Certification audit
An NDIS certification audit is the two-stage audit (desktop, then onsite) that providers registered for higher risk or more complex supports must pass. An approved quality auditor assesses them against the core module of the NDIS Practice Standards and any supplementary modules, with staff and participant interviews.
Also called: NDIS certification, certification audit NDIS, Stage 1 and Stage 2 audit, NDIS onsite audit
Key takeaways
- A certification audit is required if any of your registration groups is a higher risk or more complex support.
- Stage 1 is a desktop audit; Stage 2 is an onsite audit that should take place within three months of Stage 1.
- Each standard is rated 0 to 3, and a major non-conformity must be fixed within three months.
- Certification providers usually have a mid-term audit that starts no later than 18 months into registration.
- SIL (0138) and digital platform (0137) groups, added on 1 July 2026, both require certification.
What is an NDIS certification audit?
A certification audit is the more detailed of the two NDIS audit types, required for providers registered to deliver higher risk or more complex supports. An approved quality auditor assesses the provider against the core module of the NDIS Practice Standards, plus any supplementary modules, in two stages: a desktop audit, then an onsite audit with observation and interviews of staff and participants.
It is part of NDIS registration: you complete one to become registered, again at renewal, and in between you have a mid-term audit. The lighter alternative, for lower risk supports only, is a verification audit. Your registration groups decide which one you get, and the NDIS Commission tells you in the Initial scope of audit it sends when you apply or renew.
Who needs a certification audit
Each registration group is assigned an assessment method in section 20 of the Provider Registration and Practice Standards Rules 2018, published on the Commission's registration groups page. The key rule: if any one of your groups needs certification, your whole audit is certification. The Rules also say a certification assessment satisfies any requirement to be assessed by verification.
| Group | Name | Audit |
|---|---|---|
| 0104 | High Intensity Daily Personal Activities | Certification |
| 0107 | Assistance with daily personal activities | Certification |
| 0110 | Specialist positive behaviour support | Certification |
| 0115 | Assistance with daily life tasks in a group or shared living arrangement | Certification |
| 0117 | Development of daily living and life skills | Certification |
| 0125 | Participation in community, social and civic activities | Certification |
| 0136 | Group and centre-based activities | Certification |
| 0137 | Providing an NDIS digital platform service (from 1 July 2026) | Certification |
| 0138 | Assistance with supported independent living (from 1 July 2026) | Certification |
| 0120 / 0128 | Household tasks / Therapeutic supports | Verification (for comparison) |
This is a selection; check the full table before you apply, because groups are occasionally added or changed. Certification is also required:
- for providers implementing behaviour support plans that involve regulated restrictive practices, who are assessed against the implementing behaviour support plans module;
- for government entities (Commonwealth, state, territory or local), which the Rules require to be certified against the core module regardless of group.
How a certification audit works
The Commission's quality audit process page sets out the stages:
- 1Initial scope of auditThe Commission confirms certification and the modules that apply.
- 2Engage an auditorChoose an approved quality auditor and agree the audit plan.
- 3Stage 1: desktop auditPolicies, registers, governance records and self-assessment are reviewed.
- 4Stage 2: onsite auditWithin three months: site visits, observation, record review, and staff and participant interviews.
- 5Report and ratingsEach standard is rated 0 to 3; major non-conformities must be fixed within three months.
- 6Commission decisionThe Commission decides on registration using the audit report and its suitability assessment.
Stage 1: desktop audit
The auditor reviews your documents, usually off-site: policies and procedures, registers (incidents, complaints, risks, worker screening), governance records and your self-assessment against each applicable standard. Treat anything queried at Stage 1 as an early warning — it will be tested onsite.
Stage 2: onsite audit
Stage 2 should take place within three months of Stage 1. The auditor looks at how your policies work in practice by viewing records, visiting sites, observing supports and interviewing staff and participants. Participant sampling is opt-out: you must tell participants they are automatically included, and if someone declines you must respect, record and pass on that decision.
Ratings and the report
Each standard and indicator is rated from 3 (conforms with elements of best practice) to 0 (major non-conformity). A major non-conformity must be addressed within three months, and registration won't progress until it is. Minor non-conformities allow more time. The auditor sends the report to the Commission — for certification, up to 28 days after the audit is completed — and the Commission, not the auditor, makes the registration decision.
