NDIS document store

Free audit readiness guide

NDIS audit readiness: build evidence before the auditor asks

Audit readiness means being able to show how your provider’s actual work meets the requirements that apply to its registration scope. A polished policy is useful only when it is approved, understood, used, monitored and supported by credible records.

Free and ungatedReviewed 6 September 2026Australian provider context

Use this guide as a decision sequence.

Check the linked primary sources for your current circumstances. Record decisions, owners and evidence rather than treating general information as legal, clinical or employment advice.

1. Freeze the scope you are testing

Start with the provider registration groups, services, locations and modules that apply. Separate Verification, Core and supplementary module requirements. Record any unresolved applicability question instead of quietly treating it as not applicable.

Use the current NDIS Practice Standards and Quality Indicators as the organising source. A generic checklist can miss service-specific requirements or test material that does not apply to you.

2. Build an evidence index, not a document list

For each applicable indicator, identify the controlled policy or procedure, operational record, responsible person, evidence location, sample period and review status. Evidence may include participant records, worker files, meeting decisions, training, incidents, complaints, feedback, risk actions and improvement closure.

Mark gaps honestly. A template is not proof that a workflow has been implemented, and a synthetic example must never be presented as real provider evidence.

  • Map each applicable quality indicator.
  • Name the evidence owner and location.
  • Check that samples cover the relevant operating period.
  • Separate live evidence, planned evidence and genuine not-applicable decisions.

3. Test participant and worker files end to end

Sample files against the service lifecycle rather than checking isolated forms. Participant testing should follow referral, consent, agreement, planning, risk, delivery, notes, review, incidents or complaints where relevant, and exit. Worker testing should follow recruitment, screening, induction, competence, supervision, training and changes in role.

A file audit should record the sample basis, evidence seen, finding, risk, action owner, due date and closure test. Avoid retrospective reconstruction that makes the file look cleaner than the service was.

4. Use management review to make decisions

Management review should connect audit findings with incidents, complaints, feedback, risks, workforce trends, overdue actions and changes in source requirements. The output is a set of owned decisions, not just meeting minutes.

For each corrective action, confirm the cause, immediate control, permanent change, owner, due date and evidence that the change worked. Close an action only after that effectiveness check.

5. Prepare a calm auditor handover

Use one index, consistent file names and named contacts. Check access before the audit, make scope decisions easy to find and keep participant or worker information limited to what the auditor is authorised to view. If a gap remains, explain it accurately and show the controlled action rather than creating false evidence.

Primary sources and further reading