TL;DR: Most business software is built around transactions: a shift filled, a ticket closed, a file saved. NDIS obligations are built around conditions that must stay true over time, such as a worker in a risk-assessed role holding a current screening clearance on the day of every shift. Generic tools record the transactions accurately and have no concept of the conditions, so the gaps an auditor finds tend to sit between tools rather than inside any one of them. That mismatch is the case for R-comm, or regulated commerce: software designed around the rulebook, not adapted to it afterwards.
E-commerce did not take off because shops found better spreadsheets. It took off when software was built around how selling online actually works, so that a sale, a stock count and a shipment were one connected event instead of three records in three places.
Regulated industries are still at the spreadsheet stage. An NDIS provider can buy good rostering software, a good HR system, a good document store and a good ticketing tool, configure each one well, and still have no system that can say whether the organisation is meeting its obligations today. This article is about why, using the obligations NDIS providers carry right now.
Why does general business software struggle with NDIS obligations?
Because it models what happened, and NDIS obligations are about what must stay true.
A rostering tool knows that a worker is available, qualified in the tool's own terms, and assigned to a shift. An HR system knows the expiry date of that worker's screening clearance. Both facts are accurate. The obligation, though, is a condition that joins them: the NDIS Commission states that registered providers "are responsible for identifying and keeping records of their risk-assessed roles", and that people in those roles need an NDIS worker screening clearance (NDIS Commission, Worker screening for providers).
"Risk-assessed role" is an NDIS concept. A general rostering product has no field for it, no rule that checks it at the moment of assignment, and no reason to look at the HR record at all. The obligation lives in the gap between two products that each work as designed.
Where does the mismatch show up in day-to-day operations?
Almost everywhere a regulatory clock or condition touches a routine process. Four examples a registered provider will recognise:
Incident reporting runs on a regulatory clock
A general ticketing or incident tool tracks status: open, assigned, resolved. NDIS reportable incidents run on deadlines set by the regulator. Serious injury, abuse or neglect, and unlawful contact with a person with disability must be notified to the NDIS Commission within 24 hours, with further information due within five business days (NDIS Commission, Reportable incidents). A ticket that sits in "assigned" for a day looks ordinary in a generic tool. Under the rules, it may already be a late notification.
Record keeping now runs for seven years
Under the new NDIS laws, providers must keep records of supports and payments for seven years, the longest retention period of anyone in the scheme (NDIS, Securing the NDIS for future generations). Most document platforms have a retention setting. None of them knows which of your files are "records of supports and payments", which participants have left, or that the clock for a departed worker's shift notes is still running.
Claims will run on a 90-day window
From December 2026, claims must be submitted within 90 days of delivering a support, according to the NDIA's provider timeline for the new laws. Finance software can report on unbilled work. It does not know that an unbilled support becomes unclaimable on a fixed date, or which service records need to be complete before the claim can go in.
Practice Standards apply across every tool at once
The NDIS Practice Standards core module sets out 24 outcomes across four parts, and the quality indicators under each are what auditors use to assess compliance (NDIS Commission, NDIS Practice Standards). A single indicator can depend on HR data, roster data, participant records and a policy document together. No general product owns an indicator, so in practice no product checks one.
Why don't spreadsheets fill the gap?
They do fill it, which is the problem. The spreadsheet is where most providers join their systems together, usually maintained by one quality or compliance manager.
That works until one of three things happens: the organisation grows, the person leaves, or the rules change. All three are common in the sector right now. The Australian National Audit Office recorded that the total number of active NDIS providers grew 25 per cent between 2023 to 2024 and 2024 to 2025 (ANAO, Effectiveness of the NDIS Quality and Safeguards Commission's Regulatory Functions, 3 September 2025). Two sets of NDIS laws have passed in 2026, the Integrity and Safeguarding amendments in April (NDIS Commission media release, 3 April 2026) and the Securing the NDIS for Future Generations amendments in August, with changes staged through to July 2028.
The spreadsheet also has a cost that rarely gets counted. National Disability Services reported in its State of the Disability Sector Report 2025 that close to half of providers recorded a financial loss, and that 77 per cent delivered unfunded services at an average cost of almost $500,000 per provider. Hours spent reconciling systems by hand come out of the same stretched budget.
What would software built for the rulebook do differently?
It would start from the obligation and work back to the data, instead of starting from the data and hoping the obligation is covered.
In the NDIS context, that means a system that:
- Knows which obligations apply to your organisation, based on your registration groups, the supports you deliver and the modules you are audited against.
- Holds the conditions, not only the records. A worker assigned to a risk-assessed role is checked against screening and training at the time of the shift, not at the next audit.
- Runs the regulatory clocks. Incident notification windows, plan review dates, authorisation expiries and claim deadlines are tracked as deadlines with owners.
- Reads across existing tools rather than replacing them, because the data it needs already sits in the rostering, HR and care management systems a provider runs.
That is the R-comm argument in one sentence: regulated businesses need software whose starting point is the regulation. E-commerce software started from the sale. General business software starts from the transaction. For a regulated provider, the transaction is only half the picture.
Where does Audit Pilot fit?
Audit Pilot is building R-comm software for NDIS providers. It connects to a provider's existing systems, monitors operations against NDIS obligations on an ongoing basis, and identifies compliance gaps so they can be resolved before they become audit findings.
It does not replace rostering, HR or care management software, and it cannot guarantee an audit result. Audit findings are made by approved quality auditors under the NDIS Commission's oversight. What it changes is whether the gaps between your tools are being watched.
Providers who want to see this against their own systems can book a demo.
What can a provider check this week with the tools they already have?
- List your risk-assessed roles, then check last month's roster against them. For every shift in those roles, confirm the worker's screening clearance was current on that date. Note how many systems you had to open.
- Time your last five reportable incidents. Measure from the moment a worker became aware to the moment the Commission was notified. The ticket's "created" date is not the same thing.
- Test your retention path. Ask for the support records and payment records of a participant who left in 2021. If they take more than a day to produce, seven years of retention will be hard to demonstrate.
- Find your oldest unbilled support. With the 90-day claim window starting in December 2026, know how far back your backlog goes today.
For the regulatory detail, see our guides to what the new NDIS laws mean for providers and what happens during a compulsory NDIS audit.
Key Takeaways
- General software models transactions. NDIS obligations are conditions. A shift, a ticket and a file can all be recorded correctly while the obligation joining them is unmet.
- The gaps sit between tools. Screening against rosters, incident clocks against ticket status, retention against document settings.
- New deadlines add to the load. Seven-year record keeping applies now, and a 90-day claim window starts in December 2026.
- Spreadsheets hold it together until growth, staff turnover or rule changes break it, all of which are common in the sector in 2026.
- R-comm software starts from the regulation and reads across existing systems, but no software can guarantee an audit outcome.
Sources
- NDIS Quality and Safeguards Commission, Worker screening for providers
- NDIS Quality and Safeguards Commission, Reportable incidents
- NDIS Quality and Safeguards Commission, NDIS Practice Standards
- National Disability Insurance Scheme, Securing the NDIS for future generations
- NDIS Quality and Safeguards Commission, Regulator welcomes new powers to strengthen NDIS integrity and safeguards, 3 April 2026
- Australian National Audit Office, Effectiveness of the NDIS Quality and Safeguards Commission's Regulatory Functions, 3 September 2025
- National Disability Services, State of the Disability Sector Report 2025
Disclaimer: This article provides general information about NDIS compliance obligations and is not intended as legal, regulatory or financial advice. NDIS rules, standards and timeframes change regularly. Always check the official source before acting, and seek professional advice for your own situation.
Information current as at 25 September 2026.