WhatsApp contact icon for Nathan ISO Consulting
WhatsApp contact icon for Nathan ISO Consulting

Wellington organisations carry a category of obligation that barely exists elsewhere in New Zealand: accountability for how public functions are performed. Agencies, Crown entities and the providers delivering services on their behalf answer not only to regulators but to Parliament, to the Auditor-General, to the Ombudsman and to anyone who submits an information request.

That is a different compliance profile from a commercial one. The obligations concern integrity, transparency, proper use of public money and the ability to explain decisions, and failure surfaces publicly rather than through a private supervisory conversation.

Nathan ISO Consulting implements compliance management systems under ISO 37301:2021 for Wellington organisations across government agencies and Crown entities, financial institutions, agency service providers, health and education, and professional services.

Looking for an ISO 37301 Consultant in Wellington?

Why ISO 37301 Matters for Wellington Organisations

Public accountability is the first reason and it changes what evidence has to withstand. A compliance failure in a Wellington agency can become a select committee question, an Auditor-General finding or an Ombudsman opinion, each of which is published. Being able to show what the obligation was, who owned it and what controls operated is materially different from being able to explain it verbally afterwards.

Obligation density is the second. An agency simultaneously carries statutory functions under its own Act, machinery-of-government obligations covering integrity and conduct, financial management duties, information duties, employment obligations and whatever sector regulation applies. No single relationship covers it and no template captures it, because the combination is specific to the entity.

The third reason is supplier inheritance. Providers delivering agency services acquire obligations through contract that have no commercial equivalent: information request support, records management, conduct expectations and reporting duties. Businesses treating those as ordinary contract terms are frequently surprised by what they have accepted.

Why a Policy Library Fails Here Specifically

A policy states an intention. What a select committee, an Auditor-General enquiry or an Ombudsman investigation asks for is different: which obligation applied, who was accountable, what control was meant to operate, whether it operated, and what happened when it did not. That is a register with evidence attached, not a document set. The distinction matters more in Wellington than anywhere else in the country, because the questions are asked in public and the answers are published. Organisations that can only produce policies end up explaining their intentions while the findings describe their outcomes.

The Obligation Layers a Wellington Register Must Carry

LayerExamples Relevant to WellingtonWhat It Generates
Entity-specific statutory functionsThe Act establishing the agency or entity and the functions it confersFunctional duties, reporting obligations and limits on what the entity may do
Public sector integrity and conductStandards of integrity and conduct, and machinery-of-government expectationsConduct obligations, conflict management and accountability requirements
Public finance and accountabilityFinancial management duties, reporting and audit obligationsAppropriation compliance, annual reporting and audit response duties
Information obligationsOfficial information duties, privacy law and public records requirementsRequest handling within statutory timeframes, records retention and disposal
Financial regulationPrudential supervision and conduct licensing for financial institutionsLicence conditions, prudential standards and reporting obligations
Anti-money launderingReporting entity obligations supervised by sector-specific supervisorsRisk assessment, programme, due diligence, reporting and independent audit
Workplace and employmentHealth and safety duties, employment standards and good faith obligationsDuties, notification requirements and record keeping
Sector regulationHealth and disability standards, education regulation, care provider requirementsStandards, audit regimes and notification duties on independent cycles

Verify current regulator names, accountability requirements and licensing regimes before publishing. The combination applying to any given entity is specific, which is why registers here cannot be built from a template.

Wellington Precincts and the Wider Region

Wellington LocationBusiness ActivityCompliance Driver
Thorndon and PipiteaDepartments, ministries, Crown entities, statutory bodiesStatutory functions, integrity standards, public finance and information duties
The Terrace and Lambton QuayFinancial regulators, banks, insurers, market participantsPrudential and conduct supervision, licence conditions
CBD professional servicesLaw firms, accounting practices, consultanciesProfessional obligations and AML/CFT reporting entity duties
Agency supply chainICT suppliers, service providers, contracted delivery partnersContractual obligations covering information, records and conduct
Newtown and hospital precinctHealth providers, clinical services, aged careHealth and disability standards, notification duties, audit regimes
Kelburn and the university precinctTertiary institutions, research organisationsEducation regulation, funding conditions, research integrity requirements
Porirua and KāpitiCommunity and social services, education, local governmentContracted service obligations and accountability requirements
Not-for-profit and membership sectorSocieties, charities and associationsEntity obligations, charities reporting and officer duties
Regional deliveryProviders serving the region and nationally from WellingtonContract compliance across multiple funder relationships

Building a Register for an Entity Nobody Else Resembles

Commercial compliance registers can start from a sector template because organisations in the same industry carry broadly the same obligations. Public sector registers cannot, because the combination of statutory functions, machinery-of-government expectations and sector regulation is specific to the entity.

A register built properly here starts from the establishing legislation and works outward: what functions does the entity hold, what constrains how it performs them, what accountability obligations attach, and what sector regulation applies on top. That takes longer than adapting a template and it is the only approach that produces something defensible.

Ownership is the recurring friction, as it is everywhere. Where every obligation names the governance or legal team, an Auditor-General enquiry reads that as accountability having been centralised rather than accepted. Pushing obligations out to the people performing the functions is uncomfortable and is the most valuable part of the work.

Facing an audit, enquiry or agency contract needing a compliance system?

Our Wellington Delivery Approach

Step One – Scope and Build

Scoping starts from the establishing legislation or the licence, then works outward through accountability obligations, information duties, sector regulation and contractual requirements. The register is constructed from your own instruments rather than a sector template. Compliance risk assessment follows, producing a priority order that will survive board or committee scrutiny, then control mapping and the governance, reporting and monitoring arrangements.

