When something goes wrong, how do you know if it's reportable?
An incident happens on shift — a participant falls and needs stitches, a support worker discovers unexplained bruising, a behaviour support plan gets missed under pressure. Your team documents it, checks in with the participant, and moves on. But somewhere in that sequence sits a question with a hard deadline attached: does this incident need to go to the NDIS Quality and Safeguards Commission, and if so, how fast? Getting that judgement wrong — reporting late, under-reporting, or not recognising a reportable incident for what it is — turns a manageable safety event into a compliance problem. This guide sets out what actually counts as a reportable incident, the notification timeframes that apply, and what your record-keeping needs to look like so the decision is quick and defensible every time.
What counts as a reportable incident
Not every incident that happens during service delivery is a "reportable incident" in the legal sense. The category is defined under the National Disability Insurance Scheme (Incident Management and Reportable Incidents) Rules 2018, and the NDIS Commission's guidance on reportable incidents sets out the categories registered providers need to recognise:
- The death of a person with disability.
- Serious injury of a person with disability.
- Abuse or neglect of a person with disability.
- Unlawful sexual or physical contact with, or assault of, a person with disability.
- Sexual misconduct committed against, or in the presence of, a person with disability, including grooming for sexual activity.
- The use of a restrictive practice in relation to a person with disability, where that use is not in accordance with an authorisation or behaviour support plan.
The first five categories can involve a worker, another participant, a visitor, or an unknown party — the source doesn't change whether it's reportable, only how you investigate it. The sixth category, unauthorised restrictive practice, is specific to providers delivering behaviour support and is worth its own attention because the notification clock runs differently depending on whether the practice caused harm — more on that below.
It's worth being clear about what this scheme does not replace: your organisation's own incident management obligations apply to every incident, reportable or not. The reportable incidents scheme sits on top of your broader incident management system as the subset that must also go to the Commission.
The two notification timeframes: 24 hours and 5 business days
The Commission's guidance sets two distinct clocks, and mixing them up is one of the most common compliance failures providers run into:
- 24 hours. Death, serious injury, abuse or neglect, unlawful sexual or physical contact, and sexual misconduct must all be notified to the Commission within 24 hours of the registered provider becoming aware of the incident.
- 5 business days. The unauthorised use of a restrictive practice is notified within five business days of becoming aware — unless that use of the practice has resulted in harm to the participant, in which case it escalates to the 24-hour timeframe.
The trigger for both clocks is "becoming aware," not "confirming the facts." Providers sometimes hold off notifying while they investigate what actually happened, on the assumption that an incomplete picture isn't reportable yet. The Commission's expectation runs the other way: you notify promptly on what you know, and you can add detail as the picture develops. Waiting to be certain before you notify is one of the most avoidable ways a provider ends up outside the timeframe.
Notification itself happens through the Commission's guidance on notifying a reportable incident, which is submitted via the My NDIS Provider Portal. An initial notification captures what you know at the time; the Commission may then ask for a more detailed follow-up as your own investigation progresses. Treat the initial notification as the start of the process, not the whole of it — the Commission stays involved until it's satisfied the incident has been properly managed and, where relevant, that corrective action has actually happened.
Your incident management system: what the Commission expects in writing
Notifying on time depends on having a system that surfaces the incident to the right people fast — and that system itself is a registration condition, not just good practice. The Commission's incident management guidance and its detailed guidance for registered providers on incident management systems set out what registered providers need documented:
- How incidents — including near misses and non-reportable incidents — are identified, recorded, and escalated internally.
- How you support the person affected, including information about access to advocates and independent supports.
- How the affected person is involved in the management and resolution of the incident, consistent with their right to make decisions about their own life.
- How investigations are conducted to establish causes, effects, and any operational or systemic issues that contributed.
- How the Commission is notified, within which timeframes, and by whom.
The system needs to name responsibilities clearly: who identifies a reportable incident, who has authority to lodge the notification, and who follows up on outstanding actions. A policy that describes this well but that frontline staff have never been walked through is the most common gap — the paperwork exists, but nobody on shift at 2am is confident enough to act on it within the 24-hour window.
Record-keeping: what your incident register actually needs to show
Every incident — not only the ones that clear the reportable threshold — belongs in your incident register, because that register is what lets you show a pattern of practice rather than a series of one-off events. At minimum, a defensible entry captures: the date and time you became aware, a factual description of what happened, who was involved, the immediate action taken, whether it met a reportable incident category (and if so, which one and when it was notified), the investigation outcome, and the corrective actions taken as a result.
Two things separate a register that holds up under scrutiny from one that doesn't. First, it has to be a living document — incidents reviewed for trends, not just logged and left. Second, the register and your actual notifications to the Commission need to line up: if your register shows five reportable incidents in a quarter but only three notifications went through the portal, that gap is exactly what a documentation review is designed to find, and it's a harder conversation to have after the fact than a straightforward missed deadline would have been.
Where providers most often get this wrong
A handful of patterns show up again and again in providers who find themselves out of step with the scheme:
- Under-categorising. Treating a serious injury as a "minor incident" because the participant seemed okay afterwards, without applying the actual definition.
- Waiting for certainty. Delaying notification until an internal investigation is complete, rather than notifying promptly and adding detail later.
- Confusing the two clocks. Applying the 5-business-day timeframe to a restrictive practice incident that actually caused harm, when it should have escalated to 24 hours.
- A policy nobody has practised. Staff know an incident policy exists but haven't rehearsed who calls it, who lodges it, and how fast — so the first real reportable incident becomes a scramble instead of a routine.
- A register that doesn't match the portal. Internal records and Commission notifications drifting out of sync over time, usually because the register isn't reviewed as a whole, only entry by entry.
How Compliance Care helps
We help SIL and disability providers build genuine competence in incident management against the NDIS Practice Standards — clear written procedures, a register that actually functions as a living record, and staff who know what to do in the first hour of an incident, not just what the policy says. That's what an independent auditor is testing for, and it's also what actually keeps participants safer: a system that works under pressure, not just on paper.
If you're building or reviewing your incident management system, our SIL audit checklist is a practical starting point for checking your documentation against what's expected. Incident management sits alongside broader risk practice, and our risk assessment and management service is built to strengthen both together — because the same weaknesses that produce reportable incidents are usually visible in your risk registers well before they show up in a portal notification.
For the wider safeguarding and governance context that incident management sits inside, see our guides to participant safeguarding and governance frameworks that build a culture of compliance — incident management is only as strong as the governance and safeguarding structures around it.
Want an outside check on whether your incident management system and register would hold up under scrutiny? Book a discovery call and we'll help you find out.
Get NDIS compliance updates
Practical guidance on registration, audits and the 2027 wave. No spam, unsubscribe in one click.
