FOI 24/25-1367 - DISCLOSURE LOG
DOCUMENT 8
The contents of this document are OFFICIAL.
Participant Critical Incident Framework
The National Disability Insurance Agency (NDIA) recognises that people with disability, can be particularly vulnerable to harm including abuse, neglect and exploitation. While working with participants, their families and carers, NDIA, National Contact Centre (NCC) and Partner (inclusive of ECEI and LAC) staff may encounter circumstances or obtain information about allegations of serious harm or abuse.
The Participant Critical Incident Framework (the Framework) is designed to assist NDIA, NCC and Partner staff to determine the necessary and appropriate actions required to respond to participant critical incidents.
This Framework is underpinned by the principles that people with disability have the same right as other members of Australian society to have respect for their worth, privacy and dignity and to live free from abuse, neglect and exploitation. In regard to children and young people with disability, the best interests of the child or young person are paramount, and full consideration should be given to the need to protect the child or young person from harm.
The Framework compliments the broader NDIA Issues and Incident Management Framework, which uses a risk based approach to provide overarching guidance for managing issues and incidents in a consistent and methodical manner.
1. Checklist
| Topic | Checklist |
|---|---|
| Pre-requisites | You have: |
- Received a report of a Participant Critical Incident. | | Actions | - [ ] 3.1 About Participant Critical Incidents
- 3.2 NDIA responsibilities related to participant critical incidents
- 3.3 Responding to participant critical incidents |
Page 42 of 498
FOI 24/25-1367 - DISCLOSURE LOG
2. Procedure
2.1 About Participant Critical Incidents
There are a number of different types of incidents that may be notified to the NDIA, however this framework focuses on critical incidents (defined in part 3.1 of this framework, below) related to participants.
Anyone can contact the NDIA to make a notification of a participant critical incident including, but not limited to:
- NDIS participants
- Family members or friends of participants
- Informal carers
- Providers of NDIS services
- Advocates
- Members of the public
- Government and other mainstream services
- Partners in the Community
- Health professionals
- Parliamentarians
NDIA staff may also report incidents where, for example, they have observed or been advised of a situation that they believe constitutes a critical incident during the course of interacting with a participant and/or their family members, informal carers or providers.
NDIA, NCC and Partner staff receiving notification of a critical incident must undertake an initial assessment of the situation to ensure the participant and/or person/s involved are not in immediate danger. If a participant or other person/s are in immediate danger or require immediate medical assistance NDIA, NCC and Partner staff receiving the notification must advise the notifier to contact 000 for immediate Police or Ambulance assistance as soon as possible. If the notifier is unable to contact 000, NDIA, NCC and Partner staff receiving notification of the incident must call 000 as soon as possible for immediate assistance.
NDIA, NCC and Partner staff receiving notification of a participant critical incident must commence any emergency action immediately, any internal reporting must occur within 24 hours after any initial immediate emergency responses are actioned.
Page 43 of 498
FOI 24/25-1367 - DISCLOSURE LOG
2.1.1 What is a participant critical incident?
A report of a participant critical incident is any information provided to the NDIA, NCC and Partner staff that alleges that an event occurred involving:
- Unexpected death of a National Disability Insurance Scheme (NDIS) participant, or a death that occurs in connection with the provision of NDIS supports or services.
- Serious injury of an NDIS participant.
- Abuse or neglect of an NDIS participant.
- Unlawful sexual or physical contact with, or assault of, an NDIS participant.
- Sexual misconduct committed against, or in the presence of, an NDIS participant, including grooming of the NDIS participant for sexual activity.
- Unauthorised use of a restrictive practice in relation to an NDIS participant.
- A NDIS participant threatening or attempting self-harm or suicide.
A participant critical incident allegation may involve any stakeholder including NDIS providers, NDIA staff, informal supports, family or other person.
Participant: A person becomes a participant in the NDIS once the CEO determines that they satisfy the access criteria. This means that access has been met. Source: National Disability Insurance Scheme Act 2013 (NDIS Act) s28.
- Reportable Incidents
Registered NDIS providers in all States and Territories, are required to notify reportable incidents that relate to services and provisions provided by a registered provider, to the NDIS Quality and Safeguards Commission, under s73Z of the NDIS Act and Part 3 of the NDIS (Incident Management & Reportable Incidents) Rules 2018. For further information about participant critical incidents which are notifiable to the NDIS Quality and Safeguards Commission, visit the NDIS Quality and Safeguards Commission web page.
