Responses to Questions on Notice

‹ PrevPage 1 of 28 · Source p. 1Next ›

NDIS Quality and Safeguards Commission

Joint Committee of Public Accounts and Audits

Responses to Questions on Notice

Background

On 27 November 2025, the Joint Committee of Public Accounts and Audit resolved to conduct an inquiry into the administration of the National Disability Insurance Scheme.

The Committee will examine the National Disability Insurance Agency’s (NDIA) delivery of the National Disability Insurance Scheme (NDIS) with reference to the management of financial sustainability risks and claimant and provider compliance with NDIS claim requirements; and the monitoring, measurement and reporting of NDIA performance.

The Committee will also examine the regulatory performance of the NDIS Quality and Safeguards Commission (NDIS Commission), and the Department of Health, Disability and Ageing’s policy advice to the government.

The inquiry will have particular regard to any matters contained in or connected to the following Auditor-General reports:

  • Auditor-General Report No. 22 2024-25 Audits of the Financial Statements of Australian Government Entities for the Period Ended 30 June 2024
  • Auditor-General Report No. 25 2024-25 Performance Statements Auditing in the Commonwealth—Outcomes from the 2023-24 Audit Program
  • Auditor-General Report No. 39 2024-25 Interim Report on Key Financial Controls of Major Entities
  • Auditor-General Report No. 41 2024-25 Effectiveness of the Board of the National Disability Insurance Agency
  • Auditor-General Report No. 48 2024-25 National Disability Insurance Agency’s Management of Claimant Compliance with National Disability Insurance Scheme Claim Requirements
  • Auditor-General Report No. 2 2025-26 Effectiveness of the NDIS Quality and Safeguards Commission’s Regulatory Functions.

The NDIS Quality and Safeguards Commission appeared before the Joint Committee of Public Accounts and Audit on Thursday, 23 April 2026 and received the following Questions on Notice [Spoken and Written].

Contents Page

Ref No Topic Type Page
SQ26-000120 Quarterly Performance Report Spoken 1
SQ26-000121 Trends in data Spoken 2
SQ26-000122 Complaints vs Compliance Spoken 4
SQ26-000123 Complaints linked to providers based on size Spoken 5
SQ26-000124 Complaints data on SIL providers Spoken 6
SQ26-000125 Role of registration in quality of service and safeguarding participants Spoken 8
SQ26-000126 Regulatory Risk Framework Spoken 10
SQ26-000127 Increase workload in mandatory registration Spoken 12
SQ26-000128 Identify strategic regulatory priorities Spoken 13
SQ26-000129 Payment arrangements for self-managed participants Written 16
SQ26-000130 Quality assurance processes Written 17
SQ26-000131 Intelligence gathering Written 18
SQ26-000132 Strategies to support compliance activities Written 19
SQ26-000133 Monitoring, compliance and enforcement activities Written 21
SQ26-000134 NDIS review Written 23
SQ26-000135 Compliance actions Written 24

Answer to Question on Notice Reference: SQ26-000120

Quarterly Performance Report

Hearing: 23 April 2026 Hansard Page: Spoken

Asked by: Mr Josh Burns MP

Question:

CHAIR: I’m just going to ask one or two more questions. Do you do these quarterly reports every quarter?

Ms Sham: Yes.

CHAIR: How long have you done them for?

Ms Sham: I believe over a year, but I would need to take that on notice.

Answer:

The NDIS Quality and Safeguards Commission has produced a quarterly report since the January to March quarter of 2022.

1

Answer to Question on Notice Reference: SQ26-000121

Trends in data

Hearing: 23 April 2026 Hansard Page: Spoken

Asked by: Mr Josh Burns MP

Question:

Chair: I’d be interested in if you’re noticing major changes or trends that are happening as part of those quarterly reports, or if it remains pretty consistent. If you can provide that to the committee, that would be really useful.

Answer:

The NDIS Quality and Safeguards Commission (NDIS Commission) publishes a Quarterly Performance Report (QPR) with a focus on measuring outcomes for NDIS participants and assessing regulatory impact. The latest QPR is available here.

Complaints

Complaints received per quarter has increased steadily since the commencement of quarterly reporting in 2022. Despite the increase in complaints received, the distribution of complaints by theme has been largely consistent, with “Provider practice” consistently having the largest share with around 35% - 40% most quarters. “Worker conduct and capability” follows with around 25%, “Provider policies or procedures” around 18%, “Others” around 10%, and “Alleged abuse or neglect” having the smallest share consistently with around 5% - 8%.

Compliance

Over time the NDIS Commission has shown a significant and sustained increase in statutory actions, with the most recent QPR showing record-high statutory actions in a single quarter:

  • 95 Banning orders
  • 117 Registration revocations
  • 179 Compliance notices

Reportable Incidents

  • Although the count of reportable incidents has risen over time, the proportion of affected participants has remained stable (0.74%–0.89%), indicating that the increase is largely driven by scheme growth.
  • Serious Injury is consistently the highest proportion of incident by type (~34%), followed by Neglect (~25%) and Abuse (~15%).

2

Provider registration

  • The count of registered providers has increased steadily in the last two years, from around 16,600 in December 2023 to around 26,200 in December 2025.

