Maintenance Policy
The governance document that sits above the plan. What the organization commits to, who is allowed to decide what and up to what value, which standards apply, and how anyone knows the policy is being followed.
- Spend limits and decision rights, set once, by role
- Ten commitments written to be held to, each with its evidence
- Twelve requirements that always apply, reviewed annually
- Who may authorize a deferral, and who may never
Maintenance Policy
Position and authority, not tasks
| # | Role, authority and spend limit | Decides | Limit | Deputy |
|---|---|---|---|---|
| 1 | Board or senior responsible owner | |||
| 2 | Head of facilities or estates | |||
| 3 | Maintenance manager |
The document you will get. Download for the full, editable file.
Who this maintenance policy is for
A policy is approved by people who will never open it again and relied on by people who need one specific answer from it quickly.
The board or senior owner who approves it
You are signing the organization up to a position, including that statutory work is never deferred for budget. The principles section is the part that binds you rather than the schedule.
The facilities or estates lead who owns it
You wrote it and you enforce it. Section 4 saves you the most time, because most of what reaches you is a question about who may approve a given spend.
A manager who needs one answer
You are here for a limit or a permission, not to read a policy. That is why authority is a table rather than prose, and why it is stated once rather than per procedure.
Whoever audits against it
You are testing whether the document governs anything. The twelve requirements and the annual review with evidence are the only parts that can actually fail.
Which section matters the most in your sector
A policy is shaped by who carries the liability and who holds the budget, and those differ more by sector than the maintenance itself does. If you run one of these, the sector page goes further than the template does.
- Commercial real estate
Scope and what is out of it. Landlord and tenant obligations split service lines, and a policy that does not say which side it governs will be read both ways.
Portfolio maintenance software - FM service providers
Whether contractors are bound by it. A policy that applies only to employees governs a minority of the people doing the work on most contracted sites.
FM service provider software - Healthcare
Deferral authority. Where clinical availability competes with a statutory interval, naming who may never authorize a deferral is the control that matters.
Healthcare maintenance software - Education
Spend limits and the academic calendar. Delegated authority that works in term time is the difference between a summer window used and a summer window lost.
Campus maintenance software - Corporate facilities
Communication and acknowledgment. In office estates the policy is only as real as the number of people who have seen it and said so.
Corporate facilities software - Religious organizations
Standards adopted. Where buildings are historic or listed, the obligations register and the standards named in the policy carry more weight than any internal preference.
Facilities software for religious organizations
What a maintenance policy should contain
A maintenance policy is the governance document that states an organization's position on maintaining its assets. It sets out the commitments made, who holds which decision rights and spend authority, the standards and obligations adopted, the strategies permitted, the requirements that always apply, and how compliance with the policy is reviewed.
A. Fields specific to a maintenance policy
| Field | What goes in it | Why it earns its place |
|---|---|---|
| Document control | Reference, version, effective date, owner, review frequency and what it supersedes | A policy without a version and an effective date cannot be enforced, because nobody can say which text applied when the decision was taken. |
| Applies to | Which sites, which people, and whether contractors are bound | The most consequential line in the header. On a contracted site a policy that binds only employees governs a minority of the people doing the work. |
| Explicitly out of scope | What this policy does not govern, and why | Naming exclusions prevents the assumption running both ways. Unstated exclusions are read as covered by whoever is not covering them. |
| Ten principles | A commitment and the evidence for each | Written so they can be challenged. Safety before availability means nothing until it is paired with how anyone would know it was honored. |
| Roles, authority and spend limits | Eight roles, each with what they decide, a value and a deputy | The reason people open this document. Stating limits once removes the question from every job, and naming a deputy stops authority evaporating on annual leave. |
| Standards and obligations adopted | Legislation, codes, manufacturer instruction and insurer requirements | Including whether manufacturer intervals are a minimum or may be varied on a documented risk case, which is a genuine policy decision rather than an engineering one. |