All notifiable participant critical incidents, that meet the definition of Reportable Incidents, will be referred to the NDIS Quality and Safeguards Commission to allow them to seek a notification from the registered NDIS Provider. Other NDIA, NCC and Partner staff should not make direct referrals to the NDIS Quality and Safeguards Commission in regards to any participant critical incident, they should notify the Participant Critical Incident (PCI) staff who will pass the details to the NDIS Commission.
Page 44 of 498
FOI 24/25-1367 - DISCLOSURE LOG
The NDIS Quality and Safeguards Commission can only accept notifications of reportable incidents from Registered NDIS Providers. Participant Incidents involving unregistered providers can be referred to the NDIS Commission to be dealt with as complaints about the provider.
2. Participant Critical Incident Examples
| Incident Category | Example (not exhaustive) |
|---|---|
| Unexpected death of a participant that occurs in connection with the provision of NDIS supports or services | Report of a death where its circumstances or cause are medically or legally unexplained. This can occur (but not limited to) in the context of medical care, suicide, neglect or suspected criminal activity. |
| Serious injury of a participant | Report of a reckless or intentional act which has caused injury to a participant such as a fracture, contusion, wound, burn or concussion. Report of a participant being physically assaulted by a carer, support person, family member or member of the community which causes serious harm or injury. Report of serious injury of a participant whilst receiving NDIS supports |
| Abuse or neglect of a participant | Report of a family member, carer or support person denying food to a participant as ‘punishment’. Allegation of a participant being subject to use of offensive, abusive, or demeaning language by a support. Observation or notification of a family member, carer or support person threatening harm to a participant. Report of a participant being financially exploited. Abandonment of a Participant. |
| Unlawful sexual or physical contact with, or assault of, a participant | Observation of inappropriate physical contact between a carer or a support person and person with disability. Report of sexual assault of a participant. |
Page 45 of 498
FOI 24/25-1367 - DISCLOSURE LOG
| Incident Category | Example (not exhaustive) |
|---|---|
| Report of a participant being physically assaulted by a carer, support person or family member, or member of the community. | |
| Sexual misconduct committed against, or in the presence of, a participant, including grooming of such a person for sexual activity | Report of a rape or sexual assault of a participant. Observation of sexual conduct in the presence of a participant. Report a person developed a relationship with a participant with the intent of facilitating the participant’s involvement in sexual conduct, either with themselves or another adult. This does not necessarily involve any sexual activity or even discussion of sexual activity and may only involve establishing a relationship for the purpose of facilitating sexual activity at a later time. |
| Unauthorised use of a restrictive practice in relation to a participant | Report of use of restrictive practices (seclusion, chemical, mechanical, physical, environmental, psycho-social) without an authorisation where the relevant State or Territory has an authorisation process. Observation of a family member or support secluding or restraining the person with disability. |
| Participant self-harm or suicide | Report of participant threatening self-harm or suicide. Report a participant has self-harmed or attempted suicide. This refers to a specific event and does not include progressively escalating behaviours of concern. |
2.1.2 Other types of incidents
There are many other types of incidents that fall outside the scope of this framework and have their own reporting and management channels. Staff and managers should consider business
Page 46 of 498
FOI 24/25-1367 - DISCLOSURE LOG
and non-business disruption events and be aware of other frameworks/reporting systems that relate to these other types of incidents or refer to below table for examples.
There may be times when an incident fits the criteria of both participant critical incident and other types of incidents. Steps should be taken to ensure all streams of incident reporting are engaged and linked, for example- contacting the security team, WHS team and also notifying the PCI staff.
