What happens after registration: Your ongoing NDIS Practice Standards obligations

Last updated: June 2026  ·  Reading time: 6 minutes

Summary

  • This article is for Certification-pathway providers: those whose registration includes one or more higher-risk supports assessed against the Core Module of the NDIS Practice Standards. It explains what the Practice Standards require on an ongoing basis under each of the four Core Module standards, what the mid-term surveillance audit at 18 months assesses and how to approach it, and how to manage your compliance system when the standards change.

Your three-year registration cycle in full

Understanding your registration cycle is the foundation of ongoing compliance planning. Certification providers face five possible audit touchpoints across their registration period post-initial certification, not one.

Initial certification audit

Before registration is granted

All certification pathway providers

Full assessment against all applicable Practice Standards: documents, on-site, staff and participant interviews, and file reviews.

Registration date

Set when the Commission approves your registration

All registered providers

This is the date the NDIS Commission approves your registration, and the reference point from which all audit timing (the 18-month mid-term and the three-year renewal) is calculated, rather than the date your initial audit was completed.

Remaining elements (conditional) audit

Within 3 months of commencing service delivery; or as part of the mid-term audit if service delivery begins 12–18 months after registration

Providers granted provisional certification where some standards could not be assessed at the initial audit (typically no active participants yet)

Only the outstanding elements of certification not witnessed at the initial audit, assessed by an approved quality auditor once real service delivery is underway. Imposed as a condition of registration under section 73G of the NDIS Act.

Mid-term audit (surveillance)

Commencing no later than 18 months after registration approval date

All certification providers except those registered solely for Specialist Disability Accommodation (SDA)

Primarily Governance and Operational Management (Standard 2); corrective actions from the initial audit; any additional standards the Commission specifies; real-time operational evidence.

Condition audit

Any time during your registration period, triggered by the Commission

Any registered provider where the Commission identifies a need for follow-up.

Imposed as an additional condition of registration under section 73G of the NDIS Act and focused on the specific area of concern; may cover all standards or a single module. A common example is a condition requiring a further audit by an approved quality auditor following a serious complaint, a pattern of reportable incidents, or another identified compliance concern.

Out-of-cycle audit

When you apply to add or change registration groups mid-period

Providers seeking to vary their registration scope

Covers the new registration groups being added

Renewal audit

Commencing before registration expiry (allow 6 months minimum)

All registered providers

Full re-assessment against all applicable Practice Standards, including any updated or new standards in force at renewal

Your registration period and all audit timing calculations run from the date the NDIS Commission approved your registration, not the date your initial audit was completed. This matters because the Commission’s processing time after audit submission can be substantial, sometimes several months. If your audit was completed in February but the Commission issued your registration in April, your three-year period and 18-month surveillance date are calculated from April.

Verification providers do not undergo mid-term audits. Their registration cycle is simpler: initial verification, then a renewal verification at three years. However, the Commission can conduct a condition audit of any registered provider at any time, regardless of pathway.

What the Practice Standards require on an ongoing basis

The Core Module’s four standards — Rights and Responsibilities, Governance and Operational Management, Provision of Supports, and Support Provision Environment — are not met once at certification and then set aside. Each carries obligations that must keep operating in practice for the life of your registration. The shift from initial certification to ongoing compliance is a shift from holding the right documents to demonstrating that your systems are actually working day to day.

In broad terms: Rights and Responsibilities requires that participants are kept informed of their rights, that consent stays current, and that dignity of risk is weighed against duty of care; Governance and Operational Management requires that risk, financial and workforce systems are actively maintained, that internal review continues between external audits, and that changes to key personnel are notified to the Commission within 14 calendar days; Provision of Supports requires that support planning, incident management and complaints handling are live and evidenced; and Support Provision Environment requires that service locations, equipment and emergency procedures stay safe and current as your operations change.

The points at which providers most commonly drift are consistent across all four standards: documentation that becomes static after registration, registers that stop being maintained, training that lapses for staff who joined later, and operational changes — new locations, new participants, new key personnel — that are never reflected in the compliance system.