Worker Screening

  • Worker screening has grown steadily, with around 7% increase per quarter for applications submitted and total clearances.

3

Answer to Question on Notice Reference: SQ26-000122

Complaints vs Compliance

Hearing: 23 April 2026 Hansard Page: Spoken

Asked by: Ali France MP

Question:

Ms France: Firstly, do you have data of the number of complaints against providers and individuals, say, over a year, and how many of those had a compliant action that was taken after the complaint? You might have to take that on notice, but I’m just interested in the number of complaints and comparisons maybe between different years and what type of compliance action was taken or not taken as a result.

Ms Glanville: Thank you for that question. I think we’ll need to take that one on notice and collate that for you.

Ms France: No, that would be great, and also whether they came from where they came from, whether it was the NDIA, individual providers or whatever

Answer:

The NDIS Quality and Safeguards Commission [NDIS Commission] introduced the Risk Based Regulatory Prioritisation Model (RRPM) in July 2025, which has supported a more structured and consistent approach to assessing risk and identifying potential patterns, trends and emerging issues across the sector. While the NDIS Commission is continuing to build and mature its capability in this area, the RRPM has enabled greater consideration of intelligence aggregated from multiple matters, rather than relying solely on individual complaints as triggers for regulatory action.

In practice, this means that regulatory action may be informed by themes or trends identified across a number of complaints and reportable incidents, and not always directly connected to a specific complaint.

For example, in 2025 the NDIS Commission undertook a mealtime management regulatory campaign, informed by intelligence gathered from multiple complaints, reportable incidents and broader regulatory insights. While complaints received contributed to identifying the issue, the compliance activity was not attributable to a single complaint.

In the 2025 calendar year, the NDIS Commission received 30,983 complaints. In the same period 10,447 regulatory activities were completed to drive improved quality and safeguarding across NDIS supports and services. In 2025, 63-72% of Complaints were made by persons with disability or their support person per quarter, 23-28% were made by support workers or service providers, and 4-8% by Government bodies. Further detail is available in the Quarterly performance Reports available on the NDIS Commission website.

4

Answer to Question on Notice Reference: SQ26-000123

Complaints linked to providers based on size

Hearing: 23 April 2026 Hansard Page: Spoken

Asked by: Mr Josh Burns MP

Question:

CHAIR: To go back to Ali’s question, other than the observances of the general market, is there anything specific—maybe you can take this on notice—around the incoming of what you’re noticing around the complaints to big providers and small providers and whether or not there are any trends or information that you’re receiving as a commission that would indicate the nature of those complaints and whether or not there should be a focus on the smaller providers?

Answer:

The NDIS Quality and Safeguards Commission publishes a Quarterly Performance Report (QPR) with a focus on measuring outcomes for NDIS participants and assessing regulatory impact. The latest QPR is available here.

The report provides a breakdown of statistics by jurisdiction, gender and age. There are no statistics published that relate to provider size.

5

Answer to Question on Notice Reference: SQ26-000124

Complaints data on SIL providers

Hearing: 23 April 2026 Hansard Page: Spoken

Asked by: Carol Berry MP

Question:

Ms Berry: Likewise, we’re obviously about to start bringing on SIL providers as registered providers from 1 July, so could you provide on notice some information about whether or not, through your complaints information, you have concerns about those providers who are providing SIL services who have been unregistered and whether you’ve got a perspective on that.

Answer:

The NDIS Quality and Safeguards Commission (NDIS Commission) published its first Own Motion Inquiry (OMI) in January 2023, examining aspects of supported accommodation. The inquiry found poor-quality Supported Independent Living (SIL) supports and identified that participants were at greater risk of violence, abuse, neglect and exploitation when living in group settings and sharing supports. It examined approximately 7,000 incidents and complaints involving participants receiving services from seven NDIS providers between 1 July 2018 and 30 September 2022.

Key risks identified included:

  • Reduced choice and control over daily routines, who they lived with and support arrangements.
  • The aptitude and attitude of the workforce driving many issues in supported accommodation, including poor communication, inadequate support for autonomy and lack of evidence-based practices.
  • Higher incidents of violence, abuse, neglect and restrictive practices, with poor incident management and escalation
  • Shared living arrangements creating institutional and group home practices.
  • Interconnected housing and support arrangements with creating barriers for participants to change providers and exercise housing choice and control.
  • Limited participant voice and engagement, particularly with people with intellectual disability and communication barriers.

6

The NDIS Commission has also published a market spotlight report that analyses complaint themes. The analysis found that home and living supports accounted for 28% of all complaints received. Among complaints about home and living supports:

  • 25% of complaints related to SIL.

Of these complaints:

  • 46% related to poor quality, process and workforce
  • 31% related to violence, abuse and neglect
  • 13% to scheme integrity and,
  • 10% to participant rights and scheme principles

The introduction of mandatory registration of SIL and the SIL Practice Standards will ensure:

  • Adequate safeguard participants in high-risk SIL environments, particularly people with disability living in congregate care settings where there is heightened risk of violence, abuse, neglect and exploitation.
  • Strengthen the voice, rights and freedoms of people with disability in the way their SIL supports are delivered.
  • Address specific areas of the Core Module where further delineation of provider obligations needed, moving away from strictly compliance driven approaches to measurable, rights-informed competencies that deliver outcomes for participants.

