Concerns about integrity and risk management within the National Disability Insurance Scheme

‹ PrevPage 1 of 86 · Source p. 1Next ›

Community Affairs Legislation Committee

Submission: National Disability Insurance Scheme Amendment (Integrity and Safeguarding) Bill 2025

| Legislative Context and Sources | | This submission addresses the National Disability Insurance Scheme Amendment (Integrity and Safeguarding) Bill 2025 (“the Bill”) as introduced into the Senate and engages directly with the accompanying Explanatory Memorandum (“EM”).

Where this submission identifies divergence between stated intent and foreseeable effect, it does so by reference to the text of the Bill, the EM, Administrative Review Tribunal reasoning, documented administrative practice, publicly reported evidence, and de-identified case-study material.

| Overview | | This submission examines the proposed amendments contained in the National Disability Insurance Scheme Amendment (Integrity and Safeguarding) Bill 2025 and their likely practical effect on participants, providers, families, and others who interact with the Scheme. Participant safety, dignity, and wellbeing are paramount and non-negotiable. While the amendments are presented as strengthening integrity and safeguarding, this submission raises serious concern that, unless foundational problems are addressed first, they risk hard-wiring a defensive, enforcement-led approach into the NDIS that increases conflict, suppresses early risk identification, and undermines effective operation rather than strengthening it.

This analysis is informed by experience with large, complex systems operating under high-risk, high-consequence conditions and significant power imbalance. The issues raised are assessed against standards already recognised by the NDIS itself, including the purpose and principles of the NDIS Act, the Scheme’s own policies and safeguarding frameworks, the findings of Royal Commissions and oversight bodies, Australia’s human-rights commitments, and established risk-management principles consistent with ISO 31000:2018. The focus throughout is not on intent, but on effect — and on whether the amendments will, in practice, reduce harm or displace it elsewhere.

Fraud, abuse, and serious misconduct must be addressed. That is not in dispute. However, this submission demonstrates that existing civil, administrative, and criminal mechanisms already provide pathways to respond to serious wrongdoing. In that context, expanding compliance powers, civil penalties, and enforcement pathways does not operate neutrally. These measures change behaviour. They discourage lawful challenge, suppress advocacy, and deepen existing power imbalances — particularly in a system where disputes most often arise when clinically recommended and professionally verified supports necessary for safety, functioning, or wellbeing are contested on cost grounds.

The submission also raises serious concern about the increasing reliance on litigation and Tribunal processes as tools of control. In practice, these processes do not operate as safeguards. They silence stakeholders, concentrate power, and remove independent oversight while matters are before the

courts or the Administrative Review Tribunal. At precisely the point when power is most acute, no independent body can intervene if something goes wrong. Evidence drawn from Tribunal decisions, case studies, and lived experience demonstrates that this is already causing distress, confusion, and harm across the Scheme.

A consistent issue runs through almost every problem identified in the Explanatory Memorandum: the absence of a mature, independent, third-party quality management system capable of identifying, managing, and correcting risk at scale. This gap appears repeatedly across the issues the amendments seek to address and can be recognised as a common underlying cause. Until the foundational systems that were always intended to underpin the NDIS are fully implemented, there can be no reasonable expectation that the Scheme will operate safely or effectively. Attempting to remedy systemic failure by expanding enforcement powers without first addressing this foundational weakness creates a serious and foreseeable risk.

In a system of this scale and visibility, the greatest protection against misuse, waste, and failure does not come from deterrence alone. It comes from the people who rely on the Scheme and who have a direct, ongoing interest in its sustainability — participants, providers, families, and others who engage with it in good faith. These stakeholders are the Scheme’s most effective early-warning system. When they are treated fairly and with respect, risks are identified early, problems are surfaced, and accountability is shared.

When they are alienated, intimidated, or pushed into silence, those same risks go unreported, and the Scheme becomes weaker, not stronger.

Throughout the Explanatory Memorandum, the concept of “integrity” is repeatedly invoked. Yet integrity is not achieved by pushing responsibility downward, by blaming those with the least power, or by intimidating people through deterrence and penalty. Integrity is built through system design — through fairness, capability, proportionality, and safeguards that prevent harm before it occurs.

Approaches built on imbalance and pressure may secure short-term compliance, but they do not produce durable safety or public trust.

Taken together, these concerns point to a Scheme at risk of losing alignment with its stated purpose. Integrity cannot be built by standing over those with the least power. That approach is outdated, ineffective, and corrosive to trust. In 2026, people expect public institutions — particularly those entrusted with the lives and wellbeing of people with disability — to act with restraint, competence, and respect.

| NDIS Amendment (Integrity snd Safe Guarding) Bill 2025

Initial Risk Assessment:

The review of the amendment for this submission has been completed utilising a risk based process, aligned to International and Australian standard for risk management ISO/AS 31000:2018. The identification of these initial risks form the basis of this submission .

Risk Description

  1. Harm

  2. Cost

  3. System Viability

  4. Business and Market Understanding

  5. Legal and Governance Risk

  6. Loss of Trust and Goodwill

Giving the NDIS greater enforcement powers before fixing the underlying systems will cause more harm, not less. Without proper quality, risk and safety controls, faster and stronger decisions just mean participants get hurt more quickly.

Cracking down harder without fixing the system will increase costs. More disputes, more administration, more legal action and more crisis responses all add up to higher overall Scheme costs.

The NDIS cannot work the way it was intended until a proper, integrated, third-party quality management system is in place. You cannot regulate outcomes if the system producing them is not properly designed or controlled.

There is a clear lack of understanding within NDIS decision-making about how businesses and markets actually work. This leads to unrealistic assumptions about provider behaviour and ineffective regulatory responses.

The proposed changes create serious legal and governance risks that are not being properly recognised or managed. These include risks in employment law, consumer law, procedural fairness, the right to silence, whistleblower protections and model litigant obligations.

The NDIS has damaged its relationship with participants and families. That trust and goodwill is the Scheme’s strongest protection against failure, and losing it weakens the entire system.

Note: The completed full risk assessment of the Amendment Bill is Annexure 6. 29 January 2026 — Completed by L. Howard-Fielding

| NDIS Amendment (Integrity and Safeguarding) Bill 2025

Response to Explanatory Memorandum — INDEX |

1

Misuse of Royal Commission Authority and Consultation Claims 6 2 Government-Asserted Reasons for the Amendment Are Not Fully Disclosed 6 3 Disputes in the NDIS Arise from Cost, Not Misconduct 13 4 The NDIS Shift in Expectations and Priorities, Ignoring the Australian Prosocial Behaviours 13 5 Participants Are Not Excluded from the Practical Operation of Enforcement Powers 15 6 System Failures Maintained by Design 16 ; Case Study 1: “The Big Australian Vs the Bigger Australian: Comparative Excellence in Managing 19

Risk”

Conflict with Administrative Review Tribunal Reasoning 24 9 Manufactured Non-Compliance 24 10 Suppression of Advocacy and Access to Justice 24 11 Parallel Civil and Criminal Exposure and Compliance to other Legal Principles 24 12 Human Rights — Significant risks 29 13 Case Study 2: “With or Without Prejudice: The Catastrophic Risk of Litigation” 34 14 System Evidence Check: Complaint Volumes, Tribunal Escalation, & Model Litigant Risk 35 15 Safeguarding Framed as Participant Protection While Extending Institutional Protection 35 16 Structural Indicators of Cost Containment Within a Safeguarding Framework 38 17 Anti-promotion Orders, Section 4 of the Act, and System Integrity 39 18 Integrity Powers As Market Regulation in a System That Tolerates Over-Charging 42 19 Explanatory Memorandum vs ISO-Aligned Quality Management Systems and Proposed Powers 44 20 Auditor-General Findings on System Readiness and Enforcement Architecture 50 21 Cost Implications of the Proposed Amendments 51 22 Reactive Penalties and Lowered Evidentiary Safeguards Instead of Fixing the System 56 23 Summary: Key Findings 58 24 Closing Summary 60 25 Drivers for Committee Recommendations 63 26 Committee Recommendations 64

Annexure 1 — Case Study 1 “The Big Australian Vs the Bigger Australian: Comparative Excellence A2

in Managing Risk” Annexure 1.A, 1.B, 1.C — Case Study 1, Tables: Governance Architecture, Complaints Handling = A3-A5 and Risk Management

es AG

Annexure 3 - Table: Legislative and Explanatory Memorandum References (Expanded) Al14

Annexure 4— Table: outcomes from ART That already make decisions about items in explanatory A16

memorandum

Annexure 5 — Table: Critical analysis of item examples in EM + findings A18

Annexure 6 — Completed Risk Assessment of Proposed Amendment Bill A22 4 29 January 2026 —- Completed by L. Howard-Fielding

| Submission

  1. Misuse of Royal Commission Authority and Consultation Claims

The Explanatory Memorandum repeatedly invokes the findings of the Royal Commission into Violence, Abuse, Neglect and Exploitation of People with Disability as justification for the measures contained in the Billi It also asserts that consultation participants were “largely supportive” of strengthening accountability and enforcement within the NDISii.

This framing is misleading.

Support for the existence of safeguarding reform, or alignment with the objectives of the Royal Commission, cannot be assumed to constitute support for the specific mechanisms proposed in this Bill. The Royal Commission did not recommend the introduction of broad, coercive compliance powers divorced from robust procedural safeguards, nor did it advocate for a regulatory model that relies primarily on deterrence through penalty escalationiii

Throughout the Explanatory Memorandum, references to the Royal Commission are used as a rhetorical foundation for measures that go well beyond what the Commission contemplatediv This creates the impression that the Bill is a faithful implementation of the Royal Commission’s recommendations, when in fact the Commission emphasised systemic capability, cultural reform, accountability through competence, and participant-centred safeguards — not fear-based compliance or punitive overreach.

Similarly, the description of consultation outcomes risks overstating the degree of support for these amendmentsv.

Agreement that participant safety must be strengthened does not equate to endorsement of expanded penalty frameworks, reduced discretion safeguards, or regulatory tools that materially increase power imbalances within the Scheme.

Legislation of this significance should not rely on implied consent or borrowed authority.

Where the Royal Commission is cited, it should be done accurately and consistently with its findings, not as a generalised or misinterpreted justification for measures it did not recommend.

  1. Government Asserted Reasons for the NDIS Amendment (Integrity and Safeguarding) Bill 2025 (As articulated in the Explanatory Memorandum) Are Not Fully Disclosed The outline at the start of the EM provides six points that are said to be what the amendment bill “…will do”vi once again, just on the first page there is misleading information in regard to this legislation, not only provides a misrepresentation of what these amendments will do in the impact they will have, but they are also inflammatory stating justification for implementing this legislation that are half-truth and are not supported by any documented verified facts. The language use is inflammatory and intentionally emotive, inferring that participants are at risk of harm if these amendments are not approved, and they exclude the true reason behind the amendment being put forward. Deceptive and inflammatory type of information follows through the entire memorandum justifying why it is needed, in many cases, contradicting itself in this same memorandum.

Page 6

The below list highlights the reasons that are most highlighted throughout the memorandum by the government and include, but are not limited to:

2.1 Systemic violence, abuse, neglect and exploitation require stronger regulatory intervention

  • “The Royal Commission and the NDIS Review identified systemic issues of abuse, eglect and exploitation of people with disability…” (Explanatory Memorandum, Schedule 1 – Background)
  • “The Bill will address current concerns of safety and non‑compliance within the Scheme…” (Explanatory Memorandum, Background)
  • “The Royal Commission found that across all age groups, a greater proportion of people with disability experience violence…” (Explanatory Memorandum, Schedule 1 – Background).

Note: The Explanatory Memorandum relies on Royal Commission and Review findings as foundational justification for expanded powers, without demonstrating how current system data independently verifies scale or persistence and by aligning the objectives of this amendment with findings from the Royal Commission in a misleading way when the intentions of the finding were not in support of what is being claimed.

2.2 The NDIS Quality and Safeguards Commission requires stronger enforcement powers

  • Several submissions … highlighted that the Commission “lacks ‘teeth’ to respond to concerns about provider conduct.” (Explanatory Memorandum, Schedule 1 – Background).
  • “The Commission needed to move towards a more active regulation model, focused on monitoring and enforcement rather than education.” (Explainatory Memorandum, Schedule 1 – Background).

Note: The asserted lack of enforcement capability is used to justify expanded discretion, rather than reform of internal systems.

2.3 Existing regulatory settings are too reactive and insufficiently proactive

  • “The NDIS Review … identified the need to adopt a more active approach to monitoring and a stronger regulatory position.” (Explanatory Memorandum, Background)
  • “These powers are intended to expand the ability for the Commission to be a proactive and formidable regulator.” (Explanatory Memorandum, Schedule 1 – Summary)

Note: The framing presumes enforcement expansion is the appropriate corrective mechanism, rather than system design or correct use of the system. Stating that the NDIS wants to be a formidable regulator infer that they wish to regulate using fear and intimidation as the preventative measures rather than having a strong robust system that proactively cannot be easily take advantage of. Preventing misuse of the NDIS is the best and only way to ensure there are no losses as waiting for people to do something wrong and then giving them a penalty comes after the loss have already been incurred.

There is no other sector of society that prevents wrongdoing by the regulator being formidable.

The most effective regulation occurs in industries and sectors where their systems are so robust you cannot take advantage of them. That is the best deterrent. Also regulators who provide those who are making complaints the most effective and efficient service, treating them with respect and being professional and how they investigate and get back to them with an update how they register their complaint and how seriously it is taken are also the most formidable because people who have genuine complaints are more inclined to spend the time to make them. How often do people see something wrong but don’t even bother putting in a complaint because they already know the system doesn’t work and it won’t be followed up and they’ll be no outcome? …… The course of action is not based on any best practice examples of where this has worked, and is not even logical in its design because the system that is not working correctly cannot be formidable as it cannot manage the information that its is dealing with as it is (more pictured like a clumsy awkward scary clown falling over his own big shoes). One must get the complete processes right before it’s given more power to have more of an impact, otherwise it becomes a system that gains momentum and inevitably cause harm.

2.4 Fragmentation and inconsistency in safeguarding arrangements undermine participant safety

  • “The NDIS Review concurred that the Scheme is fragmented and that quality and safeguarding is not coordinated or consistent.” (Explanatory Memorandum, Schedule 1 – Background).

Note: Fragmentation is asserted as a rationale for centralised power, not as an operational systems failure requiring remediation. The whole point of a third-party quality management system is to provide a framework which connects everything within an organisation allowing for nonconformance and corrective actions to ensure continual improvement, to provide a baseline so the effectiveness of something that’s been implemented can be measured to ensure it is having the required outcome and to provide a mechanism to collect data so the system can be fully analysed and audited from every angle and where the core issues can be identified and corrected by looking at trends and different patterns in the organisations operations.

There could not be a fragmented scheme if this system was being utilised properly.

This is a failure of those who run the NDIS, being the same people who are asking for additional powers because they have failed to correctly and completely implemented a third-party quality management system that was identified as critical to the effective operation of the NDIS.

2.5 Existing penalties are insufficient and treated as a cost of doing business

  • “Strengthen the penalty framework to ensure a fit‑for‑purpose penalties and offences framework…” (Explanatory Memorandum, Outline, item 1)

  • “The penalty must not be viewed as a cost of doing business by the provider.” (Explanatory Memorandum, Part 2 – policy rationale).

Note: The EM asserts deterrence failure without evidencing penalty‑to‑behaviour analysis. This seeks to push the responsibility for the failure of the NDIS system down onto those who are trying to provide a service to it.

The NDIS has no way of preventing a business from factoring in the cost of penalties to their overhead costs which are added to the overall cost of goods or services.

Where this amendment has already highlighted that there is a risk the cost of penalties being passed on to the NDIS without providing any mechanism in which to prevent this occurring shows the NDIS is knowingly taking action that will likely increase its cost, not decrease them.

2.6 Serious and repeat non-compliance require clearer escalation threshold

  • “The concepts of ‘significant failure’ and ‘systematic pattern of conduct’ allow for higher penalties.” (Explanatory Memorandum, Part 2, Items 30–31; section 11B).

Note: Escalation relies on accurate classification and trend identification, which presupposes a functioning quality management system in circumstances where the NDIS itself has already acknowledged that it has a fragmented system that is not working or even fully implemented.

The NDIS has no way of knowing what “significant failures” and “systemic patterns” are because it cannot capture the data that would be required to undertake the analysis that could provide this conclusion.

The data it does have cannot be tested to have integrity because there is no benchmark in place (which s full integrated and functioning a third-party management system would provide) for it to be measured against. The concept of there being a systemic pattern is literally impossible because a system that does not have integrity and that is not fully implemented cannot be relied upon to provide such a result – and there is multiple admissions that the NDIS is fully aware of this.(I would propose the explanatory memorandum for this amendment be a prime example with multiple contradictions throughout this one document. If this cannot be produced to a standard with the data that is being used to produce it cannot be assessed to not contradict then what hope is there in a juggernaut system the size of NDIS?)

2.7 Unregistered or unsuitable providers pose heightened risks

  • “Deterrence against non-compliance is important as certain high-risk supports … require registration.” (Explanatory Memorandum, Part 2, section 73B).

  • “Participants may receive poor quality, unsafe or inadequate supports and be put at greater risk of harm.” (Explanatory Memorandum, Part 2, Item 33).

Risk Is Provider-Centric Without Addressing System Approval Or Oversight Failures

Note: Risk is framed as provider-centric, without addressing system approval or oversight failures. The most effective way to protect participants is to have a robust system that prevents non-compliance is the safer system. This is not achieved by increasing deterrent as those who would be deterred by potential punitive consequences have already made the decision to do the wrong thing. Thus, they are already accepting the risk of this occurring. It is not a deterrent.

Providers, Suppliers And Intermediaries Are Exploiting The NDIS Through Fraud Or Unethical Conduct

  • “This reinforces the requirement that anyone engaging in the NDIS must do so with integrity.” (Explanatory Memorandum, Schedule 1, Item 6; section 59A).
  • “Misrepresentation of the use of NDIS funds … undermines the integrity of the Scheme.” (Explanatory Memorandum, Part 4, Item 76 – Anti-promotion Orders).

Note: Assertions of exploitation are not accompanied by corresponding prosecution or conviction data. In fact, since the creation of an internal fraud department only 20 convictions have been made. Where it is claimed, penalties are required to prevent fraudulent activity, there are already mechanisms in place to hold people accountable for committing such acts. Using penalties as a mechanism to stop people miss using the system a reactive action that can only occur after the loss has been experienced. Having a system that has integrity that prevents this to begin with would be a far more effective way of preventing loss, prevent preventing it before it occurs. If cost-effectiveness is the priority, then using penalties to prevent loss is ineffective and will not provide cost savings, especially in circumstances where the NDIS has already identified that the cost of penalties could likely be factored into the price of goods and services as a cost of doing business (I have counted five separate times in this explanatory memorandum that this is highlighted, and regardless of how many times the NDIS states it cannot be included in the cost of doing Business….. there are no controls in place to stop penalties being included in the cost of doing Business“)

Stronger Information-Gathering Powers Are Required To Act Swiftly

  • “Strengthen the Commission’s powers to obtain relevant information … within shorter timeframes.”(Explanatory Memorandum, Outline, item 4).
  • “These changes will enable swifter action in investigating and prosecuting.”(Explanatory Memorandum, Background).
  • “The shorter period to comply with a notice to produce represents a deliberate departure from the requirement that a person be given a minimum of 14 days to comply with such a notice in A Guide to Framing Commonwealth Offences, Civil Penalties and Enforcement Powers” (Explanatory Memorandum, Part 5, Item 88)

Note: Speed is prioritised over evidentiary accuracy or safeguards against misclassification

Page 10

The NDIS is asking to have extraordinary powers over and above those that are in effect for all other Commonwealth departments on the basis that not doing so would put participants at risk of harm even though there are many other commonwealth departments who also have regulatory responsibilities that provide protections to vulnerable people that do not have these protections.

The example that is provided for Item 88, where a participant has been repeatedly assaulted by a support worker, it is said that the Commissioner requires employment and past training records from the support workers employer to investigate whether the support worker presents an ongoing risk to other participants…. In such circumstances the NDIS would be open to discrimination complaints if they tried to prevent the employment of someone who had not been proven to of committed what would be a criminal offence and preventing them from accessing employment without due process. regardless of the outcome of any investigation, the current system would not provide any mechanism that would prevent someone from being reemployed somewhere else due to there be no quality management system that providers have to adhere to.

To keep somebody’s name on a list of people that cannot be employed is the same as keeping a blacklist which is specifically unlawful under industrial relations laws.

The core issue with this example is the NDIS accepting responsibility for something that is not responsible for: it is not responsible for who is service providers employ. Trying to control something that you have no control over is impossible and a redundant exercise. The best and only way to address this issue would be to have a robust system that requires providers to meet certain standards before they are able to provide the service which includes the process in which they employ people and the qualifications and checks that need to be done prior to doing so.

There are so many things wrong with this example that it just highlights how poorly thought through this amendment really is as if the NDIS cannot identify the risks associated with one example that they’re putting in a document going to the Commonwealth government asking for amendments to the Law – then one could not expect it to be any more thought put into the knock on effect that these minutes will have as far as a full mapping of potential consequences with adequate controls put in place.

2.10 Financial sustainability of the NDIS requires stronger integrity controls

  • “This Bill will contribute to the annual growth target by strengthening Scheme integrity.” (Explanatory Memorandum, Financial Impact Statement).
  • “National Cabinet agreed … to return the NDIS to its original intent.” (Explanatory Memorandum, Background).

Note: Financial sustainability is framed through compliance and enforcement, not system efficiency or design

As per 2.8 above, the NDIS has already identified that there is a risk that penalties would be factored into the cost of doing business with the NDIS by service providers. after identifying this risk there has been no mention of any control to prevent this occurring and practically there could be no control. The NDIS could put in place that would stop any

entity factoring in a penalty to its overheads and then adding this into its margin for the provision of goods and services. As penalties are a retrospective action that occurred after the act that caused a loss, adding to this the the penalty will also be added to the cost incurred by the NDIS for the vision of goods and services that now have factored in the cost of such penalty - the use of penalties not only fails to prevent the loss of caring to begin with but also increases the likelihood of additional costs once these are affected into operating costs so this will only increase the cost to the NDIS not decrease.

   2.11   Expanded powers are compatible with and promote human rights
  • “The Bill is compatible with human rights and promotes the protection of people with disability.” (Explanatory Memorandum, Statement of Compatibility with Human Rights)

  • “Any limitation on rights is reasonable, necessary and proportionate.” (Explanatory Memorandum, Statement of Compatibility with Human Rights).

     Note: Compatibility is asserted in principle, contingent on proportional application by systems
     not yet demonstrated to be reliable or even in place.
    

