Skip to content
GovernanceNDIS

Before the NDIS audit notice arrives: a 12-point governance health check for providers

The questions every NDIS CEO should be able to answer before the Commission's audit notice lands - covering board oversight, policy currency, incident management and worker screening.

Ashley LythgoFounder & Director
  • 12 April 2026
  • 7 min read

Most providers don't fail an NDIS audit because the work isn't being done. They fail because the evidence isn't where the auditor expects to find it - and the gap between the work and the paper trail only ever shows up the week the Commission writes.

If you sit on the executive of an NDIS provider, this is the moment to walk the building with your governance hat on, not your operations one. Twelve questions. If you can answer all of them with a clear yes and the document to prove it, you're in better shape than most.

01 - Board oversight

Does your board receive a structured compliance dashboard at every meeting, or a verbal update? Boards that govern by exception need a baseline first. The dashboard should cover incident trends, complaints, audit findings, and worker screening status at minimum - and it should be archived in the board pack alongside the minutes.

02 - Policy currency

Pull the three policies most relevant to your highest-risk service. Check the version date. If any of them are older than 24 months - or older than the last NDIS Practice Standards revision - that's a red flag the auditor will find before you do.

03 - Worker screening

Can your administration team produce, within five minutes, a current NDIS Worker Screening Check clearance for every worker who provided supports in the last 90 days? If the answer involves spreadsheets and follow-up emails, the system isn't audit-ready.

04 - Incident management

Open your incident register. Look at the most recent reportable incident. Is the timeline from notification to closure documented? Are corrective actions tracked to completion, with evidence? An auditor doesn't want the story - they want the trail.

05 - Restrictive practices

If your services include any environmental, mechanical, chemical or physical restraint, you should know exactly how many participants are subject to one, the behaviour support plan that authorises it, and the consent on file. This is one of the highest-risk areas of the entire scheme.

06 - Complaints

Every complaint received, how it was acknowledged, how it was resolved, what changed as a result. The Commission will sample. Your records need to read like a story, not a list of tickets.

07 - Worker capability

Mandatory training matrix, induction records, refresher cycles. Not the LMS dashboard - the actual evidence that the work has been completed by the people doing the work today.

08 - Service agreements

Participant service agreements should be current, signed, and in plain English. The auditor will spot-check a sample. If the signature is older than 18 months and circumstances have changed, the document is stale.

09 - Conflict of interest

A live register, signed declarations at executive and board level, and a documented process for managing conflicts when they arise. Not optional, and not paperwork - it's a real risk control.

10 - Financial sustainability

The Commission isn't auditing your books, but they will ask about provider viability. A current cash-flow forecast, accounts receivable ageing, and a known break-even point are baseline.

11 - Continuous improvement

A registered provider needs a real continuous improvement plan with owners, due dates and evidence of progress. Last year's plan, unchanged, is a red flag.

12 - The walk-through

Finally - and this is the test most providers skip - pretend you're the auditor and walk through your own service. Ask the same questions out loud. See what your team produces. The gap between what you think exists and what they can find under pressure is where the audit risk lives.

Most providers don't fail an audit because the work isn't being done. They fail because the evidence isn't where the auditor expects to find it.
Ashley Lythgo

What to do with the score

Red items need an owner and a 30-day plan. Amber items need a 90-day plan. Green items still need verification on a 12-month cycle - green today doesn't mean green forever. If your red column is longer than three items, you don't have a paperwork problem. You have a governance maturity problem. That's a different conversation, and it's the one we usually start with.

Ashley Lythgo portrait
Written by

Ashley Lythgo

Director & Primary Consultant

Registered Nurse with an MBA (Governance). Senior executive experience across NDIS, aged care and community services.

Read Ashley’s profile
From article to action

Want to talk about your version of this?

Thirty minutes, free. We’ll work through where you are, where the gaps are, and what a sensible next step looks like.