30/07/2026
NDIS Audit Checklist: An Operational Documentation Review for Providers
Use this NDIS audit checklist to map the official audit scope to policies, worker records, participant documentation, incidents, owners, and follow-up.
Guide record
How this guide is reviewed
CaresLink reviews guides for plain language, practical operational use, and consistency with official sources linked on the page.
- Published
- 30/07/2026
- Reviewed
- 30 July 2026
An NDIS provider audit does not use one universal document list. The NDIS Commission's Initial scope of audit identifies the audit type, registration groups, service delivery types, relevant NDIS Practice Standards, and information to share with the Approved Quality Auditor.
This NDIS audit checklist helps a provider team organise that scope into records, owners, review dates, and follow-up actions. It is a general operational resource only. It does not determine audit scope, conformity, registration status, or audit outcome.
Start with the audit type and official scope
| Audit pathway | Official starting point | Practical document action |
|---|---|---|
| Verification audit | Lower-risk or lower-complexity supports; generally a desktop review of required documentary evidence | Use the Initial scope of audit and the current verification documentation guide to build the evidence index |
| Certification audit | Higher-risk or more-complex supports; assessment can include documents, workers, participants, and observed practice | Map the Core and applicable supplementary modules to local records and responsible owners |
| Mid-term audit | Applies to many providers that completed a certification audit; the final report is generally due 18 months into the registration period | Confirm timing and scope with the Approved Quality Auditor, including governance standards and prior corrective action areas |
| Condition or out-of-cycle audit | Trigger and scope depend on the Commission's condition or a provider registration change | Use the specific Commission notice and auditor request instead of a generic checklist |
The NDIS Commission notes exceptions to the general mid-term audit pathway. Always use the provider's current registration information and the scope supplied for that audit.
Six items to collect before reviewing files
The current Initial scope of audit or other written scope from the NDIS Commission.
The provider's registration groups and service delivery types.
The Core, verification, or supplementary Practice Standards that apply to that scope.
The Approved Quality Auditor's information request, timetable, and secure transfer instructions.
The previous audit report and any open corrective action plan, where relevant.
A local evidence index showing the record family, system, owner, review date, and access boundary.
Map each Practice Standards area to an evidence family
| Review area | Examples to locate | Questions for the local owner |
|---|---|---|
| Governance and risk | Responsibility map, risk process, continuity plan, improvement actions | Is the current owner clear, and can the team show how open actions are followed up? |
| Workers | Role records, screening status, qualifications where relevant, induction, training, supervision | Do records match the roles and supports currently delivered? |
| Participant and service delivery | Service agreement, support plan, consent or communication records, case or progress notes | Can staff locate current information and connect service delivery to the provider's approved record process? |
| Complaints | Complaint process, acknowledgement, action, outcome, participant communication | Can the team follow one matter from intake to closure without duplicating sensitive information? |
| Incidents | Incident record, immediate response, decision trail, notification and follow-up | Does the incident system show what happened, what was done, who was notified, and what changed? |
| Supplementary modules | Module-specific procedures, worker capability records, participant safeguards and review evidence | Has the team mapped only the modules included in the official audit scope? |
Review a small sample, not every file at once
Choose a small sample that reflects the provider's real work. For example, review one current participant file, one worker file, one complaint or incident workflow, and one improvement action. Use the auditor's sampling instructions when they are provided.
For each sample, record what was found, what is missing, the source record location, the responsible owner, and the next review date. Do not backdate, rewrite history, or create evidence for work that did not occur. Record the gap and the action needed.
Participant and support records need local context
The Practice Standards focus on outcomes and quality indicators. They do not make one online progress-note template suitable for every provider, support, participant, or audit.
Check whether the provider's records are current, attributable, accessible to authorised staff, and connected to the local service process. The frequency and fields for case notes or progress notes should follow the provider's service context, agreements, procedures, systems, and professional advice.
Do not upload participant records, worker files, complaints, incidents, or audit evidence to an unapproved AI tool. A metadata-only evidence index can point authorised staff to the controlled source without copying sensitive content.
Worker, complaint, and incident checks
Compare worker screening and qualification records with the roles and supports currently assigned.
Check how expiry dates, refresher training, supervision, and follow-up are tracked locally.
Trace one complaint from acknowledgement through action, outcome, and communication.
Trace one incident through immediate response, record creation, decision-making, notification where applicable, and follow-up.
Confirm that improvement actions have an owner, due date, status, and closure evidence.
A four-stage preparation sequence
| Stage | Practical action |
|---|---|
| Scope | Confirm the audit pathway, modules, dates, sample request, contacts, and secure transfer method |
| Map | Build an evidence index from the official scope and assign a primary owner and backup reviewer |
| Sample | Test a small set of current records and log gaps without altering historical facts |
| Follow up | Track missing items, questions for the auditor, staff briefings, due dates, and final handover |
Use CaresLink resources as starting points
The CaresLink NDIS Case Note Template, Incident Report Form, Care Plan Review Template, and Staff Shift Handover Form can help teams review document structure. They are editable starting points, not official audit forms. Adapt them to the provider's own systems, supports, registration scope, privacy controls, and review process.
Frequently asked questions
What is the difference between verification and certification audits?
Verification generally applies to lower-risk or lower-complexity supports and uses a desktop review of required documentary evidence. Certification applies to higher-risk or more-complex supports and can include documents, interviews, participant input, and observed practice. The Initial scope of audit confirms the pathway for the provider.
When is a mid-term audit due?
The NDIS Commission says the final mid-term audit report is generally due 18 months into the registration period for providers that completed a certification audit. Exceptions apply, so confirm the provider's own timing and scope.
Must a progress note be completed after every support session?
This CaresLink page does not set a universal frequency. The right record timing and fields depend on the support, participant context, service agreement, provider procedure, system, evidence needs, and any professional guidance.
Can an online template prove that a provider meets the Practice Standards?
No. A template can help organise information, but it cannot determine conformity or an audit outcome. Only an Approved Quality Auditor can conduct the independent quality audit, and the NDIS Commission makes registration decisions.
Is this a complete NDIS audit document list?
No. Use the current Initial scope of audit, applicable Practice Standards, Commission guidance, and the Approved Quality Auditor's request. This checklist is only an internal document-mapping aid.
Does this page provide compliance or professional advice?
No. CaresLink provides general operational resources only. This page is not legal, compliance, clinical, medical, financial, audit, registration, or professional advice.
Disclaimer
These resources are provided for general operational documentation and educational purposes only. They do not constitute legal, clinical, medical, compliance, or professional advice. Organisations should review and adapt all documents according to their own policies, procedures, registration requirements, funding arrangements, and regulatory obligations.