
NDIS Record Keeping Requirements: How Long Providers Must Keep Records (7-Year Rule)
Registered NDIS providers must now keep records for seven years. Destroying them is a criminal offence, and payments can be clawed back if you can’t produce one.
Guides, templates and real-world advice for NDIS providers, straight from our compliance team.
NDIS incident reporting is one of the compliance obligations that catches registered providers out the most, not because providers don’t care, but because the rules have two separate layers that are easy to confuse. One layer is about what you report internally. The other is about what you report to the NDIS Commission, and when.
Get the second one wrong and you’re looking at an infringement notice.
This post breaks down both layers clearly: what counts as a reportable incident, what the timeframes actually are, how the NDIS Commission portal works, and what your internal incident management system needs to cover.
Under the NDIS (Incident Management and Reportable Incidents) Rules 2018, a reportable incident is any act or event that has happened, or is alleged to have happened, in connection with delivering NDIS supports or services.
Not every incident is reportable to the Commission. But the ones that are must be notified within very specific timeframes, and there’s no grey area about that.
There are six categories of reportable incidents:
If any of these happen in connection with your supports, you must notify the NDIS Commission. Full stop. The obligation applies even when the incident has already been handled internally.
For the first five categories, death, serious injury, abuse, unlawful contact, sexual misconduct, the notification deadline is 24 hours from when the provider became aware of the incident.
That’s 24 hours. Not 24 business hours. Not when the manager gets back from leave.
The sixth category, unauthorised use of a restrictive practice, has a slightly longer window of five business days, but only if the incident has not caused immediate harm. If it did cause harm, the 24-hour window applies.
Missing these deadlines is not a minor paperwork issue. Late NDIS incident reporting can result in an infringement notice from the Commission, and repeated failures are treated as a serious compliance concern during audits.
The 24-hour window is also tighter in practice than it sounds. Your worker becomes aware of the incident on a Friday evening shift. That clock starts immediately. If your systems for escalating and documenting incidents are slow or manual, you can easily burn through most of that window before a report is even drafted.
NDIS incident reporting to the Commission happens through the NDIS Commission Portal and requires two separate forms.
Both forms are required for most reportable incidents. The 5 Day Form is the only form needed for unauthorised restrictive practice incidents that did not cause immediate harm.
Submitting the Immediate Notification Form is not the finish line. Providers who submit the initial notification and then don’t follow up with the 5 Day Form are still non-compliant.
NDIS incident reporting to the Commission is just one part of your obligations. The other part, arguably larger in day-to-day terms, is your internal incident management system.
The NDIS Practice Standards require every registered provider to have a functioning incident management system. This system needs to:
This internal system captures everything, not just the incidents that meet the reportable threshold. A near-miss where a participant almost fell. A medication prompt that was skipped. A worker who turned up late and left a participant without support. None of these may be reportable to the Commission, but all of them belong in your incident register.
Auditors look at your internal incident management system as a window into your culture. A provider with a thorough incident register, including near-misses, shows a functioning safety culture. A provider with only a handful of entries, or none, raises immediate questions.
During a certification or renewal audit, your incident management system will be examined. Auditors look at the register itself, the quality of individual reports, evidence of investigation and follow-up, and whether the timeframes for Commission notifications were met.
They may also interview workers to check whether they know what an incident is and what to do when one occurs.
Providers who manage incidents well, complete reports, documented follow-up, evidence of improvement, get through audits cleanly. Providers who have sparse registers, open incidents with no resolution, or workers who can’t explain the escalation process have a much harder time.
This is exactly where Wholii’s Medication & Incidents module removes the friction (wholii.com.au/product/medication-incidents/). A worker speaks through what happened on shift, on the phone, in the moment, and Wholii structures it into a complete incident report, timestamped, linked to the participant, and sitting in the manager’s review queue before the shift ends. No paper forms. No email chains. No details lost between a Friday evening and Monday morning.
The manager approves, follows up, or escalates directly from the dashboard. Because every incident is linked to the participant record, patterns across shifts and workers are visible in a way that a spreadsheet never shows.
For registered NDIS providers managing NDIS incident reporting across multiple sites or a large team, that visibility is the difference between a reactive incident culture and a proactive one.
Two separate obligations. One to your own incident management system, everything goes there. One to the NDIS Commission, six specific categories, 24-hour deadline for most of them, two forms required.
Missing the Commission deadline is not just a paperwork issue. Missing internal incident documentation is what auditors treat as a culture problem.
The standard here isn’t complicated. You need a system, you need trained workers, and you need a process fast enough to meet a 24-hour clock. Most providers who fail at NDIS incident reporting aren’t failing because the rules are hard, they’re failing because their systems depend on people remembering, escalating manually, and finding time to write reports at the end of a busy shift.
That’s a people problem with a systems solution.
Incident reports done before your worker leaves the location.
See how Wholii handles NDIS incident reporting for registered providers, book a free demo: wholii.com.au

Registered NDIS providers must now keep records for seven years. Destroying them is a criminal offence, and payments can be clawed back if you can’t produce one.

From 1 December 2026, NDIS providers have just 90 days to submit a claim — here is what that means for your organisation and what you need to do before the deadline hits.

The NDIS just had its biggest shake-up since launch. Here’s what registered providers need to know, and why compliance matters more now than ever.
