Suppora
Registration & compliance

Certification audit

In short

An NDIS certification audit is the two-stage audit (desktop, then onsite) that providers registered for higher risk or more complex supports must pass. An approved quality auditor assesses them against the core module of the NDIS Practice Standards and any supplementary modules, with staff and participant interviews.

Also called: NDIS certification, certification audit NDIS, Stage 1 and Stage 2 audit, NDIS onsite audit

By Updated

Key takeaways

  • A certification audit is required if any of your registration groups is a higher risk or more complex support.
  • Stage 1 is a desktop audit; Stage 2 is an onsite audit that should take place within three months of Stage 1.
  • Each standard is rated 0 to 3, and a major non-conformity must be fixed within three months.
  • Certification providers usually have a mid-term audit that starts no later than 18 months into registration.
  • SIL (0138) and digital platform (0137) groups, added on 1 July 2026, both require certification.

What is an NDIS certification audit?

A certification audit is the more detailed of the two NDIS audit types, required for providers registered to deliver higher risk or more complex supports. An approved quality auditor assesses the provider against the core module of the NDIS Practice Standards, plus any supplementary modules, in two stages: a desktop audit, then an onsite audit with observation and interviews of staff and participants.

It is part of NDIS registration: you complete one to become registered, again at renewal, and in between you have a mid-term audit. The lighter alternative, for lower risk supports only, is a verification audit. Your registration groups decide which one you get, and the NDIS Commission tells you in the Initial scope of audit it sends when you apply or renew.

Certification audit at a glance
2 stages
Desktop audit, then onsite audit
NDIS Commission
3 months
Maximum gap between Stage 1 and Stage 2
NDIS Commission
0 to 3
Rating for each standard and indicator
NDIS Commission
18 months
Latest start of the mid-term audit
Practice Standards Rules
28 days
Time for the auditor's report to reach the Commission
NDIS Commission

Who needs a certification audit

Each registration group is assigned an assessment method in section 20 of the Provider Registration and Practice Standards Rules 2018, published on the Commission's registration groups page. The key rule: if any one of your groups needs certification, your whole audit is certification. The Rules also say a certification assessment satisfies any requirement to be assessed by verification.

GroupNameAudit
0104High Intensity Daily Personal ActivitiesCertification
0107Assistance with daily personal activitiesCertification
0110Specialist positive behaviour supportCertification
0115Assistance with daily life tasks in a group or shared living arrangementCertification
0117Development of daily living and life skillsCertification
0125Participation in community, social and civic activitiesCertification
0136Group and centre-based activitiesCertification
0137Providing an NDIS digital platform service (from 1 July 2026)Certification
0138Assistance with supported independent living (from 1 July 2026)Certification
0120 / 0128Household tasks / Therapeutic supportsVerification (for comparison)

This is a selection; check the full table before you apply, because groups are occasionally added or changed. Certification is also required:

  • for providers implementing behaviour support plans that involve regulated restrictive practices, who are assessed against the implementing behaviour support plans module;
  • for government entities (Commonwealth, state, territory or local), which the Rules require to be certified against the core module regardless of group.

How a certification audit works

The Commission's quality audit process page sets out the stages:

A certification audit, start to finish
  1. 1
    Initial scope of audit
    The Commission confirms certification and the modules that apply.
  2. 2
    Engage an auditor
    Choose an approved quality auditor and agree the audit plan.
  3. 3
    Stage 1: desktop audit
    Policies, registers, governance records and self-assessment are reviewed.
  4. 4
    Stage 2: onsite audit
    Within three months: site visits, observation, record review, and staff and participant interviews.
  5. 5
    Report and ratings
    Each standard is rated 0 to 3; major non-conformities must be fixed within three months.
  6. 6
    Commission decision
    The Commission decides on registration using the audit report and its suitability assessment.

