Report serious NDIS incidents to the NDIS Commission
Death, serious injury, abuse, neglect, unauthorised restrictive practices, and sexual misconduct must be notified.
Who must comply
Registered NDIS providers (and unregistered for serious matters).
What triggers it
Occurrence of a reportable incident in connection with NDIS supports.
When due
Initial report within 24 hours; 5-day follow-up; investigation outcomes as required.
Evidence required
NDIS Commission notification (via portal), incident management plan, investigation record.
Max penalty
Civil penalties up to ~$66K per breach plus registration/banning actions
Who must comply with this? The applicability test by industry, business structure and size.
Summary
Registered NDIS providers must notify the NDIS Quality and Safeguards Commission of reportable incidents under the NDIS Act and Rules. Six categories: death; serious injury; abuse or neglect; unlawful sexual or physical contact or assault; sexual misconduct; unauthorised use of restrictive practices (NDIS Act s73Z). Death, serious injury, abuse or neglect, unlawful contact or assault and sexual misconduct are notified within 24 hours of key personnel becoming aware, with further details within 5 business days; unauthorised restrictive practices within 5 business days (NDIS (Incident Management and Reportable Incidents) Rules 2018 ss20-21). Providers must also maintain an incident management system that meets Rules ss10-13.
Enforced by
Source legislation
Industries
Topics
Related
- CWLTHComply with NDIS Practice StandardsRegistered NDIS providers must meet the NDIS Practice Standards for their registration groups.
- CWLTHReport cyber security incidents to ASD (SOCI)Critical infrastructure asset operators must report critical incidents within 12 hours and other incidents within 72 hours.
- CWLTHVerify NDIS worker screening clearanceRegistered providers must only engage workers in risk-assessed roles with a current NDIS Worker Screening clearance.
- CWLTHComply with Serious Incident Response Scheme (aged care)Registered aged care providers must maintain an incident management system and notify Priority 1 reportable incidents within 24 hours and Priority 2 within 30 days.
- CWLTHComply with NDIS quality auditor cycle for registered providersRegistered NDIS providers must pass NDIS Quality auditor cycle (verification + certification audits).
- CWLTHDevelop + authorise Behaviour Support Plans for restrictive practicesUse of restrictive practices in NDIS supports requires a comprehensive Behaviour Support Plan.
Frequently asked questions
- Who must comply with serious NDIS incidents to the NDIS Commission?
- Registered NDIS providers (and unregistered for serious matters).
- What triggers serious NDIS incidents to the NDIS Commission?
- Occurrence of a reportable incident in connection with NDIS supports.
- When is serious NDIS incidents to the NDIS Commission due?
- Initial report within 24 hours; 5-day follow-up; investigation outcomes as required.
- What is the maximum penalty for serious NDIS incidents to the NDIS Commission?
- Civil penalties up to ~$66K per breach plus registration/banning actions
- What evidence is required for serious NDIS incidents to the NDIS Commission?
- NDIS Commission notification (via portal), incident management plan, investigation record.
Source: https://ndiscommission.gov.au/providers/incident-management-and-reportable-incidents. Rules Mate is not a law firm. Always verify against the live regulator source before acting.