NDIS certification isn't a paperwork exercise. At Stage 2, an auditor sits with your team, reads your records, and cross-checks three things: what your policy says, what your staff actually do, and what your participants actually experience. That cross-check is called evidence triangulation, and it's where most avoidable non-conformances come from. The gap is almost never "we didn't have a policy." It's "we couldn't prove the policy was real."
The five stories below are composites — drawn from the failure patterns that come up again and again in audit-prep guidance for SIL providers. Names and details are illustrative, but the mistakes are very real, and every one of them is preventable.
The policy nobody had read
A provider bought a polished pack of policies before their audit — restrictive practices, incident management, the lot. Everything looked immaculate on paper. Then the auditor turned to a support worker and asked a simple question: "Walk me through what you'd do if you needed to use a restrictive practice with a participant." The worker hesitated. The answer didn't match the beautiful document. Non-conformance.
The First Aid certificate that expired last month
A provider had every worker's checks on file — screening clearance, First Aid, CPR, the works. What they didn't have was a system watching the expiry dates. Two certificates had quietly lapsed in the weeks before the audit. Nobody noticed, because "we've got it on file" felt like the job was done. The auditor noticed. What should have been a clean file became a corrective action.
The incident log with holes in it
An incident had been handled well at the time — staff responded, the participant was safe, the family was informed. But months later, the paper trail told a messier story: the incident register, the participant's file, and the staff notes didn't quite line up. A date here, a missing follow-up action there. To an auditor sampling records, inconsistency reads as a gap in your incident-management system, even when the real-world response was fine.
The overnight roster that didn't match the funding
A SIL provider ran a shared home with an overnight arrangement. Their rostering tool scheduled staff just fine — but nobody had checked the roster against the funded support ratio. On some nights the home was effectively understaffed against what participants' plans funded and required. That's a continuity-of-supports and safety question, and it's exactly the kind of thing that surfaces when an auditor samples your roster alongside participant plans.
The risk register frozen in time
A provider had a risk assessment for each participant — dated nearly two years earlier. In between, circumstances had changed and there had been an incident, but the register was never revisited. A risk document that never moves tells an auditor that risk isn't being actively managed. What looked like "we have a risk register" became "your risk management is a snapshot, not a practice."
The thread running through all five
None of these providers were negligent. They all had the policies. What they lacked was a way to prove, on the day, that the evidence behind those policies was real, current, and consistent. That's the whole game at Stage 2 — and it's the reason "audit-ready" has to mean verified evidence, not a tidy folder.
Getting audit-ready isn't about buying nicer documents. It's about being able to stand behind the ones you have. Start early, keep your evidence current, and make sure your team can speak to the policies they actually follow.