Stage 1: desktop audit

The auditor reviews your documents, usually off-site: policies and procedures, registers (incidents, complaints, risks, worker screening), governance records and your self-assessment against each applicable standard. Treat anything queried at Stage 1 as an early warning — it will be tested onsite.

Stage 2: onsite audit

Stage 2 should take place within three months of Stage 1. The auditor looks at how your policies work in practice by viewing records, visiting sites, observing supports and interviewing staff and participants. Participant sampling is opt-out: you must tell participants they are automatically included, and if someone declines you must respect, record and pass on that decision.

Ratings and the report

Each standard and indicator is rated from 3 (conforms with elements of best practice) to 0 (major non-conformity). A major non-conformity must be addressed within three months, and registration won't progress until it is. Minor non-conformities allow more time. The auditor sends the report to the Commission — for certification, up to 28 days after the audit is completed — and the Commission, not the auditor, makes the registration decision.

What happens on the onsite day

Stage 2 tests whether what's written down is what actually happens. The Commission's own description is that the focus moves quickly from what your policies say to what happens in practice. Expect the auditor to:

  • trace a participant's file end to end: service agreement, support plan, risk assessments, progress notes, rosters and any incidents;
  • trace an incident or complaint from first report to outcome, including any notification to the Commission;
  • sample staff files for screening clearances, qualifications, induction, training and supervision records;
  • observe supports, checking for consent, clear explanations and accurate documentation;
  • ask workers practical questions, such as what they would do if a participant fell on shift, or where they would find a participant's mealtime plan;
  • ask managers and directors how incident trends and risks reach leadership, and to show the last report.

Good answers match the written procedure, name specific places and people, and show the worker knows the participant they support.

What standards are assessed

A certification audit always covers the core module of the NDIS Practice Standards — rights and responsibilities, governance and operational management, provision of supports, and the support provision environment — plus every supplementary module that matches what you deliver:

  • High intensity daily personal activities (group 0104);
  • Specialist behaviour support, and implementing behaviour support plans;
  • Early childhood supports;
  • Specialised support coordination;
  • Specialist disability accommodation;
  • Supported independent living, from 1 July 2026 — see SIL Practice Standards.

Certification vs verification audit

Certification vs verification audit
FeatureCertificationVerification
Who it's forOne or more higher risk or more complex supportsOnly lower risk, lower complexity supports
StandardsCore module plus supplementary modulesVerification module
MethodStage 1 desktop, Stage 2 onsiteDesktop review of documents
Participant interviewsYes, opt-out samplingNo
Mid-term auditYes, by 18 months (some exceptions)No
Report to CommissionUp to 28 days after completionUp to 14 days after completion

After certification: mid-term and other audits

Certification isn't a one-off. Registered certification providers can expect:

The certification audit cycle
  1. Initial / renewal
    Full certification audit
    Stage 1 and Stage 2 against all applicable modules.
  2. By 18 months
    Mid-term audit
    Governance and operational management, plus earlier corrective actions.
  3. As required
    Out-of-cycle or condition audit
    To add registration groups, or when the Commission requires it.
  4. On a significant ownership change
    Change of ownership audit
    May apply to certification providers.

The mid-term audit must start no later than 18 months into the registration period unless the Commissioner allows longer. It covers governance and operational management, any standard that previously needed a corrective action plan, and any standard the Commissioner specifies. It doesn't apply to SDA-only providers, individuals or partnerships whose only certification group is early childhood supports, or transitioned providers. A certification provider that goes through a change of ownership that significantly changes its organisation or governance may also need a change of ownership audit; the requirements were amended for ownership changes from 1 July 2026.

How to prepare

  • Run an honest self-assessment against every quality indicator in your scope with the free Practice Standards self-assessment.
  • Fix high-risk gaps first: incidents, restrictive practices, worker screening, medication and emergency planning.
  • Make sure records show systems working: completed registers, supervision notes, reviewed support plans and board minutes that discuss quality and risk.
  • Tell participants about the audit early, explain opt-out, and record any opt-outs.
  • Roster frontline workers, including casuals, who can be interviewed on the day.
  • Gather staff files with screening clearances, qualifications, induction and Worker Orientation Module certificates. A resource-level audit trail makes it easier to show when records were created and changed.

