Guide 07 · preparation timing
How far before an NDIS audit should a small provider start preparing?
Short answer: Start when the scope and the provider's real evidence can be described, not when a generic countdown sounds reassuring. There is no universal official 3–12 month application-to-approval standard in the local canon. A planning range may be used as an internal estimate, but the useful first checkpoint is earlier: confirm the entity, supports, modules, sites, audit type, available evidence and the date the provider is actually working toward.
What the local canon says about timing
The due-diligence file records that the Commission publishes requirements, timelines and staged processes but not a universal 3–12 month approval standard. It preserves this official wording:
“We have created transitional arrangements to guide providers to become registered. They include information, registration requirements, timelines and staged processes.”
Source and date: NDIS Quality and Safeguards Commission, “Mandatory registration”, accessed 12 August 2026.
That distinction matters. A provider can set internal preparation checkpoints. It should not present an estimate as a regulator's service standard, an auditor booking guarantee or a promise of approval.
Work backwards from four dates
Write four dates in the scope note: the known audit or renewal date, the provider's intended submission or application date, the date by which the evidence pack must be ready for internal review, and the next internal checkpoint. If one is unknown, write NO_KNOWN_DATE or UNSURE. The purpose is to show what is known and what is not.
Then classify the preparation state. Foundation: the entity and pathway are still being confirmed. Build: policies, registers, worker controls and evidence indexing are being configured. Test: a sample is checked against the stated workflow and owners. Respond: written auditor requests or findings are being mapped to approved facts and evidence. A provider may be in different states for different dimensions.
A practical checkpoint rhythm
- Scope checkpoint: confirm provider type, supports, sites, modules, worker picture, registration status and the intended audit route. Keep the source and dated correspondence.
- Evidence checkpoint: list current policies, incident/complaint/risk registers, worker-screening and HR records, practice examples and the evidence index. Mark none, partial or unsure honestly.
- Owner checkpoint: assign a person to each control and each missing evidence item. Record dependencies such as client approval, worker information or an operational change.
- Sample checkpoint: choose a small, redacted sample and test whether a reviewer can see the policy-to-practice link, dates, owners and close-out.
- Release checkpoint: review factual statements, privacy, scope, version dates and unresolved questions before anything is sent to an auditor or regulator.
These are internal controls, not regulator instructions. They are useful because they turn time into an evidence trail instead of a vague feeling that the provider is “nearly ready.”
If the date is close
Do not hide the pressure. Write the actual date, the source or notice it came from, the provider's scope and the material that is missing. Separate work that can be completed in writing from work that requires real operations to occur. A consultant can help organise a policy suite, evidence index, response pack or action tracker; the provider must implement controls and generate truthful practice evidence.
If the date is less than the provider needs, the next useful decision may be a scope clarification, a written request for information, a triage of the notice or a staged work plan. It is not a reason to claim that a pack will produce an audit result.
Common mistakes
- Repeating a 3–12 month figure as though it were an official approval window.
- Counting pages in a policy folder instead of checking owners, registers, worker records and implemented examples.
- Leaving the audit date visible but not recording the scope, evidence dependency or internal owner for the next action.
When a written readiness view helps
The free scorecard gives a six-dimension starting view and states the intake limits. It can help a small provider decide whether the immediate problem is pathway fit, policy currency, registers, worker records, incident and complaint practice or evidence organisation. It cannot set an auditor's date, determine an application outcome or convert an estimate into a promise.
Related: verification versus certification and responding to a non-conformity. Regulatory source access date: 12 August 2026.
Want the next checkpoint written against your actual evidence?
Start the free scorecard and record the date, scope, supplied samples and unanswered questions. The written result keeps planning facts separate from regulatory decisions.