- Other incidents and response pathways
| Incident Type | Example | Agency Response Pathway or Further Information |
|---|---|---|
| Security | Loss or compromise of information. Unauthorised access, including tailgating. Theft of departmental and personal assets. Verbal or physical abuse. Damage or vandalism to buildings. All Duress Alarm activations (including false activations). |
All security incidents should be reported to the NDIA Protective Security Team either by phone or using the NDIA Security Incident Report Form on the Security Incident Reporting page. Refer to the Privacy Incident Escalation Protocol for privacy incidents. |
| Abuse, aggression or escalating behavior toward staff or Partners | Aggressive acts, verbal abuse, derogatory, racist or defamatory remarks, harassment, intimidation or violence. Rude, confronting and threatening correspondence or behaviour. Threats to harm third parties, damage property or stalking. |
Managing Unreasonable Behaviour Guidelines. Security Incident Reporting page. |
| Business Continuity/Resilience | Loss of access to building(s). Utility outages. |
Issues and Incident Management Framework. |
Page 47 of 498
FOI 24/25-1367 - DISCLOSURE LOG
| Incident Type | Example | Agency Response Pathway or Further Information |
|---|---|---|
| ICT outages. Loss of staff. |
NDIA Business Continuity Management Policy. | |
| Work, Health and Safety | Injury/Illness- slips, trips, falls, spills. Near Miss. Equipment/Property Damage. Comcare Notifiable incidents. |
Report an Incident. Incident Reporting and Investigation Procedure. |
| Employee Relations Incidents | Any participant critical incident relating to employee behaviour and the Agency code of conduct which is reported to the Employee Relations team, in addition to PCI staff. | For further see the People and Culture intranet page |
| Legal | AAT or other notices setting out that legal proceedings are being contemplated or have been lodged. | Email Legal Team |
| Privacy | Privacy complaint by a participant or allegation of a breach of privacy involving a participant. Data breach, unauthorised disclosure or loss of personal information |
Email Privacy or see the Privacy incident escalation protocol |
| Technical Advisory Branch | For significant participant behaviour of concern and/or notice of use of restricted practices (unauthorised and authorised). | See intranet page, email Technical Advisory Team or contact redacted: s47E(d) - certain operations of agencies@ndis.gov.au. |
Page 48 of 498
FOI 24/25-1367 - DISCLOSURE LOG
| Incident Type | Example | Agency Response Pathway or Further Information |
|---|---|---|
| Note: Unauthorised use of restrictive practices will need to be notified to PCI staff as a participant Critical Incident. They will also notify TAB. |
2.1.3 Deciding if an incident is a critical incident or another type of incident
There are times when it is not easy to decide if an incident is critical or related to another type of security or work, health and safety matter. The best course of action is to speak with the PCI staff and explore the option that best fits the incident circumstances. The PCI staff will provide advice and guidance on which category the incident may fall under and will escalate incidents to the appropriate area for action.
Key questions to consider include but are not limited to:
- Was there a specific event that happened?
- Does the allegation relate to a participant being harmed or at risk of harm from the actions of others?
- Who is alleged to have harmed the participant, is it a provider, informal support or other person/s?
- Is the participant threatening, abusing or being aggressive toward others?
- What is the nature of the allegation?
- Where and when did the alleged incident occur?
- Is there an indication of self-harm or attempt of suicide?
- Is there an indication the participant might be neglected by a provider or informal support?
2.2 NDIA responsibilities related to participant critical incidents
The NDIA has responsibilities related to participant critical incidents that may include:
- Reporting to responsible authorities where incident circumstances indicate emergency or urgent services;
Page 49 of 498
FOI 24/25-1367 - DISCLOSURE LOG
- Notifying the NDIS Quality and Safeguards Commission for further involvement; and
- Considering any implications for the participant’s NDIS plan (having regard to the scope of the NDIS legislation and the obligations of other service systems as agreed by Governments).
- To resolve and close participant incidents within 21 days of receiving the report.
When responding to participant critical incidents and when considering the release of information, all NDIA, NCC and Partner staff are required to comply with the provisions in the NDIS Act that relates to ‘protected agency information’ and the provisions of the Privacy Act 1988 (Privacy Act) which relates to ‘personal information’ and ‘sensitive information’. Further information can be found in the Agency’s Information Handling Operational Guideline, the Privacy Policy or by contacting the Legal support team.
