Guides4 min read

What counts as a reportable incident under the NDIS Practice Standards?

Not every incident has to go to the NDIS Commission. Here is the plain-English version of what does, what a provider decides internally, and where the line sits.

The Accorda Team · 28 September 2026

Every NDIS provider keeps an incident register. The harder question is which entries in it also have to go to the NDIS Quality and Safeguards Commission, and which ones a provider handles, records and closes out itself. Getting the answer wrong in either direction is a problem: under-report and an auditor asks why a serious event never left the building; over-report and every minor slip turns into a Commission matter. What follows is the plain-English version of where the line generally sits. The Commission's own rules set the exact categories and reporting windows, and those are the ones to confirm before you act on a real incident.

Reportable incidents are a defined category, not a judgement call

The starting point is that "reportable incident" is not a synonym for "serious incident" in the everyday sense. It is a defined category under the NDIS scheme, covering things like the death of a participant, serious injury, abuse or neglect of a participant, unlawful sexual or physical contact involving a participant, sexual misconduct, and the use of a restrictive practice that was not authorised in the participant's behaviour support plan. Some of these require notice to the Commission straight away; others allow a short window to gather the facts before the formal report goes in. Because the categories and the timeframes are set out in the Commission's rules and can be updated, confirm the current list and deadlines with the NDIS Commission before relying on this article for a live incident.

An incident that does not fall into one of the defined categories is still an incident. It still gets recorded, assessed, and followed up with corrective action if one is needed. It just does not go to the Commission as a formal notification. Most of what happens day to day in a service, a missed medication reminder, a minor complaint, a near-miss, sits in this internal category.

Why the decision has to be on the record, not just in someone's head

An auditor does not only look at whether the reportable incidents on file were actually reported. They also look at the incidents that were assessed as not reportable, and check whether that assessment holds up. If the register shows an injury with no note of who decided it was not reportable, or why, that is a finding regardless of whether the original decision was correct. The evidence an auditor wants is: what happened, who assessed it, what they decided about reportability, and what was done next.

That is a different problem from getting the decision right in the moment, and it is the one most services actually fail on. Under time pressure, the assessment happens in someone's head, in a phone call, or in a hallway conversation, and by the time anyone documents it, the reasoning is gone. A defensible register captures the decision at the time it was made, with a name attached.

What a solid process looks like in practice

A few habits make the reportable-incident decision defensible rather than a guess reconstructed after the fact:

  • Capture the incident immediately, in plain words, ideally by the person who witnessed or was told about it, on whatever device is in their hand at the time. A report written a week later, from memory, is weaker evidence than three sentences typed on the day.
  • Record the reportable assessment as its own step, with who made the call and when, separate from the narrative of what happened. This is the field an auditor looks for first.
  • Track corrective actions to close-out, not just to "assessed." A reportable incident and a completed corrective action are two different milestones, and a register that only shows the first is only half done.
  • Keep the complaints and risk registers next to the incident register. The same event sometimes shows up in more than one place, from a participant complaint about the same episode to a risk that the incident exposed. An auditor expects to see the connection, not three unrelated entries.

None of this replaces the judgement call about whether a specific incident meets the Commission's definition. That call still needs someone who knows the current rules, and for anything ambiguous, the Commission's own guidance or a call to them is the right next step.

Where Accorda fits

Accorda's incident management records the incident on a phone in plain words, captures the reportable decision and who made it as its own field on the record, and tracks corrective actions through to close-out rather than leaving them open. Complaints and risk sit in the same system, through the complaints and risk registers, so a related entry is a link away rather than a separate search. For SIL providers moving into mandatory registration, an incident register with the reportable decision already on file is one of the first things an auditor checks.

If you are not sure how your current register would look to an auditor, the free Compliance Readiness Check gives a readiness band across nine compliance domains, including incident management, in about four minutes. For the reportable-incident categories and timeframes themselves, the NDIS Commission's website is the current source; confirm anything time-sensitive with them directly rather than from this or any other secondary account.

Start today

See your compliance audit-ready in one place

Try Accorda free for 14 days. Every feature, no credit card, no auto-charge.