New Zealand

Policy management software for New Zealand organisations

Keep pace with New Zealand’s dynamic regulatory environment — Privacy Act 2020, HSWA, Employment Relations Act and more. Automated, evidenced, and fully inside Microsoft 365.

How prepared is your organisation for New Zealand compliance?

WorkSafe NZ, the Privacy Commissioner, the FMA, and the Employment Relations Authority are well-resourced and increasingly active in enforcement. Ask yourself:

Not sure where your gaps are?

Take our free 5-minute compliance risk audit. Get an instant risk score, gap analysis, and sector-specific recommendations — no sign-up required.

New Zealand regulatory landscape

Key New Zealand regulations affecting your policy obligations.

New Zealand’s regulatory environment is dynamic, well-enforced, and increasingly aligned with international best practice. Click each regulation to understand your obligations.

Strengthened privacy obligations and mandatory breach notification

New Zealand’s Privacy Act 2020 replaced the 1993 Act with a significantly updated framework, aligning closely with international standards including the GDPR. It places clear obligations on how organisations collect, use, store, and share personal information.

  • All agencies must have clear, documented, and current privacy policies that reflect actual practice
  • Mandatory data breach notification — notify the Privacy Commissioner and affected individuals of serious harm breaches
  • Privacy policies must be communicated to relevant staff with evidence of that communication
  • The Office of the Privacy Commissioner has broad investigation and enforcement powers, including compliance notices and prosecution referrals

Primary duty of care and officer due diligence obligations

The HSWA is one of the most significant pieces of workplace legislation in New Zealand’s recent history, placing strong obligations on PCBUs, officers, and workers to actively manage health and safety.

  • Every PCBU has a primary duty to ensure worker health and safety — requiring documented, current, and communicated policies
  • Officers have a personal due diligence duty — including ensuring appropriate information management practices
  • Workers must be informed of, trained on, and acknowledge relevant WHS policies
  • WorkSafe NZ expects policies to be actively implemented, reviewed, and enforced — not just documented
  • Non-compliance: infringement notices, significant fines, or prosecution

Good faith obligations and employment policy documentation

New Zealand’s employment relations framework creates substantial obligations for employers to document, communicate, and consistently apply employment policies.

  • Employers must maintain up-to-date policies on disciplinary procedures, leave entitlements, and workplace expectations
  • The duty of good faith requires employers to keep employees informed of policies that affect them
  • Employers must retain evidence of employment documentation and policy acknowledgements
  • The Employment Relations Authority can scrutinise whether employers met documentation and communication obligations during disputes

Strengthened whistleblower protections and accessible disclosure procedures

New Zealand’s Protected Disclosures Act 2022 significantly strengthened protections for employees and others who report serious wrongdoing.

  • Public sector organisations must have accessible, documented internal procedures for protected disclosures
  • Best practice for all significant employers — clear whistleblowing policies with how to disclose, what protections apply, and how the organisation will respond
  • Whistleblowing procedures must be effectively communicated to all staff
  • Retaliation against whistleblowers is unlawful — organisations must evidence preventive measures

Governance and compliance obligations for financial services organisations

For financial service providers, fund managers, insurers, and other regulated entities, the FMCA and FMA guidance create specific governance, disclosure, and compliance management obligations.

  • Licensed entities must have compliance frameworks, documented internal policies, and systems demonstrating ongoing compliance
  • The FMA expects compliance policies to be current, distributed, and actively adhered to
  • Directors and senior managers have personal accountability for compliance governance
  • The FMA may review compliance documentation at short notice — requiring immediately producible policy records
Key enforcement agencies:
WorkSafe NZ
Privacy Commissioner
FMA
Employee Relations Authority
Why it matters

New Zealand's regulators are well-resourced and increasingly active.

WorkSafe NZ, the Office of the Privacy Commissioner, the FMA, and the Employment Relations Authority all have significant enforcement powers. The consequences of poor policy management are real.

Demonstrates regulatory seriousness
Shows regulators, auditors, and boards that your organisation has taken its compliance obligations seriously and proactively.
Protects your people
Ensures employees, customers, and third parties are informed of the standards expected of them — with evidence of that communication.
Reduces regulatory exposure
Current, accessible, evidenced policies remove the ambiguity that creates findings during WorkSafe inspections and Privacy Commissioner investigations.
Builds organisational resilience
A culture of accountability and transparency that sustains your organisation as New Zealand's regulatory landscape continues to evolve.
Practical framework

How to meet your New Zealand obligations.

A structured five-step approach — from employee education through to audit-ready evidence that satisfies WorkSafe NZ, the Privacy Commissioner, and the FMA.

