NDIS mid-term audit: what it is, and a preparation checklist
Eighteen months into a three-year registration, providers who did a certification audit are audited again. This page gives the Commission's definition, what its own account of an audit day says the auditor looks for, and a checklist built from that account rather than from guesswork.
Published 25 September 2026. Every statement below was read at its own source on that date; the numbered links take you there.
What the Commission says a mid-term audit is
Among the types of audit the Commission lists, a mid-term audit is for providers who initially completed a certification audit, and is completed 18 months into your registration period.[1] Registration is generally for three years, so the mid-term audit sits at the halfway point.[2]
What the auditor looks for
The Commission's description of an audit day is the best preparation brief there is. The focus moves quickly from what your policies say to what actually happens: the auditor asks how you know participants are safe, whether you can show incidents managed from start to finish, and how leadership monitors risk and quality, and wants real examples such as incident reports, complaints records, training logs and supervision notes. Staff files are sampled for worker screening clearances, qualifications, induction records and evidence of ongoing training and supervision. Participants are interviewed privately about feeling safe, being listened to and knowing how to complain. Service delivery is observed for communication, consent and whether supports match the plan. At the closing meeting a non-conformity means something needs correcting or strengthening, with a timeframe to do it, not a failure.[1]
The preparation checklist
Each item below is an evidence type named in the Commission's account; the second column is the record we would expect to hold it.
Download this checklist as a Word file (free)
- Incidents, start to finish: the incident register with dates, actions, outcomes and, where they applied, reportable incident notifications; one incident traced end to end.[1]
- Complaints: the complaints register with acknowledgement, action, outcome and the participant's view, and what changed as a result.[1]
- Leadership monitoring of risk and quality: meeting minutes, the risk register with review dates, and incident and complaint trend reports seen by leadership.[1]
- Staff files, sampled: worker screening clearance, qualifications, induction record, training log and supervision notes for each sampled worker.[1]
- Participant records against plans: support plans, consent records and notes showing supports delivered as planned, ready for the participants the auditor will interview.[1]
- Corrective actions from the last audit: each earlier non-conformity, what was corrected or strengthened, and the evidence that it took, within the timeframe given.[1] Our corrective action template is written for exactly this.
- Key personnel and conditions: any change to key personnel notified to the Commission, and every condition on your certificate met.[2]
The Stage 1 evidence checklist lists the documents behind each of these, and the policy versus evidence guide shows what a good record looks like.
Other audits during the registration period
A condition audit can be required by the Commission during the registration period, and an out-of-cycle audit may be needed when you want to change the supports and services you provide.[1] Adding a group later therefore has an audit attached; scope it with the registration groups list first.
Questions providers are asking
Who has a mid-term audit?
Providers who initially completed a certification audit; it is completed 18 months into the registration period.[1]
Do verification providers have one?
The Commission's list of audit types ties the mid-term audit to providers who completed a certification audit; verification providers are not named.[1]
What else can happen between audits?
A condition audit can be required by the Commission during the registration period, and an out-of-cycle audit may be needed if you change your supports and services.[1]
What does an auditor look for on site?
The Commission's own description: real examples behind each policy, such as incident reports, complaints records, training logs and supervision notes; sampled staff files for screening, qualifications, induction, training and supervision; private participant interviews; and observation of supports.[1]
Is a non-conformity a fail?
The Commission says a non-conformity does not mean you have failed; it means something needs to be corrected or strengthened, and you are given a timeframe to address it.[1]
What if my key personnel changed since registration?
Registered providers must inform the Commission of changes to key personnel during the registration period, and of events that might affect their suitability.[2]
Sources
Each numbered line is the page a statement above was taken from, with the date we opened it. Read the source before you act; we summarise, the source decides.
- The quality audit process, NDIS Commission, opened 25 September 2026.
- About registration, NDIS Commission, last updated 7 August 2026, opened 25 September 2026.
- Apply for registration, NDIS Quality and Safeguards Commission, last updated 30 June 2026, opened 25 September 2026.