    The six points at the start of this explanatory memorandum, that are said to describe what the amendments “will do” – are inaccurate and don’t describe the actual impacts this amendment will have, which are far wider reaching.

    Throughout the explanation memorandum there are numerous examples where the said intent of the amendment and what the actual impact of the attendant will be a vastly different with there being uncontrolled risks that are identified by the NDIS without any intent of mitigating those risks.

    There are also examples where the NDIS admits that the powers it is seeking are outside the constraints provided by other Commonwealth policies such as the “A Guide to Framing Commonwealth Offences, Civil Penalties and Enforcement Powers“ when there is a reason such guidelines are in place for use by all Commonwealth entities and that is to protect the rights of individuals. Operating outside of these is clearly impeding on the rights of individuals.

    Where the NDIS cannot explain how it would mitigate risks to individuals and in other sections where it openly admits that it does not know what the risks will be or how they will impact others we’re dealing with vulnerable members of the public and when invoking the power to have criminal charges against individuals. It is a serious risk to the Australian public to have such legislation passed.

    In circumstances where the NDIS system has failed and is not effective, which is admitted by the NDIS themselves multiple times throughout this memorandum, and even put forward as the reason why additional authorities are required, it is impossible that it can rely upon any information or data collected through the current system as there is no way to ensure this data has been verified and has integrity.

3. Disputes in the NDIS Arise from Cost, Not Misconduct

In practice, disputes within the NDIS overwhelmingly arise when a participant’s support needs increase or become more complex and therefore more costly. These disputes are typically supported by treating clinicians, allied-health professionals, functional-capacity assessments, and specialist reports.

They do not arise from fraud or wrongdoing. They arise from contestation over cost.

Participants are repeatedly required to justify disability and need, often in circumstances where withdrawal or delay of supports causes immediate harm, deterioration, or risk. Framing these disputes as “compliance” or “integrity” issues mischaracterises their nature and obscures the real driver: expenditure control.

The Explanatory Memorandum frames the Bill as targeting misconduct and deliberate wrongdoing. However, the mechanisms chosen embed enforcement tools into ordinary administrative processes, making lawful disagreement risky and re-casting need-based disputes as regulatory failure.

Administrative Review Tribunal reasoning consistently shows that disputes concern cost and necessity, not misconduct. Media reporting by the ABC and by Rick Morton has documented the withdrawal of supports during review despite medical evidence, forcing participants into adversarial proceedings simply to maintain safety.

Incoming amendments to the NDIS where there is a reduction in what the ART can make decisions on only compounds this risk.

The foreseeable consequence is deterrence of lawful review and chilling of dispute. Parliament is on notice that cost containment is being operationalised through coercive design.

The Australian Pro-Social Society

If you ask a person on the street, what is the biggest issue with the NDIS currently? You are likely to have them reply that it is people taking advantage of it, trying to exploit it, being greedy, “taking more than their entitled to” and “taking advantage” of a system that is there to help them.

This is indirect contrast to what is widely known of our society to be prosocial.

Australia’s national and community culture exhibits measurable prosocial behaviour, in which individuals’ self-initiate actions that benefit others and contribute to social cohesion. Prosocial behaviours — such as volunteering, acts of kindness, and contributions to community wellbeing — are widely recognised in Australian research as activities that enhance societal welfare and reduce social risk factors; volunteering is embedded in both formal strategies and community practice and is actively supported through national standards and frameworks to promote civic engagement. Moreover, Australian values as articulated in official social cohesion policy include respect for individual dignity, fairness, equality of opportunity, mutual respect and compassion for those in need — all of which reflect a collective expectation that people will act ethically and cooperatively in everyday life.

However, current NDIS regulatory design and integrity-oriented enforcement frameworks tend to assume non-compliance as the default starting point, positioning participants and providers as subjects of scrutiny rather than as agents of positive engagement. This contrasts with the documented prevalence of voluntary community participation and the cultural norm of compliance with societal rules, and thus risks undermining trust, reciprocity and cooperative behaviour that are otherwise available as strengths in the system’s implementation. A more pro-socially aligned approach would leverage these voluntary behaviours as positive inputs into risk management and quality assurance, rather than treating them as peripheral to an adversarial regulatory paradigm.

People advocating for what they need and what they have been told repeatedly they are entitled to is not greed and it is not being opportunistic, and it is certainly not trying to take advantage of a system that is there to help them.

What must be kept in mind

What must be kept in mind is that the participants did not come looking for the NDIS, the NDIS came to them at the same time the supports that many had been receiving through state government schemes were going to be replaced by his Commonwealth government scheme, it was the NDIS that was calling and knocking on doors and telling participants and those who provide care for them “ we are here to help, tell us what you need “.

It is not a matter of participants not knowing their place or being ungrateful or having unrealistic expectations - they are putting an application for things that they are told that they could have and told by experts that they need - an application for support is not a wish list. There are many examples of Australian citizens voluntarily choosing to do the right thing—often termed “prosocial behaviour” or adhering to social norms—are deeply embedded in the culture, frequently driven by the “fair go” principle, mateship, and community responsibility and it would be overlooking one of the most important tools the NDS has in controlling costs and keeping participants safe – is the underlying pro social way Australians value “doing the right thing”.

  1. Participants Are Not Excluded from the Practical Operation of Enforcement Powers While the Explanatory Memorandum frames the expanded compliance and enforcement powers as being primarily directed at providers, the legal structure of the Bill does not meaningfully exclude participants from exposure to those powers or their practical consequences. That exposure arises from the breadth of information-gathering powers, the application of coercive compliance mechanisms to persons generally, and the reliance on statements of intent rather than enforceable exclusions.

The Explanatory Memorandum expressly states that strengthened information-gathering powers apply beyond registered providers, noting that “the Bill strengthens the NDIS Quality and Safeguards Commission’s powers to obtain relevant information from NDIS providers and other persons within appropriate, shorter than minimum timeframes” The category “other persons” is not defined or constrained.

In practice, participants, nominees, family members and informal supports routinely hold information relevant to plan use, service delivery and funding decisions, and therefore fall within the scope of persons capable of being subject to compulsory information requests. This group of “other people” who raise complaints with the NDIS on behalf of the participants is reported by the NDIS year on year to raise the greatest number of complaints in comparison to the other group which include the participants, government ministers, support workers and members of the public

Further, the enforcement framework is structured around obligations imposed on “a person”, rather than on providers alone. The Explanatory Memorandum explains that “section 57 of the Act provides that a person commits an offence if the person refuses or fails to comply with a requirement to provide information or documentation” . It further states that “the availability of a civil penalty provision in addition to the existing offence provision will enable the Commissioner to take proportionate compliance action in circumstances where criminal

Prosecution may not be appropriate.* These provisions are not role-specific and do not distinguish between providers and participants where a participant is the recipient of a notice or request.

Although the Explanatory Memorandum repeatedly relies on assurances that the amendments are “not intended” to have inappropriate or unintended impacts, those assurances are expressed at the level of policy intent rather than embedded as enforceable statutory limits. For example, in relation to anti-promotion orders, the Explanatory Memorandum states that “the conduct that is subject to an anti promotion order … will not unduly impact or overlap with the Australian Consumer Law”, and that “normal advertising activities that do not undermine the NDIS are not intended to be covered”. These statements rely on asserted “intention” rather than statutory exclusion and do not prevent the practical application of broad discretionary powers to persons other than providers.

Taken together, these provisions demonstrate that while the Explanatory Memorandum asserts that the amendments are directed at providers, the legal operation of the powers permits their application to a wider class of persons. In the absence of explicit participant-specific exclusions or protective mechanisms, participants are not meaningfully protected from exposure to compliance and enforcement processes, notwithstanding repeated „statements of intent“ to the contrary.

  1. System Failures Maintained by Design In risk and quality-management terms, the sustained tolerance of a known failure state constitutes a design choice, irrespective of original intent.

Table 1: Repeated, Uncontrolled Systemic Failures and Consequences — NDIA Complaints and Decision-Making Ombuds. Findings Nature of the Failure Where the Control Is Supposed to Exist Control Point Other Reviews/Evidence Consequence & Impact (Actual & Potentia) Aud-Gen Findings (2023- Quality NDIA Complaints & Quality assurance Framework; CPIT operates ‘established’ significantly; no —_ unreliable enforcement risks assurance Feedback exists on paper but at only varied found safeguards outcomes: framework inconsistently need to lift QA targets, no applied without capability remediation assurance of decision benchmarks or loop quality thresholds Neiman CPI Quality Failures are not Formal No analysis or ANAO cross-entity Errors recur; system ance Checklist; Better formally recorded or _ identification tracking of findings show cannot learn from identification Practice Guide treated as essential to non-conforman same pattern failure non-conformances _ learning ces Corrective Continuous Issues identified but —_ Earlier Poor QA Internal NDIA Known risks persist action Improvement not corrected or recommendatio outcomes did reviews lacked over years; safety and credibility eroded processes Register; CPIT tested for ns not fully not trigger implementation Quality Framework effectiveness implemented corrective plans action Continuous Complaints Complaints Improvement Complaints data RoyalCommission Participants forced to seucuiems Framework; CEP captured but not mechanisms not used to identified re-litigate the same improvement strengthening improvement unresolved issues translation into need drive recurring issues trend & internal complaints Focus on volume, Qualitative Lack of trend Royal Commission Systemic risks remain qualitative reporting not meaning or analysis and qualitative noted lack of hidden; harm analysis pattern required analysis learning escalates

Risk assessment

at intake

Escalation thresholds

Feedback into decision-making

Independent assurance

Was Governance accountability
Summary: What This Table Demonstrates

Complaints lifecycle Risk not consistently — Early risk Risk assessment RoyalCommission Deterioration in health procedures identified, recorded, _ identification not visible or highlighted and functioning; or escalated emphasised consistent unmanaged avoidable harm participant risk Complaint Escalation not linked — Proportional No linkage ART outcomes Participants forced complexity to risk severity bc escalation between risk show escalation into adversarial framework required and escalation after external tribunal processes pressure Complaints Outcomes not fed Integration with Effectivenessof ANAO cross-entity Same failures repeat; back into operations service data changes not findings confirm system blind to impact governance required monitored issue Ombudsman Assurance not Below QA internally Royal Commission _ Participants lack oversight; CPIT QA independent or ‘superior’ managed and flagged oversight protection; power complete maturity incomplete gaps imbalance entrenched Executive QA Governance Stronger QA reports left ANAO highlighted —_ Failures normalised; receives unreliable feedback loops in draft; no lack of baseline accountability or incomplete data required response evidence weakened

Across multiple independent reviews, the same types of failures appear again and again. Taken together, they reveal not a series of isolated shortcomings, but a persistent pattern of systemic failure that has remained unresolved despite repeated identification.

6.1 The failures are similar in nature

The issues identified are not random, and they are not marginal. They consistently involve:

  • weak and inconsistent quality assurance,
  • the absence of formal non-conformance handling,
  • failure to correct known and documented problems,
  • alack of learning from complaints and adverse outcomes, and
  • escalation occurring only after external pressure is applied.

These are the basic control mechanisms that any mature system relies on to prevent harm. Their repeated failure points to a system that is structurally unable to self-correct.

6.2 They have been repeatedly identified

These same issues have been identified, independently, by:

  • the Commonwealth Ombudsman through maturity assessments and better-practice reviews,
  • the Auditor-General in 2023-24,
  • the Royal Commission into Violence, Abuse, Neglect and Exploitation of People with Disability, and
  • indirectly through outcomes at the Administrative Review Tribunal, where matters are frequently resolved only after escalation.

This is not new information. It is well known, well documented, and repeatedly acknowledged.

6.3 They have not been controlled

Despite this identification:

  • recommendations have not been fully implemented,
  • corrective actions have not been consistently triggered, and
  • governance oversight has not intervened in a way that stabilises the system.

The result is recognition without control. Problems are observed, named, and reported — but not reliably fixed. The same risks reappear, often described in similar language years apart.

6.4 They continue to present real and ongoing harm The consequences of these failures are not theoretical or abstract.

They are experienced by real people, in real time.

Participants experience:

  • deterioration in health and functioning while waiting for decisions to be corrected,
  • prolonged uncertainty and distress, and;
  • forced escalation through complaints and tribunal processes simply to obtain what they were originally entitled to.

Families and carers absorb the emotional and practical burden, often while trying to protect loved ones who cannot advocate for themselves. At the same time, the NDIA incurs avoidable legal and administrative costs, diverting resources away from supports and into litigation and process.

Most critically, enforcement and penalty powers risk being applied on top of unstable foundations, magnifying harm rather than preventing it.

6.5 The core risk is systemic — and deeply human The most serious issue revealed by this table is not procedural. It is moral.

Expanded enforcement and penalty powers are being layered onto a system that oversight bodies have repeatedly found to lack reliable internal controls — and the people exposed to this risk are those least able to defend themselves.

No one is systematically measuring:

  • the cumulative impact on participants,
  • the harm caused by delay, uncertainty, and repeated escalation, or
  • the lived experience of being trapped in a system where there is no real ability to manage risk.

Participants cannot negotiate away their rights. They cannot absorb delay without consequence. They cannot mitigate harm by opting out.

They have no capacity to manage the risk being imposed on them, because the risk relates to their health, their safety, their dignity — and in some cases, their right to life.

  1. Annexure 1: Case Study 1 The Big Australian Vs the Bigger Australian: Comparative Excellence in Managing Risk BHP vs NDIS

Overview: Why BHP and the NDIS Are Comparable

7.1 Although BHP Group Limited (BHP) and the National Disability Insurance Scheme (NDIS) opera te in different sectors, they are comparable in terms of: 7.1.1 Annual operating budgets NDIS ~$46–48 billion AUD (Cost/Exp) & BHP ~US$51–55 billion (Revenue) 7.1.2 Both require massive, consistent, and urgent financial injections (capital investment for BHP; plan payouts for NDIS) to sustain operations 7.1.3 Both have heavy involvement with government regulations—BHP as a major taxpayer (US$11.2B in 2024) and NDIS as a government-run, publicly scrutinised scheme. 7.1.4 Both have recently focused on “sustainability”—NDIS via reforms to curb 20%+ growth down to 10%, and BHP through capital investment in “future-facing” commodities like copper. 7.1.5 workforce reach, 7.1.6 Similar Annual average spends per person ($67,200 average plan spend vs $116,000 average employee salary) 7.1.7 Similar. Annual administration costs (NDIS $1.6B vs BHP $2.1B annually) 7.1.8 exposure to life-critical risk. 7.1.9 The nature of the work they do is inherently high risk and sensitive environment 7.1.10 both operate in situations where there is a significant imbalance of power between themselves and their stakeholders 7.1.11 Where the stakeholders are often dependent on them or easily impacted by their decisions and actions 7.1.12 Where they have material and financial impact over the market in which they operate 7.1.13 They both operate in inspectors whether there is high demand for their services and little competition if any 7.1.14 Both are mega-entities whose decisions have direct, sometimes catastrophic, consequences for human life, public trust, and the wider economy. 7.1.15 both are examples of Australian initiative,

7.2 If governance fails, both systems have the potential to cause catastrophic loss of life. For BHP, this may occur through industrial accidents, infrastructure failure, or environmental disasters. For the NDIS, catastrophic outcomes can arise through the withdrawal, delay, or mismanagement of life-sustaining supports, including supports essential for breathing, feeding, mobility, supervision, medical access, and personal safety.

Page 19

7.3 In both contexts, failure attracts intense adverse media attention, public outcry, and

regulatory scrutiny, with the potential for licence suspension, loss of authority to operate,

or major structural intervention. Failure also creates cascading impacts across contractors,

suppliers, service providers, employees, families, and communities who depend on the

system

7.4 Both are subject to high inflationary pressures. NDIS expenses are driven by participant

plan inflation, while BHP faces high labor and input costs (roughly 4% inflation in FY24).

7.5 Economic dependency: Entire regional towns in Western Australia would collapse without

BHP’s payroll and local subcontracts. Similarly, many allied health businesses (Physio, OT,

Speech Pathology) and care agencies across Australia are now 100% dependent on NDIS

funding to keep their doors open

7.6 Both BHP and the NDIS operate with a profound imbalance of power between the entity

and those with whom it deals. They set the rules of engagement, control access to essential

resources, and possess significantly greater legal, administrative, and informational power

than individual workers, contractors, communities, participants, families, or small

providers. Where power is so concentrated, governance standards must be higher, not

lower

Table 2 Indicative Scale and Risk Comparison

Dimension BHP Group Limited NDIS
Annual financial scale = AUD $70-80 billion annual revenue = AUD $40-50+ billion annual public expenditure
Administration Costs ~USS1.34 _ Billion
(Selling & Admin)
~2.4% (S&A as % of revenue)
(“A$2.1B) ~AS1.6 Billion
(Operating Costs)
~3.3% (Admin as % of total spend)
(Agency
People directly affected = §80,000-90,000 employees;
large global contractor workforce
= 600,000+
hundreds support workers
participants;
of thousands of
Delivery model Heavily reliant on contractors
and third-party suppliers
Heavely reliant on registered
providers and __ third-party services
Nature of risk Industrial safety, environmental,
catastrophic operational risk
Life-sustaining personal,
medical, and safety support risk

Failure consequence

Regulatory exposure

Power imbalance

Multiple fatalities, environmental harm, sovereign and legal risk

Licences, approvals, and authority to operate can be

suspended or revoked

Significant imbalance between corporation and workers, contractors, communities

Preventable death, serious harm, neglect, family and

community collapse

Scheme authority, safeguards, and operating model subject to removal or overhaul

Significant imbalance between Scheme and __sparticipants, families, providers

7.7 Purpose, Scope and Methodology

This case study forms part of a broader submission examining governance, safeguarding, risk management, complaints handling, and enforcement practices within the National Disability Insurance Scheme (NDIS). It provides a detailed comparative analysis between the operational model of the NDIS and the governance systems used by BHP Group Limited

(BHP), one of the world’s largest and most highly regulated organisations. [EM-1][ISO-1]

The analysis is grounded in internationally recognised standards and frameworks, including ISO 31000 (Risk Management), ISO 10002 (Complaints Management), ISO 9001 (Quality Management Systems), and the COSO Enterprise Risk Management Framework. These frameworks emphasise prevention, accountability, and system-level controls rather than retrospective punishment. [ISO-1][ISO-2][ISO-3][COSO-1]

The purpose of this case study is to demonstrate that scale, complexity, and financial exposure do not justify coercive enforcement models where mature, integrated governance systems exist. Rather, effective safeguarding and cost control are achieved through system design, accountability, and prevention, consistent with the intent articulated in the Explanatory Memorandum to the NDIS Amendment (Integrity and

Safeguarding) Bill. [EM-2]

This analysis does not question intent or individual conduct. Instead, it examines system design, decision sequencing, accountability pathways, and structural outcomes, with particular reference to whether current NDIS enforcement practices are supported by the

Governance and quality systems assumed by the Explanatory Memorandum. [EM-3]

7.8 Scale, Complexity and Risk Exposure

BHP operates across multiple jurisdictions with tens of thousands of employees and contractors, and is exposed to catastrophic safety, environmental, legal, and financial risks. Failures within BHP’s operations can result in loss of life, irreversible environmental

damage, and sovereign-level economic consequences. [BHP-1]

20 29 January 2026 — Completed by L. Howard-Fielding

Despite this risk profile, BHP is not governed through routine punitive enforcement against contractors, employees, or counterparties acting in good faith. Instead, it relies on integrated enterprise systems, rigorous pre-qualification, continuous risk assessment, and clear managerial accountability. [ISO-1][BHP-2] The NDIS, while operating within a single jurisdiction and with a different statutory purpose, nonetheless manages a multi-billion-dollar public scheme involving vulnerable participants and complex service delivery chains. Consequences of failure include deterioration of participant health, withdrawal of essential supports, and loss of public trust. These risks demand sophisticated governance systems, as contemplated by the NDIS Act and related operational guidelines. [NDIS-Act-1][NDIS-Safeguards-1]

7.9 Governance Architecture and Accountability In BHP-style organisations, governance architecture is deliberately designed to retain accountability within the organisation. Responsibility for risk, complaints, and system performance flows vertically through named management roles to senior executives and ultimately to the board. [ISO-1][COSO-1] This architecture aligns with ISO 31000 principles requiring clear assignment of authority, responsibility, and accountability for risk outcomes. Governance failures are treated as internal management issues requiring system correction and assurance. [ISO-1][ISO-3]

By contrast, accountability within the NDIS is frequently displaced outward to participants, providers, tribunals, and external oversight bodies. Decision-makers are often insulated from downstream consequences, creating a diffusion of responsibility that would constitute a material governance weakness under ISO-aligned frameworks. This is inconsistent with the safeguarding intent expressed in the Explanatory Memorandum. [EM-4]A detailed governance comparison is provided at Annexure 1

7.10 Complaints Handling as an Early-warning System ISO 10002 establishes complaints as a critical feedback and early-warning mechanism, intended to identify emerging risks, system weaknesses, and service failures before harm escalates. [ISO-2] In BHP-style organisations, complaints are not treated as allegations by default. They are triaged, risk-rated, and managed through structured workflows prioritising harm prevention, resolution, and continuous improvement. Non-reprisal protections are embedded by design. [ISO-2][BHP-3]

Within the NDIS, complaints and claim disputes are frequently reframed as compliance or integrity matters at an early stage. This reframing can trigger enforcement responses—such as claim denial, recovery action, suspension, or referral—before meaningful risk assessment or harm mitigation occurs. [NDIS-Complaints-1][EM-5]

                                                                                                     21

This approach undermines the protective function of complaints systems described in NDIS policies and discourages early disclosure of risk. A detailed comparison is provided at Annexure B. [NDIS-Safeguards-2]

Risk Management Sequencing and Decision Logic ISO 31000 requires risk to be identified, analysed, evaluated, and treated before harm occurs. Enforcement is intended to operate as a final control, not as a substitute for risk assessment or treatment. [ISO-1]

BHP operationalises this framework through manager-led risk ownership, documented decision rationales, formal risk matrices, and continuous monitoring and review. Risk treatment focuses on prevention and control before escalation. [BHP-2][ISO-1]

The NDIS frequently reverses this sequence by applying enforcement or administrative action before undertaking meaningful risk analysis or implementing preventative controls. In practice, harm may occur first, with correction deferred to external review or tribunal processes. [EM-6][NDIS-Operational-1 A detailed risk sequencing comparison is provided at Annexure 1A and 1B

7.11 Managerial Accountability for Risk Decisions mature governance systems, managers are explicitly accountable for risk decisions and outcomes. They are required to exercise professional judgment, document reasoning, and remain accountable for both action and inaction. [ISO-1][ISO-3] Within the NDIS, risk decisions are often fragmented across teams, systems, and outsourced processes. This fragmentation weakens accountability and creates incentives to externalise risk and responsibility, contrary to accepted governance principles. [ANAO-1][RC-1]

7.12 Integrated System Architecture and Capability Gaps BHP-style organisations rely on integrated enterprise systems linking contractor management, policy and procedure control, training and competency validation, complaints handling, risk management, and assurance. These systems prevent non-compliance by design. [ISO-3][BHP-4]

The NDIS lacks equivalent integrated infrastructure. Core functions operate in silos, despite enforcement powers that assume the existence of mature, integrated systems. This gap is recognised in multiple audit and review reports. [ANAO-2][EM-7] A detailed system capability gap analysis is provided at Annexure 1C

7.13 Implications for Safeguarding and Enforcement Expanse Expanding enforcement or penalty powers without first implementing ISO-aligned governance systems risks entrenching harm, escalating administrative and legal costs, and undermining trust in the Scheme. [EM-8][ANAO-2]

Conclusion

This case study demonstrates that the NDIS enforcement model is structurally misaligned with internationally recognised governance standards. Organisations such as BHP show that safeguarding, cost control, and accountability are achieved through system design and managerial ownership rather than coercive enforcement.

