The Complete Guide to NDIS Provider Compliance

Everything registered NDIS providers need to know to meet their ongoing obligations, from the Practice Standards to incident reporting, worker screening, and what happens when things go wrong.

Last updated: July 2026  ·  Reading time: 20 minutes · Written for registered and registering NDIS providers

Summary

  • NDIS provider compliance doesn’t end after registration or an audit. Providers must maintain compliant systems every day.
  • The NDIS Practice Standards underpin all compliance obligations, guiding everything from governance and risk management to participant safety.
  • Auditors assess evidence of real-world practice, not just written policies. Your systems must be operating effectively, not just simply documented.
  • Missing compliance obligations can lead to serious consequences, including compliance notices, registration conditions, significant financial penalties or cancellation of registration.
  • A proactive compliance system reduces audit stress, protects participants, and keeps your organisation audit-ready throughout the entire registration cycle.

What NDIS provider compliance actually means

Compliance is a continuous operational state, not a point-in-time assessment. Your obligations as a registered provider begin the moment you receive your Certificate of Registration and continue uninterrupted until that registration is surrendered or revoked. The audit is a snapshot: verification that your systems work at a particular moment. The Commission requires them to work every day.

Providers who prepare intensively for audit and then revert to informal practices find themselves with incident registers that contain no data, policy documents that have never been reviewed, worker screening checks that have quietly expired, and governance meetings that stopped happening months after the auditor left. When the Commission’s next audit arrives, or, worse, when an unscheduled compliance audit is triggered by a complaint or a serious incident, the evidence is not there.

Compliance is what you do between audits: the daily operation of your incident management system, the quarterly review of your risk register, the annual policy review cycle, and the fortnightly check that worker screening is current. Run well, it protects your participants, your staff, and your registration.

The NDIS Practice Standards: your compliance framework

The NDIS Practice Standards are the legally mandated quality and safety requirements that every registered NDIS provider must meet. They are set by the NDIS Commission under the National Disability Insurance Scheme (Provider Registration and Practice Standards) Rules, and they define the baseline below which no registered provider may fall.

Understanding the Practice Standards is not optional. They are the framework against which your entire compliance system is built, assessed, and maintained. Every policy you write, every register you keep, every governance decision you make is ultimately answerable to a specific outcome in the Practice Standards.

How the Standards are structured

The Practice Standards are organised into modules. The module that applies to your organisation depends on your registration pathway and the supports you deliver.

The Core Module: for all certification pathway providers

Every provider going through the certification pathway must meet the four standards in the Core Module. These represent the baseline quality and safety requirements that apply regardless of what services you deliver or which registration groups you hold.

Rights and Responsibilities

Upholding participant rights, informed consent, choice and control, dignity and respect, protection from abuse and neglect, access to advocacy

Governance and Operational Management

Governance structures, leadership accountability, risk management, financial management, workforce management, information management, quality systems

Provision of Supports

How supports are planned, agreed, delivered and reviewed; individual support planning; continuity of supports; incident reporting; complaints management

Support Provision Environment

The physical and operational environment in which supports are delivered; safety of service locations; emergency procedures; equipment management

The Core Module is assessed through the full certification audit process, including both a document review and on-site assessment. Auditors look beyond policies to whether your systems are embedded in practice and whether your staff understand and follow them.

The Verification Module: for verification pathway providers

Providers delivering lower-risk supports through the verification pathway are assessed against four outcomes: rights and responsibilities, governance, provision of supports, and support provision environment.

The verification module assessment is a desktop document review with no site visit. The documentation requirements are less extensive than for the full Core Module, but the underlying principles, participant rights, sound risk management, safe delivery, are the same.

Specialist and supplementary modules

Providers delivering higher-risk or more complex supports are assessed against additional specialist modules on top of the Core Module. These include specialist standards for:

  • High Intensity Daily Personal Activities (HIDPA), covering competencies for complex personal care including tracheostomy, enteral feeding, subcutaneous injections, and ventilator support
  • Specialist Behaviour Support, for providers developing and implementing behaviour support plans, including those involving restrictive practices
  • Early Childhood Supports, for providers delivering supports to children under 9 with developmental delay or disability
  • Specialist Disability Accommodation, for SDA providers, covering design category requirements, tenancy rights, and property management
  • Supported Independent Living, new dedicated SIL Practice Standards in effect from 1 July 2026, covering quality and safety in shared accommodation settings

Each specialist module adds documentation requirements, evidence expectations, and audit focus areas. Providers registering for groups that trigger specialist modules should build their compliance systems to address those requirements from the outset, not as an afterthought before audit.