What happens on the onsite day
Stage 2 tests whether what's written down is what actually happens. The Commission's own description is that the focus moves quickly from what your policies say to what happens in practice. Expect the auditor to:
- trace a participant's file end to end: service agreement, support plan, risk assessments, progress notes, rosters and any incidents;
- trace an incident or complaint from first report to outcome, including any notification to the Commission;
- sample staff files for screening clearances, qualifications, induction, training and supervision records;
- observe supports, checking for consent, clear explanations and accurate documentation;
- ask workers practical questions, such as what they would do if a participant fell on shift, or where they would find a participant's mealtime plan;
- ask managers and directors how incident trends and risks reach leadership, and to show the last report.
Good answers match the written procedure, name specific places and people, and show the worker knows the participant they support.
What standards are assessed
A certification audit always covers the core module of the NDIS Practice Standards — rights and responsibilities, governance and operational management, provision of supports, and the support provision environment — plus every supplementary module that matches what you deliver:
- High intensity daily personal activities (group 0104);
- Specialist behaviour support, and implementing behaviour support plans;
- Early childhood supports;
- Specialised support coordination;
- Specialist disability accommodation;
- Supported independent living, from 1 July 2026 — see SIL Practice Standards.
Certification vs verification audit
| Feature | Certification | Verification |
|---|---|---|
| Who it's for | One or more higher risk or more complex supports | Only lower risk, lower complexity supports |
| Standards | Core module plus supplementary modules | Verification module |
| Method | Stage 1 desktop, Stage 2 onsite | Desktop review of documents |
| Participant interviews | Yes, opt-out sampling | No |
| Mid-term audit | Yes, by 18 months (some exceptions) | No |
| Report to Commission | Up to 28 days after completion | Up to 14 days after completion |
After certification: mid-term and other audits
Certification isn't a one-off. Registered certification providers can expect:
- Initial / renewalFull certification auditStage 1 and Stage 2 against all applicable modules.
- By 18 monthsMid-term auditGovernance and operational management, plus earlier corrective actions.
- As requiredOut-of-cycle or condition auditTo add registration groups, or when the Commission requires it.
- On a significant ownership changeChange of ownership auditMay apply to certification providers.
The mid-term audit must start no later than 18 months into the registration period unless the Commissioner allows longer. It covers governance and operational management, any standard that previously needed a corrective action plan, and any standard the Commissioner specifies. It doesn't apply to SDA-only providers, individuals or partnerships whose only certification group is early childhood supports, or transitioned providers. A certification provider that goes through a change of ownership that significantly changes its organisation or governance may also need a change of ownership audit; the requirements were amended for ownership changes from 1 July 2026.
How to prepare
- Run an honest self-assessment against every quality indicator in your scope with the free Practice Standards self-assessment.
- Fix high-risk gaps first: incidents, restrictive practices, worker screening, medication and emergency planning.
- Make sure records show systems working: completed registers, supervision notes, reviewed support plans and board minutes that discuss quality and risk.
- Tell participants about the audit early, explain opt-out, and record any opt-outs.
- Roster frontline workers, including casuals, who can be interviewed on the day.
- Gather staff files with screening clearances, qualifications, induction and Worker Orientation Module certificates. A resource-level audit trail makes it easier to show when records were created and changed.
Choose your auditor from the Commission's approved quality auditors list and get more than one quote; the Commission doesn't set audit prices.
Common mistakes
- Adding one certification group late. It turns a verification audit into a certification audit for the whole application.
- Scripted staff answers. Auditors notice identical phrasing; train understanding, not lines.
- Policies nobody has seen. If workers can't say where the complaints procedure is, the indicator is at risk.
- Forgetting participant consent to sampling. Opt-outs must be respected, recorded and passed to the auditor.
- Not diarising the mid-term audit. It is due by month 18 and focuses on governance.
- The lighter audit for lower risk supports
- What the audit assesses
- Supplementary module for SIL providers
- Carries out the audit
- Decides whether certification applies
- The process the audit is part of
Example
Illustrative example (fictional). Coastline Care is registered for household tasks and therapeutic supports, both verification groups. It wants to add community access (0125), a certification group, so it applies to vary its registration.
The Initial scope of audit confirms that the whole organisation now needs a certification audit against the core module. Stage 1 flags that the risk register has no review dates and that board minutes never mention incidents. Coastline fixes both before Stage 2, which takes place eight weeks later. The auditor visits the office, observes a community access shift, interviews three workers and two participants who agreed to take part, and samples staff files.
