An NDIS internal audit is a self-check where a registered provider tests its own policies, records and day-to-day practice against the NDIS Practice Standards before an approved quality auditor does. For providers audited against the Core Module, it's a requirement: the Quality Management standard asks for "a documented program of internal audits" sized to your organisation and the supports you deliver. A good internal audit samples real records, writes findings in a set format, and closes gaps with dated evidence.
Say your incident policy promises every incident is reviewed by a manager within 24 hours.
An auditor pulls six incidents from last quarter. Four were reviewed on time, one took nine days, and one was never reviewed at all.
That's a non-conformity, and your own policy created it. The auditor didn't bring a stricter standard. They held you to the one you wrote.
An internal audit finds that gap three months earlier, while it's still an internal note rather than a finding on your audit report. This guide covers how to schedule one, run it, write the findings and report the results.
What is an NDIS internal audit?
An NDIS internal audit is a planned review, run by the provider, that checks whether what actually happens matches what your policies say and what the NDIS Practice Standards require. An external audit is the independent assessment by an approved quality auditor that decides your registration.
Internal audit | External NDIS audit | |
|---|---|---|
Who runs it | Your staff or a consultant you engage | An approved quality auditor |
When | On your own schedule, spread across the year | At registration, renewal and the mid-term point |
Who sees the result | You | You and the NDIS Quality and Safeguards Commission |
What a finding costs you | Time to fix it | A non-conformity, a corrective action plan and possibly registration conditions |
Is an NDIS internal audit mandatory?
Yes, for providers assessed against the Core Module, which covers the certification pathway for higher-risk supports such as SIL and daily personal activities. Auditors will ask to see your internal audit policy, schedule, completed audit results, and proof you changed something because of what you found.
That last item is where most providers fall down. A folder of completed checklists with no follow-up shows the audits happened, but not that anything changed. Log every change in your continuous improvement register and link it back to the audit that triggered it.
How to run an NDIS internal audit in 7 steps
Pick one area. Don't try to audit everything at once. Choose one area, such as incidents, and work through it properly.
Name the criteria. Write down the Practice Standard and your own policy clause you're testing against.
Choose an auditor who doesn't do the work. Your rostering coordinator shouldn't audit rostering. In a small team, swap areas between two people.
Sample real records. We suggest at least 5 records or 10% of the total, whichever is larger, chosen from different weeks and staff.
Test practice, not paperwork. Ask a support worker to show you how they'd lodge a complaint. Don't just read the complaints policy.
Write findings in the 5 C's format (below).
Assign an owner and a date for each fix, then re-sample. A fix counts only once a fresh sample shows it works.
How to write NDIS internal audit findings with the 5 C's
Here's the incident example from the opening, written up properly:
Criteria: Incident Management Policy clause 4.2 says every incident is reviewed by a manager within 24 hours.
Condition: We sampled 6 incidents from July to September 2026. 4 were reviewed within 24 hours, 1 after nine days, and 1 was not reviewed.
Cause: The weekend on-call manager has no access to the incident register.
Consequence: A reportable incident could miss its SIRS deadline, and an auditor would raise a non-conformity.
Corrective action: Give the on-call manager register access by 15 October. The Operations Manager re-samples 6 incidents in December.
A finding written this way can go straight into your report. An auditor reading it can see you found the problem, understood why it happened and fixed it.
NDIS internal audit checklist: what to test and what a red flag looks like
Area | What to sample | Red flag |
|---|---|---|
Service agreement, plan, risk assessment, consent | Agreements signed after the service started | |
10 notes across different workers | Identical wording copied across shifts | |
Last quarter's register | Reviews that are late or missing | |
Register and outcome letters | An empty register. Auditors read that as complaints not being captured | |
Every active worker | Anyone rostered with an expired check or certificate | |
Monthly reports against the behaviour support plan | Practices used that aren't in the plan | |
SCHADS payroll | 5 weekend or broken shifts | No way to show how the pay was calculated |
The last row is the one most internal audits skip. The approved quality auditor tests you against the Practice Standards, not the SCHADS Award. Fair Work tests the Award, and it can go back six years. Your internal audit is the only review that can look at both. Check sampled shifts against the current Fair Work Ombudsman pay guide, and see our SCHADS payroll audit guide for the method.
NDIS internal audit schedule template
Your schedule should match the size of your organisation and the risk of your supports. A 50-staff SIL provider needs more than a sole trader. Here's a practical annual cycle for a provider with 10 to 50 staff:
Quarter | Areas to audit | Why then |
|---|---|---|
Q1 (Jul to Sep) | SCHADS payroll, worker screening, credentials | New award rates apply from 1 July |
Q2 (Oct to Dec) | Incidents, restrictive practices | Enough incidents have built up to sample |
Q3 (Jan to Mar) | Participant files, service agreements, progress notes | Plan reviews cluster early in the year |
Q4 (Apr to Jun) | Complaints, risk register, policy review | Run a whole-system check before the new financial year |
Add an unscheduled audit whenever a serious incident or complaint points to a system problem, and record why you triggered it.
