← All resources

Build Your Risk Register Before NZQA's iQAF Builds One

9 September 2026 · 8 min read

Build Your Risk Register Before NZQA's iQAF Builds One

NZQA has stopped waiting three or four years to catch you out. From January 2026, the integrated Quality Assurance Framework (iQAF) puts every provider on an annual self-review summary report and an improvement-plan conversation with the regulator — which means the compliance manager's real job has quietly shifted from surviving an audit to maintaining a live, provable record of risk, updated all year round.

Why This Lands on Your Desk Now

Under iQAF you personally answer for a continuous evidence trail, not a once-every-few-years external evaluation and review (EER) scramble. The annual self-review summary report and improvement-plan meeting mean you can't bank evidence-gathering for audit week anymore — NZQA expects to see it standing ready, year-round.

iQAF's four weighted criteria include quality management systems as a scored input, not an artefact you assemble for the visit. Policy currency and documentation traceability count toward your rating every year, not just the year NZQA happens to turn up.

Provider category standing carries commercial weight beyond your own compliance file, too. Immigration New Zealand has confirmed it will keep using EER-era category ratings to set visa conditions in 2026, and has previously extended work-right benefits to students at Category 1 providers. A slip in category isn't only a paperwork problem — it can flow straight into enrolments.

And NZQA's own evaluators have shown they'll name staff turnover as a compliance risk in a published report. That puts institutional knowledge, and who owns the evidence behind it, squarely on your desk — because you're usually the one left holding the file when someone leaves.

The Shift From Event to Evidence Trail

Since January 2026, NZQA has stopped starting new EER processes and assuring consistency reviews. In their place: an annual self-review summary report, followed by an improvement-plan meeting with NZQA. You're still expected to review your practice against the Education Code of Practice as a matter of course — that obligation hasn't gone anywhere.

NZQA is finishing consultation on the detail, but the direction is clear. Instead of a single compliant / non-compliant judgement, providers are proposed to be scored Highly Effective, Effective, or Not Effective against four weighted criteria: programme and micro-credential design, education delivery, assessment practice, and quality management systems. Crucially, that judgement draws on evidence NZQA already holds about you. There's no waiting for an EER cycle to build a picture — the picture is being built continuously, from whatever you've already put on record.

Three Rule-Sets Rewrote Themselves in a Year

If you've been meaning to run a full policy audit "when things quiet down," here's why that's the wrong plan. In the past year, at least three rule-sets governing Private Training Establishments (PTEs) have been substantially rewritten:

  • The Private Training Establishment Rules 2026, in force from 19 January 2026, replacing both the 2025 registration rules and the 2022 enrolment and academic records rules, and removing the annual fee.
  • The NZQA Programme Approval, Recognition, and Accreditation Rules 2025.
  • The re-issued Student Fee Protection Rules 2025.

Each one requires you to check programme documentation and internal processes line by line against the new text, not just file the new rule PDF next to the old one. If you can't name, right now, who owns the review of each rule-set and when it was last checked, that's your first gap.

What a Live Risk Register Actually Tracks

Scattered evidence is the enemy here — not because it doesn't exist, but because nobody, including you, can locate it fast enough to answer NZQA's question the day it's asked. A live register doesn't need to be complicated. It needs a handful of things visible in one place, updated as they change, not reconstructed under pressure:

  • Policy review owner and due date, mapped to each current rule-set
  • Programme approval documentation status against the 2025 Programme Approval, Recognition, and Accreditation Rules
  • Assessment and moderation evidence trail, kept current, not reconstructed
  • Fee protection compliance evidence under the 2025 Student Fee Protection Rules
  • Staff tenure and handover notes for teaching roles
  • Self-review evidence mapped explicitly to the four iQAF criteria
Checklist of six items a training provider compliance risk register should track under NZQA's iQAF

Two Providers, Two Outcomes

Published EER reports already show what this looks like in practice, on both sides.

Comparison of UUNZ's proactive policy review approach against Techtorium's EER finding despite stable delivery

UUNZ Institute of Business ran a systematic review of every policy against current regulatory requirements, kept a policy review schedule running, consolidated its policies into one overarching quality management system document, and ran an internal compliance audit against its annual NZQA statutory declaration. That audit surfaced gaps and closed them before NZQA ever asked the question.

