For NDIS & employment-services providers
NDIS providers, Right Fit For Risk, and the documents you hold
Right Fit For Risk (RFFR) is the Australian Government's security accreditation — aligned to ISO 27001 and the ASD's Information Security Manual — for providers delivering contracted employment services, including Workforce Australia and Inclusive Employment Australia (formerly Disability Employment Services). It is not an NDIS registration requirement — but participant records are among the most sensitive documents any organisation holds, whichever rules you sit under.
Does RFFR actually apply to you?
Plenty of consultant marketing says every NDIS provider must be RFFR accredited. The primary sources don't. RFFR is a condition of a deed with DEWR (or DSS) — it binds organisations contracted to deliver Australian Government employment services (Workforce Australia and related deeds, and third-party employment-systems vendors), and since 1 November 2025 providers under Inclusive Employment Australia, the program that replaced Disability Employment Services. An NDIS-registered provider is in scope only if it also holds one of those contracts. Registration with the NDIS Commission instead carries the NDIS Practice Standards, whose information-management outcome requires participant records to be accurate, current and confidential — a lower bar in form, but the same documents and the same stakes.
What assessors look at
Sensitive by default
Participant files carry health information, behaviour support plans, guardianship details and home addresses — often all in one PDF.
Controls, not intentions
RFFR is evidence-based: assessors look for ISM-aligned controls you can demonstrate, not policies you can quote.
Every third party counts
Each cloud service that touches participant data is another line in your data-flow map — and another thing to assess and defend.
Where Omitly fits an RFFR posture
Omitly processes documents entirely on the worker's machine — no cloud processor in your data-flow map, and only a document digest ever sent out if timestamping is on. Redactions are sealed, producing verifiable evidence that the file you shared is the one you sealed.
Share less, prove more
Redaction is routine in disability services: incident reports shared with families, documents released under participant access requests, files sent between providers. The failure mode is silent — a name that survived in metadata. Sealed redaction turns “we removed it” into something you can show.
What hides in a participant PDF besides the visible text? PDF metadata, explained →
Make participant documents shareable, defensibly
Local-first redaction with sealed evidence — built for organisations whose files can't afford a leak.
General information about how these frameworks are structured — not legal advice, and not a determination that any obligation applies to you or that any product satisfies one. Current as at 27 July 2026; check the primary sources below, which change independently of this page.
Sources
- DEWR — Right Fit For Risk (RFFR) accreditation
- DSS — Inclusive Employment Australia (replaced Disability Employment Services, 1 Nov 2025)
- NDIS Commission — NDIS Practice Standards (information management)
- National Disability Insurance Scheme (Provider Registration and Practice Standards) Rules 2018 — F2018L00631
- ASD — Information Security Manual (ISM)