Administrative systems and Scheme integrity

‹ PrevPage 1 of 12 · Source p. 1Next ›

January 2026

Executive summary

This submission responds to the Joint Committee of Public Accounts and Audit’s inquiry into the administration of the NDIS. It examines how administrative systems operate in practice and how their design and execution shape scheme integrity, financial sustainability and participant outcomes.

Public debate about the NDIS often focuses on fraud, compliance and cost growth. This submission focuses on how the Scheme’s administrative systems support integrity and sustainability in practice. In a scheme of this scale, outcomes depend on whether systems can identify risk early, enable timely and consistent decisions, and provide clear guidance to participants and providers.

Recent Auditor-General reporting highlights ongoing weaknesses across the NDIA and the NDIS Quality and Safeguards Commission in data, risk targeting and system capability. As a result, compliance action often occurs after issues have already affected payments or service delivery, rather than identifying and managing risk earlier in the system.

In practice, administrative reviews often begin without clear notice or explanation. Providers may only realise a review is underway when payments are delayed or requests for information arrive, with little clarity about what is being examined or how long the process will take. For participants who rely on regular supports, particularly those with complex needs, this uncertainty can interrupt services and increase reliance on family or informal carers while administrative processes are resolved.

This submission also addresses the operational reality of implementing multiple reforms at once. Changes to legislation, a stronger compliance focus and the move to universal provider registration are all progressing in parallel, significantly expanding the scope and complexity of administrative responsibilities across the NDIS. These reforms are essential and cannot be paused. Their success, however, will depend on whether administrative systems evolve alongside them, with the capacity to manage increased decision-making, oversight and information flows at scale. Where system capability does not keep pace, the effects are felt in slower decisions, greater uncertainty and increased intervention, with practical impacts on participants and providers alike.

Pricing and registration settings interact closely with these administrative pressures. Where prices currently do not cover the minimum cost of compliant service delivery, providers have limited capacity to absorb administrative disruption without flow-on effects. Instability at the provider level can then feed back into administrative systems, increasing reliance on audits, payment delays and manual intervention rather than reducing risk earlier in the process.

Overall, this submission argues that scheme integrity is fundamentally an administrative outcome. Strengthening integrity and financial sustainability requires sustained attention to the administrative foundations of the Scheme, including system

capability, transparency, risk targeting and alignment between reform ambition and delivery capacity. The recommendations focus on ensuring that compliance activity operates as a preventative and proportionate safeguard, rather than a reactive response to administrative uncertainty.

Recommendations

  1. Ensure compliance activity is supported by mature administrative systems: clear data, risk information and performance tracking are essential for effective compliance. Without them, audits and reviews are more likely to respond to uncertainty after the fact instead of preventing problems early.

  2. Improve transparency and consistency in review processes: establish clear frameworks for identifying risk, prioritising cases and resolving reviews would support more consistent and proportionate decision-making, and reduce reliance on broad or reactive administrative intervention.

  3. Improve transparency and communication during audit processes: minimum communication standards should apply when the NDIA undertakes reviews that affect claims, payments or plan administration. This should include timely notification to providers and plan managers when payments are delayed or reviewed, indicative timeframes for resolution, and a clearly identified point of contact. Clearer communication would reduce uncertainty, support continuity of supports for participants, and limit avoidable disruption for providers delivering services during review periods.

  4. Embed performance reporting on fraud and non-compliance outcomes: the NDIA should be required to report consistently on fraud and non-compliance performance measures as part of its annual performance statements, including how compliance activity contributes to risk reduction and financial sustainability over time. This would enable Parliament to assess whether increased compliance effort is delivering measurable value for money.

  5. Ensure administrative readiness for mandatory provider registration: mandatory provider registration is a foundational reform that strengthens safety, quality and market integrity across the NDIS. As registration expands to cover the full provider market, the NDIS Quality and Safeguards Commission must be adequately equipped with the systems, staffing and processes needed to manage increased volumes, ongoing monitoring and risk-based oversight. Ensuring administrative readiness will allow registration to improve visibility and accountability across the Scheme, rather than creating delays or defaulting to reactive enforcement.

  6. Align pricing with the cost of delivering quality and compliant services: pricing needs to reflect the real cost of meeting workforce, quality and compliance requirements. When prices are set too close to cost, providers who invest in training, safeguards and good systems have little ability to absorb

administrative delays or additional compliance demands without cutting services or withdrawing from the market. Sustainable pricing supports provider viability, strengthens compliance, and helps regulators focus on genuine risk rather than managing instability created by under-resourcing.

