Back to blog
Compliance7 min read

SDA consultants and auditors: A due-diligence checklist for providers

The NDIS Commission's 2026 integrity reforms have made consultant and auditor controls harder to ignore. The Commission says its strengthened powers include expanded banning order powers for auditors and consultants, and its registration guidance is clear that providers remain responsible for the content of their own applications even when they use consultants, advice services or purchased policies. For SDA providers, the practical issue is not whether outside advice is allowed. It is whether the provider can prove that consultant work, audit work, SDA assessor certification, policy packs, participant-facing evidence, claims and owner updates all match the real operating model.

Treat outside advice as a governed dependency

SDA providers often rely on specialist help: registration consultants, policy vendors, approved quality auditors, SDA design assessors, owner-side advisers, claims consultants, tenancy advisers and outsourced compliance administrators. Each role can be useful, but none of them removes the provider's accountability for how SDA is delivered.

The Commission's registration application guidance says a provider using a consultant or purchased policies is still responsible for the application, needs to understand what was submitted, and should make sure responses are specific to the organisation. That belongs in the SDA governance file, not only in procurement emails.

Start with a simple dependency register. Record the adviser name, entity, ABN where relevant, role, scope, start date, end date, official-source checks, conflict declaration, evidence access, participant contact boundaries and accountable internal owner. If the adviser touches registration, audit evidence, plan evidence, service agreements, claims or owner reporting, the dependency is operational.

Separate advice from provider evidence

A consultant can help draft an application, prepare policy structure or explain an audit requirement. The provider still needs to show that the application describes actual people, actual dwellings, actual records and actual controls. Copying a generic policy pack into an SDA folder is weak evidence if staff cannot show how the process works in a resident's home.

For each consultant-prepared document, add three checks: who supplied the source facts, who reviewed the document for accuracy, and which live StepFree or operating record proves the statement. That keeps the evidence close to the workflow instead of leaving compliance dependent on a consultant's file.

This is especially important for SDA because the operating record crosses teams. A registration statement about tenancy management may rely on maintenance records, participant communication, complaints, incidents, service agreements, RRC handling, vacancy decisions and owner-reporting boundaries. Those records should be visible before the auditor asks for them.

Check auditor and assessor identity from official sources

Only approved quality auditors can assess whether an NDIS provider complies with the NDIS Practice Standards, and the Commission says approved quality auditors are not part of the Commission. Providers should therefore verify the auditing body from the Commission's current approved auditor list before relying on a quote, audit scope or recommendation.

SDA design certification is a different control. NDIA design-standard guidance says newly built SDA enrolment applications need SDA Design Standard certification signed by an accredited third-party SDA assessor, and it separately lists qualification and conflict-of-interest expectations for assessors. Do not assume a registration auditor, consultant or access adviser is automatically the right person for design certification.

Keep the checks separate: approved quality auditor for NDIS registration audit, accredited SDA assessor for Design Standard certification, internal provider owner for the registration application, and finance or operations owner for claim evidence. Blending those roles can hide conflicts, weaken evidence and confuse owner communication.

A practical due-diligence register

Use the register before appointing a consultant or auditor, when renewing registration, when onboarding a new dwelling, when changing an adviser, and when a compliance search result or audit finding raises a concern.

Define the role

Classify the relationship as registration consultant, policy vendor, approved quality auditor, SDA assessor, owner adviser, claims adviser, compliance administrator or other. Record what the person can and cannot do.

Verify from source

Check approved quality auditors, SDA assessors, provider registration status and compliance actions from official registers or pages. Store the date checked, source URL, checked-by person and next review date.

Control conflicts

Record actual or perceived conflicts involving owners, developers, related providers, referral partners, auditors, assessors and consultants. Escalate unclear independence before relying on the evidence.

Keep evidence custody clear

Store which documents the adviser prepared, which records the provider supplied, who approved the final version, where source evidence lives and whether any participant information was shared.

Limit participant and owner access

Give advisers the minimum access needed for their role. Do not send participant plans, NDIS numbers, incident details or owner reports unless role, consent, privacy and business need are clear.

Set exit controls

When an adviser leaves, close portal access, recover working files, update evidence owners, re-check upcoming deadlines and confirm that owner-facing statements do not depend on unsupported advice.

Connect concerns to claims, vacancies and owners

A consultant or auditor issue can quickly become an SDA operating issue. If a policy pack is not provider-specific, a certification claim is unclear, an adviser had excessive portal access, or a compliance search raises a relevant action, finance and operations need to know which dwellings, participants, claims, vacancies and owner reports may be affected.

Do not turn every adviser concern into a claim stop. Use controlled states: no impact found, evidence review needed, audit scope affected, registration application affected, design certification affected, participant communication review needed, owner report hold, or escalation required. The point is to keep decisions visible and proportionate.

Owner reporting should stay factual. Useful owner-safe language includes audit evidence under review, registration adviser changed, certification source being verified, no confirmed income impact, or vacancy claim-readiness pending evidence. Avoid naming individuals, sharing participant details or giving legal assurances unless the provider has clear advice and authority to do so.

How StepFree fits the workflow

StepFree SDA can help providers keep third-party compliance dependencies connected to the daily operating record. The same portfolio view can show dwellings, residents, claims, service agreements, RRC, complaints, incidents, audit evidence, adviser dependencies, due dates and owner-safe reporting states.

That does not replace official Commission registers, approved auditors, accredited SDA assessors or legal advice. It gives SDA teams a practical control surface: what was checked, what source was used, which provider record proves it, who owns the next action and whether any claim, vacancy or owner report should wait.

Conclusion

Consultants, auditors and assessors can support SDA providers, but they should not become hidden sources of truth. Providers need to verify adviser roles from official sources, keep conflicts visible, make applications and policies provider-specific, connect audit evidence to live SDA workflows, protect participant information, and hold owner reporting when evidence is unclear. The strongest due-diligence process is simple: know who advised, know what they touched, know what source proves it, and know which operational decisions depend on it.

StepFree SDA can help providers track adviser dependencies, audit evidence, claims, vacancy controls and privacy-safe owner reporting in one SDA operations workflow.