About a week before a certification audit, the approved quality auditor sends an audit plan. Most of it is logistics: who the auditors are, the opening meeting time, which module runs on which afternoon. The last three pages are headed Documents to be reviewed, and they are the most useful thing a provider will be handed in the whole process.
Most providers read those pages as a checklist and start writing policies.
That is the wrong reading. We have a real one in front of us, issued on 12 August 2026 for a provisional certification audit, and the word policy barely appears in it. The words that recur are register, records, template, list and, more than any other, populated.
The five groups
The plan does not present the list as five groups. It presents it as a page and a half of dense paragraphs. But that is how it hangs together, and it is the order the auditor works through it, so it is the order to build your folder in.
- Key documents. The governance layer. A business plan. An analysis of the risks to the organisation and the strategies for managing them. A conflict of interest form and the register behind it. Emergency and disaster plans for the business and, separately, for participants. Delegations of management responsibility, including who acts when someone is absent. The financial management system, especially where an external accountant is used. A training register for management staff. Evidence of internal audit planning, an internal audit schedule and a continuous improvement plan. The incident form and register. The complaints form and register. The risk register. And the insurances: public liability, professional indemnity, workers' compensation and accident cover, as applicable.
- Workforce documentation. Position descriptions for every role, management and worker, describing skills, knowledge, responsibilities and scope. A populated list of risk-assessed roles, which is a record-keeping obligation under Part 3 of the Worker Screening Rules, not a nice-to-have. A list of workers with capabilities relevant to an emergency response. A plan for finding and inducting a workforce if a disaster disrupts the one you have. A list of worker contact details and secondary employment. Then, per worker: screening clearance, mandatory training in NDIS orientation, infection control and PPE, first aid where applicable, a signed contract and code of conduct, and qualifications where the registration group requires them. For transport, registration group 0108, a driver's licence, car registration and comprehensive car insurance.
- Training records. Six things for every worker: induction, complaints management, incident management including what a restrictive practice is, PPE, the emergency and disaster plans including any review of them, and how to respond to a participant's medical emergency with a system for escalation. Where you deliver them, theoretical and practical training in mealtime management, medication management, and positive behaviour support and restrictive practices. Then participant-specific training: that participant's support plan and risks, their mealtime and behaviour support plans, how they communicate an emerging health concern if they have communication difficulties, and how to respond to their medical emergency.
- What participants receive. A welcome pack or handbook and a service agreement that carry the NDIS Commission's contact details for complaints, an advocacy service, and the National Disability Abuse and Neglect Hotline. Consent templates: for privacy and information sharing, for inclusion in audits by an approved quality auditor unless the participant opts out, for photographs and video, and for building links with other providers. Where applicable, consent templates for handling money and belongings, mealtime management and medication management.
- Participant files and templates. Intake, service agreements, support plans and, where applicable, mealtime and medication plans. Then the templates themselves, with fields the auditor will look for by name. Intake must capture culture, beliefs and interpreter needs, preferences about workers, whether a mealtime plan or referral is needed, and how the participant communicates an emerging health concern. The service agreement must state the circumstances in which services may be withdrawn, a schedule of supports with item numbers and costs, alternative arrangements in an emergency, and consent to share information with other providers. The support plan must carry worker preferences, the risks identified at intake and how they are managed, and preventative health measures: vaccination, dental, comprehensive and allied health. Risk assessment templates for the participant, for transitions to and from hospital or another provider, for how dependent the participant is on your service if it were disrupted, for mealtimes, and for home visits. Participant feedback templates, and a method for people with disability to have input into your policies and procedures.
The plan closes the list with a sentence worth reading twice: there may be other things requested on the day, especially for high-risk modules.

Read it as a chain, not a list
Count what is on that list. Policies and procedures get one line, and the line is a warning: include only the modules in scope. Everything else is the machinery that shows a policy is real.
That is the nine-step chain the whole audit runs on: a standard, the policy that meets it, the procedure that carries it out, the form that captures the event, the register the form feeds, the evidence that the register is live, the audit that samples it, the finding, and the improvement action that closes the loop. The documents list is that chain written out as a set of nouns. Say it, do it, prove it.
The pairs
Notice how often the list asks for two things where a provider has prepared one.
A conflict of interest form and register. An incident form and register. A complaints form and register. Emergency plans for the business and for participants. Training that is theoretical and practical. A training register for management as well as for workers.
Every pair is a "say it" and a "prove it". The form is what you designed. The register is what happened. A provider who arrives with beautifully designed forms and empty registers has brought half of each pair, and it is the half that cannot be checked.
When there are no participants yet
This plan was for a provisional audit: a new provider with no participants and no workers other than its key people. That changes what "evidence" means, and it is worth being precise about it.
With nobody to interview and no files to sample, the auditor assesses the templates. So the fields are the evidence. The intake template either has a field for how a participant communicates an emerging health concern, or it does not. The service agreement either has a line for emergency alternatives, or it does not. Every named field in group five is a thing the auditor will look for by name on a blank form.
The plan also notes, for new providers, that the NDIS worker screening check is required after registration. So a new provider is not marked down for a clearance it cannot yet obtain, but is expected to show the system that will obtain it.
The things only checkable on the day
Some items on the list have no preparation state. They are either true on the day of the audit or they are not.
Insurance certificates in date, in the exact legal name of the audited entity. A driver's licence, registration and comprehensive insurance for every vehicle used under 0108. The populated lists: risk-assessed roles, emergency-capable workers, secondary employment. A list with headings and no rows is the finding, not the preparation for one.
What to do with the week
If the plan has arrived and you have a week, this is how to spend it.
- Build the folder in the five groups, in the plan's order. The auditor's schedule runs Division 1, then Division 2, then 3 and 4, then the modules. A folder that mirrors that order lets them move through it without asking. A folder organised by whoever wrote it makes every request a search.
- Put the register first in every folder. Not the policy. If you read one other piece here, read what NDIS auditors actually look for. The register is what gets opened first, so it should be the first thing in the folder.
- Version and date every document. In a real audit report we have read, the auditor cited eleven documents against a single outcome, and every one carried a version number and a date. That is what the auditor is silently checking: is this the current one, is it approved, does practice match it.
- Send the share link at least two working days before. The plan says so explicitly, and says that failing to do so "may result in additional auditing time and expense". Two working days is the minimum. The day before is late.
- Open every list that says "populated" and populate it. This is the cheapest finding to avoid and the most common one to receive.
What this list is not
It is one auditor's template. Other approved quality auditors lay theirs out differently. In our reading the substance moves very little between them, because every list is built from the same Quality Indicators, but the grouping and the emphasis do vary, and a provider should read the one they were sent, not this one.
It is also a list for a provisional audit of a provider whose scope ran to seven modules. A provider with the core module alone will receive a shorter version. The five groups hold; the length does not.
Grade. `V` for the contents of the list, taken from an approved quality auditor's audit plan (form F34 AudPlan NDIS, issue 2 revision 0) issued on 12 August 2026 for a provisional certification audit under the NDIS Practice Standards, the Quality Indicators Guidelines 2021 and Part 2 of the Worker Screening Rules. The claim that other auditors' lists differ in layout more than in substance rests on our own reading of several and is `C`, not `V`.
Imagery. Generated for this piece in the site's documentary grade. Nobody pictured is a customer, a participant or a worker at any provider.