Skip to content

Checklist

Policies every NGO should have: a checklist

Policies turn good intentions into habits that funders can check. Here are the ones every NGO needs, what each should say, which the law requires, which funders ask for, and how to adopt and review them.

SocioStory Knowledge desk

Reviewed 10 min read

At a glance10 min read

  • Some duties come straight from the law: an Internal Committee under the POSH Act once you have 10 or more employees, POCSO’s duty to report child sexual abuse, and appointment letters for every worker under the Labour Codes.
  • The main duties of the Digital Personal Data Protection Rules, 2025 apply from 13 May 2027, so an NGO holding donors’ or beneficiaries’ data should have a data protection policy ready before then.
  • CSR teams commonly ask for financial controls, conflict of interest, safeguarding and POSH policies as part of their due diligence.
  • A policy counts only if the board adopts it, people know it and it is reviewed: minute the adoption, date each version and review it at least once a year.
  • A small NGO can start with five core policies and add the rest as it grows, but if it works with children, a safeguarding policy is essential from the first day.
On this page
  1. The policy set at a glance
  2. Policies that put legal duties into practice
  3. What the other core policies should cover
  4. Starting small: the first five
  5. How to adopt and review policies
  6. Common mistakes
  7. Questions people ask
  8. Sources

Every NGO in India should have written policies on financial controls and procurement, conflicts of interest, safeguarding, preventing sexual harassment, human resources and data protection, and, as it grows, on whistle-blowing, volunteers, fraud and corruption, gifts, travel, communications and consent, and the environment. Some of these put legal duties into practice; others are what funders expect to see before they give money.

A policy is a short, plain statement of what the organisation will do and who is responsible for it. It turns good intentions into habits, protects the people you work with, and shows a funder that you manage risk rather than hope for the best. But a policy that sits in a folder protects no one: it has to be adopted by the board, known by staff and volunteers, and followed.

This checklist lists fifteen policies, what each should cover, which the law requires and which funders ask for, and how to adopt and review them. It is for founders, small NGO teams and board members.

The policy set at a glance

PolicyWhat it coversThe law’s role
Financial controls and procurementWho approves spending, two signatories, quotes, cash limits, bank reconciliationsTax law penalises cash and poor records
Conflict of interestDeclaring interests, a register, stepping out of decisionsTax law taxes benefits to related persons
Safeguarding and child protectionKeeping children and vulnerable adults safe; reporting concernsPOCSO’s duty to report applies to everyone
Prevention of sexual harassment (POSH)The Internal Committee, complaints and awarenessRequired: an Internal Committee at 10 or more employees
Human resourcesRecruitment, contracts, pay, leave, conduct, grievancesLabour Codes: appointment letters, minimum wages, social security
Data protection and privacyWhat personal data you collect, why, how it is kept and deletedDPDP Act and Rules: main duties from 13 May 2027
Whistle-blowingA safe way to raise concerns, with protection from retaliationGood practice for NGOs
VolunteersRoles, age, screening, induction, safety, recognitionPOSH counts volunteers as employees
Anti-fraud and anti-corruptionPreventing, detecting and responding to fraud and briberyGood practice; foreign donors often ask
Gifts and hospitalityWhat staff and board members may accept or giveGood practice
Travel and expensesWhat can be claimed, approvals and receiptsGood practice; supports clean accounts
Communications, consent and photosConsent for stories and images; never identifying children at riskThe JJ Act and POCSO bar identifying certain children
Reserves and investmentHow much to hold, where surplus money may be investedThe Income-tax Act limits where an NGO may invest
Information technology and social mediaPasswords, devices, accounts, official channelsGood practice; supports data protection
EnvironmentReducing waste, energy and travel in your own workGood practice; some funders ask

CSR teams most commonly ask for the first four. Foreign donors and larger foundations often add whistle-blowing and anti-fraud.

Preventing sexual harassment (POSH)

The Sexual Harassment of Women at Workplace (Prevention, Prohibition and Redressal) Act, 2013 protects every woman at a workplace, whatever her age or employment status. Its definition of “employee” covers people working for no pay and on a voluntary basis, and trainees and apprentices. An NGO with 10 or more employees must set up an Internal Committee: a Presiding Officer who is a senior woman employee, at least two other employees, and one external member from an NGO or association committed to women’s causes, with at least half the members women. Complaints can be made within three months, extendable by another three, and the inquiry must finish within 90 days. Smaller workplaces use the district’s Local Committee. A first violation of the Act can bring a penalty of ₹50,000. A POSH policy explains all this in plain words; see POSH for NGOs.

