NDIS SIL Audit Checklist for Providers: Every Document and Record You Need

A SIL provider preparing for an audit needs one thing above all else: certainty about what an approved quality auditor will ask to see. This checklist follows the NDIS Commission’s own audit framework and the NDIS Practice Standards. It covers every document, record, and piece of evidence auditors assess across participant files, staff records, and governance systems, including the SIL-specific Practice Standards that apply from 1 July 2026.

What Type of Audit Does a SIL Provider Need?

The NDIS Commission runs five audit types. Knowing which one applies determines how you prepare. For the full picture on registration pathways, see Mandatory Registration for SIL.

Verification audit suits providers delivering lower-risk supports through a desktop review of paperwork only. No site visit occurs. Providers with existing professional regulation, such as AHPRA registration, typically follow this pathway.

Certification audit applies to higher-risk, more complex supports. SIL sits in this category. The process runs in two stages: Stage 1 is a desktop document review, and Stage 2 is an on-site visit with file review, service observation, and interviews. At least two auditors conduct a certification audit.

Mid-term audit happens roughly 18 months into a registration period, after an initial certification audit. It centres on governance and operational management, with at least one auditor involved. Read more on our Mid-Term Audit service page.

Condition audit can be triggered by the Commission at any point during registration if concerns arise. Out-of-cycle audit applies when a provider wants to add or change the supports it delivers mid-registration.

One rule matters most: if your registration groups mix verification and certification categories, you complete a certification audit overall. Your Initial Scope of Audit document from the Commission confirms which pathway applies to you.

The 7 Evidence Areas Auditors Assess

7 evidence areas auditors assess

Every certification audit maps to seven evidence areas under the Practice Standards, including the new SIL-specific domains introduced from 1 July 2026.

  • Governance and policies: Current within 12 months, version-controlled, with staff sign-off
  • Worker screening and HR records: Every worker’s screening status tracked with renewal dates
  • Incident management records: Real-time logs meeting the 24-hour serious incident notification rule
  • Participant records: Signed agreements, support plans, progress notes, evidence of choice and control
  • Complaints register: Populated log with investigation outcomes and system improvements
  • Risk register: A live document, not one written at registration and left untouched
  • Insurance and financial records: Current certificates and sustainability indicators

For SIL providers, auditors test these on paper and in practice. A policy that staff cannot describe during an interview counts as a non-conformance, even if the document itself is perfect.

Participant File Checklist

Participant File and Staff Records Checklist

Stage 2 of a certification audit includes file sampling. A missing document at this point becomes an audit finding, not a formality.

Required for Every Participant

SIL Service Agreement: Signed by the participant or guardian, covering supports, costs, rights, and complaints. Kept separate from the tenancy agreement and updated at every plan review.

Tenancy Agreement: A distinct legal document giving tenancy rights consistent with the relevant state Residential Tenancies Act. Any conflict of interest, such as the provider also owning the property, must be documented.

Individual Support Plan (ISP): Translates NDIS goals into daily support. Covers routine, communication, cultural needs, health summary, and known risks. Reviewed annually or when needs change.

Participant Risk Assessment: Rated by severity, with action plans for high and extreme risks. Reviewed annually and after any incident affecting the risk profile.

Communication Profile: Preferred methods, how the person expresses needs or distress, and any AAC or speech pathology input. Every worker must read this before their first unsupported shift.

Emergency Contact and Key People List, reviewed every six months. Consent Documentation for service delivery and information sharing, reviewed annually, with withdrawal rights recorded.

Personal Emergency Evacuation Plan (PEEP): Required for every SIL participant, reviewed every six months and after any change in mobility.

Health Care Summary: A single-page record of diagnoses, allergies, and medications.

Goals Progress Documentation: Ongoing evidence that supports are achieving reasonable and necessary outcomes.

Required When the Trigger Applies

A Behaviour Support Plan applies wherever behaviours of concern or regulated restrictive practices exist, developed by a registered practitioner and lodged with the Commission where relevant.

A Mealtime Management Plan applies to any eating, drinking, or swallowing difficulty, built by a Speech Pathologist, with staff trained before supporting meals.

Medication Management Plans and MARs apply wherever medication is prescribed, with a MAR completed for every dose. Seizure Management Plans apply to any epilepsy history, issued by a neurologist or GP.

A Mental Health Crisis Plan applies where psychosocial disability carries crisis risk, developed with the participant directly. High Intensity Support Plans cover PEG feeding, catheter care, tracheostomy, or ventilator support, and require separate HIDPA registration.

Restrictive Practice Authorisation must be obtained before use, with monthly Commission reporting. An expired authorisation used in practice is itself a reportable incident.

