Skip to content
`Guide

School policy and compliance: the chain from the Act to the evidence

A policy on the school website is the middle of a chain, not the end of one. This guide walks the whole chain, from the Act that creates a duty to the evidence that shows the school met it.

An overhead working chain from Act to obligation, policy, procedure and evidence laid across a warm school administration table.

When the assessor asks which version, you already know.

In one paragraph

School policy and compliance is the chain that connects legislation to the proof that a school does what it says

An Act from its authoritative source, an obligation with an owner, a controlled policy that answers it, a procedure that makes it executable, a recurring compliance item that keeps it true, and accepted evidence.

  1. An Act, recorded from its authoritative source

    A school sets an applicability profile (country, state, sector, school type and conditions), enables the jurisdictions in scope, and every record carries its source, version and effective date, with a status of Current, Review required, Superseded, Repealed or Not applicable.

  2. An obligation with an owner

    What the Act requires of this school, organised into operating domains such as child safety or privacy, each with a requirement, an owner, a status and the evidence that satisfies it.

  3. A policy that answers it

    An authoritative statement of intent, held as a controlled version with an owner, a reviewer and an approver, and traced on its Legislation tab to the obligations it covers.

  4. A procedure that makes it executable

    The policy says what the school intends; the procedure says how it is done, as a trigger, ordered steps, roles, records and an exception path.

  5. A recurring compliance item that keeps it true

    A policy that says "annually" needs a record that makes it happen: one owner, a recurrence rule and an evidence definition.

  6. Evidence that proves it

    Submitted against an occurrence and accepted by a reviewer; only accepted evidence moves the item to Compliant.

Built to scale

Run at any scale. From one campus to a diocese, with every entity reporting the same way.

Switch
from your existing platform, for a low cost
25
policy domains help you make sense of the policies you have, and the ones you need
Every regulator
in Australia and New Zealand supported
Safe
data, processing and AI based in Sydney and Melbourne via AWS

Coverage spans the eight Australian states and territories, with Commonwealth law applying across all of them, and separately New Zealand. Domain figures come from the PolicyAI Research Atlas, refreshed weekly.

The concept is set out on Policy and obligations, and the register of Acts and obligations behind it is PolicyAI.

The policy lifecycle: draft, review, approve, publish, acknowledge, review date

A policy library goes stale in the gaps between those six words, so it helps to be exact about each one.

  1. Draft

    A policy enters as a draft, never as approved text. Upload a PDF or Word file and correct the extracted body and metadata in a preview before the draft exists, or start from a template with Draft with AI proposing sections from your organisation's context, applied only when a person accepts them.

  2. Review

    A reviewer opens Proposed changes and sees the exact difference and the rationale, with comments resolved on the diff before anything moves to approval.

  3. Approve

    While approval is incomplete the version never replaces the published one, and when approval is recorded the approver, the decision time and the hash of the approved content are immutable: the board has signed exact words, not a filename.

  4. Publish

    The approved version becomes current and the earlier one stays in Version History, openable, comparable and downloadable. An approved version is never edited in place; a change means a new draft, a new review and a new approval.

  5. Acknowledge

    Publish to an audience and the Acknowledgements ledger shows who is required to read it, who has, and who needs a reminder. A person does the acknowledging.

  6. Review date

    Every Overview carries owner, version, approval authority, effective date, review date and a status from Draft to Published, Superseded and Retired, with due soon and overdue shown against the date.

The lifecycle runs inside Personnel, described on the school policy software page; if your library still lives in a drive, the policy register template gives you the five columns to start with: the policy, its owner, its approval gate, its next review date and its status.

Procedures versus policies

Business managers tell us the incident call tree lives in one person's head, and that person is on leave when it matters. Principals tell us the policy was updated and the procedure beneath it never was. A policy states the organisation's intent and rules; a procedure is the executable steps, roles and records that put the intent into practice.

A procedure carries its own owner, approver, effective date and review date, and describes the trigger, the ordered steps, the roles that perform them, the inputs, outputs and records, and the exception path. It has its own diff for proposed changes and an immutable history, so an incident review can reconstruct which version applied that day. When the policy above it is superseded, the owner receives a review-required signal and the published procedure, the only version staff see, stays as it is until a person approves a new one. The module is described on Procedures.

School governance actions with named owners and evidence

The compliance calendar, and the association calendars

Business managers tell us the state calendar arrives as a PDF and is copied into a spreadsheet each January. Compliance officers tell us they cannot say whether "done" means submitted, reviewed or genuinely compliant.

