Who must report serious NDIS incidents to the NDIS Commission?
The applicability test for Report serious NDIS incidents to the NDIS Commission (NDIS Commission), computed across 35 industries, 9 business structures and 6 size bands.
Short answer: Only if
Applies when the business has NDIS registration. Where the business has industry: NDIS providers, check whether you are a registered NDIS provider.
What the obligation is
Death, serious injury, abuse, neglect, unauthorised restrictive practices, and sexual misconduct must be notified.
Registered NDIS providers must notify the NDIS Quality and Safeguards Commission of reportable incidents under the NDIS Act and Rules. Five categories: death; serious injury; abuse or neglect; unlawful sexual or physical contact; sexual misconduct; unauthorised use of restrictive practices. Initial report within 24 hours of becoming aware; 5-day follow-up.
The applicability test
Applies when the business has NDIS registration. Where the business has industry: NDIS providers, check whether you are a registered NDIS provider.
How the regulator frames it: Registered NDIS providers (and unregistered for serious matters).
What triggers it: Occurrence of a reportable incident in connection with NDIS supports.
Jurisdiction: Commonwealth law, so the test is the same in every state and territory.
Which industries are in or out
Outcome across the 35 industries Rules Mate maps (1 of 35: only if a further fact applies; 34 of 35: no).
| Industry | Answer |
|---|---|
| NDIS providers | Only if a further fact applies |
| No | 34 other industries |
Business structure and size
Structure does not change the answer in ndis providers: for every structure the answer is "only if a further fact applies".
Size does not change the answer in ndis providers: at every size band the answer is "only if a further fact applies".
Worked examples
Each line is one run of the Rules Mate applicability engine for a single business profile, with the reason the engine gives:
- Pty Ltd company in real estate agents with 6–19 employees, turnover $1M–$3M: does not apply. Requires NDIS registration.
- Pty Ltd company in ndis providers with 6–19 employees, turnover $1M–$3M: check whether it applies. applies only if you are a registered NDIS provider.
Answers that bring it into scope
Starting from a small or large professional services company that does not otherwise meet the test, each of these single facts changes the engine's answer:
- The business is a registered NDIS provider: it then applies (registered NDIS provider).
When you need to check further
The engine shows this obligation as "check whether this applies" when a business has industry: NDIS providers. It then applies only if you are a registered NDIS provider. That fact is not something Rules Mate can infer from industry, structure or size.
What you must do, and when
- When due
- Initial report within 24 hours; 5-day follow-up; investigation outcomes as required.
- Frequency
- When a triggering event occurs
- Evidence to keep
- NDIS Commission notification (via portal), incident management plan, investigation record.
- Status
- Current
- Priority
- Critical
Penalty for not complying
Maximum penalty: Civil penalties up to ~$66K per breach plus registration/banning actions.
Audit or assurance level
Rules Mate has not yet classified the audit or assurance level for this obligation. Any audit, review or certification requirement is set by the regulator source listed below.
Enforcement examples
- NDIS Commission civil penalty proceedings — multiple providers (2024): Reportable-incident clocks start when the provider becomes aware. Internal escalation must be measured in hours, not days.
- NDIS Commission v Australian Foundation for Disability (2023): Reportable-incident obligations land on the provider AND on responsible individuals personally. Banning orders are personal.
Obligations with the same applicability test
If this obligation applies to you, so do these 3: the engine uses the same rule for each.
Where it sits in the corpus
Rules Mate tracks 7 published obligations tagged "ndis", 7 of them rated critical. For a professional services Pty Ltd company with 6–19 employees operating in every state, 0 of those apply outright. This obligation is rated critical priority, and is triggered by events.
Regulator, legislation and tools
Regulated by NDIS Quality and Safeguards Commission.
NDIS Commission: NDIS provider registration, worker screening, code of conduct, reportable incidents, and complaint handling.
NDIS Act: Federal NDIS scheme + regulation.
Free tools that help with this obligation:
Questions
- Who must report serious NDIS incidents to the NDIS Commission?
- Applies when the business has NDIS registration. Where the business has industry: NDIS providers, check whether you are a registered NDIS provider.
- Do sole traders need to report serious NDIS incidents to the NDIS Commission?
- Only if a further fact applies. Looking in ndis providers and every size band, the engine's answer for a sole trader is: only if a further fact applies.
- Do businesses with 1–5 employees need to report serious NDIS incidents to the NDIS Commission?
- Only if a further fact applies (1–5 employees, turnover $100K–$1M).
- When is "Report serious NDIS incidents to the NDIS Commission" due?
- Initial report within 24 hours; 5-day follow-up; investigation outcomes as required.
Related
Sources
Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.