Back to blog
Compliance7 min read

NDIS identity checks: An SDA contact-register checklist

The NDIA announced on 10 August 2026 that it is introducing additional security checks when people contact the NDIS, and may also use those checks when the NDIA calls someone who asks to update personal information. The checks may include a one-time code sent to the mobile number or email address on record, plus extra identity questions. For SDA providers, this is not only a participant privacy update. It is an operating-control issue because urgent SDA work often depends on the right contact, the right consent, the right portal and the right evidence being available at the same time.

Treat identity checks as claim infrastructure

SDA teams usually feel identity friction during time-sensitive work: a participant move-in, a vacancy notification, a claim enquiry, a plan evidence check, an RRC question, a provider-detail update or a payment exception. If the participant, nominee, provider administrator or finance contact cannot pass the right check, the operational issue may sit unresolved even when the property record is otherwise ready.

The NDIA's identity guidance says contact details need to be current so one-time codes and contact-centre checks can work. Its provider portal guidance also says providers use the myplace provider portal to view and maintain provider contact and registration details, while the my NDIS provider portal remains central to SDA dwelling enrolment and management. That makes contact data part of claim and enrolment readiness, not just administration.

A useful SDA control is simple: every participant-dwelling record should show who can speak to the NDIA, which provider contacts are current, which portal owns the action, and what evidence should be captured after the contact is complete.

Clean up provider and participant contact records

Start with the provider entity. Record the legal name, trading name, ABN, provider number, main business email, finance contact, portal administrators, RAM authorisation owner, claim enquiry owner and after-hours escalation route. If the provider's myID email populated a portal contact field during setup, check whether the preferred business phone and email are still correct.

Then check the participant-side contact path without over-collecting. For each resident or vacancy lead, record whether the participant, plan nominee, correspondence nominee, guardian, support coordinator, plan manager or another authorised contact can speak with the NDIA about the relevant issue. Keep the consent scope specific: plan sharing, provider relationship, contact-centre discussion, personal-detail update, payment enquiry, service agreement or claim evidence.

This does not mean an SDA provider should store identity documents or one-time codes in its operating system. The stronger control is to record the verified status, source, date, contact pathway, consent limit and next action, while leaving private credentials and identity checks with the participant, nominee or official NDIS process.

Build the identity-check contact register

Use this checklist before an urgent NDIA call, after a failed identity check, during onboarding, when a nominee changes, when portal administrators change, when a claim enquiry is raised, and before owner reporting relies on an unresolved payment or vacancy assumption.

Verify the official provider contacts

Check the myplace provider portal contact details, business email, phone, ABN, provider number, RAM authorisations and backup portal users. Record the source date and who approved any update.

Map participant authority

Record who can speak with the NDIA for the specific SDA issue, whether consent is one-off or ongoing, what information may be shared, and when that consent needs review.

Route the portal action

Separate actions for my NDIS provider portal, myplace provider portal, participant portals, support coordinator requests, claim and payment enquiries, SDA dwelling enrolment and service bookings.

Protect codes and credentials

Do not ask participants or nominees for myGov, my NDIS app, participant portal details or one-time security codes. Record that the official check was completed, not the private credential itself.

Tie calls to claim evidence

After a call or portal enquiry, record the date, contact channel, reference number if provided, participant-safe identifier, dwelling, issue type, accountable owner, decision state and next follow-up date.

Restrict owner reporting

Show owners factual states such as contact details under review, claim enquiry open, participant consent pending or payment outcome not confirmed without disclosing identity checks, nominee details or plan information.

Keep privacy boundaries visible

NDIS guidance on protecting plans tells participants that providers do not need their my NDIS app, participant portal or myGov login details to process claims or service agreements. SDA providers should make that boundary explicit in onboarding scripts, vacancy workflows and finance follow-up. Staff should know what they can ask for, what they must not ask for, and where consent evidence sits.

The same boundary applies internally. Portal access does not mean every staff member needs every participant detail. The operating record should separate business contacts, portal roles, participant consent, plan-sharing permission, claim evidence, RRC records, incident records and owner summaries. That structure reduces the chance that a payment chase turns into unnecessary disclosure.

If a participant or nominee cannot complete an identity check because their contact details are out of date, the provider can record the operational blocker and the next safe step. It should not invent a workaround by using another person's phone, sharing login details or treating informal family updates as consent.

Connect identity checks to SDA workflows

SDA providers should connect the contact register to real workflows rather than leaving it as a compliance spreadsheet. During onboarding, it should sit beside service agreement, my provider, plan-sharing and claim-start checks. During vacancies, it should support fast but privacy-safe contact with authorised people. During claim exceptions, it should help finance route the enquiry without exposing unnecessary plan details.

This is also useful for fraud and non-compliance controls. The NDIS Commission says providers have a role in managing fraud risk and supporting participants affected by suspected fraud. A clean contact register helps a provider respond if a participant disputes a claim, if an invoice appears under the wrong ABN, if a contact claims authority they do not have, or if a portal user leaves the organisation.

For leadership, the metric is not how many identity documents are stored. The better metric is how many active residents, vacancies and claim exceptions have current provider contacts, clear participant authority, correct portal routing, an evidence owner and a privacy-safe owner-reporting state.

How StepFree fits the workflow

StepFree SDA can help providers keep contact authority, portal tasks, participant-dwelling records, service agreements, claims, RRC ledgers, vacancies, payment enquiries and owner-safe updates in one controlled operating workflow.

The value is operational clarity. Frontline teams can see who is authorised, finance can see whether a claim enquiry is blocked by identity or evidence, compliance can see the source trail, and owners get useful status without participant identity details leaking into commercial reporting.

Conclusion

Extra NDIS identity checks should not slow SDA operations if the provider's contact records are clean. Treat provider details, participant authority, portal routing and claim enquiry evidence as linked controls. Keep one-time codes and private credentials out of the provider record, use consent narrowly, and report owner-facing status from confirmed operating facts.

StepFree SDA can help providers manage SDA contact authority, portal workflows, claim enquiries, RRC records, vacancies and owner-safe reporting from one structured operating record.