Get the kit — A$297

Audit

What Documents Do NDIS Auditors Actually Check?

NDIS auditors appointed by the Quality and Safeguards Commission assess evidence across six main categories: governance and risk frameworks, human resource records, incident and complaints files, support planning and service agreements, safe-environment documentation, and (for SIL providers) tenancy management records. Having these organised before the audit begins is the single biggest time-saver.

Why this matters for SIL providers right now

The NDIS Quality and Safeguards Commission has been progressively strengthening the registration model and associated Practice Standards since they were introduced under the National Disability Insurance Scheme (Provider Registration and Practice Standards) Rules 2018 (as amended). For providers delivering Supported Independent Living (SIL) and other higher-risk supports, the documentary burden is significant — and auditors arrive with a structured evidence list, not a vague impression check.

This article explains, in plain English, what auditors actually request, which Practice Standards each document category maps to, and how to organise your files before an audit begins. It is general information only, not legal or compliance advice.

The two main audit types

Under the Rules, registered providers are subject to two scheduled audits during each registration period:

  • Certification audit — a full-scope assessment conducted by an approved quality auditor. Required for higher-risk registration groups, including SIL. Involves both desktop document review and on-site visits (including participant interviews).
  • Verification audit — a lighter desktop review of documentary evidence, used for lower-risk registration groups delivering supports covered by Schedule 8 (the Verification Module).

SIL providers sit firmly in certification-audit territory. The auditor is assessing compliance against the Core Module (Schedule 1) of the Practice Standards plus any additional modules relevant to your registration groups — most commonly the high-intensity supports module (Schedule 2) and the SDA-adjacent provisions in Schedule 7 if you also hold an SDA registration.

The six document categories auditors work through

1. Governance and risk management

Auditors look for evidence that your organisation has functioning systems, not just policies that exist on paper. Expect requests for:

  • Your risk management framework and the most recent risk register
  • Quality management policies with review dates and version control
  • Business continuity and emergency management plans
  • Information management and data security policies
  • Board or executive meeting minutes that show governance oversight of quality and safeguarding
  • Evidence that key personnel suitability has been assessed (NDIS Worker Screening Checks, police checks, reference checks)

What auditors look for: A live, regularly reviewed risk register — not one created for the audit. Meeting minutes that reference actual incidents or complaints, showing the governance body is genuinely aware and responding.

2. Human resource records

The Practice Standards require providers to maintain workforce management systems that demonstrate staff are suitable, trained, and supervised. Auditors will typically request a sample of staff files, which should each contain:

  • Current NDIS Worker Screening clearance (or equivalent transitional evidence)
  • Working with Children Check where applicable
  • Evidence of induction, including training on the NDIS Code of Conduct
  • Mandatory training records (manual handling, medication management, first aid, restrictive practices if relevant)
  • Role descriptions and signed employment contracts
  • Records of supervision and performance reviews
  • Volunteer and contractor agreements with equivalent clearance evidence

What auditors look for: Consistency across the sample. A provider with 60 staff whose records are in good order for 55 but incomplete for 5 will still receive a finding against human resource standards.

3. Incident management and complaints

This is one of the most scrutinised areas, particularly for SIL. The Commission expects a closed-loop system: incidents are reported, investigated, acted upon, and the learnings are fed back into practice. Request the following before the audit:

  • Your incident register for the current registration period (anonymised where required for the desktop phase)
  • Evidence that reportable incidents were notified to the Commission within required timeframes
  • Investigation summaries and outcomes for a sample of incidents
  • Your complaints register and records showing resolution and follow-up
  • Evidence that participants and their representatives were told how to make a complaint (service agreements, welcome packs, signage photos)

What auditors look for: Timeliness of reporting, quality of investigation, and evidence that systemic issues prompted practice change — not just closure of individual records.

4. Support planning and service agreements

For each participant in scope, auditors will request a file that demonstrates person-centred support delivery aligned to the participant's NDIS plan. Core documents include:

  • Current signed service agreement (including scope, price, and consent provisions)
  • Individualised support plan or care plan
  • Evidence of participant (and/or representative) involvement in planning
  • Transition plans where a participant has moved into or out of your service
  • Progress notes and shift notes that reflect the support plan goals
  • Any relevant assessments (functional, behavioural, clinical)

What auditors look for: Alignment between the NDIS plan goals, the service agreement, the individual support plan, and the day-to-day notes. Gaps between these documents are the most common finding in SIL audits.

