Checklist
Policies every NGO should have: a checklist
Policies turn good intentions into habits that funders can check. Here are the ones every NGO needs, what each should say, which the law requires, which funders ask for, and how to adopt and review them.
At a glance10 min read
- Some duties come straight from the law: an Internal Committee under the POSH Act once you have 10 or more employees, POCSO’s duty to report child sexual abuse, and appointment letters for every worker under the Labour Codes.
- The main duties of the Digital Personal Data Protection Rules, 2025 apply from 13 May 2027, so an NGO holding donors’ or beneficiaries’ data should have a data protection policy ready before then.
- CSR teams commonly ask for financial controls, conflict of interest, safeguarding and POSH policies as part of their due diligence.
- A policy counts only if the board adopts it, people know it and it is reviewed: minute the adoption, date each version and review it at least once a year.
- A small NGO can start with five core policies and add the rest as it grows, but if it works with children, a safeguarding policy is essential from the first day.
On this page
Every NGO in India should have written policies on financial controls and procurement, conflicts of interest, safeguarding, preventing sexual harassment, human resources and data protection, and, as it grows, on whistle-blowing, volunteers, fraud and corruption, gifts, travel, communications and consent, and the environment. Some of these put legal duties into practice; others are what funders expect to see before they give money.
A policy is a short, plain statement of what the organisation will do and who is responsible for it. It turns good intentions into habits, protects the people you work with, and shows a funder that you manage risk rather than hope for the best. But a policy that sits in a folder protects no one: it has to be adopted by the board, known by staff and volunteers, and followed.
This checklist lists fifteen policies, what each should cover, which the law requires and which funders ask for, and how to adopt and review them. It is for founders, small NGO teams and board members.
The policy set at a glance
| Policy | What it covers | The law’s role |
|---|---|---|
| Financial controls and procurement | Who approves spending, two signatories, quotes, cash limits, bank reconciliations | Tax law penalises cash and poor records |
| Conflict of interest | Declaring interests, a register, stepping out of decisions | Tax law taxes benefits to related persons |
| Safeguarding and child protection | Keeping children and vulnerable adults safe; reporting concerns | POCSO’s duty to report applies to everyone |
| Prevention of sexual harassment (POSH) | The Internal Committee, complaints and awareness | Required: an Internal Committee at 10 or more employees |
| Human resources | Recruitment, contracts, pay, leave, conduct, grievances | Labour Codes: appointment letters, minimum wages, social security |
| Data protection and privacy | What personal data you collect, why, how it is kept and deleted | DPDP Act and Rules: main duties from 13 May 2027 |
| Whistle-blowing | A safe way to raise concerns, with protection from retaliation | Good practice for NGOs |
| Volunteers | Roles, age, screening, induction, safety, recognition | POSH counts volunteers as employees |
| Anti-fraud and anti-corruption | Preventing, detecting and responding to fraud and bribery | Good practice; foreign donors often ask |
| Gifts and hospitality | What staff and board members may accept or give | Good practice |
| Travel and expenses | What can be claimed, approvals and receipts | Good practice; supports clean accounts |
| Communications, consent and photos | Consent for stories and images; never identifying children at risk | The JJ Act and POCSO bar identifying certain children |
| Reserves and investment | How much to hold, where surplus money may be invested | The Income-tax Act limits where an NGO may invest |
| Information technology and social media | Passwords, devices, accounts, official channels | Good practice; supports data protection |
| Environment | Reducing waste, energy and travel in your own work | Good practice; some funders ask |
CSR teams most commonly ask for the first four. Foreign donors and larger foundations often add whistle-blowing and anti-fraud.
Policies that put legal duties into practice
Preventing sexual harassment (POSH)
The Sexual Harassment of Women at Workplace (Prevention, Prohibition and Redressal) Act, 2013 protects every woman at a workplace, whatever her age or employment status. Its definition of “employee” covers people working for no pay and on a voluntary basis, and trainees and apprentices. An NGO with 10 or more employees must set up an Internal Committee: a Presiding Officer who is a senior woman employee, at least two other employees, and one external member from an NGO or association committed to women’s causes, with at least half the members women. Complaints can be made within three months, extendable by another three, and the inquiry must finish within 90 days. Smaller workplaces use the district’s Local Committee. A first violation of the Act can bring a penalty of ₹50,000. A POSH policy explains all this in plain words; see POSH for NGOs.
