
NDIS Record Keeping Requirements: How Long Providers Must Keep Records (7-Year Rule)
Registered NDIS providers must now keep records for seven years. Destroying them is a criminal offence, and payments can be clawed back if you can’t produce one.
Registered NDIS providers must now keep records for seven years. Destroying them is a criminal offence, and payments can be clawed back if you can’t produce one.
Quick answer: Under the NDIS record keeping requirements introduced by the National Disability Insurance Scheme Amendment (Securing the NDIS for Future Generations) Act 2026, registered NDIS providers must retain records for 7 years. Nominees must retain records for 5 years and participants for 3 years. Destroying records is an offence, and payments already received can be recovered if a provider cannot produce the record proving a support was delivered correctly.
Registered NDIS providers must keep records for 7 years.
This obligation comes from the National Disability Insurance Scheme Amendment (Securing the NDIS for Future Generations) Act 2026 (Act No. 66 of 2026), which received Royal Assent on 20 August 2026. Failing to hold records for the required period carries civil penalties.
Seven years is longer than most providers assume. Many organisations have historically kept records informally, for a year or two, or until the shift folder filled up. That approach no longer meets NDIS record keeping requirements.
No. The retention period depends on who holds the record.
| Who | Retention period | Why |
| Registered providers | 7 years | Must evidence that supports were delivered correctly |
| Nominees | 5 years | Act on behalf of a participant |
| Participants | 3 years | Hold records of their own plan spending |
Providers carry the longest obligation because providers are the ones expected to produce evidence if a claim is ever questioned.
A record is any document that shows a support was delivered and delivered correctly. The Act does not narrowly define records to mean invoices.
In practice, NDIS record keeping requirements cover:
If it is evidence that a support happened, it is a record, and the 7-year rule applies to it.
If a provider cannot produce the record, the payment for that support can become recoverable. This is the part that changes the stakes. The test is documentary. It asks whether you can show the support was delivered correctly, not whether it actually was. Good care that was never properly recorded does not count as care you can prove.
Yes. Destroying records is an offence under the amended Act.
This is not a grey area or a practice standard. It is a specific legal exposure that did not exist before this legislation, and it applies to deletion as well as physical destruction. A record deleted from a system to tidy up storage is treated the same way as a shredded file.
They are two separate clocks, and providers must satisfy both.
One is about speed. The other is about duration. Meeting the claim deadline does not discharge the retention obligation.
There are three practical steps, and most providers fail on the second one rather than the first.
1. Confirm your retention period actually reaches 7 years.
Not “we keep things” but a defined, reliable period applied consistently across every record type, including records held in email, messaging apps and personal devices.
2. Make records retrievable, not just stored.
A record buried in an old email thread or on a departed staff member’s laptop will not help you at audit. Storage is not the same as access. If you cannot locate a specific shift note from four years ago within minutes, you do not functionally have it.
3. Separate storage from proof.
Keeping a file for 7 years is not the same as being able to demonstrate who approved it, when, and on what basis. An audit asks for the audit trail, not just the document. Systems that timestamp approvals and preserve version history turn a stored file into admissible evidence.
How long do NDIS providers have to keep records?
Seven years, under the National Disability Insurance Scheme Amendment (Securing the NDIS for Future Generations) Act 2026.
What are the NDIS record keeping requirements for providers?
Registered providers must retain all records evidencing support delivery for 7 years, keep them retrievable, and must not destroy them within that period.
What happens if an NDIS provider cannot produce a record?
The payment for that support can become recoverable, even if the support was genuinely delivered.
Is destroying NDIS records a criminal offence?
Yes. Under the amended Act, destroying records is an offence rather than only a compliance breach.
Do participants have the same 7-year requirement as providers?
No. Participants must retain records for 3 years, nominees for 5 years, and providers for 7 years.
When did the NDIS record keeping requirements change?
The Act received Royal Assent on 20 August 2026. The related 90-day claim window takes effect from 1 December 2026.
Source: National Disability Insurance Scheme Amendment (Securing the NDIS for Future Generations) Act 2026, Act No. 66 of 2026, Royal Assent 20 August 2026.
Disclaimer: This article provides general information about NDIS record keeping requirements and does not constitute legal or compliance advice. It reflects our understanding of the National Disability Insurance Scheme Amendment (Securing the NDIS for Future Generations) Act 2026 at the time of writing, and legislation, guidance and NDIS Commission practice may change. Providers should confirm their obligations against the current legislation and seek independent professional advice before making decisions about record retention, destruction or compliance systems. Wholii accepts no liability for actions taken on the basis of this article.

Registered NDIS providers must now keep records for seven years. Destroying them is a criminal offence, and payments can be clawed back if you can’t produce one.

From 1 December 2026, NDIS providers have just 90 days to submit a claim — here is what that means for your organisation and what you need to do before the deadline hits.

The NDIS just had its biggest shake-up since launch. Here’s what registered providers need to know, and why compliance matters more now than ever.