- Other reporting requirements
Reporting a notification of a participant critical incident to the PCI staff does not negate State and Territory requirements, policies and guidelines. NDIA, NCC and Partner staff notified of critical incidents may disclose information to relevant authorities if the consent of the individual is obtained (s 60(2)(d)(iii) of the NDIS Act 2013) or if NDIA, NCC and Partner staff believes on reasonable grounds that the disclosure is necessary to prevent or lessen a serious threat to an individual’s life, health or safety (s 60(2)(e) of the NDIS Act 2013). If the Participant is at risk of immediate harm or danger contact 000 immediately. Further information regarding State and Territory reporting requirements, including child protection can be found in the Practice Guide – Participant Critical Incident or on State and Territory reporting webpages, see Australian Institute of Family Studies website.
- Investigating incidents
The NDIA, NCC and Partner staff are generally not responsible for conducting an investigation into the allegation. Depending on the allegation, a police investigation may be appropriate, or the NDIS Quality and Safeguards Commission may investigate incidents relating to a registered provider. NDIA, NCC and Partner staff should ensure the participant is safe and appropriate disability related supports are in place. However, there may also be instances where the allegation relates to NDIA or Partner in the Community staff, where an internal response is required.
Page 50 of 498
FOI 24/25-1367 - DISCLOSURE LOG
2.3 Responding to participant critical incidents
Whenever a staff member obtains information which may indicate a participant critical incident the staff member must contact their line manager in the first instance or the PCI staff for advice on appropriate action related to the incident.
If the Participant is at risk of immediate harm or danger contact 000. At times the relevant line manager may be consulted or advice may be sought from the legal team. Internal reporting must occur within 24 hours after any initial immediate emergency responses are actioned (refer to Standard Operating Procedure – Initial response to a Participant Incident Notification).
NDIA, NCC and Partner staff must:
- Refer to the process in this framework (section 4.1), in conjunction with the standard operating procedure/s, when responding to participant critical incidents;
- Apply the principles and approaches suggested in the practice guide, when responding to allegations;
- Consult your (a) line manager, noting the value of shared decision making in difficult situations, and for assistance to determine the most appropriate frontline response and escalation pathway; and
- Ensure conversations consider a person’s vulnerability and take appropriate steps to take account of that vulnerability in any dealings, making decisions and developing relationships.
The Principles for responding to participant critical incidents can be found in the Practice Guide- Participant Critical Incidents.
These principles include, but are not limited to:
- Involve the relevant emergency service if there is risk of immediate harm.
- Understand the responsibilities of the NDIA in relation to participant critical incidents, as outlined in the framework and supporting material.
- Participants should be involved in matters affecting them Support people with concerns to contact relevant authorities directly.
- Be aware of and comply with the requirements of the Privacy Act 1988 and NDIS Act 2013.
- Speak with a manager and relevant internal stakeholders for advice.
Page 51 of 498
FOI 24/25-1367 - DISCLOSURE LOG
- Consider any changes needed to the participant’s plan or other supports.
- Document details and decision making.
- Debrief and seek support - receiving a notification of a participant critical incident may be confronting and distressing, if you require support after receiving a participant critical incident, you can seek support from your (a) line manager, or from your companies Employee Assistance Program. All staff (APS and Labour Hire workers) and their eligible family members have access to support through the Agency’s Employee Assistance Program provider TELUS Health. This means all Agency staff will have access and support from the same Employee Assistance Program, including counselling services (12 sessions, per issue, per year). To find out more about the services TELUS Health Offers and contact details, please visit Employee Assistance Program intranet page. Additionally, Labour Hire workers have access to EAP services through their Labour Hire Agency. More information can be found on the Employee Assistance Program intranet page.
2.3.1 Participant Critical Incident Process
The Participant Critical Incident Process broadly includes four key stages:
- Initial Response
- Internal Notification
- Follow Up Action
- Closure and Reporting
Refer to the Practice Guide - Participant Critical Incidents for further information and considerations throughout each stage.
- Initial Response
The first stage of the participant critical incident process relates to receipt of the incident allegation ensuring the participant is safe, supported and undertaking any necessary emergency response.
If the Participant is at risk of immediate harm or danger contact 000. While you may wish to consult your line manager or seek advice from legal in some circumstances, this is not a prerequisite.
Page 52 of 498
FOI 24/25-1367 - DISCLOSURE LOG
The person reporting the matter should be encouraged to contact any authorities directly themselves, however the incident report will need to be documented and submitted. The Standard Operating Procedure – Initial response to a Participant Incident Notification includes a key contacts list which can be used to find appropriate emergency response points when receiving notification of incidents.
