Back to Articles
AI Automation

Easy NDIS Incident Reporting Audit Wins for SIRS Pros

Easy NDIS Incident Reporting Audit Wins for SIRS Pros

CareVisor

Editorial

01-06-2026
Published 01-06-2026

An auditor asks for your incident register from the last 12 months.

Your team opens a spreadsheet.

Then someone checks an email folder.

Then someone remembers an incident that was handled, but never added to the register.

The participant was supported. The family was called. The manager followed up.

But the evidence trail is broken.

That is where an NDIS Incident Reporting Audit becomes risky.

The problem is not always that providers ignore incidents. The problem is that incidents are often recorded across too many places: emails, paper notes, staff messages, shared drives, old spreadsheets, and people’s memories.

During an audit, it does not feel organised. It feels exposed.

What Is an NDIS Incident Reporting Audit?

An NDIS Incident Reporting Audit checks whether a provider can identify, record, report, investigate, resolve, and learn from incidents connected to NDIS supports. Auditors review the incident register, reportable incident notifications, 24-hour and 5-day timeframes, follow-up actions, participant support, investigation records, and evidence that the provider’s incident management system works in daily practice.

Why Incident Reporting Gets Providers Into Trouble

Incident reporting looks simple from the outside.

Something happens.
A staff member reports it.
A manager reviews it.
If it is reportable, the provider notifies the NDIS Commission.
The provider follows up and records what changed.

That is the clean version.

In real operations, it gets messy.

A support worker may text a manager instead of using the form. A participant may disclose something days later. A family member may raise a concern verbally. A shift note may mention bruising, but no incident form is created. A report may be sent, but the 5-day follow-up is missed.

An NDIS Incident Reporting Audit tests whether your system catches those moments.

It is not enough to say, “We handled it.”

The auditor needs to see the record.

NDIS Incident Reporting Requirements in Plain English

NDIS incident reporting requirements apply when an act or event happens, or is alleged to have happened, in connection with NDIS supports or services.

Registered providers must notify the NDIS Commission of reportable incidents. These include serious injury, death, abuse, neglect, unlawful sexual or physical contact, sexual misconduct, and unauthorised use of restrictive practices.

Some incidents must be reported within 24 hours. Some require a 5-day form. Some unauthorised restrictive practice incidents must be reported within 5 business days, unless immediate harm occurred.

Many providers call this area “SIRS” because they are thinking about serious incident response. In NDIS language, the safer wording is “reportable incidents and incident management.” Still, the search intent behind “SIRS NDIS reporting requirements” is clear: providers want to know what they must report, when they must report it, and what evidence auditors will check.

What Counts as a Reportable Incident?

NDIS reportable incident categories and notification timeframes

The safest way to think about it is this:

If the incident involves serious harm, possible harm, abuse, neglect, unlawful contact, sexual misconduct, death, serious injury, or unauthorised restrictive practice connected to NDIS supports, treat it as urgent until a qualified person confirms the correct pathway.

Reportable incident examples

Incident Type

Example

Typical Risk

Death of a person with disability

Participant dies while receiving supports

24-hour notification

Serious injury

Hospitalisation after a fall

24-hour notification

Abuse or neglect

Alleged neglect by a worker

24-hour notification

Unlawful physical or sexual contact

Alleged assault or unlawful contact

24-hour notification

Sexual misconduct

Grooming or sexual behaviour linked to support delivery

24-hour notification

Unauthorised restrictive practice

Restrictive practice not authorised or not in the plan

Usually 5 business days unless harm occurred

The 24-Hour Rule Providers Must Not Miss

NDIS incident reporting 24 hour rule for registered providers

The NDIS incident reporting 24 hour rule is one of the first things auditors may check.

If a serious reportable incident occurred, the auditor may ask:

  • When did the provider become aware of it?

  • Who was notified internally?

  • Who decided it was reportable?

  • When was the NDIS Commission notified?

  • Was the Immediate Notification Form submitted on time?

  • Was the participant made safe?

  • Was the family, guardian, or support person involved where appropriate?

  • Was follow-up action recorded?

The clock matters.

A provider may have supported the participant well, but if the notification was late and the reason is not documented, the record can still raise concern.

The 5-Day Report: What Auditors Look For

The 5-day report is where providers often lose the evidence trail.

The first notification may be submitted quickly. Then the team gets busy. The investigation is still open. Staff are on shift. A manager waits for more details. Five business days pass.

During an NDIS reportable incident audit, the auditor may check whether the 5-day report includes:

  • Further details of what happened

  • Actions already taken

  • Actions planned

  • Participant support provided

  • Risk review

  • Corrective action

  • Investigation notes

  • Names or roles of people responsible

  • Whether any pattern was identified

  • Whether the incident was closed properly

If your 5-day report says “follow-up completed” but nothing shows what follow-up happened, the record is weak.

