Who must comply with NDIS fraud prevention + reporting obligations?
The applicability test for NDIS fraud prevention + reporting obligations (NDIS Commission), computed across 35 industries, 9 business structures and 6 size bands.
Short answer: Some businesses
Applies when the business has NDIS services.
What the obligation is
NDIS providers must implement fraud-prevention systems + report suspected fraud.
Post-Tune Review, NDIS Fraud Strategy + Provider Obligations focus on fraud prevention. Providers must implement fraud risk frameworks + report suspected fraud via the NDIS Fraud Reporting + Scams Helpline.
The applicability test
Applies when the business has NDIS services.
How the regulator frames it: All NDIS providers (registered + unregistered).
What triggers it: Suspected fraud against NDIS scheme.
Jurisdiction: Commonwealth law, so the test is the same in every state and territory.
Which industries are in or out
Outcome across the 35 industries Rules Mate maps (1 of 35: yes; 34 of 35: no).
| Industry | Answer |
|---|---|
| NDIS providers | Yes |
| No | 34 other industries |
Business structure and size
Structure does not change the answer in ndis providers: for every structure the answer is "yes".
Size does not change the answer in ndis providers: at every size band the answer is "yes".
Worked examples
Each line is one run of the Rules Mate applicability engine for a single business profile, with the reason the engine gives:
- Pty Ltd company in ndis providers with 6–19 employees, turnover $1M–$3M: applies. NDIS provider.
- Pty Ltd company in real estate agents with 6–19 employees, turnover $1M–$3M: does not apply. Requires NDIS services.
Answers that bring it into scope
Starting from a small or large professional services company that does not otherwise meet the test, each of these single facts changes the engine's answer:
- The business is a registered NDIS provider: it then applies (registered NDIS provider).
What you must do, and when
- When due
- Suspicion event-driven.
- Frequency
- Ongoing
- Evidence to keep
- Fraud risk framework; incident reports; staff training.
- Status
- Current
- Priority
- Critical
Penalty for not complying
Maximum penalty: Criminal prosecution for fraud; provider banning.
Criminal liability
Audit or assurance level
Rules Mate has not yet classified the audit or assurance level for this obligation. Any audit, review or certification requirement is set by the regulator source listed below.
Obligations with the same applicability test
If this obligation applies to you, so does this one: the engine uses the same rule for each.
What usually applies alongside it
Across the 1,890 business profiles Rules Mate evaluates, these obligations apply to most of the businesses this one applies to, and are far more common among them than among businesses generally:
- Make mandatory notifications to AHPRA: applies to 100% of the same businesses (11.7× the overall rate)
- Notify the Coroner of a reportable death (state): applies to 100% of the same businesses (11.7× the overall rate)
- APP 12 & APP 13 access and correction requests: applies to 100% of the same businesses (1.5× the overall rate)
- APP 2 — anonymity + pseudonymity for individuals: applies to 100% of the same businesses (1.5× the overall rate)
- Provide an APP 5 collection notice at or before collection: applies to 100% of the same businesses (1.5× the overall rate)
Where it sits in the corpus
Rules Mate tracks 7 published obligations tagged "ndis", 7 of them rated critical. For a professional services Pty Ltd company with 6–19 employees operating in every state, 0 of those apply outright. This obligation is rated critical priority and carries criminal liability, and is an ongoing duty.
Regulator, legislation and tools
Regulated by NDIS Quality and Safeguards Commission.
NDIS Commission: NDIS provider registration, worker screening, code of conduct, reportable incidents, and complaint handling.
NDIS Act: Federal NDIS scheme + regulation.
Free tools that help with this obligation:
Questions
- Who must comply with NDIS fraud prevention + reporting obligations?
- Applies when the business has NDIS services.
- Does NDIS fraud prevention + reporting obligations apply to sole traders?
- Yes. Looking in ndis providers and every size band, the engine's answer for a sole trader is: yes.
- Does NDIS fraud prevention + reporting obligations apply to businesses with 1–5 employees?
- Yes (1–5 employees, turnover $100K–$1M).
- When is "NDIS fraud prevention + reporting obligations" due?
- Suspicion event-driven.
Related
Sources
Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.