Buyer's guide · Updated July 2026
NDIS compliance software: an honest buyer's guide
Three different kinds of product are sold as "NDIS software", and most buyers do not realise they are comparing across categories. Operations platforms run the business: rostering, billing, claiming, client records. Compliance monitoring tools watch obligations and flag gaps before an audit. Custom systems hold the thing neither can represent.
Buying the wrong category is the expensive mistake, and it is easy to make because the marketing language is nearly identical. Work out which category you are actually short of before comparing any two products.
I build custom software for NDIS providers. That gives me an interest in you concluding that you need custom, so read the recommendations against it. I have tried to write the guide I would want if I were buying, which means it says plainly when an off-the-shelf platform is the right answer, and that is the answer for most providers most of the time.
The three categories
This distinction is the whole guide. Everything after it is detail.
| Category | What it does | You need it when |
|---|---|---|
| Operations platform | Rostering, shifts, billing, NDIS claiming, client records, participant portals | You are running services and the admin is the bottleneck |
| Compliance monitoring | Tracks obligations, flags gaps, assembles audit evidence | You are audit-anxious and cannot answer "are we compliant right now" |
| Custom system | Holds a relationship or obligation the other two cannot represent | Your team maintains a spreadsheet beside the platform |
Most providers need the first. A meaningful minority also need the second. A small minority genuinely need the third, and they usually already know, because the spreadsheet is sitting there.
Category one: operations platforms
These run the day-to-day. Rostering, timesheets, invoicing, NDIS portal claiming, participant records. If your problem is that scheduling and billing consume your week, this is the category you want, and compliance features are a secondary benefit rather than the reason to buy.
Australian products in this category include Lumary, built natively on Salesforce and aimed at larger providers; Brevity, end-to-end NDIS management with carer mobile apps and portal integration; ShiftCare, focused on rostering and care plans with direct claiming; CareMaster, end-to-end with published entry pricing; and FlowLogic, an integrated CRM, rostering, billing and compliance system.
Feature lists will look interchangeable. They are not. Compare on the three things that actually differ: how the NDIS claiming integration behaves when a claim is rejected, whether the roster can represent your service model without workarounds, and what the data export looks like if you leave. Ask for the export file, not a description of it.
Category two: compliance monitoring
These sit above or beside operations and watch obligations: worker screening currency, incident timelines, policy review cycles, restrictive practice authorisation, plan lodgement deadlines. The pitch is that you stop discovering gaps during audit preparation.
Audit Pilot is the most visible product in this category, positioning around continuous automated checks and an audit-readiness guarantee. Sentrient and Complynce also operate in the compliance management space for Australian providers. Several operations platforms bundle compliance modules, which may be sufficient depending on how much of your obligation set they model.
The honest framing: this category earns its cost when the answer to "are we compliant right now" currently requires a person to go and check across several systems. If you can already answer it in a minute, you are buying reassurance rather than capability.
Category three: the custom piece
Not a replacement for either of the above. The narrow system that holds what neither can represent, integrated so nobody maintains two sources of truth.
The signals are specific, and if none of them describe you then this category is not your answer:
- A spreadsheet holds a relationship the platform has no field for: mixed SIL and SDA, shared programs across participants, complex subcontracting, consent withdrawn and re-given.
- You carry an obligation the platform does not model at all: a retention schedule, a funder or insurer evidence requirement, a state-specific authorisation regime.
- You are renting integration permanently: three years of connector spend between rostering, finance and compliance, none of which you own at the end.
- The same non-conformity appeared at two consecutive audits, and the corrective action each time was a manual step that decayed.
How to choose, in order
Step one: configure what you already have
A surprising share of "the platform cannot do this" is "nobody has been through the settings since implementation, and that person has left". Custom fields, workflow rules, notification schedules and report templates cover more ground than most providers realise. This step is free and skipping it is the most common way to waste money.
Step two: identify which category you are short of
Write down the last three things that went wrong or took too long. If they are scheduling, billing and claiming, you need operations. If they are "we could not find the evidence", you need compliance monitoring. If they are "the system cannot represent what we actually do", you need custom.
