Analytics and cookies

We use analytics cookies to understand which pages and calls to action are working. You can accept or decline non-essential tracking.

Essential site functionality continues either way. You can review the details in our Privacy Policy.

NDIS

NDIS Verification vs Certification Audit: Evidence Checklist for Providers

Understand NDIS verification, certification and mid-term audits, then use a practical evidence checklist to prepare participant, workforce and governance records.

12 min read | Published 2026-09-16

Start with the audit scope issued for the provider

Verification and certification are not interchangeable labels. The required audit pathway depends on the registration groups and classes of supports in the provider's application or registration scope. Providers should confirm the scope supplied through the registration process and use an Approved Quality Auditor for the required audit.

The NDIS Commission describes verification as applying to lower-risk or lower-complexity supports. Certification applies where a provider delivers higher-risk or more complex supports. The applicable Practice Standards modules and evidence sample should therefore follow the provider's real services, not a generic checklist copied from another organisation.

  • Confirm the legal entity, ABN, key personnel, locations and registration groups.
  • Record whether the current event is an initial application, renewal, variation or mid-term audit.
  • Obtain and review the audit scope before building the evidence index.
  • Identify every Core, Verification or supplementary Practice Standards module in scope.
  • Document any SIL, SDA, behaviour support, restrictive practice or high-intensity support requirements.

Verification audit evidence checklist

A verification audit is a desktop review for providers delivering lower-risk or lower-complexity supports. The exact documentary requirements depend on the registration groups and professional requirements in scope, so the provider should use the Commission's current guidance and the audit scope as the source of truth.

Even where the evidence set is smaller, documents should be current, approved and traceable to the correct person, role or control. A policy without ownership, review history or implementation evidence can still create avoidable follow-up.

  • Qualifications, professional memberships and required registrations.
  • Worker identity, screening and risk-assessed role evidence where applicable.
  • Human resource, risk, complaints and incident management documents required by the Verification Module.
  • Current insurance, business and service-scope records requested in the audit scope.
  • Document approval, version, review date and accountable owner details.
  • A controlled evidence index matching each requested item to the uploaded record.

Certification audit evidence checklist

Certification examines whether the provider's management systems and service delivery conform with the applicable NDIS Practice Standards. Preparation therefore needs evidence that controls are operating, not only copies of policies.

Providers should be ready to demonstrate governance, participant safeguards, workforce capability and the lifecycle of incidents, complaints, risks and improvements. Participant and worker samples should be complete enough to show that policies are applied consistently.

  • Governance structure, delegations, risk management and management-review evidence.
  • Participant files with service agreements, plans, consent, risk and communication records.
  • Worker screening, induction, training, competency and supervision evidence.
  • Incident and complaint records showing response, investigation, communication and corrective action.
  • Evidence mapped to every applicable Core and supplementary module outcome.
  • Closed findings with completion evidence and an effectiveness review.

Mid-term audits and continuous readiness

Registered providers that have completed a certification audit and deliver higher-risk or more complex supports may be required to complete a mid-term audit. Treating the mid-term audit as a fresh document collection exercise creates unnecessary risk.

A stronger approach is to keep the audit position live. Expiry monitoring, participant-file sampling, worker checks, incident trends, complaint outcomes and corrective actions should be reviewed throughout the registration cycle.

  • Review evidence gaps and expiries every month.
  • Sample participant and workforce files each quarter.
  • Track audit findings and corrective actions through effectiveness review.
  • Review incidents, complaints and risks for recurring themes.
  • Update the evidence matrix when services, locations or registration groups change.

A practical 30-day audit preparation plan

A short preparation cycle should prioritise scope and evidence quality rather than collecting every document in the organisation. Start with what the auditor will test, identify gaps, assign owners and preserve the review trail.

This checklist is operational guidance, not legal advice or a substitute for the audit scope, current Commission requirements or advice from an Approved Quality Auditor.

  • Week 1: confirm scope, modules, services, locations and key personnel.
  • Week 2: map obligations and quality indicators to policies, registers and record samples.
  • Week 3: resolve missing, expired, unapproved or unlinked evidence.
  • Week 4: conduct a mock evidence request, close priority gaps and approve the audit index.

Authority and currency

Primary sources reviewed

Use the official sources below to confirm the requirements that apply to your provider, registration groups and services.

Next step

Want to see this inside an NDIS provider workspace?

Book a short walkthrough and we will map the guide to provider profile, Practice Standards, participant files, worker screening, incidents, complaints and audit-ready exports.

Related Reading