Guide · SIL certification
What a SIL certification audit tests, and where the evidence breaks
A SIL certification audit tests the distance between what your documents say happens and what actually happens. The structure is built for it: two stages, assessment against the Practice Standards including the SIL-specific ones, at least two auditors, and interviews alongside document and file review.
Documented policy is the weakest evidence you can bring. The audit is looking for records that the policy was followed, carrying who and when, that nobody assembled specially for the occasion.
Transition arrangements after the 1 July commencement had not been fully finalised when this was written. Treat every date here as a prompt to check the NDIS Commission's own guidance, not as a substitute for it. This page is general information, not registration advice.
Why the structure matters more than the checklist
Providers prepare for certification by working through the standards as a list. That is necessary and it is not what determines the outcome. The outcome is determined by the audit's method, and the method is triangulation: your documents, your staff, and your participants, compared against each other.
A document review can be passed with good documents. Triangulation cannot.
The four sources an auditor compares
| Source | What it establishes | Where it fails |
|---|---|---|
| Policies | What you say you do | Nothing on its own. Every provider has them |
| Records | That something happened | Gaps, and clusters created before the audit |
| Staff interviews | What actually happens | Describes a different process from the document |
| Participant interviews | What is experienced | The hardest to prepare for, and the least rehearsable |
The last row is the one that changed the difficulty of SIL audits. You cannot brief a participant into a consistent answer, and you should not try. The only durable preparation is that the documented process and the real one are the same process.
Where evidence typically breaks
Worker screening currency
Not whether the worker was screened, but whether screening was valid on every day they delivered support. This requires a record that connects screening validity to shifts, and most providers hold those in two systems that do not talk.
Incident timelines
Reporting obligations are time-bound. An incident record without a defensible timestamp chain cannot demonstrate the timeline was met, only that the incident was recorded.
Supervision and competency
It happens, and it is evidenced afterwards if at all. Reconstructed supervision records are visible as a pattern to anyone reading dates.
Restrictive practice authorisation
Authorisation expires on its own schedule, independently of the plan it sits inside. The gap between expiry and renewal is a finding, and it is invisible in any system that stores authorisation as an attribute rather than as something with a lifecycle.
Complaints closure
Receipt is usually recorded. Closure, and what changed as a result, usually is not.
The pattern underneath all five
Every failure above shares a shape. The work happened, and the evidence was a separate act that someone had to remember. Any preparation that adds another separate act decays the same way, which is why the same non-conformity reappears at the next audit after a corrective action that promised more diligence.
Pick a random participant and a random month from last year. Ask your team to produce everything you would need to show that month was compliant. Time how long it takes and note how much has to be reconstructed. That is the audit, run cheaply, and it is a better predictor than any readiness checklist.
What to do before the audit, and what to do after
Before: close the gaps manually. Do not attempt a systems change inside an audit window. The deadline is real and a half-finished implementation is a much worse position than a manual fix that works.
After: ask what would have had to be true for those gaps to be impossible rather than unlikely. Usually the answer is that the evidence had to come from the work rather than from a person remembering. Certification repeats, so this is not a one-off cost you can absorb once.
Common questions
What does a SIL certification audit involve?
Two stages, with stage two within three months of stage one and at least two auditors. Assessment against the Practice Standards including the SIL-specific standards, with governance interviews and file sampling alongside document review.
Do auditors really interview participants?
For certification audits, interviews with participants are part of the process. This is what makes certification substantially harder than verification, because it tests the lived process rather than the documented one.
What is the most common reason providers fail?
Inadequate evidence that policies were actually followed in practice, rather than missing policies. Demonstrating real-world compliance rather than documented procedure is consistently named as the hardest part.
Can software make us audit ready?
Not by itself, and not inside an audit window. Software changes whether evidence is a by-product of the work or a project before each audit. That matters across a certification cycle, not in the weeks before one.
This guide is general information about how Australian regulatory obligations apply in practice. It is not legal advice, and requirements vary by registration group, jurisdiction and the supports you deliver.