7

Answer to Question on Notice Reference: SQ26-000125

Role of registration in quality of service and safeguarding participants

Hearing: 23 April 2026 Hansard Page: Spoken

Asked by: Carol Berry MP

Question:

Ms Berry As the Commission registers and regulates a greater proportion of the NDIS provider market, including previously unregistered providers, what value does provider registration add in upholding service quality and safeguarding participants? In particular, what concerns has the Commission identified through complaints data about unregistered providers, and how does registration address those risks?

Answer:

NDIS provider registration requirements

All NDIS providers (registered or unregistered) are required to comply with the NDIS Code of Conduct, however registered providers are subject to additional requirements and conditions of registration including:

  • Thorough suitability assessments of the provider and its key personnel
  • Requirements for all persons in risk assessed roles to undergo NDIS Worker Screening Checks
  • Requirements to be assessed by an Approved Quality Auditor as meeting the relevant NDIS Practice Standards, as well as ongoing audits, proportionate to the nature of supports and services they are registered to provide, and
  • Requirements to comply with complaints management, incident management, notification, and behaviour support requirements.

These additional requirements provide the:

  • NDIS Quality and Safeguards Commission (NDIS Commission) and NDIS participants engaging NDIS providers with greater assurance with regard to the quality, competency, and integrity of NDIS providers, and
  • NDIS Commission with greater oversight to assess the ongoing compliance of NDIS providers, and as a consequence, the safety and quality of supports and services they provide.

8

Complaints about unregistered NDIS providers

The NDIS Commission manages complaints in connection with supports and services delivered by NDIS providers and their workers. The NDIS Commission’s market oversight functions support our understanding of the market landscape through undertaking activities, including high-level analysis of data holdings. Through this work, the NDIS Commission conducted a high-level analysis of complaints data for the period 1 October 2023 to 31 December 2023, examining the allegations and themes raised in 1,500 individual complaint records through a market lens.

Analysis of 371 Supported Independent Living and Specialist Disability Accommodation complaints received over a three-month period, revealed that 83% were about registered providers, while 15% were about unregistered providers, (2% of unknown registration status).

When comparing complaint themes between registered and unregistered providers, the proportions were generally similar. However, there were two notable differences; unregistered providers had a slightly higher proportion of alleged neglect (24% compared to 15%) while registered providers had a higher proportion of alleged poor-quality supports (18% compared to 11%).

While complaints were broadly similar across registered and unregistered providers, the higher proportion of complaints relating to registered providers may reflect greater regulatory visibility, participant awareness of complaints pathways, and stronger accountability mechanisms within the regulatory market.

9

Answer to Question on Notice Reference: SQ26-000126

Regulatory Risk Framework

Hearing: 23 April 2026 Hansard Page: Spoken

Asked by: Ms Carol Berry MP

Question:

Ms BERRY: Thank you. I’m going to talk fast and I’m going to ask a number of questions, and some of them can probably be answered on notice. I want to get back to the report, The effectiveness of the NDIS Quality and Safeguards Commission’s regulatory functions. The chair went to this. In my mind, there was quite a damning observation made in that report—that is, the commission does not have a regulatory risk framework and that your overarching compliance and enforcement approach and regulatory decision-making has not been informed by risk. I know that you have done some work in that space and you have developed your framework, but to me that is a very concerning finding. Noting that you’re still a relatively young regulator, that is still—risk, I imagine, should be your guiding principle. Could you provide to the committee some more information—it doesn’t have to be now; this could be on notice—around how you triage matters; how you decide, when push comes to shove, as a group of leaders what issues you are going to pursue and how you make those decisions. To me, that goes to one of the findings in that report.

Answer:

Risk Framework

The NDIS Quality and Safeguards Commission (NDIS Commission) uses a risk-based and intelligence-informed approach to deliver its compliance and enforcement activities. This approach is operationalised through the Risk-Based Regulatory Prioritisation Model (RRPM) and its supporting Enterprise Prioritisation Criteria (EPC), which together provide an enterprise-wide mechanism for assessing incoming information, including complaints, reportable incidents and other intelligence sources.

The EPC apply approved indicators across three core domains:

  • Participant safety and human rights
  • Provider and worker compliance with NDIS legislation and rules, and
  • Scheme integrity, strategic priorities and emerging risks.

These indicators enable the NDIS Commission to assess the potential impact and seriousness of matters, determine appropriate regulatory pathways, and apply proportionate compliance or enforcement responses, in line with our compliance and enforcement approach.

10

Matters assessed as higher risk are subject to increased scrutiny, escalation and senior oversight, while lower-risk issues may be addressed through education, monitoring or targeted engagement.

The NDIS Commission acknowledges that, while these arrangements provide a structured and consistent approach to managing regulatory risk at the operational level, it does not yet have a fully developed enterprise-level regulatory risk framework that consolidates regulatory risk identification across the organisation.

