Back to Articles
AI Automation

NDIS Incident Reporting Requirements: What Providers Must Record Before an Audit

NDIS Incident Reporting Requirements: What Providers Must Record Before an Audit

CareVisor

Editorial

17-06-2026
Published 17-06-2026

An auditor asks for your incident register from the past 12 months.

Your compliance manager opens a spreadsheet. A support worker searches through emails. Someone remembers that photographs were saved in a phone folder. The follow-up notes may be in a participant file, although nobody is entirely sure which version.

The incident itself may have been handled well. The participant may have received immediate support. Your team may even have changed its procedures afterwards.

But if you cannot produce the evidence, the auditor cannot assess the story living in your staff members’ memories.

That is the real pressure behind NDIS incident reporting requirements. It is not simply about submitting a form after a serious event. It is about creating a complete, dated and defensible trail from the first report through to investigation, corrective action and resolution.

NDIS incident reporting requirements in 60 seconds

Registered NDIS providers must identify, record, assess, manage and resolve incidents connected with the supports they provide. Serious events that fall within one of the six reportable categories must also be notified to the NDIS Quality and Safeguards Commission. Most are due within 24 hours of the provider becoming aware of them. Unauthorised restrictive practices that have not caused harm are generally due within five business days.

Every incident, including incidents that are not reported to the Commission, should still be managed through your internal incident management system.

The practical test is simple:

Can you open one incident and show what happened, when it happened, who was involved, what you did, who was notified, what you learned and whether every follow-up action was completed?

When the answer is “give us a few hours”, your risk is not only the incident. It is the evidence gap.

What counts as an incident under NDIS rules?

The NDIS Commission describes an incident broadly. It may be an act, omission, event or circumstance that caused, or could have caused, harm to a person with disability. It can also include a situation where a person with disability caused serious harm, or a serious risk of harm, to another person.

That definition is deliberately wider than “something that must be reported to the Commission”.

A medication error with no resulting harm may not meet the threshold for a reportable incident. A near miss during transport may not need Commission notification. A minor fall may not qualify as a serious injury.

They still belong in your internal incident management process.

A mature provider does not use the Commission threshold as permission to ignore smaller events. Minor incidents often reveal the pattern before the serious incident arrives wearing heavier shoes.

For a step-by-step explanation of recognising and documenting events, the Imploy incident-reporting guide provides a useful operational overview. The NDIS Commission’s incident management guidance should remain your primary regulatory reference.

The six reportable incident categories

Under current NDIS incident reporting requirements, registered providers must notify the Commission when an incident or allegation is connected with delivering NDIS supports and falls within one of the following categories.

Reportable incident category

Examples

Initial notification

Death of a person with disability

A death occurring in connection with the delivery of supports or services

Within 24 hours

Serious injury

An injury requiring hospitalisation or causing significant or lasting harm

Within 24 hours

Abuse or neglect

Physical, psychological, emotional, financial or systemic abuse; serious failures of care or supervision

Within 24 hours

Unlawful sexual or physical contact or assault

Alleged assault, unlawful physical contact or non-consensual sexual contact

Within 24 hours

Sexual misconduct

Sexual misconduct against or in the presence of a participant, including grooming

Within 24 hours

Unauthorised restrictive practice

A restrictive practice without the required authorisation or outside the participant’s behaviour support plan

Usually within five business days; within 24 hours if harm occurred

The word alleged matters.

Six NDIS reportable incident categories for registered providers

You do not wait until an internal investigation, police process or disciplinary meeting has established every fact. The reporting obligation can arise when the provider becomes aware of an allegation that meets the criteria.

The official NDIS Commission reportable incidents page should be checked whenever your team is uncertain about a category or timeframe.

A useful clarification: NDIS has six categories, not eight

Search results often mix NDIS requirements with the aged-care Serious Incident Response Scheme.

The aged-care framework commonly refers to eight incident types and Priority 1 or Priority 2 incidents. Those are not the correct labels for NDIS provider reporting.

For NDIS services, use the six reportable categories and the Commission’s 24-hour and five-business-day timeframes. Blending the two systems can create confusion at exactly the moment your team needs clarity.

How quickly must an NDIS provider report an incident?

The reporting clock generally begins when the registered provider becomes aware of the incident, not necessarily when the incident originally occurred.

That distinction matters when a participant discloses an older incident, a worker reports something late, or new information changes how the event should be classified.

Within 24 hours

Notify the Commission within 24 hours after becoming aware of:

  1. The death of a person with disability

  2. Serious injury

  3. Abuse or neglect

  4. Unlawful sexual or physical contact or assault

  5. Sexual misconduct, including grooming

  6. An unauthorised restrictive practice that caused harm

The notification is made through the NDIS Commission Portal under My Reportable Incidents.

You do not need to have every answer before submitting the immediate notification. Record what is known, protect the participant, preserve evidence and provide the remaining required information through the follow-up process.

Within five business days

A five-business-day timeframe generally applies to an unauthorised restrictive practice that did not cause immediate harm.

