Get the kit — A$297

Audit

NDIS Audit Preparation Checklist (2026): A Guide for SIL and Registered Providers

To prepare for an NDIS audit in 2026, registered providers must demonstrate compliance with the relevant NDIS Practice Standards modules — starting with the Core Module, plus any supplementary modules tied to their registration groups. SIL providers face an additional layer: four new SIL-specific standards apply from 1 July 2026, requiring documented evidence around supported decision-making, safeguarding, practice governance, and housing agreements.

Why Audit Preparation Matters More in 2026

The NDIS Quality and Safeguards Commission has made 2026 a milestone year for provider accountability. From 1 July 2026, Supported Independent Living (SIL) providers who were previously unregistered must begin the mandatory registration process — and all applicants are assessed against the NDIS Practice Standards through an independent audit by a Commission-approved quality auditor.

This article is general information to help providers understand the audit process and organise their preparation. It is not legal advice. Being audit-ready does not guarantee audit passage — that depends on the evidence you produce and how consistently your organisation operates against the standards.

Step 1: Know Which Audit Type Applies to You

The Commission assigns your audit type based on the risk level of the supports you deliver. There are two main pathways:

Audit Type Who It Applies To What It Involves Typical Duration
Verification Audit Lower-risk supports (e.g. some therapies, household tasks) Remote document review, brief interview 6–12 hours
Certification Audit Higher-risk supports including SIL, behaviour support, high-intensity personal care Document review, staff interviews, site visit, participant interviews 12–36 hours across multiple days

SIL is classified as a high-risk support and requires a certification audit. After your initial registration, ongoing mid-term and renewal audits are scheduled across your registration period to confirm continued compliance. These are generally less intensive than the initial certification but still involve document review and may include site visits.

When you submit your registration application, the Commission will issue an Initial Scope of Audit document that specifies your audit type and the Practice Standards modules your organisation will be assessed against. Review this document carefully — it is your roadmap.

Step 2: Understand the Practice Standards Framework

The NDIS Practice Standards are structured in modules:

  • Core Module (Rights and Responsibilities) — applies to all providers undergoing certification. Covers person-centred supports, privacy and dignity, governance, operational management, feedback and complaints, incidents, and human resources.
  • Supplementary Modules — applied on top of the Core where relevant to your registration groups. Examples include High Intensity Daily Personal Activities, Implementing Behaviour Support Plans, and Specialist Support Coordination.
  • SIL Module (new, from 1 July 2026) — four additional standards applying specifically to supported independent living providers (see Step 3 below).
  • Verification Module — a lighter set of standards for lower-risk providers on the verification audit pathway.

Check the Commission's registration groups page to confirm which modules map to your specific registration groups.

Step 3: The Four New SIL Practice Standards (1 July 2026)

SIL providers must prepare evidence across four new standards, layered on top of the Core Module. Here is what auditors are specifically looking for under each:

1. Supported Decision-Making

Participants must be genuinely supported to make decisions about their home, routines, and relationships — not have decisions made on their behalf. Auditors look for:

  • Policies describing how workers support decision-making, not substitute it
  • Accessible information formats matched to each participant's communication needs
  • Records showing participant input on support preferences (documented, not assumed)
  • Evidence that dignity-of-risk decisions are recorded rather than quietly overridden

2. Safeguarding

Providers must protect participants from harm while respecting autonomous choices, with a focus on shared-home dynamics. Auditors look for:

  • A clear safeguarding policy with procedures specific to in-home and shared-living contexts
  • Worker training records covering de-escalation and trauma-informed practice
  • Incident management records maintained at the individual house level (not just organisation-wide)
  • Evidence that safeguarding approaches are reviewed with participants, not just written for them

3. Practice Governance

Consistent, evidence-based practice must be delivered across all shifts, with documented workforce oversight. Auditors look for:

  • A workforce training framework with supervision records
  • A documented service delivery approach for each home
  • Emergency plans that are individualised and regularly rehearsed (not generic templates)
  • Documentation of any co-tenant consultation and matching processes

4. Agreements About Tenancy, Housing and Support

Service agreements and tenancy agreements must be legally separate — a participant's housing must not be conditional on using your support services. Auditors look for:

  • Separate, signed tenancy and service agreements
  • A conflict-of-interest policy accessible to participants in plain language
  • Records that participants understand the two agreements are independent
  • Service terms that address co-tenant conflict and visitor rights