Guardianship and Decision-Making Documentation applies wherever an order or NDIS nominee exists. Expiry dates on time-limited orders need active tracking, not a one-off filing.

Staff Records Checklist

Missing staff records rank among the most common findings, and they surface fast during Stage 2.

Pre-Employment

A signed employment contract, right-to-work verification, and a current NDIS Worker Screening Check with tracked expiry. Add a Working With Children Check where the state requires it, two documented reference checks, and a signed Position Description.

Onboarding and Orientation

The free NDIS Orientation Module, completed before the first shift. A signed induction checklist, both Codes of Conduct signed annually, participant-specific plan acknowledgements, and a conflict of interest declaration reviewed yearly.

Training and Competency

Current First Aid and CPR certificates, CPR renewed annually and First Aid every three years. Manual handling and medication administration training where relevant, infection control training refreshed annually, and signed-off competency assessments for any high-intensity support, per procedure and per participant.

Ongoing Records

Monthly supervision notes, an annual formal review, and a running professional development log with dates and certificates attached.

Governance and Operational Documents

Beyond individual files, auditors assess the provider as a system. A structured NDIS Internal Audit is the recommended first step before facing a certification audit, since it tests these same areas ahead of time.

A documented governance framework with clear accountability and escalation paths. A live risk register, not a static one from registration day. A quality management system showing that incidents, complaints, and audit findings actually change practice.

Policies current within 12 months, each carrying a version number, review date, and staff acknowledgement. Outdated policies remain the single most common finding across registered providers. Add current insurance certificates covering public liability, professional indemnity, and workers compensation.

What Auditors Look For Beyond Documents

Stage 2 assessment runs on three methods, not one.

Documents are sampled directly from files, and gaps get flagged immediately. Interviews ask staff to describe, in their own words, how they’d handle an incident, a complaint, or a clinical procedure, auditors then check the answer against written policy. A policy nobody can explain is recorded as a non-conformance.

Observation covers service delivery itself: dignity, consent, communication, and whether the environment supports participant independence. The Commission has been clear that audits exist to confirm participants are safe, not to catch providers out. Keeping records current and treating the audit as a learning exercise produces the best outcome.

The 5 Most Common Non-Conformances in SIL Audits

The 5 Most common Non conformances in SIL audits

Outdated or missing policies: Not reviewed within 12 months, or no longer matching current operations after growth or new service groups.

Gaps in worker screening records: One expired check is enough to fail. With the first five-year screening checks now expiring in 2026, a live register with renewal alerts is essential.

Incomplete incident management: Incidents logged without follow-up, missed 24-hour notification windows, or no evidence that lessons were applied.

Lapsed restrictive practice authorisations: Using a restrictive practice after authorisation expires is a reportable incident on its own.

Staff who cannot describe key processes: The most consistent finding in certification audits. Briefing should build real understanding, not rehearsed answers.

Preparing Your SIL Audit, A Practical Timeline

3–4 months out: run an internal gap analysis against the Practice Standards, including the new SIL-specific domains. Check every worker’s screening expiry and review participant files for completeness.

1–2 months out: close every gap found, update policies, finish unsigned acknowledgements, renew expired checks. A structured NDIS Mock Audit at this stage tests whether staff are genuinely ready for interviews.

Final 2 weeks: organise evidence so an auditor can move through it easily. Brief frontline staff on describing incident management, complaints handling, and supported decision-making in their own words.

Get Audit-Ready With VCCG

VCCG works alongside SIL providers through every stage of audit preparation, from gap analysis to mock audits, with direct experience of what certification auditors expect in practice. This checklist is a starting point, a structured readiness review closes the gaps that matter before an auditor finds them.

Book a Free SIL Audit Readiness Review with VCCG

Frequently Asked Questions

Do SIL providers need a verification or certification audit?
SIL is classified as a higher-risk support, so SIL providers complete a certification audit, not a verification audit.

What is the difference between Stage 1 and Stage 2 of an NDIS certification audit?
Stage 1 is a desktop review of documentation. Stage 2 is an on-site visit involving file sampling, staff interviews, and observation of service delivery.

How long does a SIL provider have to fix non-conformances found at audit?
Timeframes are set by the auditor and the Commission based on the severity of the finding, so providers should confirm the exact deadline directly with their auditor.

How many auditors are required for a SIL certification audit?
At least two auditors are required for a certification audit, compared with one for a mid-term audit.

When is a SIL provider required to complete a mid-term audit?
Roughly 18 months into the registration period, following an initial certification audit, focused on governance and operational management.

Leave a Comment