In response to a recommendation of the Australian National Audit Office, the NDIS Commission is developing a broader regulatory risk framework, due for completion by June 2026.

The proposed framework is intended to strengthen enterprise-level regulatory risk identification and management by drawing together integrated data and analysis capability, clearer regulatory priorities and a more formalised regulatory risk management approach, including agreed regulatory risks, defined thresholds and controls, strengthened use of market and sector insights, and risk profiling to support consistent intake, triage and escalation decisions. Once finalised, the framework will build on existing prioritisation and governance arrangements and further support the NDIS Commission’s ability to proactively identify, monitor and respond to its highest regulatory risks.

Decision Making Framework

At intake, matters are assessed using the RRPM, which applies the EPC approved by senior leadership. This enables staff to:

  • Assess risk and potential impact in a consistent way
  • Determine the appropriate regulatory pathway
  • Identify matters requiring escalation or enhanced oversight.

This structured approach supports consistent risk-informed decision-making, ensures proportionality of regulatory responses, and enables timely and consistent triage across large volumes of matters.

Matters assessed as the highest risk, including those involving serious, systemic or repeated non-compliance, significant safeguarding concerns, or allegations of substantial seriousness, are subject to further escalation.

All matters proposed for compliance or enforcement action, or which require further investigation due to their seriousness or scale, are considered by the Operations Executive Panel (OEP).

The OEP comprises Band 1 and Band 2 Senior Executive Service officers and provides

  • Senior executive visibility and governance of the NDIS Commission’s highest-risk matters
  • Oversight of regulatory risk and resource prioritisation
  • Final decision-making on allocation to compliance and enforcement action.

Through this model, senior leadership maintains appropriate oversight and accountability for the NDIS Commission’s most serious regulatory decisions, while enabling effective operational triage and the consistent application of risk-based judgement across the organisation.

11

Answer to Question on Notice Reference: SQ26-000127

Increase workload in mandatory registration

Hearing: 23 April 2026 Hansard Page: Spoken

Asked by: Ms Carol Berry MP

Question:

Ms Berry: Also, in light of the announcements made yesterday by Minister Butler and the fact that your registration responsibilities are going to be expanding, do you feel, in order to appropriately manage the regulation of this sector, that you will need some tightened up legislation? If you’ve got more inputs coming into the system and you currently aren’t regulating according to risk, according to this report from the Auditor-General, how are you going to manage that increased volume effectively in order to appropriately regulate the scheme? Could you provide some views on that, whether or not you think you need some tightened up legislation.

Answer:

The NDIS Quality and Safeguards Commission [NDIS Commission] is committed to ensuring that its market entry levers, including NDIS registration are robust with assessment proportionate to risks identified through its assessments. The NDIS Commission’s registration assessment capabilities continue to evolve and become more efficient. Applications are streamed based on the risk profile of the applicant, with increased recognition and engagement of our co-regulatory environment and better access to information across government through capabilities established under the Fraud Fusion Taskforce.

Further, the NDIS Commission’s Risk-based Regulatory Prioritisation Model has been implemented to ensure that the NDIS Commission’s regulatory effort and approach is risk- informed and strategic. The objective is to ensure that the NDIS Commission’s operations are risk-informed and intelligence-led, targeting issues of highest risk in the NDIS market.

These improvements, along with data and system improvements as part of the NDIS Commission’s Data and Regulatory Transformation Program, will assist the NDIS Commission in managing its increased registration and regulatory workload.

The Australian Government has recently announced its intention to introduce reforms including to strengthen powers for the NDIS Commission and the National Disability Insurance Agency, and to introduce legislation to enable these changes. Further information is available on the Department of Health, Disability and Ageing’s website.

12

Answer to Question on Notice Reference: SQ26-000128

Identify strategic regulatory priorities

Hearing: 23 April 2026 Hansard Page: Spoken

Asked by: Mr Josh Burns MP

Question: Line of questioning at the hearing focused on how the NDIS Commission informs its strategic priorities and direction. The NDIS Commission would like to share the below information with the Committee.

Answer:

The NDIS Quality and Safeguards Commission (NDIS Commission) regulates a large, evolving and complex market. The NDIS Commission has developed three key priorities, set out in our Strategic Roadmap 2025-27 to address market challenges:

  • Being a formidable regulator, through enhanced statutory powers and operations;
  • Focusing on human rights, through safe, high-quality services, prioritisation of dignity and inclusion; and
  • Delivering a sustainable future for the NDIS, through an equitable, sustainable and participant-focused market.

These priorities respond to issues identified by the NDIS Commission including:

  • Lack of compliance with the NDIS Code of Conduct resulting in breaches of human rights
  • Restricted oversight of NDIS providers - only 7% of providers operating in the market are registered with the NDIS Commission¹
  • Unfair pricing practices that disrupt the market and impact service delivery
  • Supports and services that don’t meet the needs of people with complex disabilities
  • Regulatory standards and powers that need to be enhanced to support safety, quality and innovation
  • Limited collaboration between regulators in the care sector
  • The need for sustainable resourcing to fulfil our remit as regulator of the NDIS market.

