What to Expect in an NDIS Verification Audit

Your first NDIS audit doesn't have to be stressful. Here's exactly what auditors look for, how to prepare your documentation, and the common mistakes that trip providers up.

NDIS audit preparation meeting

Got an NDIS verification audit coming up? If you're feeling a bit anxious about it, you're not alone. Most providers are worried about the same thing: "What if I've missed something?"

Here's the good news. Verification audits are the lighter-touch option in the NDIS audit world. They're designed for providers delivering lower-risk supports, and the process is more straightforward than you might think.

That said, preparation matters. Auditors have seen every shortcut and workaround in the book, and they know what good documentation looks like versus what was thrown together the night before.

This guide covers what actually happens during a verification audit, what auditors focus on, and how to walk in feeling prepared rather than panicked.

Verification vs Certification: Quick Refresher

Before we get into the detail, let's make sure we're talking about the right type of audit.

Verification audits apply to providers registered for lower-risk support categories. Think plan management, support coordination, assistive technology, household tasks, or community participation.

Certification audits are the more intensive option, required for providers delivering higher-risk supports like personal care, behaviour support, early intervention, or specialist disability accommodation.

If you're delivering any high-risk supports, you'll need certification — even if most of your work falls under lower-risk categories. The higher-risk registration group determines your audit pathway.

Not sure which audit you need?

Check the NDIS Commission website for the full list of registration groups and their audit requirements. Or give us a call — we help providers figure this out every day.

How Verification Audits Work

A verification audit is essentially a desktop review. An approved quality auditor looks at your policies, procedures, and documentation to assess whether you meet the relevant NDIS Practice Standards.

There's no site visit (unless something raises concerns). The auditor reviews what you submit, may ask follow-up questions, and then makes a recommendation to the NDIS Commission about your registration.

The Timeline

For most providers, the process looks like this:

1

Book your audit

Choose an approved auditor from the NDIS Commission's list

2

Submit documentation

Upload everything to the auditor's portal securely

3

Auditor review

Assessment against Core Module standards

4

Clarification questions

Back-and-forth for additional evidence

5

Audit report

Findings sent to NDIS Commission

6

Registration decision

Commission makes final decision

From booking to decision, plan for 4–8 weeks. Delays usually happen when documentation is incomplete or the provider is slow to respond to auditor questions.

What Auditors Actually Look For

Verification audits assess you against the Core Module of the NDIS Practice Standards. That covers four outcome areas, and understanding what auditors are really looking for in each one will save you a lot of stress.

1. Rights and Responsibilities

This is about how you uphold participants' rights. Auditors want to see that participants genuinely understand their rights, feel safe raising complaints, and are treated with dignity in every interaction.

They'll ask to see your participant rights policy, but more importantly, they want evidence that you've actually communicated those rights to participants. Easy-read versions go a long way here. Your complaints process needs to be accessible and documented — not just a policy that sits in a folder. And your staff need to demonstrate they understand how to support participants in making their own decisions, rather than making decisions for them.

2. Provider Governance and Operational Management

This is the business side of things — how you run your organisation, identify and manage risks, and maintain quality across your services.

Auditors will want to understand your organisational structure and who's responsible for what. They'll look at how you approach risk management and quality improvement. Your insurance certificates need to be current (public liability and professional indemnity at minimum). They'll also want to see that you've thought about business continuity — what happens if something goes wrong? — and that your financial management practices are sound.

3. Provision of Supports

This is where the rubber meets the road. How do you actually deliver supports to participants?

Auditors are looking for evidence that your service delivery is genuinely person-centred. Your service agreements should clearly reflect what participants want, not just what you've decided to provide. Your progress notes need to show how you're responding to individual needs and working toward participant goals. And you'll need to demonstrate you have clear processes for when participants transition between services or exit your organisation altogether.

4. Support Provision Environment

Even without a physical site visit, auditors will assess how you manage the environments where supports happen — and for many providers, that means participants' homes and various community settings.

Your WHS policies need to account for the reality of working in environments you don't control. Incident management is a big one here — you need clear procedures for identifying, reporting, and learning from incidents. Auditors want to see that you're proactively identifying environmental risks before they become problems, and that you've got plans in place for emergencies and disasters.

The Documentation You'll Need

Every auditor's document request list is slightly different, but here is a breakdown of what you should have ready. Don't let the list overwhelm you — most of this is documentation you should already have as part of running your business.

Category What You'll Need
Participant Rights Rights and responsibilities policy, complaints and feedback procedure, privacy and confidentiality policy
Governance Organisational chart, risk management framework, conflict of interest policy, code of conduct
Operations Service agreement templates, continuity of supports policy, incident management procedure
Workforce HR policies (recruitment, training, supervision), staff training records, NDIS Worker Screening clearances
Safety Work health and safety policy, emergency procedures
Evidence Current insurance certificates, sample participant files (de-identified), incident register

You won't necessarily need every document listed — your auditor will confirm exactly what they need based on your registration groups.

This cannot be stressed enough: Quality over quantity

Auditors don't want a document dump. They want to see that your policies are actually used, not just filed away. Include evidence of implementation — training sign-offs, completed risk assessments, incident registers, meeting minutes discussing quality improvement. A well-worn policy with evidence of real-world use will always beat a pristine template that's never left its folder.