These are illustrations of how the standards apply on an ongoing basis, not an exhaustive list of what matters. Compliance is assessed against the full text of the NDIS Practice Standards and their indicators, and an auditor may examine any part of them. The common thread is the same throughout: at the mid-term and renewal audits, auditors look for evidence that your systems are operating in practice — current records, active registers, and decisions that can be traced — not simply that a policy exists.

The mid-term audit at 18 months

The mid-term audit is the mid-cycle checkpoint for certification providers. It is not a lighter re-run of your initial certification: it checks whether your systems are operating in practice and whether any non-conformances from your initial certification have been resolved and sustained. It is conducted on-site, with staff interviews, a review of participant files, and observation of your operational environment.

It must commence no later than 18 months after your registration approval date, so engage your AQA around the 12-to-15-month mark; auditor availability is tight given the mandatory registration expansion. If non-conformances are identified, you submit a corrective action plan within 7 days of the audit, resolving minor non-conformances within 18 months and major ones within 3 months.

When the Practice Standards change

The NDIS Practice Standards are not static. The NDIS Commission reviews and updates them periodically, and in 2026 a comprehensive review is under way that is expected to result in material changes to the standards framework. New SIL-specific Practice Standards will take effect from 1 July 2026. Further changes affecting all registered providers are expected to follow as the Commission’s Quality Framework review concludes.

Your obligation as a registered provider is to maintain compliance with the current standards, not the standards that were in force when you registered. When the Commission updates the Practice Standards, you must review your compliance system against the new requirements and update your policies, procedures, and operational practices accordingly.

Providers who set up their compliance documentation at registration and do not review it against standard updates find themselves presenting outdated policies at their mid-term or renewal audit. An auditor who sees a policy referencing a superseded standard, or one that does not address a new requirement, will note it as a finding.

In practice, staying current with Practice Standards changes requires:

  • Subscribing to NDIS Commission communications, including the reform hub newsletter
  • Monitoring the Commission’s Practice Standards page at ndiscommission.gov.au for updated standards and guidance documents
  • When a change is announced, assessing the impact on your specific compliance documentation and operational practices
  • Updating affected policies promptly with version control and approval records that show the update was made in response to the standards change
  • Ensuring staff are aware of any changes that affect their operational responsibilities

For the regulatory reform context including current changes and what is coming, see NDIS regulatory reform 2026: what every registered provider needs to know.

What a practical internal audit looks like

One way to identify non-compliance before it becomes a mid-term or renewal finding is to conduct a structured internal audit. Strategically, the ideal timing is six to nine months before your next scheduled audit, early enough to identify gaps and close them, late enough that the improvements will be embedded in practice by the time the auditor arrives.

An internal audit is a systematic check of each applicable Practice Standard against the current state of your compliance systems and operational evidence. It can be conducted by someone within your organisation with sufficient knowledge of the Standards to identify genuine gaps, not just verify that policies exist.

A practical internal audit works through each applicable Practice Standard against your current operational evidence, not just your policy library. It typically samples across the areas where compliance evidence accumulates: whether policies are current, approved and matched to how you actually operate; whether the incident and complaints registers are populated and correctly categorised; whether worker screening clearances are current and none lapse in the coming months; whether the risk register reflects your real operating environment; whether governance meetings are happening on schedule with agendas and minutes; whether participant files show current support plans, signed service agreements and documented consent; and whether the Commission’s key personnel register matches your current structure.

These are examples of where gaps most often surface, not a fixed checklist. The underlying test is the same for every standard: can you produce current, dated evidence that the system is operating in practice, and would it stand up if an auditor asked for it tomorrow?

For providers who have not been managing compliance actively, an internal audit at six months before a scheduled external audit can surface significant gaps. The benefit of finding them at six months, rather than when the auditor is sitting in front of you, is that you have time to address them properly. A corrective action taken and embedded over six months is sustainable evidence.

TrustBook makes ongoing compliance manageable

Real-time incident registers, worker-screening alerts, automated policy reviews, and governance prompts, so the evidence is there when your mid-term or renewal audit arrives.

TrustBook is a full compliance platform built for NDIS and Aged Care providers, with compliant policies and procedures, governance registers and audit-readiness checks tailored to your business.

Want a second set of eyes?

AuditHub, a proud partner of TrustBook, runs internal audits and helps you close findings before your next audit. Reach the team at support@audithub.com.au.