An auditor asks for your incident register from the last 12 months.
Your team opens a spreadsheet.
Then someone checks an email folder.
Then someone remembers an incident that was handled, but never added to the register.
The participant was supported. The family was called. The manager followed up.
But the evidence trail is broken.
That is where an NDIS Incident Reporting Audit becomes risky.
The problem is not always that providers ignore incidents. The problem is that incidents are often recorded across too many places: emails, paper notes, staff messages, shared drives, old spreadsheets, and people’s memories.
During an audit, it does not feel organised. It feels exposed.
What Is an NDIS Incident Reporting Audit?
An NDIS Incident Reporting Audit checks whether a provider can identify, record, report, investigate, resolve, and learn from incidents connected to NDIS supports. Auditors review the incident register, reportable incident notifications, 24-hour and 5-day timeframes, follow-up actions, participant support, investigation records, and evidence that the provider’s incident management system works in daily practice.
Why Incident Reporting Gets Providers Into Trouble
Incident reporting looks simple from the outside.
Something happens.
A staff member reports it.
A manager reviews it.
If it is reportable, the provider notifies the NDIS Commission.
The provider follows up and records what changed.
That is the clean version.
In real operations, it gets messy.
A support worker may text a manager instead of using the form. A participant may disclose something days later. A family member may raise a concern verbally. A shift note may mention bruising, but no incident form is created. A report may be sent, but the 5-day follow-up is missed.
An NDIS Incident Reporting Audit tests whether your system catches those moments.
It is not enough to say, “We handled it.”
The auditor needs to see the record.
NDIS Incident Reporting Requirements in Plain English
NDIS incident reporting requirements apply when an act or event happens, or is alleged to have happened, in connection with NDIS supports or services.
Registered providers must notify the NDIS Commission of reportable incidents. These include serious injury, death, abuse, neglect, unlawful sexual or physical contact, sexual misconduct, and unauthorised use of restrictive practices.
Some incidents must be reported within 24 hours. Some require a 5-day form. Some unauthorised restrictive practice incidents must be reported within 5 business days, unless immediate harm occurred.
Many providers call this area “SIRS” because they are thinking about serious incident response. In NDIS language, the safer wording is “reportable incidents and incident management.” Still, the search intent behind “SIRS NDIS reporting requirements” is clear: providers want to know what they must report, when they must report it, and what evidence auditors will check.
What Counts as a Reportable Incident?
The safest way to think about it is this:
If the incident involves serious harm, possible harm, abuse, neglect, unlawful contact, sexual misconduct, death, serious injury, or unauthorised restrictive practice connected to NDIS supports, treat it as urgent until a qualified person confirms the correct pathway.
Reportable incident examples
Incident Type | Example | Typical Risk |
|---|---|---|
Death of a person with disability | Participant dies while receiving supports | 24-hour notification |
Serious injury | Hospitalisation after a fall | 24-hour notification |
Abuse or neglect | Alleged neglect by a worker | 24-hour notification |
Unlawful physical or sexual contact | Alleged assault or unlawful contact | 24-hour notification |
Sexual misconduct | Grooming or sexual behaviour linked to support delivery | 24-hour notification |
Unauthorised restrictive practice | Restrictive practice not authorised or not in the plan | Usually 5 business days unless harm occurred |
The 24-Hour Rule Providers Must Not Miss
The NDIS incident reporting 24 hour rule is one of the first things auditors may check.
If a serious reportable incident occurred, the auditor may ask:
When did the provider become aware of it?
Who was notified internally?
Who decided it was reportable?
When was the NDIS Commission notified?
Was the Immediate Notification Form submitted on time?
Was the participant made safe?
Was the family, guardian, or support person involved where appropriate?
Was follow-up action recorded?
The clock matters.
A provider may have supported the participant well, but if the notification was late and the reason is not documented, the record can still raise concern.
The 5-Day Report: What Auditors Look For
The 5-day report is where providers often lose the evidence trail.
The first notification may be submitted quickly. Then the team gets busy. The investigation is still open. Staff are on shift. A manager waits for more details. Five business days pass.
During an NDIS reportable incident audit, the auditor may check whether the 5-day report includes:
Further details of what happened
Actions already taken
Actions planned
Participant support provided
Risk review
Corrective action
Investigation notes
Names or roles of people responsible
Whether any pattern was identified
Whether the incident was closed properly
If your 5-day report says “follow-up completed” but nothing shows what follow-up happened, the record is weak.