For other reportable incidents, additional information must normally be provided within five business days following the immediate notification. This may include witness details, further actions, risk controls and supporting documents.

The ShiftCare incident-reporting guide also explains these deadlines from an operational software perspective. Where a commercial guide and official guidance differ, always follow the NDIS Commission.

What happens if you miss the deadline?

Report the incident as soon as the omission is discovered.

Do not allow embarrassment about a late report to become a second and longer compliance failure. Document why the deadline was missed, what immediate action was taken, who reviewed the failure and what control has now been introduced.

An auditor will be interested in the missed deadline. They will also be interested in whether your organisation learned anything from it.

What must be included in an NDIS incident record?

A useful incident record is more than a description box containing “participant fell; manager informed”.

The Commission’s detailed guidance identifies minimum information that registered providers should keep.

Required record element

What good evidence looks like

Description

A factual account of what happened and the impact or harm caused

Nature of the incident

The classification and whether it was assessed as reportable

Date, time and place

When and where the incident occurred, or when it was first identified

Assessment

Whether it could have been prevented, how it was managed and whether another body required notification

People and witnesses

Names, roles and contact details of those involved or who witnessed the event

Immediate response

First aid, medical treatment, emergency services, separation, supervision or other safety action

Participant consultation

How the participant was informed, supported, involved and updated

Investigation

The investigator, evidence reviewed, findings, root causes and outcomes

Record author

The name, position and contact details of the person creating the record

A strong incident file will normally contain more than the minimum.

Consider attaching:

  • Staff statements

  • Photographs or diagrams

  • Medical documentation

  • Police or emergency-service reference numbers

  • Relevant support or behaviour support plans

  • Risk assessments

  • Correspondence with the participant, family or representative

  • Commission notification receipts

  • Investigation reports

  • Corrective-action records

  • Evidence that actions were completed

  • Management review notes

The art is not in collecting a mountain of paper. It is in connecting each item to one incident, one timeline and one outcome.

NDIS incident reporting timeline showing 24-hour and five-business-day deadlines

The seven-step incident reporting process

Your internal process should be simple enough to follow during a stressful shift and strong enough to withstand review months later.

1. Make the situation safe

Support the participant first.

Arrange medical care, call emergency services when required, remove immediate hazards and take reasonable steps to prevent further harm.

Compliance does not begin with a portal form. It begins with the person.

2. Notify the responsible manager immediately

Workers should know exactly whom to contact, including outside ordinary office hours.

A policy that says “inform management” is too vague. Your process should name the role, phone number, backup contact and escalation path.

3. Create the internal incident record

Record facts as soon as possible while memories are fresh.

Use objective language. Write what was seen, heard and done. Avoid speculation, blame or dramatic adjectives. “The participant appeared agitated” is weaker than describing the behaviour that led to that conclusion.

4. Assess whether the incident is reportable

Ask two questions:

  1. Did the incident occur, or allegedly occur, in connection with the delivery of your NDIS supports or services?

  2. Does it fall within one of the six reportable categories?

When the answer may be yes, escalate promptly to the person responsible for Commission notification.

5. Submit the Commission notification

Use the registered provider portal and record:

  • The date and time of submission

  • The person who submitted it

  • The notification reference

  • The category selected

  • The documents supplied

  • The deadline for additional information

A screenshot sitting in someone’s downloads folder is not an incident-management system.

6. Investigate and complete corrective actions

The investigation should ask more than “who made the mistake?”

Look at workload, supervision, training, communication, environment, participant plans, rostering, handovers and policy design. Individual actions matter, but repeated incidents are often wearing a system problem as a disguise.

Each corrective action needs an owner and a due date.

“Staff reminded” is not a durable control. “Medication competency reassessment completed for all relevant workers by 30 June” is.

7. Close, review and learn

Close the incident only when required actions are complete and the participant or representative has been appropriately updated.

Then review trends.

Are incidents clustering around a specific location, shift type, worker, participant need or handover process? One incident is a record. Five similar incidents are a message.

What an auditor is likely to test

Auditors do not only count incident forms. They test whether the system works.

They may select a sample from your register and compare:

  • The event date with the date staff reported it

  • The awareness time with the Commission notification time

  • The original worker account with the final investigation

  • The participant’s support plan with the response taken

  • The corrective action with evidence that it was completed

  • Repeated incidents with management trend reviews

  • Your written policy with what workers say happens in practice

Imagine an auditor selecting a serious injury from eight months ago.

You produce the initial report, medical note, immediate notification, five-day submission, staff statements, investigation, participant update, corrective action and management closure in one view.

That is audit readiness.

Now imagine the same evidence exists across four systems, two inboxes and a former employee’s phone.

That is where an otherwise responsible provider begins to look disorganised.

CareVisor’s incident management features are designed around mobile reporting, timestamped escalation, Commission-ready records and a trail from first report to resolution.

Audit test: Choose one incident at random. Start a timer. Can your team produce the complete evidence trail in ten seconds?

Common incident-reporting failures

Recording only incidents sent to the Commission

Your internal register should also contain non-reportable incidents, hazards and near misses where relevant to your incident-management process.

