Safe AI for NDIS Providers and Support Coordinators
A practical governance checklist for using AI with participant information, professional records, reports and workflow agents in an NDIS organisation.
- 1. Define the approved use case
- 2. Map the information before using the tool
- 3. Check the vendor and processing path
- 4. Keep human responsibility explicit
- 5. Apply existing access boundaries to AI agents
- 6. Protect records from silent duplication
- 7. Separate drafting from decision-making
- 8. Test with synthetic records
- 9. Give workers a simple escalation path
- 10. Review the use case after launch
- A short governance record
AI can help an NDIS organisation draft, search, summarise and progress repetitive work. It can also expose sensitive information, produce inaccurate content or blur accountability if the organisation treats a convenient tool as an approved workflow.
Safe adoption starts with the work and the participant, not with a list of AI features.
1. Define the approved use case
State what the tool may do, what information it may receive, who reviews the result and what it must never decide. "Draft a case note from supplied facts" is clearer than "use AI for documentation".
2. Map the information before using the tool
Identify personal, sensitive, health, behaviour, incident and safeguarding information. Minimise what enters the workflow. A useful draft rarely needs every detail the organisation holds.
The OAIC guidance on commercially available AI products recommends that organisations do not enter personal information, particularly sensitive information, into publicly available generative AI tools as a matter of best practice.
3. Check the vendor and processing path
- Where is information processed and stored?
- Is customer data used to train a model?
- How is access authenticated and logged?
- What retention and deletion controls exist?
- Which subcontractors or model providers receive data?
- What happens after a security or privacy incident?
4. Keep human responsibility explicit
The person using the output should verify facts, professional language, participant voice, recommendations, risks and billing context. The NDIS Quality and Safeguards Commission's AI transparency statement describes staff review and finalisation as part of its own drafting and summarisation use.
5. Apply existing access boundaries to AI agents
An agent should not receive broader access than the employee. Use organisation, role, team, participant and tool-level boundaries. Avoid shared credentials. Use expiring access and immediate revocation.
6. Protect records from silent duplication
AI clients may retry a request. An agent write should use an idempotency key so a network retry does not create two case notes, tasks or invoices. Record the actor, tool, target and outcome in an audit log.
7. Separate drafting from decision-making
Drafting a report outline is different from recommending funded supports. Summarising barriers is different from making a risk decision. Define which steps require a coordinator, manager, clinician or authorised delegate.
8. Test with synthetic records
Before using participant information, test prompts, tools, access scopes, error states, duplicate handling and revocation with synthetic data. Confirm that a coordinator cannot reach an unassigned participant through the agent.
9. Give workers a simple escalation path
Workers need to know how to report an inaccurate output, unexpected access, suspected disclosure or unsafe recommendation. Pause the workflow when the source or boundary cannot be verified.
10. Review the use case after launch
Audit samples of inputs, outputs, corrections and agent actions. Review access when roles change. Retire connections that no longer have an owner.
A short governance record
For each AI use case, record the purpose, approved users, information classes, provider, model or service, access scopes, review owner, retention, known limitations, incident path and next review date.
See the CordoCare MCP access model for an example of organisation approval, employee keys, live roles, audit history and guarded rollback.