Quality Auditing
What are audits in healthcare?
Audits in healthcare are structured checks of care, systems or records against agreed criteria, carried out to confirm what is working and to find what needs to improve. An audit measures something specific against a written reference point: a clinical guideline, an internal policy, a national standard or a regulatory requirement. The auditor gathers evidence, compares it with that reference point, and records what the evidence shows.
Audits run at very different scales. A nurse unit manager reviewing 30 patient files against a clinical handover policy is running an audit. So is an external assessor who spends three days in a hospital deciding whether the service meets a national standard set. Both follow the same method, which is the discipline at the centre of quality auditing in Australia: agreed criteria, evidence, comparison, a recorded finding.
This page sets out the main types of healthcare audit, who plans and conducts them, what evidence they examine, and what follows a finding.
Why healthcare organisations use audits
Healthcare organisations audit for two reasons: regulators, funders and accrediting agencies require documented evidence that a service meets a standard, and the service’s own managers need to know whether written processes are being followed at the bedside. The second reason is the one that changes care. A policy approved by a committee and a policy practised on a Saturday night shift can differ, and an audit is how a quality team finds out which it has.
Those purposes tend to fall into five groups.
Producing evidence for accreditation or registration. Australian health services are assessed against the National Safety and Quality Health Service (NSQHS) Standards published by the Australian Commission on Safety and Quality in Health Care (second edition, 2017), available at
safetyandquality.gov.au. Assessors want records, not assurances.
Testing whether a process works in practice. Auditing a documented pathway against what staff actually do will often surface a workaround nobody recorded.
Following up an incident. After a medication error or a fall, a targeted audit shows whether the problem was isolated or systemic.
Preparing for an external assessment. Quality teams rehearse with their own audits before an outside body arrives, which is one of the differences between
internal and external healthcare auditors.
Measuring improvement over time. Re-auditing the same criteria after a change tells a service whether the change held.
Common types of healthcare audit
Seven types cover most audit activity in Australian healthcare, including audits conducted under the National Disability Insurance Scheme (NDIS) and audits against standards published by the International Organization for Standardization (ISO). The labels carry real distinctions, and several of them are used loosely as though they were interchangeable.
Clinical audit: a systematic review of clinical care against explicit, evidence-based criteria, carried out to identify where care can improve and to check that improvements have worked.
Internal audit (first-party audit): an audit an organisation conducts on itself, of any subject matter (clinical, financial-control, WHS (work health and safety), governance), independent of an audit conducted by an outside party.
External or certification audit (third-party audit): an audit conducted by an independent, outside body, often to determine whether a management system meets a recognised standard such as ISO 9001.
Accreditation assessment: a formal assessment, by an approved accrediting agency, of whether a health service organisation meets a recognised set of standards (in Australia, most commonly the NSQHS Standards); the outcome is accreditation, not certification.
NDIS audit: an audit of an NDIS provider against the NDIS Practice Standards by an NDIS Approved Quality Auditor, in one of two forms: a verification audit (document review only, for lower-risk supports, no site visit) or a certification audit (document review, site visits and interviews, for higher-risk or more complex supports). The
NDIS Quality and Safeguards Commission sets out which form applies to which provider.
Aged care quality audit: an assessment of an aged care provider against the Aged Care Quality Standards, undertaken under the
Aged Care Quality and Safety Commission’s regulatory framework.
ISO management system audit: an audit against an ISO management system standard (for example ISO 9001 for quality management); it can be conducted internally (first-party), by a related external party (second-party, such as a supplier audit), or by an independent certification body (third-party) under the guidance in ISO 19011.
Two of those distinctions get lost in everyday use. In Australian healthcare, health services are accredited against the NSQHS Standards while organisations are certified against ISO standards, so accreditation and certification are separate outcomes reached through different kinds of body. The second is within the NDIS scheme itself: a verification audit and a certification audit differ in method and in which providers they apply to, so “NDIS audit” used on its own says very little about what a provider will face.
Who plans and conducts healthcare audits
Who conducts an audit follows from whose criteria are being tested. A hospital quality coordinator, an external assessor and an NDIS Approved Quality Auditor all use recognisable audit method, and they answer to different schemes.
