Governance
Policy Governance for NZ Social Services: The Complete Guide

Opening — answer first
Policy governance is the system boards use to make sure their organisation’s policies actually work, not just exist. In NZ social services, it means named accountability at governance level, a real review cycle (biennial is the operational default), regulatory anchors that match your sector, and – the part most organisations miss – visible evidence that policies are being practised on the ground.
Policies don’t fail because they’re missing. They fail because they’re not practised or evidenced. This guide is the complete map of what NZ boards, managers, and auditors actually look for in 2026 and what to do if you’re not sure yours would hold up.
What is policy governance?
Policy governance is the board-level oversight of how an organisation writes, approves, communicates, reviews, and evidences its policies. It’s distinct from policy management – the day-to-day operational work of updating documents and training staff – even though the two are often (wrongly) treated as the same job.
The distinction matters because in almost every NZ audit failure we’ve seen – and at The Policy Place we’ve been on all sides of that fence – the root cause traces back to the board treating policies as a management responsibility. The policies exist. They may even be reasonably current. But no one at governance level is asking, “Are these being practised? How do we know? What would we show an auditor?”
That question is the whole game.
What does good policy governance look like in Aotearoa?
Good policy governance in a NZ social or health service has six visible markers:
- Named board-level accountability. Someone, usually the chair or a dedicated portfolio holder, owns policy governance in the board’s meeting rhythm. Policies appear on the board agenda not just when something goes wrong.
- A real review cycle. Biennial as the operational default across the policy suite; annual for specific high-risk and fast-moving areas (technology, privacy, financial delegations, health and safety). We’ll come back to why the “3-year review” claim you may have seen elsewhere is wrong for most NZ contexts.
- Regulatory anchors that match your sector. Ngā Paerewa Health and Disability Services Standard for health and disability providers. Social Sector Accreditation Standards for social service providers. Te Kāhui Kahu as a regulator for SSAS-audited services. Charities Services obligations if you’re a registered charity. Privacy Act 2020 across all of it.
- Te Tiriti o Waitangi embedded, not bolted on. For services working with tangata whenua, policies that don’t reflect Te Tiriti obligations and cultural safety requirements won’t pass muster or the communities you serve. If you’re not sure which specific policies apply to your service, see What policies and procedures do NZ community services need? for the practical mapping.
- Evidence of practice, not just existence. Version-controlled documents are the floor, not the ceiling. Real policy governance asks: what shows this is happening? Staff training records, incident logs, audit trails, ProofKit evidence – the ledger of practice.
- Understandable, plain-English documents that staff actually read. A brilliantly drafted policy that no one reads is worse than a simple one that’s understood and applied. At the Policy Place, we read and write policies every day and have been doing it for more than 20 years. A common practice we see are policies that have been written for lawyers and policy makers rather than for the people delivering the service.
Miss any two of these six and the audit gets uncomfortable. Miss four and you’re at material risk.
How often should you review your policies?
The short answer: biennial is the operational default across the policy suite, with annual reviews on high-risk areas – privacy, financial delegations, and health and safety. Governance-level policies can sit on a longer cycle; frontline-facing policies can’t.
If you’ve heard “three years is fine” – that’s usually the Charities Services governance review being confused with the operational policy review cycle. They’re two different exercises. Applying the three-year rhythm to your policy suite lags is simply too long and risks outdated policies.
For the full breakdown, cycle by policy area, why each cadence, and how to build a defensible review calendar, see our deep-dive companion piece: How often must policies be reviewed in New Zealand?
Who is responsible for policies in a nonprofit?
The board owns the policy governance framework. Management owns the policy content and rollout. Both fail if either abdicates.
In practice:
- The board approves the policy framework itself (what policies exist, who signs off, how often they’re reviewed, how compliance is monitored). It doesn’t need to draft every policy but it needs to know they exist, that they’re current, and that there’s evidence they’re being followed.
- The Chief Executive / General Manager owns the operational side — drafting, staff training, incident response, and the practice ledger that shows policies are alive on the ground.
- Named policy owners (usually team leaders) will often by delegated policy areas and are the point of accountability when something goes wrong.
