Policies Every NPO Board Should Have (and Probably Doesn’t) — kaycie blog
← All posts
Governance 4 min read

Policies Every NPO Board Should Have (and Probably Doesn’t)

Nobody starts a grassroots NPO because they dreamed of writing policy documents. You start it because you saw a problem and wanted to fix it. But a handful of unglamorous documents, written once and revisited occasionally, quietly protect the organisation, its board, and the people it serves — far more than most founders realise until something goes wrong.

Financial management policy

This is the document that answers the boring-but-critical questions before a crisis forces you to answer them under pressure: who can approve an expense, and up to what amount? Who has signing authority on the bank account, and does it require two signatures? How are petty cash and reimbursements handled? Without this written down, financial decisions default to “whoever’s around at the time” — which is exactly how small, well-meaning organisations end up with disputes, or worse, exposure to fraud.

Conflict of interest policy

Beyond the legal disclosure requirements for directors, a clear policy sets expectations for the whole organisation — staff, volunteers, and board alike — about declaring relationships or interests that could influence decisions. It should also explain, in plain language, what happens once a conflict is declared: recusal, documentation, and sometimes independent review of the decision.

HR basics (even for volunteers)

If you have any paid staff at all, you need at minimum a basic employment policy covering hours, leave, disciplinary process, and grievance handling — South African labour law applies to non-profits just as it does to any other employer. Even for a purely volunteer organisation, a simple volunteer agreement covering expectations, code of conduct, and how the relationship can end protects both the organisation and the volunteer from misunderstandings down the line.

Whistleblowing / reporting policy

This is the one grassroots boards skip most often, usually because “we’re all friends here, surely we don’t need this.” But a clear, safe channel for someone — staff, volunteer, or beneficiary — to raise a concern about financial misconduct, abuse, or mismanagement, without fear of retaliation, is exactly what prevents small problems from festering into scandals. It doesn’t need to be complicated: even a simple “here’s who to contact, and here’s what happens next” document is far better than nothing.

Beneficiary protection and safeguarding policy

Especially critical for any organisation working with children, the elderly, or other vulnerable groups: a clear policy on how beneficiaries are treated, protected from harm, and given a way to raise concerns of their own. Funders increasingly ask for this specifically, and for good reason — it’s one of the areas where reputational damage from a failure can be catastrophic and near-impossible to recover from.

Document retention and data protection policy

South Africa’s Protection of Personal Information Act (POPIA) applies to NPOs too, particularly if you’re holding beneficiary records, donor details, or staff information. A simple policy on what personal information you collect, how long you keep it, and who can access it isn’t just good practice — it’s a legal obligation, and one that’s easy to overlook when the organisation’s focus is entirely on delivery.

Getting started without drowning in paperwork

You don’t need to write all of these in a weekend, and you definitely don’t need twenty-page legal documents. Start with the two or three that address your organisation’s biggest actual risk right now — usually financial management and conflicts of interest for most grassroots NPOs — and build from there. A one-page policy that’s actually read and followed beats a comprehensive one that lives in a folder nobody’s opened since it was written.

The bottom line

Policies aren’t bureaucracy for its own sake — they’re the organisation’s memory of “how we agreed to do this,” so decisions don’t have to be reinvented, and relitigated, every single time. Write them once, review them yearly, and treat them as a living part of how the organisation actually runs, not a compliance exercise to file away and forget.

kaycie handles this for you

Minutes, resolutions, compliance deadlines, 18A certificates — one trusted system that keeps the paper trail so your board doesn’t have to.

See what she does →
kaycie
Simple. Trusted. She handles the rest.
© 2026 kaycie Built by Brandzgro