---
title: NDIS Provider Audits and the Certification Chain
topic: ndis-provider-audits-certification
type: HG Reference
jurisdiction: Australia (national)
lastReviewed: 2026-09-05
publisher: Holistic Governance
publisherUrl: https://hg-au.com
canonicalUrl: https://hg-au.com/topics/ndis-provider-audits-certification.md
---


# NDIS Provider Audits and the Certification Chain

> NDIS provider registration in Australia is gated by third-party audits conducted by approved quality auditors that the provider itself finds, chooses and pays. The chain — provider → auditor → JAS-ANZ accreditation → NDIS Quality and Safeguards Commission approval — came under scrutiny in June 2026 when the Commission issued its first lifetime banning orders against a consultant and an auditor alleged to have colluded to register more than 200 providers on false or misleading information.

## How does NDIS provider registration and auditing work?

NDIS registration is administered by the **NDIS Quality and Safeguards Commission**. Registration itself is free, but a provider cannot register without passing an audit against the **NDIS Practice Standards**. There are two audit types:

- **Verification audit** — a lighter desktop review, for providers delivering lower-risk supports (typically those already regulated by another professional body).
- **Certification audit** — a fuller assessment (stage 1 document review and stage 2 on-site/interview assessment) for providers delivering higher-risk or more complex supports.

The provider must **find, choose and pay the auditor itself**. The Commission does not assign the auditor and does not set the price; providers are told to obtain quotes and compare. The commercial relationship runs directly between the provider and the auditor it hires.

## Who approves NDIS auditors?

Auditors are accredited by **JAS-ANZ** (the Joint Accreditation System of Australia and New Zealand), which operates the NDIS Approved Quality Auditors Scheme on the Commission's behalf, and are then approved by the Commission itself. Accreditation runs under the **NDIS (Approved Quality Auditors Scheme) Guidelines 2018**, which invoke **ISO/IEC 17065:2012** — the international standard for bodies certifying products, processes and services, whose requirements include the impartiality and independence of certification bodies.

As at 31 July 2026, just **seventeen certification bodies** audited the entire NDIS market (count as published in the companion analysis; check the Commission's [Find an auditor list](https://www.ndiscommission.gov.au/provider-registration/apply-registration/find-auditor) for the current number). Applications for new auditor accreditation have been **suspended since the response to the NDIS Review and the Disability Royal Commission**, with the pause remaining under review through the 2025–26 reform program.

**Audit cycle:** certification audits run on a three-year cycle — an initial certification audit, a mid-term audit (around the 18-month mark), and a recertification audit — while verification audits recur with each registration renewal. The certification audit assesses providers against the NDIS Practice Standards, including the **Governance and Operational Management module**: governance arrangements, risk management, quality management, and incident and complaints management — so the governing body's own arrangements are themselves within audit scope.

## What happened in June 2026?

On **17 June 2026** the Commission issued its **first lifetime banning orders against a consultant and an auditor**, alleged to have colluded to register more than 200 providers on false or misleading information. On the back of the investigation, the Commission refused 195 registration applications and revoked a further 40.

The orders are permanent and nationwide, and they are the first issued under new powers created by the **National Disability Insurance Scheme Amendment (Integrity and Safeguarding) Act 2026** (No. 41 of 2026; assent 8 April 2026). Before that Act, the Commission could ban only *providers* and *workers* — not the auditors and consultants who sit in the registration chain.

It was not the sector's first warning: as documented in the [companion analysis](https://hg-au.com/articles/ndis-banning-orders-certification-chain.html), an approved quality auditor had previously been sanctioned for selling consultancy to the very providers it was auditing — the same conflict, inside an accredited body.

## Why is the provider-paid audit model criticised?

The party being judged is the auditor's paying customer, and it chooses which auditor to hire. An auditor that fails too many clients loses them to one that does not. That commercial incentive is wired into the structure — the same lesson learned by other conformance industries (financial audit, building certification). The accreditation layer (ISO/IEC 17065 impartiality requirements, JAS-ANZ, Commission approval) is designed to manage this conflict, but in the 2026 matter the registrations were caught **after the fact by investigation and banning order**, not before by the impartiality controls.

The governance question this raises for any certification system: *can the independence in the chain be demonstrated — sampled, stress-tested, enforced — or is it only asserted on paper?*

## How does aged care's audit model differ?

Aged care providers do pay registration and audit fees under the **Aged Care Quality and Safety Commission (ACQSC)**'s cost-recovery arrangements — but they pay the **regulator**, not an auditor of their choosing. The ACQSC arranges the audit against the **Strengthened Aged Care Quality Standards** and supplies the assessor: the provider cannot select, shop between, or contract the body that audits it. The structural conflict at the heart of the NDIS matter — auditor selection by the audited party, with a direct commercial relationship between them — does not exist in the aged care registration pathway. (See the companion reference: [ACQS Accreditation Audit](https://hg-au.com/topics/acqs-accreditation-audit.md).)

This structural difference is why the two schemes should not be treated as equivalent when audit independence is the subject.

## Questions for boards and providers

1. If we rely on certification (our own, or a partner's), can we show the independence behind it was real — or only assumed?
2. Who advised us before our audit, and is that adviser connected to our auditor in any way?
3. If we operate in both NDIS and aged care, do we understand that the two schemes' audit independence models differ structurally?
4. If our auditor were sanctioned tomorrow, what would our exposure be — and do we know how the Commission would treat certifications that auditor issued?
5. Do our own internal audit and assurance arrangements demonstrate independence we could defend, applying the same standard we expect of external auditors?

## Sources

- NDIS Quality and Safeguards Commission — banning-order records (17 June 2026): https://www.ndiscommission.gov.au/node/1963244 and https://www.ndiscommission.gov.au/node/1963245
- Federal Register of Legislation — National Disability Insurance Scheme Amendment (Integrity and Safeguarding) Act 2026 (No. 41 of 2026): https://www.legislation.gov.au/C2026A00041
- NDIS Quality and Safeguards Commission — The quality audit process: https://www.ndiscommission.gov.au/provider-registration/apply-registration/types-audits
- NDIS Quality and Safeguards Commission — Information for quality auditors: https://www.ndiscommission.gov.au/provider-registration/apply-registration/information-quality-auditors
- Federal Register of Legislation — NDIS (Approved Quality Auditors Scheme) Guidelines 2018: https://www.legislation.gov.au/F2018N00114/2020-01-01
- JAS-ANZ — NDIS Approved Quality Auditors Scheme: https://www.jas-anz.org/national-disability-insurance-scheme-approved-quality-auditors-scheme
- Aged Care Quality and Safety Commission — Assessors: https://www.agedcarequality.gov.au/about-us/assessors
- Aged Care Quality and Safety Commission — Cost recovery: https://www.agedcarequality.gov.au/providers/provider-registration/cost-recovery
- JAS-ANZ — Suspension of applications for AQA Scheme accreditation: https://www.jasanz.org/stories/suspension-of-applications-for-accreditation-under-the-ndis-approved-quality-auditor-aqa-scheme
- Holistic Governance analysis: [The design flaw behind the NDIS's first auditor bans](https://hg-au.com/articles/ndis-banning-orders-certification-chain.html) — also published in Pearls and Irritations (24 August 2026): https://johnmenadue.com/post/2026/08/ndis-auditor-bans-shows-a-deeper-problem-with-provider-paid-audits/

---

*This reference document is maintained by [Holistic Governance](https://hg-au.com) as general information and decision support, not legal advice. Verify current legislative and regulator positions against the Federal Register of Legislation and the NDIS Commission before acting.*