The failure mode we see most often is boards signing off a policy suite once and then not revisiting it until a funder or auditor forces the issue. By then, the policies have drifted from practice, and the board discovers the problem in the worst possible setting. New board members inheriting an existing policy suite face the same problem in reverse , see Governance induction for community services boards, for the practical handover approach.
The Proof of Practice principle
Here’s the single sentence to pin above your desk:
Policies don’t fail because they’re missing. They fail because they’re not practised or evidenced.
Auditors, funders, and the courts don’t reward organisations that have the right policies. They reward organisations that can show they’re being practised – that staff know them, that decisions reference them, that incidents are handled the way the policy says they will be, and that the evidence trail exists to prove it.
This is the moat between compliant-on-paper and genuinely governed. It’s also the shift most organisations underestimate. Writing a policy is a job that can be done in an afternoon. Building the practice and evidence around it is the ongoing work of governance.
At The Policy Place we call this Policy → Practice → Proof:
- Policy – the written framework, current and correct
- Practice – the day-to-day behaviour of the team, informed by the policy
- Proof – the evidence trail that lets you show it
Our platform manages the Policy layer. The Good Practice Hub covers Practice (adaptive learning that closes the staff-understanding gap) and Proof (audit-ready evidence via ProofKit). Together they close the whole loop – but the principle stands even if you use different tools. It’s the system, not the software, that matters.
Policy governance and Te Tiriti o Waitangi
For NZ social and health services, policy governance that doesn’t reflect the partnership and obligations of Te Tiriti o Waitangi is incomplete. Funders and accreditors including Te Kāhui Kahu, and contract managers – expect to see governance prioritising inequities and prioritising the achievement of positive Māori outcomes.
What this looks like at policy governance level:
- Rangatiratanga – Māori voice and authority in decisions that affect Māori clients, staff, and communities. Named at governance level, not delegated downward.
- Equity – strategic commitment to equitable outcomes with policies that support the commitment and target unacceptable practices. P
- Partnership – collaborations with iwi, hapū and other services to benefit those served by the agency and to provide a holistic response – the spiritual, emotional, and relational dimensions out of “service delivery.”
Policy governance in the age of AI
Two years ago this section wouldn’t have existed. In 2026 it’s non-negotiable.
Every NZ social and health service is now using AI in some form – Copilot for meeting notes, ChatGPT for drafting, transcription tools in supervision, image tools for training material. Most are using them without a policy framework, without staff guidance, and without any evidence trail. That’s a governance gap the sector has to close in the next 12 months.
Policy governance for AI doesn’t mean banning it. It means:
- A named position on which AI tools are approved for which uses (and which aren’t)
- Privacy safeguards – the Privacy Act 2020 applies to information you feed into an AI tool the same way it applies to information you email
- Equity – AI outputs tend to be anglocentric. For good AI governance safeguards against bias and reinforcing inequities are essential
- A practice ledger – what AI tools are actually being used, by whom, for what
- An evidence trail – the ability to show an auditor or funder how you’re managing AI use
The organisations that get ahead of this in 2026 will find AI governance folds into their existing policy framework naturally. The organisations that leave it another year will find themselves retrofitting under pressure.
Common policy governance mistakes we see
Between us Kendra and Lu have 40+ years across law, policy, government contract management and accreditation – designing standards, applying them, and being audited against them. The failure patterns we see most often:
- Treating policies as a compliance chore rather than a governance tool. Policies get updated when a funder asks; the rest of the time they sit on a shared drive no one opens.
- The board signs off once and doesn’t revisit. Two years later the policy suite is out of step with legislation, and no one knows.
- Named policy owners drift. The person who owned the safeguarding policy leaves; no one is assigned; the policy quietly ages.
- Evidence lives in the wrong place. Practice is happening but there’s no ledger to show it. When an auditor asks “how do you know,” the answer is anecdotal.
- Cultural safety as an add-on paragraph. A stated commitment to legal equality and Te Tiriti o Waitangi but no follow through on policies to support and monitor for cultural safety.
- Policies written for lawyers rather than staff. Correct, comprehensive, and completely unread. The best policy is one the frontline can quote back to you.
None of these are unusual. All of them are fixable but not by tinkering at the margins. They’re symptoms of a policy governance framework that isn’t doing its job.