Otherwise, you lose the data needed to identify patterns.

Waiting for the investigation before reporting

The immediate notification is not the final verdict. Report within the required timeframe and update the record as reliable information becomes available.

Using vague descriptions

“Behavioural incident occurred” tells an auditor almost nothing.

What happened immediately beforehand? What behaviour was observed? What support strategy was attempted? Who was present? What was the impact?

Closing the incident before actions are complete

An investigation report does not close an incident if training, plan updates or environmental changes remain outstanding.

Failing to document participant involvement

The record should show how the affected person was supported, informed and included, using their preferred communication method where possible.

Keeping evidence in separate locations

A spreadsheet may list the incident, while emails contain the investigation and a shared drive holds the supporting documents.

Technically, the evidence exists. Practically, the trail is broken.

Keeping records for too short a period

Incident-related records should generally be retained securely for at least seven years from the date the record is made, subject to any longer Commonwealth, state or territory requirement.

How CareVisor supports an audit-ready incident process

CareVisor is not a replacement for sound judgement, trained staff or your responsibility to notify the Commission.

It gives the process somewhere disciplined to live.

Workers can record an incident from the field. The system timestamps the entry, captures the details and routes higher-risk events for escalation. Supporting files, follow-up actions and resolution evidence stay attached to the same record.

That matters because the auditor’s question is rarely, “Do you own an incident policy?”

It is usually closer to:

“Show me what happened after this event.”

A connected record answers that question without the archaeology.

Providers preparing for an audit should also review the NDIS audit preparation guide and the guide explaining what NDIS auditors check.

NDIS incident reporting requirements: final checklist

Before your next audit, confirm that:

  • Every worker knows what an incident is

  • Every worker knows whom to contact immediately

  • After-hours escalation is documented

  • Reportability is assessed against the six NDIS categories

  • The 24-hour clock begins when the provider becomes aware

  • Five-business-day follow-up deadlines are tracked

  • Non-reportable incidents are still recorded internally

  • Every record contains the required minimum information

  • Participant support and consultation are documented

  • Investigations identify causes, not just individuals

  • Corrective actions have owners and due dates

  • Repeated incidents are reviewed for patterns

  • Records are stored securely for at least seven years

  • The complete evidence trail can be produced quickly

If several of those answers depend on one person remembering where everything is stored, your process is more fragile than it looks.

Start a 7-day CareVisor trial and test your incident register using real operational data before the auditor chooses the sample for you.

Frequently asked questions

1. What counts as an incident that needs reporting to the NDIS?

An incident must be reported to the Commission when it occurred or allegedly occurred in connection with NDIS supports and falls within one of the six reportable categories. Other incidents may not require Commission notification but should still be recorded and managed internally.

2. How quickly must an incident be reported to the NDIS?

Most reportable incidents must be notified within 24 hours after the registered provider becomes aware of them. An unauthorised restrictive practice that did not cause harm is generally notified within five business days. Additional information for other incidents is usually due within five business days.

3. What should be included in an NDIS incident report?

Include the incident description, impact, category, date, time, location, people involved, witnesses, immediate actions, participant consultation, assessment, investigation details, corrective actions and the name of the person creating the record.

4. What are the six reportable incident categories?

They are death, serious injury, abuse or neglect, unlawful sexual or physical contact or assault, sexual misconduct including grooming, and unauthorised restrictive practice.

5. Do minor or non-reportable incidents still need to be recorded?

Yes. Registered providers need an incident management system that identifies, records, assesses, manages and resolves incidents, not only events submitted to the Commission. Minor incidents and near misses may also reveal repeat risks.

6. How long must NDIS incident records be kept?

Incident-related records should generally be stored securely for a minimum of seven years from the date the record is made. Other laws may require a longer period in some circumstances.

7. Who is responsible for notifying the NDIS Commission?

The provider’s incident management system should identify the person or role responsible for submitting notifications. This may be a member of key personnel, a manager or another specifically designated person. Workers should report internally without delay so the responsible person can assess and notify.

8. Does the NDIS use eight incident types or Priority 1 and Priority 2 categories?

No. Those terms are commonly associated with the aged-care Serious Incident Response Scheme. NDIS providers should follow the six NDIS reportable incident categories and the Commission’s 24-hour and five-business-day notification rules.

About CareVisor

CareVisor is an Australian-built NDIS service provider platform designed to help registered providers keep their daily operations organised, connected and audit-ready. Instead of managing participant information, staff records, incidents, shifts and compliance evidence across separate systems, providers can bring their essential workflows together in one place.

The platform supports staff credential and compliance tracking, rostering, GPS-verified shifts, participant documentation, service agreements, incident management, NDIS claiming and SCHADS payroll records. Each workflow creates a clearer evidence trail, helping providers respond more confidently when an auditor requests participant files, incident records, worker clearances or shift documentation.

CareVisor is built for Australian NDIS provider owners, operations teams and compliance managers who want fewer disconnected spreadsheets and better visibility across their organisation. Learn more about CareVisor, review the NDIS audit preparation guide, or start a 7-day free trial to assess your current audit readiness.