Safeguarding and child protection
No single law requires every NGO to have a written child protection policy, but the law sets duties the policy must reflect. Under section 19 of the Protection of Children from Sexual Offences Act, 2012 (POCSO), anyone who knows or suspects that a sexual offence against a child has been or may be committed must report it to the police or the Special Juvenile Police Unit; not reporting is an offence, and a person in charge of an institution faces a heavier penalty. POCSO (section 23) and the Juvenile Justice Act, 2015 (section 74) bar publishing anything that could identify child victims or children in need of care and protection. An institution that houses children in need of care must be registered under the JJ Act (section 41).
A good policy covers a code of conduct, safe recruitment and background checks, the two-adult rule (never one adult alone with a child), photos and online safety, a named safeguarding lead and a reporting route that sends concerns to the police without delay. See child protection and safeguarding.
Data protection
The Digital Personal Data Protection Act, 2023 applies to any organisation handling digital personal data, charities included. Under the DPDP Rules, 2025, its main duties for organisations apply from 13 May 2027: clear consent notices for a specific purpose, collecting only what you need, reasonable security, telling affected people and the Data Protection Board about a breach (with a detailed report within 72 hours), a contact for questions, honouring people’s rights, and deleting data you no longer need. For anyone under 18, you need verifiable consent from a parent or guardian. Penalties run up to ₹250 crore. Start now; see data protection for NGOs.
Human resources
The four Labour Codes have been in force since 21 November 2025. Every worker must get an appointment letter, minimum wages apply to all, working hours are capped, provident fund applies from 20 employees, and fixed-term staff get gratuity after one year of service. An HR policy covers recruitment, contracts, pay, leave, working hours, conduct, discipline and grievances. Remember that unpaid volunteers generally aren’t employees for wages and social security, but the POSH Act counts them. See the labour codes for NGOs.
What the other core policies should cover
Financial controls and procurement: who can approve how much; two signatories or two approvals for payments; written quotes above a set amount (often three for larger purchases); no splitting of orders to avoid limits; a petty cash limit; monthly bank reconciliations; a fixed asset register. It also helps you keep the tax rules: cash payments of more than ₹10,000 to one person in a day generally don’t count as spending on your objects, and receiving ₹2 lakh or more in cash from one person in a day is barred (Section 186 of the Income-tax Act, 2025, formerly section 269ST).
Conflict of interest: what counts as an interest; a declaration by every board member, staff member and adviser on joining and every year; a register; stepping out of decisions; how the board approves any dealing with a related person. See the NGO board.
Whistle-blowing: who can raise a concern (staff, volunteers, partners, community members), how (a named person, an email address, a route around management), confidentiality, protection from retaliation, and how concerns are investigated and reported to the board.
Anti-fraud and anti-corruption: no bribes or facilitation payments, separation of duties, surprise checks, what to do when fraud is suspected, recovering losses and telling funders.
Volunteers: the roles volunteers can and can’t do, a minimum age, screening, induction, supervision, insurance and safety, recording hours honestly and recognition. See working with volunteers.
Communications, consent and photos: informed consent in a language people understand, the right to withdraw it, no identifying details of children at risk or survivors, dignity in images, and removing location data from photos. See consent, photos and dignity.
Reserves and investment: how many months of costs to hold in reserve, who decides, and a rule that surplus money is invested only in the forms Section 350 of the Income-tax Act permits.
Starting small: the first five
A new NGO can’t write fifteen policies in its first month, and shouldn’t try. Adopt these five first:
- Financial controls and procurement, before the first rupee is spent.
- Conflict of interest, with the first declarations at the first board meeting.
- Safeguarding and child protection, before any work with children or vulnerable adults begins.
- Prevention of sexual harassment, with an Internal Committee once you reach 10 employees.
- Data protection, before you start collecting beneficiaries’ or donors’ details.
Add HR, whistle-blowing, volunteers and the rest within the first year or two, as you hire and grow.
How to adopt and review policies
- Write for your organisation. Start from a good model if you like, but change the names, roles, limits and procedures to fit how you actually work.
- Have the board adopt it by resolution, and minute the decision with the date.
- Give every policy a version number, an owner and a review date.
- Tell people. Brief staff and volunteers, get a signed acknowledgement, and translate key policies into the languages your team uses.
- Publish the ones others need: how to raise a safeguarding concern, a POSH complaint or a whistle-blowing report.