Until comparable system foundations exist within the NDIS, expanding penalty or enforcement powers is inconsistent with international standards, the Explanatory Memorandum’s stated objectives, and basic principles of good governance.

  1. Conflict with Administrative Review Tribunal Reasoning The ART exists to correct imbalance, ensure fairness, and prevent administrative overreach. Tribunal reasoning has consistently emphasised proportionality, restraint, and continuity of supports during review.

The Explanatory Memorandum asserts that the Bill does not undermine review rights. However, the Bill enables escalation and enforcement during active disputes, structurally conflicting with Tribunal principles and rendering review rights increasingly hollow.

Parliament is on notice that the Bill undermines the corrective function of the ART.

  1. Manufactured Non-Compliance Non-compliance does not need to be deliberate to become actionable. It can be produced through administrative delay, inaccessible communication, shifting information demands, trauma responses, cognitive impairment, or lack of advocacy.

The Bill introduces expanded notice and information-gathering powers without corresponding disability-aware safeguards. This enables the State to create the conditions of breach and then penalise the outcome.

Parliament is on notice that the Bill enables enforcement against incapacity, not misconduct.

  1. Suppression of Advocacy and Access to Justice Participants cannot afford legal parity with the State. Advocacy is not optional in the NDIS system — it is essential. Provisions extending regulatory reach to those assisting participants create a chilling effect on advocacy, entrenching inequality and deterring lawful dispute.

Parliament is on notice that suppressing advocacy undermines access to justice.

11. Parallel Civil and Criminal Exposure and Compliance to other Legal Principles

11.1

The concurrent design of civil penalty provisions, criminal offences, and expansive information-gathering powers in the Bill also raises significant international human rights considerations. Article 14 of the International Covenant on Civil and Political Rights (ICCPR), to which Australia is a party, enshrines the right to a fair and public hearing by a competent, independent and impartial tribunal, and the presumption of innocence in criminal proceedings. Article 14 further encompasses the privilege against self- incrimination, which is reflected in Australian administrative law principles and recognised by domestic jurisprudence as a core component of procedural fairness. This privilege safeguards individuals from being compelled to provide information in one forum that may be used to establish criminal liability in another.

11.2

Under the Bill’s structure, a person may be required to give information or explanations during civil or administrative proceedings — for example under a compliance notices regime or in response to an NDIS Commission investigation — that could later form part of the evidentiary basis for criminal charges. Clauses such as the expanded information- gathering powers in Part X (e.g., powers to require production of documents, compelling attendance and questioning) and the concurrent civil penalty regime mean that information provided under compulsion in an administrative review could, in practice, be relied upon in a subsequent criminal prosecution unless explicit protections are placed on its use. While the Bill includes various civil compliance mechanisms and enforcement pathways, it does not, on its face, provide a statutory bar on the use of compelled information in later criminal proceedings.

11.3

Without statutory immunities or clearly articulated procedural safeguards — such as use-immunity or explicit separation of enforcement streams — affected persons may be forced to choose between defending their interests in civil or administrative forums and preserving their right to silence in relation to potential criminal exposure. The High Court has repeatedly acknowledged that compulsion to answer questions or produce material that is then used in a criminal context can infringe the privilege against self-incrimination and jeopardise fairness in criminal adjudication.

11.4

The Robodebt Royal Commission’s findings on coercive system design are directly instructive, as it concluded that harm — including profound psychological distress — was a foreseeable consequence of processes that compelled participation and explanation in administrative enforcement without adequate protections or clarity. Parliament is therefore on notice that where civil and criminal enforcement powers run in parallel without robust safeguards, there is a real risk of incompatible outcomes with Australia’s human rights obligations under ICCPR Article 14 and longstanding common law principles concerning the privilege against self-incrimination.

11.5 Harmans Obligation

In addition, the Bill’s enforcement architecture engages Harman’s obligation and the Commonwealth’s Model Litigant obligations, both of which impose constraints on how

Section 11: Legal Obligations

11.5 Use Limitation under Harman’s Obligation

information obtained through compulsory or limited-purpose processes may be used by the State. Harman’s obligation requires that information or documents obtained under compulsion, or through legal or quasi-legal processes for a specific purpose, not be used for any ulterior or collateral purpose without lawful authority. Where the NDIS Commission or associated agencies compel the production of information for regulatory, safeguarding, or civil compliance purposes, and that same material is later relied upon to support criminal enforcement, civil penalties, or punitive regulatory action beyond the original purpose, there is a material risk that Harman’s obligation may be engaged or breached unless explicit statutory authorisation or use-limitation safeguards are in place.

11.6 Model Litigant Rules

Similarly, the Commonwealth’s Model Litigant obligations require agencies to act fairly, consistently, and in accordance with the highest standards of integrity when dealing with individuals, including by avoiding the use of technical advantages, coercive practices, or unfair surprise. Pursuing an individual or entity using material that was obtained under compulsion for a different regulatory purpose — particularly where the person was not clearly informed of the potential downstream uses of that information — risks undermining these obligations. In circumstances where civil, administrative, and criminal pathways operate concurrently, the absence of clear firewalls, use-immunity provisions, or disclosure constraints increases the likelihood that enforcement action may be perceived as unfairly leveraging the State’s superior position, contrary to Model Litigant principles. Taken together, these risks reinforce the need for explicit statutory safeguards to ensure that information gathered under the Bill is used strictly for its stated purpose, and that enforcement conduct remains consistent with Australia’s legal obligations governing fairness, proportionality, and proper use of compulsory powers.

11.7 Officers of the Court, Pursuit of Justice, and Enforceable Professional Constraints

Under the Legal Profession Uniform Law and the Australian Solicitors’ Conduct Rules, solicitors are not merely representatives of a client but are, above all else, officers of the court, owing a paramount duty to the administration of justice. That duty prevails over all other obligations, including the duty to act in a client’s interests, and governs how solicitors may obtain, question, and rely upon information, particularly in regulatory and enforcement contexts involving power imbalance, stress, vulnerability, or compulsory processes.

The nature of this obligation has been articulated by the Honourable Justice David Ipp, who identified core characteristics of an officer of the court. Relevantly, an officer of the court must:

  • Act in the interests of justice, not merely in the interests of the client.
  • Assist the court to arrive at a correct and just outcome, rather than to secure advantage through imbalance of power or technicality.
  • Refrain from conduct that undermines procedural fairness or the integrity of legal processes.
  • Avoid taking unfair advantage of another person’s vulnerability, ignorance, inexperience, or lack of representation; and
  • Maintain public confidence in the administration of justice, recognising that legitimacy depends upon fairness, restraint, and ethical conduct.

These principles are not aspirational. They are given direct, enforceable effect through the Australian Solicitors’ Conduct Rules, which spell out specific professional constraints that apply equally in regulatory, investigative, and enforcement settings.

How the Solicitors’ Conduct Rules Give Effect to the Ipp Principles

    11.7.1  Acting in the interests of justice, not merely the client
            This principle is reflected in the overarching ethical framework requiring
               solicitors to act consistently with the administration of justice and not to
         pursue outcomes through coercion or exploitation. Rule 5.1 expressly prohibits
         conduct that would undermine justice:

          Rule 5.1 — Dishonest or disreputable conduct
         "A solicitor must not engage in conduct in the course of legal practice or
          otherwise which … is likely to a material degree to be prejudicial to, or diminish
            public confidence in, the administration of justice." 
           This obligation applies regardless of whether the conduct occurs in litigation,
          regulatory investigations, or administrative enforcement.

     11.7.2  Assisting the court to reach a correct and just outcome
      A solicitor’s role as an officer of the court requires conduct that promotes
              fairness and clarity, not pressure or distortion of a person’s understanding of
              their position. This is reinforced by the duty to act honestly and courteously:

           Rule 4.1 — Other fundamental ethical duties
          "A solicitor must be honest and courteous in all dealings in the course of legal
               practice."
             Professional standards guidance recognises that courteous conduct includes
            respect for dignity and the avoidance of language or behaviour that is
             oppressive, demeaning, or designed to coerce — particularly relevant where
            explanations or admissions are sought from persons under stress.

    11.7.3  Refraining from conduct that undermines procedural fairness or integrity
        The conduct rules expressly prohibit oppressive or coercive behaviour that
        would compromise fairness in legal or quasi-legal processes. Rule 5.1 captures
         conduct that includes bullying, intimidation, or coercive questioning:

          Rule 5.1 — Dishonest or disreputable conduct
         "A solicitor must not engage in conduct … likely to a material degree to be
             prejudicial to, or diminish public confidence in, the administration of justice." 
                                                                                                     26

Avoiding Unfair Advantage Through Coercion

This rule has been interpreted as extending to conduct that improperly pressures individuals to participate, explain, or admit matters without proper regard to their rights or circumstances.

Avoiding unfair advantage of vulnerability or lack of representation

Justice Ipp’s articulation of this principle is given direct expression in the rules governing vulnerability and unrepresented persons:

Rule 4.2 — Undisclosed personal advantage and abuse of trust

“A solicitor must not take advantage of a person’s vulnerability, ignorance, inexperience or misfortune.”

This obligation applies whether the person is a client, witness, or respondent in a regulatory or compliance matter and captures situations of stress, fear of consequences, disability, or situational disadvantage.

In addition: Rule 9.3 — Disclosure and fairness in dealing with unrepresented persons

“A solicitor must not take unfair advantage of a person who appears to be unrepresented.”

This is particularly relevant where a person is under pressure to provide explanations or admissions in regulatory or enforcement processes.

Maintaining public confidence in the administration of justice

Public confidence is undermined where individuals are pressured, discriminated against, or treated unfairly in the exercise of state power. The conduct rules expressly prohibit discriminatory conduct:

Rule 6 — Respect for rights and duties of others

“A solicitor must not act in a way that suggests disrespect for a person’s race, religion, gender, national or ethnic origin, sexual orientation, disability or age.”

This rule applies across all contexts, including regulatory investigations, compliance meetings, compelled witness interactions, and enforcement actions.

Relevance to Regulatory and Enforcement Design

Taken together, these provisions demonstrate that solicitors — including those acting for regulators or the State — are ethically prohibited from exploiting stress, vulnerability, confusion, or power imbalance, and from engaging in coercive, oppressive, or discriminatory conduct. Where regulatory schemes rely on compelled explanations, admissions, or document production, particularly in circumstances where civil, administrative, and criminal pathways operate concurrently, these professional obligations are squarely engaged.

Absent clear statutory safeguards

Absent clear statutory safeguards, use-limitations, and separation of enforcement pathways, system design risks placing legal practitioners in ethically untenable positions and eroding the foundational principle identified by Justice Ipp: that the pursuit of justice must prevail over expedience, enforcement outcomes, or institutional convenience.

Note

  • ICCPR Article 14 as applied in Australia: It is part of our international obligations and underpins procedural fairness principles used by courts and tribunals when evaluating whether compelled information can be used in subsequent criminal contexts.
  • Privilege against self-incrimination: Not explicitly codified in all contexts in Australia but recognised in administrative law as arising from fundamental fairness requirements (see Petrovic v R and similar authority).
  • Cross-references to Bill clauses: The examples I’ve given are illustrative of mechanisms in the Bill which may be engaged, not claims that those clauses cause specific harms.
  • I am not a lawyer and this is my best understanding of what the legal impacts are.(I was advised by my dad numerous times as a child that when I grow up I should pursue becoming a lawyer, to get paid for my natural talent of arguing…. at this point in life, I concede he may of had a point)

Human Rights – Internal Inconsistencies within the Explanatory Memorandum

This section identifies internal inconsistencies between the Statement of Compatibility with Human Rights in the Explanatory Memorandum (EM) for the National Disability Insurance Scheme Amendment (Integrity and Safeguarding) Bill 2025 and the detailed provisions described elsewhere in the EM. The examples below illustrate how the penalty and enforcement framework, as actually designed, conflicts with the assurances given about alignment with the Attorney-General’s Guide to Framing Commonwealth Offences, Infringement Notices and Enforcement Powers (the Guide) and with Australia’s human-rights obligations under the ICCPR and CRPD. [HR1]

Example 1 - Internal inconsistency with the Human Rights statement

In the Statement of Compatibility with Human Rights, the EM acknowledges that: “This Bill does propose new and increased penalties. The intention of these amendments is to clarify the circumstances which may elevate the seriousness of a contravention of the Act and align the penalty framework with the policy objective of determining serious and repeat instances of non-compliance. The significant increase in penalties has been considered and aligns with the A Guide to Framing Commonwealth Offences, Infrangment Notices and Enforcement Powers.”[HR2] On its face, that is an assurance that the penalty framework respects the Attorney- General’s Guide (the Guide) and, by extension, the safeguards it is designed to protect (presumption of innocence, fair hearing, proportionality). However, elsewhere in the same EM the drafters expressly concede that key elements of the penalty regime do not align with that Guide.

Deliberate departure from the Guide on strict-liability penalties

In the discussion of the new strict-liability offence for failing to comply with a banning order

(proposed section 73ZNA), the EM records that:

“Subsection 73ZNA(3) provides that strict liability applies for failing to comply with a banning order, with a penalty of 150 penalty units.”[HR3] and that:

“The pecuniary penalty for the strict liability offence represents a deliberate development from the standard strict liability penalty units in the A Guide to Framing Commonwealth Offences, Infringement Notices and Enforcement Powers.”[HR3]

The Attorney-General’s Department’s Guide, and the Australian Law Reform Commission’s summary of it, state that strict liability “should only apply for offences where the penalty does not include imprisonment, and where there is a cap of 60 penalty units for monetary penalties”.[HR4]

By contrast, this Bill:

  • imposes strict liability for breaching a banning order; and
  • attaches a 150-penalty-unit monetary penalty – two and a half times the Guide’s recommended cap – while simultaneously expanding monitoring, information-gathering and enforcement powers.

Far from “aligning” with the Guide, the EM admits a deliberate departure from its core protective settings.

Strict liability combined with expanded coercive powers

The same ALRC summary of the Guide emphasises that strict liability “should not be imposed where it is accompanied by an excessive or unreasonable increase in agency powers of control, search, monitoring and questioning”.[HR4] Yet this Bill couples:

  • new and expanded monitoring and information-gathering powers (shortened timeframes to comply with sections 55 and 56 notices, broader document and information requirements); and
  • new evidentiary certificate provisions (Part 7) that allow the Commissioner’s certificate to stand as prima facie proof of key facts in civil penalty and criminal proceedings, unless the person can disprove it; with:
  • substantially increased civil penalties, including strict-liability penalties well above the Guide’s recommended ceiling.

This is the precise combination - strict liability plus expanded coercive powers - that the Guide and ALRC say should be avoided if human-rights protections (presumption of innocence, fair trial rights, equality of arms) are to be respected.[HR4]

12.1.3 Penalty design versus “no cost of doing business” policy

The human-rights section also suggests that the penalties are calibrated and proportionate, designed simply to clarify seriousness and deter non-compliance. In other parts of the EM, however, the Government states that penalties:

  • must not be treated as a cost of doing business; and
  • are deliberately set at a level intended to bite financially, rather than operate as routine regulatory costs (for example, repeated statements that penalties “are not intended to be costed into doing business with the NDIS”).[HR6] Combined with:
  • the use of strict liability for high-value penalties; and
  • evidentiary certificates that ease the regulator’s path to enforcement,[HR5] thi demonstrates that the penalties are highly punitive in effect, even though they are framed as civil. Under the Guide, penalties that are primarily punitive or deterrent in nature should generally be left to the criminal law and accompanied by full criminal-process safeguards.[HR4]

12.1.4 Overall Human-Rights Risk From The Penalty Framework

Taken together, these internal inconsistencies support the conclusion that:

  • the EM’s human-rights section gives an assurance of alignment with the Guide and proportionality of penalties which is not borne out by the detailed provisions.
  • the Bill in fact deliberately departs from the Guide on strict-liability penalties, exceeds its recommended penalty caps, combines strict liability with expanded coercive powers, and uses evidentiary certificates in a way that shifts practical evidential burdens onto participants and providers; and
  • those features raise genuine concerns under the right to a fair hearing and the presumption of innocence in Article 14 of the ICCPR and sit uneasily with the CRPD requirement that safeguards in disability schemes be rights-enhancing, not rights-diminishing.[HR7]

12.2 Example 2 – Presumption Of Innocence Vs Evidentiary Certificates And Strict Liability

In the Human Rights discussion of criminal process rights (Article 14 ICCPR), the EM asserts that the presumption of innocence applies and that penalties can only be imposed and determined by the courts, which is presented as sufficient to ensure due process and compatibility with human rights.[HR2] However, elsewhere the EM describes measures that materially tilt the evidential and practical balance against participants and providers. First, the EM explains that the Bill will “provide for an evidentiary certificate signed by the Commissioner to be prima facie evidence of the matters specified in the certificate”, in order to allow “quicker and simpler court proceedings”.[HR5] In practical terms, this

Page 31

means that a certificate issued by the Commissioner is taken as correct unless and until the person can disprove it.

Secondly, the EM confirms that the Bill engages strict and absolute liability offences alongside very high civil penalties, designed to have a strong deterrent effect, and that some offences will carry heavy financial sanctions without a requirement to prove fault.[HR3][HR4]

Taken together, the use of evidentiary certificates and strict liability with substantial penalties shifts the practical burden of proof onto participants and providers who must displace the Commissioner’s version of events. This sits uneasily with the EM’s assertion that the presumption of innocence and fair-hearing rights are fully preserved under Article 14 ICCPR.[HR7]

Example 3 – “Not Arbitrary” Privacy Limits Vs Broad Information-Compulsion Powers

In the privacy component of the Human Rights section, the EM acknowledges that expanded powers to compel information and share protected NDIS Commission information engage the right to privacy (Article 17 ICCPR and Article 22 CRPD), but asserts that these interferences are “not arbitrary” because they are reasonable, proportionate and necessary for the Commission to operate as a proactive regulator and to obtain information in a timely fashion.[HR2][HR7] Elsewhere in the EM, however, the same measures are described in a way that emphasises breadth and coercive effect. The Bill delegates to the Commissioner power to make rules prescribing the persons or bodies to whom protected Commission information may be disclosed and the purposes of such disclosures, and states that the purpose is to ensure the Commission has the “requisite levers to compel information in a timely manner” where there is a risk of serious harm to a participant.[HR5][HR6]

The EM also uses examples where the Commissioner can demand employment histories, taining and supervision records and investigation documents from providers within five days (in relation to an allegedly abusive support worker), or sign-in logs and other documents within seven days where a banned director is suspected of ongoing involvement. Failure to comply can attract strict-liability offences and high penalties.[HR3][HR6] When combined, broad discretion to define recipients and purposes for information sharing, compressed compliance timeframes and strict-liability, high-penalty consequences look closer to open-ended surveillance and data compulsion than to a narrowly tailored, minimum-necessary interference with privacy. This conflicts with the assurances in the Human Rights section that the impact on privacy is modest, proportionate and non-arbitrary.[HR7]

Example 4 – “Regulatory” civil penalties vs overtly punitive, quasi-criminal design

In the Human Rights section, the EM relies on Parliamentary Joint Committee on Human Rights Guidance Note 2 to argue that the proposed penalties are civil and regulatory rather than criminal in nature, and that, as part of a regulatory scheme, they are appropriate,

proportionate and compatible with Articles 14 and 15 of the ICCPR.[HR2] The EM also asserts that the penalty framework aligns with the Guide.[HR2]

Elsewhere in the EM, however, the Government makes clear that the penalties are designed so they “will not be viewed as a cost of doing business by the provider” and to “eliminate the rhetoric that current penalties can be absorbed as a cost of doing business in the NDIS”[HR6]. This language indicates that penalties are deliberately calibrated to bite financially and to send a strong deterrent signal, rather than to function as routine administrative sanctions.

Under the PJC Human Rights criteria and the Guide, a civil penalty begins to look “criminal” in substance where it is primarily punitive or deterrent, and involves a substantial pecuniary sanction [HR4][HR8]. By openly characterising the penalties in these terms, and coupling them with strict liability and evidentiary certificates, the EM itself supports the conclusion that the regime is quasi-criminal in nature, even if labelled “civil”. This undermines the assertion that the penalties can be assessed under a more lenient standard of review for human rights purposes and that Articles 14 and 15 ICCPR are fully respected. [HR7][HR8]

Table 3 — Internal inconsistencies in the Explanatory Memorandum and corresponding human-rights conflicts

This table summarises specific points where the Explanatory Memorandum’s Statement of Compatibility with Human Rights is contradicted by its own clause-by-clause explanations and identifies the corresponding provisions of the ICCPR and CRPD engaged in each case.[HR1]

# EM - Human Rights claim (Statement of Compatibility) Conflicting text elsewhere in the Explanatory Memorandum Corresponding human-rights provision Short explanation of the conflict
1 “The significant increase Clause notes for proposed ——ICCPR Article 14(1)-(2) The Human Rights section tells Parliament that increased penalties align with the Guide and are proportionate. Elsewhere, the EM concedes a deliberate departure from the Guide’s protective caps and safeguards for people with disability. CRPD Articles 4(1) and 16 (proportionate safeguard for people with penalty units versus the Guide’s 60-unit benchmark), undermining the proportionality and fairness claimed.
[HR4][HR7]
in penalties has been section 73ZNA record that _— (fair hearing and “Subsection 73ZNA(3) presumption of innocence); CRPD
considered, and aligns “Subsection 73ZNA(3) provides that strict liability applies for failing to comply with a banning order, witha penalty of 150 penalty units”, safeguards for people imposes a very high strict-liability
with the Guide to Framing Commonwealth Offences, Infringement Notices and Enforcement Powers“ = and that “the pecuniary penalty for the strict liability offence represents a deliberate departure from the standard strict liability penalty units in the Guide to Framing Commonwealth Offences, Infringement Notices and Enforcement Powers” [HR2].