What Auditors Check in an NDIS Incident Register

The incident register is the centre of the audit.

A good register does more than list incident dates. It shows the full journey from first report to closure.

The 6 register fields auditors check first

Field

Why It Matters

Incident date and awareness date

Shows whether reporting timeframes were met

Participant and service context

Shows where and how the incident connects to support delivery

Incident category

Shows whether the provider identified reportable incidents correctly

Immediate action taken

Shows participant safety came first

Notification status

Shows whether the NDIS Commission was notified when required

Follow-up and closure evidence

Shows the provider learned from the incident and acted

If these six fields are missing or unclear, the auditor may need to dig deeper.

That creates pressure for your team.

NDIS Incident Register Audit: Weak vs Strong Record

Weak incident record

Date: 12 March
The participant fell during support. Staff helped the participant. Family informed.
Status: Closed.

This record may be true, but it does not show enough.

Strong incident record

Date: 12 March
Awareness time: 10:40 am
Incident: Participant fell during transfer from chair to bed.
Immediate action: Staff checked for injury, called supervisor, monitored participant, and contacted family.
Risk review: Transfer plan reviewed. Manual handling training gap identified.
Reportable decision: Notified manager. Assessed against reportable incident criteria.
Follow-up: Staff retraining completed. Participant risk plan updated.
Closure: Manager reviewed and closed on 18 March.

This record gives the auditor a trail.

It shows what happened, who acted, what changed, and why the provider believes the incident was managed.

Common Failures in an NDIS Incident Reporting Audit

1. Incidents exist, but the register is incomplete

A staff member remembers an incident. A participant's file mentions it. A family email refers to it. But it never appears in the register.

That tells the auditor your system may not capture all incidents.

2. Reportable incidents are not identified correctly

Some teams record serious events as “case notes” or “behaviour notes” instead of assessing whether they are reportable.

That creates risk.

3. The 24-hour notification is late

Late reporting is one of the clearest audit issues. If it happened, document why it happened and what control has been put in place to stop it happening again.

4. The 5-day report is missed or thin

A late or shallow 5-day report can make it look like the provider responded at first, then lost control of the process.

5. Follow-up actions are not closed

“Training to be completed” is not enough.

The register should show who completed it, when, and what changed.

6. Staff do not know how to report

Auditors may ask workers what they would do after an incident.

If the worker says, “I would tell my manager,” the auditor may ask what happens next.

Your team needs a clear answer.

7. Historical incidents have no evidence

This is the hidden risk.

The provider handled the incident. The participant was supported. Everyone remembers it.

But the record is missing.

Memory is not an incident management system.

NDIS Incident Reporting Compliance Checklist

Use this checklist before your next audit.

Incident identification

  • Workers know what an incident is

  • Workers know what a reportable incident is

  • Workers know who to notify

  • Staff understand the 24-hour rule

  • Staff understand 5-day reporting follow-up

Incident register

  • Every incident has a date and an awareness time

  • Each incident has a category

  • Each record shows immediate action

  • Each record shows whether it was reportable

  • Reportable incidents show the notification date and time

  • Follow-up actions have owners and due dates

  • Closure dates are recorded

Participant support

  • The participant was made safe

  • The participant was informed where appropriate

  • Support persons were involved where appropriate

  • Access to advocacy or support was considered

  • Communication was recorded

Investigation and review

  • Cause was assessed

  • Impact was recorded

  • Operational issues were considered

  • Corrective actions were documented

  • Lessons learned were added to the process

  • Repeated incidents were reviewed for patterns

How to Report an NDIS Reportable Incident

This section should be used as a practical guide, not legal advice.

Step 1: Make the person safe

Do not start with paperwork.

Start with the participant.

Check health, safety, immediate risk, medical needs, environmental risk, and whether emergency services are needed.

Step 2: Record what happened

Capture the facts as soon as possible.

Include:

  • Date and time

  • Location

  • Who was involved

  • Who witnessed it

  • What happened

  • Immediate action taken

  • Injuries or risks

  • Who was notified internally

Step 3: Assess whether it is reportable

A trained manager or responsible person should assess the incident against the NDIS reportable incident categories.

When unsure, escalate quickly.

Step 4: Notify the NDIS Commission if required

For incidents that require 24-hour notification, act fast. For relevant 5-business-day matters, track the deadline and owner clearly.

Step 5: Complete the 5-day follow-up

Add further information, actions taken, investigation progress, and participant support.

Step 6: Investigate and close the loop

Do not close the incident just because the form was submitted.

Close it when the risk has been reviewed, actions are completed, and the record shows what the provider learned.

