Guided tools that build your NDIS policies and procedures from your answers. Created by an NDIS auditor.
Explore the tools →An internal audit can sound more complicated than it needs to be. At its core, it’s just a way of checking whether your service is doing what your policies and procedures say it’s doing, before an external auditor shows up to check the same thing (or worse, before an incident occurs).
This article is for NDIS providers who want to run their own internal audits without overcomplicating it.
Why bother?
There’s no requirement in the NDIS Practice Standards for providers undergoing Verification audits to conduct internal audits, and Certification providers aren’t given a prescribed schedule either. So there are a lot of providers that skip them entirely, or do a last-minute crazed sweep in the weeks before their audit is due to make sure the paperwork is in place.
This works, technically, but it also kind of misses the point.
The value of an internal audit isn’t the document you produce at the end, it’s finding out whether your service is running the way you think it is (and while you still have time to fix things). An external auditor arriving at your service is not the moment you want to discover that your incident register hasn’t been updated in four months, or that three staff members can’t find the complaints policy.
The other reason to do them regularly: what typically slips between external audits is the practice, not the documentation, the day-to-day reality of how supports are actually being delivered. A good internal audit is how you catch that gap before it becomes a risk to your participants and your business.
What you’re actually checking
An internal audit has a few layers:
Documentation: does your paperwork meet the NDIS Practice Standards? Are your policies current, do they reflect how your service actually operates, and are all your registers and forms capturing the right information?
Implementation: is your day-to-day practice matching what your policies and procedures describe? This is where you look at participant files, staff files, and any other records that should be demonstrating how processes are being followed. A policy that says you conduct regular supervision doesn’t mean much if there’s no evidence supervision is actually happening.
You don’t have to do everything at one, and trying to audit everything in one sitting tends to produce shallow results rather than anything useful.
A rolling schedule beats a pre-audit panic
One approach that works well: pick a different area (or two) each month and audit that properly, rather than trying to cover everything at once before your audit date.
For example:
- January: incident management – are incidents being identified, recorded, and closed out correctly?
- February: staff files – are worker screening checks current, are qualifications on file, and is training evidence up to date?
- March: complaints – are complaints being logged, and is there evidence of resolution and follow-up?
- And so on through your applicable standards.
By the time your external audit comes around, you’ve touched every area in the past 12–18 months, you have a record of what you found and what you fixed, and you’re not scrambling. Your auditor will be looking to see an internal audit schedule, so this type of rolling schedule works well as evidence here.
But if a rolling schedule doesn’t suit how you work, doing a thorough pre-audit review is still genuinely useful.
Can a one-person provider audit themselves?
Yes, if you’re honest about it!
The independence concern with self-auditing is real, but it can be overcome. The goal is to find out what’s actually happening in your service, not to just produce a document that makes your service look good. A solo operator who reviews their own participant files, looks at whether their risk registers reflect current participants, and asks themselves hard questions about whether their practice matches their policies, is likely producing a useful internal audit result.
A team of five who review each other’s work and record only positive findings, on the other hand, is not getting useful results.
If you work with others, having someone other than the person responsible for a particular area review it does add value, e.g. a coordinator reviewing incident records they didn’t write themselves is more likely to spot patterns than the person who wrote them. But for a one-person business, honest self-review is better than nothing, and auditors know the difference between a solo operator doing their best and a larger team producing suspiciously perfect results.
What to look for
Beyond checking boxes, a useful internal audit is about looking for patterns.
Are there recurring incidents involving the same participant, the same staff member, the same time of day? Are complaints clustering around a particular service type or location? Are staff file gaps concentrated in your most recently hired workers, or spread across the team?
Patterns tell you something! A single incident or a single file gap is a correction to make, while a pattern is a signal that something in your systems or your culture needs attention. This is the kind of insight your external auditor is also looking for when they’re reviewing your data.
What the output should look like
There’s no required format for an NDIS internal audit report. But having a simple template is worth it, even if it’s one page, to keep a consistent record of what you looked at.
At minimum, capture:
- What was audited (which standard, which area, which files)?
- What sample was reviewed? (i.e. how many files did you look at and which ones?)
- What findings were made?
- What corrective actions are needed, and who is responsible?
- A follow-up date to check that corrections have actually been made
That last point matters more than most providers realise. Setting corrective actions and then never checking whether they were implemented is one of the more common internal audit failures, as the whole point is to close the loop: identify any gaps, fix them, and confirm they’re fixed.
What your external auditor does with your internal audit records
They probably won’t read all of them, but they’ll look at some, and what they’re looking for is honesty.
An internal audit report that identifies findings, sets actions, and shows follow-up is a meaningful piece of evidence that your quality system is functioning. It demonstrates that your organisation is honestly monitoring itself, not just producing documents to satisfy a requirement.
Twenty internal audit reports showing perfect systems with zero findings, on the other hand, might not get you the positive response from your auditor that you might be picturing. Either your service genuinely has nothing to improve (which is unlikely) or the audits aren’t being done honestly.
A report that says ‘we found three staff files missing infection control certificates, these were obtained by [date], confirmed complete’ tells an auditor something about how your organisation operates, and this is what you’re going for.
A simple starting point
If you’ve never done an internal audit before and aren’t sure where to start, pick one area that you suspect might have slipped (like incident management or staff files) and review a sample of five to ten records against your policy.
Write down what you find, set actions for anything that needs fixing, and then check back in a month.
That’s an internal audit! While there are some amazing consultants out there that can help you get started or even work with you to complete internal audits, most providers don’t need a consultant or a specialist tool to get started. You just need to look honestly at what’s happening in your service and act on what you find.
About the author
Penny Halpin
Penny is an NDIS Lead Auditor who has worked in certification since the first audits in 2018, and was previously a Senior Manager at an Approved Quality Auditor with technical review across thousands of audit reports. She built the Paperbark tools to help providers create documentation that reflects how they actually work.
More about Penny →