| Strategy statement | Which strategies are permitted and when run to failure is acceptable | The policy says which strategies may be used; the plan chooses one per asset. Keeping that split is what stops this document dating. |
| Deferral authority | How deferrals are recorded, who may authorize, and who may never | The control that does the most work. Most statutory slippage happens through an informal deferral nobody was named against. |
| Twelve requirements | The conditions that always apply, each with evidence and an owner | From every asset having a named owner to permits, isolation, records retention and change control. These are the parts a policy can actually fail on. |
| Annual compliance review | Ten areas marked met, partly met or not met, with evidence seen | Answering this honestly is the only thing separating a policy that governs from a policy that is filed. It is also the one calculation the workbook performs. |
| Communication and acknowledgment | How it is published, who must acknowledge it, and how breaches are handled | A policy nobody has acknowledged is difficult to enforce against an individual, which is precisely when enforcement is attempted. |
| Out-of-cycle review trigger | What forces a review before the annual date | A major incident, a change of law, a significant asset change or a failed audit. Without a trigger, a policy stays unchanged through the events that should have changed it. |
The test of this document is whether it can be broken, and that is what section 7 and the annual review are for. A policy made of aspirations cannot fail: every statement is true by construction, nobody is accountable, and the annual review is a paragraph saying the policy remains appropriate. The twelve requirements are written the other way round, as conditions with evidence and an owner, so answering them produces either proof or a gap. Section 4 does the same job for authority. Most of what actually goes wrong in maintenance governance is not a wrong decision, it is an unclear one: nobody could say who was allowed to approve a spend, or who was allowed to defer a statutory task, so it happened informally and was discovered afterwards. Stating limits once, by role, with a named deputy and an explicit list of who may never authorize a deferral, removes the ambiguity that those failures depend on.
B. What it looks like filled in
Six rows from the authority table, which is the part of this document people actually come for. Read across: the value is only half of what is being set.
| Role | Decides | Spend limit | Deputy |
|---|---|---|---|
| Board or senior owner | Policy, budget, strategy | Unlimited | Deputy CEO |
| Head of facilities | Contracts, deferrals, standards | 50,000 | Maintenance manager |
| Maintenance manager | Reactive spend, contractor call-out | 10,000 | Supervisor |
| Supervisor | Parts and consumables | 1,000 | Maintenance manager |
| Technician | Nothing committed without approval | Nil | n/a |
| Any role | Deferral of a statutory task | Head of facilities only | No deputy |
The last row is the one worth copying, and it is not about money. Every other line delegates authority downward, which is what a spend table is usually for. That row does the opposite: it reserves one decision at a named level and then explicitly refuses a deputy for it, so the authority cannot quietly pass down the chain when somebody is on leave and a contractor is waiting. Statutory deferrals are where maintenance governance most often fails, and it almost never fails through a deliberate decision to accept risk. It fails because the question arrived at a busy moment, nobody was sure who owned it, and the task slipped by default. A nil limit against the technician row is doing similar work from the other end. It is not a statement of distrust, it is a statement that nobody should be placed in the position of committing spend they were never given authority for.
Word is the version to work in, since a policy is prose and tables rather than arithmetic. The Excel adds the annual compliance review, which is the one part that calculates: mark the ten areas met, partly met or not met and the policy compliance figure follows. PDF for circulation and acknowledgment. Free, and yours to rebrand.
How do you write a maintenance policy?
Write it in the order it will be read: what we commit to, who may decide, what we are bound by, and how anyone would know. Keep dates and task lists out. Six steps.
Set the header, and say who it binds
Organization, reference, version, effective date, owner, review frequency and what it supersedes. Then the line that matters most: which sites, which people, and whether contractors are bound by it. On a contracted site that answer decides most of the document's reach.
State the purpose and draw the scope
Why the policy exists, which assets and systems it covers, what is explicitly out of scope and why, and the related policies it sits alongside. Name the exclusions, because an unstated exclusion is assumed to be somebody else's.
