NDIS Verification Audit Checklist 2026: What Providers Need to Prepare
Preparing for an NDIS Verification audit can feel deceptively simple. It is often described as a desktop audit, but that does not mean uploading a few generic policies and waiting for approval.
Your Approved Quality Auditor will review documentary evidence connected to your registration groups, professional requirements and the four areas of the NDIS Verification Module. The goal is to show that your organisation has suitable systems in place—and that those systems are supported by current, authentic records.
This guide gives you a practical NDIS Verification audit checklist to help organise your evidence before you submit it to your auditor.
Important: Your Initial Scope of Audit and your auditor’s evidence request take priority over any general checklist. Requirements vary according to your registration groups, services, workforce and professional obligations.
Quick answer: what do you need for an NDIS Verification audit?
Most providers preparing for Verification should expect to organise evidence across these areas:
-
Initial Scope of Audit and registration information
-
Qualifications and professional association evidence
-
Worker identity, experience and pre-engagement checks
-
NDIS worker orientation and professional-development records
-
Infection prevention, control and PPE training
-
Incident management policies, procedures and records
-
Complaints management policies, procedures and records
-
Risk management, insurance and emergency-planning evidence
-
Document approval, version control and evidence indexing
The exact list must be checked against your Initial Scope of Audit, the NDIS Practice Standards Qualification and Professional Associations Required Documentation Guide, and the request supplied by your Approved Quality Auditor.
What is an NDIS Verification audit?
Verification is the audit pathway generally used for providers delivering lower-risk or lower-complexity supports and services.
It is conducted by an Approved Quality Auditor as a desktop review of the required documentary evidence. The audit assesses the provider against the NDIS Practice Standards relevant to the application.
The NDIS Verification Module covers four areas:
-
Human resource management
-
Incident management
-
Complaints management
-
Risk management
Verification is not determined by your profession alone. Your registration groups and the Initial Scope of Audit issued for your application determine the audit pathway you need.
Already unsure which pathway applies? Read Launchly’s NDIS Verification vs Certification guide before choosing documentation.
Start with your Initial Scope of Audit
Do not begin by downloading random policies or copying a checklist from another provider.
After you submit an NDIS provider registration application, the NDIS Commission issues an Initial Scope of Audit. This document identifies:
-
The type of audit required
-
Your registration groups or classes of support
-
Your types of service delivery
-
The relevant NDIS Practice Standards
-
The information you need to share with your auditor
Use the Initial Scope when requesting quotes from Approved Quality Auditors and when deciding which documents you need to prepare.
Initial Scope checklist
Before moving on, confirm that you have:
The current Initial Scope of Audit for your application or renewal
The correct legal entity name and ABN
The registration groups listed in your application
The types of service delivery shown in the scope
The audit type clearly identified as Verification
The relevant Practice Standards and evidence requirements
Any questions that need clarification from your auditor
What if your scope includes Verification and Certification groups?
When an application includes registration groups associated with both Verification and Certification, the provider must complete a Certification audit.
That is why it is risky to choose a documentation pack based only on a profession, job title or one service you intend to offer. Check the entire scope first.
NDIS Verification audit checklist
The following checklist is organised around the main evidence areas providers should review. It is not a substitute for an organisation-specific auditor request.
1. Registration, scope and business information
Create a central folder containing the information your auditor will use to identify the organisation and understand the audit scope.
Prepare:
Initial Scope of Audit
Legal entity and ABN details
Business and trading names
Contact details for key personnel
Registration groups being applied for or renewed
Service-delivery types and operating locations
Current organisation chart or responsibility structure, where relevant
Previous audit report and corrective actions, for renewal audits
A document index showing where each item is stored
Use the same organisation name consistently across your policies, forms, insurance certificates and supporting records.
2. Qualifications and professional requirements
Some Verification registration groups have specific qualification, experience, registration or professional-association requirements.
Check the current NDIS Practice Standards Qualification and Professional Associations Required Documentation Guide for the requirements connected to your registration groups.
Depending on the profession and registration group, evidence may include:
Certified qualification documents
AHPRA registration details, where applicable
Professional association membership
Evidence of relevant professional experience
Clinical supervision records, where required
Continuing professional development records
Role-specific competency evidence
Evidence for each worker delivering the relevant service
Do not assume that one director’s qualification automatically covers every worker or contractor delivering the support.