One minor non-conformity is raised: supervision isn't recorded for casual staff. Coastline submits a corrective action plan, and the Commission approves the variation. Its mid-term audit, focused on governance, is booked for month 17.
Frequently asked questions
What is an NDIS certification audit?
It is the two-stage audit for NDIS providers registered to deliver higher risk or more complex supports. An approved quality auditor reviews documents at Stage 1, then visits, observes supports and interviews staff and participants at Stage 2, assessing against the core module and any supplementary modules.
What is the difference between a certification and verification audit?
A verification audit is a desktop review of documents against the verification module for lower risk, lower complexity supports. A certification audit has a desktop stage and an onsite stage, assesses the core and supplementary modules, includes participant interviews and is followed by a mid-term audit.
How long after Stage 1 is the Stage 2 audit?
The NDIS Commission says the Stage 2 onsite audit should take place within three months after Stage 1 is completed.
What happens if I get a major non-conformity?
A major non-conformity must be addressed within three months, and your registration won't progress until it is fixed and the audit is completed. Minor non-conformities give you longer and the process can continue.
When is the NDIS mid-term audit?
Certification providers usually have a mid-term audit that starts no later than 18 months into the registration period. It covers governance and operational management, any standard that needed a corrective action plan, and anything the Commissioner specifies.
Do participants have to take part in a certification audit?
No. Participant sampling is opt-out. Providers must tell participants they are included automatically, and anyone who doesn't want to take part can decline; the provider must respect, record and pass on that decision to the auditor.
Related terms
- Approved quality auditor (AQA)An approved quality auditor (AQA) is an independent audit organisation approved by the NDIS Commission to assess providers against the NDIS Practice Standards. Providers choose and pay an AQA for their verification or certification audit; the auditor reports to the Commission, which decides registration.
- NDIS Practice StandardsThe NDIS Practice Standards are the quality and safety standards that registered NDIS providers must meet and are audited against. Grouped into core, verification and supplementary modules such as SIL, each standard has a participant outcome and quality indicators that auditors use to rate the provider.
- NDIS registrationNDIS registration is the process by which the NDIS Quality and Safeguards Commission approves a provider to deliver specific NDIS supports. It involves an online application, an audit against the NDIS Practice Standards and a suitability check, ending in a certificate of registration, usually for three years.
- Registered NDIS providerA registered NDIS provider is a person or organisation approved by the NDIS Quality and Safeguards Commission, after a Practice Standards audit, to deliver specific NDIS supports. Registration lets them serve NDIA-managed participants and deliver supports such as SIL and SDA, subject to ongoing conditions.
- Registration groupAn NDIS registration group, also called a class of support, is a category of supports that a registered NDIS provider is approved to deliver, numbered 0101 to 0138. Each group sets the audit type, appears on the provider's certificate, and forms the four-digit middle segment of every support item number.
- SIL Practice StandardsThe SIL Practice Standards are a supplementary module of the NDIS Practice Standards that registered supported independent living providers must meet from 1 July 2026. They add four standards to the Core module: supported decision-making, safeguarding, practice governance, and tenancy and support agreements.
- Verification auditA verification audit is the desktop NDIS registration audit for providers delivering only lower risk, lower complexity supports. An approved quality auditor reviews documents against four standards: human resource, incident, complaints and risk management. There is no onsite stage or mid-term audit.
Go deeper
Sources
- ndiscommission.gov.au/provider-registration/apply-registration/types-audits
- ndiscommission.gov.au/provider-registration/apply-registration/registration-groups-or-classes-support
- legislation.gov.au/F2018L00631/latest/text
- ndiscommission.gov.au/provider-registration/apply-registration/find-auditor
- ndiscommission.gov.au/rules-and-standards/ndis-practice-standards
- ndiscommission.gov.au/provider-registration/apply-registration
General information, not legal, clinical or financial advice. NDIS rules change — check the official source before you act.
Suppora editorial team
NDIS operations and compliance writers
The Suppora editorial team writes practical guides for NDIS providers, checked against the NDIS Commission, NDIA and Fair Work sources cited on each page.
- NDIS Practice Standards
- NDIS pricing and claiming
- SCHADS Award
- Incident management
- Supported Independent Living

