What is Certification audit?
A certification audit is the NDIS registration audit for providers delivering higher-risk or more complex supports. An approved quality auditor assesses the provider against the core module and relevant supplementary modules of the NDIS Practice Standards in two stages, including an onsite visit with staff and participant interviews.
Supports such as supported independent living, high intensity daily personal activities and implementing behaviour support plans are typical of the certification pathway.
Providers who registered through certification also have a mid-term audit 18 months into the registration period.
The two stages
- Stage 1: the auditor reviews the provider's documented systems, policies and procedures against the modules that apply.
- Stage 2: an onsite audit, held within three months of Stage 1 finishing, where the auditor checks how the policies are actually implemented. This can include viewing records, visiting sites, observing supports and interviewing workers and participants.
Participants are automatically enrolled in the audit unless they opt out, so let them know in advance. After Stage 2 the auditor drafts a report, the provider checks it for factual accuracy, and the final report goes to the NDIS Commission within 28 days of the audit finishing.
What auditors sample
- Governance: how risks and incidents are escalated to leadership, and board or management meeting minutes
- Staff files: screening clearances, qualifications, induction and training records
- Participant files: service agreements, support plans, progress notes and risk assessments
- Incident and complaints registers, including how trends are reviewed
- Restrictive practice records and behaviour support plans, where relevant
Findings are rated as conformity, minor non-conformity or major non-conformity, with corrective actions and timeframes for anything that falls short.
The mid-term audit
Providers that completed a certification audit and are registered for higher-risk or more complex supports need a mid-term audit 18 months into their registration period. It checks that the systems seen at certification are still working, so the evidence needs to be kept up between audits, not rebuilt before them.
The Commission can also require a condition audit during the registration period, and an out of cycle audit may be needed if you want to change the supports and services you deliver.
How Rostery helps
Rostery keeps audit-ready records for sampling: worker screening and qualification expiry, progress notes against shifts, incidents with reporting deadlines, and restrictive practice and behaviour support records.
Questions people ask
How long is the gap between Stage 1 and Stage 2?
The Stage 2 onsite audit should take place within three months after Stage 1 is complete.
Will the auditor talk to participants?
Usually, yes. Participants are enrolled in the audit unless they opt out, and auditors may interview them about their experience of supports.
Who needs a mid-term audit?
Providers who completed a certification audit and are registered for higher-risk or more complex supports, 18 months into their registration period.
When does the auditor submit the certification report?
Up to 28 days after the audit is completed.
Checked against the official sources on 2 October 2026. Rules change: confirm the current position with the agency before you rely on it.
Related terms
More in Compliance
Rostery handles this in practice
SCHADS interpretation, NDIS price-guide validation, claiming and the evidence an audit asks for — built for Australian providers.
