What Policies and Procedures Do NZ Community Services Need? A Practical 2026 Guide

Policies aren’t paperwork. Done well, they’re how your organisation protects people, secures funding, and stays out of trouble. Done badly, they’re a binder no one opens.

If you run a New Zealand community service — whānau support, disability services, mental health, youth, family violence, social housing, or anything in between — you already know the policy landscape can feel relentless. Funders ask for them. Auditors check them. Boards approve them. Staff are meant to follow them. And the legislation underpinning them keeps shifting.

This guide is a practical answer to a question we hear constantly: what policies and procedures do NZ community services actually need? Not a maximalist wish-list. Not a generic template pack. The real, sensible, sector-grounded answer.

Why this matters more in 2026

Three forces are tightening the bar on community services policies and procedures right now:

  • Te Kāhui Kāhu audits have shifted from “do you have it?” to “prove it works.”

    The Social Sector Accreditation Standards (SSAS) themselves haven’t changed, but the February 2026 refreshed guidance clarified how they’re applied in practice. [tekahuikahu.govt.nz]

    In 2026 audits, providers are consistently reporting that auditors:

    • Ask more detailed questions about how policies operate in practice
    • Expect specific, named policies, not just general coverage across documents
    • Require evidence that policies are followed, not just that they exist
    • Probe high‑risk areas (especially safeguarding and vetting) more deeply

    The effect is a real shift in the audit lens: the bar hasn’t moved, but it’s now more visible, more explicit, and more consistently enforced.

  • Privacy law has shifted. The Privacy Amendment Act 2025 took effect in May 2026, introducing changes around the indirect collection of personal information. Policies that haven’t been reviewed since 2024 are out of date.
  • Funders are scrutinising governance. Government and philanthropic funders increasingly want evidence that providers have current policies — not just policy names on a list.

In short: if your policy suite was built three years ago and hasn’t been formally reviewed since, you’re likely to struggle to demonstrate compliance under the way audits are now being conducted in 2026.

“In 2026, compliance isn’t about having policies — it’s about proving your policy system works.”

The core policy categories every NZ community service needs

A complete policy suite for a NZ community service organisation typically spans six categories:

1. Governance

Sets the rules for how your organisation is governed. Includes the constitution or rules document, board charter, conflict of interest, risk management, financial delegations, and chief executive / board reporting arrangements. These are the policies your board approves and lives under.

2. People & Culture

The employment and workplace policies. Recruitment and selection, vetting and screening, code of conduct, professional boundaries, supervision, leave, grievance, bullying and harassment, performance management, training and development. Must align with the Employment Relations Act 2000 (and 2025 reforms), Holidays Act 2003, Equal Pay Act 1972, and Human Rights Act 1993.

3. Health & Safety

Health and safety in the workplace, hazard management, incident reporting, psychosocial safety, fitness for work, and emergency procedures. Anchored in the Health and Safety at Work Act 2015.

4. Service Delivery

How you actually do the work. Includes service-specific operational policies (e.g. intake, assessment, care planning, case management, exit), client records, informed consent, confidentiality, working with whānau, cultural safety, and the policies specific to your sector or contract obligations.

5. Abuse & Protection (safeguarding)

This is the one many providers underestimate. It’s not a single policy — it’s a connected suite that covers prevention, screening and vetting, safe environments, response and reporting, learning and improvement, and the links between safeguarding and complaints, conduct, and supervision. See our companion article on Te Kāhui Kahu SSAS audits in 2026 for the detail on what auditors expect here.

In 2026 audits, this is also where the biggest gaps are being surfaced – particularly where organisations rely on a single Abuse Response policy without demonstrating a full, connected safeguarding system.

6. Privacy & Information

How you collect, use, store, share, and dispose of personal information. Includes privacy, information security, record-keeping, retention and disposal, and breach notification. Must reflect the Privacy Act 2020 and the 2025 amendments.

These six categories aren’t optional. Every NZ community service organisation needs coverage across all of them. The specific policies within each category depend on your service context — but the categories themselves are non-negotiable.

These categories also haven’t changed. What has changed is how clearly you’re expected to demonstrate coverage across them — and how well those policies connect and operate as a system.

What “good practice” looks like in 2026

Beyond the categories above, here’s what auditors, funders, and good-practice expectations are converging on in 2026:

  • Policies are dated, version-controlled, and clearly reviewed — auditors want to see when a policy was last reviewed, by whom, and what changed
  • Policies reference each other — your Complaints policy mentions your Abuse Response policy; your Code of Conduct connects to Professional Boundaries. Auditors check whether your framework hangs together
  • Policies reflect current legislation — out-of-date references to the Privacy Act 1993 or the old Health and Safety Act will be flagged
  • Te Tiriti o Waitangi is embedded, not bolted on — for NZ community services, kaupapa Māori principles should run through service-delivery and engagement policies, not sit in a separate “cultural policy” off to the side
  • Staff understand the policies they’ve signed off — induction records, refresher cadences, and evidence of comprehension are increasingly expected
  • Policies are backed by evidence of use — auditors increasingly expect to see proof that policies are embedded in practice (e.g. case notes, supervision records, training completion, incident follow-up), not just signed documents

The bar in 2026 is not “do you have a policy?”- it’s “is the policy current, connected, understood, and used?”