The NDIS Commission also uses our holdings and market oversight analysis to inform annual regulatory priorities. In 2025-26 these are:

  • The reduction and elimination of regulated restrictive practices.

¹ NDIS Quarterly Report Q3 2024–25

13

  • Strengthened oversight and regulation of unregistered NDIS providers and sole traders.
  • Provider obligations to support participants to proactively identify and manage high-risk health concerns.
  • Provider obligations to support, train and monitor appropriately skilled and capable workers.

Like many regulators, the NDIS Commission faces challenges arising from information and data that are fragmented across multiple systems. This fragmentation limits our ability to identify patterns across incidents, link complaints to provider history, and detect emerging systemic risks.

In response, the NDIS Commission is modernising its regulatory approach through the Data and Regulatory Transformation (DART) program. DART will ultimately reduce regulatory burden, provide richer and more timely insights, support information sharing with other regulators, and improve the long-term efficiency and effectiveness of regulatory responses.

The NDIS Commission is also continuing to test and refine its risk-based regulatory prioritisation model. This model and associated processes are designed to ensure regulatory efforts are directed to areas where they can have the greatest impact. It embeds a consistent, efficient and responsive approach to assessing incoming information based on the level of risk to NDIS participants and the Scheme.

Key features of the model include:

  • Risk assessment – identifying and evaluating risks based on impact to the human rights and safety of participants; provider and worker compliance with NDIS legislation; and alignment with strategic priorities and emerging risks.
  • Proportionate response – applying a proportionate response to the level of risk, escalating high risk matters for more robust regulatory response, or managing low- medium risk matters with less intervention or referral on to other appropriate bodies.
  • Data-driven decisions – ensuring decisions are informed by data and continuously updated risk profiles that adapt to changing circumstances.

In addition to DART and the prioritisation model, the NDIS Commission has commenced new programs of work to strengthen its ability to identify and manage regulatory risk, deliver strategic priorities, and maximise limited resources. This includes:

  • Implementing a comprehensive Regulatory Risk-based Framework, addressing gaps identified by the Australian National Audit Office [ANAO] and establishing an overarching, evidence-based framework for the oversight, assessment, management and prioritisation of regulatory risk.
  • Developing a Compliance Monitoring Framework and Strategy to embed an iterative and consistent approach to compliance monitoring across the NDIS Commission.

These initiatives will also strengthen existing processes for setting annual regulatory priorities, which analyse themes and market trends and enable the NDIS Commission to focus resources on areas of heightened risk.

This significant program of work will take time to fully develop, implement and embed, and will be delivered in alignment with the ANAO audit cycle, capability development initiatives such as DART, and ongoing regulatory reform.

14

During this period, the NDIS Commission will continue to evolve as a mature, intelligence-led and risk-based regulator by enhancing regulatory practices and making effective use of available data, information and evidence to guide risk-informed regulation. This includes data and intelligence obtained through complaints, reportable incidents, provider registration processes, third-party audits, market insight reports, research, own-motion inquiries and reviews, and information shared with the National Disability Insurance Agency, state and territory authorities, and other Commonwealth regulators.

Publicly available data and information can be accessed through the following sources:

  • NDIS market oversight | NDIS Quality and Safeguards Commission

  • Strategic Roadmap 2025-27

  • NDIA Market monitoring reports| NDIS

  • Quarterly financial and performance reports

  • Inquiries and Reviews | NDIS Quality and Safeguards Commission

  • Our regulatory priorities | NDIS Quality and Safeguards Commission

  • NDIS Regulatory Reform | NDIS Quality and Safeguards Commission

15

Answer to Question on Notice Reference: SQ26-000129

Payment arrangements for self-managed participants

Hearing: 23 April 2026 Hansard Page: Written

Question:

Payment arrangements for self-managed participants: The NDIS Commission advised the ANAO that it does not have visibility of payment arrangements for self-managed participants [ Auditor- General Report No. 25 2025–26, p. 19 ]

(a) Why does the NDIS Commission not have visibility of payment arrangements for self- managed participants?

Answer:

The NDIS Quality and Safeguards Commission [NDIS Commission] does not see detailed payment arrangements for self-managed participants because of how the NDIS is structurally designed— especially the separation between funding administration (National Disability Insurance Agency) and regulation (NDIS Commission), and the reporting requirements for self-management.

The NDIS Commission may access information about self-managed payments when, complaints are lodged, serious incidents are reported, compliance or fraud investigations occur, or the NDIA shares data or conducts reviews.

Roles and Responsibilities

The NDIS Commission regulates provider behaviour, enforces the NDIS Code of Conduct and handles complaints and incidents. The NDIA manages participants plan, funding allocations, access, and payments.

Self-Managed Participants

Self-managed NDIS participants have full control over choosing providers, negotiating prices, and tailoring supports, which can increase flexibility, value, and responsiveness. In return, self-managed NDIS participants are responsible for managing payments, records, and compliance with the NDIA’s requirements.

16

Answer to Question on Notice Reference: SQ26-000130

Quality assurance processes

Hearing: 23 April 2026 Hansard Page: Written

Question:

Quality assurance processes: The ANAO found that the NDIS Commission did not have processes in place to assure itself for compliance activities [Auditor-General Report No. 2 2025–26, p. 56] and investigations into suspected non-compliance [Auditor-General Report No. 2 2025–26, p. 65]. The NDIS Commission is not able to assess its effectiveness in the absence of quality assurance frameworks.

