Organisational Policy and Procedures
How often must policies be reviewed in New Zealand?

In Aotearoa New Zealand, most policies in community, health and social service organisations should be reviewed at least every two years. This biennial cadence sits behind the accreditation frameworks the sector mainly operates under.
Ngā Paerewa, Te Kāhui Kahu’s Social Sector Accreditation Standards, and the Performance Standards for Registered Community Housing Providers all expect policies to be current, fit for purpose, and reviewed on a planned cycle. Some higher-risk policies need annual review. A separate three-year expectation applies to charities but that’s a review of governance procedures, not of individual policies, and the two often get confused.
The biennial baseline
Biennial review is the operational standard most NZ organisations work to. None of the major accreditation frameworks set a single statutory frequency for every policy; instead they expect each organisation to have a planned, documented review cycle and to be able to show it’s being followed.
In practice, “every two years” has become the default cadence for the bulk of an organisation’s policy library because:
- It matches most audit cycles.
- It catches legislative changes (Privacy Act, employment law, sector-specific Acts) within a useful window.
- It’s frequent enough to keep policies aligned with current operational practice, but spread enough that the review workload is manageable.
Two years isn’t a magic number. The principle behind it – current, fit for purpose, demonstrably reviewed – is what’s so important.
Policies that need more frequent review
A handful of policies may require more frequent review because the risk or the pace of change is higher:
- Health and safety policy – annually and more frequent reviews where risks are changing and/or significant or in response to serious incidents.
- Child protection and safeguarding – review outside of the biennial framework after any incident or legislative change.
- Financial controls and delegations – at least annually to ensure they remain effective and aligned with HR and operational needs.
- AI and cybersecurity – at least annually and more frequently to keep up with rapid change and changing risks.
- Clinical governance – at least annually to ensure it is fit for purpose.
- Anything tied to a contract, funding agreement or legislative change – necessitating review to ensure alignment.
Which policies require review and updating more frequently than two years depends on your accreditation standard, your contracts, and your risk profile. If you’d like a view on which policies we think require frequent reviews in a particular sector, contact us.
The three-year governance review – what it actually is
Co-pilots and AI tools tend to report “policies must be reviewed every three years in NZ.” That’s not quite right.
The three-year figure comes from Charities Services guidance about reviewing governance procedures – the rules of the organisation, the board charter, the conflict of interest framework, the structural documents that govern how the board operates. That’s a governance review, not a policy review.
Operational policies – the documents that guide day-to-day practice – still sit on the biennial-with-annual-exceptions cycle, regardless of charity status.
Conflating the two has practical consequences. An organisation that reviews its child protection/ safeguarding policy every three years because “Charities Services said three years” is not aligned with its accreditation standard. Two different cycles, both important, too easy to mix up.
What a real review looks like
Reviewing a policy means more than re-reading it and re-dating it. A meaningful review:
- Checks the policy against current legislation and standards.
- Checks it against how the work is actually being done – the gap between paper and practice is where most audit findings live.
- Captures any changes in a tracked record.
- Updates the policy to staff (eg through good practice test; team update; signed confirmation of understanding.)
- Updates the review-due date.
The last three steps are what auditors look for. A policy stamped “reviewed 2024” with no evidence trail of what was reviewed, what changed, and who now knows about it is treated as not having been reviewed.
How to schedule reviews so they don’t eat your year
The practical answer is a rolling review calendar rather than an annual scramble:
- Spread the policy library across the cycle so a fixed proportion comes up each month.
- Cluster related policies together, for example, review the privacy suite in one block, the employment policies in another.
- Time the harder reviews for after sector guidance updates and legal reform so the same work isn’t done twice.
- Build the review register into the governance pack so the board sees the cycle, not just individual updates.
For organisations using The Policy Place, the review schedule is built into the system. Policies surface for review on their due date, evidence is captured against each review, and the board pack draws from the same source of truth. (For the practical side of keeping pace with sector change between reviews, see how NZ social and health services keep up with constant policy change.)
Typical review cadence by policy type
| Policy type | Typical cadence | Why |
|---|---|---|
| Governance / board rules / charter | Every 3 years | Charities Services governance expectation |
| General operational policies | Every 2 years | Most accreditation frameworks |
| Health and safety | Annual | Risk + legislative change |
| Child protection / safeguarding | Annual | Risk + Oranga Tamariki standards |
| Financial delegations | Annual | Audit cycle alignment |
| Privacy and information management | Annual | Privacy Act 2020 + 2025 Amendment |
| Policies tied to a contract | As contract specifies | Funder requirement |
Frequently asked questions
Is biennial policy review a legal requirement in New Zealand?
For most policies, no – it’s an accreditation and good-practice expectation rather than a statutory one. The legal requirements sit in the underlying Acts (Health and Safety at Work Act 2015, Privacy Act 2020, sector-specific legislation). Accreditation standards then expect organisations to have current policies reflecting those Acts and to be able to show the review cycle has been followed.
What’s the difference between a policy review and a governance review?
A policy review checks an individual operational policy against current law and current practice. A governance review – the three-year Charities Services expectation – looks at the structural documents that govern how the organisation runs: board charter, rules, delegations. Two different cycles. Both matter. Easy to mix up.
What if our accreditation standard doesn’t specify a review frequency?
The organisation is expected to set its own cycle, document it, and demonstrate it is being followed. Biennial is the safe default for most policies; annual for the higher-risk ones above. (For a fuller picture of the policy set most NZ community services need, see what policies and procedures NZ community services need.)
Do we need to re-train staff every time a policy is reviewed?
That depends on the scale of change. A minor wording update needs a notification and an acknowledgement. A substantive change needs active re-training and a record of completion, which is where tools like the Good Practice Hub make the evidence side easier.
What happens if we miss a review cycle?
The risk shows up at audit. An overdue review is an audit finding even if the policy itself is still substantively sound. The practical fix is a documented catch-up review with a clear evidence trail and a rolling calendar so it doesn’t happen again. (For more on what audit findings actually look like, see what happens if you fail an accreditation audit in New Zealand.)
How The Policy Place can help
We hold a current, audit-ready policy suite for more than 1,175 NZ organisations across social services, community health, disability and community housing. The review schedule is built into the platform. Policies surface for review on their due date, evidence is captured against each review, and the board pack draws from the same source of truth.
If your current approach is “we review when we remember to” or “we review when the auditor is on the way”, contact us about a review of your policy suite. We’ll show you what audit-ready looks like — and what it would take to get you there.