Step three: shortlist two, not five
Vendor demos are optimised to look similar. Two products compared properly beats five compared superficially, and the comparison that matters is against your actual obligation set, not against each other's feature lists.
Step four: test the exit before you enter
Ask for a real data export during the trial. Not a promise that export exists. The file. This single request tells you more about a vendor than any reference call.
Questions to ask any vendor
These are the ones that separate products in this space. Most sales conversations never reach them.
On evidence
- Can the system show what a status was on a given date, or only what it is now?
- When a status says compliant, can it show what that was calculated from?
- Is evidence captured at the point of work, or entered separately afterwards?
On retention
- If a staff member leaves and their account is deactivated, what happens to records they created?
- Can anyone delete a record inside its retention period through the normal interface?
- Does the system hold a different retention clock for records relating to a child?
- If we migrate off this platform in three years, does the retention clock survive intact?
On data and exit
- Where is participant data hosted, and does it ever leave Australia, including for support or backups?
- What does a full export contain, and can I see one during the trial?
- What happens to our data if you are acquired or cease trading?
On your specific model
- Can one record belong to two arrangements at once?
- Show me how you would represent [your most awkward arrangement] without a workaround.
"If a staff member leaves tomorrow, what happens to records they created?" Many platforms tie record visibility to account state, and the failure only surfaces when someone departs. Providers are obliged to retain participant records for a minimum of seven years, and until a child participant turns 25. A system that cannot retain records without an active user account cannot meet that obligation, and very few vendors have a rehearsed answer.
Red flags
- A pass-rate or compliance guarantee with no method behind it. Ask what it is measured over. A number without a method is marketing, and auditors read it the same way.
- Reluctance to show a real data export. The most reliable signal available to you.
- "Fully compliant" as a product claim. Software cannot make an organisation compliant. It can make evidence available. Vendors who blur that are describing something they cannot deliver.
- Implementation quoted as free. Migration and configuration always cost something, usually your staff's time. A vendor who says otherwise has moved the cost somewhere you will find later.
- No answer on what happens after acquisition. This sector consolidates.
What this costs, honestly
Published pricing in the operations category starts around $99 a month for a handful of users and scales with seats and modules. Compliance monitoring products generally price per provider or per participant volume. Custom development is quoted per engagement and anyone giving you a range before seeing your obligations is guessing.
The number worth calculating before any of it: what does the current situation cost you? Staff hours on manual evidence assembly, the last audit's corrective action work, and the risk-weighted cost of a finding. If that total is small, the honest answer is to change nothing.
Common questions
What is the best NDIS compliance software?
There is no single best product, because three different categories are sold under that name. Operations platforms such as Lumary, Brevity, ShiftCare, CareMaster and FlowLogic run rostering, billing and claiming. Compliance monitoring products such as Audit Pilot, Sentrient and Complynce track obligations and audit evidence. Custom systems hold what neither can represent. Identify which category you are short of before comparing products.
Do I need compliance software to pass an NDIS audit?
No. Many small providers pass on well-run manual processes. Software becomes worth considering when the volume of evidence exceeds what anyone can reliably maintain by hand, or when the same evidence has to be assembled repeatedly for different purposes.
How much does NDIS software cost in Australia?
Operations platforms publish entry pricing from around $99 per month for a small number of users, scaling with seats and modules. Compliance products typically price per provider or by participant volume. Custom development is scoped per engagement.
Should we build custom NDIS software?
Usually not. Build only when your service model cannot be represented in a platform's data model, when you carry an obligation no platform models, or when you are permanently renting integration you will never own. Below roughly 30 staff with standard Practice Standards obligations, an established platform is almost always the better answer.
How long do NDIS providers have to keep participant records?
Generally a minimum of seven years from creation or last service date, and until the participant turns 25 for records relating to a child. Worker screening records carry a seven-year requirement, and from 1 July 2026 payment records must also be retained for seven years.
What changed for NDIS providers on 1 July 2026?
Supported independent living providers and NDIS digital platform providers now need to undergo audit and register with the NDIS Quality and Safeguards Commission in order to continue delivering supports.
This guide is general information about how Australian regulatory obligations apply in practice. It is not legal advice, and requirements vary by registration group, jurisdiction and the supports you deliver.