(a) Why were relevant quality assurance frameworks not established? (b) Have relevant quality assurance frameworks been established since ANAO’s findings?

Answer:

(a)

Relevant quality assurance frameworks were not initially established due to the NDIS Quality and Safeguards Commission’s [NDIS Commission] early operational focus on standing up core regulatory functions in a rapidly evolving and resource constrained environment. At esstablishment, priority was given to delivering frontline regulatory activities and responding to safeguarding risks while implementing legislative requirements amid rapid scheme growth and changing policy settings. Quality assurance activities were undertaken through a range of operational policies, procedural controls and management oversight mechanisms, rather than through a consolidated entity wide quality assurance framework. While these controls supported day to day operations, they did not provide a consistent enterprise level approach to assuring the quality, consistency and effectiveness of regulatory decision-making across functions.

(b)

Since the ANAO’s findings, the NDIS Commission has an entity-wide Quality Assurance Framework (QAF) and is currently piloting the QAF to strengthen oversight, consistency and assurance across all its regulatory activities. The QAF aims to provide a structured approach to quality assurance, including clear principles, roles and responsibilities, review mechanisms and escalation pathways. It supports consistent application of legislative requirements, regulatory decision making, complaints handling, incident management and investigations, and aligns quality assurance activities with the NDIS Commission’s broader risk-based regulatory approach.

The establishment of this framework addresses the gaps identified by the ANAO and strengthens transparency, accountability and confidence in the NDIS Commission’s regulatory outcomes.

17

Answer to Question on Notice Reference: SQ26-000131

Intelligence gathering

Hearing: 23 April 2026 Hansard Page: Written

Question:

Intelligence gathering: COS is the main business system used to create, capture and manage digital information documenting the core or unique functions and activities of the NDIS Commission [4 Auditor-General Report No. 2 2025–26, p. 30]. COS has capability limitations and was assessed by the Commission as being non-compliant with Australian Government record keeping requirements [Auditor-General Report No. 2 2025–26, p. 9] The ANAO suggested that the NDIS Commission could update its Information Management Policy to set out expectations for using the Commission’s systems [Auditor-General Report No. 2 2025–26, p. 9]

(a) Has the NDIS Commission updated its Information Management Policy?

Answer:

The NDIS Quality and Safeguards Commission [NDIS Commission] Information Management Policy has been updated to include reference to the Commission Operating System (COS), the Parliamentary Document Management System and LEX systems.

The policy notes that, while COS is an endorsed business system, there are acknowledged limitations of the system. The new Data and Regulatory Transformation system, known as RADAR, currently being built to replace COS, will address the capability limitations and ensure compliance with the Australian Government record-keeping requirements.

Concurrently, there are information management improvements in train, which include:

  • a procurement process for a NDIS Commission owned Electronic Document and Records Management System (EDRMS). The new EDRMS will integrate with RADAR to ensure Australian Government record-keeping requirements; and
  • updating the Information Management Framework, including recommendations from the Australian National Audit Office, National Archives of Australia and Protective Security Policy Framework Information Security audits, which includes: o The creation of the ‘What is a Record’ factsheet to assist staff in identifying records and the appropriate business system for the records to be saved to. The factsheet includes reference to COS being a NDIS Commission business system.

18

Answer to Question on Notice Reference: SQ26-000132

Strategies to support compliance activities

Hearing: 23 April 2026 Hansard Page: Written

Question:

The NDIS Commission’s approach to compliance is not informed by risk. The NDIS Commission had not established a strategic framework or formalised processes for its analysis activities [Auditor-General Report No. 2 2025–26, p. 9]. The ANAO also found that the NDIS Commission’s regulatory decision-making is not guided by a risk-based strategy [Auditor-General Report No. 2 2025–26, p. 8]. The NDIS Commission had not established a framework for assessing, prioritising and managing risks of provider non-compliance [Auditor-General Report No. 2 2025–26, p. 8].

(a) Why had the NDIS Commission not established strategic frameworks for its analysis activities, regulatory decision-making, and managing provider non-compliance? (b) Have strategic frameworks for its analysis activities, regulatory decision-making, and managing provider non-compliance been established now? If so, how are these frameworks informed by risk?

Answer:

(a)

The NDIS Quality and Safeguards Commission [NDIS Commission] did not initially establish a single and consolidated strategic framework across all functions to inform analysis activities, regulatory decision-making and management of provider non-compliance due to the NDIS Commission’s early-stage maturity and the operating environment in which it was established.

At commencement, the NDIS Commission faced rapid scheme growth and an expanding and diverse provider market, together with evolving legislative and policy settings. The NDIS Commission’s regulatory remit was also implemented in stages and so was not operating across all state and territory markets until December 2020.

Strong expectations to respond quickly to safeguarding risks impacting on individuals resulted in priority given to standing up core regulatory functions while focused, in the main, on NDIS participant safety. While this approach enabled responsiveness during the establishment phase, it limited consistency, transparency and systematic risk prioritisation across regulatory functions.

