HomeBlog › Audit do's and don'ts
NDIS Audits

NDIS Audit Do's and Don'ts: A SIL Provider's Field Guide

A plain-English checklist for SIL providers heading into certification. Not theory — the practical moves that separate a smooth audit from a scramble.

By AuditM8 · Updated July 2026 · 6 min read

Certification for SIL is the rigorous, two-stage audit pathway: a desktop review of your documents, then an on-site visit where the auditor interviews staff and participants and samples your records. Most of what decides the outcome is settled long before the auditor arrives — in how you prepared your evidence, your team, and your policies. Here's the field guide, grouped by when it matters.

Before you book

✓ Do

Book your auditor early. Two major approved auditors left the market in 2026, so wait times are tightening as the 1 October registration deadline approaches. Getting in the queue early is the single cheapest thing you can do.

✕ Don't

Don't wait for the deadline to force your hand. A rushed audit prep is where corners get cut and gaps appear. Time is the resource you can't buy back later.

✓ Do

Map your evidence to the Practice Standards that apply to you (including the SIL-specific module). Know which standard each document answers.

✕ Don't

Don't assume more documents is better. A pile of unmapped, generic policies is harder to defend than a lean set you actually use and understand.

Your policies and evidence

✓ Do

Keep your own policies — the ones your team actually follows — and make sure they reflect how you really operate. Adapt, don't just adopt.

✕ Don't

Don't drop in a template pack you've never operationalised. If your staff can't speak to it, a beautiful policy becomes a liability at Stage 2.

✓ Do

Treat "verified" as the bar. Evidence should be real, current, and confirmed by a human — not assumed because it's "on file somewhere."

✕ Don't

Don't let an AI tool silently "fix" your compliance evidence. An auditor's first question is "who verified this?" — and "the software did" is not a comfortable answer.

✓ Do

Track every credential's expiry — worker screening, First Aid, CPR, qualifications. Know what's lapsing and when, before the auditor does.

✕ Don't

Don't rely on an annual folder check. Clearances lapse quietly. A once-a-year glance is how expired certs slip through.

✓ Do

Keep incident and complaint records complete and consistent across every system they touch, and close out follow-up actions.

✕ Don't

Don't let the register and the participant file disagree. Inconsistency reads as a system gap, even when your real-world response was good.

✓ Do

Keep risk registers and support plans alive. Review them at set intervals and after incidents — dates that move show risk is actively managed.

✕ Don't

Don't let a risk register go stale. A document dated two years ago that never changed signals risk isn't being managed at all.

✓ Do

Check your roster against funded ratios — including overnights and sleepovers. Understaffing is a safety and audit risk; overstaffing quietly costs you.

✕ Don't

Don't assume your rostering tool has this covered. Scheduling software fills shifts; it doesn't check them against what's funded.

Your team

✓ Do

Prepare staff for the Stage 2 conversation. Make sure they can explain, in their own words, the policies they follow day to day.

✕ Don't

Don't coach staff to recite scripts. Auditors can tell. Genuine familiarity with your real processes beats a memorised line every time.

On the day

✓ Do

Be honest and organised. Know where each piece of evidence lives so you can produce it quickly. Calm and prepared beats defensive.

✕ Don't

Don't try to paper over a gap on the spot. If something's missing, a clear plan to fix it lands far better than an improvised cover-up.

Notice the pattern: almost every "do" is about evidence that's real, current, and consistent, and almost every "don't" is about assuming a document equals proof. That's the exact job AuditM8 was built for — verified evidence only, live expiry tracking, your own policies, and a roster-vs-funded-ratio check nothing else runs.

Certification rewards providers who can prove their systems are real. Prepare early, keep your evidence current, and back the policies you actually follow — and audit day becomes a conversation you're ready for, not one you're dreading.

This guide is general information based on commonly published NDIS audit-preparation guidance, not legal or compliance advice. AuditM8 is an audit-preparation aid and does not guarantee any audit outcome. Always confirm current requirements with the NDIS Quality and Safeguards Commission (ndiscommission.gov.au) and your approved quality auditor.

Turn "we have a policy for that" into evidence you can prove.

AuditM8 gives SIL providers a live, verified audit-readiness score — built for the 2026 registration wave.

Start free trial