Safeguarding and child protection

No single law requires every NGO to have a written child protection policy, but the law sets duties the policy must reflect. Under section 19 of the Protection of Children from Sexual Offences Act, 2012 (POCSO), anyone who knows or suspects that a sexual offence against a child has been or may be committed must report it to the police or the Special Juvenile Police Unit; not reporting is an offence, and a person in charge of an institution faces a heavier penalty. POCSO (section 23) and the Juvenile Justice Act, 2015 (section 74) bar publishing anything that could identify child victims or children in need of care and protection. An institution that houses children in need of care must be registered under the JJ Act (section 41).

A good policy covers a code of conduct, safe recruitment and background checks, the two-adult rule (never one adult alone with a child), photos and online safety, a named safeguarding lead and a reporting route that sends concerns to the police without delay. See child protection and safeguarding.

Data protection

The Digital Personal Data Protection Act, 2023 applies to any organisation handling digital personal data, charities included. Under the DPDP Rules, 2025, its main duties for organisations apply from 13 May 2027: clear consent notices for a specific purpose, collecting only what you need, reasonable security, telling affected people and the Data Protection Board about a breach (with a detailed report within 72 hours), a contact for questions, honouring people’s rights, and deleting data you no longer need. For anyone under 18, you need verifiable consent from a parent or guardian. Penalties run up to ₹250 crore. Start now; see data protection for NGOs.

Human resources

The four Labour Codes have been in force since 21 November 2025. Every worker must get an appointment letter, minimum wages apply to all, working hours are capped, provident fund applies from 20 employees, and fixed-term staff get gratuity after one year of service. An HR policy covers recruitment, contracts, pay, leave, working hours, conduct, discipline and grievances. Remember that unpaid volunteers generally aren’t employees for wages and social security, but the POSH Act counts them. See the labour codes for NGOs.

What the other core policies should cover

Financial controls and procurement: who can approve how much; two signatories or two approvals for payments; written quotes above a set amount (often three for larger purchases); no splitting of orders to avoid limits; a petty cash limit; monthly bank reconciliations; a fixed asset register. It also helps you keep the tax rules: cash payments of more than ₹10,000 to one person in a day generally don’t count as spending on your objects, and receiving ₹2 lakh or more in cash from one person in a day is barred (Section 186 of the Income-tax Act, 2025, formerly section 269ST).

Conflict of interest: what counts as an interest; a declaration by every board member, staff member and adviser on joining and every year; a register; stepping out of decisions; how the board approves any dealing with a related person. See the NGO board.

Whistle-blowing: who can raise a concern (staff, volunteers, partners, community members), how (a named person, an email address, a route around management), confidentiality, protection from retaliation, and how concerns are investigated and reported to the board.

Anti-fraud and anti-corruption: no bribes or facilitation payments, separation of duties, surprise checks, what to do when fraud is suspected, recovering losses and telling funders.

Volunteers: the roles volunteers can and can’t do, a minimum age, screening, induction, supervision, insurance and safety, recording hours honestly and recognition. See working with volunteers.

Communications, consent and photos: informed consent in a language people understand, the right to withdraw it, no identifying details of children at risk or survivors, dignity in images, and removing location data from photos. See consent, photos and dignity.

Reserves and investment: how many months of costs to hold in reserve, who decides, and a rule that surplus money is invested only in the forms Section 350 of the Income-tax Act permits.

Starting small: the first five

A new NGO can’t write fifteen policies in its first month, and shouldn’t try. Adopt these five first:

  1. Financial controls and procurement, before the first rupee is spent.
  2. Conflict of interest, with the first declarations at the first board meeting.
  3. Safeguarding and child protection, before any work with children or vulnerable adults begins.
  4. Prevention of sexual harassment, with an Internal Committee once you reach 10 employees.
  5. Data protection, before you start collecting beneficiaries’ or donors’ details.

Add HR, whistle-blowing, volunteers and the rest within the first year or two, as you hire and grow.

