Have you ever opened a draft policy, skimmed the title, seen the word “compliance,” had your eyes glaze over, and immediately thought, “Well, I guess this needs to go to the board”? Legal-sounding documents have a special talent for making everyone suddenly very interested in approval chains. But a policy does not need board approval just because it sounds official, arrives in a PDF, or includes a few words that make people sit up straighter. The better question is: who actually has authority to approve this? If you’ve ever wondered what decisions require nonprofit board approval or asked “what does a nonprofit board need to approve?”, start by sorting your project into the right lane: board approval of a policy, executive approval of a policy or rule, or staff implementation of a policy or rule.
1. Board approval belongs with board-level responsibility
Board-level responsibility means the board is legally, structurally, or institutionally accountable for the decision, oversight, delegation, or documentation. In nonprofit terms, that usually means the policy touches fiduciary duties, mission protection, executive director or CEO oversight, major financial stewardship, governance structure, conflicts of interest, related-party transactions, or decisions reserved to the board by state law, bylaws, committee charters, funder requirements, or prior board action. The board owns that responsibility, although an authorized committee may handle parts of the work if the organization’s governing documents and applicable law allow it.
Management can draft the policy, prepare the materials, recommend edits, and implement the approved rule. But management should not be the final approver for policies that define, limit, or document the board’s own authority. (That’s a little too “I graded my own exam,” and we try to avoid that in governance.)
A policy usually belongs with the board when it tells the board how it will act, monitor, approve, disclose, recuse, delegate, or document, or just generally maintain accountability for the organization. Think conflict of interest, whistleblower, document retention and destruction, executive compensation, gift acceptance, related-party transactions, joint ventures, board committee authority, delegation of authority, or major transaction approval.
This can be a bit confusing at first because staff often think of some of those as applying only to staff-level activities. The key is to separate ownership of the rule from implementation of the rule.
Some board-approved policies are carried out almost entirely by staff; document retention is a classic example. The board typically approves the organization’s document retention and destruction policy because it’s a governance-facing policy, one that supports oversight, accountability, and the organization’s ability to explain to the IRS or other regulators how records are preserved or destroyed. But staff will usually maintain the retention schedule, organize files, follow the destruction process, and handle the practical “where does this PDF live?” questions that make everyone secretly regret having shared drives (by the way, if you need help updating your document retention policy because it was originally written sometime around Y2K, when we all still pretended paper files were a personality trait, reach out and we can discuss how I can help).
Also, it’s important to note that the IRS Form 990 asks whether an organization has written conflict of interest, whistleblower, and document retention policies, and it also asks about the organization’s compensation-setting process and any written policy or procedure for certain joint ventures. Those Form 990 governance questions are not the same thing as a blanket federal rule requiring board approval for every policy, but they do show what the IRS expects organizations to be able to explain publicly, and if your organization is saying it has those policies, it should actually have those policies.
2. Executive approval belongs with organization-wide operating rules
Some policies are legal in subject matter, but operational in effect. They might involve legal risk, compliance obligations, or words like “protocol” (which admittedly sounds like something that should come with a clipboard). But if the policy doesn’t define the board’s own role, it might not need board approval.
That said, as with board-level policies, a policy is not executive-level just because staff will be the ones using it. Many governance policies predominantly impact daily operations after the board approves them. The consideration is whether management is approving the underlying rule, or whether management is implementing a rule that belongs to the board.
These types of policies tell the organization how work should happen across staff, programs, vendors, systems, budgets, or reporting lines. Some policies that might fall under this category are those on AI use, vendor management, data privacy operations, cybersecurity acceptable use, expense reimbursement, grant administration, employee handbook updates, internal reporting, or program participant conduct. These policies usually need executive approval because leadership has to decide whether the organization can handle the practical consequences, like training people on the rule and enforcing it.
This is where I see nonprofits overuse their board the most—sometimes out of confusion or a perceived lack of expertise, and sometimes because the board itself might be overstepping. If the policy requires managers to change how teams work, supervise staff, use systems, report issues, spend money, or enforce standards, executive approval usually belongs in the process.
Legal can identify the risk, and then various operations departments (like HR, finance, IT, development, programs, etc.) might each own a piece of implementation. But the final approval should come from the executive sponsor who can make the policy happen within the organization, and that’s not necessarily Legal. Most nonprofits already have enough things sitting in (virtual) binders gathering dust.
3. Staff implementation of either kind of policy belongs with procedures, forms, checklists, and training
Once your policy is settled on and properly approved, staff implementation is the final layer that helps people follow an approved policy. While a policy sets the rule, a procedure is the way it’s implemented. Intake forms, approval workflows, training slides, checklists, reporting templates, internal FAQs, standard operating procedures, vendor questionnaires, escalation charts, email templates, and file naming rules…all of those things usually don’t need board or executive approval unless they change the underlying policy. Staff should be able to update those materials as the work changes, because requiring a board vote to fix a checklist typo is how should-be-simple processes go to live in committee purgatory.
For example, the board will usually approve the document retention and destruction policy, while staff maintain the retention chart, file naming rules, destruction log, storage process, and training materials. Same subject matter, different approval lane. The policy belongs higher up while the implementation tools belong with the staff doing the work.
Here are some examples of how that might work in practice when the same topic crosses a board-level policy, an executive-level operating rule, and a staff-level implementation tool:
| Item (policy or tool) | Usually approved by | Why |
| Document retention and destruction policy | Board | Governance-facing policy tied to oversight, accountability, and public reporting expectations |
| Retention schedule or file storage checklist | Staff, possibly with executive/legal review | Implementation tool for a board-approved policy |
| Conflict of interest policy | Board | Policy that governs disclosures, recusals, related-party issues, and board conduct |
| Annual conflict disclosure form | Staff, legal, or governance committee | Implementation tool for a board-approved policy |
| Expense reimbursement policy | Executive team | Organization-wide operating rule |
| Expense form or receipt upload instructions | Staff or finance | Implementation tool for an organization-wide operating rule |
The easiest way to keep this all straight often is to create a straightforward policy approval matrix. For each policy, identify the policy owner, final approver, review cycle, any board committee involved, executive sponsor, implementation owner, date approved, and next review date. That matrix helps answer what your nonprofit board needs to approve without treating every quasi-legal document like a critical board matter. The goal is to leave each decision to the people who actually have authority to make it, without automatic escalation.
When a nonprofit does that well, policies are easier to adopt, easier to update, and much easier to explain later.
_________________________________
If this was helpful, I’d love to add you to my weekly email, The Nonprofit Minutes, for first access to new articles and free resources, plus need-to-know legal updates affecting nonprofits, real-world compliance tips, Q&A where I answer reader questions, and behind-the-scenes commentary from my work as a nonprofit attorney.
You also might find these other posts helpful: