Why NDIS providers fail audits — and how to pass
5 min read · Freddy Ortega · June 2026
Understanding why NDIS providers fail audits rarely comes down to intent. Every provider I've worked with wants to do the right thing — they employ good people, they care about participants, they work hard. And then an audit comes around and something goes wrong, not because of fraud or negligence, but because the systems and records that prove compliance weren't in place. Below I explain what happens if you fail an NDIS audit, the pattern behind almost every failed NDIS audit, and the practical steps to fix each gap before your next review.
What providers assume
- We manage risk well day-to-day
- Our policies are up to date
- The board is across governance
- Staff are trained and compliant
- Our incident process works
What auditors need to see
- Risk register reviewed this quarter
- Policies reviewed on schedule with sign-off records
- Board minutes show active risk governance
- Training records current for every staff member
- Incident register complete, closed-loop, trend-analysed
The auditor can't see intent. They can only see evidence.
The Real Reason NDIS Audits Go Wrong
The NDIS Quality and Safeguards Commission audits against the Practice Standards. Those standards cover everything from governance and risk to incident management, complaints handling, and human resources practices. Providers fail — or receive significant non-conformances — not because they're doing the wrong thing, but because they can't demonstrate they're doing the right thing. If your risk register hasn't been reviewed in 18 months, that's a finding. If your board minutes don't show active governance of key risks, that's a finding. None of those things mean you're running a bad service. They mean your visibility infrastructure hasn't kept pace with your operation.
Risk Register
Created at accreditation. Rarely updated. No clear ownership. By audit time — out of date.
Fix: Quarterly review cycle. Board-sighted. Owner assigned to every risk.
Policy Governance
Policies exist but aren't lived. No review schedule. Staff not trained against them. No breach records.
Fix: Review calendar. Training records. Board sign-off trail.
Board Reporting
Board papers don't include risk dashboard, incident summary or compliance status.
Fix: Standard board paper template covering quality and risk every meeting.
What to Fix First
If an audit is approaching or you've recently received findings, the most valuable thing you can do isn't to write new policies. It's to audit your own evidence trail. Ask yourself: if an auditor asked to see proof of X tomorrow, what would I show them?
Audit readiness score
0%
Not where you want to be? Book a free clarity call
The Visibility Problem
The NDIS Practice Standards are not unreasonable. Most providers, if you described what they actually do, would meet them. The challenge is that what you do and what you can prove you do are two different things. Compliance isn't a document exercise. It's a visibility exercise. The organisations that sail through audits aren't necessarily better run — they're better documented.
If you want a hand closing those gaps, our fractional COO and governance support gives NDIS providers ongoing senior oversight without a full-time hire. And if manual reporting is slowing your evidence trail, see the hidden cost of a manual finance process.
NDIS Audits: Your Questions Answered
How do I prepare for an NDIS audit?
Start early. Map your policies, procedures and records against the NDIS Practice Standards that apply to your registration groups, and make sure the evidence behind them is current. Check that participant files, consent and plans, incident and complaints records, and worker screening clearances are complete and up to date. Run a mock audit a few weeks ahead so any gaps surface while you still have time to fix them.
What are the most common reasons NDIS providers fail audits?
In our experience it is rarely about poor care. It is about gaps in evidence. The usual culprits are policies that exist on paper but are not followed day to day, incomplete participant records, expired or missing worker screening clearances, weak incident and complaints handling, and no clear record of continuous improvement. Good providers get caught out because the paperwork does not show what they actually do.
What happens if you fail an NDIS audit?
There is no simple pass or fail. Your approved quality auditor rates you against each NDIS Practice Standard from 0 to 3, where 1 is a minor non-conformity and 0 is a major one. A major non-conformity gives you three months to fix it, and your registration will not progress until it is resolved. A minor one gives you longer and you can keep progressing in the meantime. In both cases you respond with a corrective action plan that sets out the fix and how you will stop it recurring. A non-conformity is something to close out, not the end of your registration.
What is an NDIS internal audit checklist?
It is a short list you run yourself between external audits, so nothing drifts. Check that policies are current and version-controlled, participant files are complete with consent and plans on record, worker screening and training are up to date, incidents and complaints are logged and closed out, and improvements are documented. Running this each quarter means an external audit holds no surprises.
Frequently Asked Questions
Freddy Ortega is the founder of Careonyx and has held senior executive roles across NDIS, health, and community service organisations. He works with small-to-medium providers to strengthen governance, compliance and operational systems.
Book a Free Executive Clarity Call