Becoming an NDIS provider? Get audit-ready in days, not months, with our proven system

NDIS verification audit vs certification audit: which one applies to you

An NDIS verification audit is a desktop audit only: one stage, off-site, reviewing your documentation. It applies to providers who deliver only low-risk, low-complexity supports. A certification audit runs two stages: that same desktop audit, plus an on-site stage with a site inspection and interviews with your staff and participants. Which audit you face is set by the supports you apply to deliver, not by choice.
NDIS verification audit and certification audit compared side by side

Written by the Provider360 team. Provider360 is Australia’s leading done-for-you NDIS registration and compliance solution, supporting 3,000+ disability service providers nationally. Verification or certification is the first question almost every provider brings us.

Key takeaways

  • One high-risk support in your scope puts the whole registration on the certification pathway.
  • Certification adds a second, on-site stage: site inspection and interviews. Verification has no site visit and no interviews.
  • Certification providers also sit a mid-term audit by 18 months. Verification providers do not.

What is an NDIS verification audit, and what is a certification audit?

An NDIS verification audit is an assessment by an approved quality auditor conducted as a desktop audit: the auditor reviews your documentation against the applicable standard, off-site. A certification audit is an assessment that adds two things to that desktop audit: an inspection of the sites, facilities, equipment and services used to deliver supports, and interviews with relevant persons, including your key personnel and the people receiving supports.

Read those two definitions side by side. Certification is not a stricter version of verification: it is the verification desktop audit plus a site inspection plus interviews. Everything in the smaller audit is inside the bigger one.

The word that decides which one you get is “only”. The Commission’s rule is that verification applies to providers who only deliver low-risk or low-complexity supports and services, while certification applies to providers delivering one or more high-risk or complex supports. One certification-level support anywhere in your scope moves the entire registration across. That single word carries the whole comparison, and it is what providers most often get wrong when they scope an application.

Did the 2026 reforms change the two audit pathways?

No. The 2026 reforms changed who must register and which module they are assessed against, not how the two audits work. Mandatory registration for supported independent living and NDIS digital platform providers, the new registration groups, and the new SIL Practice Standards all sit on top of the same two-pathway framework.

And the framework is current: the Commission refreshed its quality audit process guidance on 20 July 2026 with the two-pathway rule intact, and the Provider Registration Rules were compiled on 1 July 2026 with the section 4 and section 5 definitions unchanged in substance. If you are reading an older explanation that describes surveillance audits in your first and second calendar years, it is out of date: the current guidelines no longer contain that wording.

Which NDIS Practice Standards will you be assessed against?

Verification and certification are defined as two assessment methods in the NDIS (Provider Registration and Practice Standards) Rules 2018, at section 4 and section 5(1) of compilation F2026C00527 (1 July 2026). The audits themselves are conducted under the NDIS (Approved Quality Auditors Scheme) Guidelines 2018, compilation F2025C01100, Compilation No. 5 (15 November 2025), where section 12 states that a verification audit includes the activities of a stage one audit, and section 13 states that a certification audit comprises both a stage one audit and a stage two audit.

That split decides which standards you are assessed against:

  • Schedule 8 of the Provider Registration Rules applies to a verification audit.
  • Schedules 1 to 7 apply to a certification audit.
  • Part 2 of the Practice Standards (Worker Screening) Rules 2018 applies to both.

Nor is the audit the same size for every provider on a pathway. Certification assessment must be proportionate to the size of the provider, the scale of its operations including geographical area and number of locations, and the scope and complexity of the supports delivered, and it may be conducted by an appropriate sampling method. That is why two providers on the same pathway can face very different audit effort.

Only approved quality auditors can assess you. They are accredited by JASANZ, the Joint Accreditation Scheme for Australia and New Zealand.

Which audit pathway applies to you?

Your pathway follows the registration groups you apply for, and the Commission confirms it in your Initial scope of audit. Our page on NDIS registration groups maps every group to the audit it triggers. Four situations cover almost every provider:

If you deliver only low-risk supports, then you are on the verification pathway. Therapy supports, plan management, assistive equipment, home modifications and similar sit here. A desktop audit, no site visit, no participant interviews. Part of the rationale is oversight that already exists: as the Commission puts it, many of these providers have already met the requirements of professional regulation, for example through the Australian Health Practitioner Regulation Agency or another professional body.

If you deliver any core or high-risk support, then you are on the certification pathway. Personal care, assistance with daily life, community participation, supported independent living and behaviour support all sit here. Two stages, site inspection and interviews included. Supported independent living is always certification, and it now carries mandatory registration: see SIL registration and transition pathways.

