If you are a registered NDIS provider heading into a certification audit, here is the uncomfortable truth: auditors rarely fail you for having the wrong policy. They fail you because you cannot prove that your systems work in practice. A beautifully written medication policy means nothing if you cannot show the signed, dated records that demonstrate it was followed. This is an evidence game, and the providers who pass are the ones whose documentation is complete, current and traceable.
This NDIS audit evidence checklist walks through exactly what an approved quality auditor asks for at each stage, organised by Practice Standard area, so you can prepare before your auditor requests it rather than scrambling in the week before Stage 1. Everything below reflects how the two-stage certification audit actually runs under the NDIS Quality and Safeguards Commission framework.
How the NDIS certification audit works (and why evidence matters)
Higher-risk registration groups require a certification audit, which runs in two stages conducted by an approved quality auditor that you engage and pay. Lower-risk supports instead go through a simpler desktop verification audit. If you are unsure which pathway applies to you, read our guide on NDIS verification vs certification audits before you go further.
The certification audit has two distinct stages:
- Stage 1 (desktop/document review): Conducted off-site. Your auditor requests a structured set of documentation and evidence demonstrating compliance with each applicable Practice Standard and Quality Indicator. This is where your policies, procedures and registers are examined on paper.
- Stage 2 (onsite audit): Takes place within three months of Stage 1. The auditor visits your sites, interviews staff and participants, samples participant files, reviews records and makes observations to test whether your documented systems actually operate day to day.
The NDIS Commission does not conduct the audit itself; it makes the final registration decision based on the auditor's report. Certification then runs on a three-year cycle, with a mid-term audit commencing no later than 18 months after your registration takes effect.
Governance and operational management evidence
This is the backbone of every audit and the focus of the mid-term review. Auditors want to see that your organisation is run by capable people with clear accountability. Have the following ready:
- Organisational chart and position descriptions showing lines of accountability
- Governance and management policies, each with a version number, approval date and documented review history
- Risk management framework and a live risk register with dated reviews
- Continuous improvement register showing issues identified, actions taken and outcomes
- Conflict of interest policy and declarations
- Financial records demonstrating viability and appropriate use of participant funds
- Insurance certificates of currency
The single most common gap here is version control. If your policy says "reviewed annually" but the last review date is three years old, that is a finding in itself.
Human resource and worker screening evidence
Auditors scrutinise staff files closely because workforce failures are the fastest route to participant harm. For a sample of workers, be prepared to produce:
- NDIS Worker Screening Check clearances (valid and current)
- Qualifications and relevant certifications
- Induction and onboarding records
- Ongoing training logs, including the NDIS Worker Orientation Module and any role-specific training (for example, high-intensity daily personal activities or medication competency)
- Supervision and performance records
- Evidence of reference and work-history checks
The trap is traceability: it is not enough that a worker completed training; you must be able to show when, and that their screening was verified before they delivered supports.
Participant file and service delivery evidence
At Stage 2 your auditor will pull a sample of participant files and test them against your documented process. Each file should contain:
- A signed and dated service agreement that reflects the participant's current supports
- A care or support plan with evidence of participant involvement and documented reviews
- Consent records, including consent to share information
- Progress notes that are contemporaneous, factual and dated
- Goal tracking that links daily supports back to NDIS plan goals
- Risk assessments specific to the participant
Auditors look for consistency between what the file says and what staff describe in interviews. If a support plan references a daily routine that the on-duty worker cannot explain, that mismatch undermines the whole file. This is why providers increasingly keep rostering, progress notes and participant records in one connected system rather than scattered spreadsheets — see how Rostery's NDIS software keeps shifts, notes and participant records traceable in one place.
Incident management evidence
Incident management is a high-stakes standard and a frequent source of non-conformities. Your auditor will ask for:
- Your incident management policy and procedure
- A complete incident register with dates, categories and severity
- Investigation records and outcomes for individual incidents
- Evidence of reportable incidents notified to the Commission within the required timeframes (immediate notification for the most serious, and five business days for others)
- Corrective and preventive actions, including what changed to stop recurrence
A register that logs incidents but shows no investigation, no outcome and no follow-up action tells an auditor your system is a filing cabinet, not a safeguard.
Complaints, feedback and rights evidence
Providers must demonstrate a working complaints and feedback loop. Prepare:
- Complaints and feedback policy explained in accessible formats
- A complaints log with the nature of each complaint, actions taken, resolution and timeframe
- Evidence participants know how to complain to you and directly to the NDIS Commission
- Records showing feedback feeds into your continuous improvement register
What happens if you have gaps: non-conformities and corrective action
When the evidence is missing or a system is not operating, the auditor records a non-conformity. These are graded:
- Major non-conformity: a serious or systemic failure. You must provide a corrective action plan within 7 days and close it out within 3 months, usually with a follow-up review.
- Minor non-conformity: an isolated or lower-risk gap. It must be closed within 12 months, or at your mid-term or recertification audit (whichever comes first) — if it is not closed in time, it can escalate to a major.
The practical lesson is simple: almost every non-conformity is an evidence or record-keeping problem, not a missing policy. Date-stamped rosters, progress notes, incident records and training logs are what turn a good policy into provable practice.
A pre-audit evidence checklist you can action this week
- Pull a random sample of five participant files and check each has a signed, current service agreement and a reviewed support plan.
- Confirm every active worker has a valid screening clearance recorded with a verification date.
- Review your incident register for any entry without a documented outcome or close-out.
- Check the review date on your top ten policies — update anything overdue.
- Reconcile your training matrix against your current roster so no one is delivering a support they are not trained for.
- Make sure your continuous improvement register shows recent entries, not a stale list from last year.
Work through that list and you will catch most of the gaps an auditor would otherwise find for you.
Frequently Asked Questions
What evidence do NDIS auditors actually ask for?
Auditors request governance documents and policies (version-controlled with review dates), staff files showing worker screening, qualifications and training, participant file samples with signed service agreements and reviewed support plans, an incident register with investigations and outcomes, a complaints log with resolutions, and a live risk and continuous improvement register.
What is the difference between Stage 1 and Stage 2 of an NDIS audit?
Stage 1 is an off-site desktop review where the auditor examines your documentation against each applicable Practice Standard. Stage 2 is an onsite audit, held within three months of Stage 1, where the auditor interviews staff and participants, samples participant files and observes whether your systems operate in practice.
How long do you have to fix an NDIS audit non-conformity?
A major non-conformity requires a corrective action plan within 7 days and close-out within 3 months. A minor non-conformity must be closed within 12 months — or at your mid-term or recertification audit, whichever comes first — otherwise it can escalate to a major.
How often does an NDIS certification audit happen?
Certification runs on a three-year cycle. There is an initial audit after you register, a mid-term audit that must commence no later than 18 months after your registration takes effect, and a recertification audit every three years.
Who conducts the NDIS audit and who decides if I'm registered?
An independent approved quality auditor, which you engage and pay, conducts the audit and submits a report. The NDIS Quality and Safeguards Commission then makes the final decision on your registration.