NDIS internal audit report template
Keep each report to two pages:
Scope: the area, date range and criteria tested
Auditor: name and role, confirming they don't do the work being audited
Sample: which records were checked and how they were chosen
Findings: each written in the 5 C's format
What's working: conformities worth keeping
Actions: owner, due date and re-test date for each finding
Sign-off: reviewed by the director or quality lead
How does the external NDIS audit process work, and what does it cost?
There are two main NDIS audit types. Verification audits are for lower-risk supports. Certification audits are for higher-risk supports and include an on-site stage. Every registered provider is re-audited at renewal every three years, and certified providers also have a mid-term audit 18 months into registration. Providers pay the auditor directly.
Auditors quote very different prices depending on your size, registration groups and number of sites. Industry estimates for 2026 run from about $900 to $1,800 for verification and $2,800 to $12,000 or more for certification. Get at least three quotes. Our NDIS registration cost guide covers the full budget.
Book early. Two approved quality auditors left the market in 2026, so fewer auditors are taking bookings. The Commission's types of audits guidance explains which pathway applies to you. For preparation, read what NDIS auditors check and how to prepare for an NDIS audit.
NDIS internal audit tools: spreadsheet or software?
Spreadsheet and Word templates | Compliance software | |
|---|---|---|
Cost | Free | Monthly subscription |
Sampling | You pull every record by hand | Records are already in one place |
Evidence trail | Easy to backdate, hard to prove | Time-stamped automatically |
Best for | Sole traders and very small teams | Providers with 10+ staff |
Spreadsheets work if you're disciplined about them. The weak point is timestamps. An auditor who sees 40 records all created the week before the audit will start asking questions. NDIS compliance software keeps a time-stamped record as the work happens.
Key takeaways
An NDIS internal audit tests whether your practice matches your policies and the Practice Standards.
Core Module providers must keep a documented internal audit program and show the changes it produced.
Sample real records, use an auditor who doesn't do the work, and write findings in the 5 C's format.
Schedule audits quarterly and put SCHADS payroll first, straight after the 1 July rate change.
External audits cost roughly $900 to $12,000 or more depending on pathway, so book your auditor early.
Frequently asked questions
What are the 5 C's of internal audit?
Criteria, condition, cause, consequence and corrective action. Criteria is the rule. Condition is what you found. Cause is why it happened. Consequence is the risk. Corrective action is the fix, with an owner and a date.
What is a red flag in an NDIS internal audit?
The common red flags are:
records created in a batch just before the audit
progress notes copied word for word across shifts
an empty complaints register
staff rostered with expired screening
policies promising "every" or "always" when the records show otherwise
How often do NDIS providers get audited?
All registered providers are audited when they renew registration, every three years. Certified providers also have a mid-term audit 18 months into registration. The Commission can require extra audits, and adding new supports can trigger an out-of-cycle audit.
What are the two main NDIS audit types?
Verification audits cover lower-risk, lower-complexity supports and are a document review. Certification audits cover higher-risk supports such as SIL and include an on-site assessment.
What questions will the NDIS auditor ask me?
Expect "show me" questions rather than "tell me" ones. Common examples are:
Walk me through your last incident.
How do you know every worker's screening is current?
How would a participant make a complaint?
What changed after your last internal audit?
What should I not say during an NDIS audit?
Don't guess, don't say "we always do that" without records to back it up, and don't promise fixes you haven't started. If you're unsure, say you'll get the record, then produce it.
Is there a free NDIS internal audit template?
Yes. The schedule and report structure above can be copied into Excel and Word for free. They cover everything an auditor expects: scope, sample, findings, actions and sign-off.
Run your own audit before the real one
It sounds like the worry isn't the audit day itself. It's not knowing what's sitting in your records right now.
Start with the area most internal audits skip. The FairWork Diagnostic is a 30-minute call with Ahmed, followed by a written payroll exposure report within 3 business days. There's no product pitch on the call.
Book your FairWork Diagnostic →
Or see how CareVisor keeps time-stamped evidence across incidents, credentials and SCHADS pay. Start a 7-day free trial.
About CareVisor
CareVisor is the NDIS Operating System for Australian disability service providers, built in Sydney by NDIS operators who have prepared for and passed Quality and Safeguards Commission audits. It brings rostering, SCHADS pay logged per shift, claiming, incident reporting, credential tracking and compliance records into one NDIS service provider platform mapped to the NDIS Practice Standards. Every record is time-stamped, so your internal audit is working from evidence that was created as the work happened, not assembled the week before. Planning your next cycle? Read our NDIS registration renewal guide.