← Back to blog

Building a policy suite NFP boards can defend under audit

August 23, 2026
Building a policy suite NFP boards can defend under audit

A policy suite proves one thing to a regulator or a funder: that your board understands its duties and has evidence to show it. Policy suite development for an NFP is not about producing a folder of documents. It is about producing a system where every policy has a board resolution behind it, every procedure has a named owner, and every claim you make to the ACNC or the NDIS Commission can be backed by a dated record.

The single next step, if your suite has not been reviewed recently, is straightforward:

  • Pull every current policy and procedure into one list
  • Check which ones have a board minute approving them
  • Flag any gap to your next board meeting as a formal resolution to begin the review

The Planning and Practice Hub works with boards on exactly this audit, but you can start it yourself this week.

Key Takeaways

A defensible NFP policy suite pairs board-approved policy with CEO-owned procedure and dated evidence, mapped directly to ACNC and NDIS requirements.

PointDetails
Board approves, CEO implementsKeep policy adoption at board level and procedure sign-off with the CEO, recorded separately.
Map every policy to a standardBuild a matrix linking each policy to the ACNC Governance Standard or NDIS module it serves.
Evidence beats good writingMinutes, registers, and training logs prove a policy was acted on, not just approved on paper.
Review on a schedule, not by memorySet annual review dates at the same meeting a policy is adopted, and track them on a compliance calendar.
Get done-for-you supportThe Planning and Practice Hub builds the policy pack, standards mapping, and evidence folder for boards short on time.

What documents belong in your NFP policy suite

Three layers make up a defensible suite: board policies, operational procedures, and the registers that prove both were acted on. Confusing these layers is the most common gap we see in governance reviews.

Board-level documents set direction and cannot be delegated:

  1. Governing document — your constitution or rules, which under ACNC Governance Standard 1 must include not-for-profit and winding-up clauses. Amending this later is slower than most boards expect, so get it right early.
  2. Board charter — how the board operates, delegates, and reviews its own performance.
  3. Delegations policy — what the CEO can approve without board sign-off, and the dollar or risk thresholds that trigger escalation.
  4. Conflict of interest policy — how conflicts are declared, managed, and recorded.

Operational policies sit underneath these and cover the day-to-day risk areas regulators care about most: privacy, financial controls, complaints handling (including child safe requirements under the National Principles for Child Safe Organisations where relevant), incident management, and HR.

Registers turn all of this into evidence. Your Responsible People register, conflict-of-interest register, board minute book, and staff training log are what an auditor actually reads. A governance documentation guide can help you work out which registers your organisation is missing.

NFP office desk with registers and tablet

Who approves policy and who signs off procedure?

This distinction trips up more boards than any other part of policy suite development. Policy sets intent and risk appetite. It is the board's job, full stop. Procedure sets the operational steps that deliver on that intent, and it belongs to the CEO or executive team.

Why does this matter beyond neatness? Governance Standard 5 requires Responsible People to act with reasonable care and diligence and to manage financial affairs responsibly. A board that has never formally approved its privacy policy cannot demonstrate that duty was discharged, no matter how good the policy document looks on paper.

  • Board minutes should record the resolution wording, not just "policy noted"
  • The CEO's sign-off on procedures should be dated and version-controlled separately from the policy
  • An annual review calendar should list which policies are due for board re-approval and when

Pro Tip: Draft your resolution wording before the meeting, not during it. "The board approves the Privacy Policy dated [date], superseding the version approved [date]" leaves no ambiguity for an auditor six months later.

Our guide to what boards must get right covers this separation of duties in more depth, and the policy versus procedure distinction is worth reading if your board has never formally agreed on where the line sits.

How do you map policies to regulatory standards?

Build a simple matrix: one row per policy, one column for the standard or rule it serves, one column for the evidence you hold. This single artefact does more to speed up an audit than any amount of extra policy text.

For charities registered with the ACNC, your conflict of interest policy and Responsible People register map directly to Governance Standard 5's duties, while your governing document and public reporting map to Standard 1. If you are a registered NDIS provider, your incident management and complaints policies need to sit against the specific quality indicators in the NDIS Practice Standards, which are broken into core, supplementary, and verification modules depending on what you deliver.

  • Complaints handling policy → NDIS core module, complaints management indicator
  • Financial controls policy → ACNC Governance Standard 5, financial responsibility duty
  • Privacy policy → funder due diligence checklist, Australian Privacy Principles

Where your organisation operates across state-based schemes as well, such as aged care or child safety frameworks, the mapping gets more complex and jurisdiction-specific. That is the point where it is worth bringing in specialist legal or NDIS advice rather than guessing at overlap.