How to adopt and review policies

  1. Write for your organisation. Start from a good model if you like, but change the names, roles, limits and procedures to fit how you actually work.
  2. Have the board adopt it by resolution, and minute the decision with the date.
  3. Give every policy a version number, an owner and a review date.
  4. Tell people. Brief staff and volunteers, get a signed acknowledgement, and translate key policies into the languages your team uses.
  5. Publish the ones others need: how to raise a safeguarding concern, a POSH complaint or a whistle-blowing report.
  6. Review every year, and whenever the law changes or something goes wrong.
PolicyOwnerAdoptedNext review
Financial controls and procurementTreasurer12 June 2026June 2027
Safeguarding and child protectionSafeguarding lead12 June 2026June 2027
Data protectionProgramme manager9 January 2027Before 13 May 2027

A register like this, kept with the board papers, shows a funder at a glance that your policies are alive.

Common mistakes

  • Policies copied from another organisation that still carry its name or describe roles you don’t have.
  • Policies that promise what you can’t do, such as monthly external audits.
  • Safeguarding procedures that delay or filter reports to the police.
  • Never training anyone, so nobody knows the policy exists.
  • No review since adoption, so the policy still describes laws that have changed.

The Academy’s Safeguarding for leaders course covers safe practice, consent and reporting in depth, and Starting an NGO shows how policies fit into good governance from day one.

Questions people ask

Which policies are mandatory for an NGO in India?

No law lists a full set, but some duties are compulsory: an Internal Committee under the POSH Act once you have 10 or more employees, appointment letters and minimum wages under the Labour Codes, POCSO’s duty to report child sexual abuse, and, from 13 May 2027, the main duties of the DPDP Rules. Written policies are how an NGO shows it meets them.

Does a small NGO need a POSH policy?

The POSH Act protects women at every workplace, whatever its size. An Internal Committee is compulsory only at 10 or more employees, and the Act’s definition of an employee includes people working without pay or as volunteers. Smaller NGOs rely on the district’s Local Committee, but should still have a short policy explaining how to complain.

What should an NGO’s child protection policy include?

A code of conduct, safe recruitment and background checks, the two-adult rule, rules on photos and online contact, a named safeguarding lead, training, and a reporting procedure that sends concerns about sexual offences to the police or Special Juvenile Police Unit without delay, as POCSO requires. It should also bar publishing anything that identifies a child at risk.

Do NGOs need a data protection policy?

Yes, if they hold digital personal data about donors, beneficiaries, staff or volunteers. The DPDP Act, 2023 applies to charities, and the main duties under the DPDP Rules, 2025 apply from 13 May 2027, including consent notices, security, breach reporting and verifiable parental consent for anyone under 18.

Which policies do CSR funders ask for?

Most commonly financial controls and procurement, conflict of interest, safeguarding and child protection, and POSH. Larger funders and foreign donors often add whistle-blowing, anti-fraud and data protection. They look for policies the board has adopted and actually uses, not documents written the week before the visit.

Sources

  1. The POSH Act, 2013: backgrounder (February 2026) · Press Information Bureau
  2. The Protection of Children from Sexual Offences Act, 2012 · India Code, Ministry of Law and Justice
  3. Digital Personal Data Protection Rules, 2025: backgrounder · Press Information Bureau
  4. The four Labour Codes made effective (21 November 2025) · Press Information Bureau
  5. Income-tax Act, 2025 (Sections 186, 341 and 350) · Gazette of India

Go deeper in the Academy

Your work deserves a story.

Tell us what you’ve done. Our editors will help you shape it, free.

Share your story
  • People and safeguarding

    Child protection and safeguarding for NGOs

    Any organisation that works with children must keep them safe, and act fast when something is wrong. Here is what the law requires, what a good policy contains and exactly what to do if you are worried about a child.

    Guide · 11 min read

  • People and safeguarding

    POSH: preventing sexual harassment at NGOs

    The POSH Act protects women at every workplace, NGOs included, and its idea of an employee takes in volunteers and interns. Here is what your organisation must set up, how a complaint is handled and what you must report each year.

    Guide · 11 min read

  • People and safeguarding

    Data protection for NGOs: the DPDP Act and Rules

    India’s data protection law applies to charities as much as to companies, and its main duties start on 13 May 2027. Here is what counts as personal data, what you will have to do, and how to get ready now.

    Guide · 10 min read

  • Funding for NGOs

    The documents CSR teams will ask for

    Before it funds you, a company’s CSR team will ask for a set of documents and check them against public records. Here is the full list, why each one matters, how to keep a ready data room, and what to keep private.

    Checklist · 9 min read