Skip to content
Monday - Friday (10am - 05 pm)
Provider Compliance
Call Us: 1800 299 452(Monday - Friday)
Suite 1.10e/142 King StreetSydney NSW 2000, Australia
Provider Compliance
  • Home
    • Blogs
    • About Us
    • Contact Us
    Provider Compliance
    • Home
    • Blogs
    • About Us
    • Contact Us
    Call Us: 1800 299 452(Monday - Friday)
    Suite 1.10e/142 King StreetSydney NSW 2000, Australia
    Book a Consultation
    Book a Consultation

    What Is the Difference Between an NDIS Verification and Certification Audit?

    • Home
    • Compliance
    • What Is the Difference Between an NDIS Verification and Certification Audit?
    Two neatly prepared audit folders of different thickness side by side on a meeting table

    A verification audit is a shorter, mostly desktop check for lower-risk NDIS supports, while a certification audit assesses you against the full NDIS Practice Standards for higher-risk or more complex supports. The supports you register for decide which one applies. Your size and your preference do not.

    This article explains how each audit works, what auditors look for, what happens when you deliver both kinds of support, and how to prepare. It is written for providers applying for NDIS registration and for registered providers planning to add supports.

    What is an NDIS verification audit?

    A verification audit is the lighter of the two. An approved quality auditor reviews evidence that you have the basics in place to deliver lower-risk supports safely. It is generally done as a desktop review, without a site visit.

    The auditor typically looks at:

    • the qualifications, experience and registrations your workers need for their roles
    • your insurance
    • incident management
    • complaints management
    • risk management

    The NDIS Quality and Safeguards Commission sets the scope of the verification audit and which supports it covers. Check its current guidance for the supports on your application, since the registration reforms are changing how supports are grouped.

    What is an NDIS certification audit?

    A certification audit is more thorough. The auditor assesses your organisation against the core NDIS Practice Standards and any supplementary modules that apply to the supports you deliver. It is usually run in two stages.

    1. Stage 1, documentation review. The auditor checks that your policies, procedures and systems address each standard that applies.
    2. Stage 2, implementation. The auditor checks that those systems work in practice. This usually means a site visit or remote sessions, interviews with key personnel and workers, file reviews and, where you already deliver services, conversations with participants.

    Certification applies to supports that carry more risk for participants or need more specialised skills. The Commission publishes which supports need certification and which modules attach to them, and that guidance is the one to rely on.

    Verification and certification side by side

    FeatureVerification auditCertification audit
    Who it is forProviders delivering only lower-risk supportsProviders delivering any higher-risk or complex supports
    What is assessedCore evidence: qualifications, insurance, incidents, complaints and riskThe core Practice Standards plus any modules that apply
    FormatMostly a desktop reviewTwo stages, including implementation checks and interviews
    Participant inputGenerally noneYes, where you already have participants
    Relative cost and effortLowerHigher
    Ongoing auditsRepeated when you renewRepeated when you renew, with any mid-term audit the Commission requires

    The audit type also has a large effect on how long registration takes. We cover that in how long NDIS registration takes.

    What auditors look for in certification interviews

    Interviews are where many providers are caught out. A well-written policy cannot answer for a worker who has never read it.

    Auditors typically ask staff to describe, in their own words, what they would do if a participant was injured, wanted to make a complaint or refused a support. They ask key personnel how the organisation identifies and manages risk, and how incidents and complaints lead to changes. Where participants are interviewed, the auditor listens for whether they feel respected, informed and able to raise concerns.

    The answers do not need to be word-perfect. They need to match what your procedures say and show that the process is used. Our article on common audit readiness mistakes covers the gaps auditors find most often.

    What if you deliver both types of support?

    If any support on your registration needs certification, expect your registration to go through certification. You do not get to pick the lighter audit for part of your services. The Commission’s guidance explains how mixed registrations are audited under the current model.

    This is why choosing supports carefully matters. Registering for a higher-risk support you do not plan to deliver soon can move your whole registration into a certification audit, with more cost and a longer timeline.