2 The Human Rights Part 7 describes evidentiary ICCPR Article 14(2) Although the Human Rights section relies on court involvement to claim

discussion asserts that certificates that “allow an (presumption of innocence) and Article _ that the presumption of innocence is preserved, the combination of penalties are imposed only by courts, and that this preserves due prima facie evidence of the determination of a criminal charge); prima facie proof of the Commissioner’s case) with strict liability and high penalties in CRPD _ shifts the evidential and practical burden onto participants and

32 29 January 2026 — Completed by L. Howard-Fielding

compatible with Articles that strict and absolute Article 13 (effective providers. This is difficult to reconcile 14 and 15 ICCPR.[HR2] liability offences with access to justice).[HR7] with a robust presumption of substantial civil penalties will innocence and equality of arms under be used in Article 14 ICCPR.[HR5][HR7] enforcement.[HR5]

3 The Human Rights Elsewhere, the EM states ICCPR Article 17 (no The Human Rights narrative minimises section on privacy that the Bill will give the arbitrary or unlawful the privacy impact, describing it as non- asserts that expanded Commissioner the “requisite interference with arbitrary and proportionate. The information-gathering levers to compel information privacy); CRPD Article 22 clause-by-clause text emphasises broad and information-sharing in a timely manner” and (respect for privacy); discretion to compel and disseminate powers are “not delegate power to make CRPD Article 4(1) information, compressed compliance arbitrary”, and that any rules prescribing the persons (obligation to ensure timeframes, and penalty-backed non- interference with and bodies to whom safeguards are compliance. Taken together, these privacy is reasonable, protected NDIS Commission proportional and features look closer to open-ended necessary and information may be disclosed tailored).[HR7] surveillance and compulsion than to proportionate to enable and for what purposes, the narrowly tailored, minimum- proactive regulation by accompanied by examples of necessary interference required by the Commission.[HR2] 5-day and 7-day notices Article 17 ICCPR and Article 22 backed by strict-liability CRPD.[HR5][HR6][HR7] offences and high penalties.[HR5][HR6]

4 The Human Rights In the penalty-calibration ICCPR Articles 14 and 15; The Human Rights section treats the section relies on discussion, the EM states PJC Human Rights penalties as ordinary civil/regulatory Parliamentary Joint that penalties are designed Guidance Note 2 criteria measures. The detailed EM text Committee on Human so they “will not be viewed for when civil penalties characterises them as strongly punitive Rights Guidance Note 2 as a cost of doing business by are criminal in substance and deterrent (“not a cost of doing to characterise the the provider” and to (punitive/deterrent business”), with high quantum, strict penalties as civil and “eliminate the rhetoric that purpose and substantial liability and evidentiary shortcuts. regulatory (rather than current penalties can be pecuniary sanction); Under Guidance Note 2, this criminal) and concludes absorbed as a cost of doing CRPD Article combination is criminal in substance, that, as part of a business in the NDIS”, 4(1).[HR4][HR8] triggering stronger ICCPR protections regulatory scheme, they indicating a deliberately than the EM are appropriate, punitive and deterrent acknowledges.[HR4][HR6][HR8] proportionate and purpose coupled with high compatible with Articles monetary sanctions.[HR6] 14 and 15 ICCPR.[HR2][HR8]

                                                                                                     33

14. System Evidence Check: Complaint Volumes, Tribunal Escalation, and Model Litigant Risk

14.1 Complaint volumes (NDIA and NDIS Commission)

  • NDIA complaints from participants: 30,091 (2021–22) and 28,951 (2022–23)xix
  • NDIS Commission complaints about providers: 16,305 (2022–23) and 29,054 (2023– 24).xx
  • NDIA quarterly report data records 20,027 participant complaints in Q4 2023–24 alone (with data‑system change caveats).xxi

14.2 Escalation to external merits review (AAT/ART)

  • Applications for external merits review lodged by participants: 4,189 in 2022–23xxii
  • Applications for external merits review lodged by participants: 4,043 in 2023–24 (and 97.2% of finalised cases resolved via ADR without a substantive hearing).xxiii
  • Post‑AAT transition: media reporting indicates 7,132 NDIS appeals lodged in the ART in the most recent reported year.xxiv

14.3 Settlement dynamics and evidentiary reliability

  • The operational reality described in public reporting and audit material sits uneasily with the Bill’s premise that expanded punitive and information‑gathering powers are a proportionate, evidence‑based response to established system risks. For example, Rick Morton reports that, of the 4,500 “legacy” matters then on the books, “90 per cent have been resolved by the new dispute resolution processes.”xxv

This aligns with NDIA reporting that the overwhelming majority of matters finalised in 2023–24 was resolved through alternative dispute resolution rather than a substantive hearing.xxvi

At the same time, the ANAO found the NDIA did not have a mature, closed‑loop complaints improvement system, including gaps in analysis and baseline evidence for improvement activities.

        Where the underlying system cannot reliably categorise, triage and learn from
           complaints at scale, expanding coercive compliance settings increases the probability
            that enforcement tools (including penalties and reputational harms) will be applied in
          the wrong cases—magnified by the structural imbalance of power between the
        Commonwealth and participants/providers.

             In this context, the Commonwealth’s Model Litigant Obligation is directly relevant.
          Appendix B requires that the Commonwealth and its agencies “act honestly and fairly
             in handling claims and litigation”, including by “not taking advantage of a claimant who
             lacks the resources to litigate a legitimate claim”.xxvii

Summary of Safeguard gaps

  • No explicit participant exclusion from broad information‑gathering powers framed to apply to “providers and other persons”, leaving participants structurally within scope absent clear guardrails.xxviii
  • No defined quality-assurance / error-correction loop tied to enforcement triggers before punitive tools are escalated, notwithstanding audit-identified maturity gaps.1
  • No practical protection against collateral impacts (service disruption, plan delays, funding variation) arising from compliance activity, despite very high ADR settlement rates.5
  1. Safeguarding Framed as Participant Protection While Extending Institutional Protection

i’ve never liked Framing of the Amendments

The Bill is framed as a response to the findings of the Royal Commission into Violence, Abuse, Neglect and Exploitation of People with Disability and the 2023 Independent Review into the NDIS. These inquiries identified serious and systemic harms experienced by people with disability and called for stronger safeguards to prevent abuse, neglect, and exploitation within the Scheme.

These framing positions participant protection as the primary justification for the amendments. However, the Explanatory Memorandum makes clear that the reforms are also directed toward strengthening the regulatory authority, enforcement capability, and institutional integrity of the NDIS itself. Some of the instances where this occurs throughout this amendment include:

   15.1   Dual Purpose: Participant Safety and Protection of the Scheme
      The Explanatory Memorandum explicitly states that the amendments address priority
       measures required by the NDIA and the Commission to protect both the NDIS and NDIS
         participants from non-compliant activity. This confirms that the Bill has a dual purpose:
        safeguarding participants on the one hand and safeguarding the Scheme and  its
        administering entities on the other.

                                                                                                     35

“The Bill strengthens the compliance, investigation, and enforcement powers of the NDIS Quality and Safeguards Commission and enables the National Disability Insurance Agency to strengthen operational elements of the Scheme to increase its integrity.”

15.2 Existing Safeguards Already Embedded in the NDIS Framework The NDIS already operates within a comprehensive safeguarding framework, including provider registration and regulation, reportable incident schemes, complaints and investigation mechanisms, worker screening, compliance and enforcement powers, NDIA operational guidelines, external review rights, and the application of existing criminal and consumer protection laws. These mechanisms demonstrate that the Scheme is not under-regulated, nor lacking tools to address abuse, non-compliance, or exploitation. The issues prevailed not because of lack of a system but lack of implementing the system properly having a complete third-party quality management system across the NDIS. It cannot work if not connected to each other it cannot work without clear lines of accountability. The system has not failed; it has never actually been properly or fully implemented and in doing so I’ve been rendered ineffective.

15.3 Prevention Through System Design Rather Than Punitive Control The most effective protection against exploitation of a complex public scheme is not the continual expansion of punitive or coercive powers, but the strength and resilience of the system itself. Robust safeguarding is achieved through:

  • clear, well-designed systems and procedures that limit opportunities for misuse
  • highly competent, well-trained staff capable of exercising judgment proportionately and consistently,
  • strong, transparent relationships with providers and suppliers grounded in accountability and mutual understanding, and.
  • a deep, individualised understanding of participants, recognising that each person’s needs, circumstances, communication styles, and vulnerabilities are different.

A system that is well-designed, competently administered, and relationally grounded is inherently resistant to exploitation. Such a system reduces reliance on enforcement after harm has occurred and instead prevents misuse from arising in the first place.

15.4 Risks of a Punitive and Control-Focused Model By contrast, a regulatory approach that prioritises punishment, surveillance, and control risks producing unintended consequences. It may:

  • discourage honest engagement and early disclosure of issues,
  • entrench fear and compliance-driven behaviour rather than trust and collaboration, and
  • shift focus away from systemic improvement toward reactive enforcement.

Where safeguarding is pursued primarily through coercive mechanisms, the system itself becomes brittle — dependent on constant intervention rather than designed resilience.

15.5 Safeguarding as System Integrity, Not Continuous Punishment

The goal of safeguarding should be to create a Scheme that cannot be readily penetrated or exploited, regardless of the persistence or sophistication of those who attempt to misuse it. A truly robust system is one that remains intact even when individuals act in bad faith, because its design, controls, and relationships do not permit exploitation to take hold. Safeguarding should therefore be measured not by the severity of penalties imposed, but by the Scheme’s capacity to prevent harm, support participants safely, and operate with integrity without resorting to continuous punishment or control.

15.6 Safeguarding Must Be Measured by Impact, Not Intent

While the Bill is framed as implementing participant-focused recommendations of the Royal Commission, its emphasis on expanded enforcement powers risks prioritising institutional protection over systemic resilience. In doing so, it may overlook the foundational safeguards already in place and the importance of strengthening system design, capability, and relationships as the primary means of protecting participants. This tension between stated intent and practical effect warrants scrutiny

16. Structural Indicators of Cost Containment Within a Safeguarding Framework

Public reporting and ministerial statements have repeatedly acknowledged that the NDIS’s growth and fiscal sustainability are policy priorities for the Commonwealth, with the Minister for the NDIS defending integrity reforms as necessary to ‘save $14 billion’xxix and control cost growth, and government planning documents committing to an 8 % annual growth target xxx for long-term sustainability. Media reporting and parliamentary materials over several years have described the NDIS as financially unsustainable in its existing form xxxi and have framed integrity, compliance, and enforcement measures as necessary mechanisms to curb expenditure growthxxxii

This context is directly relevant to the Bill. The Explanatory Memorandum situates the proposed amendments within a broader narrative of “Scheme sustainability” and “integrity”, repeatedly linking strengthened enforcement powers and increased penalties to the need to prevent misuse, deter exploitation, and reduce pressure on the Scheme’s finances. While safeguarding participants and preventing fraud are legitimate objectives, the Explanatory Memorandum does not operate in a policy vacuum. The measures are introduced against a backdrop in which cost containment has been openly identified as a priority, and where integrity reforms are routinely discussed alongside fiscal restraint.xxxiii

Against that backdrop, the design features of the Bill warrant close scrutiny. Rather than investing in internal system capability, decision quality, or administrative accuracy, the amendments rely heavily on deterrence, expanded enforcement powers, and the externalisation of compliance risk. These design choices have predictable structural effects: they suppress utilisation, discourage engagement, and shift the financial and administrative burden of error away from the Scheme and

Page 38

onto participants and providers. In practical terms, responsibility is pushed down onto those least able to carry it — participants, who by the nature of the NDIS are people with disability, and the families, carers, nominees, and informal supports who assist them.

This outcome sits in tension with the Scheme’s own legislative principles and guidancexxxiv. The National Disability Insurance Scheme Act explicitly recognises that participants are people with disability who may be vulnerable, and that the Scheme exists to support their dignity, autonomy, inclusion. NDIS operational guidance, practice standards, and safeguarding frameworks similarly acknowledge the heightened risk of harm where people with disability are exposed to complex, coercive, or punitive administrative processes xxxv , and emphasise the need for proportionate, supportive, and participant-centred approaches.xxxvi

Safeguarding frameworks are ordinarily associated with increased upfront investment in training, oversight, internal controls, and decision-making quality. In summary the strength of any entity in systems to protect it should be proactive not reactive preventing the impact before it happens.

By contrast, the measures proposed in the Bill are nearly all reactive and don’t control the risk they don’t simply divert it which inevitably gives the NDIS even less control over these impacts., It also prioritise punitive tools that deter engagement and shift risk outward, while leaving underlying system weaknesses unresolved. In this context, cost containment emerges not as an incidental by- product, but as a foreseeable structural consequence of the regulatory design described in the Explanatory Memorandum.

This does not require an inference of improper motive. Regulatory systems shape behaviour. Where enforcement mechanisms are designed in ways that discourage participation, reduce flexibility, and increase the personal cost of engagement, reductions in utilisation and expenditure are an inevitable outcome.

The question for the Committee is whether those outcomes are compatible with the Scheme’s stated safeguarding purpose, or whether fiscal restraint is being substituted for genuine participant protection. The best and only way to address these issues is to address the core issues in which they are related to and although many of those are not specifically mentioned in this amendment, they have a critical impact that is not been discussed or identified where these have been identified in previous reports completed by other government departments. They have been ignored by the NDIS and have not been corrected. In a completely integrated third-party quality management system this type of failure to address corrective actions and the risk associated with it would be flagged and transparent and easily identified and could also be costed as to what this failure is adding to the operating cost of the NDIS.

Note: Detailed evidence regarding the use of external legal representation in administrative review proceedings, and the associated public expenditure and risks arising from systemic decision-making error, is set out in Annexure C.

17. Anti-promotion Orders, Section 4 of the Act, and System Integrity

This section addresses Schedule 1, Part 4 of the Bill, including the proposed anti-promotion regime and rule-making power under section 73ZOA, and its interaction with the objects and principles of the Act in section 4, as explained in Part 4 of the Explanatory Memorandum. While framed as an integrity and safeguarding measure, the proposed approach raises serious concerns about proportionality, regulatory duplication, market impact, advocacy, and the prioritisation of punitive enforcement over systemic quality and prevention.

17.1 Reliance on punitive measures rather than system capability

The reforms proposed in Part 4 continue a broader pattern within the Bill of responding to perceived risk through punitive measures, including restrictions, banning orders, and criminal consequences, rather than strengthening the underlying administrative framework of the NDIS. This approach assumes that integrity failures are best addressed after the fact, through enforcement action, rather than prevented through:

  • clear and robust rules.
  • competent and well-resourced decision-making.
  • effective pre-payment scrutiny; and consistent application of existing requirements.

Before any payment is made under the NDIS, claims already pass through multiple layers of checks and balances, including providers, support workers, plan managers or agencies administering funds, and NDIA systems. If these systems are functioning as intended, conduct that is misleading, false, or non-compliant should be identified and prevented at the point of payment, not retrospectively managed through coercive enforcement.

An enforcement-first model implicitly acknowledges weaknesses in system design, capability, or clarity, and risks shifting responsibility away from the Scheme itself and onto participants, advocates, and small entities.

17.2 Acknowledged overlap with existing consumer law protections

Part 4 of the Explanatory Memorandum expressly states that the anti-promotion power is intended to “complement, not displace” Australian Consumer Law (ACL), and that it is not intended to unduly impact or overlap with existing consumer protections. This acknowledgement is significant. It confirms that the types of conduct targeted — misleading, deceptive, or exploitative promotion — are already regulated under ACL, with established enforcement mechanisms overseen by specialist regulators.

If existing consumer law protections are adequate — as the Explanatory Memorandum asserts — this raises a legitimate question as to the necessity and proportionality of introducing an additional, sector-specific power that allows a different regulator to restrict promotional conduct based on market impact. The Explanatory Memorandum does not identify a clear regulatory gap in ACL enforcement that would justify the breadth of the proposed power.

17.3 Market competition and regulatory overlap

Part 4 of the Explanatory Memorandum explicitly acknowledges that anti-promotion rules are intended to address conduct with a “negative impact on the NDIS market”, confirming that the rule-making power is designed to influence market behaviour and conditions.

Market competition, misleading conduct, and unfair trading practices are already regulated under Commonwealth law by specialist regulators. Introducing a parallel, discretionary NDIS-specific mechanism to shape market conduct risks:

  • regulatory duplication and overlap.
  • inconsistent standards across markets.
  • selective or uneven application; and
  • distortion of competition through restrictions imposed on some entities and not others.

Preventing a business or individual from promoting services directly affects their ability to compete for clients, undermines competitive neutrality, and may reduce participant choice — outcomes that sit uneasily with the objects and principles of the Act in section 4.

17.4 Impact on advocacy and access to justice

Many participants rely on advocates — including volunteers, not-for-profit organisations, and individuals receiving modest fees — because private legal representation is unaffordable. The breadth of the anti-promotion regime, as described in the Explanatory Memorandum, creates a real risk that advocacy activity could be targeted, particularly where advocates engage in communication, guidance, or representation that could be characterised as influencing participation in the Scheme.The deterrent effect of potential enforcement, penalties, or criminal exposure is likely to:

  • discourage advocacy.
  • make volunteer and low-cost advocacy unviable; and
  • exacerbate the existing power imbalance between participants and the regulator.

This outcome is inconsistent with the principles in section 4, which emphasise participation, choice, and support for people with disability.

17.5 Use of “intent” rather than enforceable safeguards

Throughout Part 4 of the Explanatory Memorandum, assurances are framed in terms of what is “not intended” to occur — including that normal advertising will not be captured, and that consumer law will not be overlapped.

However, intent is not a legal safeguard. It does not create enforceable limits, objective criteria, or procedural protections.

Proposed subsection 73ZOA(3) requires ministerial satisfaction that conduct undermines the objects or principles of the Act before rules are made, but it does not:

  • define objective thresholds.
  • require proportionality or necessity assessments.
  • mandate consideration of competition, advocacy, or access impacts;
  • provide protections for those affected by the rules.

For a power with potentially serious consequences — including market exclusion, restriction of advocacy, and exposure to criminal penalties — reliance on statements of intent is insufficient and creates regulatory uncertainty.

17.6 Consultant example and misdirected assumptions The Explanatory Memorandum’s example relating to consultants — particularly the suggestion that providers or participants may confuse internal audits with third-party quality audits — reflects an assumption that does not justify coercive regulation.

Across regulated industries, the distinction between internal audits and third-party accredited audits is well understood. Third-party accreditation is objectively identifiable through certification, approved auditors, and recognised marks. If a consultant misrepresents their services, that conduct is already regulated under consumer law.

It is neither necessary nor proportionate to introduce a discretionary anti-promotion regime on the assumption that professionals or consumers cannot distinguish between these services. Responsibility for accurate representation lies with the consultant; responsibility for appropriate engagement lies with the purchaser. Existing frameworks already address this.

  1. Integrity Powers As Market Regulation in a System That Tolerates Over-Charging On page 2 of the Explanatory Memorandum, the Government states:xxxvii

“The amendments in this Bill consider the NDIS Review recommendation 19.3 which emphasised the importance of the NDIS Commission having the powers and approach to proactively and effectively regulate the market. The Bill will strengthen the NDIS Commission’s capacity to detect, prevent and respond to breaches of obligations under the Act. The Bill will address current concerns of safety and non-compliance within the Scheme and resolve existing structural issues that minimise the effectiveness of regulatory action to combat abuse, neglect and exploitation that continue to cause significant harm to participants in the NDIS.”

This is an explicit statement that the Integrity and Safeguarding Bill are intended to be a market- regulation instrument: it will give the NDIS Commission new powers and tools to shape the behaviour of providers and others across the NDIS “market”, in the name of safety, non-compliance and structural issues.

However, when read alongside the Auditor-General’s findings on the NDIA’s claim-compliance arrangements and the NDIA’s own integrity communications, a different picture emerges:

18.1 The Australian National Audit Office concludes that the NDIA’s management of claimant compliance is only “partly effective”; that “prior to 2024, the NDIS lacked basic prevention controls for fraud and non-compliance”; that the Scheme was “designed and implemented (up until 2024) without basic prevention controls, such as clear claim

Auditor-General Report No. 48 (2024–25)

18.2 The NDIA’s Crack Down on Fraud and Fraud Fusion Taskforce programs are still constructing the basic control environment (identity, claim validation, data analytics and case management) that should have been in place at Scheme design, with tranche two not due to be implemented until December 2025xxxviii

18.3 Manual pre-payment reviews currently cover only around 0.4 per cent of NDIS claims by dollar value, and less than 0.1 per cent by number, yet over 50 per cent of reviewed claims (by value) are cancelled as non-compliant – a pattern consistent with upstream design failure rather than isolated misconductxxxix

18.4 The NDIA and Australian Federal Police report that, since the establishment of the Fraud Fusion Taskforce in November 2022, there have been 20 successful criminal prosecutions for NDIS-related matters, despite estimates that 6–10 per cent of NDIS outlays may be affected by non-compliance, error or fraudxl

In this context, the Explanatory Memorandum’s promise that the Bill will “proactively and effectively regulate the market” raises two serious concerns.

First, the Bill uses an immature and incomplete control environment as the platform for stronger market intervention. The ANAO has already found that the NDIA has no fit-for-purpose compliance framework and that its current approach is only partly effective, with basic prevention controls still being built [Auditor-General Report No. 48 (2024–25)] Expanding the Commission’s powers to “detect, prevent and respond” to breaches in this environment risks amplifying the weaknesses of the existing system: decisions will be taken on the basis of incomplete data, immature analytics, and frameworks that the Auditor-General has already assessed as structurally deficient.

Second, the Bill frames “market regulation” around integrity and safety, while leaving price-setting and over-charging largely untouched. Participants and their families experience “the market” most acutely through the prices they are quoted for everyday supports. In practice, many NDIS-funded goods and services are routinely priced well above ordinary retail or non-NDIS rates – sometimes several multiples higher – for identical items or near-identical services. This includes basic supports such as lawnmowing and garden maintenance, domestic assistance, low-cost assistive technology, continence supplies, and common mobility equipment.

Under current arrangements: - Self-managed and plan-managed participants are permitted (and often required) to pay above NDIA price limits but are not given transparent tools or bargaining power to resist excessive pricing. - The NDIA’s own pricing structures and catalogue design can entrench high prices, with little real-time feedback on whether participants are being charged systematically more than non-NDIS customers for the same goods and services.

  • Over-charging and opaque pricing are rarely treated as integrity breaches in their own right; instead, the focus of enforcement activity is on documentation, coding, and technical rule compliance by participants and providers who are operating inside a distorted market.