Techtorium, by contrast, was found not meeting the Programme Approval and Accreditation Rules criterion on assessment and moderation — despite maintaining continuity of delivery throughout. Staying open, staying stable, keeping students enrolled: none of that protected against one specific, evidenced finding. Operational health and compliance health aren't the same thing, and NZQA will separate them cleanly.

The Staff Turnover Blind Spot

At least one EER report ties staff attrition directly to compliance risk: evaluators noted that four of six teaching staff in a focus-area programme had been employed for a year or less. That's not just a workforce statistic — it's a signal that institutional knowledge, and the evidence sitting behind it, is walking out the door faster than it's being replaced.

If the person who understood why a policy was written a certain way has left, and nobody documented the reasoning, you inherit a compliance gap you didn't create and may not even know exists yet. Handover discipline belongs on your risk register alongside document version control.

Correction Has a Ceiling

NZQA does allow correction of purely compliance matters before a report is finalised. That's real, and it's worth knowing. But it doesn't extend to filling long-term performance or self-assessment gaps — you can't manufacture a year of evidence in the fortnight before a conversation. The system rewards providers who can show ongoing, provable compliance, not ones who rectify well under pressure. That's the whole logic behind moving to an annual, continuous model.

Key takeaways

  • iQAF replaces the periodic EER cycle with an annual self-review summary report and an improvement-plan meeting — evidence-gathering is now continuous, not event-based.
  • Quality management systems are one of four weighted criteria feeding your rating, meaning policy currency is a scored input every year, not just an audit-week artefact.
  • Three PTE rule-sets have been rewritten in the past year (PTE Rules 2026, Programme Approval and Accreditation Rules 2025, Student Fee Protection Rules 2025) — each needs deliberate, line-by-line review, not filing.
  • Published EER reports show NZQA rewards a scheduled, systematic policy-review discipline (UUNZ) and will still flag a specific evidenced gap even where delivery is stable (Techtorium).
  • Staff attrition and thin institutional knowledge have already been named by NZQA evaluators as a compliance risk — handover and evidence ownership need explicit tracking.
  • Correction before a report is finalised covers compliance matters, not long-term self-assessment gaps — there's no substitute for an ongoing evidence trail.

Our take

The old model let compliance managers get away with being reactive, because the clock only really mattered once every three or four years. iQAF removes that shield. If your evidence lives in a shared drive, a compliance folder, and whatever's in your head, you are the single point of failure — and NZQA's own reports show that single point of failure most often shows up as staff turnover or a policy nobody rechecked in time.

The providers who did well under the old EER system already look like the ones who'll do well under iQAF: not the ones with the fewest problems, but the ones who can say, on any given Tuesday, exactly what their open risks are and who's closing them. Building that visibility is less about finding more hours in the week and more about deciding, now, what a risk register actually needs to hold — and refusing to let it slide back into a spreadsheet nobody opens between audits.

FAQ

What is NZQA's integrated Quality Assurance Framework (iQAF), and when did it start? The iQAF went live from January 2026. NZQA has stopped starting new external evaluation and review (EER) processes and assuring consistency reviews, replacing them with an annual self-review summary report and an improvement-plan meeting, while providers are still expected to review their practice against the Education Code of Practice.

Does the annual self-review summary report replace EER entirely? It replaces the mechanism for new evaluations going forward. NZQA is consulting on final design, proposing to score providers Highly Effective, Effective, or Not Effective against four weighted criteria — programme and micro-credential design, education delivery, assessment practice, and quality management systems — drawing on evidence NZQA already holds.

How do the four iQAF criteria change what evidence I need to keep? Because quality management systems is one of the four weighted criteria, policy currency, review schedules, and documentation traceability become scored inputs every year rather than artefacts you produce specifically for an audit. A live, dated policy-review schedule matters more than it used to.

Can I still fix issues before NZQA finalises a report? Yes, for purely compliance matters. NZQA allows correction of compliance issues before an EER-style report is finalised, but this doesn't extend to filling long-term performance or self-assessment gaps — those require an ongoing evidence trail, not last-minute rectification.

What would your risk register show if NZQA asked for it tomorrow, not at the end of the year?

Share

See VETos on your own scope.

A 30-minute walkthrough — bring a unit of competency and watch a validation-ready draft take shape.

VETos is coming to the UK.

Join the early-adopter programme and help shape it for FE, ITPs and EPA.

Join the waitlist