Published 23 July 2026. Last updated 23 July 2026. By Aaron Price, Founder of Wyzed.
In short: NDIS compliance means meeting the obligations set by the NDIS Quality and Safeguards Commission — being registered where required, meeting the NDIS Practice Standards, following the NDIS Code of Conduct, screening and training your workers, managing incidents and complaints, handling restrictive practices correctly, and keeping the records to prove all of it. This guide walks through each requirement in plain English, current to the 2026 reforms, so you know exactly what is expected of your organisation.
Quick answer: The core NDIS compliance requirements for providers are: register with the NDIS Commission where required; meet the NDIS Practice Standards; comply with the NDIS Code of Conduct; complete worker screening and mandatory worker orientation; run incident-management and complaints-management systems; manage restrictive practices and behaviour support correctly; drive continuous improvement; pass quality audits; and keep records (commonly for seven years). These are overseen by the NDIS Quality and Safeguards Commission — not the NDIA.
Who regulates NDIS compliance?
This is the single most-confused point in NDIS compliance, so it is worth getting right first. Two separate bodies are involved, and they do different jobs:
The NDIS Quality and Safeguards Commission is the independent regulator. It runs provider registration, sets and enforces the Practice Standards and Code of Conduct, manages worker screening, oversees complaints and incidents, and takes compliance and enforcement action. When people talk about "NDIS compliance," this is the body they mean.
The National Disability Insurance Agency (NDIA) administers the scheme itself — participant plans, funding and pricing. It does not regulate provider quality or conduct audits.
So compliance obligations, audits and enforcement all sit with the Commission, not the NDIA. Getting this distinction right matters, because much of the advice online (including from law firms and other vendors) blurs the two.
NDIS registration
Registration is the first requirement for many providers. You must be registered with the NDIS Commission if you deliver certain supports — including Specialist Disability Accommodation, specialist behaviour support, supports involving regulated restrictive practices, and supports to participants whose plans are NDIA-managed.
The 2026 change to know: from 1 July 2026, registration became mandatory for Supported Independent Living (SIL) providers and NDIS digital platform providers — the first stage of a broader phased rollout. The transition matters if you already deliver SIL: a provider operating SIL unregistered as at 1 July 2026 may keep delivering it while its application is processed, but only if it lodges a valid registration application by 1 October 2026 — after that date it must stop. New SIL providers get no grace period and cannot deliver SIL until registration is granted. Operating SIL without registration is a serious offence, carrying a maximum penalty of two years' imprisonment, a fine of 120 penalty units, or both. Check the Commission's mandatory registration reform hub for current staging. (Mandatory registration for support coordination, once floated for this stage, has been paused.)
The NDIS Practice Standards
The NDIS Practice Standards are the benchmark your organisation is audited against. A common mistake is to treat the "core" outcomes as the whole framework — they are not. The Standards are built in modules:
The Core Module applies to every registered provider and covers four outcome areas: rights and responsibilities; provider governance and operational management; the provision of supports; and the provision of supports environment.
Supplementary modules apply depending on the supports you deliver — for example high-intensity daily personal activities, specialist behaviour support, implementing behaviour support plans, early childhood supports, specialist disability accommodation, and — in force from 1 July 2026 — a supported independent living (SIL) module covering supported decision-making, safeguarding, practice governance, and agreements about tenancy, housing and support arrangements.
The Verification Module applies to lower-risk providers, covering the essentials: human resource management, risk management, complaints management and incident management.
Each standard has outcomes you must achieve and quality indicators an auditor assesses you against. Which modules apply to you depends entirely on your registration groups — so the first step is knowing which modules you are actually measured on.
The NDIS Code of Conduct
The NDIS Code of Conduct sets the standard of behaviour expected of every provider and worker — and importantly, it binds both registered and unregistered providers. It requires you to:
respect individual rights to freedom of expression, self-determination and decision-making
respect the privacy of people with disability
provide supports safely and competently, with care and skill
act with integrity, honesty and transparency
promptly raise and act on concerns about quality and safety
take all reasonable steps to prevent and respond to violence, exploitation, neglect and abuse
take all reasonable steps to prevent and respond to sexual misconduct
Every worker should understand these obligations — which is why training and induction are part of meeting them.
Worker screening
Every worker in a "risk-assessed role" — and every member of your key personnel — must hold a current NDIS Worker Screening Check. The check is a national clearance, valid for five years, and providers must keep a record of each worker's clearance and make sure it does not lapse. An expired clearance is a genuine compliance risk, not an administrative footnote.
The Worker Orientation Module
Beyond screening, there is one nationally mandated piece of training: the NDIS Commission's Worker Orientation Module, "Quality, Safety and You." Every worker delivering NDIS supports for a registered provider is expected to complete it. It is the floor, not the ceiling — you still need role-specific and refresher training on top.
Incident management and reportable incidents
Registered providers must have an incident management system — a documented process for identifying, managing and resolving incidents. Within that, certain reportable incidents must be notified to the Commission within set timeframes:
Within 24 hours: the death of a participant, serious injury, abuse or neglect, unlawful sexual or physical contact, and sexual misconduct.
Within 5 business days: the use of an unauthorised or non-compliant restrictive practice (note that if the same incident also caused, for example, serious injury, it separately triggers the 24-hour categories above).
Being able to show an incident's full trail — reported, actioned, resolved — is exactly what an auditor looks for.
Complaints management
Providers must operate a complaints management and resolution system: a clear, accessible way for participants and others to raise concerns, and a documented process for responding to them. It is a condition of registration, assessed under the Practice Standards, and auditors will ask to see both the system and evidence it is used.