How to get started
If you’ve read this far and you’re wondering where to begin, the honest answer is: start with an audit of what you have, not with drafting anything new. (And if you’ve already been through an audit that didn’t go well, that’s a different starting point – see What happens if you fail an accreditation audit in New Zealand? for the corrective-action path.)
- List every policy your organisation currently has. In a spreadsheet. Named, dated, owner assigned.
- Assess each against the six markers of good governance above. Which have a real review cycle? Which have cultural safety embedded? Which have evidence of practice? Which don’t?
- Prioritise the gaps. Not by “which policy is worst” but by “where would the biggest risk exposure be if this failed?”
- Assign a review calendar. Biennial as default, annual on high-risk. Put it on the board’s meeting rhythm.
- Build the practice ledger. For each policy, know how you’d prove it’s being followed. If you can’t answer, that’s where the work is.
You can do all of this without a policy platform, and many organisations do. If you want the work done for you, with all six markers pre-built, biennial review cycles baked in, and ProofKit evidence rails ready — that’s what The Policy Place platform exists for. And the Good Practice Hub — free StartSmart induction, PracticeLab Pro for the full library – closes the practice + proof side of the loop.
Either way, the important thing is that someone at governance level is asking the right question:
Are our policies being practised? How do we know? What would we show?
If your board isn’t asking that regularly, that’s where policy governance in your organisation actually starts. And if the issue you’re wrestling with is more about the pace of change than the framework itself – legislation shifting, funder expectations moving – see How can NZ social and health services keep up with constant policy change? for what actually works when everything’s moving at once.
Frequently Asked Questions
How often must policies be reviewed in NZ social services? Biennial (every two years) is the operational standard for most policies, with annual review on high-risk areas – privacy, financial delegations, and health and safety. The “three-year review” you may have seen elsewhere refers to the Charities Services governance review, which is a separate board self-assessment, not the operational policy review cycle.
Who is responsible for policies in a NZ nonprofit? The board owns the policy governance framework – deciding what policies exist, how often they’re reviewed, and how compliance is monitored. The CEO or general manager owns the operational policy content and rollout. Especially in larger organisations, staff (usually team leaders) will “own” individual policy areas. All three layers need to be functioning; if one abdicates, policy governance fails.
What’s the difference between policy governance and policy management? Policy governance is the board-level system that decides how policies work in your organisation – accountability, review cycles, evidence of practice. Policy management is the operational work of drafting, updating, and training. Governance is what and why; management is how and when. Both are needed.
How do I prove my policies are being practised, not just written? The practice ledger: staff training records, incident reports referencing the policy, decision minutes citing it, audit trails from your policy platform, ProofKit evidence, complaints handling records that follow the policy’s stated process. Auditors don’t ask “do you have this policy?” — they ask “show me it’s being followed.”
What NZ regulatory frameworks apply to my policy suite? Depends on your sector. Health and disability services fall under Ngā Paerewa (Health and Disability Services Standard). Social service providers contracted to MSD, Corrections, MoJ or Oranga Tamariki have contract-based obligations. Te Kāhui Kahu-accredited services follow the SSAS standards. Registered charities are subject to Charities Services obligations. Privacy Act 2020 applies to everyone. Te Tiriti o Waitangi applies to any service working with tangata whenua.
Do we really need a policy platform, or can we manage in Word documents? You can absolutely manage in Word documents – many organisations do. The trade-off is time and evidence. Version control, review cadence, staff acknowledgements, and audit trails all become manual. When the auditor asks “when was this last reviewed, who signed off, and what evidence do you have that staff read it,” Word documents make the answer harder. A platform bakes those in. Whether that’s worth it depends on your scale and risk exposure.
This guide was written by Kendra Beri, co-director of The Policy Place. Kendra brings a foundation in law, policy, and organisational leadership — including an LLB (Hons) and a Master of Education (Organisational Development). Her career spans 20+ years across Law & Policy and government & community operational management in Aotearoa and Australia.
Reviewed by Kendra Beri (legal / policy lens).
The Policy Place has been supporting Aotearoa’s social and health services since 2019. If you’d like to talk about what policy governance could look like in your organisation, book a 30-minute consult — no obligation.