Allied Health NDIS Audit Checklist
RegistrationNDIS Provider Registration Rulesndis-provider-registration-rules--s73y-73z-incident-management-system-and-reportable-incident
Requirement

Incident management system and reportable incident notification

NDIS Provider Registration Rules ss 73Y and 73Z, stated plainly and cited to the edition held, with the evidence an auditor or the regulator asks for, the common gaps, and a free worksheet to fill in.

Clause

Provider Registration Rules ss 73Y and 73Z

Regulator

NDIS Quality and Safeguards Commission

Edition held

NDIS (Provider Registration and Practice Standards) Rules 2018, Compilation No. 6 (F2026C00527), in force 1 July 2026, with NDIS Act 2013 Part 3A as in Compilation No. 27 (C2026C00401)

Checked current

6 October 2026, Federal Register: latest version on 6 October 2026

Who it applies to

Registered NDIS providers, every profession. Unregistered providers are not bound by these Rules.

Under review, not in force

Civil penalties were raised and new offences added by the latest amendments; the plan management changes start on proclamation. The provisions this product cites are in force.

ss 73Y and 73ZIncident management system and reportable incident notificationsource
Requirement, our statement of the clause

A registered provider implements and maintains an incident management system appropriate to its size and supports and meeting the NDIS (Incident Management and Reportable Incidents) Rules 2018, and notifies and manages reportable incidents as those rules prescribe. Reportable incidents are the death of, serious injury to, abuse or neglect of, unlawful sexual or physical contact with or assault of a person with disability, sexual misconduct against or in the presence of them (including grooming), and use of a restrictive practice other than in accordance with a State or Territory authorisation. The Commissioner may require the provider to inform people of their right to an advocate, and to fund an independent investigation and give the report to the Commissioner.

Evidence that typically shows this
  • Incident management system documents and incident register
  • Reportable incident notifications with timestamps against the rule timeframes
  • Independent investigation reports where required by the Commissioner
Common gap to check
  • Unauthorised restrictive practices not recognised as reportable
  • Late notifications
Worksheet: what your practice holds, and where
RefHeld (yes, partly, no, not applicable)Where it is keptOwnerLast reviewedNext review
ss 73Y and 73Z

Completing this worksheet records what your practice holds and where. It does not make a practice compliant or ready for audit, and it is not legal advice.

Related requirements

See every requirement for your practiceSee the specimen practice