Wellington organisations carry a category of obligation that barely exists elsewhere in New Zealand: accountability for how public functions are performed. Agencies, Crown entities and the providers delivering services on their behalf answer not only to regulators but to Parliament, to the Auditor-General, to the Ombudsman and to anyone who submits an information request.
That is a different compliance profile from a commercial one. The obligations concern integrity, transparency, proper use of public money and the ability to explain decisions, and failure surfaces publicly rather than through a private supervisory conversation.
Nathan ISO Consulting implements compliance management systems under ISO 37301:2021 for Wellington organisations across government agencies and Crown entities, financial institutions, agency service providers, health and education, and professional services.
Looking for an ISO 37301 Consultant in Wellington?
Why ISO 37301 Matters for Wellington Organisations
Public accountability is the first reason and it changes what evidence has to withstand. A compliance failure in a Wellington agency can become a select committee question, an Auditor-General finding or an Ombudsman opinion, each of which is published. Being able to show what the obligation was, who owned it and what controls operated is materially different from being able to explain it verbally afterwards.
Obligation density is the second. An agency simultaneously carries statutory functions under its own Act, machinery-of-government obligations covering integrity and conduct, financial management duties, information duties, employment obligations and whatever sector regulation applies. No single relationship covers it and no template captures it, because the combination is specific to the entity.
The third reason is supplier inheritance. Providers delivering agency services acquire obligations through contract that have no commercial equivalent: information request support, records management, conduct expectations and reporting duties. Businesses treating those as ordinary contract terms are frequently surprised by what they have accepted.
Why a Policy Library Fails Here Specifically
A policy states an intention. What a select committee, an Auditor-General enquiry or an Ombudsman investigation asks for is different: which obligation applied, who was accountable, what control was meant to operate, whether it operated, and what happened when it did not. That is a register with evidence attached, not a document set. The distinction matters more in Wellington than anywhere else in the country, because the questions are asked in public and the answers are published. Organisations that can only produce policies end up explaining their intentions while the findings describe their outcomes.
The Obligation Layers a Wellington Register Must Carry
| Layer | Examples Relevant to Wellington | What It Generates |
|---|---|---|
| Entity-specific statutory functions | The Act establishing the agency or entity and the functions it confers | Functional duties, reporting obligations and limits on what the entity may do |
| Public sector integrity and conduct | Standards of integrity and conduct, and machinery-of-government expectations | Conduct obligations, conflict management and accountability requirements |
| Public finance and accountability | Financial management duties, reporting and audit obligations | Appropriation compliance, annual reporting and audit response duties |
| Information obligations | Official information duties, privacy law and public records requirements | Request handling within statutory timeframes, records retention and disposal |
| Financial regulation | Prudential supervision and conduct licensing for financial institutions | Licence conditions, prudential standards and reporting obligations |
| Anti-money laundering | Reporting entity obligations supervised by sector-specific supervisors | Risk assessment, programme, due diligence, reporting and independent audit |
| Workplace and employment | Health and safety duties, employment standards and good faith obligations | Duties, notification requirements and record keeping |
| Sector regulation | Health and disability standards, education regulation, care provider requirements | Standards, audit regimes and notification duties on independent cycles |
Verify current regulator names, accountability requirements and licensing regimes before publishing. The combination applying to any given entity is specific, which is why registers here cannot be built from a template.
Wellington Precincts and the Wider Region
| Wellington Location | Business Activity | Compliance Driver |
|---|---|---|
| Thorndon and Pipitea | Departments, ministries, Crown entities, statutory bodies | Statutory functions, integrity standards, public finance and information duties |
| The Terrace and Lambton Quay | Financial regulators, banks, insurers, market participants | Prudential and conduct supervision, licence conditions |
| CBD professional services | Law firms, accounting practices, consultancies | Professional obligations and AML/CFT reporting entity duties |
| Agency supply chain | ICT suppliers, service providers, contracted delivery partners | Contractual obligations covering information, records and conduct |
| Newtown and hospital precinct | Health providers, clinical services, aged care | Health and disability standards, notification duties, audit regimes |
| Kelburn and the university precinct | Tertiary institutions, research organisations | Education regulation, funding conditions, research integrity requirements |
| Porirua and Kāpiti | Community and social services, education, local government | Contracted service obligations and accountability requirements |
| Not-for-profit and membership sector | Societies, charities and associations | Entity obligations, charities reporting and officer duties |
| Regional delivery | Providers serving the region and nationally from Wellington | Contract compliance across multiple funder relationships |
Building a Register for an Entity Nobody Else Resembles
Commercial compliance registers can start from a sector template because organisations in the same industry carry broadly the same obligations. Public sector registers cannot, because the combination of statutory functions, machinery-of-government expectations and sector regulation is specific to the entity.
A register built properly here starts from the establishing legislation and works outward: what functions does the entity hold, what constrains how it performs them, what accountability obligations attach, and what sector regulation applies on top. That takes longer than adapting a template and it is the only approach that produces something defensible.
