Wholii logo black

How to prepare for an NDIS audit in 2026: the complete checklist

Guides, templates and real-world advice for NDIS providers, straight from our compliance team.


If your NDIS audit 2026 date is approaching, you are preparing under a different set of rules than last year. The Australian Government’s Securing the NDIS for Future Generations reforms landed in July 2026, and the compliance standards auditors expect have shifted significantly. New mandatory registration requirements, stricter documentation standards, and expanded audit obligations mean the bar is higher, and the NDIS Quality and Safeguards Commission knows it.

This is the complete NDIS audit 2026 checklist. Not a generic guide you could have found three years ago. The actual things auditors check, updated for where the scheme sits right now, with practical steps to make sure you are ready before the auditor walks in.

Start here at least eight weeks before your audit date.

What changed in 2026 and why it matters for your audit

The NDIS has been through significant reform before, but the 2026 changes are different in scale. Understanding what shifted helps you understand what auditors are now looking for.

Mandatory registration for SIL providers

From 1 July 2026, all providers delivering Supported Independent Living must be registered with the NDIS Quality and Safeguards Commission. Previously, registration was voluntary for most service types. That changed. If you deliver SIL supports without registration, you are not just at risk of a compliance issue, you risk losing your ability to operate altogether.

This matters for audits because new registrations trigger a Certification audit, not a lighter Verification audit. If you registered in 2026, expect scrutiny at the higher standard.

Stricter documentation requirements

The 2026 reforms tightened documentation expectations across all registered providers. Auditors now expect traceable, timestamped records, not just policies that exist on paper, but evidence they have been read, signed off, and followed. A policy in a folder is not enough. You need to show it was implemented.

Expanded audit obligations

Some providers who previously faced Verification audits now face full Certification audits as registration categories are tightened. If you support participants in higher-risk categories, expect deeper scrutiny of your staff credentials, incident management, and governance records.

The providers who will struggle in NDIS audit 2026 preparations are the ones still managing compliance reactively, pulling everything together in the two weeks before the auditor arrives. That approach was already fragile before 2026. Now it is a liability.

The complete NDIS audit checklist for 2026

Work through each area below. Give yourself time to identify gaps and fix them, not just locate them.

1. Staff credentials and worker screening

This is the first thing an auditor checks. Every time. Without exception.

  • NDIS Worker Screening Check current for every staff member
  • First Aid and CPR certificates within their validity period
  • Police checks completed within the required timeframe
  • Role-specific credentials current — medication administration, manual handling, behaviour support
  • Any lapsed credentials documented, with a record of how they were managed at the time

The 2026 risk: auditors are now checking credential status at the time of service delivery, not just at onboarding. A credential that lapsed six months ago while a staff member was actively rostered is a finding — even if it has since been renewed. Document everything.

2. Incident management records

Incident management is one of the highest-scrutiny areas in any NDIS audit. The Commission cross-references incident data, so inconsistencies get noticed.

  • All incidents logged within required timeframes from the date of occurrence
  • NDIS reportable incidents identified and submitted to the Commission within 24 hours
  • Full investigation documented for each reportable incident
  • Evidence of management review and sign-off on every investigation
  • Corrective actions recorded — and evidence they were followed through
  • Any incident-related staff communications retained

One thing auditors flag consistently: incident logs that look too clean. Zero incidents across a full year of service delivery with complex participants will prompt questions. Your records need to reflect reality.

3. Participant records

Every active participant needs a complete, current file. Auditors will pull records, and gaps are findings.

  • Current NDIS plan on file for every active participant
  • Service agreements signed and up to date
  • Support plans that reflect the participant’s current goals — not goals from two years ago
  • Consent documentation in place for records, sharing, and photography
  • Behaviour support plans authorised by a registered practitioner where required
  • Medication records current and accurate where medication is administered
  • Emergency contact information and health alerts up to date

4. Policies and procedures

Policies are not just documents — they are evidence of your governance. Auditors will check that they exist, that they are current, and that staff have actually read them.