    Yet the Bill does not introduce clear, enforceable obligations on providers to avoid excessive or discriminatory pricing, nor does it establish a transparent, participant-centred test for when price conduct will be treated as “non-compliance” subject to regulatory action. Instead, it strengthens information-gathering and penalty powers that can be applied to participants, nominees, plan managers and providers alike, in an environment where the structural drivers of over-charging are created and maintained by government system design.

    In effect, the Government is asking Parliament to sign off on broad market-regulation powers that will operate through an integrity system the Auditor-General describes as incomplete and only partly effective, while participants continue to pay a de facto “NDIS premium” on the supports they need to live an ordinary life. A genuine market-regulation response would:

  • prioritise the elimination of the NDIS price premium through transparent benchmarking and enforcement against unjustified differentials.

  • embed ISO-aligned prevention, validation and feedback controls before expanding coercive sanctions; and

  • clearly allocate responsibility for structural pricing failures to the agencies that design and regulate the Scheme, rather than to individual participants and small providers.

    Until those pre-conditions are met, empowering the Commission to “proactively and effectively regulate the market” risks translating, in practice, into cost-containment and compliance pressure on participants and frontline providers, rather than meaningful protection from abuse, neglect, exploitation and systematic over-charging.

19 Explanatory Memorandum vs ISO‑Aligned Quality Management Systems and Proposed Powers This table compares what the Explanatory Memorandum to the National Disability Insurance Scheme Amendment (Integrity and Safeguarding) Bill 2025 says the Bill is intended to achieve, with the changes the Bill actually makes to civil and criminal powers, and with the way those same issues would ordinarily be addressed under established ISO‑aligned quality, risk, complaints and records-management systems.

On page 2 of the Explanatory Memorandum, the Government states: “The amendments in this Bill consider the NDIS Review recommendation 19.3 which emphasised the importance of the NDIS Commission having the powers and approach to proactively and effectively regulate the market. The Bill will strengthen the NDIS Commission’s capacity to detect, prevent and respond to breaches of obligations under the Act. The Bill will address current concerns of safety and non-compliance within the Scheme and resolve existing structural issues that minimise the effectiveness of regulatory action to combat abuse, neglect and exploitation that continue to cause significant harm to participants in the NDIS.”

EM / Bill theme

What the EM / Bill Proposed fix in the Bill ISO standard(s) How an [SO-aligned system (plain language) says this is for (extra civil/criminal most relevant would address this powers)

‘Proactively and Give the NDIS Broad uplift in AS/NZS ISO ISO says: start with context, clear effectively regulate Quality and Commission enforcement 9001:2016; AS ISO objectives, risk criteria and the market“ (p.2) Safeguards toolkit — strengthened 31000:2018 defined processes before Commission powers banning orders, new enforcement. You would build a and approach to anti-promotion orders, documented regulatory regulate the NDIS __ higher civil penalties, framework and market. expanded continuous-improvement cycle information-gathering and first, then add coercive tools as evidentiary powers. the end of the chain, not the start. ya “Strengthen Enhance detection, More notices, broader AS/NZS ISO In ISO logic, “detect, prevent, capacity to detect, prevention and power to compel 9001:2016; AS ISO respond” is a full PDCA cycle. The prevent and response to information from any 31000:2018; AS ___ Bill skews heavily to “respond” response“ (p.2) person, evidentiary ISO 15489.1:2017 (sanctions) while prevention and detection systems (rules, data

This is an explicit statement that the Bill is a market-regulation and integrity instrument, premised on the idea that stronger powers will improve safety, regulatory effectiveness and respect for the integrity of the NDIS.

By contrast, the Auditor-General concludes in Auditor-General Report No. 48 (2024-25), National Disability Insurance Agency’s Management of Claimant Compliance with NDIS Claim Requirements, that: Auditor-General Report No. 48 (2024—25)]

“Prior to 2024, the NDIS lacked basic prevention controls for fraud and non-compliance.”

The same report records that the NDIA’s management of claimant compliance is only “partly effective”, and that work to build a fit-for-purpose control environment is still underway. In other words, the primary driver of current integrity and safeguarding problems is not a lack of powers, but the absence of a mature, ISO-aligned quality and risk-management system.

The table below sets out, for 30 separate themes or measures in the Explanatory Memorandum and Bill: = ‘What” the Explanatory Memorandum says the change is for. = what the proposed legislative “fix“ does in terms of additional civil or criminal powers. = what the impact of the proposed fix would be and; = how an [SO-aligned quality, risk, complaints and records-management system would usually address the same issue. This comparison demonstrates that many of the problems identified in the Explanatory Memorandum are, in substance, system-design and quality-management problems, yet the Bill’s principal response is to expand coercive powers operating within that incomplete system, with the burden of these proposed fixes push down onto the shoulders of those who can least afford to carry them being the participants, and incorrectly push the burden onto those who provide services for the NDIS, in a way that would not be financially beneficial, but in fact compound the current inefficiencies by adding to them the cost of the penalties which would naturally be passed on to the NDIS (regardless of how many times it is noted in the EM they wont be, they will be)

Breaches of obligations

breaches of penalties and new quality, validation) are _ still obligations. offences to support incomplete. investigations and enforcement outcomes. ean ‘Address safety Use regulatory Stronger civil penalty AS ISO ISO would require a structured land powers to address regime, higher maximum 45001:2018; AS hazard and risk register, control non-compliance” safety issues and penalties, more ISO 31000:2018; hierarchy, and corrective-action (p.2) non-compliance. circumstances where AS/NZS ISO system. Safety and providers and individuals 9001:2016 non-compliance would be can be banned or managed through formal restricted. non-conformance handling, not primarily by dialling up penalties.

“Resolve structural Fix structural issues Legal restructuring of AS/NZS ISO Structural issues are system that undermine offence and penalty 9001:2016; AS ISO design failures. ISO says: fix regulatory framework, new powers 31000:2018 governance, processes, data and effectiveness of = effectiveness. (such as anti-promotion feedback loops. Here, the “fix” is regulatory action” orders and broader mostly stronger levers applied (p.2) banning orders) to through the same incomplete unblock regulatory action. structures.

Implement NDIS = Align with the NDIS_ Implementation largely AS/NZS ISO ISO. would implement the Review’s call for through new and 9001:2016; recommendation by building an recommendation stronger expanded civil penalties, AS/NZS integrated quality, complaints 19.3 (powers and Commission powers banning powers, 10002:2014 and risk system. The Bill instead lapproach) and proactive information-gathering and emphasises punitive capability, regulation. court tools, rather than leaving the “approach“ through mandated quality (methods) largely undefined in or complaints quality terms. terminology. frameworks.

Stronger civil Increase penalties New aggravated civil AS/NZS ISO ISO requires you to define penalties for where there is major penalty tiers tied to 9001:2016; AS ISO “significant failure” and “significant failure” or repeated provider significant or systemic 31000:2018 “systemic pattern” via metrics lor “systemic failure. breaches of conditions or and trend analysis. Without that, pattern of Code obligations. higher penalties can be applied conduct” inconsistently, based on subjective judgment rather than a documented quality threshold.

New civil penalties Deter false Creation of specific civil ASISO An 1|SO-aligned system treats or false or documentation and _ penalty provisions for 15489.1:2017; record integrity as a core misleading misreporting. giving false or misleading AS/NZS ISO control. If | documentation information or information or documents 9001:2016 processes are poor or confusing, idocuments to the NDIA or you risk penalising people for Commission. system-induced errors rather than deliberate deceit.

Civil penalties for Enforce compliance New or heightened civil AS ISO ISO requires clear information ailing to provide with penalty provisions for 15489.1:2017; requirements, realistic information-gatheri non-compliance with AS/NZS ISO timeframes and support. gng notices. information requests, plus 9001:2016 Without that, penalties land on dexpanded scope of who participants and small providers can be required to provide for not coping with complex, information. under-supported requests. Protect sensitive New civil penalty regime ASISO ISO. —~would first’ ~=ensure Commission for unauthorised use or 15489.1:2017; AS classification, access control, information. disclosure of protected ISO 31000:2018 training and audit logs are in Commission information. place. Penalties then target intentional misuse, not confusion created by poor

Higher Penalties or Aggravated Breaches

Higher Penalties or Aggravated

breaches of the INDIS Code of Conduct

Higher Penalties or Causing or

Higher Penalties or Contravening a compliance notice

0 comply with banning orders
supports requiring

Offence: failing to

Higher Penalties Or Offences For Failing To

Offence: Providing

Deter serious non-compliance by registered providers. Deter serious conduct breaches. Protect whistleblowers and complainants from retaliation. Ensure providers comply with Commission directions. Enforce exclusion of high-risk actors. Stop unregistered providers delivering regulated supports. Create a criminal back-stop for banned providers. Increased maximum civil penalties and possibly criminal exposure for aggravated non-compliance with conditions of registration. Increased penalty units and broader circumstances where AS/NZS ISO 9001:2016; AS ISO 31000:2018 AS ISO 45001:2018; AS/NZS ISO 9001:2016; AS/NZS 10002:2014 Uplifted civil penalties for victimisation and broader coverage of who is protected. Increased maximum penalties for ignoring or breaching compliance notices. ISO 45001:2018 AS/NZS ISO 9001:2016; AS ISO 31000:2018 RISK, QMS Code breaches can attract civil penalties and banning action.

Higher Penalties Or Aggravated Non-Compliance With Conditions Of Registration:

Increased Maximum Civil Penalty Units And Possibly Criminal Exposure For Aggravated Non-Compliance With Conditions Of Registration.

Increased Penalty Units And Broader Circumstances Where As/ Nz S Iso 9001 : 2016 ; As Iso 31000 : 2018

As / Nzs Iso 45001 : 2018 ; As / Nzs Iso 9001 : 2016 ; As / Nzs 10002 : 2014

Uplifted civil penalties for victimization and broader coverage of who is protected.

increased maximum penalties for ignoring or breaching compliance notices.

iso 45001 : 2018

as/nz s iso 9001 : 2016; as iso 31000:2018

RISK, QMS

Code breaches can attract civil penalties and banning action.

AS/NZS ISO 9001:2016; AS ISO 31000:2018 RISK, RECORDS information-governance systems. In ISO, registration conditions would be backed by documented controls and internal audits. Penalties should attach to clear, well-communicated, auditable failures, not to _ providers operating under ambiguous or shifting requirements. ISO culture is built via training, procedures, supervision and open reporting. Heavy penalties belong at the end of that chain, not as the primary mechanism to make the code real. Complaint standards would build anti-reprisal protections into policy, process and monitoring. Penalties then backstop a robust, well-communicated system rather than substituting for one. In ISO terms, a compliance notice is a formal non-conformance. A structured corrective and preventive action process should be the main tool; penalties reinforce but do not replace that quality loop. Banning decisions must rest on robust, documented risk assessment and transparent criteria. ISO would insist on due process and review otherwise severe penalties risk being built on opaque judgments. An iso system would ensure role definitions and registration triggers are crystal clear and accessible with proactive communication. The danger now is criminalising behaviour in a setting where the rules and categories are complex and shifting. Records standards would require that banning orders reasons scope and notifications are well recorded and communicated so that any criminal liability is based on clear provable knowledge of the order.

‘¥AAnti-promotion misleading

‘E:]Banning orders

sk }Stronger

Commission

demanded.

civil action.

providers error.

yvaViandated claim

yZ§Plan variations can Enable NDIA flexibility in total budget amounts.

Stop harmful or

marketing to participants.

information-gather compelled to ing powers for the provide information and third parties), lower and what can be

yiiUse of evidentiary Streamline proof in certificates in court prosecutions and

yauEntirely electronic Modernise and claiming system for secure claims, reduce fraud and

Improve traceability

data (ABN, and reduce

description, high-risk,

levidence over undocumented hreshold) claims.

Additional Ensure participants

safeguards and understand communication consequences of options for withdrawal. participants

ithdrawing

New power for the Commission to issue orders restricting or prohibiting certain marketing and promotional activities.

Capture third parties Amendments enabling who facilitate non-compliance.

banning orders to be made against auditors, advisors and consultants, not just providers.

(to participants, families

thresholds, and wider use of compelled information across regulatory functions.

New evidentiary certificate provisions allowing Commission officers to certify certain facts for court, shifting evidentiary burdens.

Moves towards mandatory electronic claiming and structured claim data for providers.

Hard statutory requirements for specific data elements and evidence above set dollar thresholds, with non-compliance enforceable via penalties.

New notice and communication requirements and procedural steps when a participant leaves the Scheme.

Clarifies that plan variations can both increase and decrease total supports and

QMS,

A quality system would first

COMPLAINTS, RISK define acceptable marketing

AS/NZS ISO

9001:2016; AS ISO

31000:2018

Broaden who can be Expanded scope of notices RECORDS, QMS,

COMPLAINTS

AS ISO

15489.1:2017;

AS/NZS ISO

9001:2016

AS/NZS ISO

9001:2016; AS ISO

31000:2018; AS

ISO 15489.1:2017

QMS, RECORDS

AS/NZS

10002:2014;

AS/NZS ISO

9001:2016; AS ISO

45001:2018

RISK, QMS

standards and embed participant feedback. The risk here is that anti-promotion powers are used bluntly, without a transparent, ISO-style standard for what counts as exploitative.

ISO requires clear control over

external providers with documented expectations and monitoring. Without that,

consultants can be banned for operating in a grey zone the system itself created.

1SO-aligned complaints and investigation processes would ensure’ proportionality and support. Heavy _ information powers in an immature system risk over-burdening participants and smaller providers.

Evidentiary shortcuts assume robust underlying records and systems. In a system assessed as only partly effective, this risks

hard-coding inaccuracies and making them difficult to challenge.

An 1SO-aligned design would start with process mapping and risk controls before mandating

technology. If done badly, electronic claims can entrench design flaws and shift administrative risk onto

participants and small providers.

This is essentially a quality control, but ISO would emphasise usability, training and error-handling. The Bill’s lever is punishment for non-compliance

rather —_ than building a supportive, error-tolerant process.

ISO would treat withdrawal as a high-risk change requiring risk assessment and safety planning. The Bill’s focus is primarily procedural, not on embedding a structured risk review and

follow-up. ISO. change-control would require documented impact assessment, consultation and sign-off for any _ significant reduction. The Bill enables downward variation power 47

29 January 2026 —- Completed by L. Howard-Fielding

funding, with less need for full plan reassessments.

y4-4“Addresscurrent Target existing Uses the upgraded AS ISO

concerns of safety safety and penalty and banning 45001:2018; AS land compliance toolkit as the primary ISO 31000:2018; non-compliance” concerns via new vehicle to “address” AS/NZS

(p.2) powers. concerns, rather than 10002:2014 specifying system-level

corrective actions.

“Combat abuse, _—‘ Target serious Relies heavily on OHS,

exploitation” failures. banning powers,

causing significant anti-promotion orders and harm (p.2) information-gathering to identify and punish abusive actors.

yy A Alignment with Respond to systemic Positions the new penalty QMS, OHS, Disability Royal safeguarding gaps and banning framework COMPLAINTS

Commission identified by the and information powers safeguarding Royal Commission. as key Royal Commission ndings responses. y2:3 Alignment with Implement Review Uses expanded AS/NZS ISO INDIS Review proposals for better market-regulation powers 9001:2016; AS ISO recommendations market oversight. (suchas anti-promotion, 31000:2018 or market broader banning and data stewardship use) as primary tools of

stewardship.

yz:}Stronger penalty Use higher penalties Uplift in penalty units, AS/NZS ISO ‘amework to and offences to new offences and civil 9001:2016; AS ISO “change drive cultural penalty categories across 31000:2018; behaviour” across change. multiple sections to “send AS/NZS

he market a message”. 10002:2014

ElOverall framing: Deliver integrity and Uses expanded integrity AS/NZS ISO integrity, safeguarding while and safeguarding powers 9001:2016; AS ISO safeguarding and moderating cost as a key lever to moderate 31000:2018; AS cost control growth and meeting cost growth, without ISO 15489.1:2017 the 8 per cent explicit system-level

target. quality obligations.

without embedding that quality discipline.

ISO would expect evidence that root-cause analysis has been done and_ system changes implemented first. Here, “addressing concerns” is largely equated with tougher sanctions, not system redesign.

Safety and complaint standards

neglect and safeguarding increased penalties, COMPLAINTS, RISK would _ prioritise preventive

controls (screening, training, culture, escalation pathways) and strong incident learning. Enforcement is a back-stop, not the core safeguarding mechanism.

A quality system response to a Royal Commission would be to redesign processes, embed new

controls, then verify effectiveness. The Bill focuses on law-enforcement style

responses more than’ on transparent system redesign.

Stewardship in ISO terms is about systems and indicators, not just enforcement. The risk is a narrow interpretation where stewardship means more powers, not better system architecture and data transparency.

ISO culture change relies on leadership, engagement, clarity and feedback. Over-reliance on punishment, especially in a flawed system, tends to create fear and defensive compliance, not genuine improvement.

ISO insists that trade-offs between safety, quality and cost are explicit and managed. Here, cost control is embedded inside “integrity” without transparent risk analysis, increasing the chance that participants bear the brunt of enforcement-driven savings.

29 January 2026 —- Completed by L. Howard-Fielding

20 Auditor-General Findings on System Readiness and Enforcement Architecture

20.1 NDIA claimant-compliance system (ANAO Report No. 48, 2024–25)

The Auditor-General found that the NDIA’s core compliance system is not yet fit to carry the weight of strong enforcement powers. Key findings include:

  • 20.1.1 The NDIA’s current arrangements are only partly effective: “The NDIA’s management of claimant compliance with NDIS claim requirements is partly effective.”[AG1]

  • 20.1.2 The Scheme operated for a decade without basic prevention controls: “Prior to 2024, the NDIS lacked basic prevention controls for fraud and non- compliance.”[AG1]

  • 20.1.3 The NDIA itself recognised “catastrophically weak” prevention controls but still has not put effective preventive processes in place: “After identifying in 2023 that the NDIA was implemented with ‘catastrophically weak’ prevention controls, the NDIA has not yet established effective processes for preventing non-compliant claims.”[AG1]

  • 20.1.4 The Auditor-General emphasises that a proper framework is itself a countermeasure against fraud and corruption: “Having a fit-for-purpose framework to ensure claimants comply with legislative and policy requirements is a countermeasure to help prevent fraud and corruption.”[AG1]

  • 20.1.5 Despite this, the NDIA’s own Compliance and Enforcement Framework already points to a full suite of coercive tools: “…enforcement strategies — criminal sanctions, civil penalties, and administrative actions, including debt recovery and referral to the NDIS Quality and Safeguards Commission…”[AG1]

Taken together, these findings show that criminal sanctions and civil penalties are already being used within a compliance environment that the Auditor-General explicitly describes as lacking basic prevention controls and not yet supported by a fit-for-purpose framework.

20.2 NDIS Quality and Safeguards Commission regulatory system (ANAO audit of the

Commission) The body that the Bill would give even stronger market-regulation and safeguarding powers is itself assessed as only partly effective, with key elements of a modern regulatory system missing. The Auditor-General has reported that

  • 20.2.1 Overall regulatory performance is again only partly effective: “The NDIS Commission is partly effective in exercising its regulatory functions.”[AG2]

20.2 Regulatory Risk Framework

20.2.2 The Commission lacks a basic regulatory risk framework to guide enforcement decisions:

“The NDIS Commission has not established a regulatory risk framework to guide decision-making.”[AG2]

20.2.3 Monitoring, compliance and enforcement are not yet risk-responsive and proportionate:

…does not have risk responsive and proportionate monitoring, complianceand enforcement activities…”[AG2]

These findings indicate that the Commission’s use of its existing powers is not yet anchored in astructured, risk-based framework of the kind reflected in contemporary standards for quality andrisk management.

21 Cost Implications of the Proposed Amendments

21.1 “Cost of Doing Business”

The Explanatory Memorandum repeatedly states that civil penalties under the NationalDisability Insurance Scheme Amendment (Integrity and Safeguarding) Bill 2025 areintended to be significant enough that they cannot be treated as an acceptable “cost ofdoing business” with the NDIS. The key passages are set out below for ease of reference.

21.1.1 Page 14 – general discussion of penalty levels and court discretion:

“…not be viewed as a cost of doing business by the provider. The penalty to beimposed in any given matter is determined solely by the Courts …” [EM14]

21.1.2 Page 16 – penalties for contraventions of subsections 73B(2) and (3):

“…is intentionally significant to ensure a penalty cannot be considered anacceptable cost of doing business.”[EM16]

21.1.3 Page 19 – penalties for serious contraventions of subsections 73ZC(1) andAuditor-General Report No. 48 (2024–25)]

“…section 73V is intentionally significant to ensure a penalty cannot beconsidered an acceptable cost of doing business.”[EM19a]

“C(1) and (2) is intentionally significant to ensure a penalty cannot beconsidered an acceptable cost of doing business.”[EM19b]

21.1.4 Page 21 – penalties for breaching banning orders (section 73ZNA):“

“…contravention is intentionally significant to ensure a penalty cannot beconsidered an acceptable cost of doing business.”[EM21]

21.1.5 Page 51 – human rights discussion of the penalty framework:

Page 51

“…it will eliminate the rhetoric that current penalties can be absorbed as a cost of doing business in the NDIS.”[EM51]

In practice, that assumption that penalties will not be passed on to the NDIS as a “cost of doing business” is not credible in a large, mixed market where providers are expected to operate as commercial entities and manage regulatory risk in the same way they manage other business risks. From a risk-management perspective:

  • Rational providers will treat the possibility of civil penalties, investigations and enforcement action as part of their overall risk profile and will price that risk into their services in the same way they price insurance, compliance and overheads.
  • The more complex, opaque and punitive the penalty environment becomes, the higher that perceived risk premium will be, especially for smaller providers who are less able to absorb shocks or fund legal defences.
  • That risk premium is then spread across all customers – in this case, across all NDIS participants and plans – not only those directly subject to penalties.

