NDIS 7-Year Records, Inducement Ban and New Fraud Offences: The 2026 Provider Obligations | CrossVault
← All Posts Compliance

NDIS 7-Year Records, Inducement Ban and New Fraud Offences: The 2026 Provider Obligations

CrossVault Team · · 9 min read

Most of the coverage of the Securing the NDIS for Future Generations Bill has been about participant funding. The half that providers most need to read got far less attention: a new record retention duty, a broad ban on inducements carrying a custodial penalty, a set of new criminal offences in the NDIS Act, and faster banning orders. We also cover the strengthened whistleblower framework, which is widely misattributed to this Bill but actually came from a separate Act that has been in force since April 2026. These land on every registered and unregistered provider, not just the ones the Fraud Fusion Taskforce is already looking at. This is what changes and what you need in place.

Seven years of records, with a civil penalty attached

Providers must keep records relating to the payment and receipt of NDIS funds for 7 years. Failure to retain them is a civil penalty. Participants and plan managers carry a shorter 3-year obligation.

The phrase doing the work is "relating to the payment and receipt of NDIS funds". Read broadly — and regulators do read it broadly — that reaches well past invoices:

  • Claims and claim reversals, including the reasoning behind any adjustment
  • Service agreements and variations
  • Rosters and timesheets, because they evidence that the claimed support was delivered, by whom, and for how long
  • Progress notes and service delivery records
  • Worker classification and pay records underpinning the cost base of the claim
  • Sub-contractor and labour-hire arrangements where someone else delivered the support you claimed for

Two practical traps. First, retention policies commonly set at 3, 5 or "7 years from end of engagement" now need checking against a 7-year floor measured from the transaction. Second, a record you cannot produce is functionally a record you did not keep — a 7-year retention policy sitting over a rostering system whose data export was decommissioned two vendors ago will not help you.

Audit your deletion schedules now, including automated ones. Cloud rostering and payroll platforms frequently purge on a rolling window by default.

The inducement ban

Providers cannot offer gifts to induce someone to use their service. Alcohol, tobacco, cash and cash-like products, and electronic devices are banned in all cases. The penalty is a fine, up to 2 years imprisonment, or both.

"Cash-like products" is the phrase that catches otherwise well-meaning providers. Gift cards are cash-like. So, on any sensible reading, are prepaid debit cards, vouchers redeemable for goods, and store credit.

Things worth reviewing before assent:

  • Referral incentives paid to support coordinators, plan managers or other providers
  • Welcome or sign-up gifts for new participants, including hampers and vouchers
  • Devices provided to participants — tablets or phones supplied outside a properly funded assistive technology item
  • Retention offers made when a participant signals they are moving to another provider
  • Staff referral bonuses where the referred party is a participant rather than a worker
  • Events and hospitality for referrers, particularly anything involving alcohol

This is not a reason to stop ordinary hospitality at a community event. It is a reason to write down where your line is, apply it consistently, and be able to show the policy existed before anyone asked.

New offences in the NDIS Act

The Bill inserts a tiered set of offences. The penalties reported for each:

  • Giving false or misleading information — up to 12 months imprisonment or 120 penalty units for an individual, rising to 5 years or 1,000 penalty units for a serious breach.
  • Obtaining funds by deception — the same tiering.
  • Impersonation — up to 5 years for an individual, up to 10 years or 2,000 penalty units for a serious breach.
  • Destroying records — up to 2 years imprisonment or 240 penalty units.

Note how the record destruction offence interacts with the 7-year retention duty. Together they mean that losing records is a civil penalty and disposing of them can be criminal. If a genuine data loss occurs — a failed migration, a ransomware event, a decommissioned system — document it contemporaneously, with dates and cause. The difference between an accident and an offence is evidence, and evidence assembled after the request arrives carries much less weight.

A Senate amendment also corrected the standard of proof for serious civil penalty breaches back to the balance of probabilities, having been drafted at the criminal standard. That makes serious civil penalties materially easier for the regulator to establish than the introduced Bill implied.

Faster banning orders and removed immunity

Two changes shorten the distance between a concern and a consequence.

Delegation of banning powers. Executive Level 2 NDIS Commission employees can now make and revoke banning and anti-promotion orders. Previously these sat higher in the delegation chain. The practical effect is throughput: expect more orders, made faster. If your organisation has ever operated on the assumption that a banning order takes months to materialise, revise it.

Immunity claims removed for document production. Providers can no longer resist document production on immunity grounds, which enables bodies including the Australian Criminal Intelligence Commission to pursue organised crime operating inside the scheme. The ACIC has publicly warned that organised crime groups have moved into the NDIS.

For a legitimate provider the meaningful consequence is that a notice to produce is now much harder to slow down. That puts a premium on records being retrievable in a usable form on short notice — which is the same capability the 7-year duty demands.

Whistleblower protections — a different Act, and worth getting right

Whistleblower protections are frequently attributed to this Bill. They are not in it. The strengthened framework came from the NDIS Amendment (Integrity and Safeguarding) Act 2026, which received Royal Assent on 8 April 2026, with the whistleblower provisions in Schedule 3 commencing 9 April 2026. They have been in force for months.

The framework is substantially aligned with the Aged Care Act whistleblower framework and, per legal commentary on the amendments, differs from the Corporations Act 2001. If your policy was drafted against a Corporations Act template, it is aligned to the wrong model.