  1. Invest in system capability alongside reform delivery: as reforms are implemented, targeted investment should be made in the administrative systems, guidance and data capability needed to support them. Where changes expand administrative discretion, sustained resourcing of these supporting functions is essential to enable consistent decision-making and to minimise uncertainty for participants and providers.

  2. Shift compliance effort upstream through better system design: there should be a strategic shift from retrospective, manual compliance mechanisms towards earlier risk identification through improved data quality, system integration and information sharing across the NDIA and the NDIS Quality and Safeguards Commission. This would reduce reliance on audits and payment holds as primary risk controls.

About Hireup

Hireup is a national NDIS-registered provider of disability and aged care support services, operating across all states and territories. Since commencing operations in 2015, Hireup has grown into one of Australia’s largest NDIS platform providers.

Each year, Hireup employs more than 14,000 support workers and delivers over three million hours of NDIS-funded support to approximately 11,000 participants nationwide. This scale of operation means Hireup regularly engages with the full range of administrative, compliance and regulatory processes examined by this inquiry, including plan management, payment systems, audits, registration requirements and reporting obligations.

Hireup employs its support workers directly and has been registered with the NDIS Quality and Safeguards Commission since the beginning. As a fully registered provider operating under award wages, superannuation, workers compensation and quality assurance requirements, Hireup’s experience reflects the practical realities of delivering compliant services within current pricing, administrative and regulatory settings.

This submission draws on our experience operating within the regulated NDIS market. As a registered provider, we are constantly engaging with registration requirements, audits, compliance reviews and NDIA administrative processes. The issues raised reflect how these systems function in practice and the impacts they have on participants, workers and service delivery.

Scheme integrity starts with administration

Debates about the integrity and financial sustainability of the NDIS commonly centre on fraud control, compliance activity, and expenditure growth. While these issues matter, this framing can underplay the more structural influences of how the Scheme performs in practice. In a system of this scale and complexity, the design and operation of administrative arrangements shape behaviour, risk and decision-making across the Scheme, with direct consequences for integrity, financial sustainability and participant outcomes.

Administrative design and compliance effectiveness

The effectiveness of compliance is determined primarily by process design, data integrity and organisational capability, rather than enforcement effort alone. Where administrative systems are clear, proportionate and transparent, compliance operates as a preventative mechanism, guiding behaviour and reducing risk before costs are incurred. Where systems are fragmented or opaque, risk is not eliminated but displaced, often emerging later through disputes, delayed payments and disrupted service delivery.

From a provider perspective, administrative gaps are most visible in how compliance processes interact with routine service delivery. While reviews and audits are necessarily retrospective, they are often experienced as isolated interventions rather than as part of a clear, ongoing risk-based framework. Expectations are not always well signposted in advance, timelines for review can be uncertain, and feedback is limited or arrives after disruption has occurred. As a result, compliance activity is less effective in shaping behaviour early and more likely to be felt as a corrective response once issues have already emerged.

Audit findings on administrative capability

The Auditor-General’s examination of regulatory functions within the NDIS reinforces this experience¹. The Australian National Audit Office (ANAO) observed that assurance activities are frequently constrained by incomplete intelligence, inconsistent data flows and limited visibility across the provider market. These constraints have implications not only for regulatory effectiveness, but also for the NDIA’s capacity to align compliance activity with actual risk exposure rather than volume or visibility alone.

The ANAO has further noted that where agencies cannot clearly articulate how compliance activity contributes to risk reduction, financial sustainability and improved outcomes, the effectiveness of those activities remains uncertain². In these circumstances, the issue is not the level of compliance effort applied, but whether the

¹ Effectiveness of the NDIS Quality and Safeguards Commission’s Regulatory Functions | Australian National Audit Office (ANAO) ² Auditor-General Report No. 48 2024-25 National Disability Insurance Agency’s Management of Claimant Compliance with National Disability Insurance Scheme Claim Requirements

administrative systems in place are sufficiently mature to ensure that effort is purposeful, measurable and preventative.

These concerns are reflected across the Auditor-General’s 2024–25 audit program, which has increasingly focused on whether NDIS agencies have established the administrative foundations necessary to support effective compliance and assurance³. Across multiple audits, the ANAO has highlighted persistent weaknesses in risk assessment, performance measurement and system integration that limit the agencies’ ability to demonstrate that controls are operating effectively, particularly in high-risk and high-growth areas of the Scheme.