3. Human resource management evidence
The Verification Module expects providers to maintain records showing that workers are suitable and competent for their roles.
Your workforce evidence may include:
Worker identity records
Right-to-work evidence
Pre-engagement and background checks
Qualifications and experience
Position descriptions
Defined responsibilities, scope and limitations
Completed NDIS Worker Orientation Module records
Induction and orientation records
Continuing professional development records
Supervision and competency records
Infection-prevention and control training
PPE training for workers who directly support participants
NDIS Worker Screening clearance for risk-assessed roles, where applicable
A workforce or training register
For sole traders, the evidence still needs to exist. Your “worker file” may effectively be your own professional evidence folder.
4. Incident management system
A Verification provider needs an incident management system that is relevant and proportionate to the services delivered and the organisation’s size and complexity.
Review whether you have:
Incident Management Policy and Procedure
Incident Report Form
Incident Register
Escalation and response steps
Reportable-incident notification process
Investigation and review records
Corrective-action records
Worker training or acknowledgement records
Participant information about incident management
Documented review and learning following incidents
A policy explains the process. Completed reports, registers, reviews and corrective actions show how the system is used.
A new provider may not have historical incidents to show. Your auditor can clarify what implementation evidence is appropriate for a provider that has not yet commenced delivering services.
5. Complaints management system
Participants and other people need to be able to access a complaints process that is understandable, fair and appropriate to the organisation.
Prepare:
Complaints and Feedback Management Policy and Procedure
Complaints or Feedback Form
Accessible information for participants
Complaints Register
Acknowledgement and response templates
Assessment and investigation records
Outcome and resolution records
Referral and escalation pathways
Information about external complaint options
Worker complaints-handling training
Review and improvement records
Check that your participant-facing information explains how to raise a complaint without fear of adverse treatment and how to contact the NDIS Commission.
6. Risk management evidence
The Verification Module requires a documented risk management system that is proportionate to the provider’s size, services and complexity.
Your evidence may include:
Risk Management Policy and Procedure
Organisational Risk Register
Risk assessment template
Completed organisational or service risk assessments
Risk treatments, owners and review dates
Work health and safety risk controls
Service-delivery risk considerations
Evidence that risk controls are reviewed
Infection-prevention and control procedures
PPE availability and management, where required
Your risk register should be specific to your business. Generic entries such as “staff risk” or “participant risk” are unlikely to explain what could happen, who may be affected, how the risk is controlled or when it will be reviewed.
7. Emergency, disaster and service-disruption planning
Risk management under the Verification Module includes emergency and disaster planning.
The standards also require risk assessments to consider:
-
How much participants rely on the provider’s services for daily living needs
-
How their health and safety could be affected if services were disrupted
Prepare:
Emergency and Disaster Management Plan
Business Continuity Plan
Emergency contacts and escalation responsibilities
Service disruption risk assessment
Alternative service arrangements, where applicable
Communication process for affected participants
Testing or review schedule
Records of plan reviews or exercises, where available
The detail should reflect your actual services. A sole allied health practitioner operating from a clinic will have different continuity risks from a provider delivering daily supports in participants’ homes.
8. Insurance evidence
The Verification risk-management indicators refer to appropriate insurance, including professional indemnity, public liability and accident insurance.
Organise:
Current professional indemnity certificate
Current public liability certificate
Accident or personal accident insurance, where applicable
Workers compensation insurance, where applicable
Vehicle or other service-specific insurance, where applicable
Policy schedules showing the insured entity
Renewal dates recorded in a compliance calendar or register
Check that the legal entity named on each certificate matches the provider entity being audited.
9. Infection-control and PPE evidence
Infection prevention and control appears in both the human resource and risk-management areas of the Verification Module.
Review:
Infection Prevention and Control Policy and Procedure
Worker infection-control training
Refresher-training records
Hand-hygiene and respiratory-hygiene guidance
PPE training for direct-support workers
Evidence that required PPE is available
Cleaning, waste or exposure procedures relevant to your services
Records showing how infection-control risks are reviewed
Avoid including clinical procedures that your organisation does not perform. The documents should match your real scope of practice and service environment.
10. Document control and evidence organisation
Even strong documents become difficult to assess when they are duplicated, undated or scattered across multiple folders.