What Auditors Check in an NDIS Incident Register
The incident register is the centre of the audit.
A good register does more than list incident dates. It shows the full journey from first report to closure.
The 6 register fields auditors check first
Field | Why It Matters |
|---|---|
Incident date and awareness date | Shows whether reporting timeframes were met |
Participant and service context | Shows where and how the incident connects to support delivery |
Incident category | Shows whether the provider identified reportable incidents correctly |
Immediate action taken | Shows participant safety came first |
Notification status | Shows whether the NDIS Commission was notified when required |
Follow-up and closure evidence | Shows the provider learned from the incident and acted |
If these six fields are missing or unclear, the auditor may need to dig deeper.
That creates pressure for your team.
NDIS Incident Register Audit: Weak vs Strong Record
Weak incident record
Date: 12 March
The participant fell during support. Staff helped the participant. Family informed.
Status: Closed.
This record may be true, but it does not show enough.
Strong incident record
Date: 12 March
Awareness time: 10:40 am
Incident: Participant fell during transfer from chair to bed.
Immediate action: Staff checked for injury, called supervisor, monitored participant, and contacted family.
Risk review: Transfer plan reviewed. Manual handling training gap identified.
Reportable decision: Notified manager. Assessed against reportable incident criteria.
Follow-up: Staff retraining completed. Participant risk plan updated.
Closure: Manager reviewed and closed on 18 March.
This record gives the auditor a trail.
It shows what happened, who acted, what changed, and why the provider believes the incident was managed.
Common Failures in an NDIS Incident Reporting Audit
1. Incidents exist, but the register is incomplete
A staff member remembers an incident. A participant's file mentions it. A family email refers to it. But it never appears in the register.
That tells the auditor your system may not capture all incidents.
2. Reportable incidents are not identified correctly
Some teams record serious events as “case notes” or “behaviour notes” instead of assessing whether they are reportable.
That creates risk.
3. The 24-hour notification is late
Late reporting is one of the clearest audit issues. If it happened, document why it happened and what control has been put in place to stop it happening again.
4. The 5-day report is missed or thin
A late or shallow 5-day report can make it look like the provider responded at first, then lost control of the process.
5. Follow-up actions are not closed
“Training to be completed” is not enough.
The register should show who completed it, when, and what changed.
6. Staff do not know how to report
Auditors may ask workers what they would do after an incident.
If the worker says, “I would tell my manager,” the auditor may ask what happens next.
Your team needs a clear answer.
7. Historical incidents have no evidence
This is the hidden risk.
The provider handled the incident. The participant was supported. Everyone remembers it.
But the record is missing.
Memory is not an incident management system.
NDIS Incident Reporting Compliance Checklist
Use this checklist before your next audit.
Incident identification
Workers know what an incident is
Workers know what a reportable incident is
Workers know who to notify
Staff understand the 24-hour rule
Staff understand 5-day reporting follow-up
Incident register
Every incident has a date and an awareness time
Each incident has a category
Each record shows immediate action
Each record shows whether it was reportable
Reportable incidents show the notification date and time
Follow-up actions have owners and due dates
Closure dates are recorded
Participant support
The participant was made safe
The participant was informed where appropriate
Support persons were involved where appropriate
Access to advocacy or support was considered
Communication was recorded
Investigation and review
Cause was assessed
Impact was recorded
Operational issues were considered
Corrective actions were documented
Lessons learned were added to the process
Repeated incidents were reviewed for patterns
How to Report an NDIS Reportable Incident
This section should be used as a practical guide, not legal advice.
Step 1: Make the person safe
Do not start with paperwork.
Start with the participant.
Check health, safety, immediate risk, medical needs, environmental risk, and whether emergency services are needed.
Step 2: Record what happened
Capture the facts as soon as possible.
Include:
Date and time
Location
Who was involved
Who witnessed it
What happened
Immediate action taken
Injuries or risks
Who was notified internally
Step 3: Assess whether it is reportable
A trained manager or responsible person should assess the incident against the NDIS reportable incident categories.
When unsure, escalate quickly.
Step 4: Notify the NDIS Commission if required
For incidents that require 24-hour notification, act fast. For relevant 5-business-day matters, track the deadline and owner clearly.
Step 5: Complete the 5-day follow-up
Add further information, actions taken, investigation progress, and participant support.
Step 6: Investigate and close the loop
Do not close the incident just because the form was submitted.
