Skip to content
Paperbark NDIS
Open menu
Need policies and procedures for your Certification audit?Learn more
Audit Preparation

NDIS Audit Checklist: Preparing for Your Certification Audit

by Penny Halpin |

This checklist covers what to do before, during and after an NDIS Certification audit, which includes an on-site stage, whether it's your initial audit, a mid-term or a renewal. If you're on the Verification pathway, see what to expect from your NDIS Verification audit instead.

Passing your audit is one step in running a safe, effective service for your participants and workers, and an audit checks whether you meet the NDIS Practice Standards at one point in time. Preparing well helps you meet your audit requirements, but more importantly, it means your policies, records and day-to-day practice line up, which is what keeps participants and workers safe between audits.

Some of the items below are requirements of the Practice Standards, while others are preparation I'd recommend regardless. For a list of the documents themselves, see what documents you need for your NDIS audit.

Scope

  • Check your Initial Scope of Audit, which confirms your audit pathway and which modules apply.
  • Make sure every registration group you deliver (or intend to) and every site you deliver from is included, and that your participant numbers are accurate and current, because the sample is built from what you tell the auditor.
  • Confirm which supplementary modules apply (for example, Module 1 for high intensity supports, or Module 2A if you implement behaviour support plans with regulated restrictive practices).
  • If you're unsure about anything in your scope, double check with your auditor before the audit.

Your auditor

  • Get quotes from more than one Approved Quality Auditor (the auditing bodies approved by the NDIS Commission to conduct NDIS audits). Our article on questions to ask before engaging an auditor covers what to check (and cheapest is not always best).
  • Confirm the audit dates, what format the auditor wants documents in, and when they need them.
  • Ask whether they'd like your documents cross-referenced to the indicators. Some auditors prefer it, but if it isn't useful to you as a provider, I wouldn't consider it necessary.

Gap analysis and internal audit

  • Work through each indicator that applies to you and note where you meet it, where you partly meet it, and where you don't. Our free Practice Standards Gap Analysis covers all modules.
  • Complete some key internal audits before your external one, and record what you found and what you're doing about it.
  • If you find any gaps, put them into your continuous improvement plan with owners and dates.
  • Review your self-assessment and make sure it still reflects how you operate.

Documents

  • Check that your policies and procedures describe how you operate. If you've bought templates, review and adapt them, because even if your records are good they need to match what your documents say you do.
  • A single policy and procedure manual works well for uploading, but if you use separate policies, label each one clearly.
  • Make sure every policy has a version, an approval date and a review date, and that the review dates haven't passed.
  • Check that your forms, registers and templates match what your policies say you use, and that workers are using the current versions day to day.

Records and implementation

Make sure that you have records showing your processes are being followed, including:

  • registers with real entries (risk, incidents, complaints, continuous improvement), and if your complaints register is empty, a way of showing you still seek and record feedback
  • signed and current service agreements and support plans for each participant
  • progress notes that reflect the supports delivered
  • complete worker files, including screening clearances, qualifications, orientation module certificates, induction records and training records
  • competency assessments for any support a worker needs to be able to do, not just know
  • supervision records
  • evidence you've acted on what you found, such as completed actions from incidents, complaints, internal audits and risk reviews

If you don't have participants yet, you won't have participant records to show, which the auditor will be prepared for. If you're awarded qualified certification after a provisional audit, a follow-up audit has to occur to review implementation once you have participants. Either way, you'll still need to show that you understand the NDIS rules and Practice Standards, that you can explain your own documents, and that you have the knowledge and experience to safely and effectively run an NDIS business.

Your team

  • Make sure workers know where your policies are and can explain how the key processes work in practice, such as reporting an incident, raising a complaint, or what to do in an emergency.
  • Let workers know they might be interviewed by the auditor, and tell them to be honest. If a worker doesn't know what to do in a situation or where to find information, it's better for your auditor to identify it and give you the chance to fix it than for it to go unnoticed and contribute to an incident later.
  • Tell your team the audit dates and arrange cover for anyone who needs to be available.

Participants

Participants may be interviewed as part of your audit.

  • Participation is by consent. Participants can change their mind at any time, even if the audit has been planned for months.
  • Participant involvement works as an opt-out process, so explain it to participants somewhere in your information for them, including that the auditor may access their information, and give them the chance to opt out.
  • Think about and have processed for any participant who might need support, an interpreter, or a familiar person present to take part in the audit.
  • If a sampled participant isn't available or doesn't want to take part, tell the auditor. They'll select alternatives until they reach the minimum sample. Auditors also report the number of participants who opt out to the Commission.

Logistics

  • Have accurate participant, worker and site lists ready for sampling. Auditors may request this in the planning phase of the audit so you can better prepare for the day.
  • Organise your documents so you can find and share them quickly, in the format your auditor asked for.
  • Confirm who from your organisation will attend the opening and closing meetings (the meetings at the start and end of the audit).

During the audit

Keep notes of what's discussed and anything the auditor asks for. If you don't understand a finding, ask the auditor to clarify it, and if they haven't explained what to do if you disagree with a finding, ask them to (all AQAs will have a process for this). A guessing game doesn't help either of you.

After the audit

  • Read the audit report carefully, including any non-conformities.
  • If you have a lot of findings, don't take it as a failure: each one is a chance to fix a gap before it affects a participant or worker, and you'll be stronger for it.
  • Develop a corrective action plan for any non-conformities, within the required timeframes.
  • Add any opportunities for improvement to your continuous improvement plan.
  • Give your auditor feedback, good or bad, if you think it's relevant.
  • Put your next audit in the calendar, including your mid-term audit.
  • Keep your internal audit schedule running between external audits.
  • Take a breather. If this was your first audit, the next one is usually easier now that you know what to expect.

Paperbark NDIS

Need policies and procedures for your Certification audit?

Our comprehensive tool asks about how you work as an NDIS provider and builds your policies to match. Includes 20+ unique policies and procedures, and more than 40 forms and registers.

Learn more

About the author

Penny Halpin

Penny is an NDIS Lead Auditor who has worked in certification since the first audits in 2018, and was previously a Senior Manager at an Approved Quality Auditor with technical review across thousands of audit reports. She built the Paperbark tools to help providers create documentation that reflects how they actually work.

More about Penny →