If you deliver a mix of both, then certification governs the whole registration, and you sit one audit rather than two. This is the fork that costs providers the most confusion. You are assessed against Schedules 1 to 7 instead of Schedule 8, and certification satisfies verification: where compliance with a standard must be assessed using verification, that requirement is met if compliance is assessed using certification. So your low-risk services are not audited separately, and they are not left out either: they are covered by the wider audit you were always going to sit.

If you are not sure, or your scope is still moving, then get the scope settled before you commit to anything. The Initial scope of audit is authoritative, but it arrives after you apply, which is too late to be your planning tool. The practical interim step is a scope assessment: work out which registration groups you actually need, and the pathway falls out of it. Our free NDIS Registration Roadmap does that in about 60 seconds and tells you which pathway your scope lands on.

NDIS verification audit vs certification audit: the full comparison

Every row is sourced. Read the first row first: the stage structure is the difference that holds in every case, and everything else follows from it.

 Verification auditCertification audit
Audit stages1: desktop audit only2: desktop audit plus on-site audit
Who it applies toProviders delivering only low-risk, low-complexity supportsProviders delivering one or more high-risk or complex supports
Legal definitionDesktop audit and documentation reviewDesktop audit, plus site inspection, plus interviews with key personnel and participants
Where it happensOff-siteStage one off-site; stage two on-site
Site inspectionNoYes
Interviews with staff and participantsNoYes, with opt-out sampling of participants
Practice Standards assessedSchedule 8Schedules 1 to 7
Worker screening standardsYes, Part 2 Worker Screening RulesYes, Part 2 Worker Screening Rules
Gap between stagesNot applicableStage two should commence within 3 months of stage one
Audit report due to the CommissionUp to 14 days after completionUp to 28 days after completion
Mid-term auditNoYes, commencing by 18 months, using certification
RenewalVerification audit in year 3, no earlier than 6 months before renewalRecertification in year 3, no earlier than 6 months before renewal
Commission decision, median calendar days (new applications, Jan to Mar 2026)49 days34 days
Typical end to end, in Provider360’s experience4 to 6 months8 to 12 months
Minimum audit teamAt least 1 auditor; no audit team leader requiredAt least 2 auditors, subject to the Commissioner’s exceptional-circumstances exemption

Those two pathways cover your initial registration audit, but they are not the only audits in the system. There are four others, each with its own trigger: a provisional audit assesses readiness when you have no participants yet; a mid-term audit falls due by 18 months on the certification pathway; a condition audit can be imposed by the Commissioner, including after a provisional audit or an unresolved minor non-conformity; and an out of cycle audit is triggered when you expand your scope mid-cycle.

What does certification actually add after the desktop audit?

A whole second audit. Stage two should commence within three months of stage one, and it is the stage verification providers never sit: the auditor inspects the sites, facilities and equipment used to deliver supports, and interviews your key personnel and the people receiving them. Participants are included on an opt-out basis, so you have to notify them, respect and document any decision to opt out, and tell the auditor.

What the auditor is testing changes in stage two as well. In the Commission’s own words, the focus moves from what your policies say to what actually happens in practice: auditors ask how you know participants are safe, and to be shown how incidents are managed from start to finish, wanting real incident reports, complaints records, training logs and supervision notes rather than the policy on its own. Closing that distance before audit day is what our pre-audit evidence review is for: it catches an average of 16 gaps before the auditor sees them.

The obligations that follow are heavier too. The audit report is due to the Commission within 28 days on certification against 14 on verification. A mid-term audit must commence no later than 18 months after your registration period begins, carried out using certification, with narrow exclusions: providers delivering only early intervention supports for early childhood, only specialist disability accommodation, or transitioned providers. Expanding your registration groups mid-cycle triggers an out of cycle audit. And a major non-conformity, a rating of 0, gives you three months to fix it, with registration not progressing until it is addressed.

One number cuts against the expected story, and it is worth stating plainly. The Commission publishes median calendar days from the auditor submitting the audit recommendation to the registration decision. For new applications in January to March 2026, certification decisions took a median of 34 days and verification decisions 49. Certification was the faster of the two in that step. Three caveats matter: this measures one step only, not preparation, application, auditor scheduling or the audit itself, so it is not how long registration takes; these are medians, so half of applications took longer; and the figures move quarter to quarter. The honest reading is that the pathway difference lives in the audit, not in the Commission’s decision window.

