Rostery
Registration & Compliance

NDIS Verification vs Certification Audit: The Difference

Verification or certification? Your NDIS registration groups decide which audit pathway you are on - and the difference in cost, time and site visits is huge. Here is how the two pathways work, plus the three-year audit cycle including the 18-month mid-term audit.

RRostery Team·23 September 2026·8 min read
NDIS Verification vs Certification Audit: The Difference

If you are registering as an NDIS provider — or renewing an existing registration — one of the first questions you have to answer is whether you need a verification audit or a certification audit. The two pathways sound similar, but they differ enormously in cost, time, intensity and what happens across your three-year registration period. Choosing your registration groups without understanding this can leave you underquoted, underprepared and scrambling before a site visit you did not expect.

The short answer: a verification audit is a desktop review for lower-risk, lower-complexity supports; a certification audit is a two-stage assessment — including an on-site visit — for higher-risk or more complex supports. This guide explains the difference between an NDIS verification and certification audit, how the NDIS Quality and Safeguards Commission decides which one applies to you, what each involves, and how to prepare so nothing on audit day is a surprise.

What decides your audit type: your registration groups

Your audit pathway is not something you choose — it is determined by the registration groups (classes of support) you apply to deliver. The NDIS Commission maps every registration group to either the verification or certification pathway based on the risk and complexity of that support.

The critical rule that trips providers up: if every registration group you apply for is a verification-class support, you are on the verification pathway. But if even one of your groups is a certification-class support, your entire registration moves to certification. You cannot mix pathways — the higher requirement applies to the whole registration.

This is why a provider adding a single higher-risk support to an otherwise low-risk registration can suddenly find themselves facing a site visit and a much larger auditor bill. Before you finalise your registration groups, check the Commission's registration groups table to see which pathway each one triggers.

What a verification audit is

A verification audit applies to providers who deliver only lower-risk, lower-complexity supports and services — examples commonly include some therapeutic supports, plan management, household tasks, assistive technology, home modifications, and interpreting and translating. For these, the Commission accepts that a documentary review provides enough assurance.

In a verification audit you engage an Approved Quality Auditor to complete a desktop review of your required documentary evidence — there is no on-site visit. The required documents are set out in the Commission's verification documentation guide, and even for verification the expectations in 2026 are more substantial than many providers assume. You will need to show evidence of systems for:

  • Incident management and reportable incidents;
  • Complaints handling;
  • Work health and safety;
  • Risk management;
  • Relevant qualifications, professional registration (for example AHPRA where applicable) and insurances.

These systems should be proportionate to the size and scope of your organisation. Because it is documentation-only and single-stage, verification is generally faster and cheaper than certification — but "documentation only" does not mean "easy". Missing or thin policies are still the most common reason verification audits stall.

What a certification audit is

A certification audit is the more thorough pathway, required for providers delivering higher-risk or more complex supports — including Supported Independent Living (SIL), personal care, early childhood supports, behaviour support and high intensity daily personal activities. If any of your groups is certification-class, this is your pathway.

Certification runs in two stages:

  1. Stage 1 (off-site / desktop): the auditor reviews your documented systems — your policies, procedures and the evidence that you have designed processes that meet the applicable NDIS Practice Standards (the Core module on provider governance and operational management, plus the supplementary modules for the supports you deliver).
  2. Stage 2 (on-site): the auditor visits your service locations to confirm those systems are actually being implemented. This stage typically includes reviewing records, observing work practices, and interviewing workers and participants (with consent).

Stage 2 must be undertaken within three months of Stage 1. A certification audit is conducted by an audit team and is significantly more intensive and longer to complete than verification, because it tests not just what your policies say, but whether your practice matches them on the ground.

The NDIS three-year audit cycle for certification providers: two-stage initial audit, 18-month mid-term audit, and recertification before renewal

The three-year audit cycle: it is not a one-off

A common and costly misunderstanding is treating your audit as a single event to get through. Under the NDIS (Approved Quality Auditors Scheme) Guidelines, the standard registration cycle is three years and begins on your registration approval date. What happens across that cycle depends on your pathway.

Certification providers face three scheduled audit events

  • The initial two-stage certification audit before registration is granted.
  • A mid-term audit that must commence no later than 18 months into the registration period. This is a condition of registration, and it is the one providers most often forget. It assesses you against the Practice Standards relating to provider governance and operational management, plus any standard previously assessed as needing a corrective action plan, and any additional standards the Commission specifies.
  • A recertification audit in the third year — no earlier than six months before your registration renewal date. Recertification mirrors the initial audit: a full two-stage assessment against all applicable Practice Standards.