Step 4: The Core Document Checklist

Regardless of audit type, every provider should have the following organised, current, and retrievable on audit day:

  • Organisational policies and procedures (reviewed within the past 12 months)
  • Individual risk assessments and risk management plans
  • Incident and complaint registers with evidence of follow-up and learning
  • Staff qualification records, role descriptions, and training completion logs
  • Participant service agreements (signed, current)
  • Evidence of participant feedback collection and how it has influenced practice
  • Board or governance meeting minutes that show the organisation reviews its quality systems
  • Worker screening records (NDIS Worker Screening Check status)
  • Emergency management plans (individualised, not generic)
  • Evidence of continuous improvement — what changed as a result of complaints or incidents

Worked Example: A Gap-Assessment Exercise

Consider a SIL provider with two shared homes preparing for their initial certification audit. A useful starting exercise is a simple gap table:

Standard / Requirement Evidence We Have Gap / Action Needed Owner By When
Supported decision-making policy Draft policy (not yet signed) Finalise, sign, train staff Practice Manager 30 June 2026
Separate tenancy agreements per house Combined agreement in use Separate and re-sign with all residents CEO + Solicitor 30 June 2026
House-level incident register Central register only Create per-home registers Ops Lead 15 June 2026
Worker training — de-escalation Training booked, not completed Complete and upload certificates HR 30 June 2026

Running this exercise against every applicable Practice Standards indicator — and resolving each gap with documented evidence — is the practical core of audit preparation.

What Auditors Actually Look For (Beyond the Checklist)

Commission-approved auditors are increasingly focused on outcomes-based evidence, not just documentation. Having a policy is not sufficient on its own. Auditors will:

  • Interview frontline workers to check they can explain how policies apply to their day-to-day work
  • Speak directly with participants to assess whether their experience reflects what the paperwork says
  • Review whether incidents led to genuine practice change, or were simply recorded and filed
  • Look for a culture of continuous improvement, not a compliance exercise performed at registration time

Common reasons providers struggle at audit include outdated policies, gaps in worker training records, no evidence of participant voice influencing services, and complaint registers with no documented resolution or learning.

Key Dates for SIL Providers in 2026

  • 1 July 2026: Mandatory registration commences for SIL providers; new SIL Practice Standards take effect
  • 1 October 2026: Final deadline to have applied for registration; delivering SIL without applying after this date may breach the NDIS Act

Allow adequate lead time: certification audits can take three months to a year from application to outcome, depending on auditor availability and the complexity of your organisation. Book your approved auditor early — visit the Commission's Find an Auditor page to search by state and registration group.

Get the Free SIL Readiness Pack

If your organisation is working toward SIL registration and needs a plain-English summary of what the Commission expects across the Core Module and four new SIL standards, download the free SIL Readiness Pack. It covers the key evidence requirements for each standard in straightforward language — a practical starting point for your internal gap assessment, without the compliance jargon.

Important: This article provides general guidance about NDIS compliance requirements. It is not legal or professional advice. Requirements may change as the NDIS Commission updates its policies and Practice Standards. Always verify current requirements with the NDIS Quality and Safeguards Commission or a registered NDIS consultant before making compliance decisions.

Frequently asked questions

What is the difference between a verification audit and a certification audit for NDIS providers?

A verification audit applies to lower-risk supports and involves a remote document review with a brief interview — typically 6 to 12 hours in total. A certification audit applies to higher-risk supports (including SIL) and is far more comprehensive: it includes extended document review, interviews with staff and participants, and on-site visits, taking anywhere from 12 to 36 hours across multiple sessions. The Commission specifies which audit type applies to you in your Initial Scope of Audit document.

When do SIL providers have to be registered under the new NDIS rules?

From 1 July 2026, SIL providers must begin the mandatory registration process. The apply-by deadline is 1 October 2026 — providers who have not lodged a registration application by that date may breach the NDIS Act by continuing to deliver SIL. Because certification audits can take several months to complete, the Commission recommends providers begin their application well before the July commencement date.

What are the most common reasons NDIS providers fail or receive non-conformances at audit?

The most common issues are policies that are outdated or have not been reviewed recently, insufficient evidence of worker training (especially for higher-risk practices), incident and complaint registers with no documented follow-up or learning, and an inability to show that participant feedback has actually influenced how services are delivered. Auditors are increasingly focused on outcomes and practice culture, not just whether documents exist.

Keep reading

Free: the SIL Readiness Pack

A checklist and a sample policy page, sent as a download. No sequence.