Recent audit reporting demonstrates how these structural issues manifest within the NDIA’s compliance arrangements. In its performance audit of the NDIA’s management of claimant compliance with NDIS claim requirements, the ANAO found that while a range of compliance activities has been implemented, the Agency has not demonstrated that these operate as a coherent, integrated and risk-based system capable of preventing and detecting non-compliance efficiently. This finding goes directly to the effectiveness of administration as a safeguard, rather than to the presence or absence of compliance activity itself.

Impacts on participants and providers

The effects of administrative and compliance processes are most visible when they intersect with service delivery and payment. Many compliance activities, including reviews of claims or plan spending, occur after services have already been delivered. When these processes are slow, unclear or heavily manual, problems tend to surface only once payments are delayed or interrupted, rather than being identified earlier through clearer systems and guidance.

For participants, this often appears as sudden uncertainty in otherwise stable support arrangements. Payment delays or administrative holds can disrupt the continuity of services, particularly for people with higher or more complex support needs who rely on regular, ongoing assistance. While issues are being reviewed, participants may experience interruptions to care or increased reliance on informal supports, even though there has been no change to their assessed needs.

For providers, these same processes translate into delayed payments, repeated requests for documentation and unclear timelines for resolution. Where administrative systems rely on manual checks and retrospective review, providers are required to continue delivering supports while absorbing wage costs, compliance obligations and administrative workload, without clarity on when payment will resume. This creates operational and financial pressure that can affect workforce stability and service planning.

³ Auditor-General Report No. 25 2024-25 Performance Statements Auditing in the Commonwealth—Outcomes from the 2023-24 Audit Program

Findings from the Australian National Audit Office reinforce these experiences. In its audit of the NDIA’s 2023–24 annual performance statements, the Auditor-General identified gaps in performance reporting, including the absence of information on fraud and non-compliance outcomes. Without this reporting, it is difficult to assess whether compliance activity is improving over time, whether it is reducing risk, or whether resources are being directed to the areas of greatest concern.

The same audit also highlighted limitations in the NDIA’s digital systems, including constraints on reporting against Participant Service Guarantee timeframes and on verifying participant outcome data. In practical terms, this means greater reliance on manual processes, documentation requests and retrospective checks. For providers, this increases administrative burden. For participants, it increases the likelihood that issues are addressed only after payment or service impacts have already occurred.

Together, audit evidence and lived experience point to a clear conclusion relevant to this inquiry. The effectiveness of compliance activity depends heavily on the strength of the administrative systems that support it. Where information is fragmented and systems are slow or unclear, compliance becomes reactive rather than preventative. The challenge facing the NDIS is therefore not the absence of compliance effort, but the need for administrative systems that can support early risk identification, timely decision-making and clear communication, reducing disruption for participants while improving value for money and scheme integrity.

Compliance in practice

Patterns identified in Auditor-General reporting⁴ help explain how administrative limitations shape compliance in practice across the NDIS. While compliance activity has expanded in response to concerns about fraud and misuse, the systems required to ensure that this activity is proportionate, preventative and consistently targeted have not yet matured.

How compliance is experienced on the ground

From the perspective of providers operating within the Scheme, these limitations are evident in how compliance is applied and communicated. Reviews are often initiated without clear articulation of scope, risk rationale or expected timelines. Outcomes are not consistently communicated in ways that inform future practice. As a result, it is often unclear what behaviours are being assessed, which risks are prioritised, or how compliance activity is intended to drive improvement.

The Auditor-General’s performance audit of the NDIA’s management of claimant compliance reflects these concerns⁵. While the NDIA has established a range of compliance activities, the audit found that the Agency has not demonstrated that these

⁴ Terms of Reference – Parliament of Australia ⁵ Auditor-General Report No. 48 2024-25 National Disability Insurance Agency’s Management of Claimant Compliance with National Disability Insurance Scheme Claim Requirements

activities operate within an integrated framework capable of preventing and detecting non-compliance efficiently. The absence of a clearly articulated link between compliance actions and risk reduction outcomes limits confidence that effort is being directed to the areas of greatest exposure.

These weaknesses are reinforced by findings from the audit of the NDIA’s 2023–24 annual performance statements⁶, which identified the absence of reported performance information relating to fraud and non-compliance. Without clearly articulated risk thresholds or performance measures, it is difficult to assess whether compliance effort is being directed to areas of highest exposure or simply responding to administrative triggers.