19

(b)

Yes, the NDIS Commission was already developing an enterprise-wide risk-based prioritisation model when the ANAO was undertaking its audit. As it was not formally adopted at the time of the audit, ANAO was unable to be considered in the audit findings.

The NDIS Commission is continuing to mature strategic frameworks that operate across all functions to lift the capability of analysis activities, regulatory decision-making and to ensure regulatory priorities are informed by high quality and comprehensive data centred on systemic risk analysis. Enhancing the management of provider non-compliance is being progressed through work relevant to ANAO recommendations 4, 5, 6 and 8. This includes development of the Risk-Based Regulatory Framework, Quality Assurance Framework and Compliance Monitoring Framework, supported by operational tools such as the Regulatory Risk-Based Prioritisation Model and Data and Regulatory Transformation.

These significant and whole of enterprise initiatives will, once implemented, strengthen the NDIS Commission’s ability to assess risk, prioritise regulatory effort and respond proportionately to emerging issues. Recommendations 5, 6 relate to progressing the development of a Risk-Based Regulatory Framework and Compliance Monitoring Framework and Recommendation 8 is being progressed through alignment of regulatory business processes and integration of complaints, incident and investigation processes within the Quality Assurance Framework. Collectively, these frameworks and tools embed risk at the centre of regulatory prioritisation, escalation and response, improving consistency, transparency and defensibility in regulatory practice.

20

Answer to Question on Notice Reference: SQ26-000133

Monitoring, compliance and enforcement activities:

Hearing: 23 April 2026 Hansard Page: Written

Question:

Monitoring, compliance and enforcement activities: The NDIS Commission has not effectively implemented risk responsive and proportionate monitoring, compliance and enforcement activities [Auditor-General Report No. 2 2025–26, p. 8]. The Commission does not have oversight of all the NDIS providers delivering services in the market as there is no requirement for all providers to be registered [Auditor-General Report No. 2 2025–26, p. 8]. The ANAO recommended the development and implementation of an entity-wide compliance monitoring strategy –[Auditor-General Report No. 2 2025–26, p. 11].

(a) Why are there no requirements for all providers to be registered? (b) Would making mandatory registration for all providers improve the NDIS Commission’s oversight and positively impact provider compliance rates? (c) What is the NDIS Commission’s progress on implementing an entity-wide compliance monitoring strategy?

Answer:

(a)

Currently, registration with the NDIS Quality and Safeguards Commission [NDIS Commission] is mandatory for NDIS providers delivering specialist disability accommodation (SDA), specialist behaviour support services, supports or services to NDIS participants with National Disability Insurance Agency (NDIA) managed funding, and plan management services. Registration is also required for NDIS providers implementing regulated restrictive practices. NDIS Providers who are not required to be registered to deliver the above supports, may choose to apply for registration.

All NDIS services and supports delivered under the NDIS are recognised by the registration process, but only the four abovementioned circumstances mandate registration.

Regulatory Reforms mandating registration for Supported Independent Living and Platform Providers are well advanced with implementation commencing from 1 July 2026. Recent announcements by the Minister for Disability and the NDIS, the Hon Mark Butler MP included the expansion of provider registration, commencing from July 2027, with full implementation by the end of 2030.

It should also be noted that allowing unregistered NDIS providers to operate in the NDIS market is a feature of the scheme’s original design and explained in the 2016 NDIS Quality and Safeguarding Framework (the Framework).

21

The Framework has been the subject of comprehensive and independent reviews, starting with the Royal Commission into Violence, Abuse, Neglect and Exploitation of People with Disability (Disability Royal Commission), followed by the Independent Review of the National Disability Insurance Scheme (NDIS Review). The Disability Safeguards Consultation, led by the Department of Health, Disability and Ageing, commencing in November 2025, is the government’s response to relevant recommendations made by the Disability Royal Commission and NDIS Review. A second round of public consultation is planned for later in 2026.

(b)

Expanding mandatory registration would ensure the NDIS Commission has full visibility of the NDIS provider market and its workforce. Currently, the NDIS Commission’s ability to identify unregistered NDIS providers places significant reliance on complaint information and other market intelligence as well as drawing down on payment information from NDIS participant plans (data held by the NDIA that the NDIS Commission has limited access to).

As expressed in the NDIS Commission’s submission to the Productivity Commission’s 2025 Inquiry into Delivering Quality Care More Efficiently, registered NDIS providers (7% of the NDIS provider market) are required to comply with a range of requirements all of which are focused on ensuring services and supports delivered meet quality and safety expectations. Unregistered NDIS providers are still regulated by the NDIS Commission through the legislated NDIS Code of Conduct. Unregistered NDIS providers are expected to comply with all relevant laws in delivering NDIS supports and services, including the Code of Conduct. Relevant obligations for all NDIS providers regardless of registration status are made public on the NDIS Commission’s website.

Supporting quality services to be delivered safely in the NDIS market starts with who can access the NDIS market and the NDIS Commission, the NDIS provider market and workforce regulator, having visibility (and therefore greater control and influence) over what good looks like in delivering quality services.