  • All policies reviewed within the last 12 months
  • Version control visible on every document — date of last review, version number
  • Staff sign-off records showing each policy has been read and acknowledged, with timestamps
  • Complaints handling policy live and accessible to participants and their families
  • Whistleblower policy in place
  • Incident management policy aligned with current Commission requirements
  • Code of conduct signed by all staff

A policy dated 2022 with no review record is a red flag. Under the 2026 documentation requirements, you need to show active governance — not just documentation that once existed.

5. Staff training records

Training records need to be traceable to the individual. A completion certificate saved in a general folder is not enough — it needs to be linked to the staff member and timestamped.

  • NDIS Worker Orientation Module completed for all staff
  • Abuse and neglect training current
  • Any mandatory training specific to your registration category completed and documented
  • Records stored per individual staff member, not in a general file
  • Any training gaps documented with a remediation plan in writing and a completion date

6. Governance and quality management

This area catches providers who deliver good care but run a loose organisation. Auditors look for evidence that leadership is actively managing compliance — not just reacting to it.

  • Board or management meeting minutes showing compliance is a standing agenda item
  • Internal audit or self-assessment completed within the last 12 months
  • Complaints register with evidence of resolution for every complaint received
  • Risk register updated and reviewed by management
  • Continuous improvement records — what you identified and what you did about it

7. Your audit evidence pack

When the auditor arrives — or joins remotely — you need to produce everything above, organised by NDIS Practice Standard, with an index so they can find what they need without asking you.

For a remote audit, you will also need a secure way to share read-only access to documents. Emailing 47 files is not a system.

This is where most providers lose hours — or days — they do not have. The organisations that pass quickly are the ones where the evidence pack assembles itself, because compliance was being tracked every day, not just before the audit.

The real gap between passing and failing in 2026

Most NDIS audit failures in 2026 will not be because providers are delivering bad care. They will fail because they cannot prove the care they deliver.

The evidence was not recorded at the time. Or it was recorded somewhere — a notebook, a shared drive, a WhatsApp group — and cannot be located or verified. Or a credential lapsed and nobody noticed until the auditor pointed it out.

The providers who pass first time, with zero findings, are the ones where compliance is not a project they do before an audit. It is how they operate. Credentials tracked automatically. Incidents logged the moment they happen on a phone. Policies read and signed off digitally with a timestamp. By audit day, there is nothing to scramble for — because it was all already done.

That is not an accident. It is a system.

How Wholii makes your NDIS audit 2026 checklist automatic

Wholii is built specifically for registered NDIS providers. Every item on this checklist is either tracked in real time or automated inside the platform.

Credentials and documents

Wholii tracks every credential across your whole team and fires expiry alerts before anything lapses. Your entire team’s credential status is on one dashboard, updated in real time. You see gaps before they become findings.

Incident reporting

Staff speak their incident report into their phone. Wholii transcribes it, timestamps it, structures it, and automatically identifies NDIS reportable incidents — complete with a 24-hour countdown timer to the reporting deadline. No one misses the window. Managers are notified immediately. The investigation tracker runs through to sign-off.

Participant records

NDIS plans, service agreements, support notes, and consent documents are all stored in the participant’s profile — searchable, linked, and current. No digging through folders. No re-entering data.

Policy sign-offs and training

Staff acknowledge policies digitally from any device. Every sign-off is timestamped and linked to the individual. Training records sit in the staff profile. When an auditor asks for evidence, it is there.

Audit trail

Every action in Wholii is logged automatically — who did what, when, on which participant or document. Your audit trail builds itself every day. When your NDIS audit 2026 date arrives, you are not assembling an evidence pack from scratch. You are exporting what already exists.

The providers who dread audit day are the ones managing all of this across spreadsheets and shared drives. With Wholii, you do not have to.

Get audit-ready before the pressure hits

The best time to prepare for your NDIS audit 2026 is not two weeks before the auditor arrives. It is now, when you have time to find the gaps and fix them — not just find them.

Book a free Wholii demo and see what your compliance looks like when it runs in the background every day. Most providers are set up in under 30 minutes.

[ Book a Free Demo → ]

Table Of Contents

More NDIS News & Insights

Your team deserves compliance that works for them.

Join teams who’ve transformed their compliance culture, without the chaos, the chasing, or the crunch.
  • No credit card
  • Quick 30 min demo