HomeBlog › Audit horror stories
NDIS Audits

5 NDIS Audit Horror Stories (and How to Avoid Them)

The providers in these stories didn't fail because they were careless. They failed because "we have a policy for that" is not the same thing as evidence an auditor can verify. Here's what tripped them up — and how to make sure it doesn't happen to you.

By AuditM8 · Updated July 2026 · 7 min read

NDIS certification isn't a paperwork exercise. At Stage 2, an auditor sits with your team, reads your records, and cross-checks three things: what your policy says, what your staff actually do, and what your participants actually experience. That cross-check is called evidence triangulation, and it's where most avoidable non-conformances come from. The gap is almost never "we didn't have a policy." It's "we couldn't prove the policy was real."

The five stories below are composites — drawn from the failure patterns that come up again and again in audit-prep guidance for SIL providers. Names and details are illustrative, but the mistakes are very real, and every one of them is preventable.

Story 1

The policy nobody had read

A provider bought a polished pack of policies before their audit — restrictive practices, incident management, the lot. Everything looked immaculate on paper. Then the auditor turned to a support worker and asked a simple question: "Walk me through what you'd do if you needed to use a restrictive practice with a participant." The worker hesitated. The answer didn't match the beautiful document. Non-conformance.

The lesson: Auditors don't just read your policies — they check whether your team lives them. A document your staff have never internalised is a liability, not evidence. Policies you actually wrote (or adapted to how your team really works) are far easier for staff to speak to under questioning than a stranger's template.
Story 2

The First Aid certificate that expired last month

A provider had every worker's checks on file — screening clearance, First Aid, CPR, the works. What they didn't have was a system watching the expiry dates. Two certificates had quietly lapsed in the weeks before the audit. Nobody noticed, because "we've got it on file" felt like the job was done. The auditor noticed. What should have been a clean file became a corrective action.

The lesson: A credential is only evidence while it's current. Worker-screening clearances began reaching their five-year expiry in 2026, and First Aid and CPR run on tight cycles. You need a live view of what's expiring and when — not a folder you check once a year.
Story 3

The incident log with holes in it

An incident had been handled well at the time — staff responded, the participant was safe, the family was informed. But months later, the paper trail told a messier story: the incident register, the participant's file, and the staff notes didn't quite line up. A date here, a missing follow-up action there. To an auditor sampling records, inconsistency reads as a gap in your incident-management system, even when the real-world response was fine.

The lesson: Good incident handling and good incident evidence are two different things. Records need to be complete, consistent across every system they touch, and closed out — because the auditor is checking the trail, not just the outcome.
Story 4

The overnight roster that didn't match the funding

A SIL provider ran a shared home with an overnight arrangement. Their rostering tool scheduled staff just fine — but nobody had checked the roster against the funded support ratio. On some nights the home was effectively understaffed against what participants' plans funded and required. That's a continuity-of-supports and safety question, and it's exactly the kind of thing that surfaces when an auditor samples your roster alongside participant plans.

The lesson: Rostering platforms schedule shifts; they don't check whether those shifts match funded ratios. Understaffing is a safety and audit risk, and overstaffing quietly burns money you weren't funded for. The roster is evidence too — and almost nobody checks it against the funding.
Story 5

The risk register frozen in time

A provider had a risk assessment for each participant — dated nearly two years earlier. In between, circumstances had changed and there had been an incident, but the register was never revisited. A risk document that never moves tells an auditor that risk isn't being actively managed. What looked like "we have a risk register" became "your risk management is a snapshot, not a practice."

The lesson: Compliance documents are living things. A risk register, a policy, a support plan — if the date never changes, that's a red flag. Reviews after incidents and at set intervals are part of the evidence that your system actually works.

The thread running through all five

None of these providers were negligent. They all had the policies. What they lacked was a way to prove, on the day, that the evidence behind those policies was real, current, and consistent. That's the whole game at Stage 2 — and it's the reason "audit-ready" has to mean verified evidence, not a tidy folder.

This is exactly why AuditM8 works the way it does: AI can read your documents and suggest what they are, but nothing counts until a human verifies it, and your readiness score is built only from that verified evidence. It tracks expiries, keeps your own policies, and even checks your roster against funded ratios — so the five stories above don't become yours.

Getting audit-ready isn't about buying nicer documents. It's about being able to stand behind the ones you have. Start early, keep your evidence current, and make sure your team can speak to the policies they actually follow.

These stories are illustrative composites based on commonly reported NDIS audit failure patterns, not accounts of specific providers. AuditM8 is an audit-preparation aid and does not guarantee any audit outcome. Always confirm current requirements with the NDIS Quality and Safeguards Commission (ndiscommission.gov.au) and your approved quality auditor.

Don't let a folder of good intentions fail your audit.

AuditM8 turns your staff certs and policies into a verified, audit-ready evidence pack — and keeps it current. Built for the 2026 SIL registration wave.

Start free trial