The NDIS Quality and Safeguards Commission has issued its first lifetime banning orders against a consultant and an auditor alleged to have colluded to register more than 200 providers on false or misleading information. On the back of the investigation, the Commission refused 195 registration applications and revoked a further 40. These are the first banning orders of their kind, because the power behind them is new.

What changed, and when. The banning orders were made on 17 June 2026, permanent and nationwide, and they are the first issued under new powers to ban auditors and consultants. Until the National Disability Insurance Scheme Amendment (Integrity and Safeguarding) Act 2026 (assented 8 April 2026), the Commission could ban only providers and workers. Closing that gap is the single most significant change here; the power itself, not the two individuals, is the story.

It is good to see the clean-up beginning, and the new power actually being used. But the two individuals are only the visible end of the problem. The matter raises a sharper question about the chain those registrations passed through, and about a structural feature of the NDIS model that made the conflict possible in the first place.

A provider shops for the auditor that judges it

Follow the money, because it explains the rest. NDIS registration is free, but a provider cannot register without passing an audit, and it must find, choose and pay the auditor itself. The Commission does not assign the auditor and does not set the price. Providers are told to get quotes and compare, and the commercial relationship runs directly between the provider and the auditor it hires.

Strip away the language and the design is this: the party being judged is the auditor's paying customer, and it gets to pick which auditor to hire. An auditor that fails too many clients loses them to one that does not. That is not a hypothetical bias, it is a commercial incentive wired into the structure. Every conformance industry built this way, from financial audit to building certification, has learned the same lesson the hard way.

The "independent" layer that was meant to fix this, and didn't

There is a check, and it is worth naming precisely so its failure is clear.

Auditors do not appoint themselves. They are accredited by JAS-ANZ (which runs the scheme on the Commission's behalf, monitors auditors, and holds them to the NDIS auditor guidelines and Code of Conduct), and then approved by the Commission itself. Two keys. Accreditation runs under the NDIS (Approved Quality Auditors Scheme) Guidelines 2018, which invoke ISO/IEC 17065:2012, the international standard whose entire purpose is the impartiality and independence of certification bodies.

So on paper the conflict is handled: an international impartiality standard, an accreditor and a regulator, all stacked on top of the provider-pays model.

On paper. In this matter, a consultant and an auditor allegedly colluded to push more than 200 providers through, and that accreditation-and-approval layer did not stop it. The registrations were caught after the fact, by investigation and banning order, not before, by the impartiality controls that were supposed to make it impossible. That is the uncomfortable finding: the safeguards did not prevent the harm; enforcement cleaned up afterwards.

And it was not the first warning. The sector has already seen an approved quality auditor sanctioned for selling consultancy to the very providers it was auditing: the exact conflict, in plain sight, inside an accredited body. One case is an outlier. A second, on the back of a 200-provider collusion, looks less like bad luck and more like a pattern the design invites.

Failed, or never tested?

So the question is blunt: did the impartiality controls fail, or were they never really exercised?

Either way, banning two people treats the symptom. The cause is a registration gate that lets the assessed party choose and pay its own assessor, policed by an accreditation layer that only moved once the damage was done. And there is no scale excuse. Just seventeen certification bodies audit the entire NDIS market at the time of writing, and the Commission is not currently accepting new applications to join them, approvals paused amid the integrity reforms now reshaping the scheme. A closed pool of seventeen makes the oversight question answerable, not impossible.

Aged care built it differently

Aged care avoided the core mistake. There is no finding your own auditor and no paying the person who grades you directly. It all runs through the Aged Care Quality and Safety Commission, which arranges the audit, supplies the assessor and stands between the provider and the decision. The commercial relationship that sits at the heart of the NDIS matter simply does not exist. That single structural difference is why the two schemes should not be spoken of in the same breath when independence is the subject.

Personal experience

I do not say this from the outside. I audit in the aged care and hospital sectors, and I have deliberately stayed out of NDIS auditing. Not because the work cannot be done with integrity (many do it conscientiously), but because a model that makes the provider the auditor's paying customer puts independence in tension with commercial survival from the very first engagement. I did not want my name on a certificate issued under that tension. That is a judgment about the design, not about the people working within it.

The discipline is the same wherever you audit. A certification system is only as good as the independence it can actually demonstrate: sampled, stress-tested, enforced. Not the independence it asserts on paper.

For providers, boards and the assurance bodies themselves, the question is the same on both sides of the fence: can you show that the independence in your certification chain was real, or only assumed?

Sources

Holistic Governance provides governance and compliance decision support for the aged care and disability sectors. This article is general commentary, not legal advice.