1
Educate
Build structured programmes explaining your policy framework and the regulatory obligations that underpin it. Under HSWA and FMCA, demonstrating workers are informed is as important as the policies themselves.
2
Develop
Establish clear policies covering privacy, workplace safety, employment relations, financial compliance, and whistleblower protections. Version control is essential — regulators may scrutinise whether the acknowledged version was current at the time of an incident.
3
Distribute
A policy that is hard to find is a policy that will not be followed. Automated, targeted distribution by role, location, and employment type ensures comprehensive coverage without manual effort.
4
Monitor
Real-time tracking of who has acknowledged which policy — and who hasn't. Automated reminders and escalation workflows ensure outstanding attestations are resolved before they become regulatory findings.
5
Evidence
Comprehensive, timestamped audit trails for every policy action. Exportable reports for WorkSafe NZ, Privacy Commissioner, FMA, and internal audits — available on demand, not assembled under pressure.
How Xoralia help

Built for New Zealand organisations on Microsoft 365.

Xoralia automates the full policy lifecycle — helping New Zealand organisations distribute policies, track acknowledgements, and maintain the audit evidence that regulators require.

Policy library & Document management

A single, structured, searchable library inside SharePoint. Custom metadata and filtering ensure every employee finds the right, current policy. Automated version control and expiry tracking mean outdated policies are never circulated.

Automated workflows & Approvals

Multi-stage review and approval workflows reflecting your NZ governance requirements. From a simple approval to a complex multi-sign-off framework — Xoralia accommodates it, with escalation for overdue actions.

Targeted distribution & Audience management

Assign policies using Active Directory integration. A HSWA policy for warehouse workers, a privacy policy for customer service staff, an FMCA policy for your investment team — each distributed automatically to exactly the right people.

Employee attestation & Knowledge testing

Every acknowledgement is timestamped and auditable. For safety-critical or regulated roles, built-in knowledge testing verifies comprehension rather than just completion. Manager dashboards show real-time team compliance status.

Audit trail & Compliance reporting

Every policy action logged — creation through to archival. Exportable reports for WorkSafe NZ site visits, Privacy Commissioner inquiries, FMA reviews, and internal audits. Compliance readiness is continuous, not event-driven.

Microsoft 365 native

Runs inside your existing Microsoft 365 environment. Single sign-on through Azure Active Directory. Your data stays within your environment — no new platforms to procure or separate infrastructure to maintain.

Why Xoralia

Why New Zealand organisations choose Xoralia.

Designed for policy management
Built from the ground up for policy and procedure management — not adapted from a document manager. Xoralia does one thing and does it comprehensively.
Native to Microsoft 365
Xoralia runs inside your existing Microsoft 365 tenant. Your data never leaves your environment - stored in Microsoft's ANZ data centres, not offshore infrastructure.
Continuously audit-ready
Every policy action is logged from creation. When a regulator requests evidence, it is available immediately — not assembled under pressure the week before an inspection.
Multi-site capability
Supports targeted distribution by location — manage policies consistently across Auckland, Wellington, Christchurch, and any other site, with location-specific variations where required.
Fast to deploy, easy to run
Most New Zealand organisations are live within two to four weeks. Our onboarding team guides you through configuration, library setup, and staff enablement.
Transparent, scalable pricing
Per-user annual licensing with no hidden costs — scaling from small teams to large, multi-site organisations.
FAQs

Common questions — New Zealand compliance

Legislative change in Australia continues to reshape compliance requirements. Click each regulation to understand what it means for your policy management obligations.

Xoralia helps organisations manage obligations under the Privacy Act 2020, Health and Safety at Work Act 2015, Employment Relations Act 2000, Protected Disclosures (Protection of Whistleblowers) Act 2022, and Financial Markets Conduct Act 2013. Xoralia provides the platform infrastructure to manage, distribute, and evidence compliance — it does not provide legal advice.

Xoralia enables you to distribute WHS policies to relevant workers, track and evidence their acknowledgement, schedule regular policy reviews, and maintain a complete audit trail of every policy action — all of which support demonstrable due diligence capability under the HSWA.

Yes. Xoralia enables organisations to create, version-control, distribute, and evidence acknowledgement of privacy policies and data handling procedures — supporting obligations under the Privacy Act 2020 and demonstrating proactive governance to the Office of the Privacy Commissioner.

Most New Zealand organisations are live within two to four weeks. Our implementation team provides hands-on support throughout the process.

Yes. Xoralia supports targeted distribution based on location, role, and department — allowing organisations with offices across New Zealand to manage policies consistently while accommodating any location-specific differences.

Ready to bring order to compliance for your New Zealand organisation?

Automate your policy lifecycle. Evidence every acknowledgement. Stay permanently audit-ready — all inside Microsoft 365.

Start your FREE Xoralia trial!