A workable process for developing and reviewing your suite

Most policy suite projects stall not from lack of will but from lack of a repeatable process. Four stages keep it moving:

  1. Audit — list every existing policy and procedure, then flag the gaps. The most common ones we find are missing adoption minutes, no supporting register, and procedures that were never updated after a policy changed.
  2. Draft — start from an authoritative template, not a blank page. The Institute of Community Directors policy bank offers free templates, but every one needs adapting to your organisation's size, risk profile, and activities before it goes anywhere near a board agenda.
  3. Adopt — convene the board, record the resolution, assign an owner for each procedure, and set the next review date at the same meeting.
  4. Monitor — version control, a compliance calendar, and a short annual spot-check of whether procedures still match practice.

Preparing one indexed evidence folder and a single mapping matrix per major regulator is a small investment that often separates funded applications from unfunded ones when funders run due diligence.

A gap analysis process built for this exact workflow will save your board a lot of back-and-forth in step one.

What auditors and funders actually want to see

Auditors do not read policy text closely. They look for the record that the policy was acted on. That is the whole game.

The items that speed up an audit or grant assessment consistently include:

  • Dated board minutes showing the resolution to approve each policy
  • Signed Responsible People undertakings and declarations
  • A current conflict-of-interest register with entries, not just a blank template
  • Training records showing staff were briefed on the policy, not just handed a copy
  • A financial approval trail matching your delegations policy
Evidence ItemWhat It Proves
Dated board minutesPolicy was formally approved, not just circulated
Signed declarationsResponsible People duties were personally acknowledged
Conflict register entriesConflicts were actively managed, not just policy-permitted
Training logsStaff understood and applied the procedure

Keep these in a single indexed evidence folder rather than scattered across shared drives, and set retention periods and access controls so the right people can find the right document quickly. A governance policy gaps guide walks through what these gaps look like in practice.

A small disability service closes its evidence gap

A mid-sized disability service, registered with the NDIS and running two government grants, came to a governance review with policies that read well but had no adoption trail behind them. No board minutes referenced the privacy or incident management policies. No conflict register existed at all.

The board prioritised three policies first: incident management, complaints handling, and financial delegations, because those mapped directly to NDIS audit requirements and grant conditions.

  • Each policy went to the board with resolution wording drafted in advance
  • A conflict register was built and backdated declarations collected from all directors
  • Adoption dates were recorded against the compliance calendar for annual review

Within one review cycle, the organisation's next NDIS audit took a fraction of the preparation time it had before, and its grant renewal application included the evidence folder as an attachment rather than a scramble.

What most boards get wrong about policy work

The pitfall we see most often is treating policy as a writing exercise rather than a governance system. A beautifully worded document with no board minute behind it protects nobody, and it certainly won't hold up under an NDIS audit or a funder's due diligence check. The organisations that get this right treat every policy as a piece of evidence from the day it is drafted, not something retrofitted after the fact.

Take this to your next board meeting: for each policy on our register, can we produce the minute that approved it and the register entry that proves it was applied?

How The Planning and Practice Hub can build your suite with you

If your board has identified the gaps but not the time to close them, that is where a scoped policy suite engagement earns its place. The Planning and Practice Hub works with boards and executives to build the policy pack, map it against ACNC and NDIS requirements, and assemble the evidence folder that auditors and funders actually want to see.

The Planning and Practice Hub

This is not a template drop and goodbye. Our approach, shaped by founder Rachel Willis's near three decades across governance and compliance in human services, means every policy is drafted against your organisation's actual risk profile and adopted through a proper board process, not handed over as generic paperwork. If your suite needs standards mapping specifically, our quality and compliance consulting work covers that in detail, and our compliance calendar tool keeps your review dates from slipping once the suite is live.

The next step is simple: get in touch through our services page and ask for a scoped quote against your current policy gaps.

Sources

FAQ

What is the difference between an NFP policy and a procedure?

A policy states the board's position and risk appetite on an issue. A procedure sets the operational steps staff follow to deliver on that policy, and it's owned by the CEO or executive team.

Which policies do funders check first?

Funders and auditors most commonly request evidence of privacy, financial controls, and complaints or incident management policies, along with board minutes proving adoption.

How often should an NFP review its policy suite?

Most boards set an annual review calendar, though high-risk policies like incident management or financial delegations may warrant a more frequent check if activities or regulations change.

Do NDIS providers need extra policies beyond ACNC requirements?

Yes. Registered NDIS providers must map relevant policies against the specific quality indicators in the NDIS Practice Standards, which sit alongside, not instead of, ACNC Governance Standards obligations.

Can The Planning and Practice Hub help build a policy suite from scratch?

Yes. The Planning and Practice Hub develops policy packs, maps them against ACNC and NDIS requirements, and helps assemble the evidence folder boards need for audits and grant applications.