The proposed amendments therefore create a perverse financial dynamic:

a) Penalties are largely reactive and applied after the loss has already occurred. Under the current integrity design, penalties operate as an end-of-pipe deterrent. They are applied after an alleged non-compliant payment has been made, after funds have left the Scheme, and often after harm has already been experienced by participants. The penalty does not prevent the underlying loss; it simply attempts to claw back money or punish conduct after the fact; within a system the Auditor-General describes as lacking basic prevention controls. b) The cost of those penalties is then priced in up-front as a risk of doing business. Even though the Explanatory Memorandum insists that penalties are not to be treated as a “cost of doing business”, basic commercial logic means that prudent providers will do exactly that. They will factor the risk and potential cost of penalties, investigations, legal advice and reputational damage into their pricing models. That additional “regulatory risk margin” is not confined to entities that ultimately breach the rules; it will be built into prices for all NDIS work, including for providers who never incur a penalty but must still carry and insure against the risk. c) The result is an additional, system-wide cost loading on NDIS supports. Instead of penalties operating as a narrowly targeted consequence for specific misconduct, the risk and cost of penalties become another component of the NDIS price premium for supports and services. Participants and taxpayers effectively pay twice:

  • once in the initial loss caused by non-compliant or poor-quality claims that slip through an immature control system; and
  • again, in the higher baseline prices that reflect providers’ need to cover the risk of penalties, even where they are acting in good faith.

d) In short, a penalty-centric integrity model in an incomplete quality system does

not simply “strengthen Scheme integrity at no financial cost”. It compounds system losses by:

  • responding to failures after the money has already left the Scheme; and
  • encouraging providers to treat penalties and regulatory risk as part of their cost structure, which is then passed on across the market.

A prevention-first, ISO-aligned quality and risk-management framework would reverse this logic: it would minimise non-compliant payments before they occur and reduce the need for penalties, thereby reducing both direct losses and the hidden inflationary effect of regulatory risk on NDIS pricing.

21.2 Cost of Litigation

The Explanatory Memorandum asserts that “the changes in this Bill will not introduce any financial impacts” and that the Bill will simply “contribute to the annual growth target by strengthening Scheme integrity”.[F1] In reality, the existing enforcement model already generates substantial costs, and the proposed expansion of civil and criminal powers is likely to increase those costs for both government and the market.

21.2.1 Current cost of pursuing participants

Over recent years, the NDIA and the Commonwealth have spent tens of millions of dollars per year on legal representation to defend NDIS decisions in external review:

  • Senate Estimates evidence in May 2023 recorded that total legal costs for AAT cases in that financial year were $55,210,569 to the end of March, i.e. nine months of the year. On a straight-line basis, this implies full-year legal spending in the order of $70 million on AAT matters alone.[F2]
  • Earlier analysis of NDIA data showed that in one year the Agency spent $34.8 million pursuing AAT matters, including $17.3 million on external law firms, with legal spending rising sharply as appeals spiked.[F3]
  • More recently, media and advocacy reports indicate that in 2024–25 the federal government paid more than $60 million to private law firms to contest NDIS participants’ appeals in the new Administrative Review Tribunal, while allocating only $7.3 million in additional funding to help participants obtain legal support.[F4]

At the same time, most of these matters never reach a full hearing, and many are resolved only when the NDIA eventually changes its own decision:

  • The NDIA has publicly stated that “almost 90 per cent of all AAT matters are resolved without going to hearing”.[F5]
  • Advocacy and policy analysis suggest that in one recent period around 70 per cent of decisions were changed as a result of ART involvement, despite the high legal costs incurred to defend them.[F6]

In other words, large sums are already being spent to pursue participants

through adversarial processes, only for the Agency to concede or vary its original decision in most cases, often based on evidence that was available at the outset. Those costs are not acknowledged in the Explanatory Memorandum’s claim of “no financial impacts”.

21.2.2 Extending this model to providers under a penalty-heavy regime The Bill’s expanded penalty and banning framework, coupled with stronger investigative and information-gathering powers, will not only maintain this adversarial spending pattern against participants; it will extend and intensify it in relation to providers and other third parties.

On the government side, additional enforcement powers against providers inevitably drive:

  • more investigations, compulsory information-gathering exercises and audits.
  • more civil penalty proceedings and banning-order applications in courts and tribunals; and
  • higher internal and external legal, expert and administrative costs associated with building and running those cases.

Recent examples demonstrate that the Commission is already pursuing seven-figure penalties against providers for serious contraventions (for example, a $1.1 million penalty imposed on a Tasmanian provider for safety and reporting failures), which necessarily involve substantial investigation and litigation effort.[F7] The Bill makes such large-scale enforcement activity easier and more attractive by increasing maximum penalties, broadening who can be pursued (including auditors and consultants) and introducing evidentiary shortcuts.

On the provider side, a more punitive regime creates a new category of costs that will be priced into NDIS services:

  • Regulatory-risk costs – providers will factor the probability and potential size of civil penalties, banning orders and legal disputes into their overall risk profile, in the same way they cost insurance and compliance overheads.
  • Defensive-compliance and legal costs – more complex and high-stakes enforcement powers encourage providers (especially larger organisations) to invest in legal advice, internal investigations, and compliance systems designed primarily to manage enforcement risk, not participant outcomes.
  • Insurance and financing costs – as the enforcement environment becomes more severe, insurers and lenders treat NDIS work as higher risk, increasing premiums and capital costs. Unlike most participants, NDIS providers – particularly medium and large organisations – typically have the financial capacity to obtain professional legal advice and representation to contest investigations, civil penalties and banning actions. This

Reactive Penalties and Lowered Evidentiary Safeguards Instead Of Fixing The System

Multiple inquiries – including the recent Auditor-General performance audit of NDIA claimant compliance – have recommended that the Commonwealth’s priority should be to build robust, predictive fraud and quality-management controls into the design of the NDIS, not to escalate penalties after the fact. The Auditor-General found that the scheme was implemented without

basic prevention controls for fraud and non-compliance

that pre-payment checking still occurs on only around 0.4 per cent of claims by value, that targeted reviews identify non-compliance in more than half of those claims, and that the NDIA’s current compliance approach is only “partly effective”. [R1] Despite this, the Government’s primary response has been to expand civil penalties, criminal offences and evidentiary shortcuts, rather than to complete the quality-management system that should have been in place from the start.

22.1 Evidence that the current “fraud crackdown” model is not delivering:

Taken together, publicly reported data show that the investigative and enforcement model being used for the NDIS is high-volume and high-cost, but produces very few proven fraud outcomes:

  • 22.1.1 Very low criminal conviction numbers NDIA media releases indicate that, since the Fraud Fusion Taskforce commenced in late 2022, around 20 successful criminal prosecutions for NDIS fraud have been achieved nationally, despite tens of thousands of tip-offs and hundreds of investigations.[R2]

  • 22.1.2 Enormous investigative volume versus tiny court follow-through fraud taskforce and agency updates routinely highlight tens of thousands of fraud tip-offs (for example, more than 26,000 in one recent reporting period) and thousands of participants “under investigation”, but only dozens of matters actually reaching a criminal court.[R3] Independent commentary on Senate evidence has estimated that up to 99 per cent of NDIS fraud allegations do not result in a court conviction, because many matters are intelligence-based, not evidence-ready.[R4]

  • 22.1.3 Heavy investment in civil litigation, little to show for it public reporting and FOI material show that NDIA spends tens of millions of dollars each year on external legal services to contest participant decisions in tribunals, with one period alone recording over $34.8 million in AAT-related costs and more recent figures exceeding $40–60 million. [R5] At the same time, NDIA’s own statistics indicate that 80–90 per cent (and in some years over 95 per cent) of NDIS matters in the AAT or ART are resolved or withdrawn before a hearing or published decision. [R6]

  • 22.1.4 Commonwealth-wide fraud data show limited criminal outcomes across the entire Australian Government, the Australian Institute of Criminology reports that in 2023–24 external fraud losses totalled approximately $104.5 million, with a median external fraud loss per entity of around $10,859, and that only about one per cent of substantiated external fraud matters were referred to police or another agency. [R7] That is, even when fraud is substantiated against Commonwealth programs more broadly, the overwhelming majority of cases are dealt with administratively (recovery,warnings, infringement notices), not by criminal prosecution.

System design, not mass criminality, is the main issue

The Auditor-General’s audit of NDIA claimant compliance concludes that the NDIA has not yet established effective processes for preventing non-compliant claims, that risk assessments and governance are incomplete, and that the scheme’s control environment was structurally weak at rollout. [R1] Former ATO and NDIA integrity leads have told Senate committees that prosecution is not the answer and that the real solution must be prevention and better system controls, not ever more punitive enforcement activity. [R8]

These points support the conclusion that the current “fraud crackdown” is primarily generating intelligence, media statements and administrative disruption, not a proportionate number of proven criminal or even civil penalty outcomes. For participants and providers, the lived impact is investigations, audits and legal disputes that often resolve without any finding of fault, but at significant personal, financial and psychological cost.

Lowering evidentiary safeguards instead of improving proof

Rather than addressing the acknowledged weaknesses in its data, systems and risk controls, the Bill attempts to make it easier for the NDIA and NDIS Commission to obtain civil penalties and criminal convictions by lowering the practical evidentiary barriers in court.

Evidentiary certificates as prima facie proof

Part 7 of the NDIS Amendment (Integrity and Safeguarding) Bill introduces new evidentiary certificate provisions. Under these provisions, a certificate signed by the NDIS Commissioner can be tendered in court as prima facie evidence that specified facts (for example, that a person was a registered provider, that certain claims were made, or that particular obligations applied) are correct, and those facts are taken to be correct unless the defendant proves otherwise. [R9]

Practical shift in the burden of proof

On paper, the criminal standard of proof (beyond reasonable doubt) and the civil standard (balance of probabilities) remain unchanged. In practice, however, allowing the regulator’s own certificate to stand as proof of key elements unless and until a participant or provider can disprove it shifts the evidential burden away from the state and onto the regulated person. This is particularly concerning in a context where the Auditor-General says the NDIA’s data quality, risk assessments and control environment are incomplete and only partly effective; participants and many small providers lack the resources to obtain expert evidence to rebut an NDIA certificate; and the same agency that designed the flawed systems is issuing the certificate used to prove that those systems have been correctly applied. [R1]

22.2.3 Tension with Commonwealth guidance on civil penalties and enforcement powers

the Commonwealth Guide to Framing Offences, Infringement Notices and Enforcement Powers emphasises that civil penalty provisions should not be used as a substitute for criminal offences where genuinely criminal conduct is involved; that any reversal of the legal or evidential burden of proof must be strictly justified and kept to what is necessary and proportionate; and that where penalties are large and primarily punitive or deterrent, strong arguments exist that the protections associated with criminal process – including the presumption of innocence and the prosecution bearing the onus of proof – should effectively apply.[R10]

By combining high, punitive penalties with evidentiary certificates that treat the regulator’s assertions as fact unless disproved, the Bill moves the NDIS enforcement regime closer to a quasi-criminal model without providing the procedural safeguards that the Commonwealth’s own guidance says should accompany such powers.

Instead of implementing the basic prevention and quality-management controls repeatedly recommended by the Auditor-General, the Royal Commission and other oversight bodies, the Government has chosen a reactive model that expands penalties and relies on evidentiary certificates to ease the path to enforcement. This reverses the logic of modern fraud control – which places prevention and system design at the top of the control hierarchy – and sits uneasily with the Commonwealth’s own Guide to Framing Offences and Civil Penalties, which cautions against punitive civil regimes that erode the presumption of innocence. In a scheme that still lacks reliable data, validated systems and effective risk assessments, lowering practical evidentiary safeguards to “get runs on the board” in enforcement materially increases the risk of unjust outcomes for both participants and providers.

Summary – Key Findings

This summary consolidates the key findings arising from analysis of the National Disability Insurance Scheme Amendment (Integrity and Safeguarding) Bill 2025, the accompanying Explanatory Memorandum, oversight reports, Tribunal outcomes, and lived experience. Each finding is stated plainly and briefly elaborated. Together, these findings explain why the proposed amendments present material risk in their current form.

  1. No evidence of widespread fraud There is no evidence of fraud occurring at the scale asserted. Public reporting indicates approximately 20 fraud convictions since dedicated fraud functions were established, which does not support claims of systemic or pervasive fraud warranting expanded powers.

  2. Penalty-based reform will likely increase costs Civil penalties and litigation occur after loss has already occurred. In practice, penalties, legal costs, and compliance risk will be absorbed into pricing and margins, increasing overall Scheme cost rather than reducing it.

  3. Penalties will not deter deliberate fraud Those willing to commit fraud already tolerate high legal and financial risk and are unlikely to be deterred by higher penalties. Instead, risk-averse participants, advocates, and compliant providers are more likely to be deterred.

  4. NDIA data relied upon cannot be independently verified The NDIA relies on internally generated data without an independent, third-party quality management system. Without benchmarks or assurance, the Scheme cannot reliably review itself or substantiate the projections relied upon.

  5. Conflicts with Model Litigant and Harman obligations The interaction of civil penalties, criminal offences, and compelled information creates real risk of breaching Model Litigant obligations, Harman’s obligation, and the privilege against self- icrimination.

  6. Litigation practices function as cost containment Approximately 90% of ART matters resolve before hearing, indicating supports were justifiable long before litigation. Prolonged legal action appears to function defensively to delay or suppress expenditure, at significant human and public cost.

  7. Delegated authority lacks effective control Although powers are attributed to the Commissioner, authority is exercised by delegated officers, including instructing lawyers to take action that may suspend or withdraw essential supports, without transparent safeguards.

Page 59

  1. Participants are left unprotected once proceedings commence When matters enter legal processes, participants are silenced by without-prejudice constraints and no institution intervenes to protect them from harm during proceedings, creating a safeguard vacuum.

  2. Structural parallels with Robodebt Reliance on internal data, intent-based assurances, coercive information gathering, and reversed evidentiary burdens mirrors design failures identified in the Robodebt Royal Commission.

  3. Intent is not a safeguard Repeated statements that powers are ‘not intended’ to impact participants do not operate as enforceable controls and cannot prevent foreseeable misuse in practice.

  4. EM examples reveal flawed system understanding The examples used to justify expanded powers demonstrate misunderstandings of employment law, market behaviour, and regulatory responsibility, including proposing actions that would be unlawful or unnecessary if systems functioned properly.

  5. Evidentiary certificates undermine basic protections Provisions allowing NDIA certificates to stand as prima facie evidence shift the burden of proof onto individuals in circumstances of extreme power imbalance, undermining procedural fairness.

  6. Whistleblower protections are at risk Information-sharing penalties risk capturing whistleblowers acting in the public interest, creating a chilling effect on disclosure.

  7. Advocacy may be suppressed by anti-promotion orders Anti-promotion and related orders could be weaponised against advocates assisting participants through complaints, reviews, or public scrutiny, deterring advocacy and reducing transparency.

  8. Access to justice depends on advocates Legal representation is unaffordable for most participants. Advocates often provide the only practical support. Deterring advocacy would isolate participants and undermine access to justice.

  9. NDIS market regulation has worsened outcomes Regulatory approaches have contributed to price escalation and reduced accessibility. Without competition or tendering, enforcement cannot correct market failure.

  10. Penalties substitute for market design In the absence of selective contracting or competitive pressure, penalties replace contractual leverage, incentivising short-term profit taking rather than compliance.

II Closing Summary

This submission has been deliberately restrained and evidence-based, not because the issues lack urgency, but because experience shows that when concerns of this kind are dismissed as emotional or speculative, harm follows.

What emerges is not a theoretical risk, but a pattern Australia already recognises: when systems are designed around suspicion, coercion, and enforcement without adequate safeguards, harm is not accidental — it is foreseeable. The Robodebt Royal Commission made that clear. Once Parliament is on notice, responsibility no longer rests in ignorance, but in the choices that follow.

The only defence I would offer those currently charged with running the NDIS is that they are responsible for a system that is not working as intended, under immense pressure to control costs while also delivering safe and effective outcomes. However, that reality makes the implementation of foundational quality management systems more urgent, not less.

In a system as large, visible, and politically exposed as the NDIS, risk cannot be managed through threat, intimidation, or deterrence by penalty alone. A scheme of this scale will inevitably attract scrutiny and bad actors, but if its primary response is to defend itself through force of regulation rather than resilience of design, it risks ending up in conflict with the very people it depends on. The strongest protection the NDIS can have is goodwill — internally and externally — and a shared sense of responsibility for its sustainability. Participants and providers are not merely subjects of regulation; they are the Scheme’s most effective early-warning system. If those closest to the NDIS are alienated, fearful, or disengaged, risks will go unreported, problems will remain hidden, and the Scheme will be weaker, not stronger. A system that turns its natural allies into adversaries cannot protect itself.

If Committee members wish to see a true and unfiltered account of the impact that litigation and the ART process are having on participants, I respectfully recommend a simple exercise: open Facebook and search for a group using the words “NDIS ART”. Members will find a large, active community made up of thousands of everyday Australians currently navigating this process. What is immediately apparent is not opportunism or exploitation, but a consistent pattern of fear, confusion, exhaustion, and disbelief that the NDIS has placed them in this position. Participants and carers are asking one another how to cope, what to expect, and how to survive the process. Notably, across thousands upon

  • thousands of comments, there is a complete absence of any discussion about how to extract money
  • from the Scheme. No one asks how to “get more” from the NDIS. Instead, people are trying to
  • understand why they are being treated as adversaries, and how to protect themselves and their loved
  • ones from a system they once trusted. That reality deserves to be seen before further powers are
  • granted.

I make this submission because I believe deeply in the Australian instinct to act pro-socially — to do

  • the right thing even when no one is watching, and to protect those who are doing it toughest. I grew
  • up and spent most of my working life as far from Canberra as one can physically get in Australia, in the
  • East Pilbara region of Western Australia, in an industry that on the surface appears far removed from
  • social policy. Yet the values that underpin that work — responsibility, fairness, and looking out for one
  • another when the consequences are real — are the same values that underpin the social contract. I
  • contribute willingly and substantially as an individual because that is part of that contract. I want the
  • NDIS to work.

I am increasingly concerned that the Scheme is being framed primarily through the lens of cost, while

  • the human consequences of system failure are treated as secondary. Behind closed doors, in towns and
  • cities across this country, people caring for loved ones with profound disability and complex medical
  • needs are already under extreme pressure. They are providing care twenty-four hours a day, seven days
  • a week; fighting to keep someone alive, dignified, and safe; and carrying the constant, unspoken fear
  • of what will happen when they are no longer there. That fear is not abstract. It keeps people awake at
  • night.

No safeguarding framework that increases suspicion, coercion, or silence can be reconciled with the

  • purpose of the Scheme. An amendment described as strengthening safeguards, but which in practice
  • strips them away, is an oxymoron.

Without attributing intent, it is deeply concerning that these real-world impacts are consistently absent

  • from the Explanatory Memorandum, which presents a one-sided account that does not fully disclose
  • the foreseeable consequences of the powers proposed. If consultation has occurred, it has not been
  • conducted based on full and transparent disclosure of those consequences.

Parliament now has a responsibility to ensure that the NDIS remains a source of trust, stability, and

  • dignity — not a system people learn to fear. That is not what the Scheme was intended to be, and it is
  • not who we are meant to be.

III Drivers for Recommendations

Australia’s safeguarding obligations to people with disability begin with foundational human-rights constraints on the exercise of State power.

1. Universal Declaration of Human Rights

1.1 Article 7 of the Universal Declaration of Human Rights provides that “all are equal before the law and are entitled without any discrimination to equal protection of the law.”

1.2 Article 12 further provides that “no one shall be subjected to arbitrary interference… [and that] everyone has the right to the protection of the law against such interference or attacks” are given specific expression in the UNCRPD.

2. United Nations Convention on the Rights of Persons with Disabilities

2.1 United Nations Convention on the Rights of Persons with Disabilities (CRPD), which Australia has ratified:

2.2 Article 5(1) provides that “States Parties recognise that all persons are equal before and under the law.”

2.3 Article 16(1) requires States to “take all appropriate… measures to protect persons with disabilities… from all forms of exploitation, violence and abuse,” and

2.4 Article 13(1) requires “effective access to justice… on an equal basis with others.”

3. The Royal Commission into Violence, Abuse, Neglect and Exploitation of People with Disability then tested these commitments against evidence. It found that:

3.1 “Violence, abuse, neglect and exploitation” are “pervasive and systemic,” driven by “inadequate safeguarding, failures in systems and services, and the exercise of power without accountability,”,

3.2 It emphasised that safeguarding must prevent harm, not merely respond to it. Where government relies on the Royal Commission to justify reform, it assumes responsibility for acting consistently with its findings and safeguards.

4. These same commitments are embedded in the National Disability Insurance Scheme Act 2013 (Cth).

4.1 Section 3(1) states that the purpose of the Act is “to give effect to Australia’s obligations under the Convention on the Rights of Persons with Disabilities” by supporting independence, participation, and choice and control. Financial sustainability appears only as a secondary consideration,

4.2 with section 3(3) requiring merely that “regard is to be had” to sustainability in giving effect to those objects.

4.3 Section 4 of the Act then sets out binding General Principles, including that people with disability have the same right as others to realise their potential

4.4 (s 4(1)); should have certainty of lifetime supports

4.4.1 (s 4(3)); should be supported to exercise choice and control, including taking reasonable risks
4.4.2 (s 4(4)); have the right to dignity and to live free from abuse, neglect and exploitation

4.4.3 (s 4(5)); are assumed to have capacity to determine their own best interests

4.4.4 (s 4(8)); and that “the best interests of children with disability are paramount”

4.4.5. (s 4(9)). Section 4(17) requires the NDIA to perform its functions consistently with these principles.

Taken together, these sources describe a single safeguarding pathway — from foundational human rights, through ratified international obligations, through the findings of the Royal Commission, and into the NDIS’s own statutory purpose and operating principles. The Committee now stands at the decision point on that pathway. The following recommendations identify the lowest-risk option available: one that aligns with this established framework and avoids foreseeable harm. Other pathways remain open. This submission simply makes clear which path is load-bearing, and which paths carry known and avoidable risk.

IV Committee Recommendations

The following recommendations are respectfully provided for the Committee’s consideration in parallel with its consideration of the obligations reflected in the above-mentioned international conventions and domestic Acts, all of which mandate the prioritisation of the safety, dignity and wellbeing of people with disability.

From the Universal Declaration of Human Rights through to the day-to-day operation of the NDIS in people’s homes, protection of people with disability is the primary and unifying objective. That objective must remain paramount, and it must sit at the core of every risk assessment and decision making process, consistent with the safeguarding and risk-management frameworks the NDIA states it applies. In the current climate of heightened sensitivity to risk following recent, widely reported loss of life involving people with disability, the practical consequences of legislative design are neither abstract nor theoretical.

Decisions taken in this context have real-world impacts, and where safeguards fail, lives are genuinely

at risk.

No Requested Action UNCRPD- Reason (final — tightened, firm, Article _ plain English) (Art)

1 Recommend the Bill Backgro Vol 1, Art The case for urgency hasn’t been

NOT BE PASSED in its und; Recom 4(1)(b), | made, and the foundations are

current form (or Financia mendati Art 16 not reliable enough for heavier

defer). | on 4.3 penalties. Expanding coercive

Impact; powers into a system with known Part 2 control gaps will multiply errors

and unfair outcomes. Fix the system first, then calibrate enforcement.

