Governance
Te Kāhui Kāhu SSAS Audits in 2026: What NZ Social Services Need to Know

The Social Sector Accreditation Standards haven’t been rewritten. But the way Te Kāhui Kāhu is applying them has changed and it’s impacting social service audits in 2026.
If you’ve been through a recent Te Kāhui Kāhu social services audit, you’ll already know the tone has shifted. Auditors are asking different questions – more “how you”. They’re also being more prescriptive about what they expect to see in your policies. And the gaps they’re flagging aren’t always the obvious ones.
If you haven’t been audited yet, this article will help you walk in with eyes open.
What hasn’t changed: the SSAS standards themselves
First, the reassurance: the Social Sector Accreditation Standards (SSAS) are the same standards you’ve always worked to. Te Kāhui Kāhu hasn’t quietly rewritten the framework. There’s been no announcement of new criteria. The eight outcome areas still anchor the assessment.
This matters because it means your strategic policy work – your existing investment in a coherent policy suite – still holds. You haven’t suddenly fallen behind a moving target.
What has changed: how the new guidelines are being applied in social service audits
What has shifted is the interpretive guidance Te Kāhui Kāhu auditors are now working with and the prescriptiveness of how they’re checking that organisations meet the standards in practice.
In recent audits, providers are reporting that auditors:
- Look harder for specific named policies, so that coverage in related area of no longer enough
- More focus on “the how” – with more focus on policy detail
- Want evidence of practice, not just the existence of a written policy
- Probe specific high-risk areas more deeply – particularly anything involving vetting, safeguarding, and the protection of people who use services
None of this is unreasonable. It reflects what good practice should look like anyway. But for agencies whose policy sets were built over years and never quite tidied, the new prescriptiveness can surface gaps you didn’t know you had.
The biggest pattern we’re seeing: Safeguarding and Vetting policies
Of all the prescriptive expectations we’ve watched land in recent audits, one stands out clearly.
Providers often think they’re covered for safeguarding because they have an Abuse Response and Reporting policy. That policy tells staff what to do if abuse is disclosed or suspected – who to tell, when, how to escalate, what records to keep. It’s an important policy. It’s just not the whole picture.
Auditors are now consistently asking for a wider focus – policy content that demonstrates a complete safeguarding framework, not just a reporting pathway. The expectation is that an organisation can show:
- How it prevents abuse and harm in the first place
- How it screens, supervises, and supports staff and volunteers who work with people who use services
- How it keeps the child or vulnerable person safe throughout
- How it responds when concerns arise for children and vulnerable adults
- How it reports, learns, and improves after the fact
- How it manages risks that surface through screening or which emerge in the course of employment.
A single Abuse Response and Reporting policy can’t carry all of that load. When auditors ask “and where is your prevention framework documented?” or “show us how this connects to your screening practice for new volunteers” – a one-policy answer doesn’t satisfy.
Vetting and community safeguarding are a priority focus for Te Kāhui Kahu. The interpretive guidance has tightened around what auditors expect to see and a focus on vetting prior to employment or appointment and without risk management is not sufficient.
What auditors are looking for in 2026
Across recent audits, the prescriptive expectations cluster around five themes:
1. A Safeguarding policy framework, not a single policy
As above. If you only have Abuse Response and Reporting or only Child Protection when you work with vulnerable adults, you have a gap – even if that single policy is excellent.
2. Vetting practice documented, current, and evidenced
Auditors want to see your screening and vetting processes for staff and volunteers including police vetting renewal cadences, reference checks, role-based screening levels, and how you respond when something concerning surfaces in a check or during employment.
3. Focus on the policy specifics
The 2026 audit lens is on policy specifics. If your Behaviour Management policy just states that you will engage clients in planning this won’t be enough. You need to specify how you engage them. Likewise references to “conduct” are too broad. In your Code of Conduct it is now necessary to clarify that this includes online activities.
4. Evidence of staff understanding
It’s increasingly not enough to say “our staff have read the policy.” Auditors want evidence that staff understand the policies they’ve signed off – particularly the safeguarding ones. Induction records, refresher training, capability evidence, and proof of knowledge are all in scope.
5. Live policies, not stale ones
Policies dated 2019 raise eyebrows. Auditors check review dates, version histories, and whether your policies reflect the current regulatory environment (Privacy Act 2020, Health and Safety at Work Act 2015, recent Culturally Responsive practices and the Privacy Amendment Act 2025 changes that took effect in May 2026).
For more on the policies NZ agencies need, see our blog here.
