A new parliamentary inquiry has examined fraud, non-compliance and sharp practices in the NDIS. Here is what the report found and what it means for providers going forward.
Background
In March 2026, the Joint Standing Committee on the National Disability Insurance Scheme agreed to self-refer an inquiry into the integrity of the NDIS, following a recommendation from the Minister for the NDIS. The inquiry examined the nature and extent of non-compliance, fraud and sharp practices in the Scheme, the impact of this behaviour on participants and their families, and what legislative or other reforms might be needed to strengthen Scheme integrity.
The committee received 97 submissions and held three public hearings in Canberra, Sydney and Melbourne. Evidence was heard from participants, families, advocates, providers, workers, peak bodies, regulators and government agencies, including a joint submission from the Department of Health, Disability and Ageing, the National Disability Insurance Agency (NDIA) and the NDIS Quality and Safeguards Commission (NDIS Commission).
The inquiry sits within a broader period of reform. Since 2022, the Scheme has moved from a largely compliance-based approach to a more coordinated, intelligence-led response to fraud, including through the establishment of the Fraud Fusion Taskforce. The NDIS Amendment (Integrity and Safeguarding) Act 2026 passed parliament in April 2026, and the National Disability Insurance Scheme Amendment (Securing the NDIS for Future Generations) Bill 2026 was introduced concurrently with the inquiry, proposing further changes to fraud controls and provider regulation.
The committee's report was tabled with 12 recommendations. It is worth noting that the report includes additional comments from Coalition members and from the Australian Greens, both of whom raised concerns that the majority recommendations do not go far enough in different respects. Providers should be aware that further legislative change in this space is likely as these perspectives are considered by government.
Key Findings
The committee's report painted a picture of a Scheme under increasing strain from fraud, non-compliance and sharp practices, with risks that have grown more organised over time.
The NDIA does not measure fraud directly, but instead tracks a broader "integrity leakage" figure covering everything from administrative errors to deliberate fraud, currently estimated at 8.2 to 8.3 per cent of Scheme payments, or around $3.7 billion a year. Evidence to the committee, including from the Australian Criminal Intelligence Commission, suggested this leakage increasingly reflects organised and coordinated exploitation rather than isolated misconduct, including cases where small inducements or profit-sharing arrangements were used to gain access to a participant's plan.
Registration remains a key gap: a high percentage of providers in the NDIS market are unregistered, creating what several submitters described as a "two-tiered" market with uneven oversight. The plan management sector was also flagged as high-risk, with over 90 per cent of the smallest 1,000 plan managers carrying fraud risk indicators. In response, from 1 July 2026, providers delivering supports that meet the new definition of supported independent living, and providers operating defined NDIS digital platform services, are subject to mandatory registration requirements. Mandatory registration of support coordination has been paused while further reform is considered.
Significant improvements have already been made to payment systems since 2022, including payment holds, bulk claim review, and stronger evidence requirements, contributing to $3.4 billion in combined savings and redirected funds. The Securing the NDIS for Future Generations Bill proposes reducing the claim-submission period from two years to 90 days from 1 December 2026. As at 15 July 2026, the current two-year claim period remained in force, and the proposed 90-day limit had not yet become law.
Beyond the financial picture, the committee heard evidence of real harm to participants, including plan depletion, exposure to unqualified workers, coercive control and psychological distress, with these risks often compounded in thin markets, regional and remote areas, and First Nations communities.
What This Means for Providers
The direction of travel is clear: registration requirements are expanding, oversight of plan managers and support coordinators is tightening, information sharing between regulators is increasing, and penalties for serious misconduct are becoming more severe. Providers should treat the following as priorities:
- Determine whether the new mandatory-registration rules apply. If your organisation delivers SIL or operates a digital platform, determine whether the new mandatory-registration definitions apply and follow the relevant transition pathway. Providers of other supports should monitor further registration reforms and should not assume that every personal-care or daily-living service is already subject to mandatory registration. Begin preparing for NDIS Practice Standards compliance and suitability assessments now rather than waiting for your registration category to come into scope.
- Review your conflict-of-interest arrangements. Where your organisation provides plan management, support coordination, and direct service delivery, or where family or personal relationships intersect with service delivery arrangements, ensure these are clearly documented, disclosed and managed. The government has flagged that a formal conflict-of-interest framework is likely to be introduced.