Step Two – Assessment

Fewer bodies assess compliance management than quality or security, and fewer still operate here, so dates are secured well ahead. We look for assessors who have genuinely worked in regulated or public sector settings, agree commercial terms, and deliver readiness through internal audit and a minuted review. Both visits are attended.

Step Three – Keeping It Alive

Registers decay as legislation is amended, machinery-of-government changes take effect, licence conditions are varied and guidance is reissued. Maintenance is ours, alongside the audit cycle and surveillance readiness, so the register reflects the current position rather than the position at handover.

The Documentation You Receive

  • Obligation register. Each requirement carrying its source instrument, the function it attaches to, a named accountable owner and the control with supporting evidence.
  • Accountability mapping. Which obligations answer to which body, including Parliament, audit, the Ombudsman and sector regulators.
  • Risk ranking. Each obligation scored on how probable failure is and how serious it would be, giving a monitoring sequence defensible under public examination.
  • Control alignment. Existing practice measured against stated requirements, with shortfalls designed alongside the teams who will operate the controls.
  • Breach and reporting framework. Identification, threshold assessment, escalation and reporting to the correct body, with reasoning documented either way.
  • Governance reporting pack. Testing scope, frequency and method endorsed at board or committee level, with coverage and open items visible.

Where Wellington ISO 37301 Projects Go Wrong

  • A register adapted from a sector template, missing the statutory functions and accountability obligations specific to the entity
  • Policies presented as the compliance system, with no path from an obligation to evidence that a control operated
  • Information obligations treated as an administrative function rather than a compliance obligation with statutory timeframes
  • Suppliers accepting agency contract terms covering records, conduct and information support without registering them as obligations
  • A single team named against every obligation, which reads to an enquiry as responsibility concentrated rather than genuinely taken on
  • Testing carried out whenever someone finds time, instead of following a schedule with settled coverage and fixed intervals

Preparing for an upcoming audit?

Who Certifies You, and Where We Fit

We implement. An accredited body certifies.

Nathan ISO Consulting builds and implements management systems. We do not issue certificates, and no legitimate consultancy does. Your certificate comes from an independent certification body accredited by JAS-ANZ, the accreditation authority established jointly by the New Zealand and Australian governments. Accredited bodies operate under impartiality rules that prohibit them from certifying a system they helped build, which is precisely why the two roles are separate. Our job is to get you audit-ready, help you select the right accredited body, and stand alongside you through assessment.

Selecting the accredited body, negotiating the fee and fixing the dates are things we take on, matched to your scope, your sector and the audit approach that fits your operation. Our people are present for Stage 1 and Stage 2, and anything the assessor raises becomes our task rather than a list handed back when they leave. Do one check independently: confirm the JAS-ANZ register shows that body accredited for your scope. Unaccredited certificates are inexpensive and quick to obtain, and procurement teams turn them away often enough to make the check worth a minute.

Send Us the Establishing Legislation

For an agency or Crown entity, the Act creating you and the functions it confers is where the register starts. For a supplier, the agency contract schedules covering information, records and conduct are the equivalent.

Ready to start your ISO 37301 certification journey?

FAQ'S

No. We are an implementation consultancy. Certificates are issued by independent certification bodies accredited by JAS-ANZ. Accreditation rules prevent a body from certifying a system it helped build, so the consulting and certification roles must stay separate.

A JAS-ANZ accredited certification body of your choosing. We shortlist accredited bodies against your scope and sector, manage the quote process, and attend both audit stages with you. The certificate and the audit decision rest entirely with them.

Check the JAS-ANZ register and confirm the body is accredited for the specific standard and scope you need. Unaccredited certificates are widely available, inexpensive and routinely rejected by procurement teams, which means paying twice and starting over.

No consultancy honestly can, because the decision belongs to an independent auditor. What we can do is run your internal audit the way an external auditor would, close findings before assessment, and attend both stages so issues get resolved in the room.

Because the combination of statutory functions, accountability obligations and sector regulation is specific to the entity. Templates capture common commercial duties and miss what the establishing legislation confers and constrains, which is usually the most consequential layer.

Yes. Official information and records duties carry statutory timeframes and public consequences for failure. Treating them as an administrative function rather than a compliance obligation is a recurring source of adverse findings.

Agency contracts commonly impose obligations covering information request support, records management, conduct expectations and reporting. Those are compliance obligations you have accepted, and they belong in a register even though they arrived commercially.

Its predecessor gave advice and could not be certified against. The present standard turned that thinking into requirements an assessor can test. Earlier effort still counts, but the framework needs reconstruction before certification comes within reach.

It changes what you can produce. An enquiry asks which obligation applied, who owned it, what control operated and whether it worked. A register with evidence answers that; a policy library describes intentions instead.

The people carrying out the function concerned, while compliance or governance curates the register itself. Where one team appears against every entry, a published finding reads that as accountability held centrally rather than genuinely accepted.

Yes. Where an entity holds prudential or conduct obligations alongside public sector duties, the register carries both. Wellington organisations frequently sit across that boundary in ways their peers elsewhere do not.

What must exist is a function with real authority and an unobstructed line to the board. No particular role or staffing level is specified. Smaller entities regularly fold it into legal or risk, which passes where the independence is authentic.

Usually twenty to thirty-five weeks. Assembling the register sets the pace, and bodies holding statutory functions on top of sector regulation land at the longer end. Shortening that stage delivers something that collapses the first time it is publicly examined.

Straightforwardly. Shared clause structure with security, continuity and quality standards means governance, audit and review get constructed a single time. Entities here answering to several accountability relationships often operate multiple certificates from one system.

CONTACT
Reach out to us for any inquiries, collaborations,
or just to say hello!

Contact information for Nathan ISO Consulting

CLIENTELE
Our Valuable Client

WHEN NUMBERS MATTER
Empowering Insights into our Business Performance