    The NDIS Review recommended a graduated, risk-proportionate approach to regulation, and the Government has been reworking how supports are grouped and how audits are assigned. Before you book an auditor, confirm with the Commission which audit applies to the supports on your application. Our article on NDIS reforms and provider compliance gives the wider background.

    How to prepare for each audit

    The preparation is similar in kind but very different in depth.

    For verification:

    • Worker qualifications, experience and screening records are current and filed.
    • Certificates of currency for your insurance are on hand.
    • An incident management procedure exists, and you can show it has been used or tested.
    • A complaints procedure exists, and participants are told how to complain.
    • A risk register and risk management procedure are in place.

    For certification, everything above plus:

    • Policies and procedures mapped to every core Practice Standard and each module that applies.
    • Governance evidence, such as management or board minutes, delegations and a conflict-of-interest register.
    • Participant files showing assessment, planning, consent and review.
    • Staff training records and induction evidence.
    • Workers who can explain how the procedures work in their own words.
    • A continuous improvement register with real entries.

    A mock audit is the most reliable way to find gaps before the auditor does, particularly for certification.

    Moving from verification to certification later

    Many providers start with verification and add higher-risk supports as they grow. Adding those supports generally means applying to change your registration and completing a certification audit. The Commission sets out the current process for this.

    Building systems that already meet the full Practice Standards makes the step up far less disruptive. You avoid rewriting policies and retraining staff at the same time as you take on new services. If you are weighing up how to resource that growth, see our comparison of an end-to-end compliance partner vs in-house compliance.

    Not sure which audit your supports need? Our NDIS consultant services include audit preparation for both types, and we quote a fixed fee after a free 15-minute call. Book a call.

    Frequently asked questions

    Which is harder, a verification or certification audit?

    Certification. It covers the full Practice Standards and checks that your systems work in practice, including interviews with staff and participants.

    Is a verification audit done onsite?

    Generally no. Verification is usually a desktop review of your documents and evidence, though the Commission’s current guidance is the final word.

    Can I choose verification to save money?

    No. The supports you register for decide the audit type. You can reduce the audit burden only by not registering for higher-risk supports you do not deliver.

    How often are NDIS audits required?

    Both audit types are repeated when you renew your registration. The Commission sets the registration period and any mid-term audit requirements, so check its current guidance.

    Who conducts NDIS audits?

    Approved quality auditors that you engage and pay. The Commission then reviews the audit report and makes the registration decision.

    Recent Posts

    • How Long Does NDIS Registration Take?
    • What Is the Difference Between an NDIS Verification and Certification Audit?
    • What Providers Need to Do Under the Strengthened Aged Care Quality Standards
    • How to Fix NDIS Audit Non-Conformities and Stop Them Coming Back
    • Frequent Compliance Pitfalls for Support Workers and How to Avoid Them
    Provider Compliance

    Outstanding NDIS and Aged Care Compliance Support

    • Suite 1.10e/142 King Street, Sydney NSW 2000, Australia
    • 1-800-299-452
    • info@providercompliance.com.au

    Our Services

    • Aged Care Consultant
    • Business Growth Strategy
    • ISO Compliance
    • NDIS Consultant Services

    Locations

    • Adelaide, SA
    • Brisbane, QLD
    • Canberra, ACT
    • Darwin, NT
    • Melbourne, VIC
    • Perth, WA
    • Sydney, NSW
    • Tasmania, TAS

    Newsletter

    Send us a newsletter to get update

    NDIS consultants

    • Adelaide
    • Brisbane
    • Canberra
    • Darwin
    • Melbourne
    • Perth
    • Sydney
    • Tasmania

    Aged care consultants

    • Adelaide
    • Brisbane
    • Canberra
    • Darwin
    • Melbourne
    • Perth
    • Sydney
    • Tasmania

    © Copyright 2026 Provider Compliance All Rights Reserved.

    Terms of Service | Privacy Policy