The most common gaps we see

Across NZ community services, the policy gaps that are now most consistently surfaced in 2026 audits are:

  • Single-policy safeguarding — relying on one Abuse Response policy instead of the full Abuse & Protection suite
  • Out-of-date privacy policies — drafted before the Privacy Act 2020 or before the 2025 amendments
  • Vetting practice not documented — screening is happening, but the policy doesn’t describe what the organisation actually does
  • Stale review dates — policies written 3+ years ago, never formally reviewed since
  • Disconnected policies — each one fine on its own, but no internal references showing how they fit together
  • No evidence of staff comprehension — sign-off records exist, but nothing demonstrates that staff actually understand what they’ve signed
  • Generic templates that don’t match the organisation — copy-pasted policy text that mentions a sector the organisation isn’t in, or roles that don’t exist on the team

The good news: every one of these gaps is fixable, and most of them are quicker to address than starting from scratch.

How often should you review and update your policies?

A reasonable review cadence for an NZ community service organisation is:

  • Annually: high-risk policies — safeguarding, health & safety, privacy, conduct, vetting
  • Every 2 years: everything else
  • Immediately: any policy affected by legislative change (e.g. the 2025 Privacy Act amendments triggered an immediate review for most privacy and information-security policies)
  • Immediately: any policy that fails an audit, contract review, or incident review

The most important thing is that the review is documented. A policy with a review date in the footer that hasn’t been touched in three years tells auditors something. A policy with a clear history of annual review — even if the content didn’t change much — tells them something else entirely.

How to know when it’s time to refresh your full suite

Some signals that your full policy suite needs more than incremental review:

  • It’s been 3+ years since you did a comprehensive review of the whole suite
  • An audit, contract review, or funder query has surfaced more than one gap
  • Your organisation has grown, restructured, or added new service streams since the suite was built
  • Major legislation in your sector has changed (Privacy Amendment Act 2025, Te Kāhui Kahu guidance updates, employment law reforms)
  • Te Tiriti o Waitangi obligations haven’t been worked through the suite as a whole

If two or more of these signals apply, a structured policy review project — not just a tidy-up — is likely the right call.

Building it yourself vs using a sector-built suite

There are essentially two paths to a complete policies and procedures suite for an NZ community service:

Build and maintain it yourself. A capable in-house person or contractor drafts each policy, the board approves, and someone takes responsibility for ongoing review. The advantage is total customisation. The cost is real: drafting a full suite from scratch is months of work, and keeping it current with sector and legislative change is a permanent commitment.

Use a sector-built policy platform. A platform like The Policy Place gives you a complete suite of bilingual, NZ-specific, sector-aligned policies that are kept current as legislation, guidance, and audit expectations evolve. You get the customisation you need (organisation name, service context, role titles), without the burden of being the one tracking every Te Kāhui Kahu guidance update.

For most NZ community services — particularly those without a dedicated policy person — the platform path is significantly cheaper than internal drafting, and dramatically lower-risk than letting policies go stale.

How The Policy Place helps

The Policy Place was built specifically for NZ community service providers — by founders who used to be on the funder and accreditation side of community services. We know which policies actually matter because we used to ask for them.

Our policy platform gives you:

  • A complete, sector-aligned policy suite across all six categories above
  • Policies that are bilingual (English + te reo Māori) with Te Tiriti woven in, not bolted on
  • Real-time updates as legislation, Te Kāhui Kahu guidance, and good-practice expectations shift
  • Monthly policy review summaries so you know what changed and why
  • Audit-ready evidence when funders or auditors ask for current policies

And if you want help getting staff understanding evidenced for audit, our Good Practice Hub offers a free sector StartSmart Induction Kit. This is a set of role-curated induction quizzes that produce ProofKit completion records for your next audit.

Frequently asked questions

What policies does an NZ community service organisation need?

At minimum, an NZ community service needs policies across six categories: Governance, People & Culture, Health & Safety, Service Delivery, Abuse & Protection (safeguarding), and Privacy & Information. The specific policies within each category depend on the organisation’s service context, but coverage across all six categories is non-negotiable for accreditation and funding.

How often should community services review their policies and procedures?

High-risk policies (safeguarding, health & safety, privacy, conduct, vetting) should be reviewed annually. Other policies can be reviewed every two years. Any policy affected by legislative change should be reviewed immediately — for example, the Privacy Amendment Act 2025 triggered an immediate review for most NZ privacy policies.

What’s the difference between a policy and a procedure?

A policy sets out what the organisation does and why — the principle and the position. A procedure sets out how it’s done — the steps, roles, and timeframes. Most community services need both: the policy gives accountability and direction; the procedure gives staff a clear “do this next.”

Do non-profits need different policies from private organisations?

The categories are largely the same, but non-profits have additional governance requirements (constitution, charity reporting, conflict of interest at board level), and many have sector-specific accreditation or funding-contract obligations that drive specific policy requirements. NZ non-profits delivering social services typically also need to meet Te Kāhui Kahu Social Sector Accreditation Standards.

What policies are needed for Te Kāhui Kahu accreditation?

Te Kāhui Kahu assesses organisations against the Social Sector Accreditation Standards (SSAS), which cover governance, management, service delivery, staff competence, and safeguarding. Required policies include governance documents, recruitment and vetting, code of conduct, complaints, abuse and protection (a full suite, not just response and reporting), privacy, health and safety, and service-delivery operational policies.

How long does it take to set up a complete policy suite?

Built from scratch in-house, a comprehensive NZ community services policy suite typically takes 4–6 months of dedicated work — drafting, board approval, implementation, and staff training. Using a sector-built platform like The Policy Place, most organisations are fully set up within 2–4 weeks, including customisation and platform onboarding.

This guide was written for NZ community service organisations needing a current, sector-grounded answer to “what policies do we actually need?” If you’d like a hand reviewing your existing suite or building a complete one, get in touch with The Policy Place team — we’re here to help.

false