The hardest part of a reportable incident isn't usually the paperwork. It's the clock. Something happens on a Friday evening, a support worker isn't sure whether it crosses the line, and by the time it reaches the right person, hours of the notification window are already gone. For a registered NDIS provider, that window is where good intentions quietly turn into a compliance breach.
The obligation itself is settled and well-documented. What separates providers who handle it calmly from those who scramble isn't knowing the rules — it's having a system that catches an incident early, assesses it correctly, and produces the evidence on demand. This piece walks through what you must report, the timeframes that apply, where providers most often come unstuck, and how to build the kind of process that holds up under scrutiny.
What counts as a reportable incident
Registered NDIS providers have two related but distinct obligations. The first is to maintain an incident management system that records and responds to all incidents connected to the supports you deliver. The second — the focus here — is to notify the NDIS Quality and Safeguards Commission of a specific subset of those incidents, known as reportable incidents.
Reportable incidents are the serious ones. They fall into defined categories set out in the NDIS (Incident Management and Reportable Incidents) Rules 2018:
The death of a participant
Serious injury of a participant
Abuse or neglect of a participant
Unlawful sexual or physical contact with, or assault of, a participant
Sexual misconduct committed against, or in the presence of, a participant, including grooming
The use of a restrictive practice in relation to a participant that is not authorised or not in line with a required authorisation process
Two points catch providers out. First, the obligation covers incidents that occur in connection with the delivery of NDIS supports — not only those a worker directly caused. Second, allegations count. If a participant discloses something, that disclosure can trigger the reporting obligation before any investigation has concluded. You don't wait for proof, a police finding, or an internal review to complete before notifying.
When in doubt, report. Notifying an incident that turns out not to be reportable isn't a breach. Failing to notify one that is, is.
The notification timeframes
There are two notifications, with separate clocks, and both matter.
Most reportable incidents must be notified to the Commission within 24 hours of the provider becoming aware of them. This first notification is a prompt alert, not a complete account — it flags the nature of the incident, who was involved, when it occurred or was discovered, and the immediate actions taken. You are expected to notify within the window even if you don't yet have every detail.
A detailed report follows within five business days, covering the investigation, findings, and corrective actions taken or planned.
Unauthorised restrictive practices sit slightly differently: they're notified within five business days, unless the use also caused harm or a risk of harm to the participant, in which case the 24-hour timeframe applies. And where the Commission requests it, a final report may be required within 60 days of the five-day report.
The detail that trips people up most: the clock starts when the incident occurs or when the provider's key personnel become aware of it — not when your internal investigation wraps up. Calculating the deadline from the wrong moment is one of the most common reasons a notification lands late.
Reportable to the Commission, or recorded internally?
Not every incident goes to the Commission, but every incident goes somewhere. Minor injuries, near misses, medication errors, behavioural changes and environmental hazards generally don't meet the reportable threshold — but they still have to be recorded in your incident management system, responded to, and used to identify trends and reduce risk.
This distinction is worth training your team on explicitly, because the instinct under pressure is often the opposite of what's required: staff either over-escalate everything, or hesitate on something genuinely reportable because they're not sure. A clear, well-understood system removes that guesswork. And your records aren't short-lived — reportable incident records must be kept for seven years from the date of notification.
Where providers come unstuck
Auditors tend to see the same failure patterns, and the 2026 registration renewal cycle has brought sharper scrutiny of incident notification compliance. The recurring gaps are worth naming, because each is preventable:
Clock confusion. Timeframes calculated from the wrong starting point, usually the end of an internal investigation rather than the moment of awareness.
After-hours blind spots. Reportable incidents don't pause for weekends or public holidays. Without an out-of-hours escalation path, a Saturday-night incident can blow the 24-hour window before Monday.
Register mismatches. When an auditor compares your internal incident register against the Commission's records and finds incidents that were recorded but never notified.
Thin frontline training. Support workers are almost always the first to know. If they can't recognise a reportable incident or don't know who to tell, the system fails at its most important point.
Weak evidence of improvement. The Commission wants to see that your system drives genuine quality improvement, not box-ticking — corrective actions that actually close the loop.
The through-line is that incident compliance is less about any single report and more about a dependable process running quietly in the background, every day, including the days you'd rather not think about it.
Building an incident system that holds up
A few habits separate the providers who stay ready from the ones who firefight:
Set internal deadlines tighter than the regulator's. If frontline staff escalate priority incidents to management within a few hours, you've bought yourself room to notify well before 24 hours.
Make reportability easy to assess. Give workers clear, plain-language guidance on what crosses the line, so the decision isn't left to a stressed judgement call.
Template your notifications. Pre-built Stage 1 and Stage 2 formats mean nobody is writing from scratch mid-crisis.
Track the clock deliberately. Record the date and time of awareness, the notification, and the due date for the follow-up report — so nothing drifts.
Reconcile regularly. Periodically compare your internal register against the Commission portal to catch gaps before an auditor does.
Close the loop. Document corrective actions and show they were completed, not just planned.
How Accorda helps
This is exactly the kind of process a purpose-built platform is designed to carry. Accorda's incident management lets your team log an incident quickly — typing or dictating it — and uses AI triage to help assess severity and flag whether it looks reportable, so the judgement call isn't left to memory under pressure. Each incident moves through a clear lifecycle with corrective actions tracked to completion, not lost in an inbox. Records are tamper-evident, with integrity you can independently verify, and when an auditor asks, a per-incident evidence pack pulls the full trail together in one place. Smart, bundled notifications keep the right people aware without burying them in noise.
Accorda doesn't submit to the Commission portal on your behalf — that final lodgement stays with your authorised delegate — but it does the surrounding work that makes hitting the timeframe realistic: catching the incident, assessing it, documenting it, and keeping the evidence audit-ready.
The bottom line
Reportable incident obligations are among the most consequential things an NDIS provider has to get right, and enforcement is only tightening. The rules themselves are stable and knowable; the risk lives in the gap between an incident happening and it being recognised, assessed and notified in time. Build a system that closes that gap — early escalation, clear guidance, tracked timeframes, provable records — and the 24-hour clock stops being a source of dread. It becomes just another process you already have covered.
Want incident management that catches the clock for you? See how Accorda helps NDIS providers stay audit-ready in one place at accorda.com.au.
Sources
NDIS Quality and Safeguards Commission (ndiscommission.gov.au): reportable incidents, notification timeframes, and incident management system guidance for registered providers.
National Disability Insurance Scheme Act 2013 and the NDIS (Incident Management and Reportable Incidents) Rules 2018.
Confirm current requirements, categories and timeframes directly with the NDIS Quality and Safeguards Commission before acting.
Disclaimer
This article is general information only, current as at July 2026, and is not legal or compliance advice. Regulatory requirements can change. Confirm your obligations with the NDIS Quality and Safeguards Commission.