Close it when the risk has been reviewed, actions are completed, and the record shows what the provider learned.
The Hidden Risk: “We Handled It Internally”
This sentence creates problems in audit.
“We handled it internally” may mean staff did the right thing.
But the auditor will ask:
Where is the record?
Who assessed the risk?
Was it reportable?
Was the participant informed?
What changed afterward?
Was the same issue seen again?
If the answers are not in the record, the provider is relying on an explanation.
That is not strong enough.
How Long Should NDIS Incident Records Be Kept?
Providers should keep incident records in line with the NDIS rules, registration requirements, privacy obligations, and internal record-keeping policy. For audit readiness, the practical rule is simple: keep incident records secure, complete, easy to retrieve, and linked to follow-up actions.
The article should link this section to your broader NDIS record-keeping guide once published.
What Good Incident Management Software Should Show
The best NDIS incident management software in Australia should help a provider prove the incident journey.
It should show:
Incident date and awareness date
Participant involved
Service context
Incident category
Reportable status
24-hour notification tracking
5-day report tracking
Follow-up actions
Person responsible
Closure status
Pattern review
Evidence trail
Do not choose software only because it stores forms.
Choose a system that helps your team see deadlines, owners, actions, and audit evidence.
Where CareVisor Fits
CareVisor helps NDIS providers keep incident records easier to manage as part of their daily operations.
For an NDIS Incident Reporting Audit, CareVisor supports a clearer view of:
Incident records
Follow-up actions
Reporting evidence
Staff responsibilities
Participant documentation
Audit-readiness gaps
The goal is simple.
When an auditor asks for the incident register, your team should not need to search five places.
They should be able to show the evidence trail.
Check Your Audit Readiness Score
Check Your Incident Register Before the Auditor Does
If your incident records live across spreadsheets, emails, notes, and memory, review the risk before audit week.
Check your Audit Readiness Score or book an Audit Readiness Call with CareVisor.
Downloadable Asset: NDIS Incident Reporting Template
A strong page should include a downloadable NDIS incident reporting template.
The template should include:
Incident ID
Date and time
Awareness date and time
Participant name or ID
Service type
Worker involved
Incident category
Immediate action
Reportable decision
NDIS Commission notification date
5-day report status
Investigation notes
Corrective action
Owner
Due date
Closure date
This is the linkable asset for the page.
It gives providers something useful. It also gives partners and consultants something worth sharing.
Final Audit Readiness Test
Pick three incidents from the last 12 months.
For each one, ask:
Can we show when we became aware of it?
Can we show who reported it?
Can we show how the participant was supported?
Can we show whether it was reportable?
Can we show whether the 24-hour or 5-day timeframe applied?
Can we show what follow-up action happened?
Can we show who closed it?
Can we show what changed after the incident?
If you cannot answer these questions from the record, your NDIS Incident Reporting Audit preparation should start now.
Frequently Asked Questions
What is an NDIS Incident Reporting Audit?
An NDIS Incident Reporting Audit is a review of how a provider identifies, records, reports, investigates, resolves, and learns from incidents connected to NDIS supports. It usually includes the incident register, reportable incident notifications, follow-up actions, investigation records, and evidence of participant support.
What are NDIS incident reporting requirements?
Registered providers must have an incident management system and must notify the NDIS Commission of reportable incidents. Timeframes depend on the incident type, with serious categories often requiring 24-hour notification and further follow-up within 5 business days.
What is the NDIS incident reporting 24-hour rule?
The 24-hour rule applies to serious reportable incidents such as death, serious injury, abuse, neglect, unlawful sexual or physical contact, sexual misconduct, and unauthorised restrictive practice where harm has occurred.
What is the NDIS reportable incident 5-day report?
The 5-day report provides further information after the initial notification. It should include actions taken, investigation details, participant support, risk review, and next steps.
What auditors check in an NDIS incident register?
Auditors may check incident dates, awareness dates, categories, reportable status, notification timeframes, immediate actions, follow-up actions, investigation records, corrective actions, and closure evidence.
What is the biggest incident reporting audit risk?
The biggest risk is a broken evidence trail. The provider may have acted, but if the incident was not recorded, assessed, followed up, and closed properly, the auditor may find the system weak.
Does CareVisor help with NDIS incident reporting compliance?
CareVisor helps NDIS providers organise incident records, follow-up actions, staff responsibilities, and audit evidence so teams can review gaps before audit pressure begins.