The common gaps we see in social service audit responses
In our work supporting agencies through audits, the gaps that show up most often are:
- Single-focus safeguarding – for example, relying on Abuse Response and Reporting alone, without prevention, screening, environment, and culture policies around it; or child protection without a focus on vulnerable adults
- Disconnected vetting – vetting practice is happening but not documented in policy, or the policy is generic and doesn’t reflect what the organisation actually does
- Stale review dates – policies were drafted well but haven’t been formally reviewed in 2–3+ years
- Missing evidence – registers to reflect policy implementation are live and not being used as they were intended (eg hazard and risk register.)
- No evidence of staff understanding – policies are signed off (via employment agreement) but no record exists of induction, refresher, or comprehension.
The good news: every one of these is fixable. None of them require you to rebuild your policy suite from scratch.
How to prepare your organisation for a 2026 Social Service Audit
If you’ve got an audit coming up in the next 6–12 months, the practical steps are:
Step 1 – Develop an inventory of your policies against the SSAS level you are funded for
List every policy you have that touches the criteria of each standard and collate evidence of your implementation.
Step 2 – Check your policies for coverage of the full safeguarding framework
Compare your inventory against a complete framework: prevention, vetting, safe practice, response, recordkeeping, reporting and improvement. Where are the gaps?
Step 3 – Refresh your review cadence
For high-risk policies (cybersecurity, health & safety, privacy, conduct), aim for regular review. For others, every 2 years is reasonable. Document the review – auditors look for the evidence that review happened, not just claims.
Step 4 – Build evidence of staff understanding
If you don’t already have an induction system that captures staff comprehension of key policies, this is now the highest-leverage thing you can put in place. A simple quiz at induction, with a record of completion, satisfies the evidence question that auditors are increasingly asking.
Step 5 – If something is flagged, act fast
If your auditor raises a concern about a specific policy, the response that lands well is: “Yes, we hear you. Here’s what we’re doing about it, on this timeline.” Don’t defend a gap. Close it.
How The Policy Place helps
The Policy Place was built specifically for NZ social service providers by people who have been on the service provider side as well on the funder and accreditation side of community services. We know what auditors are looking for because we’ve been in those conversations from all sides.
For organisations on our platform, the full policy suite is ready to enable, not a separate purchase, just a matter of switching on the policies that match your service context. When auditors ask for the interconnected safeguarding framework, you can hand it to them. (See our blog on Audit-ready policies for health and social service agencies.)
We update policies in real time as Te Kāhui Kāhu’s interpretive guidance evolves. The updates flow out to every client on the platform. If your auditor raises something specific, please get in touch with us directly – there’s a strong chance we’ve already addressed it across the customer base (or are about to).
For organisations not yet on the platform, our Good Practice Hub offers a free StartSmart Induction Kit – including free induction quizzes covering Code of Conduct, Workplace Safety, Conflict of Interest, Feedback & Complaints, and Child Protection, with audit-ready completion evidence (ProofKit). Try it free at goodpracticehub.com.
Book a consultation with our team →
Frequently asked questions
What is Te Kāhui Kahu?
Te Kāhui Kāhu is the accreditation body for social service and other agencies contracted to government agencies in Aotearoa New Zealand working with the courts, Ministries of Justice, Corrections, Social Development and Oranga Tamariki. It assesses providers against the Social Sector Accreditation Standards (SSAS) to ensure services are safe, effective, and well-governed.
What are the SSAS standards?
The Social Sector Accreditation Standards are a set of outcome-based standards that NZ social service providers must meet to hold accreditation with Te Kāhui Kahu. They cover governance, management, service delivery, staff competence, and safeguarding, among other areas.
What is the full Safeguarding policy suite?
The full Safeguarding policy set is the connected set of policies an organisation needs to demonstrate safeguarding of children, young people and vulnerable adults. It’s not just a reporting pathway. It typically includes prevention, screening and vetting, safe practice, response and reporting, learning and improvement, and the links to related policies like Code of Conduct, Complaints, and Supervision.
How often should NZ social services review their policies?
For high-risk and fast-moving areas (like Artificial Intelligence, Health & Safety, Privacy, Conduct), regular review for updating when necessary is best practice. For other policies, every 2 years is reasonable. The most important thing is that review is documented auditors look for evidence of review, not just claims.
What happens if our auditor flags a policy issue?
Don’t panic, and don’t defend the gap. Acknowledge the concern, get advice on how to close it, and act on a clear timeline. If you’re a Policy Place client, contact us directly- there’s a strong chance we’ve already addressed the issue across the client base, or can build it into the next update.
Does The Policy Place keep policies current with Te Kāhui Kahu changes?
Yes. We update policies in real time as Te Kāhui Kahu’s interpretive guidance evolves, and the updates flow out to every client on the platform automatically. Our clients don’t need to track guidance changes themselves because that’s our job.
This article was written for NZ social service providers preparing for Te Kāhui Kahu SSAS audits in 2026. If you have a specific audit question or would like a hand reviewing your policy suite, get in touch with The Policy Place team – we’re here to help.