How the standards are assessed in practice

Meeting the Practice Standards is not about having the right documents. They are assessed against evidence of how your organisation actually operates.

An auditor reviewing your incident management system will not just check that you have an incident management policy. They will open your incident register and look for actual incidents. They will check that incidents are categorised correctly, that notifications to the Commission were made within the required timeframes, that investigations were conducted, and that corrective actions were implemented and followed up. A policy with no corresponding register entries points to a paper-only system, which is itself a finding.

The distinction between having a policy and having a working system is the central challenge of NDIS compliance. Every standard in the Practice Standards has quality indicators that specify exactly what evidence is required. Providers who build their compliance systems around those indicators are audit-ready on any given day. Providers who build systems around what they think auditors want to see often find significant gaps when a real auditor arrives.

Your ongoing compliance obligations

Once registered, your compliance obligations fall into several distinct areas. Each is a standing requirement, not something you address at audit time and then set aside. The sections below give you an overview of each area; the linked articles go deeper.

Incident management and reportable incident notification

Incident management is one of the highest-stakes compliance obligations, and an area where the Commission takes failure seriously. Every registered provider must have a functioning incident management system: a process for identifying, recording, investigating, and resolving incidents connected to service delivery.

Within that system, a specific subset of incidents, called reportable incidents, must also be formally notified to the NDIS Commission within legally mandated timeframes. The categories of reportable incidents are defined in legislation and include:

  • Death of a participant
  • Serious injury to a participant
  • Abuse or neglect of a participant
  • Unlawful sexual or physical contact with, or assault of, a participant
  • Unauthorised use of a restrictive practice
  • A participant going missing in circumstances that put their safety at risk

The timeframes for reporting are non-negotiable. Most reportable incidents must be notified to the NDIS Commission within 24 hours of a provider’s key personnel becoming aware of the incident. Unauthorised restrictive practices that have not resulted in serious harm must be notified within 5 business days. In each case, a full written report must be submitted to the Commission within 5 business days of initial notification, documenting the incident, the investigation, the findings, and the corrective actions taken or planned.

Missing reporting timeframes is a compliance breach. Under the NDIS Amendment (Integrity and Safeguarding) Act 2026, the Commission’s enforcement response to repeated or serious failures has materially stronger consequences than in previous years. The 24-hour notification period begins when any key personnel member becomes aware of the incident, not when a formal escalation process has been completed.

The 24 Hour Rule in Practice

The notification clock starts when any key personnel member, a manager, director, or person responsible for notifying the Commission in your incident management system, becomes aware of the incident.
It does not start when the incident is formally escalated through your internal process. Your incident management system must ensure that key personnel are notified immediately when a reportable incident occurs, and that the Commission notification happens within 24 hours of that notification regardless of what else is happening in your organisation.

Worker screening

Every worker in a risk-assessed role must hold a current NDIS Worker Screening Check before they can deliver supports to NDIS participants. The definition of a risk-assessed role is broad: it covers anyone who has more than incidental contact with participants, including support workers, managers, and key personnel.

Worker screening is not a once-done obligation. NDIS Worker Screening Checks must be renewed, and the renewal timeline varies by state and territory. As a registered provider, you are responsible for maintaining a workforce screening register that tracks the status and expiry of every worker’s check, and for ensuring that no worker in a risk-assessed role delivers supports without a current, valid check.

The Commission’s enforcement attention on workforce screening has intensified in recent years. Audits in 2025–2026 have identified providers deploying workers with lapsed or invalid screening checks as a primary audit finding. Given the penalty framework introduced by the Integrity and Safeguarding Act 2026, the cost of systemic failure is now very high.

Complaints management

Every registered provider must have a complaints management system: a formal process for receiving, recording, investigating, and resolving complaints from participants, their families, and other stakeholders. It is a specific requirement under the NDIS Practice Standards (Provision of Supports, Standard 3), assessed at every certification audit.

The system must include a complaints policy, a complaints register with evidence of active use, a process for escalating complaints that are not resolved at the first contact, and records demonstrating that participants are made aware of their right to complain, both to the provider and directly to the NDIS Commission.

One of the most common audit findings in this area is a complaints register that exists but is empty, or one that contains only formal complaints while informal concerns have never been recorded. Auditors expect to see a register that reflects the real experience of participants, including concerns raised and resolved without formal escalation. A register with no entries reflects a system that is not being used, not a complaint-free organisation.

