Back to Articles
AI Automation

SIRS Compliance for NDIS Providers: The Plain-English Guide

SIRS Compliance for NDIS Providers: The Plain-English Guide

CareVisor

Editorial

22-06-2026
Published 22-06-2026

What is a reportable incident under the NDIS?


SIRS compliance under the NDIS means meeting your obligations under the Serious Incident Response Scheme: identifying reportable incidents, notifying the NDIS Commission within the required timeframes (24 hours for Priority 1, five business days for Priority 2), recording them in an incident register, investigating, and taking corrective action. It applies to all registered NDIS providers.

There's a particular kind of quiet that falls over an office when a serious incident happens. A support worker calls in. Something has gone wrong with a participant. And in that moment, the clock you didn't know was running has already started.

That clock is SIRS. The Serious Incident Response Scheme is the NDIS framework that decides what you must report, how fast, and what happens next. Get it right and a difficult day stays a difficult day. Get it wrong and a difficult day becomes an audit finding, or worse.

Most providers know SIRS exists. Far fewer can confidently say their register would survive an auditor opening it cold. This guide closes that gap. We'll cover what SIRS is for, which incidents are reportable, the timeframes that trip people up, and how to build a system that proves your compliance instead of just hoping it holds.

What is the purpose of SIRS in the NDIS?

SIRS exists for one reason: to keep people with disability safe.

The Serious Incident Response Scheme requires registered NDIS providers to report serious incidents to the NDIS Quality and Safeguards Commission, so that harm gets identified, responded to, and prevented from happening again. It shifts the focus from "did you fill in a form" to "did you actually respond and protect the person."

For you as a provider, the purpose is twofold. First, it's a genuine safeguard for participants. Second, it's a record of how seriously you take that duty. When an auditor reviews your SIRS compliance, they're really asking a deeper question: when something went wrong, did your organisation notice, act, and learn?

A quick note on a common mix-up. People sometimes ask about "the 6 NDIS standards" or "the 7 domains of NDIS." SIRS sits alongside the broader NDIS Practice Standards, but it's its own specific obligation under the reportable incidents rules. Don't conflate the two. The Practice Standards are the wider exam. SIRS is one critical section of it.

What incidents are reportable under SIRS?

This is the question that matters most, because everything else flows from getting it right.

Under the Serious Incident Response Scheme, the reportable incidents are:

  1. The death of a person with disability.

  2. Serious injury of a person with disability.

  3. Abuse or neglect of a person with disability.

  4. Unlawful sexual or physical contact with, or assault of, a person with disability.

  5. Sexual misconduct committed against, or in the presence of, a person with disability, including grooming.

  6. The use of a restrictive practice in relation to a person with disability, where it is not in accordance with an authorisation or a behaviour support plan.

That sixth category is where many providers stumble, because unauthorised restrictive practices are reportable even when no one was visibly harmed. The act of restricting, without proper authorisation, is the reportable event.

So when the search data asks "what kind of incidents must be reported" or "what are considered reportable incidents under NDIS," that list above is your answer. Print it. Put it where your team can see it. The fastest way to fail SIRS compliance is for a frontline worker not to recognise a reportable incident when it's in front of them.

Reportable incidents NDIS under SIRS, the six categories registered providers must notify

Priority 1 and Priority 2: the timeframes that decide everything

Knowing an incident is reportable is half the job. Reporting it on time is the other half, and this is where SIRS compliance is most often lost.

Reportable incidents are split by priority, and each priority has its own deadline.

Priority

What it covers

Notification deadline

Priority 1

Death, serious injury, abuse or neglect, unlawful sexual or physical contact, sexual misconduct, and unauthorised restrictive practices causing harm

Within 24 hours of the provider becoming aware

Priority 2

Other unauthorised use of a restrictive practice not in a behaviour support plan

Within 5 business days of becoming aware

Two details catch people out.

First, the clock starts when any of your staff becomes aware, not when management hears about it. If a support worker knew on Monday and it reached your desk on Thursday, the auditor counts from Monday.

Second, the 24-hour Priority 1 notification is followed by a more detailed written report, generally within five business days. The first notification is the alarm. The written report is the account.

People ask "what is the difference between Priority 1 and Priority 2 SIRS incidents." The honest short version: Priority 1 is the serious-harm category with the 24-hour clock. Priority 2 is the narrower restrictive-practice category with the five-day clock. When in doubt, treat it as the higher priority and notify faster. Over-reporting is a process note. Under-reporting is a finding.

What is compliance in NDIS, and where does SIRS fit?

Compliance in the NDIS is the ongoing work of meeting your obligations under the NDIS Act, the Practice Standards, and the various rules, and being able to prove it.

SIRS compliance is one pillar of that wider structure. A strong NDIS incident reporting system has four moving parts:

  • Identification. Staff trained to recognise a reportable incident the moment it happens.

  • Notification. The right report lodged in the NDIS Commission Portal inside the timeframe.

  • Investigation. A documented look at what happened, why, and what changes.

  • Record-keeping. An incident register that holds all of it, time-stamped and complete.