Ownership is the recurring friction, as it is everywhere. Where every obligation names the governance or legal team, an Auditor-General enquiry reads that as accountability having been centralised rather than accepted. Pushing obligations out to the people performing the functions is uncomfortable and is the most valuable part of the work.
Facing an audit, enquiry or agency contract needing a compliance system?
Our Wellington Delivery Approach
Scoping starts from the establishing legislation or the licence, then works outward through accountability obligations, information duties, sector regulation and contractual requirements. The register is constructed from your own instruments rather than a sector template. Compliance risk assessment follows, producing a priority order that will survive board or committee scrutiny, then control mapping and the governance, reporting and monitoring arrangements.
Fewer bodies assess compliance management than quality or security, and fewer still operate here, so dates are secured well ahead. We look for assessors who have genuinely worked in regulated or public sector settings, agree commercial terms, and deliver readiness through internal audit and a minuted review. Both visits are attended.
Registers decay as legislation is amended, machinery-of-government changes take effect, licence conditions are varied and guidance is reissued. Maintenance is ours, alongside the audit cycle and surveillance readiness, so the register reflects the current position rather than the position at handover.
The Documentation You Receive
Where Wellington ISO 37301 Projects Go Wrong
Preparing for an upcoming audit?
Who Certifies You, and Where We Fit
We implement. An accredited body certifies.
Nathan ISO Consulting builds and implements management systems. We do not issue certificates, and no legitimate consultancy does. Your certificate comes from an independent certification body accredited by JAS-ANZ, the accreditation authority established jointly by the New Zealand and Australian governments. Accredited bodies operate under impartiality rules that prohibit them from certifying a system they helped build, which is precisely why the two roles are separate. Our job is to get you audit-ready, help you select the right accredited body, and stand alongside you through assessment.
Selecting the accredited body, negotiating the fee and fixing the dates are things we take on, matched to your scope, your sector and the audit approach that fits your operation. Our people are present for Stage 1 and Stage 2, and anything the assessor raises becomes our task rather than a list handed back when they leave. Do one check independently: confirm the JAS-ANZ register shows that body accredited for your scope. Unaccredited certificates are inexpensive and quick to obtain, and procurement teams turn them away often enough to make the check worth a minute.
Send Us the Establishing Legislation
For an agency or Crown entity, the Act creating you and the functions it confers is where the register starts. For a supplier, the agency contract schedules covering information, records and conduct are the equivalent.
Ready to start your ISO 37301 certification journey?
FAQ'S
No. We are an implementation consultancy. Certificates are issued by independent certification bodies accredited by JAS-ANZ. Accreditation rules prevent a body from certifying a system it helped build, so the consulting and certification roles must stay separate.
A JAS-ANZ accredited certification body of your choosing. We shortlist accredited bodies against your scope and sector, manage the quote process, and attend both audit stages with you. The certificate and the audit decision rest entirely with them.
Check the JAS-ANZ register and confirm the body is accredited for the specific standard and scope you need. Unaccredited certificates are widely available, inexpensive and routinely rejected by procurement teams, which means paying twice and starting over.
No consultancy honestly can, because the decision belongs to an independent auditor. What we can do is run your internal audit the way an external auditor would, close findings before assessment, and attend both stages so issues get resolved in the room.
Because the combination of statutory functions, accountability obligations and sector regulation is specific to the entity. Templates capture common commercial duties and miss what the establishing legislation confers and constrains, which is usually the most consequential layer.
Yes. Official information and records duties carry statutory timeframes and public consequences for failure. Treating them as an administrative function rather than a compliance obligation is a recurring source of adverse findings.
Agency contracts commonly impose obligations covering information request support, records management, conduct expectations and reporting. Those are compliance obligations you have accepted, and they belong in a register even though they arrived commercially.
Its predecessor gave advice and could not be certified against. The present standard turned that thinking into requirements an assessor can test. Earlier effort still counts, but the framework needs reconstruction before certification comes within reach.
It changes what you can produce. An enquiry asks which obligation applied, who owned it, what control operated and whether it worked. A register with evidence answers that; a policy library describes intentions instead.
The people carrying out the function concerned, while compliance or governance curates the register itself. Where one team appears against every entry, a published finding reads that as accountability held centrally rather than genuinely accepted.
Yes. Where an entity holds prudential or conduct obligations alongside public sector duties, the register carries both. Wellington organisations frequently sit across that boundary in ways their peers elsewhere do not.
What must exist is a function with real authority and an unobstructed line to the board. No particular role or staffing level is specified. Smaller entities regularly fold it into legal or risk, which passes where the independence is authentic.
Usually twenty to thirty-five weeks. Assembling the register sets the pace, and bodies holding statutory functions on top of sector regulation land at the longer end. Shortening that stage delivers something that collapses the first time it is publicly examined.
Straightforwardly. Shared clause structure with security, continuity and quality standards means governance, audit and review get constructed a single time. Entities here answering to several accountability relationships often operate multiple certificates from one system.





















0
Projects
0
Services
0
Clients Serving
0
Countries Serving