System capability constraints compound these challenges. Where data reliability is limited and reporting systems are incomplete, compliance activity defaults to manual documentation requests, retrospective review and payment controls. While these mechanisms provide assurance in individual cases, they are resource intensive, slow to resolve and poorly suited to early intervention at scale.

Auditor-General reporting has also highlighted the uneven regulatory landscape within which compliance operates. A substantial proportion of providers remain outside the NDIS Quality and Safeguards Commission’s registration framework, limiting regulatory visibility across the market. For registered providers, this creates an uneven compliance environment in which oversight intensity is not consistently aligned with risk, undermining confidence in the fairness and effectiveness of the regulatory system.

The implications of current compliance practices

This misalignment between compliance ambition and administrative capability has direct consequences for people with disability. Compliance processes that are resource-intensive but imprecise can introduce uncertainty into support arrangements, delay payments and disrupt the continuity of care on which participants rely. Rather than risk being identified and addressed early, issues are often managed retrospectively through manual review, creating periods of instability that are experienced most acutely by participants with higher and more complex support needs.

The cumulative effect is a compliance environment that is active but imprecise. Rather than risk being identified and addressed early, issues are often managed after disruption has occurred. The consequences of this misalignment are borne by participants and providers, not absorbed within the system itself.

⁶ Audit report of the 2023–24 annual performance statements National Disability Insurance Agency

The impact of administrative reviews on payments and service delivery

Claim reviews, sometimes referred to as audits of claims, are an accepted and necessary part of administering the NDIS. They play an important role in ensuring public funds are used appropriately and that supports are delivered in line with Scheme rules. The issue raised in this submission is not the existence of reviews, but how they are currently relied upon to manage uncertainty.

In practice, reviews often occur after services have already been delivered and invoices submitted. While a review is underway, payments may not be released. This is typically not the result of a formal decision to suspend funding, but a consequence of how the review process operates. Where earlier administrative systems lack clarity, consistency or timely risk signals, reviews are used to resolve issues late in the process. The result is that financial and operational impacts are experienced by providers and participants, rather than risks being identified and addressed earlier through clearer systems and processes.

Audit processes and communication gaps

From a provider perspective, compliance reviews are often experienced as administrative checks rather than clearly targeted responses to identified risk. A compliance review typically involves the NDIA examining participant spending or provider claims to assess whether supports have been delivered and claimed in line with NDIS rules. These reviews commonly occur after services have already been delivered and invoices submitted.

Currently providers are not always notified when a participant’s plan or plan manager becomes subject to review. Awareness frequently arises indirectly, through a participant or plan manager, or when payments are delayed without prior explanation. Information about why a review has commenced, what claims or time periods are being examined, and how long the process is expected to take is often limited or unclear.

During the review period, payments may be paused while services continue to be delivered. Providers may be asked to supply documentation without clear guidance on scope or expectations, and enquiries seeking updates or timeframes often yield little information. This makes it difficult to determine whether the review relates to a specific concern or reflects broader administrative checking, and complicates decisions about cash flow, workforce planning and ongoing service delivery.

Over the past eight months, providers have observed an increase in the number of participants subject to review, with payment holds applied during assessment. In several cases, this has resulted in valid invoices remaining unpaid for extended periods, despite services continuing to be delivered. Providers are required to absorb

wage costs, compliance obligations and administrative overheads during this time, placing pressure on operational viability.

These experiences point to an administrative issue rather than a concern with the existence of reviews themselves. Compliance reviews are an accepted and necessary feature of scheme oversight. However, where reviews are conducted without clear communication, defined points of contact or indicative timelines, uncertainty increases for providers and participants without a corresponding improvement in risk management. For participants, this uncertainty can extend to concerns about whether their supports will continue, particularly where providers must make decisions while payments remain on hold.

Scale, financial exposure and system risk

The scale of the Scheme amplifies the effects of this approach. In 2023–24, the NDIA paid out $41.85 billion in participant plan expenses. In September 2023, the NDIA estimated that between 6 and 10 per cent of these outlays may have been for non-compliant, fraudulent or incorrect claims, equivalent to between about $2 billion and $3.5 billion in potential leakage for that year alone.⁷ The Agency projected this exposure could grow if administrative weaknesses persist. These figures demonstrate that even small proportions of non-compliance translate into very large financial sums, and that the design of compliance systems can materially affect the Scheme’s financial sustainability.

Overall, when audits and payment holds are used to make up for gaps earlier in the system, they become less about protecting participants and more about managing uncertainty. This approach increases cost and disruption for providers, without clearly improving integrity or safety outcomes.

