outs are documented and passed to the auditor.
Frequently Asked Questions
What is the difference between an NDIS verification audit and a certification audit?
A verification audit is a desk audit of your documentation with no site visit and no interviews, and it assesses the verification module of the Practice Standards. A certification audit adds an inspection of your sites, facilities, equipment and services, and interviews with key personnel and participants. Section 5 of the Provider Registration Rules defines both. Your registration groups decide which applies.
What documents do I need for an NDIS audit?
Current versions of your core policies (governance, risk management, complaints, incident management, privacy, code of conduct), a worker screening register for every risk-assessed role, incident and complaints logs, participant service agreements and support plans, staff training records, insurance certificates, and your risk register. Certification audits also require evidence against any supplementary modules your registration groups trigger.
Who needs to complete an NDIS mid-term audit?
Providers registered for a class of supports assessed by certification. Section 13B(7) of the Provider Registration Rules exempts an individual or partnership registered only for early intervention supports for early childhood, a provider registered only for specialist disability accommodation, and transitioned providers and transitioned RAC providers. Verification-pathway providers never had the obligation.
When is the NDIS mid-term audit due?
It must start no later than 18 months after the beginning of your registration period, unless the Commissioner allows longer. The Commission's guidance has you engaging an auditor and confirming scope at the 12-month mark, then finalising the audit and having the report submitted by 18 months. Missing the date breaches a condition of registration.
How long do I have to fix an NDIS audit non-conformity?
A corrective action plan is due to your auditor within seven calendar days of written notification, for both ratings. A major non-conformity must be downgraded or closed within three calendar months. A minor non-conformity must be closed out within eighteen calendar months at your mid-term or recertification audit, whichever comes first, or it escalates to a major automatically.
What happens if my NDIS audit finds a major non-conformity?
A rating of 0 precludes a recommendation for certification, so registration does not progress until it is resolved. Your auditor reviews the implemented corrective actions within three calendar months of receiving your plan, with an on-site follow-up if needed. At a mid-term or recertification audit, failing to downgrade or close it within three calendar months automatically suspends the certification decision.
How long does an NDIS certification audit take?
There is no published end-to-end figure, but the fixed points are known. Stage 2 should start within three months of Stage 1 finishing. Stage 1 findings arrive at least two weeks before Stage 2 where a non-conformity is found or suspected. The report goes to the Commission within 28 days of the audit completing. Commission processing then varies with the size of the organisation.
Who are the approved quality auditors for NDIS in 2026?
Seventeen firms, all operating Australia-wide, on the Commission's Find an auditor page as at 31 July 2026: BSI Group ANZ, DNV, Global-Mark, HDAA Australia, Institute for Healthy Communities Australia Certification, Quantum Certification Services, SAI Global, Assured Auditing, Certification Partner Global, Certifii, Global Compliance Certification, AQC Group, Australian Quality Certification, AVA Certification, Sustainable Certification, Audit Wise Group and Platinum Certification. The Commission is not accepting new auditor applications.
When can I renew my NDIS registration, and can I keep delivering while it is processed?
Any time in the six months before your expiry date. Apply within that window and section 73K of the NDIS Act keeps your registration in force until the Commissioner decides, so you keep delivering. Apply after expiry and your registration has lapsed: no valid registration during the process, and a full new application and audit. For a first-time application you are not registered until the certificate issues, and delivering supports that require registration without it is an offence under section 73B(4) carrying imprisonment for 2 years or 120 penalty units, or both. The NDIS Amendment Bill guide covers the provisions.
Have the 2026 NDIS reforms changed the audit process?
Not the mechanics. The pathways, stages, Annex C timeframes and report deadlines are unchanged. What did change: two new certification registration groups (0137 digital platforms, 0138 supported independent living), a new supported independent living supplementary module from 1 July 2026, a change in ownership audit condition under section 13BA, and shorter timeframes for notifying the Commission of certain events and changes.
Part of
NDIS Provider Compliance