(c)

The NDIS Commission is progressing implementation of an entity wide approach to compliance monitoring through a sequenced and structured program of work. The NDIS Commission is developing a Compliance Monitoring Framework as a foundational step prior to development of a formal Compliance Monitoring Strategy. The Compliance Monitoring Framework will establish consistent principles, risk-based monitoring approaches, roles, and governance arrangements across the NDIS Commission. Subject to approval of the Framework, development of an entity wide Compliance Monitoring Strategy will commence, building on the Framework to articulate strategic priorities, maturity pathways and targeted monitoring approaches aligned to risk. This sequencing ensures that the Strategy is underpinned by agreed and consistent regulatory foundations, supporting a more coherent, proportionate, and intelligence-led compliance monitoring system.

22

Answer to Question on Notice Reference: SQ26-000134

NDIS review

Hearing: 23 April 2026 Hansard Page: Written

Question:

NDIS Review: Recommendation 17 of the Independent Review into the NDIS related to NDIS Commission visibility of unregistered providers: ‘Develop and deliver a risk-proportionate model for the visibility and regulation of all providers and workers and strengthen the regulatory response to long-standing and emerging quality and safeguards issues.’ [Auditor-General Report No. 2 2025–26, p. 19]

(a) Has the NDIS Commission established a risk-based approach to gain visibility and regulation of all providers, and explain how the approach works?

Answer:

On 22 April 2026, Minister for Disability and the National Disability Insurance Scheme, the Hon Mark Butler MP announced a suite of significant reforms to the NDIS including the introduction of the National Disability Insurance Scheme Amendment (Securing the NDIS for Future Generations) Bill following the release of the 2026-27 Budget. Announced changes include tackling fraud and non-compliance through an expansion of mandatory registration, the introduction of an enrolment system for most providers and the strengthening of payment and information processes.

In December 2025, the Government announced that mandatory registration for NDIS providers delivering supported independent living (SIL), as well as NDIS digital platforms (platform providers) commencing from 1 July 2026. The NDIS Quality and Safeguards Commission (NDIS Commission) is on track to implement these changes, subject to a Rule amendment.

This reform increases regulatory oversight, strengthens safeguards and increases provider accountability in higher-risk markets. The changes respond to recommendations by external reviews (NDIS Review, Royal Commission into Violence, Abuse, Neglect and Exploitation of People with Disability, and NDIS Provider and Worker Taskforce advice), as well as the NDIS Commission’s Own Motion Inquiries, where findings have indicated unreasonable levels of risk in the delivery of SIL and platform provider supports.

23

Answer to Question on Notice Reference: SQ26-000135

Compliance actions

Hearing: 23 April 2026 Hansard Page: Written

Question:

Compliance actions: The Commission undertook 9,520 compliance actions in 2022–23; increasing 3.73 times in 2023–24 to 35,519 compliance actions [Auditor-General Report No. 2 2025–26, p. 56].

(a) What was the cause of the significant increase in the use of compliance and enforcement actions? (b) What proportion of compliance and enforcement actions were related to claim requirements?

Answer:

a)

The increase in compliance actions in 2023-24 were the result of proactive work completed by the NDIS Quality and Safeguards Commission’s Practice Quality team, including:

  • 3,341 Written warnings sent between 16 and 27 of October 2023 to providers registered to use restrictive practices to ensure they took appropriate steps to reduce and/or eliminate any Unauthorised Restrictive Practices they were currently implementing.
  • 7,858 education letters sent in November 2023 to clarify the expectations when developing behaviour support plans that contain regulated restrictive practices. Providers and practitioners were also provided with new resources including a regulated restrictive practice summary and protocols.
  • 8,391 education letters sent on 30 January 2024 to registered specialist behaviour support providers and NDIS behaviour support practitioners who were targeted in a proactive educational campaign about the safe reduction and elimination of restrictive practices. They were also provided resources to improve the quality of behaviour support plans including revised Behaviour Support templates. These resources are consistent with commitments made to the Disability Royal Commission.

b)

The National Disability Insurance Agency (NDIA) is responsible for the oversight and management of claims and payments. The Fraud Fusion Taskforce plays a key role in protecting the integrity of NDIS claims and payments through the process of detection and prevention of fraudulent or incorrect claims made against the NDIS, and investigating suspicious payment activity, including false invoices or services not delivered.

24

Claim anomalies are an important source of information and regulatory intelligence and are often a useful indicator of potential fraudulent practice and substandard service provision. The NDIS Commission, alongside the NDIA, have increased the identification and investigation of anomalous payment behaviour and quality and safeguarding standards of NDIS providers.

The NDIS Commission will consider anomalous payment behaviour in the broader context of quality and safeguarding with a primary focus on participant safety and will act where Code of Conduct obligations are not met and when safety and quality standards are not met.

Additionally, the NDIS Commission uses insights from its own data holdings to proactively identify providers who may not be meet standards. This includes through suitability assessments at point of registration.

The NDIS Commission does not collect and hold specific data associated with claims and therefore it is not possible to determine the quantum of regulatory action taken where a provider’s claim behaviour may have contributed to the decision to take regulatory action against a provider.

25