Policy currency and documentation management

Your policies and procedures are the documented evidence of how your organisation meets the Practice Standards. They must be current, accurate, and reflective of how your organisation actually operates. Policies that were accurate at registration but have not been reviewed since, or that were purchased from a template provider without customisation, are among the most common causes of audit non-conformances.

Every policy must have a version number, a review date, and an approval record. The NDIS Practice Standards are periodically updated, sometimes with significant changes that require corresponding updates to your compliance documentation. Providers who do not monitor Commission updates and do not have a structured policy review cycle find themselves presenting policies that reference superseded standards or do not address new requirements.

A minimum annual review of all policies is prudent practice. Any change to the Practice Standards, your services, your workforce structure, or your operational model should trigger an immediate review of the relevant policies, regardless of when the scheduled review falls.

Surveillance audits and the certification cycle

Certification providers do not simply wait three years for their renewal audit. The certification cycle includes a mandatory surveillance audit at the eighteen-month mark, a mid-term assessment against the Practice Standards conducted by your AQA. The surveillance audit is typically less comprehensive than a full certification audit, but it is a formal compliance assessment with real consequences if significant non-conformances are identified.

Your registration period, and your surveillance audit clock, begins from the date the NDIS Commission approves your registration, not the date your audit was completed. This is an important distinction: if your audit completion and Commission decision are separated by several months (which is common), your three-year period and eighteen-month surveillance date are calculated from the Commission approval date, not the audit date.

The Commission can also conduct an unscheduled compliance audit at any time. Unscheduled audits are typically triggered by a complaint to the Commission, a pattern of incident notifications that raises concern, or a specific regulatory investigation. They can occur at any point in your registration cycle and are not constrained by the scheduled surveillance or renewal timeline.

The NDIS provider compliance calendar: key recurring obligations

Ongoing compliance has a temporal structure. Some obligations are continuous, incident management, for example, is never ‘off’. Others recur on a defined schedule. Understanding which obligations recur, and when, is the foundation of a compliance calendar.

Reportable incident notification

Within 24 hours of becoming aware (most incidents); 5 business days (unauthorised restrictive practices)

Infringement notice, compliance action, enforcement

Full incident report

Within 5 business days of initial notification

Compliance notice, conditions on registration

Worker screening check verification

Ongoing, before each worker begins risk-assessed work; monitor for expiry

Non-conformance finding; potential enforcement

Policy review

Minimum annually; immediately when standards change

Non-conformance finding at audit

Risk register review

Minimum quarterly

Non-conformance finding at audit

Governance/board meetings

As specified in governance framework, minimum quarterly recommended

Non-conformance finding at audit

Surveillance audit

18 months after Commission approval of registration

Non-conformance finding at audit; conditions on registration

Renewal audit commencement

Allow 6 months before registration expiry

Risk of registration lapsing

Registration renewal

3 years from Commission approval date

Lapse of registration; cannot deliver supports

Practice Standards monitoring

Continuously, Commission reform hub and communications

Operating against superseded standards at audit

When things go wrong: the Commission’s enforcement toolkit

Knowing what the Commission can do when a provider fails to meet its obligations is essential operational knowledge. The Integrity and Safeguarding Act 2026 materially expanded the Commission’s enforcement powers, and providers need to understand what they are operating within.

Compliance notices and requests for information

The Commission’s first response to a suspected compliance issue is typically a request for information or a compliance notice. A compliance notice formally identifies an area of non-compliance and requires the provider to take specified corrective action within a defined timeframe. These are the Commission’s most common enforcement tools and resolve most issues without progressing further.

Conditions on registration

Where the Commission has concerns about a provider’s ongoing compliance, it can impose conditions on that provider’s registration. Conditions might include requirements to report more frequently, to engage an external compliance advisor, to undergo unscheduled audits, or to restrict the types of supports delivered. Conditions are a serious signal that the Commission has identified systemic issues requiring active management.

Suspension and cancellation of registration

The Commission can suspend a provider’s registration where it has reasonable grounds to believe that the provider poses an unacceptable risk to participants. Suspension is a significant step, a suspended provider cannot deliver NDIS-funded supports, which immediately affects both participants and the provider’s business. Under the Integrity and Safeguarding Act 2026, the Commission has enhanced powers to act on a suspension quickly when participant safety is at risk.