Administrative discretion and system confidence

Reform density and administrative load

The NDIS is deep into a phase of reform that is both wide-ranging and operationally demanding. Legislative changes, stronger safeguards, expanded compliance activity and rising expectations of both the NDIA and the NDIS Quality and Safeguards Commission are all being implemented at the same time, while the Scheme continues to grow in size and complexity. Together, these changes place increasing pressure on the administrative systems responsible for turning reform into practice.

What matters in this context is not even the final specifics of reform, but whether the systems tasked with delivering it are ready to operate at this scale. As more

⁷ Audit report of the 2023–24 annual performance statements National Disability Insurance Agency

responsibility sits with administrative decision-making, the quality, clarity and reliability of those systems increasingly determine how reform is experienced by participants and providers.

Recent legislative changes highlight this shift. The NDIA now has greater influence over how plans are structured, how funding is released, how spending is monitored and when intervention occurs. These decisions shape everyday experiences of the Scheme, including the stability of plans, the continuity of supports and the predictability of payments. Where systems are well connected and information is clear, this discretion can support better risk management. Where systems are slow or fragmented, the same discretion introduces delay and uncertainty.

Expanded oversight and system readiness

Mandatory provider registration materially changes the administrative environment in which the Scheme operates. Moving from a system in which an estimated 7 to 10 per cent of providers sit within formal regulatory oversight to one in which the full provider market is visible brings a substantially larger and more diverse cohort into direct administrative scope. This expands the volume of registration, monitoring and compliance activity that must be managed on an ongoing basis. In this context, the effectiveness of oversight will depend less on the existence of regulatory powers and more on the strength of the systems that support risk differentiation, information sharing and consistent decision-making across the market.

Pricing, provider capacity and regulatory effectiveness

Pricing settings are a critical part of how these reforms operate in practice. Many providers, particularly those operating within the registered market, already deliver supports at prices that closely reflect the minimum cost of meeting workforce, quality and compliance requirements. As legislative and administrative reforms increase expectations around reporting, documentation and responsiveness, providers are expected to absorb additional administrative effort and manage greater uncertainty around payments and decisions.

Where pricing leaves little-to-no margin, providers have limited capacity to manage payment delays, audit-related disruption or shifting administrative requirements without flow-on effects. These pressures can affect workforce retention, service continuity and the ability to respond flexibly to participant needs. In turn, instability at the provider level increases administrative intervention, including audits, payment holds and corrective controls, as the system attempts to manage consequences that originate upstream. In this way, pricing, administration and compliance are not separate issues but reinforcing parts of the same system.

Why alignment matters for scheme confidence

What this section highlights is the importance of alignment. Legislative reform, increased oversight and expanded regulatory reach all rely on administrative systems

that can absorb change without transferring instability elsewhere in the Scheme. Where systems are clear, joined up and well calibrated, reform can simplify decision-making and improve consistency. Where they are not, added layers of control can increase friction without materially improving outcomes.

What emerges is not a failure of intent, but a question of alignment. Legislative reform, expanded oversight and administrative discretion rely on systems that can absorb change without transferring instability elsewhere in the Scheme. Where systems are clear and integrated, reform can improve consistency and confidence. Where they are not, added controls risk increasing friction without improving outcomes.

For a Committee concerned with accountability and value for money, this interaction matters. The success of reform will depend less on the expansion of authority and more on the capacity of administrative systems to use that authority predictably, transparently and at scale. Ensuring that administrative design, pricing settings and regulatory arrangements move together is central to protecting participant outcomes, supporting provider viability and sustaining confidence in the NDIS as it continues to evolve.

Conclusion

The administration of the NDIS has become central to how integrity, sustainability and participant outcomes are realised in practice. As the Scheme evolves, more responsibility is being exercised through administrative decision-making rather than through policy design alone. This makes the quality, consistency and readiness of administrative systems increasingly consequential.

The evidence examined in this submission suggests that while compliance activity has expanded, the systems that support it have not yet matured to the point where risk is consistently identified early, managed proportionately and resolved predictably. Where administrative design, pricing settings and regulatory arrangements are not aligned, pressure is displaced rather than reduced, with consequences felt most acutely by participants and the providers who support them.

The opportunity before the Committee is not simply to consider whether more oversight is required, but whether the foundations that underpin oversight are strong enough to deliver it well. Strengthening administrative capability, improving system integration and aligning reform settings will be critical to ensuring that the NDIS continues to protect participants, support quality services and maintain confidence as it enters its next phase.