← Resources
Business Operations ComplianceHRRecord Keeping

The Register Nobody Owns: What Happens to Policies After They Are Written

Policies get written once. The registers underneath them need maintaining continuously, and that upkeep is the part that quietly stops being done.

16 September 2026

Minimalist hand-drawn illustration of a card index box with a subtle amber accent, representing records that are kept and findable.

The policies usually get written at a specific moment. The business hits fifteen staff, or an insurer asks, or a template pack gets bought from an HR provider. Then they sit in a folder on the shared drive.

The question worth asking is what has happened to them since. Specifically: when was the last time anyone signed one, when was the last version change, and where is the record showing which employees have read which document.

That record is the part that carries weight, and it is the part that quietly stops being maintained not long after the policies are written.

The documents and the registers underneath them

The policy set for a small Australian employer generally covers work health and safety, privacy and data handling, equal opportunity and anti-discrimination, code of conduct, IT and acceptable use, social media, leave and entitlements, and performance and disciplinary process. The exact set depends on the industry and the size of the business, and the wording should be checked by someone qualified to check it.

Underneath each one sits a register, and the register is where the actual administration lives:

  • Induction sign-offs. Which employee acknowledged which policy version, on what date, with the acknowledgement retained
  • Version history. What changed, when, who approved it, and which version was in force on any given date
  • Training records. Certifications held, completion dates, expiry dates, renewal bookings
  • Incident log. Date, description, people involved, action taken, follow up completed and closed
  • Contractor compliance. Public liability certificates, workers compensation, licences and their expiry dates for every trade and supplier on the books
  • Leave and entitlement records. Balances, approvals, parental leave schedules and return dates
  • Equipment and access register. What was issued, to whom, what was returned, which accounts were closed at exit

A policy without its register is a document that describes what the business intends to do. The register is what shows what the business actually did, which is what matters when it is examined.

Why the register is the part that fails

The policy gets written once by someone motivated to write it. The register needs maintaining every time a person joins, leaves, renews a certificate, has an incident or takes leave, which is to say continuously and unpredictably.

That work has no obvious home. It belongs to whoever handles HR, who is usually also the person handling finance, or the owner, or an office manager with a full day already. It gets done when something forces it, which is typically an audit, an insurance renewal, a claim or a dispute.

At that point the work is reconstruction rather than record keeping, and reconstruction is where the gaps become visible.

A cadence that keeps it current

The whole thing runs on a fixed schedule with named triggers:

On hire: induction pack issued, acknowledgements collected and filed against the employee record, equipment and access logged, certifications recorded with expiry dates, entitlements set up.

On exit: access closed and logged, equipment returned and recorded, final entitlements calculated, records archived to the retention period the business has set.

Weekly: any incident from the past week logged within 24 hours of being reported, open incident actions followed up.

Monthly: certifications and contractor insurance certificates expiring in the next 60 days identified and renewal chased. This is the one worth protecting, because expired contractor insurance stays invisible until something happens.

Quarterly: policy review dates checked against the register, anything due flagged to the owner or adviser, version history updated for anything changed.

Annually: full acknowledgement audit. Every current employee against every current policy version, with gaps chased and closed.

What this looks like by industry

In a property management business, the documented procedures that matter most are the ones covering entry and inspection safety, key handling and register, trust account handling, and the trade panel compliance file with current insurances and licences.

In an agency, it is client sign-off protocols, data and file handling for client material, IT access and offboarding, and contractor agreements for the freelancers who work on client accounts.

In both cases the sector specific documents get written last, because they sit outside whatever template pack the business bought.

Where the records live and how long they stay

Two questions decide the structure. How long records have to be kept, and who can see them.

Employee records carry a retention obligation under the Fair Work Act, and the period is long enough that it outlasts most of the systems businesses store them in. Records that live in a departed manager’s email, in a spreadsheet on a laptop, or in a platform the business has since stopped paying for are records the business no longer effectively holds.

The structure that survives is unglamorous: one location, a folder structure that matches the register list, consistent file naming that includes the date and version, and access limited to the people who need it. Personal information, medical certificates and disciplinary records need tighter access than a policy acknowledgement does, and that distinction should be built into where they sit rather than managed by trust.

The test is straightforward. If the person who currently maintains the records left tomorrow, could someone else produce a complete file on any employee within an hour. Where the answer is no, the reason is usually location rather than effort.

What stays with the business and its advisers

Policy content, legal review, the decision about what the business will actually do, disciplinary outcomes, and anything involving employment law advice. An HR adviser, employment lawyer or industry association covers this, and the wording of a policy is worth paying for.

The drafting from an approved template, the distribution, the acknowledgement chasing, the register maintenance, the expiry monitoring and the review calendar are administration with a defined standard and a fixed cadence.

Where the role sits

An administration specialist owning this maintains the registers in whatever the business already uses, whether that is Employment Hero, a SharePoint structure or a set of well built spreadsheets. The daily work is small and constant: log the incident, chase the acknowledgement, book the renewal, update the version history, file the certificate.

The first thirty days are usually spent on one job, which is establishing the current position. Every employee against every policy version, every certification against its expiry date, every contractor against their insurance. That picture rarely exists in one place, and assembling it is where the gaps get found while they are still inexpensive to close.

HIPPO sets the register cadence with you before day one and stays involved through the first ninety days, which is roughly how long the current position takes to establish and hold. If your policies are current and your registers are three years old, a connect session takes 45 minutes and starts with who should be keeping them. Book a Connect Session

Work with HIPPO

Ready to build
your back office?

Book a Connect Session to talk through how a specialist role fits your business. You leave with a written Leverage Plan the same day.

Book a Connect Session