63 29 January 2026 —- Completed by L. Howard-Fielding

Refer the Explanatory Memorandum for independent review and re-issue.

The Explanatory Memorandum is EM; example of recom mendati ons; on 11.3 Stateme nt of Compati bility. The document Parliament relies on to understand what this Bill actually does. If it contains gaps, misstatements or selective framing, scrutiny is compromised. An independent review is a basic integrity step before the Bill proceeds.

  • Separate safeguarding from cost or growth controls in the legislation.

Backgro und; Financia l Impact; Part 2: Safeguarding and cost containment are not the same policy objective and should not be legislated as if they are. Blending them under an ‘integrity’ banner masks intent and weakens accountability. Separate the purposes so the public can see what’s driving decisions.

  • Make system readiness a legal prerequisite with an independent ISO-aligned QMS.

Part 2; ANAO Recom endati on 4(1)(c): Enforcement is only defensible when the underlying system is demonstrably capable and auditable. Without a tested, independent quality-management backbone, stronger powers simply magnify mistakes. Make verified system readiness the legal precondition.

  • Implement key Royal Commission/Review reforms before enforcement expansion.

Royal Commis sion referenc es; Part 2: The Royal Commission and NDIS Review focused on fixing the front-end failures—complaints, governance, decision-making and safeguards—because that prevents harm. Penalties are a blunt tool that arrive after damage is done. Reform first; enforcement second.

  • Publicly map each Royal Commission recommendation to each Bill provision.

Royal Commis sion referenc es: If the Bill truly implements the Commission’s recommendations, that alignment should be traceable and easy to verify. A public crosswalk forces clarity and prevents ‘headline alignment’ without delivery. It’s a simple

transparency measure with high value.

7 Do not rely on Parts 2– Vol 6, Art 5(1) ‘Safeguarding’ language can’t ‘safeguarding’ 3 Recom substitute for evidence that new language to justify new mendati punitive tools are necessary and punitive tools. on 11.8 effective. If the risk is real, it should be demonstrated with data, and the response should be proportionate. Powers must match proven need, not rhetoric.

8 Refer the Bill for Stateme Vol 7, Art 5, Strict liability, high penalties and enhanced nt of Recom Art 12, broad discretions can create real human‑rights scrutiny Compati mendati Art 13 human-rights impacts in practice, and revise the bility; on 12.1 not just on paper. Independent Statement of Parts 2 scrutiny strengthens the Bill and Compatibility. & 7 reduces the risk of later harm and litigation. Get the rights settings right before expansion.

9 Align offences and Part 2 Vol 6, Art 22, The Commonwealth already has penalties with the Recom Art 17 well-established design principles Attorney‑General’s mendati for offences and penalties. Guide. on 11.9 Aligning with that guidance keeps measures proportionate, consistent and defensible. If the Bill can’t meet those standards, it shouldn’t proceed as drafted.

10 Limit parallel Parts 2, Vol 6, Art Compulsory information powers civil/criminal exposure 5, 7 Recom 14(2) combined with penalties can place and protect the right to mendati people in an impossible position. silence. on Basic protections—like limits on 11.10 use and clear preservation of the right to silence—are non- negotiable. Fair process is part of safeguarding.

11 Exclude Parts 2 Vol 4, Art 3(d), Participants, nominees and participants/nominees/ & 5 Recom Art 12 families should never be collateral families from penalty mendati damage of provisions aimed at provisions except for on 7.6 misconduct. ‘Intent’ statements in serious fraud. an EM don’t protect people once the words are in the Act. The

drafting must explicitly exclude them, except for serious fraud.

12 Protect advocacy,

Part 4 Vol 4, Art Advocacy and representation are advice and Recom 13(1) essential safeguards—especially representation from mendati when power is imbalanced. If the being treated as on 7.5 Bill chills advice or is misread as promotion. ‘promotion’, people will lose support at the worst time. Build clear protections so access to justice remains real.

13 Remove or significantly narrow anti‑promotion orders.

Part 4 Vol 4, Art 21 Anti-promotion orders risk Recom silencing legitimate information, mendati criticism and community warning on 7.3 signals. That undermines transparency and can reduce safety rather than improve it. Any restriction must be narrowly defined, necessary and tightly controlled.

14 Re-orient the framework to prevention first, enforcement last.

Part 2 Vol 5, Art 26 Good systems prevent harm; Recom penalties punish after the fact. A mendati prevention-first model is safer for on 10.4 participants and cheaper for government. The Bill should be reoriented to build capability and controls before escalating coercion.

15 Complete ANAO-driven reforms with milestones before activating new powers.

ANAO Vol 6, Art Oversight findings already identify Recom 33(2) gaps that must be closed, with mendati milestones and verification. on 11.6 Expanding powers before those reforms are completed increases the risk of misuse and waste. Make readiness measurable and time-bound, then proceed.

16 Make high penalties contingent on proven system controls.

Part 2 Vol 6, Art 5(4) High penalties only work when Recom detection, data and decision mendati pathways are accurate and fair. on 11.9 Otherwise, the system punishes the wrong people and increases dispute and cost. Make the

Penalty regime contingent on proven controls

17 Require transparent public reporting on the use and outcomes of new powers. Parts 2–3 Vol 1, Art 33(2) If new powers are justified, their real-world use should withstand daylight. Transparent reporting on frequency, outcomes and impacts is the minimum for accountability. Without it, mistakes become invisible and normalised.

18 Require independent evaluation within 12 months with escalation pathways. Statement of Compatibility; Parts 2, 5, 7 Vol 1, Art 33(2) Large reforms need early independent evaluation, not a ‘wait and see’ approach. A 12-month review with clear escalation pathways catches harm before it becomes systemic. Build the feedback loop into the law from day one.

19 Confirm reasonable-and-necessary disputes are not integrity matters. Part 2 Recom mendati Vol 5, Art 12(3) Reasonable-and-necessary disputes are part of lawful decision-making, not an ‘integrity’ problem. If ordinary entitlement disagreements are treated as misconduct, people will be deterred from review and fairness will erode. Draw a bright line in the statute.

20 Tighten ‘a person/other persons’ to defined regulated entities. Part 5 Recom mendati Vol 6, Art 5(1) ‘A person’ and ‘other persons’ is drafting that invites overreach and uncertainty. If obligations are intended for regulated entities, the Act should say so. Precision is a safeguarding tool because it prevents accidental capture and abuse.

21 Constrain information-gathering powers with necessity and privilege safeguards. Part 5 Recom mendati Vol 6, Art 22 Information-gathering powers must be tightly bounded by necessity, proportionality and privilege safeguards. Broad reach and short notice can create severe imbalance and procedural unfairness. Safeguards protect

both legitimate enforcement and

community trust.

22 Invest in effective Safegua Vol 4, Art A functional complaints system is

complaints handling rding Recom 16(3) one of the strongest safeguards and early resolution. narrativ mendati available. It resolves issues early, e e on 7.2 reduces escalation and prevents harm before enforcement is needed. Investing here is practical, cheaper and more humane than punishment-first.

23 Secure funding and Complia Vol 4, Art Independent advocacy is a

   protection for          nce     Recom    29(b)      protective mechanism that
  independent advocacy.   framing   mendati             balances power and improves

e on 7.1 decision quality. Without stable funding and clear protection, l advocacy becomes fragile—and participants carry the risk. If safeguarding is serious, advocacy must be protected.

24 Adopt recognised Integrity Vol 6, Art Audited quality and risk

   ISO‑aligned quality and   rational  Recom    4(1)(b)    frameworks are standard in high-
    risk frameworks.        e        mendati                risk sectors because they drive
                              on 11.4              consistency, learning and continuous
                                                       improvement. They prevent problems rather than merely reacting to them. The
                                                      Scheme should meet the same
                                                             professional baseline.

25 Insert use‑limitation Parts 5 Vol 6, Art 14, Compelled information should not

  and use‑immunity for   & 7      Recom    Art 22    be repurposed in ways that strip
                                 mendati            people of fairness. Use-limitation compelled information.

pos on and use-immunity reduce the risk 11.10 of coercion becoming a shortcut d to punishment. These are standard safeguards where compulsion exists.

26 Ensure enforcement Parts 2, Vol 6, Art 13 Enforcement interacting with

   aligns with lawyers’       5, 7     Recom                 litigation creates high risk—cost
   duties and add                   mendati             blowouts, strategic misuse and
    litigation oversight.              on                    unfairness. Clear safeguards and
                                    11.11                oversight ensure coercive powers
                                                          don’t distort court processes.

Litigation should remain a forum for fairness, not leverage.

27 Mandate training, ethical KPIs and oversight for staff instructing lawyers.

Commis powers: Vol 6, Recom 4(1)(d)

Decisions to escalate matters are high-stakes and should be made with training, ethical KPIs and independent oversight. Without standards, discretion can drift into culture and habit. Measurable accountability is how you prevent misuse.

28 Strengthen executive commercial and market capability.

Market regulation: Vol 5, Recom Art 19, Art 28

A regulated market of this size requires specialist capability—commercial, regulatory and consumer protection expertise. If that capability is weak, enforcement becomes the default tool rather than smart prevention. Build capability so regulation is competent, not punitive.

29 Use independent facilitation for consultation where power imbalance exists.

Consultation framing: Vol 1, Recom

Consultation is meaningless if people can’t speak freely due to power imbalance. Independent facilitation reduces fear and improves candour, making consultation usable and honest. Better consultation produces better safeguards and fewer disputes.

30 Research pro-social and trust-based compliance approaches.

Deterrence focus: Part 2, Vol 1, Recom Art 8

Compliance works best when people trust the system and understand what’s expected. Pro-social, behavioural approaches reduce error and improve cooperation, especially in complex schemes. Enforcement should be balanced with trust-based design, not dominated by deterrence.

31 Re-engage participants through short, regular surveys during implementation.

Safeguarding intent: Vol 1, Recom 33(3)

Participants are the first to notice when safeguards fail in practice. Short, regular surveys provide an early warning system and a way to fix issues quickly. If the goal is

End

.

70

End Note References

i National Disability Insurance Scheme Amendment (Integrity and Safeguarding) Bill 2025 – Explanatory Memorandum, Background and Outline. ii Explanatory Memorandum, Consultation section. i ii Royal Commission into Violence, Abuse, Neglect and Exploitation of People with Disability, Final Report (2023). iv Royal Commission into Violence, Abuse, Neglect and Exploitation of People with Disability, Final Report (2023). v Explanatory Memorandum, Schedule 1. vi Explanatory Memorandum, Overview Page 1 vii Productivity Commission, Disability Care and Support, Report No. 54 (2011). viii Australian Government, History of the NDIS, National Disability Insurance Agency. xix National Disability Insurance Scheme Act 2013 (Cth) tx United Nations Convention on the Rights of Persons with Disabilities. txi NDIS Quality and Safeguards Commission, NDIS Quality and Safeguarding Framework. txii National Disability Insurance Scheme Amendment (Integrity and Safeguarding) Bill, Explanatory Memorandum tx iii Australian National Audit Office; Royal Commission into Violence, Abuse, Neglect and Exploitation of People with Disability — findings relating to system design, access disputes, and participant harm. txiv National Disability Insurance Scheme Amendment (Integrity and Safeguarding) Bill 2025, Explanatory Memorandum, Outline, item 4. tx v Figure 1.1 Auditor-General Report No. 23 2023–24 Management of Complaints by the National Disability Insurance Agency tx vi National Disability Insurance Scheme Amendment (Integrity and Safeguarding) Bill 2025, Explanatory Memorandum, Schedule 1, Items 1–3 (section 57 explanatory material).txvii National Disability Insurance Scheme Amendment (Integrity and Safeguarding) Bill 2025, Explanatory Memorandum, Schedule 1, Item 3.txviii National Disability Insurance Scheme Amendment (Integrity and Safeguarding) Bill 2025, Explanatory Memorandum, Part 4, Item 76.xix Australian National Audit Office (ANAO), Auditor‑General Report No. 23 (2023–24), Management of Complaints by the National DisabilityInsurance Agency (published 22 April 2024). xx ANAO, Auditor‑General Report No. 30 (2024–25), Effectiveness of the NDIS Quality and Safeguards Commission’s regulatory functions(2025). x x i NDIA, NDIS Quarterly Report to disability ministers – 30 June 2024 (Q4 2023–24), Table D.18. xx ii NDIA Annual Report 2022–23 – AAT external merits review applications lodged by participants

xx iii NDIA Annual Report 2023–24 – AAT external merits review applications lodged by participants and ADR finalisation rate.

xx iv The Guardian (Australia) reports on ART appeal volumes (7,132 in the most recent reported year).txv Rick Morton, The Saturday Paper, 28 Oct 2023, reporting on legacy AAT matters and dispute resolution outcomes.txvi NDIA Annual Report 2023–24 – AAT external merits review applications lodged by participants and ADR finalisation rate.txvii Legal Services Directions 2017, Appendix B (Model Litigant Obligation), paragraph 2 and sub-paragraph 2(f) tx viiix NDIS Amendment (Integrity and Safeguarding) Bill 2025 – Explanatory Memorandum, Outline item 4.xxxx Bill Shorten defends NDIS reforms that will save the government $14 billion, ABC News, 25 Aug 2024 d xxx Bill Shorten responds to concerns around NDIS changes, ABC News, 2 Oct 2024.d xxi National Cabinet commits to a sustainable NDIS, Media Release, 28 Apr 2023.dx xx ii Shorten defends disability cost savings, Australian Financial Review, 25 Aug 2024.dx xiii Bill Shorten under pressure to rein in NDIS costs, The Australian, 20 May 2023. dx iv National Disability Insurance Scheme Act 2013 (Cth), s 4 (general principles)dxx v NDIS Code of Conduct; NDIS Practice Standards; NDIS safeguarding and operational guidance acknowledging participant vulnerability.Itdxvi Explanatory Memorandum, Schedule 1 (penalties, deterrence, and enforcement mechanisms)dxvii Explanatory Memorandum, National Disability Insurance Scheme Amendment (Integrity and Safeguarding) Bill 2025, p.

x xv iii Auditor-General Report No. 48 2024–25, National Disability Insurance Agency’s Management of Claimant Compliance with NDIS Claim Requirements, summary and Chapter 1 (including paras describing the system as “partly effective” and lacking basic prevention controls before 2024). x lxiv Auditor-General Report No. 48 2024–25, ibid., analysis of pre-payment review coverage and cancellation rates (Table 2.4 and associated discussion).xl National Disability Insurance Agency, media release “$86 million in dodgy NDIS claims blocked by Fraud Fusion Taskforce”, 8 October 2025, reporting 20 successful criminal prosecutions since November 2022.

A. Reference Register (Refreshed) A. Acronyms and abbreviations ISO — International Organisation for Standardisation IEC — International Electrotechnical Commission COSO — Committee of Sponsoring Organisations of the Treadway Commission ERM — Enterprise Risk Management SMS — Safety Management System BCMS — Business Continuity Management System ISMS — Information Security Management System WCAG — Web Content Accessibility Guidelines NDIS — National Disability Insurance Scheme

NDIA — National Disability Insurance Agency

ANAO — Australian National Audit Office ART — Administrative Review Tribunal ICCPR — International Covenant on Civil and Political Rights CRPD — Convention on the Rights of Persons with Disabilities

Reference codes used in the document (unique)

EM-1 — Explanatory Memorandum — overview/policy intent (general framing) EM-2 — Explanatory Memorandum — safeguarding/integrity objectives asserted EM-3 — Explanatory Memorandum — intent-based assurances (“not intended…”) EM-4 — Explanatory Memorandum — accountability/proportionality/enforcement framing EM-5 — Explanatory Memorandum — complaints, compliance escalation, information powers EM-6 — Explanatory Memorandum — enforcement sequencing/speed emphasis EM-7 — Explanatory Memorandum — system fragmentation/capability/data gaps EM-8 — Explanatory Memorandum — justification for expanded powers EM-9 — Explanatory Memorandum — overarching enforcement architecture claims EM-14 — Explanatory Memorandum — penalty levels/deterrence rationale EM-16 — Explanatory Memorandum — penalties relating to section 73B EM-19a — Explanatory Memorandum — penalties for serious contraventions (as cited) EM-19b — Explanatory Memorandum — penalty calibration / “cost of doing business” rationale EM-21 — Explanatory Memorandum — clause notes (as cited) EM-51 — Explanatory Memorandum — later provisions (as cited) HR-1 — Statement of Compatibility with Human Rights (in the Explanatory Memorandum) HR-2 — Human-rights analysis in EM (ICCPR compatibility claims) HR-3 — EM clause notes — strict/absolute liability and increased penalties HR-4 — Attorney-General’s Guide to Framing Commonwealth Offences (and ALRC commentary as used) HR-5 — EM — evidentiary certificates / prima facie evidence mechanism HR-6 — EM — “not a cost of doing business” penalty intent HR-7 — ICCPR + CRPD provisions relied on in human-rights conflicts (as cited) HR-8 — Parliamentary Joint Committee on Human Rights — Guidance Note 2 ISO-1 — AS/NZS ISO 9001:2016 — Quality Management Systems — Requirements ISO-2 — AS ISO 31000:2018 — Risk Management — Guidelines ISO-3 — AS ISO 10002:2018 — Complaints Handling — Guidelines COSO-1 — COSO (2017) — Enterprise Risk Management: Integrating with Strategy and Performance BHP-1 — BHP public reporting — governance/ERM/board accountability (as cited) BHP-2 — BHP risk/contractor management frameworks (as cited) BHP-3 — BHP complaints/whistleblower mechanisms (as cited) BHP-4 — BHP integrated enterprise systems/disclosures (as cited) ANAO-1 — ANAO Auditor-General Report No. 48 (2024–25) — claimant compliance controls (as cited) ANAO-2 — ANAO Report No. 48 (2024–25) — system readiness/control environment (as cited) RC-1 — Disability Royal Commission — safeguarding/accountability findings (as cited) NDIS-Act-1 — National Disability Insurance Scheme Act 2013 (Cth) NDIS-Complaints-1 — NDIS complaints/feedback framework (as cited) NDIS-Safeguards-1 — NDIS Quality and Safeguards Commission — safeguarding guidance (as cited) NDIS-Safegards-2 — NDIS Quality and Safeguards Commission — compliance/enforcement guidance (as cited)

In-text authority tag you added (for former stray “2” markers)

Auditor-General Report No. 48 (2024–25) — National Disability Insurance Agency’s Management of Claimant Compliance with NDIS Claim Requirements — used as [Auditor-General Report No. 48 (2024–25)].

VI Disclosure by the Author:

Limited drafting assistance was used to support editing and organisation of this submission. Responsibility for the content and any conclusions drawn rests with me. This submission was prepared independently and voluntarily; I have not received payment, endorsement, or other consideration in connection with it. I declare no conflict of interest: I do not work for any government, political, health, or disability service organisation, and I do not hold any business or contractual interests that could benefit from outcomes relating to the NDIS. My knowledge of the NDIS is that of an informed citizen, based on research and lived engagement. References to BHP Group Limited are illustrative only and do not imply representation or endorsement, purely a deep respect. This submission has been prepared carefully and in good faith, drawing on the best information available to me; however, it reflects the work of an individual rather than a formal system. In recognition of the power and trust dynamics involved when engaging with vulnerable people, readers are encouraged to independently verify any information on which they intend to rely and to exercise their own judgment.

Community Affairs Legislation Committee

Submission: National Disability Insurance Scheme Amendment

(Integrity and Safeguarding) Bill 2025

Submission Annexures

  1. Annexure 1 — The Big Australian Vs the Bigger Australian: Comparative Excellence in A2

Managing Risk

Comparison of governance architecture, accountability structures, complaints handling,

and risk sequencing between an |SO-aligned industrial model and the current NDIS

framework. 1.1 Annexure 1A — Governance Architecture A3 Accountability design and risk ownership comparison. 1.2 Annexure 1B — Complaints Handling A4 ISO 10002 safeguards contrasted with current NDIS practice. 1.3 Annexure 1C — Risk Management Sequencing AS

Preventive risk treatment versus enforcement-first approaches.

-—______ S

  1. Annexure 3 — Legislative and Explanatory Memorandum Cross-References A14 Clause-by-clause mapping of identified issues to the Amendment Bill and relevant EM provisions

  2. Annexure 4 — Relevant ART Decisions A16 Selected Tribunal decisions demonstrating practical application of procedural fairness, evidence standards, and “reasonable and necessary” criteria.

  3. Annexure 5 — Analysis of Explanatory Memorandum Examples A18 Assessment of EM scenarios against existing legal, regulatory, and |SO-based controls to

test whether additional enforcement powers are necessary.

  1. Annexure 6 — Risk Assessment Workbook (separate Excel attachment) A22 Standards-based risk register identifying hazards, consequences, controls, and residual risks associated with the proposed amendments.

Submission - National Disability Insurance Scheme Amendment (Integrity and Safeguarding) Bill 2025 Al

29 January 2026 —- Completed by L. Howard-Fielding

  1. Annexure 1—- Case Study 1: The Big Australian Vs the Bigger Australian: Comparative Excellence

in Managing Risk

Purpose

This annexure provides a structured comparison between the governance architecture of a large, high

risk industrial organisation (BHP) and the National Disability Insurance Scheme.

Description

The comparison illustrates how organisations of comparable financial scale and systemic consequence routinely implement formal risk management, quality assurance, and accountability controls aligned to recognised international standards (including ISO 31000 and ISO 9001). It is provided to demonstrate that the absence of equivalent third-party quality and risk controls within the NDIS is a design gap rather than an inherent feature of large or complex systems, and that proven governance models already exist which could be adapted to the Scheme.

Dimension BHP Group Limited National Disability Insurance Scheme

(NDIS)

annual

AUD $40-50bn+ expenditure

public

People directly 80,000-90,000 employees; large 600,000+ participants; hundreds of affected contractor workforce thousands of workers

Delivery model Contractors and suppliers Registered providers and third-party

services Nature of risk Industrial, environmental, Life-sustaining personal and medical catastrophic safety risk support risk

z-le-Meels-vel-e-meViultiple fatalities, environmental Preventable death, serious harm, harm neglect

Submission - National Disability Insurance Scheme Amendment (Integrity and Safeguarding) Bill 2025 A2 29 January 2026 —- Completed by L. Howard-Fielding

  1. Annexure 1A —Governance Architecture

Purpose

This annexure summaries differences in accountability structures and decision-making controls.

