NDIS Provider Compliance Calendar: The Key Compliance Cycles Every Registered Provider Must Know

Last updated: June 2026  ·  Reading time: 8 minutes

Summary

  • There is no standard NDIS Provider Compliance Calendar. Every date runs from your own registration approval date, so no two providers share the same schedule.
  • The obligations still share a pattern: some run continuously, some start when an event happens, and some recur on a fixed cycle. Once you know which is which, you know when each one falls for you.
  • This guide lists every timeframe with its trigger and consequence, ready to build into the systems you already run.

Continuous obligations are never really “due”

A handful of your most important compliance obligations aren’t scheduled at all. They are either operating continuously or they are not.

  • Incident identification, recording and investigation: your incident register is either being used in real time or it isn’t. No scheduled check-in substitutes for a system that runs every day.
  • Worker screening verification: every worker in a risk-assessed role must hold a current NDIS Worker Screening Check before they start, and you must keep verifying their status through the NDIS Worker Screening Database for as long as they remain in that role, since a clearance can be suspended or revoked at any time.
  • Complaints intake and register maintenance: a complaints register that is only checked before audit shows the system is not being used day to day.
  • Monitoring NDIS Commission communications: the Practice Standards, reportable incident categories and worker screening requirements can all change without notice. Watching the Commission’s reform hub needs to be a routine task throughout the year.

These obligations don’t belong on a calendar the way a renewal date does, but they still need a named owner and a process to ensure that compliance is monitored, for example a weekly register check or a standing agenda item. Without that, they quietly stop happening.

For the systems that make each of these work day to day, see our dedicated guides on incident management (Article 2.4), worker screening (Article 2.5) and complaints management (Article 2.6).

NDIS Provider compliance timeframes

The table below lists every recurring or event-triggered compliance obligation referenced across this guide, in order of how quickly its timeframe starts, with the shortest first. The middle column tells you what event triggers the timeframe, and the right-hand column tells you what happens if you miss it.

Add your own dates, your registration date, your workers’ start dates, your last audit outcome, to customise the calendar for your specific organisation.

Reportable incident: immediate notification (most incidents)

Within 24 hours of any key personnel member becoming aware

Compliance breach; infringement notice; enforcement action

Reportable incident: unauthorised restrictive practice (no serious harm)

Within 5 business days of becoming aware

Compliance breach; enforcement action

Full written incident report

Within 5 business days of the initial notification

Compliance notice; conditions on registration

Notify the Commission of a key personnel change

Within 14 calendar days of the change

Registration information inaccurate; non-conformance finding

Corrective action plan submission

Within 7 days of an audit identifying a non-conformance

Non-conformance escalates unresolved

Worker screening verification

Before every worker in a risk-assessed role starts, and continuously while they remain in that role

Non-conformance finding; potential enforcement

Resolve a major non-conformance

Within 3 months of the audit finding

Conditions on registration; further Commission action

Condition audit / remaining elements of certification

Often within 3 months of commencing services in a certification class of support; the exact timeframe is set on your Certificate of Registration. Also imposed on a change of ownership or by Commission direction

Breach of registration conditions; suspension or revocation

Risk register review

Minimum quarterly (recommended)

Non-conformance finding at audit

Governance / board meetings

Minimum quarterly (recommended)

Non-conformance finding at audit

Policy review

Minimum annually (recommended), and immediately when a standard changes

Non-conformance finding at audit

Resolve a minor non-conformance

Within 18 months of the audit finding

Non-conformance finding at next audit

Mid-term (surveillance) audit

Commence no later than 18 months after the Commission approves your registration

Non-conformance findings; conditions on registration

Renewal audit commencement

Allow at least 6 months before registration expiry

Risk of registration lapsing

Registration renewal

3 years from the Commission approval date

Lapse of registration; cannot deliver supports

Worker screening check renewal

Every 5 years per worker; allow 6 to 8 weeks for processing

Worker cannot continue in a risk-assessed role

Practice Standards monitoring

Continuous, via the Commission’s reform hub and communications

Operating against superseded standards at your next audit

Why the Commission approval date matters

Every date in the audit and renewal rows above runs from the date the NDIS Commission approves your registration, not the date your audit was completed. Commission processing time after audit submission can run to several months, so if your audit finished in February but your registration was approved in May, your 18-month mid-term date and your 3-year renewal date are both calculated from May.
Confirm your registration date on your Certificate of Registration before you set any reminders.