You'll see plenty of generic frameworks online: the "5 C's of compliance," the "7 elements of compliance," the "4 phases." They're fine as background theory, but they aren't NDIS-specific. Your obligation is defined by the reportable incidents rules and the Practice Standards, not by a generic compliance acronym. Build to the actual rules.

For the wider picture of how SIRS connects to your full obligations, the CareVisor articles library breaks down each register and requirement in detail.

How to build a SIRS register that survives an audit

Here's where most SIRS compliance quietly fails. Not in the reporting, but in the record.

When an auditor reviews your SIRS compliance, they open your incident register and sample it. For each incident, they look for the same fields. If those fields are populated consistently, you pass. If they're patchy, you have a finding. Build your register around these:

  1. Date and time of the incident (kept separate from the date it was reported).

  2. Participant details and an impact assessment.

  3. Priority classification (P1 or P2, with the reasoning).

  4. Notification record (date, time, and the Portal reference number).

  5. Investigation summary (who investigated, what they found, what changed).

  6. Outcome and closure (closure date, participant informed, corrective action done).

Then run this test on your own system right now. Pick any incident from the last six months. Can you produce all six fields in under a minute? If you're reconstructing from emails and memory, your register isn't audit-ready, and a spreadsheet where rows can be quietly deleted is worse, because it can't prove the record wasn't changed.

This is the difference between a record and evidence. A record says something happened. Evidence proves it happened, when, and that you can't have tidied it up afterwards. For the full breakdown of what auditors check in a register, our guide to NDIS incident reporting and audits walks through it field by field.

Compliant SIRS incident register for NDIS showing the six fields auditors check.

Common SIRS compliance mistakes (and how to avoid them)

A few failures show up again and again. Knowing them is half the fix.

  • Late Priority 1 notifications. The single most common finding. The Portal timestamps everything, so a missed 24-hour window is visible instantly.

  • Frontline staff who can't identify a reportable incident. If your support workers don't know the six categories, incidents go unreported until it's too late.

  • Unauthorised restrictive practices treated as routine. These are reportable. Many providers don't realise it until an audit.

  • Investigations that never close. An incident logged but never investigated reads as a system that doesn't follow through.

  • No participant communication trail. You investigated, but there's no record the participant or their guardian was told the outcome.

  • The deletable spreadsheet. No audit trail means no way to prove the register is honest.

Fix these six and your SIRS compliance moves from fragile to defensible.

Frequently asked questions

Is SIRS considered an emergency?
No. SIRS is a reporting scheme, not an emergency service. If someone is in immediate danger, call 000 first, then meet your SIRS notification obligations. Safety comes before paperwork, always.

What is reportable under SIRS?
Reportable incidents under SIRS include the death, serious injury, abuse or neglect of a person with disability, unlawful sexual or physical contact, sexual misconduct, and the use of an unauthorised restrictive practice. Registered providers must notify the NDIS Commission within the required timeframes.

How many SIRS criteria must be met for an incident to be reportable?
An incident is reportable if it falls into any one of the reportable incident categories. It doesn't need to meet multiple criteria. If it matches a single category, the obligation to report is triggered.

What is the difference between a Priority 1 and a Priority 2 SIRS incident?
Priority 1 covers serious-harm incidents and must be reported within 24 hours. Priority 2 covers the use of a restrictive practice not in a behaviour support plan and must be reported within five business days. When unsure, report at the higher priority.

What should a support worker not do after a serious incident?
A support worker should not delay reporting, alter or remove records, or decide alone that an incident isn't reportable. The safest action is to ensure the person's immediate safety, then escalate straight away so the notification clock is met.

How long do I keep SIRS incident records?
Incident records should be retained for at least seven years from the date of the incident, stored securely under the Australian Privacy Principles, and kept so they can be produced for the Commission on request.

SIRS compliance comes down to three things done consistently: recognise a reportable incident, notify within the timeframe, and keep a record that proves you did. The providers who handle SIRS well aren't the ones who never have incidents. They're the ones whose system captures every step as it happens, so audit day is a confirmation rather than a scramble.

If your current setup relies on a shared drive and a good memory, that's the gap worth closing before your next audit, not during it.

See your SIRS readiness in 7 days. Start a free CareVisor trial, load your real incident data, and check your compliance score on day one. Every incident logged in CareVisor produces a time-stamped audit trail by default, so your register is always ready before the auditor asks.

Start your free 7-day trial →

About CareVisor

CareVisor is the audit-ready operating system for Australian NDIS providers, built in Sydney by NDIS operators who have prepared for and passed Quality and Safeguards Commission audits firsthand. Every workflow maps to the NDIS Practice Standards. SIRS compliance, including reportable incident notifications, Priority 1 and Priority 2 timeframes, investigations, and your full incident register, is captured by default with a time-stamped audit trail. CareVisor turns NDIS incident reporting from a once-a-year scramble into a daily operational habit. Start your free 7-day audit-readiness trial at carevisor.com.au.

TAGS

SIRS compliance NDISreportable incidents NDISNDIS incident reporting requirementsSerious Incident Response SchemeNDIS Priority 1 incidentNDIS Priority 2 incidentNDIS incident registerNDIS Quality and Safeguards CommissionNDIS restrictive practicesNDIS compliance software