Description

It contrasts vertically integrated governance models, where responsibility and risk ownership are clearly assigned to named decision-makers and auditable management systems, with the current NDIS structure, where accountability is frequently diffuse and reliant on external review or litigation. The comparison highlights how clear ownership, documentation, and internal oversight operate as primary safeguards in mature systems

Governance Element ISO / BHP-Style Model NDIS Current Model

Accountability flow Vertical to management and board Horizontal to external bodies

Risk ownership Named managers Diffuse or unclear

Decision rationale Documented and auditable Often opaque

Oversight Board and audit committees Reliance on litigation and review Submission - National Disability Insurance Scheme Amendment (Integrity and Safeguarding) Bill 2025 A3

29 January 2026 —- Completed by L. Howard-Fielding

  1. Annexure 1B — Complaints Handling

Purpose

This annexure compares complaints handling practices under recognised quality standards with current NDIS processes.

Description

Using ISO 10002 as a reference framework, the table illustrates how early resolution, non-reprisal protections, and mandatory learning loops operate as preventive controls in quality-managed environments. It is provided to show how the absence of these controls in the NDIS shifts disputes toward escalation and formal review rather than timely system improvement.

Complaint Stage ISO 10002 / BHP-Style NDIS Current Practice

Initial framing Neutral, risk-based Compliance-focused

Non-reprisal System enforced Not structurally protected

Escalation Last resort Often routine

Learning loop Mandatory system improvement Limited or optional

Submission - National Disability Insurance Scheme Amendment (Integrity and Safeguarding) Bill 2025 A4

29 January 2026 —- Completed by L. Howard-Fielding

  1. Annexure 1C — Risk Management Sequencing and System Capability

Purpose

This annexure demonstrates how enforcement should function within a mature risk management system.

Description

Drawing on ISO 31000 principles, it shows that enforcement mechanisms are ordinarily applied as a last-stage control after risks have been identified, analysed, and treated through preventive measures. It contrasts this with current NDIS practice, where enforcement or compliance responses may precede structured risk treatment, increasing the likelihood of avoidable harm and dispute.

Risk Step ISO 31000 / BHP Model NDIS Model

Risk identification Proactive and continuous Triggered by dispute

Risk analysis Likelihood x consequence Often absent

Risk treatment Controls before enforcement Enforcement first

Monitoring and review —_ Continuous internal review External appeal after harm

Submission - National Disability Insurance Scheme Amendment (Integrity and Safeguarding) Bill 2025 AS

29 January 2026 —- Completed by L. Howard-Fielding

  1. Annexure 3 — Legislative and Explanatory Memorandum Cross-References

Purpose

This annexure maps identified issues to specific provisions of the Amendment Bill and the corresponding Explanatory Memorandum.

Description

It provides a clause-by-clause reference tool linking each concern raised in the submission to the relevant legislative text and explanatory material. The table is provided to assist the Committee in verifying the factual and legal basis for each issue and to enable efficient cross-checking between the submission, the Bill, and the Explanatory Memorandum.

Issue Issue Summary Amendment Bill — Amendment Bill — Key Effect Explanatory Memorandum —

No. Location Reference & Issue

Participants not Part 2—Compliance and _ Civil penalties, infringement notices, Chapter 1— Overview and meaningfully excluded Enforcement Framework and information-gathering powers Policy Intent. Statements that from enforcement and apply broadly to “persons” and participants are “not intended”

penalties “entities” without an _ express to be the focus of enforcement statutory exclusion for participants rely on intent rather than legal acting in good faith. immunity.

Structural power Part 2—Compliance and Centralises coercive and Chapters 1—2 — Context,

imbalance between — Enforcement Framework discretionary powers in the NDIA Rationale, and Financial

participants and the without corresponding duties tolmpact. Emphasis on

NDIA mitigate vulnerability, enforcement efficiency with disability-related barriers, or limited acknowledgement of information asymmetry. participant dependency or

power imbalance.

ART litigation used Part 2 — Enforcement Enforcement action may proceed Chapter 1— Review and coercively and at scale Architecture prior to, alongside, or irrespective of Oversight. Merits review the outcome of merits review, framed as downstream rather increasing pressure to abandonthan a safeguard requiring

review rights. protection. Existing mechanisms N/A -— Existing legal No demonstrated gap analysis Chapter 1— Interaction with already address fraud frameworks showing why existing criminal, civil, Existing Laws. EM states and abuse acknowledged consumer-law, and regulatoryamendments are not intended mechanisms are insufficient. to displace Australian

Consumer Law, criminal fraud provisions, or professional

regulation. Cost containment Part 2 — Enforcement Expanded powers operate as Chapters 1-2 —-Scheme prioritised over and Compliance indirect budgetary controls through Sustainability and Financial safeguarding Expansion deterrence, risk transfer, andImpact. Repeated reliance on enforcement escalation. expenditure control and leakage prevention as justification. Non-compliance can Part 2— Strict timeframes and compliance Chapter 1— Operation of be manufactured Information-Gathering triggers apply to regulated parties Powers. EM does not address through delay or and Compliance Notices without reciprocal obligations on how delay, silence, or disability complexity can convert administrative Submission - National Disability Insurance Scheme Amendment (Integrity and Safeguarding) Bill 2025 A14

29 January 2026 —- Completed by L. Howard-Fielding

the NDIA to act promptly or failure into alleged

accessibly. non-compliance. Conflict with Part 2 — Enforcement Enforcement powers are Chapter 1— Review established ART Powers exercisable notwithstanding Mechanisms. No reconciliation reasoning and findings repeated adverse findings against with established ART

the NDIA in merits review. jurisprudence on fairness or

proportionality.

Human-rights Part 2 — Penalty and Penalty exposure and_ coercive Statement of Compatibility

obligations Enforcement Framework powers engage rights to fairness, with Human Rights.

undermined equality before the law, and Compatibility asserted without proportionality without graduated detailed operational analysis. safeguards.

Model-litigant and Part 2 — Enforcement Framework incentivises deterrence Chapter 1 — Enforcement

legal-ethics risks Philosophy and capitulation over fairness, Philosophy. Limited increasing adversarial conduct by consideration of the State. Commonwealth model-litigant obligations. Parallel civil and Part 2 — Compelled’ disclosure operates Chapter 1 — Safeguards. criminal exposure Information-Gathering alongside potential civil and criminal Limited practical guidance on Powers liability, placing pressure on the protection of privilege, right to silence and privilege. particularly for unrepresented persons. Regulatory duplication Part 2 — Enforcement Discretionary enforcement Chapter 1 — Threshold land indeterminate Thresholds triggered by vague standards rather Language. Use of terms such as thresholds than objective statutory criteria. “may”, “intended”, and “intense” without definitional clarity. No reciprocal Part 2 — Penalties Escalating sanctions apply to Chapter 1— Oversight laccountability for Framework participants and providers without Narrative. Absence of NDIA equivalent consequences for NDIA reciprocal accountability maladministration delay, error, or unlawful mechanisms.

decision-making.

Consultation claims N/A-—Reliance on Legislative justification relies on Chapter 1— Consultation and

mischaracterised consultation narrative — consultation claims without Policy Context. Conflation of disaggregating support for this support for Royal Commission specific model. findings with support for the

amendments as drafted.

Structural parallels Part 2—Burden-Shifting Deterrence-first enforcement and Chapter 1— Assumptions of with Robodebt Design burden transfer operate prior toCompliance. Similar logic to proof or independent verification. Robodebt identified.

Real-world case N/A — Operational Existing cases demonstrate Chapter 1 — Safeguards and studies show harm practice procedural harm, delay, and Oversight. EM does not engage land accountability accountability diversion without with ART outcomes or lived diversion expanded powers. administrative experience.

Anti-promotion and Part 2—Risk and Penalty Risk concentration discourages Chapters 1-2 — Review chilling effects Allocation advocacy, market participation, and Interaction and Regulatory lawful challenge. Impact. No assessment of chilling or deterrent effects.

Submission - National Disability Insurance Scheme Amendment (Integrity and Safeguarding) Bill 2025 A15 29 January 2026 —- Completed by L. Howard-Fielding

  1. Annexure 4 —- Relevant ART Decisions

Purpose

This annexure summarises selected Administrative Review Tribunal decisions relevant to NDIS decision-making and safeguards.

Description

The decisions demonstrate how statutory criteria such as “reasonable and necessary supports”, procedural fairness, evidence requirements, and proportionality are applied in practice by an independent merits review body. They are included to show that careful, evidence-based reasoning already operates as a safeguard within the existing framework, and to highlight potential tension between that approach and expanded compliance or enforcement mechanisms

Decision (Tribunal Core topic (what the

Tribunal

decided)

citation / date)

Butler and National Scope of Disability Insurance — supports and Agency (NDIS) [2025] ‘s 24 ARTA 1579(28Aug __ disabilities’ vs

  1. other health conditions; application of s 34 and

Schedule

exclusions Sharp and National _ Notice /

Disability Insurance reasons

Agency [2023] AATA _ obligations for 1323 (25 May 2023) statement of participant supports

(SOPS)

decisions Arnel and National Access criteria Disability Insurance — — disability Agency [2019] AATA requirements 4778 (18 Nov 2019) _unders 24

Key principle extractable point

/ Relates Where to cite in your to Core submission (suggested Issue(s) insertion point)

Demonstrates Tribunal’s 6, 7, 15 Issue 7 (conflict with ART

granular, evidence-based approach to s 34 criteria, the need to link supports to the accepted disability, and careful treatment of overlap with non-s 24 conditions; illustrates why enforcement-style assumptions and broad discretions conflict with merits reasoning.

Supports procedural 6, 7, fairness argument: 12, 15 Tribunal commentary

indicates the statutory notice-and-reasons

requirements may not have been met on the

materials available; evidence how administrative _ failures

(notice, reasons, clarity) can drive dispute and ‘manufacture’ non compliance risk.

Illustrates

willingness to set aside NDIA decisions where evidence supports access

criteria; supports the proposition that independent merits

reasoning often differs from NDIA assumptions

reasoning) and Issue 15 (case studies / real-world harm): use as a worked example of the Tribunal’s approach to evidence, clarity, and statutory limits.

Issue 6 (manufactured

non-compliance) and Issue

12 (no reciprocal accountability): cite to show the Tribunal’s expectation of proper notice/reasons and the consequences when NDIA process is deficient.

Tribunal 3, 7, 15 Issue 3 (litigation at scale)

and Issue 7 (conflict with ART reasoning): an example of Tribunal correction of NDIA decisions; supports argument that coercive

29 January 2026 —- Completed by L. Howard-Fielding

EM __ topic (where EM should be tested)

engaged claims

EM: Overview / policy intent; safeguards and review narrative; any EM claims = about ‘systemic failure’ or need for stronger compliance powers should be reconciled with how the Tribunal applies the law case by-case.

EM: Review’ and oversight; administrative impact; human-rights compatibility (fair hearing / procedural fairness).

EM: Consultation and necessity claims; oversight _ narrative; any EM framing that stronger powers are

needed despite existing review A16

Submission - National Disability Insurance Scheme Amendment (Integrity and Safeguarding) Bill 2025

A1729 January 2026 – Completed by L. Howard-Fielding

and that safeguards lie in escalation undermines correction robust review rights (not lawful external review. mechanisms. extended enforcement).

McCutcheon v Reasonable Demonstrates that 7, 11, Issue 7 (ART reasoning) EM: Overview and National Disability and necessary ‘reasonable and 15 and Issue 11 policy intent; human- Insurance Agency supports — necessary’ is applied (indeterminate rights compatibility; [2015] AATA 624 (21 interpretation through evidence, thresholds): cite show any EM claims that Aug 2015) of s 34 and statutory criteria, and Tribunal’s structured reforms provide use of context; supports approach to s 34 and why ‘clarity’ should be testified against Tribunal evidence argument that rigid vague enforcement methodology. enforcement narratives thresholds risk inconsistency and (‘intended’, ‘may’) cannot overreach. substitute for case-by- case legal application.

Deacon v National Recognition of 2, 6, 16 Disability Insurance guardians / Agency [2022] AATA representation 3209 processes

  1. Annexure 5 — Analysis of Explanatory Memorandum Examples

Purpose

This annexure examines illustrative scenarios relied upon in the Explanatory Memorandum to justify

expanded regulatory powers.

Description

Each example is assessed against existing legal, consumer protection, employment, and quality management frameworks to determine whether additional NDIS-specific coercive powers are necessary. The analysis indicates that many scenarios describe issues that are already addressed through established controls, suggesting that systemic quality and accreditation mechanisms may

provide a more proportionate and effective response than expanded penalties.

EM

Reference

Item 35, page 10

Explanatory Memorandum “Example“

as Justification For Increased Powers

in Proposed Amendment

“Provider Georgiou applies to the Commissioner to be a registered NDIS provider for plan management supports. Provider Georgiou provides evidence of appropriate qualifications to support their registration application. The Commissioner registers Provider Georgiou as a registered NDIS_ provider for plan management supports.

The Commissioner later receives complaints about Provider Georgiou and following an

How Proposed Increased Powers are

Unnecessary, Ineffective Or Legally

Redundant

In a third-party, ISO-aligned quality framework, the “Provider Georgiou” scenario is a basic failure of competence and verification controls that should be prevented by the provider’s quality system and the certifier, not cleaned up later by NDIS penalties. AS/NZS ISO 9001:2016 requires organisations to “determine the necessary competence of person(s) doing work under its control” and to “ensure that these persons are competent on the basis of appropriate education, training or experience” and to “retain appropriate documented

investigation, identifies that the | information as evidence of competence”

qualifications provided in their registration | (clause 7.2), and to “implement production and

application were _ falsified. These | service provision under controlled conditions”

qualifications were a central requirement to be deemed suitable to deliver plan management supports. Provider Georgiou would otherwise not have met _ the suitability requirements for registration.

10 NDIS providers are required to provide supports and services in a safe and competent manner with care and skill and act with integrity, honesty, and transparency. Provider Georgiou’s conduct amounts to false representation to the Commissioner and undermines the integrity of the NDIS and puts NDIS participants at increased risk of harm. Their conduct amounts to a serious contravention of section 73D. The Commissioner commences civil penalty proceedings, seeking a high penalty against Provider Georgiou for the serious contravention.”

(clause 8.5.1). In practice, that means independent verification of qualifications at registration and periodic surveillance by the certification body; falsified qualifications would be detected at those points and treated as a major non-conformance leading to suspension or withdrawal of certification, rather than relying on ex-post civil penalty proceedings by the NDIS Commissioner.

29 January 2026 —- Completed by L. Howard-Fielding

A18

Item 80 Page 27

“Ophelia Auditing is an approved quality auditor and also provides consultancy services. Approved quality auditors are expected to not promote or represent any business interests (for example, consultancy services) or any entity with which they have an interest or may have an interest while conducting audits.

Provider Swift engages Ophelia Auditing to

undertake its quality audit as part of its application for registration. At the same time as auditing Provider Swift, Ophelia Auditing also promoted its consultancy services to Provider Swift.

Ophelia Auditing’s conduct undermines impartiality and standards expected of approved quality auditors. The Commissioner imposes a banning order against Ophelia Auditing prohibiting the promotion of vested business interests.”

In a genuine third-party, ISO-aligned quality framework, the Ophelia Auditing scenario is simply an impartiality and consultancy breach that should be prevented by existing rules, not managed through bespoke NDIS_ banning powers. AS/NZS ISO/IEC 17065:2013 requires that certification activities “shall be undertaken impartially” and that the body “shall not allow commercial, financial or other pressures to compromise impartiality”, and further that its services “shall not be marketed or offered as linked with the activities of an organisation that provides consultancy”. ISO/IEC 17021-1 adds that “the certification body and any part of the same legal entity … shall not offer or provide management system consultancy”. Together, these provisions would prevent an approved auditor from both auditing a provider and promoting its own consultancy services at the same time, and would allow the accreditor to treat that conduct as a non-conformance leading to corrective action or suspension.

“Provider 123 would like to become a registered NDIS Provider. Provider 123 wants the application process to go smoothly so they engage a consultancy service (Luna Consultancy) to help them with their application. Luna Consultancy promises to “guarantee registration” or “fast-track approval” and charges Provider 123 a fee to complete the registration application on their behalf.

Luna Consultancy does not create a new tailored registration application on behalf of

Provider 123. Instead, Luna Consultancy

copies a previous application they submitted on behalf of a different provider (Provider ABC) and uses the same information for Provider = 123’s application. luna Consultancy continues to use this generic information across many different provider registration applications. By doing this, Luna Consultancy is providing the Commissioner with information that does not accurately represent Provider 123.

This may lead to Provider 123 not having an understanding of their obligations or having appropriate systems for incident and risk management, complaints handling or behaviour support resulting in non compliance. This creates a greater risk of harm to NDIS_ participants receiving supports from Provider123 and undermines the integrity of registration in the NDIS.

It is not the role of the NDIS Commissioner to manage generic business practices occurring entirely outside the Scheme that are already regulated under consumer-protection and fair trading laws. Using NDIS-specific banning powers to police this kind of commercial behaviour is a symptom of the absence of a coherent third-party quality and accreditation framework, not a principled solution to an integrity problem.

This conduct is exactly what AS/NZS ISO 9001:2016 (clause 8.5.1 “production and service provision under controlled conditions”) is designed to prevent, and it is already regulated under the Australian Consumer Law, particularly section 18 (misleading or deceptive conduct), section 29 (false or misleading representations about services) and section 60 (services to be provided with due care and skill).

29 January 2026 —- Completed by L. Howard-Fielding

A19

Under this amendment, the Commissioner can now make a banning order to prohibit Luna Consultancy from engaging in this harmful practice and other specified activities as contained in the banning order.”

“The Commissioner receives a complaint that an NDIS participant (John) has been repeatedly assaulted by a support worker (Emily) who is employed at Provider001. The Commissioner urgently requires information or documents from Provider001 such as information about investigations or actions taken to prevent further harm to participants and the employment history of Emily including training and supervision. This information or documents will enable the Commissioner to determine whether there is an ongoing risk of harm to John or any other NDIS participant that Emily has close contact with.

29 The Commissioner reasonably believes that allowing a 14-day period for ProviderO0O1 to give the information or produce the document, would significantly increase the risk of serious harm to John and any other NDIS participant that Emily supports. The Commissioner is satisfied that a five-day period is reasonable in the circumstances.

Under this amendment, the Commissioner issues a section 56 notice and specifies a five-day period within which Provider001 is to give the information or produce the document to the Commissioner.”

Australian industrial law does not recognise “joint” or “dual” employment — an employee can only have one employer at a time, and courts have been explicit that there is “no concept of dual employment” whereby a second body shares employer _ status. Employment matters (recruitment, supervision, discipline, termination and wage disputes) are regulated under the Fair Work framework, and the NDIS’s own Pricing Arrangements acknowledge that “employment disputes or wage negotiations” fall under industrial law, not NDIS regulation. In this context, section 56 powers must not be used in a way that goes beyond obtaining information from ProviderOO1 and drifts into directing, influencing or co-managing the employment of “Emily”, because that would place the Commissioner in the position of a de facto second employer, contrary to established industrial law and outside the proper remit of NDIS regulation.

“Xander is a director of Provider Green (a registered NDIS provider). The Commissioner has imposed a banning order on Xander because he has been convicted of an offence of fraud and dishonesty involving Mehdi (an NDIS participant).

The Commissioner has received information Xander is continuing to claim supports against Mehdi’s NDIS plan and wants to request sign-in logs and other documents to investigate and ensure Xander is no longer involved with Provider Green. The Commissioner reasonably believes that allowing a 14-day period for Provider Green to produce these documents would significantly increase the risk of serious harm to Mehdi and other NDIS participants if Xander is not complying with the banning order. The Commissioner is satisfied that a

In a third-party, |SO-aligned quality system, the

“Xander” scenario should be prevented by basic governance, competence and_ control requirements, not chased with extra NDIS penalties. AS/NZS ISO 9001:2016 requires top management to “ensure that responsibilities and authorities for relevant roles are assigned, communicated and understood” (clause 5.3) and to “determine the necessary competence of person(s) doing work under its control” and “ensure that these persons are competent” (clause 7.2). It further requires the organisation to “implement production and service provision under controlled conditions” (clause 8.5.1), including control over who can perform critical activities. Taken together, these provisions mean a provider’s quality system must (and, if working properly, would) remove a_fraud convicted, banned director from any role involving claims, system access or participant contact. If Xander can still submit claims after a

29 January 2026 —- Completed by L. Howard-Fielding

A20

Submission - National Disability Insurance Scheme Amendment (Integrity and Safeguarding) Bill 2025

A2129 January 2026 – Completed by L. Howard-Fielding

seven-day period is reasonable to produce the documents in these circumstances. The failure of Provider Green’s governance and quality system, not a gap that can be meaningfully fixed by lowering the threshold for NDIS civil penalties.

31 Under this amendment, the meaning of Commissioner requests the sign-in logs and other documents, specifying a seven-day period within which Provider Green is to produce the documents to the Commissioner.”

It is entirely unrealistic to expect that a person who has already demonstrated such a low threshold for risk by committing criminal fraud would be meaningfully deterred by the prospect of an additional civil penalty for failing to provide documents to the NDIS.

Annexure 6 – Risk Assessment Workbook

(separate spreadsheet attachment)

Purpose

This annexure provides the structured risk assessment underpinning the conclusions of this submission.

Description

This workbook applies a standards-based risk management methodology consistent with ISO 31000 and third-party quality systems routinely used in other high-consequence industries. It identifies foreseeable hazards, consequences, existing controls, proposed controls, and residual risk ratings associated with the NDIS Amendment (Integrity and Safeguarding) Bill 2025.

The risk assessment template is adapted from a system originally developed for a large Australian iron ore operation with annual revenues comparable to the NDIS (in excess of $60 billion). It reflects established third-party quality management practices and aligns with recognised Australian and international risk management standards.

This assessment has been prepared both as a practical exercise and as a demonstration of the value of structured, evidence-based risk management in policy design. In the absence of a formal, documented risk assessment process during development of the proposed amendments, this analysis illustrates how foreseeable operational, legal, financial, and participant-safety risks can be identified and treated in advance.

Had a systematic risk assessment been undertaken at the policy design stage, it is likely that issues such as increased administrative burden, higher dispute and litigation costs, counter-productive enforcement outcomes, and unintended risks to vulnerable participants could have been recognised earlier and mitigated or avoided.

Consistent with the recommendations made throughout this submission for the adoption of a formal quality and risk management framework within the NDIS, this workbook demonstrates how straightforward risk identification, control planning, and accountability allocation can support more effective and defensible decision-making.

In short, this assessment is not theoretical. It is a worked example of the type of structured analysis that should routinely inform significant legislative and operational changes within the Scheme.

Access Risk Assessment- NDIS Amendment Integrity & Safeguarding) Bill 2025

Worksheets in spreadsheet:

  1. Context (Al risk assessment)
  2. Participants (participated in creating the risk assessment)
  3. Risk Assessment (this is the main worksheet in the spreadsheet.)
  4. Action Register (allocating responsibility for controls)
  5. Assessment Tool Matrix (the matrix to assess risk and generate a risk rating score)

QED