Choose your auditor from the Commission's approved quality auditors list and get more than one quote; the Commission doesn't set audit prices.

Common mistakes

  • Adding one certification group late. It turns a verification audit into a certification audit for the whole application.
  • Scripted staff answers. Auditors notice identical phrasing; train understanding, not lines.
  • Policies nobody has seen. If workers can't say where the complaints procedure is, the indicator is at risk.
  • Forgetting participant consent to sampling. Opt-outs must be respected, recorded and passed to the auditor.
  • Not diarising the mid-term audit. It is due by month 18 and focuses on governance.
How a certification audit connects to other terms
Certification audit

Example

Illustrative example (fictional). Coastline Care is registered for household tasks and therapeutic supports, both verification groups. It wants to add community access (0125), a certification group, so it applies to vary its registration.

The Initial scope of audit confirms that the whole organisation now needs a certification audit against the core module. Stage 1 flags that the risk register has no review dates and that board minutes never mention incidents. Coastline fixes both before Stage 2, which takes place eight weeks later. The auditor visits the office, observes a community access shift, interviews three workers and two participants who agreed to take part, and samples staff files.

One minor non-conformity is raised: supervision isn't recorded for casual staff. Coastline submits a corrective action plan, and the Commission approves the variation. Its mid-term audit, focused on governance, is booked for month 17.

Frequently asked questions

What is an NDIS certification audit?

It is the two-stage audit for NDIS providers registered to deliver higher risk or more complex supports. An approved quality auditor reviews documents at Stage 1, then visits, observes supports and interviews staff and participants at Stage 2, assessing against the core module and any supplementary modules.

What is the difference between a certification and verification audit?

A verification audit is a desktop review of documents against the verification module for lower risk, lower complexity supports. A certification audit has a desktop stage and an onsite stage, assesses the core and supplementary modules, includes participant interviews and is followed by a mid-term audit.

How long after Stage 1 is the Stage 2 audit?

The NDIS Commission says the Stage 2 onsite audit should take place within three months after Stage 1 is completed.

What happens if I get a major non-conformity?

A major non-conformity must be addressed within three months, and your registration won't progress until it is fixed and the audit is completed. Minor non-conformities give you longer and the process can continue.

When is the NDIS mid-term audit?

Certification providers usually have a mid-term audit that starts no later than 18 months into the registration period. It covers governance and operational management, any standard that needed a corrective action plan, and anything the Commissioner specifies.

Do participants have to take part in a certification audit?

No. Participant sampling is opt-out. Providers must tell participants they are included automatically, and anyone who doesn't want to take part can decline; the provider must respect, record and pass on that decision to the auditor.

Related terms

Go deeper

Sources

  1. ndiscommission.gov.au/provider-registration/apply-registration/types-audits
  2. ndiscommission.gov.au/provider-registration/apply-registration/registration-groups-or-classes-support
  3. legislation.gov.au/F2018L00631/latest/text
  4. ndiscommission.gov.au/provider-registration/apply-registration/find-auditor
  5. ndiscommission.gov.au/rules-and-standards/ndis-practice-standards
  6. ndiscommission.gov.au/provider-registration/apply-registration

General information, not legal, clinical or financial advice. NDIS rules change — check the official source before you act.

Written by

NDIS operations and compliance writers

The Suppora editorial team writes practical guides for NDIS providers, checked against the NDIS Commission, NDIA and Fair Work sources cited on each page.

  • NDIS Practice Standards
  • NDIS pricing and claiming
  • SCHADS Award
  • Incident management
  • Supported Independent Living

All NDIS terms A–Z

Doing this in Suppora

See how audit evidence is kept ready

Suppora keeps the rosters, notes, incidents and funding records behind this in one place, so the evidence is ready when someone asks.