There is no such thing as a TEQSA quality audit. TEQSA does not audit providers in the way ASQA audits registered training organisations; it assesses applications, conducts compliance assessments, runs site visits and issues requests for further information, all of them framed by the Threshold Standards and by the provider's own risk profile. Preparing for scrutiny therefore means keeping evidence of operation current at all times, not preparing for a scheduled inspection.
This article explains what TEQSA actually does when it looks closely at a provider, what triggers that attention, and the habits that make a provider ready whenever it comes. It draws on fifteen years of TEQSA work with private providers, a good number of whom first called us because they had been told an audit was coming and wanted to know what that meant.
Why the phrase TEQSA quality audit is misleading
The word audit comes from the vocational sector, where ASQA audits RTOs against the Standards for RTOs on a schedule and on complaint. Providers moving from VET into higher education bring the vocabulary with them, and it shapes their behaviour in an unhelpful way: they prepare a file for the audit, and between audits the file goes back in the cupboard.
TEQSA works differently. Its instruments under the TEQSA Act are assessments of applications for registration, accreditation and renewal, compliance assessments where a concern has arisen, and the information-gathering powers that support them. Its posture is risk-based: annual data, compliance history and the strength of evidence in past applications determine how closely any given provider is examined. A provider can go years with little direct contact and then find itself answering detailed questions within a fortnight. The preparation that works is the same in both cases, and it is not a file.
What TEQSA actually does
The most common form of scrutiny is the assessment that follows an application. At renewal of registration, for example, the provider lodges a self-assurance report of no more than ten pages with an evidence index, independent reviews of its governing body and academic governance against Domain 6, and its risk management evidence. TEQSA does not require evidence against every standard; it selects what to test on the basis of risk, and it reads the self-assurance report as a claim to be verified against the evidence index. Assessors follow the index to the documents, and then to the records that show the documents in use.
A compliance assessment is different. It is opened when TEQSA has a specific concern, whether from a complaint, from annual data, from a material change notification or from media coverage, and it focuses on the standards in question. A request for further information can accompany either, and it typically gives the provider a defined period to respond. A site visit lets assessors meet the governing body, the academic board, staff and students, and to see whether what was described in writing is what actually happens. Every one of these is an assessment of evidence of operation, which is the point our companion article on common TEQSA compliance mistakes keeps returning to.
What draws attention
TEQSA's own list of material changes is a good guide to what it watches. Changes of ownership, major shareholding or CEO; incidents significantly affecting student safety; questions of good standing such as research misconduct allegations or an unscheduled audit by another regulator; significant changes in revenue; new third-party delivery arrangements; failures of control over third parties; and major changes to courses, including a notable reduction in duration. Each of these must be notified no later than fourteen days after the provider would reasonably be expected to have become aware. I set out the full picture in what triggers TEQSA scrutiny.
Beyond material changes, the annual data collections and the National Register give TEQSA a continuous view. Sharp growth in enrolments, a surge in international student numbers, a fall in progression rates or a spike in complaints will all be visible before the provider hears from anyone. In my experience the providers that are surprised by scrutiny are those that were not reading their own data.
Best practices for being ready at any time
The first practice is an evidence habit. Every academic and corporate process should produce a record as a matter of course, filed where the evidence index can find it, so that a request for further information is answered from the filing system rather than reconstructed. The second is an internal review cycle that mirrors TEQSA's: an annual self-assessment against the Threshold Standards, reported to the academic board and the governing body, with actions tracked to closure. Our article on the role of internal audit in meeting TEQSA's quality assurance standards describes how that function fits.
The third is governance that notices. TEQSA is looking for the body that will see a problem and act, and the minutes are the only evidence that such a body exists. The fourth is a material change discipline: someone owns the fourteen-day clock, and the board knows it does. The fifth is a straightforward relationship with the regulator. Providers that notify early, answer completely and never overstate their position are, in my experience, treated as lower risk, and the assessment that follows is shorter.
My advice on the mindset
Stop preparing for a TEQSA quality audit and start running a provider that could answer a request for further information tomorrow. The standards are in the present tense; so is the regulator's attention. A provider that keeps evidence of operation current, reviews itself honestly and keeps its boards informed has nothing to prepare, because the preparation is the ordinary business of the institution.
Download the Re-registration Evidence Index Template
— a working index that maps each Threshold Standard to the records that show it operating, drawn from our TEQSA registration and governance work with private providers. Get the template
Want the full article?
Enter your email for free access to the rest of this guide and our TEQSA resource library.
Frequently asked questions
Does TEQSA conduct audits like ASQA?
No. TEQSA assesses applications for registration, accreditation and renewal, conducts compliance assessments where a concern has arisen, and uses site visits and requests for further information. It does not run scheduled audits in the ASQA sense.
What is a TEQSA compliance assessment?
A focused examination of a provider's compliance with particular Threshold Standards, opened where TEQSA has a specific concern arising from a complaint, annual data, a material change or other information.
How much notice does TEQSA give before a site visit?
Site visits are arranged with the provider as part of an assessment, but the time available to prepare is short and the visit tests what the provider already does. Readiness comes from current evidence, not from preparation after notice.
What should a provider do when it receives a request for further information?
Read the request precisely, answer every element with evidence of operation, meet the deadline, and take the response through the relevant board so the record shows the governing body's involvement.
Dr Brendan Moloney is CEO of Darlo Higher Education, Australia's largest specialist TEQSA consultancy. He holds a PhD from the University of Melbourne, is a Cambridge University Press author on governance in higher education, and has advised private providers on registration and course accreditation for more than fifteen years.