End to end, in our own experience across 3,000+ providers, verification registrations typically run 4 to 6 months and certification 8 to 12. Those are Provider360’s observed timelines, not Commission-published figures. The documentation load tracks the same gap: a verification-scope provider works from 70+ documents, a Core Module certification provider from 120+. What the audit costs is a separate question with real figures behind it, and we answer it in what NDIS registration costs in 2026.

Get the documentation your pathway is audited against

We are not an approved quality auditor. We prepare the documentation your audit tests: Verification Platinum, 70+ documents for verification scope; Certification Platinum (Core Module), 120+ for core supports. Both include your application submitted for you, auditor recommendations, a pre-audit evidence review and our 100% money-back guarantee.

Verification Platinum Package → Certification Platinum Package (Core Module) →

NDIS verification audit and certification questions

How often do NDIS audits happen?

Every three years, with one extra audit in the middle on the certification pathway. Certification starts with the two-stage initial audit, stage one a desktop audit and stage two on-site, before registration is granted. A mid-term audit then commences by the 18-month mark, and a full re-registration audit falls due in year three, no earlier than six months before your registration expires. Verification is simpler: the desktop audit at registration, then the renewal audit in year three. There is no mid-term audit on the verification pathway.

What is the difference between a certification audit and a provisional audit?

A provisional audit assesses your readiness to start delivering supports, with no participant interviews, while a certification audit assesses services you are already delivering and includes interviews with current staff and participants. Provisional applies when you are seeking registration but have no participants yet. Both assess compliance with the NDIS Practice Standards, and a provisional audit can be followed by a condition audit once you are operating.

What documents do I need for my audit?

It depends on your pathway, and the two lists are built differently. On verification, the requirements attach to qualifications and professional memberships, and the Commission publishes the specific list in its Qualification and Professional Associations Required Documentation Guide, hosted on the Verification Module page. On certification, you are evidencing the Core Module and any supplementary modules across Schedules 1 to 7, which means policies, procedures, registers and the records that show them working. The distinction that trips people up is that certification auditors want evidence of practice, not just the documents themselves.

Who chooses my auditor, and when should I get quotes?

You do, and the best time is after your application is submitted. Provider360 is not an NDIS approved quality auditor and cannot quote or conduct the formal audit. What we do is recommend trusted approved quality auditors at no extra cost and gather competitive quotes for you. The reason to wait until after you apply is the Initial scope of audit: it is what auditors quote against, so a quote requested before it exists is a guess.

Related Articles

The three clocks that decide how long it takes to become an NDIS provider: preparation, audit and Commission decision

How long does it take to become an NDIS provider? The three clocks, stage by stage

How long does it take to become an NDIS provider? There is no single number, because registration is not one clock but three, running in sequence: your preparation, your auditor's queue, and the NDIS Commission's decision. Only the third is officially measured: a median of 36 days for new applications in January to March 2026. End to end, we see 4 to 6 months for verification and 8 to 12 months for certification.

Provider360 guide to the 38 NDIS registration groups and the audit pathway each one triggers

NDIS registration groups: all 38, and the audit each one triggers

There are 38 NDIS registration groups, numbered 0101 to 0138. A registration group is the class of support you are approved to deliver, and the mix you pick decides your audit: 23 of the 38 sit on the verification pathway and 15 on certification. Groups 0137 and 0138 were added to the Provider Registration Rules on 1 July 2026.

Provider reviewing the NDIS Pricing Schedule 2026-27 price limit changes

NDIS Pricing Schedule 2026-27: what changed and who wins

The NDIS Pricing Schedule 2026-27 is the NDIA's new pricing document, replacing the Pricing Arrangements and Price Limits (PAPL) from 1 July 2026. Disability support worker price limits rose 4.8% to $73.58 an hour, psychology rose 8.6% to $252.99, and dietetics, exercise physiology and the Other Professional rate were cut. Support coordination and plan management are frozen, and the Annual Pricing Review flags a 10% cut for unregistered community-participation providers from 1 January 2027.

How much does it cost to become an NDIS registered provider — full 2026 breakdown

NDIS provider registration cost in 2026 depends on the pathway your services require: Verification (low-risk) or Certification (high-risk core, with or without specialised services). First-year costs sit in three categories: Approved Quality Auditor fee, insurance, and preparation (documentation plus audit-readiness services). The NDIS Commission itself charges no registration fee. With the 1 July 2026 SIL deadline tightening auditor capacity, the cost of starting later includes the cost of the queue.

×

Thank you! Your message has been sent.