Blog
September 2026

Ask a provider how they are preparing for certification and they will talk about policies. Ask an approved quality auditor how they spend the day and you get a different answer entirely.
The auditor opens the register.
Not the policy. Not the procedure. The register: the running record of things that actually happened. They sample rows from it, trace each one backwards to the form that created it and forwards to the action it triggered. Prose is checked last, and often barely.
That single fact reorganises how you should prepare, and it is not what the market sells you.
This is the shape of nearly every area of an audit, whatever the subject matter. It is two walks: from a record back to its evidence, and from a record forward to its consequence.
If those two traversals are fast, you pass. If the register is thin, nothing in the policy library rescues it.

The Quality Indicators Guidelines set the areas. Certification for higher-risk supports runs as a document review, then site visits with interviews of both workers and participants. Participant sampling is opt-out, so participants are included unless they decline. The auditor recommends; the Commission decides.
They open participant files, consent records and the participant handbook, then interview participants directly. The interview is the part providers underprepare for, because it cannot be tidied in advance. What a participant says about choice and control either matches your records or it does not.
Delegations, board or management minutes showing compliance genuinely on the agenda, conflict-of-interest declarations and the register behind them, and your notification history to the Commission. Mid-term audits concentrate here.
The tell is the minutes. Compliance appearing as a standing item with no discussion recorded against it, meeting after meeting, reads as an organisation that has learned the shape of governance without doing any of it.
The risk register: currency, ownership, whether participant-specific risks actually reach support plans, and whether incidents feed back into it. That last link is the one most often broken. Incidents get recorded in one register and change nothing in the other.
The incident register, then the individual records, then whether anything changed as a result. Reportable incident timeframes tightened in 2026, so the gap between the date an event happened and the date it was entered is now itself evidence.
Notice what all four have in common. Every one is a record of events, not a statement of intent.


Because policy is the part you can finish.
A policy can be written, approved, filed and ticked off. It has an end state, and it produces a feeling of completion. A register never does. It is a habit, it degrades the moment attention moves elsewhere, and it cannot be produced retrospectively without that being obvious to anyone who has read a few.
That asymmetry is why the market sells document packs. A pack is a deliverable, and a deliverable can be bought. The thing being assessed is not a deliverable. It is a practice, and nobody can sell you one.
There is a second reason, and it is structural. Most providers meet an auditor once every few years and meet their own policy library every week. The library is what feels like compliance, because it is what they touch.
If you have a week, do not spend it re-reading policies.
The gap you find doing this is information. The gap you do not go looking for is the one that gets written up.
If your registers are honest and current, a thin policy library is a minor finding you can close.
If your registers are thin, a beautiful policy library makes it worse, because it demonstrates the organisation knew exactly what it was supposed to be doing.
Everything above is drawn from the Quality Indicators Guidelines, compilation C03, in force 1 July 2026, and from Rise's own auditor focus map. Where it rests on practitioner consensus rather than the instrument, the dossier says so, and so do we.
We’ll show you a certification done in ten hours.
You decide whether it holds up.