3 September 2026 · 3 min read · Behind the build, Compliance
Behind the build: a compliance platform for NDIS and care providers
How Accorda went from one provider's spreadsheet problem to a multi-sector platform — and what it taught us about building software for regulated businesses.

Accorda started the way most useful software does: with someone trying to survive an audit using Word documents.
The problem
An allied health provider working under the NDIS needed to prove, on demand, that staff were qualified and screened, that policies were current and acknowledged, and that incidents were reported and followed up correctly. The evidence existed — in folders, spreadsheets, email threads and a filing cabinet. Assembling it took weeks, and every audit turned up something missing.
This isn't unusual. Care providers operate under some of the most detailed regulation in Australia, and most of them manage it with tools designed for writing letters.
The first version
We built a single-tenant portal for that one provider: staff records with credential expiries, a policy library with sign-off tracking, and an incident register. Each sign-off was hashed and chained so nobody — including us — could alter the history after the fact. The portal made the next audit a morning's work.
That version taught us the two things that mattered most:
- Staff will only use it if it's faster than paper. Logging an incident had to take two minutes on a phone, photos included, or it wouldn't happen.
- Auditors care about provability. "Here's the record" is good; "here's the record, and here's mathematical proof it hasn't been edited" ends the conversation.
Turning it into a platform
The same problem exists across NDIS, aged care, childcare, allied health and — with different paperwork — trades. So we rebuilt it multi-tenant: every organisation gets its own secure space, sector templates seed the right policies and registers, and the workflows understand each framework's rules (what's reportable, to whom, by when).
Key pieces of the current platform:
- Registers with real workflows. Incidents, complaints, risks and corrective actions each move through defined states with owners, due dates and escalation. Nothing sits in an inbox.
- Credential and licence tracking with evidence uploads and reminders before things expire.
- AI-assisted policy authoring. Drafting a policy from the framework and your context, checking it against your other policies for contradictions, and updating it from audit findings. A human approves every change.
- Evidence packs. One button produces a branded PDF bundle for an auditor — every register, every action, every acknowledgement for the period.
- Tamper-evident records with a public verifier so anyone can confirm a document is genuine.
- Time-limited auditor access, read-only, that expires automatically.
What we'd tell anyone building for a regulated sector
Map the framework before you design a screen. The regulation defines the data model. Build the screens around it, not the other way around.
Optimise for the worst day. The platform is judged on the day an incident is reportable and the clock is running. Everything else is secondary.
Keep humans in charge of anything AI touches. AI is superb at drafting and flagging. It should never be the last step.
Migrate history properly. When we moved the first provider into the new platform, we reproduced every hash in the sign-off chain so their years of evidence stayed provable. That took real care; it was worth it.
Where it is now
Accorda serves multiple care sectors and trades businesses, and continues to grow a feature or two a month. Most of what we now offer as compliance and records systems for other businesses is a right-sized version of what we learnt building it.
If you're a provider spending weeks on audit prep, you don't have to build your own platform. You can use ours, or we can build the smaller version your business actually needs.