Cancellation of registration terminates the provider’s ability to deliver registered NDIS supports permanently. Cancellation decisions can be appealed, but the process is lengthy and the operational consequences are immediate.

Civil penalties and criminal offences

Under the Integrity and Safeguarding Act 2026, civil penalties for serious misconduct have increased from a maximum of approximately $412,500 to more than $15 million where serious misconduct results in participant death or serious injury. New criminal offences carry a maximum of five years’ imprisonment for providing supports that require registration without being registered, and for failing to comply with a banning order.

Banning orders

The Commission can ban an individual from working in any role connected with NDIS service delivery. Banning orders now extend beyond providers and their employees to include auditors, consultants, and business advisors involved in NDIS compliance and service delivery. A banning order is a career-ending regulatory action for the individual concerned.

Why compliance never ends, and why that matters for your business

The regulatory environment is not static. The Commission updates the Practice Standards, issues new guidance, revises reportable incident categories, changes worker screening requirements, and introduces new obligations, continuously and without waiting for your audit cycle.

Between 2024 and 2026 alone, the Commission has:

  • Introduced mandatory registration for SIL and platform providers
  • Implemented new dedicated SIL Practice Standards
  • Passed the Integrity and Safeguarding Act 2026, fundamentally changing the penalty framework
  • Commenced a full review of the NDIS Practice Standards that will affect all registered providers
  • Signalled further mandatory registration expansion from July 2027

Providers who are not actively monitoring Commission communications and updating their compliance systems in response are, at any given time, potentially operating against a standard that has already changed. When their next audit arrives, the gap between their current practice and the current standard is what the auditor measures.

The goal of a well-designed compliance system is not to pass your next audit. It is to be audit-ready on any given day, whenever the Commission decides to look. That standard is achievable, but only with systems that are designed to run continuously, not in bursts.

The ongoing compliance advantage

Providers with strong continuous compliance systems spend significantly less on audit preparation than those who scramble before each audit cycle. They generate fewer non-conformances, resolve them faster when they do arise, and have lower total compliance cost over the life of their registration.
The investment in a well-functioning ongoing compliance system consistently pays for itself, often several times over, across a three-year registration period.

Building a compliance system that works between audits

A compliance system that works continuously has five characteristics that distinguish it from a compliance system that only works at audit time.

It is embedded in operations, not kept separate from them

Incident registers are completed in real time, not reconstructed before audit. Worker screening checks are tracked in a live register, not checked when an auditor asks. Risk registers are reviewed at governance meetings, not created fresh for each audit. The compliance documentation reflects how the organisation actually operates, because it is maintained by the people doing the work, for operational purposes, not to produce evidence.

It is maintained by named people with clear accountability

Every compliance obligation has a named owner: the person responsible for ensuring incident notifications are submitted on time, the person who maintains the worker screening register, the person who manages the policy review schedule. Without named accountability, compliance obligations diffuse into shared responsibility that nobody actively manages.

It is responsive to change

Commission guidance is monitored. When a Practice Standard is updated or a new guidance document is issued, the relevant policies are reviewed and updated. When a new worker joins, their screening is verified before they start. When a service changes, the risk register is updated to reflect the change. The system responds to the real environment the organisation operates in, rather than remaining static between audits.

It generates useful data

A working incident management system generates data about what kinds of incidents are occurring and where. A working complaints system generates data about what participants are dissatisfied with and why. A working risk register generates data about where the organisation is most exposed. Providers who use their compliance data for operational improvement get substantially more value from their compliance investment than those who use it to pass an audit.

It is proportionate to the organisation

A sole practitioner delivering therapeutic supports needs a compliance system that is rigorous but not bureaucratically burdensome. A large SIL provider with multiple sites and a hundred staff needs something substantially more structured. The right compliance system achieves genuine compliance for your specific organisation, not the one that looks most impressive on paper or was built for an organisation twice your size.

Ready to get started?

The TrustBook platform helps registered NDIS providers stay compliant every day, not just in the weeks before an audit. It tracks your incident obligations, monitors your worker screening register, manages your policy review schedule, and alerts you when the Commission issues updates that affect your compliance system.

When your next audit arrives, you will have the evidence because you built it day by day, not because you scrambled to reconstruct it.

Need hands on help?

Need expert advisory support? AuditHub’s compliance advisors, led by Amanda Watson, with more than 1,500 audits of combined experience, can assess your current compliance system, identify gaps, and help you build the infrastructure for ongoing compliance.