- Strengthen record-keeping now. The National Disability Insurance Scheme Amendment (Securing the NDIS for Future Generations) Bill proposes a statutory obligation to retain records relating to claims and support delivery for a minimum period. Providers should ensure invoicing practices include clear descriptions, accurate hours, and verifiable evidence of service delivery, rather than relying on the current informal approach. For clinical, high-intensity and behaviour-support services, documentation should also record relevant assessment findings, consent, risks, clinical instructions, support provided, participant response, changes in condition, escalation actions, incidents and communication with relevant health practitioners.
- Prepare for identity verification requirements. Confirm the digital identity and authorisation requirements that apply to staff accessing NDIA or NDIS Commission systems on the organisation’s behalf. This may include myID and Relationship Authorisation Manager arrangements, depending on the portal and the person’s role. Ensure your organisation's authorised representatives are ready to complete this verification.
- Review service agreements. The NDIA's Service Agreements Improvement Project identified widespread problems, including rushed sign-up processes, overly complex language, generic templates, and unclear cancellation terms. Providers should review their service agreements against these findings, ensuring they are written in plain language, individually tailored, and clearly explain fees and cancellation terms.
- Monitor the proposed national worker registration scheme. The committee has recommended a national NDIS worker registration scheme focused on entry-level prerequisites, qualifications and ongoing professional development. Providers, particularly those employing entry-level or unregulated support workers, should begin considering how their workforce will meet these emerging requirements, noting that professional registration (for example, through AHPRA) may be recognised to avoid duplication. For high-intensity and clinical supports, providers should verify role-specific competence through training, observed practice, assessment, supervision and periodic reassessment. A qualification or completed online module alone may not demonstrate competence to safely support a particular participant.
- Expect closer scrutiny of pricing and claiming patterns. With enhanced data analytics, digital identity, and payment holds now embedded in NDIA systems, claiming patterns that were not previously visible are increasingly being detected. Providers should proactively review their own claiming practices for consistency, accuracy, and alignment with participants' plans.
- Be alert to the changing whistleblower landscape. Review complaint, incident and protected-disclosure arrangements. The Integrity and Safeguarding reforms broadened aspects of the NDIS protected-disclosure framework, while the committee recommended further consideration of alignment with Corporations Act protections. Providers should ensure staff, former staff, contractors, participants and families can raise concerns safely, including anonymously where available, and that allegations are triaged without retaliation.
- Monitor for signs of exploitation and coercive control. Providers should train workers to identify unexplained plan depletion, sudden provider changes, pressure to approve claims, inducements, restricted access to statements, unauthorised use of participant information, control by family members or intermediaries, and services that do not match the participant’s observed needs or preferences.
- Strengthen governing-body oversight. Boards and key personnel should receive regular information on complaints, incidents, reportable incidents, restrictive practices, worker screening, conflicts of interest, claim anomalies, participant outcomes and corrective actions. Serious or systemic concerns should be escalated promptly rather than managed solely as billing discrepancies.
- Conduct an integrity and safeguarding readiness review. Map each service your organisation delivers against current registration requirements, the NDIS Code of Conduct, applicable Practice Standards and announced reforms. Review participant service agreements, conflicts of interest, worker competence, digital access, claim evidence, clinical documentation, complaints, incidents, restrictive practices and continuity-of-support arrangements. Record identified gaps, assign accountable owners and report progress to the governing body.
Conclusion
Taken together, the report signals a continuing shift toward broader market visibility, more active regulatory oversight and stronger evidence requirements across both registered and unregistered providers. The direction of reform is consistent across every area examined by the committee: greater visibility of who is operating in the market, stronger evidence behind every claim, clearer accountability where conflicts of interest arise, and less tolerance for providers who cannot demonstrate that the supports they are funded for are actually being delivered.
The reforms are being driven by consistent, serious evidence of harm to participants, from plan depletion and coercive control to exposure to unqualified workers, and by a Scheme-wide recognition that fraud and non-compliance are not victimless. Providers who treat these obligations as central to how they operate, rather than as an administrative burden layered on top of service delivery, will be better placed to withstand the scrutiny that is coming and to build trust with participants, families and regulators alike.
About the Authors
Nicole is a Principal Consultant at Ideagen CompliSpace with a background in the healthcare industry across acute, aged and community services. Throughout her career, she has held various management and clinical positions, contributing significantly to both research and higher education within the sector. Nicole provides valuable knowledge and insights from both a clinical perspective and a nuanced understanding of the operational and strategic aspects of healthcare. She holds a Bachelor in Nursing, a Postgraduate Certificate and a Doctor of Philosophy (PhD).
Nick is a Legal Content Senior Associate at Ideagen CompliSpace. Nick has several years' experience designing and administering eLearning for the Aged Care Sector and holds a Bachelor of Laws from the University of Technology Sydney with First Class Honours.