Before sending evidence to your auditor, check:
Every policy has an owner
Approval and review dates are completed
Version numbers are consistent
Superseded copies are clearly separated
File names are easy to understand
Registers contain current information
Supporting records can be traced to the relevant policy
Confidential information is shared securely
An evidence index maps each requirement to the relevant file
Outstanding gaps have an owner and completion date
A simple evidence index can save time for both you and your auditor.
Policies are not the same as evidence
One of the most important distinctions in audit preparation is the difference between a template and evidence.
A policy describes what your organisation intends to do. Documentary evidence demonstrates how the system has been established or used.
| System | Policy or procedure | Supporting evidence |
|---|---|---|
| Human resources | Workforce Management Policy | Qualifications, checks, induction and training records |
| Incidents | Incident Management Procedure | Incident forms, register, investigations and corrective actions |
| Complaints | Complaints Management Procedure | Accessible information, forms, register and resolution records |
| Risk | Risk Management Procedure | Risk register, assessments, treatments and review records |
| Emergency planning | Emergency and Continuity Plan | Contact lists, disruption assessments, testing and review records |
Templates are useful foundations, but they should not be submitted unchanged. Customise them to reflect your organisation, assign responsibilities, approve them, implement them and connect them to genuine records.
A seven-day Verification preparation plan
Day 1: Confirm your scope
Read the Initial Scope of Audit, list every registration group and identify anything that needs clarification from the auditor.
Day 2: Build the workforce folder
Collect qualifications, registrations, memberships, identity evidence, screening records, orientation completion and professional-development evidence.
Day 3: Review incidents and complaints
Check the policies, participant information, forms, registers, escalation pathways and worker guidance.
Day 4: Review risks and emergencies
Complete the organisational risk register, service-disruption assessment, emergency plan and infection-control documents.
Day 5: Check insurance and business records
Confirm entity names, policy dates, certificates, responsibilities and renewal reminders.
Day 6: Customise and approve documents
Replace placeholders, remove irrelevant wording, assign document owners and complete version-control information.
Day 7: Complete an internal evidence review
Use an evidence index to map each requirement to a file. Record any gaps and confirm unresolved questions with your Approved Quality Auditor.
Frequently asked questions
Is an NDIS Verification audit a desktop audit?
Yes. The NDIS Commission describes Verification as a desktop review of the required documentary evidence conducted by an Approved Quality Auditor.
Who can conduct a Verification audit?
Only an Approved Quality Auditor can assess a provider against the NDIS Practice Standards for registration. Use the current auditor list published by the NDIS Commission.
Do I need policies and procedures for Verification?
You need systems and documentary evidence addressing the applicable Verification requirements. Policies and procedures usually form part of that system, but they should be supported by relevant records, registers, certificates and completed evidence.
Does Verification apply to every allied health professional?
Not automatically. The audit type depends on the registration groups in the application. Check the Initial Scope of Audit and the current registration-group table.
What happens if I apply for both Verification and Certification registration groups?
Where an application includes registration groups associated with both pathways, a Certification audit is required.
Can a template pack guarantee that I will pass the audit?
No. Audit and registration outcomes depend on your scope, professional requirements, customised documents, authentic evidence, implementation and the wider assessment process.
Prepare your Verification documentation with a clearer system
Trying to build every policy, procedure, form, register and audit tool separately can create duplication and make evidence harder to organise.
The Launchly Verification Documentation System brings editable Word documents and Excel workbooks together in a structured system for providers whose Initial Scope confirms Verification.
It includes provider documentation, risk and emergency-management resources, complaints documents, workforce evidence tools and audit-preparation workbooks designed to be customised for your organisation.
Before purchasing, confirm that Verification is the audit pathway shown in your Initial Scope of Audit.
View the Verification Documentation System
Important information
This article provides general information and does not replace your Initial Scope of Audit, current NDIS Commission guidance, an Approved Quality Auditor’s evidence request, or organisation-specific legal, professional or clinical advice.
Launchly is independent from the NDIS Quality and Safeguards Commission, the NDIA and Approved Quality Auditors. Templates must be reviewed, customised, approved, implemented and maintained by the purchasing organisation. No template or checklist guarantees registration or a particular audit outcome.