The Hidden Risk: “We Handled It Internally”

This sentence creates problems in audit.

“We handled it internally” may mean staff did the right thing.

But the auditor will ask:

Where is the record?
Who assessed the risk?
Was it reportable?
Was the participant informed?
What changed afterward?
Was the same issue seen again?

If the answers are not in the record, the provider is relying on an explanation.

That is not strong enough.

Book an Audit Readiness Call

How Long Should NDIS Incident Records Be Kept?

Providers should keep incident records in line with the NDIS rules, registration requirements, privacy obligations, and internal record-keeping policy. For audit readiness, the practical rule is simple: keep incident records secure, complete, easy to retrieve, and linked to follow-up actions.

The article should link this section to your broader NDIS record-keeping guide once published.

What Good Incident Management Software Should Show

The best NDIS incident management software in Australia should help a provider prove the incident journey.

It should show:

  • Incident date and awareness date

  • Participant involved

  • Service context

  • Incident category

  • Reportable status

  • 24-hour notification tracking

  • 5-day report tracking

  • Follow-up actions

  • Person responsible

  • Closure status

  • Pattern review

  • Evidence trail

Do not choose software only because it stores forms.

Choose a system that helps your team see deadlines, owners, actions, and audit evidence.

CareVisor incident reporting software for NDIS audit readiness

Where CareVisor Fits

CareVisor helps NDIS providers keep incident records easier to manage as part of their daily operations.

For an NDIS Incident Reporting Audit, CareVisor supports a clearer view of:

  • Incident records

  • Follow-up actions

  • Reporting evidence

  • Staff responsibilities

  • Participant documentation

  • Audit-readiness gaps

The goal is simple.

When an auditor asks for the incident register, your team should not need to search five places.

They should be able to show the evidence trail.

Check Your Audit Readiness Score

Check Your Incident Register Before the Auditor Does

If your incident records live across spreadsheets, emails, notes, and memory, review the risk before audit week.

Check your Audit Readiness Score or book an Audit Readiness Call with CareVisor.

Downloadable Asset: NDIS Incident Reporting Template

A strong page should include a downloadable NDIS incident reporting template.

The template should include:

  • Incident ID

  • Date and time

  • Awareness date and time

  • Participant name or ID

  • Service type

  • Worker involved

  • Incident category

  • Immediate action

  • Reportable decision

  • NDIS Commission notification date

  • 5-day report status

  • Investigation notes

  • Corrective action

  • Owner

  • Due date

  • Closure date

This is the linkable asset for the page.

It gives providers something useful. It also gives partners and consultants something worth sharing.

Final Audit Readiness Test

Pick three incidents from the last 12 months.

For each one, ask:

  1. Can we show when we became aware of it?

  2. Can we show who reported it?

  3. Can we show how the participant was supported?

  4. Can we show whether it was reportable?

  5. Can we show whether the 24-hour or 5-day timeframe applied?

  6. Can we show what follow-up action happened?

  7. Can we show who closed it?

  8. Can we show what changed after the incident?

If you cannot answer these questions from the record, your NDIS Incident Reporting Audit preparation should start now.

Frequently Asked Questions

What is an NDIS Incident Reporting Audit?

An NDIS Incident Reporting Audit is a review of how a provider identifies, records, reports, investigates, resolves, and learns from incidents connected to NDIS supports. It usually includes the incident register, reportable incident notifications, follow-up actions, investigation records, and evidence of participant support.

What are NDIS incident reporting requirements?

Registered providers must have an incident management system and must notify the NDIS Commission of reportable incidents. Timeframes depend on the incident type, with serious categories often requiring 24-hour notification and further follow-up within 5 business days.

What is the NDIS incident reporting 24-hour rule?

The 24-hour rule applies to serious reportable incidents such as death, serious injury, abuse, neglect, unlawful sexual or physical contact, sexual misconduct, and unauthorised restrictive practice where harm has occurred.

What is the NDIS reportable incident 5-day report?

The 5-day report provides further information after the initial notification. It should include actions taken, investigation details, participant support, risk review, and next steps.

What auditors check in an NDIS incident register?

Auditors may check incident dates, awareness dates, categories, reportable status, notification timeframes, immediate actions, follow-up actions, investigation records, corrective actions, and closure evidence.

What is the biggest incident reporting audit risk?

The biggest risk is a broken evidence trail. The provider may have acted, but if the incident was not recorded, assessed, followed up, and closed properly, the auditor may find the system weak.

Does CareVisor help with NDIS incident reporting compliance?

CareVisor helps NDIS providers organise incident records, follow-up actions, staff responsibilities, and audit evidence so teams can review gaps before audit pressure begins.

Start a Free 7-Day Trial