Each obligation becomes a compliance item with a requirement, one owner, a reference, a recurrence rule (weekly, monthly, quarterly, yearly, term or once-off) and an evidence definition with a named reviewer, and one template generates the dated occurrences that the Overview, Calendar and Table views all share. Statuses run Scheduled, Due soon, Overdue, In progress, Submitted, Compliant, Exception and Not applicable. Submitted does not count as Compliant until a reviewer accepts the evidence, and where an obligation cannot be met or does not apply, an exception carries a rationale, conditions, an expiry and an approving authority.

The library holds the state association calendars (AISSA, ISV, AISNSW, ISQ and AISWA) as profiles: load the profile, prune it to your school, and the occurrences are generated for you. Each obligation traces to the association guidance and the legislation it rests on, so when the source changes the connected obligations are flagged for review and the owner is notified.

The module is described on the compliance calendar page, the principle on compliance connected to the associations, and the compliance calendar template lays the year on paper first, with an owner and an evidence column.

School Compliance Software Australia: Compliance Calendar

Faith-based and ethos-preserving policy

In a faith-based school a policy does two jobs at once. It must meet state education standards, child safety frameworks and workplace obligations, and it must align with the theological, philosophical or cultural identity of the school, so the board governs both the compliance and the alignment.

The failure patterns are quiet: review dates tracked in spreadsheets, board approvals recorded in minutes only with no link to the document version, some policies reviewed annually while others drift, and directors relying on termly reports rather than live visibility. They are signs that policy governance is running on goodwill rather than infrastructure, and in a dispute or a regulatory review the policy history is what matters.

Strong policy management here adds one thing to the lifecycle above: an alignment check, so each update stays consistent with mission and values. The controlled lifecycle makes that check evidence rather than intention: the approver signs the exact words and the version history shows what changed. Dave Yeates set this out in Policy management for faith-based schools.

The sandstone cloister of a faith-based school, its arches opening onto a courtyard.
In brief

When the law moves: legislative change and PolicyAI, in beta

Principals tell us they usually learn of a change when a colleague at another school mentions it. The chain is built so the change arrives through the register instead. When an authoritative source changes, the Change Monitor raises a review-required change event without altering the prior version.

Get in contact

  • 25policy domains as
Everything you asked us, answered

The seven we are asked every time.

Still weighing something up? Thirty minutes with us, on your own registers, answers the rest.

Get in contact
  1. 01What is the difference between a policy and a procedure?

    A policy states the organisation's intent and rules; a procedure is the executable steps, roles and records that put it into practice. EthosOne holds them as separate controlled documents, each with its own owner, approval and review date.

  2. 02How often should school policies be reviewed?

    On the review date set on the policy's Overview, and immediately when the Change Monitor raises a change event against an obligation the policy covers. A policy is due for review the day its source law moves.

  3. 03What counts as evidence of compliance?

    Something submitted against a specific occurrence of a compliance item and accepted by the named reviewer. Until acceptance the item reads Submitted, not Compliant, and the reviewer, the decision time and the evidence version are recorded on acceptance.

  4. 04Do we still need our own compliance calendar if the association publishes one?

    The association calendar is the starting population. EthosOne holds the AISSA, ISV, AISNSW, ISQ and AISWA calendars in its library, so you load the profile, prune it to your school, add the streams that are yours alone, and put an owner and an evidence rule on every item.

  5. 05How do we know which legislation applies to our school?

    Set up the applicability profile with country, state, sector, school type and conditions, enable the jurisdictions in scope, and the catalogue scopes to that context. An accountable person confirms applicability, and the Change Monitor raises a review when a source moves.

  6. 06Is PolicyAI the same as the policy library?

    No. HR Compliance is the governed library, a Focus module at $5,000 a year, and it runs on its own. PolicyAI is a separate Premium module in beta that reads that library and scores coverage across 25 policy domains.

  7. 07School policy and compliance: from the Act to the evidence, in full: what does it cover?

    EthosOne, governance, risk and compliance software built only for schools, holds every link as a record with an owner. PolicyAI, in beta, reads across the chain and scores coverage across 25 policy domains on AccuFind legislative intelligence: the consolidated primary-source law of the Commonwealth, every Australian state and territory, and New Zealand, refreshed weekly.

When the assessor asks which version,you already know.

The chain from an Act to an obligation, a policy, a procedure, a compliance item and evidence, for schools.