Incidents & safeguarding
How to Write an NDIS Incident Management Policy (2026 Template + Example)
An NDIS incident management policy must document how your organisation identifies, records, responds to, and reports incidents — including reportable incidents to the NDIS Commission. Under the NDIS (Incident Management and Reportable Incidents) Rules 2018 and the Practice Standards, registered providers need a written system, clear staff roles, and defined timeframes before an auditor will be satisfied.
Why your incident management policy matters more than ever in 2026
The NDIS Commission's strengthened Practice Standards and the 2024–2026 registration model changes place heavier emphasis on demonstrable, operational risk governance. An auditor reviewing a Supported Independent Living (SIL) or similar high-intensity support provider will not simply ask whether you have a policy — they will trace whether staff know it, whether records match it, and whether improvements loop back into it.
This article gives you a practical structure for writing or upgrading your incident management policy, grounded in the NDIS Commission's incident management obligations and the NDIS Practice Standards. It is general information, not legal or compliance advice. Always verify current requirements with the Commission directly.
What the NDIS Practice Standards require
The NDIS Practice Standards (Core Module — Rights and Responsibilities) require registered NDIS providers to have a documented incident management system. The key obligations, drawn from the NDIS (Incident Management and Reportable Incidents) Rules 2018, are:
- Maintain a written incident management system that includes policies and procedures.
- Record all incidents, including near misses, whether or not they are reportable to the Commission.
- Notify the NDIS Commission of reportable incidents within defined timeframes (see below).
- Ensure participants can report incidents without fear of retribution.
- Investigate incidents and take corrective action.
- Review the system regularly and use incident data to drive continuous improvement.
The Practice Standards also connect incident management to Outcome 1.7 (Responsive Support Provision) and the high-intensity daily activities module for SIL providers. Auditors cross-reference incident records against support plans and progress notes.
What counts as a reportable incident
Under the Rules, a reportable incident is one that occurs in connection with providing NDIS supports and falls into defined categories, including:
- The death of a person with disability.
- Serious injury of a person with disability.
- Abuse or neglect of a person with disability.
- Unlawful sexual or physical contact with, or assault of, a person with disability.
- Sexual misconduct committed against, or in the presence of, a person with disability.
- Use of a restrictive practice not authorised under a behaviour support plan (or where no plan exists).
Your policy must define each of these categories in plain language so frontline workers can identify them immediately. Do not leave definitions implicit.
Notification timeframes at a glance
| Incident type | Initial notification to Commission | Full written report |
|---|---|---|
| Death of a participant | As soon as practicable, within 24 hours | Within 5 business days |
| Serious injury, abuse, assault, or sexual misconduct | As soon as practicable, within 24 hours | Within 5 business days |
| Unauthorised restrictive practice | As soon as practicable, within 5 business days | Within 5 business days |
Note: Always confirm current timeframes on the NDIS Commission reportable incidents page, as these may be subject to regulatory updates.
The eight sections every policy needs
A policy that satisfies both an audit and day-to-day operations should include the following sections.
1. Purpose and scope
State plainly what the policy covers (all supports delivered, all worksites, all staff and contractors), which legislation it is anchored in, and who it applies to.
2. Definitions
Define "incident," "near miss," "reportable incident," and each reportable incident category. Use the Commission's language, then add a one-sentence plain-English translation. Avoid jargon that a new support worker might not recognise.
3. Roles and responsibilities
Assign named roles, not just job titles in the abstract:
- Support worker — identifies, responds to, and records the incident at the time.
- Team leader / rostered supervisor — reviews the record within 24 hours, determines reportability, escalates to management.
- Compliance officer / manager — submits the Commission notification, manages the investigation.
- CEO / authorised officer — signs off on systemic responses; accountable for Commission engagement.
4. Incident reporting procedure (step by step)
Walk through the exact sequence a worker follows from the moment an incident occurs through to Commission notification. Flowcharts help here. State what form or system to use, where records are stored, and who to call out of hours.
5. Investigation process
Describe how investigations are conducted, by whom, within what timeframe, and what the minimum investigation outputs are (root-cause analysis, corrective action plan, evidence file). Note when an independent investigator is required (for example, where a staff member is implicated).
6. Participant rights and safety
Confirm participants can report incidents directly to the Commission at any time via the Commission's complaints and incident line. State how you protect participants and whistleblowing staff from retribution.