Common Mistakes That Trip Providers Up

After years of working with NDIS providers, the same issues come up again and again. These are the ones that cause the most headaches — and they're all avoidable.

Policies that don't match practice

Your complaint policy says concerns will be acknowledged within 24 hours. But when the auditor asks for evidence, you can't show a single documented complaint response. That's a problem.

Auditors are trained to spot policies that were downloaded from the internet and never actually implemented. They'll ask questions like "Can you show me an example of when this process was followed?" If you're scrambling to remember, that tells them everything they need to know.

Incomplete staff records

Worker screening checks, working with children checks, police clearances, training records — it all needs to be current and documented. One expired clearance in your audit sample can derail the whole process. The fix here is simple: set up a system that tracks expiry dates and reminds you before anything lapses. Whether that's a spreadsheet with alerts or purpose-built software like My Care CRM that handles it automatically, the important thing is having something in place.

No evidence of participant involvement

The NDIS Practice Standards are big on person-centred approaches. If your documentation shows you doing things to participants rather than with them, that's a red flag. Service agreements should show evidence of participant input — not just your standard terms with a signature at the bottom. Progress notes should reflect participant goals and preferences, written in a way that demonstrates you're actually listening.

Missing incident records

Here's something that surprises a lot of providers: an empty incident register is worse than one with entries. Every NDIS provider has incidents — it's the nature of the work. If your register is empty, auditors won't assume you're running a perfect operation. They'll wonder what you're not reporting.

Have a clear process, document everything, and show evidence of follow-up actions. This is actually one of the areas where having the right system makes a real difference — My Care CRM walks you through the reporting and follow-up procedures step by step, creating exactly the kind of documentation trail that auditors want to see.

Last-minute document creation

Auditors can tell when documents were created the week before the audit. Version histories, creation dates, and a lack of review records all give it away. Providers sometimes submit beautifully formatted policies that were clearly generated for the audit — and auditors see right through it. Start building your documentation culture now, not when the audit is booked.

How to Actually Prepare

If your audit is a few weeks away, here's a practical approach that works time and time again.

Week
1–2

Gap Analysis

Grab the Core Module requirements and go through them honestly. For each outcome area, ask yourself three questions: Do we have a policy for this? Does it actually reflect what we do in practice? And can we show evidence that we've implemented it?

Be honest with yourself here. This isn't about ticking boxes — it's about identifying where you need to focus your energy before the auditor does it for you.

Week
3–4

Fill the Gaps

This is where the real work happens. Update policies that have drifted out of date. Create records for processes that happen routinely but never get documented. Run training sessions and make sure attendance is recorded.

The goal here isn't perfection — it's having genuine evidence of compliance efforts. Auditors understand that no organisation is perfect. What they want to see is that you're actively working on it.

Week
5+

Organise and Submit

Get your documents organised in a logical structure. Use clear file names that match what's on the auditor's request list. If you're submitting participant records, de-identify them unless the auditor specifically asks otherwise.

Make the auditor's job easy. A well-organised submission signals that you're on top of your operations — and the process will go much faster as a result.

Struggling to keep on top of all this?

Everything discussed in this article — the incident documentation, staff clearance tracking, policy version control, participant records — My Care CRM handles it all in one place. It's built specifically for NDIS providers, and it creates exactly the kind of audit trail that makes verification audits straightforward.

See How It Works Try Our Free Tools

What Happens If You Don't Pass

Let's address the fear head-on: what if the auditor finds problems?

First, understand that minor issues are completely normal. It is rare to see an audit where the auditor doesn't identify at least a few areas for improvement. That's part of the process. You'll have the opportunity to address these before the final report goes to the Commission.

If there are more significant gaps, the auditor may request additional evidence or give you time to implement corrective actions. Outright failures are actually quite rare for providers who've made a genuine effort to prepare. The audit process isn't designed to catch you out — it's designed to lift quality across the sector.

Go in with the mindset that this is a quality improvement exercise, not an exam. That shift in perspective makes a real difference to how the whole experience feels.

After the Audit

Once you've passed, resist the temptation to file everything away and forget about it until next time. Your next audit will come around in three years, and the auditor will want to see that you haven't just been coasting.

They'll be looking for evidence of continuous improvement since your last audit. Have your policies been updated to reflect regulatory changes? Have your staff continued to develop their skills? How have you responded to incidents and complaints along the way?

The providers who cruise through audits are the ones who build compliance into their everyday operations. They're not scrambling every three years because there's nothing to scramble for — it's just how they run their business.

Key Takeaways

The key takeaway from this article is that verification audits don't have to be stressful. They're desktop reviews for lower-risk providers, assessing you against the Core Module of the NDIS Practice Standards.

Focus on demonstrating that your policies are actually implemented, not just written. Pay attention to the common weak spots — staff records, incident documentation, and evidence of participant involvement. Start preparing well in advance, because last-minute document creation is obvious to anyone who's been doing this for a while.

And most importantly, treat compliance as an ongoing commitment rather than a three-yearly scramble. That's the real secret to stress-free audits.

Got questions about preparing for your audit? Get in touch — the My Care CRM team is happy to help.