What actually changed:

  • Anonymous disclosure is now available. The requirement for a whistleblower to give their name and to act in good faith has been removed.
  • Revealing a discloser’s identity is a civil penalty — 30 penalty units for unauthorised disclosure of the identity of a person who made a qualifying protected disclosure, or of information likely to lead to their identification.
  • Authorised exceptions are narrow: disclosure to the NDIS Commission, to law enforcement, to a legal practitioner, with the discloser’s consent, or where necessary to prevent a serious threat to safety.
  • The burden of proof reverses in civil penalty proceedings where someone has been harmed for making a protected disclosure. You have to show the detriment was not because of the disclosure.
  • “Detriment” is defined broadly — job loss, injury, changed duties, discrimination, harassment, psychological harm, and damage to property, reputation or finances.

The reversed burden of proof is the provision to brief managers on. Once a protected disclosure exists, any subsequent adverse treatment of that worker is something you have to affirmatively justify — which is very hard to do retrospectively if the performance concerns were never documented before the disclosure.

What to have in place: a policy aligned to the Aged Care Act model rather than a Corporations Act template; a disclosure route that accepts anonymous reports and bypasses the person a disclosure might concern; manager training on detriment and on the reversed burden; and a documented separation between any disclosure and subsequent performance management.

Debt recovery safeguards cut both ways

The Senate added notification requirements before recovery action: participants get 28 days to respond, providers get 14 days, and the low-value waiver threshold rises from $200 to $500.

Fourteen days is not long to reconstruct why a claim was made if the underlying roster, timesheet and progress note live in three systems that do not reconcile against each other. The safeguard only helps you if you can use the window.

The test worth running: pick a claim from eleven months ago at random and see how long it takes to produce the shift that backs it — the roster entry, the actual worked times, the worker, their classification, the applicable penalty or allowance, and the progress note. If that takes more than an hour, the 14-day window is a theoretical protection rather than a real one.

A 30-day action list

  1. Set retention to 7 years for everything touching payment and receipt of NDIS funds, and check automated purge settings in every rostering, payroll and document system you use.
  2. Verify retrievability, not just retention. Export a sample from your oldest retained period and confirm it is readable and complete.
  3. Write an inducements policy covering gifts, vouchers, devices, referral incentives and hospitality, and communicate it to anyone with a business development function.
  4. Update your whistleblower policy to the Aged Care Act–aligned model, not a Corporations Act template — anonymous disclosure accepted, identity protected, and managers briefed on the reversed burden of proof.
  5. Run the claim-reconstruction test above and fix whatever it exposes.
  6. Document any historical data loss that predates these obligations, with cause and date, while the people who remember it still work for you.
  7. Brief your board. Custodial penalties and faster banning orders change the risk profile enough to warrant a formal update.

Common Questions

Frequently Asked Questions

Do the 7-year record obligations apply to unregistered providers?
The obligation attaches to records relating to the payment and receipt of NDIS funds. If you receive NDIS funds, plan for the duty to apply. Separately, SIL providers previously operating unregistered — including those delivering to self-managed or plan-managed participants — have been required to register with the NDIS Quality and Safeguards Commission since 1 July 2026.
Are timesheets and rosters covered by the 7-year rule?
Treat them as covered. Rosters and timesheets are the records that evidence the support you claimed was actually delivered, by whom and for how long, which puts them squarely within records relating to the payment and receipt of NDIS funds. They also carry separate Fair Work record-keeping obligations, so there is no scenario in which discarding them early is safe.
Is a gift card to a participant now illegal?
If it is offered to induce someone to use your service, yes — cash and cash-like products are banned in all cases, and gift cards are cash-like. The penalty is a fine, up to 2 years imprisonment, or both. Write down where your line sits and apply it consistently before the Act commences.
What happens if we genuinely lost records in a system migration?
Document it contemporaneously — what was lost, when, and why. Failing to retain records is a civil penalty; destroying records is an offence carrying up to 2 years imprisonment or 240 penalty units. Evidence of an accidental cause, recorded at the time, is what separates the two. Evidence assembled after a regulator asks carries much less weight.
Can we still pay a referral fee to a support coordinator?
Review it carefully against the inducement ban and take your own advice. The ban targets giving something to induce a person to use your service, and it names cash and cash-like products as banned in all cases. Arrangements that route a payment to an intermediary in exchange for participant referrals are exactly the conduct the amendment was aimed at.
Did this Bill change NDIS whistleblower protections?
No, and this is commonly reported wrongly. The strengthened whistleblower framework came from the NDIS Amendment (Integrity and Safeguarding) Act 2026, which received Royal Assent on 8 April 2026, with the whistleblower provisions in Schedule 3 commencing 9 April 2026. That framework is substantially aligned with the Aged Care Act whistleblower framework and differs from the Corporations Act 2001. It removes the requirement to give your name or act in good faith, makes unauthorised disclosure of a discloser's identity a civil penalty of 30 penalty units, and reverses the burden of proof where someone suffers detriment after a protected disclosure.
When do these obligations start?
The Bill passed Parliament on 19 August 2026 and is awaiting Royal Assent. Commencement varies by measure and some provisions require supporting rules. Because retention, policy and systems work takes months, treat the obligations as effective now for planning purposes rather than waiting for a commencement date.

Make every claim reconstructable in minutes

CrossVault ties each shift to the SCHADS Award rate that applies and keeps the working — the evidence trail you need when a 14-day notice lands.