7. Record keeping
State the minimum data captured for every incident (date, time, location, people involved, description, immediate response, notification status) and how long records are retained. The Commission recommends records be retained for at least seven years; verify your state obligations as they may be longer.
8. Review and continuous improvement
Describe how incident data is aggregated, how patterns are identified (at a minimum, quarterly review), and how findings feed into staff training, risk registers, and support plan reviews. An auditor will ask to see your last review meeting minutes.
Worked example: an internal incident record entry
The following is an illustrative example of a non-reportable internal incident record entry to show the level of detail expected.
Date/time: 12 June 2026, 09:15
Location: 14 Acacia Street, Brunswick (SIL house)
Participant: [Identifier code — names in separate file per privacy procedure]
Description: Participant slipped on wet bathroom floor while transferring to shower chair. Support worker present. No injury sustained. Participant was shaken; offered reassurance and a warm drink.
Immediate response: Area made safe. Incident supervisor notified at 09:20. Participant's key worker informed. Incident reviewed with participant at 09:45; participant confirmed they did not want a GP visit.
Reportable incident? No — no injury sustained. Classification reviewed by team leader and agreed.
Corrective action: Non-slip mat ordered for bathroom. Risk register updated. Reviewed at next team meeting (scheduled 17 June 2026).
Recorded by: [Worker code], cosigned by Team Leader [TL code] at 10:30.
What an auditor specifically looks for
When an NDIS auditor reviews incident management under the Practice Standards, they typically check:
- Does the policy document match what staff actually do? (They will interview workers.)
- Are all incidents recorded, including near misses and low-severity events?
- Are reportable incidents flagged and notified within the required timeframes?
- Are investigations completed and corrective actions implemented — not just documented?
- Is there evidence the system drove a practice change? (Meeting minutes, updated procedures, training records.)
- Can participants describe how to report an incident, and do they know their rights?
A policy that looks complete on paper but has no matching records, no staff awareness, and no evidence of improvement will not pass a mid-term or renewal audit.
Get your SIL documentation audit-ready
If you are preparing for registration renewal or a new SIL registration under the 2026 model, incident management is one of the first documents a Commission auditor will request. Our free SIL Readiness Pack is a plain-English checklist of what the Commission expects across all Core and SIL module requirements — including incident management, behaviour support, and the high-intensity daily activities evidence trail. Download it to see exactly where your documentation stands before an auditor does.
This article provides general information for NDIS registered providers. It is not legal advice. Requirements may change; always verify with the NDIS Quality and Safeguards Commission and seek independent legal or compliance counsel for your specific circumstances.
Important: This article provides general guidance about NDIS compliance requirements. It is not legal or professional advice. Requirements may change as the NDIS Commission updates its policies and Practice Standards. Always verify current requirements with the NDIS Quality and Safeguards Commission or a registered NDIS consultant before making compliance decisions.
Frequently asked questions
Does every NDIS provider need an incident management policy, or only those with registration?
Only registered NDIS providers are legally required to have a documented incident management system under the NDIS (Incident Management and Reportable Incidents) Rules 2018. However, all providers — registered or not — must notify the Commission of certain serious incidents involving NDIS participants. The Practice Standards audited during registration require a written system, defined roles, and evidence of use.
What happens if we don't notify the NDIS Commission of a reportable incident on time?
Failure to notify the Commission within the required timeframes can constitute a breach of your conditions of registration. The Commission can issue compliance notices, require an audit, impose conditions on your registration, or — in serious cases — suspend or revoke registration. There is no formal 'grace period'; the obligation begins as soon as the provider becomes aware the incident is reportable.
Can we use an off-the-shelf incident management policy template?
A template is a useful starting point, but it must be customised to your organisation's size, support types, staffing structure, and the specific supports you are registered to deliver. An auditor will ask staff to describe how the policy works in practice — if workers reference a procedure that does not match your template, that is a finding. The policy also needs to reference your actual reporting system (paper form, digital platform, or other), your specific escalation contacts, and your real investigation process.
Keep reading
- How to write an NDIS incident management policy (2026 template + example)
- NDIS Incident Management Policy Template: Free vs Paid vs Consultant (2026)
- Common Mistakes in an NDIS Incident Management Policy
- Do you need an NDIS incident management policy? Provider requirements
- NDIS Incident Management Policy Checklist for New Providers
Free: the SIL Readiness Pack
A checklist and a sample policy page, sent as a download. No sequence.