Verification providers have a lighter cycle

Verification-pathway providers do not have a mid-term audit. They re-verify at renewal. There is also a fourth type to be aware of on either pathway — a condition audit, which the Commission can require at any point during your registration period (for example, in response to a complaint, an event, or a change in your circumstances). Auditors can also assess at short notice or unannounced when investigating concerns.

Verification vs certification: the differences at a glance

To summarise the practical differences between the two NDIS audit pathways:

  • Trigger: verification for all-low-risk registrations; certification if any group is higher-risk/complex.
  • Stages: verification is a single desktop review; certification is two stages (desktop + on-site).
  • Site visit: none for verification; required for certification.
  • Interviews: not part of verification; workers and participants are interviewed in certification Stage 2.
  • Mid-term audit: none for verification; required at 18 months for certification.
  • Renewal: re-verification for verification providers; full two-stage recertification for certification providers.
  • Cost and time: verification is generally faster and lower-cost; certification takes longer and costs more because of the second stage and larger audit team.

How to prepare, whichever pathway applies

The best preparation is the same for both pathways: run your organisation the way the Practice Standards describe, every day, so an audit is a snapshot of business-as-usual rather than a fire drill. A practical preparation checklist:

  1. Confirm your pathway early. Check each registration group against the Commission's table before you apply, so the audit type and auditor quote are no surprise.
  2. Map your evidence to the applicable Practice Standards. Know which Core and supplementary modules apply to your groups, and hold a document for each requirement.
  3. Keep systems live, not just written. Incident, complaints, WHS and risk registers should show real, dated entries — auditors look for use, not just existence.
  4. For certification, prepare for the site visit. Brief staff and participants that auditors will observe practice and may interview them, and make sure records match what workers actually do.
  5. Diarise your mid-term audit. If you are on certification, calendar the 18-month mid-term the day your registration is approved — do not wait for a reminder.
  6. Fix corrective actions promptly. Anything flagged at the initial audit will be revisited at the mid-term; close it out and keep the evidence.

Much of what auditors ask for is operational evidence — rosters that show continuity of support, records that show workers hold current qualifications, and clean documentation trails. Keeping that evidence in one system rather than scattered spreadsheets makes every audit dramatically easier. For the registration steps that come before the audit, see our guide to how to become a registered NDIS provider in 2026, and see how Rostery keeps rostering, worker compliance and records audit-ready on the Rostery features overview.

Frequently Asked Questions

What is the difference between an NDIS verification and certification audit?

A verification audit is a single desktop review of your documentation, for providers delivering only lower-risk, lower-complexity supports — there is no site visit. A certification audit is for higher-risk or more complex supports and runs in two stages: an off-site Stage 1 review of your systems, then an on-site Stage 2 that includes reviewing records, observing practice and interviewing workers and participants. Certification is more intensive, takes longer and costs more.

How do I know which audit type I need?

Your audit type is set by the registration groups you apply for, not by choice. If every group is a verification-class support, you are on verification. If even one group is a certification-class support — such as SIL or personal care — your entire registration moves to certification. Check each registration group against the NDIS Commission's registration groups table before you apply.

What is the NDIS mid-term audit?

The mid-term audit applies only to certification-pathway providers and must commence no later than 18 months into your three-year registration period. It assesses you against the Practice Standards for provider governance and operational management, revisits any standard previously flagged for a corrective action plan, and covers any additional standards the Commission requires. Verification providers do not have a mid-term audit.

How long does NDIS registration last?

The standard registration cycle is three years and begins on your registration approval date. The Commissioner sets the exact period on your certificate of registration and can vary it, so always check your own certificate. To stay registered beyond the term you must pass a recertification (or re-verification) audit before your registration expires — certification providers should start that process no earlier than six months before the renewal date.

What is a condition audit?

A condition audit is an audit the NDIS Commission can require during your registration period, on either pathway — for example in response to a complaint, an incident, or a change in your circumstances. Auditors can also assess at short notice or unannounced when investigating concerns, which is another reason to keep your systems audit-ready at all times rather than only before a scheduled audit.

#NDIS audit#verification audit#certification audit#NDIS registration#Practice Standards#mid-term audit#NDIS Commission#NDIS providers
R

Written by

Rostery Team

Part of the Rostery team — sharing NDIS workforce management insights, compliance guidance, and practical resources for Australian disability providers.

Found this useful?

Share it with your NDIS network.

Start Today

Ready to modernise your NDIS operations?

Join 600+ providers using Rostery to manage rostering, compliance, and billing — all in one place.

No obligation · Australian support team · Your data stays in Australia