HealthQ icon

NDIS Certification Audit vs Verification Audit: Which One Do You Need?

Not all NDIS audits are the same. Your audit pathway is determined by your registration groups, not your size or years in operation.

Verification Audit (lower-risk supports)

A verification audit applies to providers delivering lower-risk, lower-complexity supports.

What it looks like:

  • Desktop audit (documents only)
  • No site visit
  • No staff or participant interviews

The auditor reviews evidence across four areas:

  • Human resource management
  • Incident management
  • Complaints management
  • Risk management

Common verification providers include:

  • Plan managers
  • Household supports (cleaning, gardening)
  • Assistive technology and equipment providers
  • Some allied health and community-based supports

This is often described as the “lighter” audit, but only if your documents and systems are genuinely in order.

Certification Audit (higher-risk supports)

A certification audit is required for higher-risk or more complex supports, where participant safety relies heavily on systems, training and oversight.

What it looks like:

  • Stage 1: Desktop review of policies and documents
  • Stage 2: On-site audit (or virtual equivalent)
  • Interviews with staff and sometimes participants
  • Review of real participant and staff files

Certification audits also require a mid-term (18-month) audit to confirm systems are still working in practice.

Common certification providers include:

  • Supported Independent Living (SIL)
  • Support coordination
  • Behaviour support
  • High-intensity or personal care services
  • Specialist Disability Accommodation (SDA)

What other audit types are there?

While verification and certification audits (and the mid-term audit) are the most common pathways, there are several other audit types that can apply depending on your circumstances. These are often less well understood, and where many NDIS providers get caught off guard.

Out-of-cycle audits

These audits occur outside your normal  NDIS registration schedule, usually triggered by a specific event or risk.

Common triggers include:

  • Notifiable incidents or reportable changes
  • Complaints or regulatory concerns
  • Significant organisational change (e.g. restructure, rapid growth)
  • Adding new or higher-risk registration groups

Out-of-cycle audits tend to be more targeted and can focus deeply on a specific issue, rather than reviewing your entire business.

Mid-term (surveillance) audits

For NDIS providers undergoing certification, a mid-term audit is required 18 months into the registration period. It focuses on:

  •  Whether systems are still being applied in practice
  • Evidence of continuous improvement
  • Consistency between policy and day-to-day delivery

Renewal audits

When your NDIS registration period ends (typically every 3 years), you must undergo a renewal audit. This is a:

  • A full reassessment (verification or certification, depending on your supports)
  • Greater emphasis on track record and evidence over time\
  • Deeper review of outcomes, not just compliance

Providers often underestimate renewal audits, they are not a simple “tick and flick” of your previous audit.

Scope extension audits

If you add new registration groups (especially higher-risk ones), you may be required to complete an additional audit before delivering those supports.

This ensures:

  • You have the right systems in place for the new service
  • Staff capability and governance match the risk level
  • Participants are protected from day one

This can delay service expansion if not planned early.

Focused or follow-up audits
Where non-conformities are identified, auditors may return to verify that corrective actions have been implemented. These audits are typically:

  • Shorter and targeted
  • Evidence-heavy
  • Time-sensitive (often within strict deadlines)

They’re not just administrative, failure to close out issues can impact your registration status.

Who has to be audited under the NDIS?

All Registered NDIS providers must undergo an audit. That includes:

  • Sole traders
  • Small providers
  • Large organisations
  • New providers
  • Existing providers renewing registration

If you change or add registration groups during your registration period, you may trigger an additional or out-of-cycle audit.

How to prepare for an NDIS Audit (without the last-minute panic)

The biggest audit mistakes don’t happen on audit day, they happen in the months before it, when preparation is unclear or left too late.

The simplest way to think about audit preparation is this:

  1. Strong systems all year. 
  2. Focused preparation in the final 90 days.

Turning audit anxiety into confidence

When done well, audit preparation:

  • Reduces stress across your whole team
  • Clarifies roles, responsibilities and decision-making
  • Strengthens participant safety
  • Builds a culture of continuous improvement — not panic compliance

That’s when audits stop being something you fear… and start being something you’re ready for. As NDIS consultants and NDIS registration consultants, HealthQ can provide the NDIS audit support you are looking for.

How HealthQ helps

Our NDIS business consultants work alongside providers, not above them, to:

  • Explain exactly which audit applies to you
  • Identify gaps early (before auditors do)
  • Align policies, practice and evidence
  • Prepare staff so interviews don’t feel like interrogations

No generic templates.

No confusing jargon.

Just practical, down-to-earth audit preparation that actually works.  Through our  NDIS audit support, and NDIS registration support, have mentored and supported small and large providers to grow into their NDIS compliance understanding so that they pass audits with elements of best practice, and ultimately better understand quality and compliance.