5. Safe environments

For SIL providers, the property and physical environment is part of the assessment. Auditors may conduct on-site walkthroughs and will request:

  • Maintenance and safety inspection logs for each property
  • Medication management records (medication charts, administration logs, storage compliance)
  • Mealtime management plans where choking risk is assessed
  • Emergency evacuation plans specific to each site, with evidence of drills
  • Waste disposal procedures (particularly for clinical waste)
  • Records of any participant funds or property held in trust

6. SIL-specific: tenancy and conflict of interest

Schedule 7 of the Practice Standards addresses specialist disability accommodation and the inherent tension when one entity acts as both landlord and support provider. Even where formal SDA registration is not held, SIL providers operating in shared housing should have:

  • Tenancy agreements separate from service agreements
  • Documented conflict-of-interest policy and declarations
  • Evidence that participants have been given choice about housing independently from their choice of support provider

Worked example: a pre-audit document checklist

The table below is a simplified self-check based on the Practice Standards schedules. It is not exhaustive but covers the areas most commonly requested in initial evidence requests.

Document category Key documents Practice Standards reference
Governance Risk register, quality policy, board minutes, BCP Core Module, Schedule 1
Human resources Screening clearances, training records, supervision logs Core Module, Schedule 1
Incidents & complaints Incident register, reportable-incident notifications, complaints log Core Module, Schedule 1
Participant support files Service agreements, support plans, progress notes, transition records Core Module, Schedule 1
Safe environments Maintenance logs, medication charts, evac plans, drill records Core Module, Schedule 1
High-intensity supports Clinical protocols, certified worker evidence, procedure logs Schedule 2
SIL / tenancy Tenancy agreements, COI declarations, housing-choice evidence Schedule 7

Practical tips for getting audit-ready

  • Centralise your evidence before you receive the audit notice. Auditors typically issue an evidence request list shortly after engagement; having a shared drive organised by the categories above means your team is not scrambling.
  • Date-stamp everything. Policies without review dates, training records without completion dates, and plans without sign-off dates are common audit findings, even when the underlying practice is sound.
  • Conduct a participant file audit internally. Pull a random sample of five participant files and check whether the service agreement, support plan, and most recent progress notes are consistent and current.
  • Check your reportable incident history. If any incidents should have been notified to the Commission and were not, seek compliance advice before the audit rather than after.
  • Prepare your staff. Auditors interview workers during on-site visits. Staff should understand your policies and be able to describe how they apply them in practice — not recite them from memory.

What "audit-ready" actually means

Being audit-ready means your documents genuinely reflect your practice, your practice meets the Practice Standards, and your team can explain both. It does not mean producing documents for the audit that do not exist in day-to-day operations. Auditors are experienced at distinguishing live systems from recently assembled compliance packs.

If you are preparing for a certification audit for the first time, or your registration is up for renewal under the strengthened model, a gap analysis against all applicable schedules is the most efficient starting point.

To help SIL and community-care providers work through this systematically, we have put together a free SIL Readiness Pack — a plain-English checklist of what the Commission expects across each Practice Standards module, formatted so your team can self-assess before audit engagement begins. Download it from our homepage.

This article is general information only and does not constitute legal, compliance, or registration advice. Requirements may change as the Commission updates the Practice Standards and registration model. Always verify current obligations at ndiscommission.gov.au and consider seeking independent advice for your specific circumstances.

Important: This article provides general guidance about NDIS compliance requirements. It is not legal or professional advice. Requirements may change as the NDIS Commission updates its policies and Practice Standards. Always verify current requirements with the NDIS Quality and Safeguards Commission or a registered NDIS consultant before making compliance decisions.

Frequently asked questions

How far back do NDIS auditors look at incident and complaint records?

Auditors typically review records for the current registration period (usually three years for certification audits). They are looking for patterns, systemic issues, and whether your organisation closed the loop on investigations — not just the volume of incidents. Maintain a complete, dated register and keep investigation summaries on file.

Do auditors interview participants as well as checking documents?

Yes. On-site certification audits include structured interviews with a sample of participants and, where appropriate, their families or representatives. Auditors use these conversations to triangulate what your documents say against the lived experience of the people you support. Participant interviews are weighted heavily in the overall assessment.

Our registration is renewing under the strengthened Practice Standards model — do the document requirements change?

The core document categories remain consistent with the existing Practice Standards Rules, but the Commission has been progressively updating quality indicators and guidance to place greater emphasis on outcome evidence rather than process documentation alone. Check the current Practice Standards on the Commission's website before your next audit cycle, and ensure your self-assessment is against the version in force at the time of your audit.

Keep reading

Free: the SIL Readiness Pack

A checklist and a sample policy page, sent as a download. No sequence.