Certification vs Verification vs Mid-Term: What Each Audit Expects

The NDIS has three different audit types, and each one asks different questions.
Verification audits are for providers delivering lower-risk supports. It's a desktop review — no on-site visit. The auditor checks four areas: human resources, incident management, complaints management, and risk management. Usually finishes in 2–3 weeks.
Certification audits are for higher-risk supports like SIL, SDA, or specialist behaviour support. There are two stages: a desktop review (Stage 1) and an on-site visit (Stage 2) where auditors interview your staff and participants. Certification runs on a 3-year cycle.
Mid-term audits happen 18 months after your initial certification. They're shorter, but not light-touch. Auditors check anything flagged at your first audit, any changes since, and whether your continuous improvement is real or paper-only.
The best preparation for any of the three is the same: keep evidence current as you go, not in the six weeks before the auditor arrives.


