NDIS auditor bans shows a deeper problem with provider-paid audits

The front facade of the NDIS building at Malop Street in Geelong. Cropped Image iStock Jade Craven

The NDIS has introduced new powers to ban auditors and consultants after more than 200 providers were allegedly registered using false or misleading information. The case raises concerns about a system in which providers choose and pay the auditors who assess them.
The NDIS Quality and Safeguards Commission has issued its first lifetime banning orders against a consultant and an auditor alleged to have colluded to register more than 200 providers on false or misleading information. On the back of the investigation, the Commission refused 195 registration applications and revoked a further 40. These are the first banning orders of their kind, because the power behind them is new.

The banning orders were made on 17 June 2026, permanent and nationwide, and they are the first issued under new powers to ban auditors and consultants. Until the National Disability Insurance Scheme Amendment (Integrity and Safeguarding) Act 2026 (assented 8 April 2026), the Commission could ban only providers and workers. Closing that gap is the single most significant change here; the power itself, not the two individuals, is the story.

But the two individuals are only the visible end of the problem. The matter raises a sharper question about the chain those registrations passed through, and about a structural feature of the NDIS model that made the conflict possible in the first place.

Follow the money, because it explains the rest. NDIS registration is free, but a provider cannot register without passing an audit, and it must find, choose and pay the auditor itself. The Commission does not assign the auditor and does not set the price. Providers are told to get quotes and compare, and the commercial relationship runs directly between the provider and the auditor it hires.

Strip away the language and the design is this: the party being judged is the auditor’s paying customer, and it gets to pick which auditor to hire. An auditor that fails too many clients loses them to one that does not. That is not a hypothetical bias, it is a commercial incentive wired into the structure.

There is a check, and it is worth naming precisely so its failure is clear. Auditors do not appoint themselves. They are accredited by JAS-ANZ, which runs the scheme on the Commission’s behalf and monitors auditors, and then approved by the Commission itself. Accreditation runs under the NDIS (Approved Quality Auditors Scheme) Guidelines 2018, which invoke the international standard whose entire purpose is the impartiality and independence of certification bodies ( ISO/IEC 17065, 2012).

So on paper the conflict is handled: an international impartiality standard, an accreditor and a regulator, all stacked on top of the provider-pays model.

On paper. In this matter, a consultant and an auditor allegedly colluded to push more than 200 providers through, and that accreditation-and-approval layer did not stop it. The registrations were caught after the fact, by investigation and banning order, not before, by the impartiality controls that were supposed to make it impossible. That is the uncomfortable finding: the safeguards did not prevent the harm; enforcement cleaned up afterwards. And it was not the first warning. The sector has already seen an approved quality auditor sanctioned for selling consultancy to the very providers it was auditing. A second, on the back of a 200-provider collusion, looks less like bad luck and more like a pattern the design invites.

So the question is blunt: did the impartiality controls fail, or were they never really exercised? If they failed, with conflicts declared and waved through and technical review a formality, the accountability belongs at the certification-body level, not only with two banned individuals. If they were never tested, because the framework assumes good faith and never looks at who advised the provider before the audit, then it is not a safeguard. It is paperwork.

Either way, banning two people treats the symptom. The cause is a registration gate that lets the assessed party choose and pay its own assessor, policed by an accreditation layer that only moved once the damage was done. Just 17 certification bodies audit the entire NDIS market at the time of writing, and the Commission is not currently accepting new applications to join them, approvals paused amid the integrity reforms now reshaping the scheme. A closed pool of 17 makes the oversight question answerable, not impossible.

Aged care avoided the core mistake. There is no finding your own auditor and no paying the person who grades you directly. It all runs through the Aged Care Quality and Safety Commission, which arranges the audit, supplies the assessor and stands between the provider and the decision. The commercial relationship that sits at the heart of the NDIS matter simply does not exist. That single structural difference is why the two schemes should not be spoken of in the same breath when independence is the subject.

I do not say this from the outside. I audit in the aged care and hospital sectors, and I have deliberately stayed out of NDIS auditing. Not because the work cannot be done with integrity, as many do it conscientiously, but because a model that makes the provider the auditor’s paying customer puts independence in tension with commercial survival from the very first engagement. I did not want my name on a certificate issued under that tension. That is a judgment about the design, not about the people working within it.

The discipline is the same wherever you audit. A certification system is only as good as the independence it can actually demonstrate: sampled, stress-tested, enforced. Not the independence it asserts on paper. The question is the same on both sides of the fence: can you show that the independence in your certification chain was real, or only assumed?

Naomi Alefelder