NDIS Verification vs Certification Audit: Which Do You Need?
- P&P Consulting
- Aug 14
- 4 min read
Your registration groups decide whether you need a verification or certification audit, not your size. Here's how to tell which applies to you.

If you are registering as an NDIS provider, or coming up for renewal, the first question to settle is which audit you actually face. There are two, they are not interchangeable, and the answer is not based on how big your organisation is. So we'll break down for you NDIS Vertification vs Certification Audit: which do you need.
Your registration groups determine your audit pathway. A provider delivering only lower risk supports goes through a verification audit, which is assessed on documents alone. A provider delivering one or more higher risk or more complex supports goes through a certification audit, which includes an on-site assessment. A two-person organisation delivering complex supports will face a certification audit. A larger organisation delivering only low risk supports may not.
NDIS verification vs certification audit: what is the difference?
The difference is scope and depth. Verification checks that you hold the right documents and meet the applicable NDIS Practice Standards. Certification examines how your organisation actually operates, in person.
Verification audit | Certification audit | |
Applies to | Lower risk, lower complexity supports | One or more higher risk or complex supports |
Site visit | No, documents only | Yes, on site |
Stages | Single desktop review | Two stages |
Mid-term audit | Exempt | Required at 18 months |
How do I know which one applies to my organisation?
Check your registration groups against the NDIS Quality and Safeguards Commission's registration group table. Each group is designated as either verification or certification. If any single group you are registered for requires certification, you are on the certification pathway for your whole registration. You cannot mix and match.
This catches people out. Providers often assume that because most of their supports are simple, they will get the simpler audit. One higher risk group is enough to move you across.
What actually happens in a certification audit?
It runs in two stages, and the timing between them is fixed.
Stage 1: desktop review
Your auditor reviews your policies, procedures and evidence remotely. This commonly takes anywhere from two to twelve weeks depending on how ready your documentation is. Most of the delay providers experience happens here, and almost all of it is avoidable with preparation.
Stage 2: on-site assessment
Your auditor visits, observes how the work is actually done, and interviews staff and often participants. Stage 2 must commence within three months of Stage 1 being completed, so a slow Stage 1 compresses everything that follows.
What is a mid-term audit, and am I exempt?
A mid-term audit happens 18 months into your registration period and applies only to providers who completed a certification audit. It focuses on the Governance and Operational Management standards, plus any corrective actions still outstanding from your last audit.
You are exempt if you were verified rather than certified, or if you are registered solely for Specialist Disability Accommodation.
The practical point: if you closed out corrective actions on paper but never changed how the work is done, the mid-term audit is where that surfaces.
How should I prepare?
The providers who struggle are rarely the ones doing poor work. They are the ones who cannot evidence good work. Preparation is mostly about closing that gap.
Confirm your pathway first. Check your registration groups before you plan anything else, because it changes the timeline and the cost.
Map your evidence to the standards. For each applicable NDIS Practice Standard, know which document or record demonstrates it. If you cannot name it, the auditor will not find it either.
Check your policies match reality. A policy describing a process nobody follows is worse than no policy, because it evidences a gap between what you say and what you do.
Close out old corrective actions properly. Outstanding items from a previous audit are explicitly revisited.
Run an internal audit before the real one. Finding a non-conformity yourself is a fixable problem. Finding it during Stage 2 is a delay.
Getting help with it
P&P Consulting supports NDIS and ISO readiness across Adelaide and South Australia. Our team holds Lead Auditor credentials in ISO 9001, ISO 14001 and ISO 45001, and we have supported every certification project to date with zero major non-conformities.
We work through gap analysis, readiness and internal audits, so the first time an external auditor sees your systems is not the first time anyone has checked them. You can read more about our NDIS and ISO readiness and auditing services, or book a free 30-minute consultation to work out which pathway applies to you.
Frequently asked questions
Can I choose which NDIS audit type I have?
No. Your audit type is determined by the registration groups you apply for, not by preference or organisation size. If any group you register for requires certification, you are on the certification pathway.
How long does an NDIS certification audit take?
Stage 1, the desktop review, commonly takes two to twelve weeks depending on how complete your documentation is. Stage 2, the on-site assessment, must commence within three months of Stage 1 being completed.
Do I need a mid-term audit?
Only if you completed a certification audit. It happens 18 months into your registration and focuses on Governance and Operational Management, plus any outstanding corrective actions. Verified providers and those registered solely for Specialist Disability Accommodation are exempt.
What is the difference between the NDIS Practice Standards and ISO certification?
They are separate schemes with different auditors, but the underlying discipline overlaps heavily: documented processes, evidence of what you actually do, internal auditing and corrective action. Providers who already run an ISO-aligned system usually find NDIS audits considerably less disruptive.



Comments