Your registration cycle at a glance

The obligations above sit inside a larger three-year registration cycle that runs from your Commission approval date through to renewal.

Initial certification / verification audit

Before registration is granted

Full assessment against all applicable Practice Standards

Registration date

Set when the Commission approves your registration

The reference point for every later date in this cycle

Mid-term (surveillance) audit

No later than 18 months after the registration date

Certification-pathway providers only, except SDA-only providers

Condition audit

Often within 3 months of commencing services in a certification class of support; exact timeframe set on your Certificate of Registration

Certification-pathway providers. Imposed where the initial audit could not witness active service delivery, such as a new provider with no participants, or on a change of ownership. If services start 12 to 18 months after registration, it is completed as part of the mid-term audit

Renewal audit

Commences at least 6 months before expiry

All registered providers

Registration renewal

3 years from the registration date

All registered providers

This is a summary view. Providers with provisional certification, additional registration groups, or a Commission-imposed condition audit face additional touchpoints within this cycle. The complete breakdown, including provisional, condition and out-of-cycle audits, is covered in What Happens After Registration: Your Ongoing Practice Standards Obligations.

You are responsible for managing your own external audit cycle. Your approved quality auditor (AQA) will usually email you as your mid-term or renewal audit approaches, but treat that as a courtesy rather than your safeguard. Record each audit milestone in your compliance calendar against your own registration date, and schedule audit planning to start three months before the due date, so your evidence is ready before the AQA makes contact.

Embedding these timeframes into your management systems

Knowing the structure is the easy part. The providers who stay ahead of it don’t keep a compliance calendar off to the side. They build each timeframe into the management system that already owns the obligation, so it surfaces through normal operations.

  • Give every obligation an owner inside the system that runs it: an obligation with no owner does not get actioned. Each row above should sit with one accountable person inside the relevant management system.
  • Build audit and renewal dates into your quality management system, with the processing buffer already in them: worker screening renewals need 6 to 8 weeks of processing time, and a renewal audit needs at least 6 months’ notice to your AQA given current audit capacity pressure. Set the internal reminder well ahead of the Commission deadline.
  • Make recurring reviews standing items in your governance framework: risk register review, policy currency and board reporting belong in the governance cycle as standing agenda items.
  • Wire worker screening into your HR onboarding and offboarding system: a clearance is checked before a worker starts a risk-assessed role and tracked through to its five-year renewal from within the same workforce system.
  • Keep Commission monitoring with whoever owns your policies, and keep both dates visible: assign the reform hub and Commission communications to your policy owner on a fixed schedule, and record the internal target date and the actual Commission deadline together, so a slipped internal target never hides the real one.

The NDIS Practice Standards require a quality management system that drives continuous improvement, and internal audit against the Standards is how you evidence it. Your internal audit program is where these embedded timeframes are verified: a scheduled review that confirms each obligation above is being met, records any gap in your continuous improvement register, and closes it before an external auditor does.

Run it on a fixed cycle, test a sample of your incident, screening, policy and audit records against the timeframes in this guide, and report the results to your governance body.

Related Articles

TrustBook builds this into a live calendar for you

The TrustBook platform tracks every obligation above automatically: incident notification windows, worker screening expiries, policy review cycles, governance meeting schedules, and your mid-term and renewal audit dates, calculated from your actual Commission approval date. You get an alert ahead of each one, well before the auditor asks.

Need help mapping this into your organisation?

AuditHub’s advisors, led by Amanda Watson, can build your full compliance calendar and set up the tracking system behind it.