Key Document:
- Standard Operating Procedure - Providing an Initial Response to a Participant Critical Incident.
- Participant Critical Incident Form
- Internal Notification
With the initial response provided, this stage relates to gathering and documenting available information and internal notification of the incident to the Escalations and Participant Incident Team, including completion, submission and assessment of the participant critical incident form, within 24 hours after any initial immediate emergency responses are actioned. This should be undertaken by the team who receives the report of the incident immediately, and be detailed and factual, without judgement or drawing conclusions. Staff should always consult with a line manager as part of this stage of the incident process. The completed Participant Critical Incident Form is sent via email to Participant Incidents Team with the subject line: Participant Critical Incident Report. Do not record any details of the incident on the CRM Business System. If the Participant record is mastered in PACE, please see the Just In Time resources for instructions for a PCI Case in PACE.
The Participant Critical Incident Team is responsible for entering the incident in CRM and will acknowledge the referral with the team who has provided the information.
Key Document:
- Standard Operating Procedure - Internal notification of a Participant Critical Incident.
- Participant Critical Incident Form
- Follow Up Action
The PCI staff are responsible for reporting participant critical incidents that meet the criteria for a reportable incident to the NDIS Quality and Safeguards Commission.
NDIA, NCC and Partner staff, are responsible for referral or reports to internal and external stakeholders and engaging with the participant, their nominee or other
Page 53 of 498
FOI 24/25-1367 - DISCLOSURE LOG
parties, as well as examining and, where appropriate, adjusting the plan and funded supports.
Key Document:
- Closure and Reporting
This stage ensures that all follow up actions have been progressed and, where possible, finalised. Service Delivery and enabling areas are responsible for providing the PCI staff with an email sumarising actions and outcomes of follow up actions.
The PCI staff will ensure follow up actions are clearly and appropriately documented in their off system tracker and all emails and key documents are stored in accordance with agency record keeping requirements.The PCI staff will close the CRM my requests tile once the matter is considered finalised. Should Agency staff require detiled information regarding the outcome, they should request this via redacted: s47E(d) - certain operations of agencies@ndis.gov.au.
Incidents will be resolved and closed within 21 days of the Participant Incident report being received by the PCI staff.
The PCI staff will ensure that the matter is finalised, as well as undertaking reporting to applicable Senior Executives.
Key Document:
3. Related procedures or resources
- Standard Operating Procedure - Providing an Initial Response to a Participant Critical Incident
- Standard Operating Procedure – Initial response to a Participant Incident Notification
- Standard Operating Procedure - Internal notification of a Participant Critical Incident
- Standard Operating Procedure – Undertaking follow up action for a Participant Critical Incident
Page 54 of 498
FOI 24/25-1367 - DISCLOSURE LOG
- Standard Operating Procedure — Closure and Reporting of a Participant Critical Incident
- Participant Critical Incident Form
4. Feedback
If you have any feedback about this Framework, please email CPIT Business Improvement Team. In your email remember to include the title of the product you are referring to and describe your suggestion or issue concisely.
5. Version control
| Version | Amended by | Brief Description of Change | Status | Date |
|---|---|---|---|---|
| 2.0 | EGS121 | Endorsement of Framework | APPROVED | 2019-12-20 |
| 2.1 | EGS121 | Accessibility Changes | APPROVED BC0038 |
2020-01-06 |
| 2.2 | EGS121 | Initial 3 month review and update | APPROVED BGW312 |
2020-03-06 |
| 2.3 | MWN756 | Move to new template and check accessibility | DRAFT | 2021-07-07 |
| 3.0 | SGN258 | Updated document links and terminology. Reviewed by HSP875. |
APPROVED BGW312 |
2021-08-19 |
| 3.1 | HSP875 | Reviewed by HSP875 to amend following audit recommendations | APPROVED Y4O |
2022-08-08 |
| 3.2 | TEM907 | Accessibility check, updated document links and terminology | 2023-05-23 | |
| 3.3 | MP0075 | To update all Labour Hire workers now have access to the full suite of EAP supports through TELUS Health | NGC832 | 2024-04-23 |
Page 55 of 498