What NDIS auditors actually look for

Blog

September 2026

A man sitting at a sunlit table, hands clasped, looking toward the window in thought

Ask a provider how they are preparing for certification and they will talk about policies. Ask an approved quality auditor how they spend the day and you get a different answer entirely.

The auditor opens the register.

Not the policy. Not the procedure. The register: the running record of things that actually happened. They sample rows from it, trace each one backwards to the form that created it and forwards to the action it triggered. Prose is checked last, and often barely.

That single fact reorganises how you should prepare, and it is not what the market sells you.

The traversal, in the order it happens

This is the shape of nearly every area of an audit, whatever the subject matter. It is two walks: from a record back to its evidence, and from a record forward to its consequence.

  1. Open the register. Is it current? Who owns it? When was the last entry, and does the gap since then look plausible for an organisation this size? A register with nothing in it for five months either describes an organisation where nothing happened, or one that stopped writing things down.
  2. Sample rows. Not the ones you offer. Rows the auditor chooses, and they choose the awkward ones: the oldest item still open, the one with no closure date, the one that appears twice, the one entered three weeks after the date it records.
  3. Trace backwards to the form. Does a completed form exist for this row? Filled in at the time, by someone who was there, with the detail the form asks for rather than one word in each box.
  4. Trace forwards to the action. What happened next, who did it, when, and is there evidence it closed? An incident with no follow-through is worse evidence than no incident, because it proves the system noticed and then did nothing.
  5. Only then, read the policy. And read it to check it describes what they have just watched happen. Not to assess its prose.

If those two traversals are fast, you pass. If the register is thin, nothing in the policy library rescues it.

A hard diagonal band of afternoon sun cutting across a plain cream wall

Where they look, area by area

The Quality Indicators Guidelines set the areas. Certification for higher-risk supports runs as a document review, then site visits with interviews of both workers and participants. Participant sampling is opt-out, so participants are included unless they decline. The auditor recommends; the Commission decides.

Rights of participants

They open participant files, consent records and the participant handbook, then interview participants directly. The interview is the part providers underprepare for, because it cannot be tidied in advance. What a participant says about choice and control either matches your records or it does not.

Governance and operational management

Delegations, board or management minutes showing compliance genuinely on the agenda, conflict-of-interest declarations and the register behind them, and your notification history to the Commission. Mid-term audits concentrate here.

The tell is the minutes. Compliance appearing as a standing item with no discussion recorded against it, meeting after meeting, reads as an organisation that has learned the shape of governance without doing any of it.

Risk management

The risk register: currency, ownership, whether participant-specific risks actually reach support plans, and whether incidents feed back into it. That last link is the one most often broken. Incidents get recorded in one register and change nothing in the other.

Incident management

The incident register, then the individual records, then whether anything changed as a result. Reportable incident timeframes tightened in 2026, so the gap between the date an event happened and the date it was entered is now itself evidence.

Notice what all four have in common. Every one is a record of events, not a statement of intent.

A studio portrait of a man in a plain sage top against a warm grey backdrop
Macro detail of woven linen in raking light

Why providers get this backwards

Because policy is the part you can finish.

A policy can be written, approved, filed and ticked off. It has an end state, and it produces a feeling of completion. A register never does. It is a habit, it degrades the moment attention moves elsewhere, and it cannot be produced retrospectively without that being obvious to anyone who has read a few.

That asymmetry is why the market sells document packs. A pack is a deliverable, and a deliverable can be bought. The thing being assessed is not a deliverable. It is a practice, and nobody can sell you one.

There is a second reason, and it is structural. Most providers meet an auditor once every few years and meet their own policy library every week. The library is what feels like compliance, because it is what they touch.

What to do in the week before an audit

If you have a week, do not spend it re-reading policies.

  • Open every register. Find the rows with no owner, no date or no closure. Close them properly, or record honestly why they are still open. An open item with a reason is fine. An open item with silence is a finding.
  • Run the traversal on yourself. Pick five rows genuinely at random and walk backwards to the form and forwards to the action. Where it breaks for you is where it will break for the auditor.
  • Check the joins. Do incidents in the incident register appear in the risk register where they should? Do participant-specific risks appear in that participant's support plan?
  • Time the retrieval. Someone should be able to produce any named record in under a minute. Speed reads as control. Hunting reads as the opposite, whatever the document eventually says.

The gap you find doing this is information. The gap you do not go looking for is the one that gets written up.

The uncomfortable version

If your registers are honest and current, a thin policy library is a minor finding you can close.

If your registers are thin, a beautiful policy library makes it worse, because it demonstrates the organisation knew exactly what it was supposed to be doing.

Everything above is drawn from the Quality Indicators Guidelines, compilation C03, in force 1 July 2026, and from Rise's own auditor focus map. Where it rests on practitioner consensus rather than the instrument, the dossier says so, and so do we.

Otherblogs

We’ll show you a certification done in ten hours.

You decide whether it holds up.

Rise © 2026