Restrictive practices and behaviour support
If you deliver supports involving regulated restrictive practices, additional obligations apply. Their use must be authorised in line with state or territory requirements and set out in a behaviour support plan, and any unauthorised use is a reportable incident. Providers implementing behaviour support plans have different obligations from specialist behaviour support providers who develop them — know which role you hold, and report authorised use as required.
Continuous improvement
Continuous improvement is not just good practice — it is a Practice Standards requirement. You must be able to show that you identify issues, act on them, and improve over time: a live continuous-improvement register with evidence that things actually changed, not a document that sits untouched between audits.
Quality audits
Compliance is verified through quality audits, conducted by independent Approved Quality Auditors and overseen by the Commission. Lower-risk providers undergo a verification audit (a desktop review); higher-risk providers undergo a certification audit (a two-stage process including an onsite assessment), with a mid-term audit around the halfway point of the registration period. For the full detail on preparing, see our guide on how to prepare for an NDIS audit.
Record-keeping
Underpinning all of the above is record-keeping. You must keep accurate records — participant files, worker screening and training records, incident and complaints records, and financial records — and retain them for the required period (commonly seven years). If you cannot produce the record, you cannot prove the compliance.
Non-compliance and enforcement
The Commission has a graduated enforcement toolkit, from education and guidance through to compliance notices, enforceable undertakings, civil penalties, banning orders, and suspension or revocation of registration. Under the National Disability Insurance Scheme Amendment (Integrity and Safeguarding) Act 2026, banning orders have been extended beyond providers and workers to cover auditors, consultants and advisers. Non-compliance is not just a paperwork risk; it can end an organisation's ability to operate.
What is changing in NDIS compliance in 2026
The compliance landscape is shifting. The key changes to plan for:
Mandatory registration for SIL and NDIS digital platform providers from 1 July 2026, with existing unregistered SIL providers needing to lodge an application by 1 October 2026 to keep operating.
A new SIL Practice Standard, now in force for SIL providers, covering supported decision-making, safeguarding, practice governance, and tenancy, housing and support agreements.
Broader banning orders — under the National Disability Insurance Scheme Amendment (Integrity and Safeguarding) Act 2026, banning orders now reach beyond providers and workers to auditors, consultants and advisers.
A shift toward continuous, real-time compliance monitoring rather than relying solely on point-in-time audits — which raises the bar on keeping evidence current all year, not just before an audit.
Where training and evidence fit
Training and evidence are not a separate topic — they are how you meet several of the requirements above. Worker screening records, the mandatory orientation module, role-based training, incident trails and audit evidence all have to be current and retrievable. Doing that manually across a workforce is where providers lose the most time, which is why many automate it with a purpose-built NDIS learning system: you add an employee once and it onboards them, trains them for their role, and keeps them compliant from then on, without ongoing admin. For the detail, see the essential LMS features for NDIS compliance and how to keep your staff audit-ready.
Managing this evidence in practice? Compare the best LMS for NDIS providers and see how the options stack up in Wyzed vs DSC.
Frequently asked questions
Who regulates NDIS compliance — the NDIA or the NDIS Commission?
The NDIS Quality and Safeguards Commission regulates provider compliance — registration, the Practice Standards, the Code of Conduct, worker screening, incidents, complaints and enforcement. The NDIA administers participant plans, funding and pricing, and does not conduct audits or regulate provider quality.
What are the main NDIS compliance requirements for providers?
Registration where required, meeting the NDIS Practice Standards, following the Code of Conduct, worker screening and mandatory orientation, incident and complaints management systems, correct handling of restrictive practices, continuous improvement, passing quality audits, and keeping records — all overseen by the NDIS Commission.
Does the NDIS Code of Conduct apply to unregistered providers?
Yes. The NDIS Code of Conduct binds both registered and unregistered providers and their workers. It sets the expected standards of behaviour — respecting rights and privacy, acting safely and with integrity, and preventing violence, exploitation, neglect, abuse and sexual misconduct.
How long is an NDIS Worker Screening Check valid?
An NDIS Worker Screening Check is valid for five years. Providers must keep a record of each worker's clearance and ensure it is renewed before it expires, as an expired clearance is a compliance risk.
What happens if an NDIS provider is non-compliant?
The Commission can respond with education, compliance notices, enforceable undertakings, civil penalties, banning orders, and suspension or revocation of registration. Under the 2026 Integrity and Safeguarding Act, banning orders now extend beyond providers and workers to auditors, consultants and advisers.
What is changing in NDIS compliance in 2026?
From 1 July 2026, registration is mandatory for SIL and NDIS digital platform providers — existing unregistered SIL providers must lodge an application by 1 October 2026 to keep operating. A SIL Practice Standard is now in force, banning orders have broadened to auditors and advisers, and the Commission is moving toward continuous compliance monitoring.
How often are NDIS providers audited?
Registration typically runs for three years. Higher-risk (certification) providers also have a mid-term audit around the halfway point, plus any out-of-cycle audits the Commission directs if a compliance concern arises.
About the author
Aaron Price is the founder of Wyzed, the LMS purpose-built for NDIS providers. He has worked with more than 300 Australian disability service providers on making staff training simple, customisable and audit-ready, and writes about NDIS compliance, workforce training and choosing the right tools for the sector. Connect with Aaron on LinkedIn.
Sources
NDIS Quality and Safeguards Commission. "NDIS Practice Standards." ndiscommission.gov.au
NDIS Quality and Safeguards Commission. "NDIS Code of Conduct." ndiscommission.gov.au
NDIS Quality and Safeguards Commission. "Worker screening." ndiscommission.gov.au
NDIS Quality and Safeguards Commission. "Reportable incidents and incident management." ndiscommission.gov.au
NDIS Quality and Safeguards Commission. "Compliance and enforcement." ndiscommission.gov.au
NDIS Quality and Safeguards Commission. "Mandatory registration reform hub." ndiscommission.gov.au




