Guide · SIL certification

What a SIL certification audit tests, and where the evidence breaks

Updated 29 July 2026 Ricardo Santos · AI Systems Engineer 10 min read
The short answer

A SIL certification audit tests the distance between what your documents say happens and what actually happens. The structure is built for it: two stages, assessment against the Practice Standards including the SIL-specific ones, at least two auditors, and interviews alongside document and file review.

Documented policy is the weakest evidence you can bring. The audit is looking for records that the policy was followed, carrying who and when, that nobody assembled specially for the occasion.

Confirm the dates before you rely on them

Transition arrangements after the 1 July commencement had not been fully finalised when this was written. Treat every date here as a prompt to check the NDIS Commission's own guidance, not as a substitute for it. This page is general information, not registration advice.

Why the structure matters more than the checklist

Providers prepare for certification by working through the standards as a list. That is necessary and it is not what determines the outcome. The outcome is determined by the audit's method, and the method is triangulation: your documents, your staff, and your participants, compared against each other.

A document review can be passed with good documents. Triangulation cannot.

The four sources an auditor compares

SourceWhat it establishesWhere it fails
PoliciesWhat you say you doNothing on its own. Every provider has them
RecordsThat something happenedGaps, and clusters created before the audit
Staff interviewsWhat actually happensDescribes a different process from the document
Participant interviewsWhat is experiencedThe hardest to prepare for, and the least rehearsable

The last row is the one that changed the difficulty of SIL audits. You cannot brief a participant into a consistent answer, and you should not try. The only durable preparation is that the documented process and the real one are the same process.

Where evidence typically breaks

Worker screening currency

Not whether the worker was screened, but whether screening was valid on every day they delivered support. This requires a record that connects screening validity to shifts, and most providers hold those in two systems that do not talk.

Incident timelines

Reporting obligations are time-bound. An incident record without a defensible timestamp chain cannot demonstrate the timeline was met, only that the incident was recorded.

Supervision and competency

It happens, and it is evidenced afterwards if at all. Reconstructed supervision records are visible as a pattern to anyone reading dates.

Restrictive practice authorisation

Authorisation expires on its own schedule, independently of the plan it sits inside. The gap between expiry and renewal is a finding, and it is invisible in any system that stores authorisation as an attribute rather than as something with a lifecycle.

Complaints closure

Receipt is usually recorded. Closure, and what changed as a result, usually is not.

The pattern underneath all five

Every failure above shares a shape. The work happened, and the evidence was a separate act that someone had to remember. Any preparation that adds another separate act decays the same way, which is why the same non-conformity reappears at the next audit after a corrective action that promised more diligence.

The test that predicts your result

Pick a random participant and a random month from last year. Ask your team to produce everything you would need to show that month was compliant. Time how long it takes and note how much has to be reconstructed. That is the audit, run cheaply, and it is a better predictor than any readiness checklist.

What to do before the audit, and what to do after

Before: close the gaps manually. Do not attempt a systems change inside an audit window. The deadline is real and a half-finished implementation is a much worse position than a manual fix that works.

After: ask what would have had to be true for those gaps to be impossible rather than unlikely. Usually the answer is that the evidence had to come from the work rather than from a person remembering. Certification repeats, so this is not a one-off cost you can absorb once.

Common questions

What does a SIL certification audit involve?

Two stages, with stage two within three months of stage one and at least two auditors. Assessment against the Practice Standards including the SIL-specific standards, with governance interviews and file sampling alongside document review.

Do auditors really interview participants?

For certification audits, interviews with participants are part of the process. This is what makes certification substantially harder than verification, because it tests the lived process rather than the documented one.

What is the most common reason providers fail?

Inadequate evidence that policies were actually followed in practice, rather than missing policies. Demonstrating real-world compliance rather than documented procedure is consistently named as the hardest part.

Can software make us audit ready?

Not by itself, and not inside an audit window. Software changes whether evidence is a by-product of the work or a project before each audit. That matters across a certification cycle, not in the weeks before one.

This guide is general information about how Australian regulatory obligations apply in practice. It is not legal advice, and requirements vary by registration group, jurisdiction and the supports you deliver.

Related

After the audit, the evidence problem is still there

The next certification is in three years. Two weeks inside your workflow establishes whether the evidence can be a by-product of the work instead of a project each cycle.

Start a conversation