Internal quality, clinical governance and clinical audit teams plan and run first-party audits across the year, usually to an annual audit programme approved by a governance committee.
Approved accrediting agencies conduct accreditation assessments of health services against the NSQHS Standards.
NDIS Approved Quality Auditors conduct verification and certification audits of NDIS providers.
Certification bodies conduct third-party ISO management system audits.
The type and frequency of audit a provider faces depend on its sector, risk profile and regulator, so no single audit model applies uniformly across every Australian hospital, aged care provider or NDIS provider.
Auditors build the method through a mix of experience and formal training. BSB50920 Diploma of Quality Auditing is a nationally recognised diploma that builds the practical skills to plan, conduct and report on quality and compliance audits, and it can be a pathway toward lead auditor roles across industries. TalentMed Pty Ltd (RTO 22151) delivers it online. Completing BSB50920 does not itself issue an ISO 19011 certificate or an Exemplar Global lead auditor certificate, and it is not equivalent to third-party auditor certification; those are separate schemes, issued by their own bodies under their own criteria.
What evidence an audit may examine
An audit examines objective evidence, meaning information an auditor can verify rather than information someone recalls. The evidence-based approach is one of the principles of auditing set out in ISO 19011:2018, the International Organization for Standardization’s guidelines for auditing management systems (ISO, 2018). In a health service, that evidence usually comes from six places.
Documents that set the criteria. Policies, procedures, clinical guidelines, position descriptions, training registers and committee terms of reference. These establish what the organisation said it would do.
Records of care delivered. Patient notes, medication charts, consent forms, handover documentation, observation charts, incident reports.
Direct observation. Watching hand hygiene at the point of care, checking how medication fridges are monitored, confirming that a storeroom matches its stock procedure.
Interviews with staff and, where appropriate, consumers. An auditor asks a registered nurse to describe the escalation process, then checks the description against the policy and the records.
Data and quality indicators. Infection rates, falls data, pressure injury reporting, complaints and compliments, medication incident trends.
Previous findings and corrective action records. Evidence that a past problem was closed out, which is frequently where an audit finds its most useful material.
Sampling is decided during planning rather than on the day, and the sample has to be large enough and representative enough to support the conclusion drawn from it. Clinical audit methodology in Australian healthcare covers how criteria, sample and data collection are set up for clinical topics.
What happens after findings are recorded
A finding records whether the evidence met the criterion, and what happens next follows from what the finding says. Audit reports separate conformity from nonconformity, and most also record opportunities for improvement where practice met the criterion but sat close to the line.
Each nonconformity gets a corrective action, an owner and a date. The action addresses the cause rather than the single record that exposed it.
Someone verifies the action. That might be a desktop check of new evidence, or a follow-up audit of the same criteria.
External findings feed a formal decision. An accrediting agency decides accreditation against the NSQHS Standards, and a certification body decides certification against an ISO standard. Read the
NSQHS Standards explained in plain English for how those assessments are structured.
Internal findings feed self-assessment and governance reporting. Audit results go to a quality committee and, through it, to the board, which is part of how
clinical governance works in practice.
An audit that records findings and stops there has done half a job. Improvement comes from the corrective action and the re-audit that checks it, which is why audit programmes are built as cycles rather than as annual events.
Frequently asked questions
Audits in healthcare are structured checks of care, systems or records against agreed criteria. The criteria might be a clinical guideline, an internal policy, a national standard such as the NSQHS Standards, or a regulatory requirement. Seven types cover most of the work: clinical audit, internal audit, external or certification audit, accreditation assessment, NDIS audit, aged care quality audit and ISO management system audit.
Hospitals are audited from inside and from outside. Internal quality, clinical governance and clinical audit teams run first-party audits through the year. Accreditation assessments are conducted by approved accrediting agencies against the NSQHS Standards, and the outcome of that assessment is accreditation rather than certification. A hospital that also holds ISO 9001 is audited separately by a certification body.
Yes. An internal audit run against the same criteria an external assessor will use shows a service where its evidence is thin while there is still time to strengthen it. Quality teams commonly schedule internal audits through the accreditation cycle for that reason, then use the findings in their self-assessment. Internal audit work does not replace the external assessment, because the accreditation or certification decision rests with the external body.
Related healthcare audit resources