- Review every year, and whenever the law changes or something goes wrong.
| Policy | Owner | Adopted | Next review |
|---|---|---|---|
| Financial controls and procurement | Treasurer | 12 June 2026 | June 2027 |
| Safeguarding and child protection | Safeguarding lead | 12 June 2026 | June 2027 |
| Data protection | Programme manager | 9 January 2027 | Before 13 May 2027 |
A register like this, kept with the board papers, shows a funder at a glance that your policies are alive.
Common mistakes
- Policies copied from another organisation that still carry its name or describe roles you don’t have.
- Policies that promise what you can’t do, such as monthly external audits.
- Safeguarding procedures that delay or filter reports to the police.
- Never training anyone, so nobody knows the policy exists.
- No review since adoption, so the policy still describes laws that have changed.
The Academy’s Safeguarding for leaders course covers safe practice, consent and reporting in depth, and Starting an NGO shows how policies fit into good governance from day one.
Questions people ask
- Which policies are mandatory for an NGO in India?
No law lists a full set, but some duties are compulsory: an Internal Committee under the POSH Act once you have 10 or more employees, appointment letters and minimum wages under the Labour Codes, POCSO’s duty to report child sexual abuse, and, from 13 May 2027, the main duties of the DPDP Rules. Written policies are how an NGO shows it meets them.
- Does a small NGO need a POSH policy?
The POSH Act protects women at every workplace, whatever its size. An Internal Committee is compulsory only at 10 or more employees, and the Act’s definition of an employee includes people working without pay or as volunteers. Smaller NGOs rely on the district’s Local Committee, but should still have a short policy explaining how to complain.
- What should an NGO’s child protection policy include?
A code of conduct, safe recruitment and background checks, the two-adult rule, rules on photos and online contact, a named safeguarding lead, training, and a reporting procedure that sends concerns about sexual offences to the police or Special Juvenile Police Unit without delay, as POCSO requires. It should also bar publishing anything that identifies a child at risk.
- Do NGOs need a data protection policy?
Yes, if they hold digital personal data about donors, beneficiaries, staff or volunteers. The DPDP Act, 2023 applies to charities, and the main duties under the DPDP Rules, 2025 apply from 13 May 2027, including consent notices, security, breach reporting and verifiable parental consent for anyone under 18.
- Which policies do CSR funders ask for?
Most commonly financial controls and procurement, conflict of interest, safeguarding and child protection, and POSH. Larger funders and foreign donors often add whistle-blowing, anti-fraud and data protection. They look for policies the board has adopted and actually uses, not documents written the week before the visit.
Sources
- The POSH Act, 2013: backgrounder (February 2026) · Press Information Bureau
- The Protection of Children from Sexual Offences Act, 2012 · India Code, Ministry of Law and Justice
- Digital Personal Data Protection Rules, 2025: backgrounder · Press Information Bureau
- The four Labour Codes made effective (21 November 2025) · Press Information Bureau
- Income-tax Act, 2025 (Sections 186, 341 and 350) · Gazette of India
Go deeper in the Academy
Free course with a certificate · Beginner · about 1 hour
Free course with a certificate · Beginner · about 4 hours
Free course with a certificate · Intermediate · about 3½ hours
Your work deserves a story.
Tell us what you’ve done. Our editors will help you shape it, free.
Share your storyRead next
People and safeguarding
Child protection and safeguarding for NGOs
Any organisation that works with children must keep them safe, and act fast when something is wrong. Here is what the law requires, what a good policy contains and exactly what to do if you are worried about a child.
Guide · 11 min read
People and safeguarding
POSH: preventing sexual harassment at NGOs
The POSH Act protects women at every workplace, NGOs included, and its idea of an employee takes in volunteers and interns. Here is what your organisation must set up, how a complaint is handled and what you must report each year.
Guide · 11 min read
People and safeguarding
Data protection for NGOs: the DPDP Act and Rules
India’s data protection law applies to charities as much as to companies, and its main duties start on 13 May 2027. Here is what counts as personal data, what you will have to do, and how to get ready now.
Guide · 10 min read
Funding for NGOs
The documents CSR teams will ask for
Before it funds you, a company’s CSR team will ask for a set of documents and check them against public records. Here is the full list, why each one matters, how to keep a ready data room, and what to keep private.
Checklist · 9 min read