SecureLoop
NDIS Compliance10 min read

NDIS Billing Compliance in 2026: What Plan Managers Need to Know

The NDIA has stopped automatic payments for claims from almost 1,000 plan managers — those claims are now manually reviewed before payment is released. Around 20,000 high-risk claims are reviewed across the scheme each month. The Commission is tightening documentation expectations for everyone in the billing chain. This is what you need to have in place.

SL
SecureLoop Team
··Figures verified 23 July 2026
Key takeaway

Billing compliance for NDIS plan managers has shifted from “have a fraud policy” to “demonstrate active, documented monitoring controls.” The Commission expects evidence that you are proactively detecting billing anomalies — not just processing invoices accurately.

Plan managers are already under direct scrutiny

This is not a hypothetical future risk. Under the NDIA’s Crack Down on Fraud program, automatic payments have been stopped for claims from almost 1,000 plan managers. Those claims are now manually reviewed for compliance against participant plans before the plan manager is paid.

Across the scheme more broadly, the NDIA reviews around 20,000 high-risk claims each month. System enhancements have allowed the Agency to identify more than 2,100 providers with problematic claiming behaviours, none of whom can be paid without a Manual Payment Review on every claim.

If your claims are being manually reviewed, payment timing becomes unpredictable and every submission is scrutinised. If they are not, the systems that flagged those other plan managers are still running against your data. The broader 2026 enforcement picture covers where this sits alongside Fraud Fusion Taskforce activity.

What the Commission expects from plan managers

Plan managers sit at the centre of NDIS financial flows. You receive invoices from providers, validate them against participant plans, submit claims to the NDIA portal, and release payments. Every one of those steps is a potential point where billing anomalies can enter the system.

The Commission’s expectations go beyond processing invoices accurately. They expect documented evidence that you are actively monitoring for anomalies — not just checking that an invoice matches a line item in a plan, but looking for patterns across your entire portfolio that individual invoice checks would not surface.

This includes monitoring for duplicate billing across different invoices, periods, or providers; unusual claim patterns such as after-hours billing, volume spikes, or services not in the support plan; provider bank account changes before scheduled payments; and spend acceleration against approved plan budgets. Each of these is covered in more detail in our NDIS fraud detection guide.

Why manual checks fall short

A plan manager processing invoices manually — even with a careful, experienced team — is reviewing a sample. You check the invoices that look unusual, the ones from new providers, the ones with round numbers. What you cannot do is review every transaction against every historical baseline for every participant.

The structural problem is that sampling only finds anomalies in the sample. Everything outside it goes undetected until a Commission review surfaces it, or until a participant’s plan funds run out unexpectedly and someone asks why.

The gap is not negligence. It is volume. A plan manager handling 200 participants might process thousands of invoices per month. Each needs validating not just against the plan, but against the participant’s historical spending pattern, the provider’s billing history, and the expected delivery schedule. That is a pattern-matching problem that scales beyond what a human team can do by hand.

The Australian National Audit Office made a related finding about the NDIA’s own controls — that manual pre-payment reviews covered a small proportion of outlays while detecting high levels of non-compliance within that sample. Low coverage with a high hit rate is exactly the signature of a sampling problem.

What automated monitoring adds

Automated fraud detection establishes a baseline for each participant and provider in your portfolio, then scores every incoming transaction against that baseline in real time.

When an invoice arrives that deviates from the pattern — a provider billing for after-hours support that does not match rostered shifts, a duplicate claim spanning two invoicing periods, a support item not in the participant’s current plan — the system flags it with a risk score and the context needed to make a decision.

Your team still makes the call. The system does not block payments or reject invoices. It surfaces the transactions that warrant human review and provides the historical comparison that makes the review meaningful.

Every flag, decision, and resolution is logged with timestamps and full context. That audit trail is the documentation the Commission looks for when assessing financial management practices.

What this means for your compliance position

When the Commission reviews a plan manager’s financial management practices, it is looking for two things: evidence that you have systems in place to detect billing anomalies, and documentation of how flagged transactions were handled.

A plan manager who can show that every transaction is monitored against historical baselines, that anomalies are flagged and reviewed, and that decisions are documented in an audit trail is in a fundamentally different position to one relying on sample checks.

This is not about catching fraud in your portfolio specifically. It is about demonstrating that you have the systems that would catch it if it existed. That distinction matters when the Commission comes asking.

Practical next steps

The first step is understanding your current exposure. If you are processing invoices through Xero, MYOB, or QuickBooks, the transaction data needed for automated monitoring already exists in your accounting system. Monitoring connects to your existing data — it does not require a new platform or a migration.

Implementation typically takes 5–8 business days. Setup includes connecting to your accounting system, configuring participant and provider baselines, setting alert thresholds, and testing against your actual transaction data. The system uses read-only access — it monitors transactions but cannot execute payments.

Before committing to any fraud detection investment, it is worth checking whether your own Microsoft 365 environment is secure. If your email and file storage are compromised, your billing data and participant information are exposed regardless of what monitoring you have in place. A free M365 security check takes 2 minutes and gives you a personalised risk score.

Frequently asked questions

Are NDIS plan managers required to have fraud detection systems in 2026?

There is no explicit legislative mandate requiring AI-powered fraud detection for plan managers. However, the Commission expects documented evidence of proactive billing monitoring as part of financial management practices. Plan managers who rely solely on manual invoice checks face higher compliance risk during Commission reviews.

Why has the NDIA stopped automatic payments for some plan managers?

Under the Crack Down on Fraud program, automatic payments have been stopped for claims from almost 1,000 plan managers so those claims can be manually reviewed against participant plans before payment. Around 20,000 high-risk claims are reviewed each month across the scheme.

What types of billing anomalies can automated monitoring detect that manual checks miss?

Duplicate billing across different invoicing periods, after-hours claims that do not match rostered shifts, spend acceleration against plan budgets, provider bank account changes before payment runs, and volume spikes against historical baselines. The difference is coverage — every transaction is scored rather than a subset reviewed.

What accounting systems does NDIS fraud detection connect to?

Xero, MYOB, QuickBooks, and NDIS plan management software including Brevity, SupportAbility, and ShiftCare. Read-only access is used for monitoring — the system cannot execute payments.

How long does NDIS fraud detection take to set up?

Most implementations are live within 5–8 business days. Setup includes connecting to your accounting system, configuring baselines, setting alert thresholds, and testing against actual transaction data. Fixed price from $2,800.

About these figures

Enforcement and program statistics in this article are drawn from NDIA and Australian National Audit Office publications and were verified on 23 July 2026. Compliance requirements change — confirm your obligations directly with the NDIS Quality and Safeguards Commission. This article is general information, not legal or compliance advice.

NDIS billing complianceNDIS plan managerfraud detectionNDIS Commissionmanual payment reviewinvoice monitoring

Want to strengthen your compliance position?

SecureLoop builds NDIS fraud detection for plan managers. Connects to Xero or MYOB, monitors every transaction, and maintains the audit trail the Commission requires. Fixed price from $2,800.