Write ten commitments you would be held to
Safety before availability, statutory compliance never deferred, prioritization by criticality, planned preferred to reactive, competent people only, complete records, a defined standard, evidence over habit, environmental impact considered, improvement measured. Add how each is evidenced.
Set authority and spend limits once, by role
Eight roles from the board down to technician, each with what they are responsible for, what they may decide, the value they may commit and who deputizes. This is the section people open the policy for, so it belongs in a table rather than in prose.
Adopt your standards and set the deferral rule
The legislation, codes, manufacturer instructions and insurer requirements you are bound by, and where the obligations register lives. Then which strategies are permitted, when run to failure is acceptable, how deferrals are recorded, who may authorize one and who may never.
Make it testable, then review it annually
Twelve requirements that always apply, each with evidence and an owner. Then the annual review across ten areas marked met, partly met or not met with the evidence seen, plus how the policy is communicated, who must acknowledge it, and what triggers a review before the annual date.
A maintenance policy versus a maintenance plan
These two get written by the same person in the same week and then confused forever. The clearest test is how quickly each one goes out of date.
| Aspect | This policy | The maintenance plan |
|---|---|---|
| What it states | Position and authority | What will be done, to which assets, this year |
| How long it lasts | Years, reviewed annually | One plan period, then rewritten |
| Who approves it | The board or a senior responsible owner | The budget holder and the plan owner |
| What it never contains | Task lists, frequencies, dates | Nothing about who may approve a spend |
| The question it answers | Are we allowed to, and who decides | What are we doing, and can we afford it |
| If it is wrong | Decisions get made by whoever is nearest | The year is undeliverable, and you find out in March |
If your policy contains dates, it has quietly become a plan and will be wrong within months. That is the failure mode worth guarding against, because it is so easy to fall into: somebody asks for a policy, the honest answer involves what actually gets maintained and how often, and a task table appears. The document then dates on the schedule's clock rather than the organization's, and because policies are reviewed annually at best it spends most of its life describing a program that has moved on. The separation also protects the plan. A plan that has to re-establish who may approve a deferral, every year, in its own words, will eventually say something slightly different from the last version, and the difference will be discovered during the argument the clause exists to settle. Set authority once here, let the plan reference it, and let the plan change as often as it needs to.
When the template starts to feel limiting
A policy is a document about position, so most of its weaknesses are about whether anybody is actually governed by it. Four show up quickly.
You cannot see whether it is being followed
The requirements section is answered once a year from memory and a sample. Between reviews, whether every job really went through an approved contractor is not a question the document can answer.
Authority lives here and decisions happen elsewhere
The spend limits are in a policy; the approvals happen in email, in a system, or verbally. Nothing compares the two, so an over-limit approval is found by audit rather than prevented.
Reviews and acknowledgments drift
An annual review date and a list of people who must acknowledge the policy, both held in a file. Neither chases itself, and a policy nobody has acknowledged is hard to enforce against an individual.
Deferrals leave no trail
The rule says who may authorize one. Whether a deferral happened, and who authorized it, is recorded only if somebody chose to write it down at the moment they were under pressure not to.
What running this in Facilio looks like
The template is the paper version of this governance. The positions are the same; the difference is that authority becomes something the system applies, and the annual review reads from what actually happened.
Work Completion Validator
Approved work is work that met the policy
Requirements such as permits issued, isolation under a written procedure and competent people only stop being annual assertions, because a job that fails one of them is caught as it closes rather than sampled a year later.
Ops Performance Intelligence
Deferrals and reviews stop being invisible
A statutory task being pushed is an event with a date and a name against it, so the deferral rule in section 6 is enforced at the moment it matters rather than examined afterwards.
Audit Report Intelligence
The annual review reads from evidence
The ten areas are answered from what the records show rather than from a sample and a recollection, which is the difference between a review that can fail and one that cannot.
Contractor Work Tracker
Contractors are inside the policy, not beside it
Approval status, competence and insurance sit against the contractor record, so the requirement that work goes only to approved parties is checked when work is issued.
Hallucination-free by design. Atom AI answers from the records in your tenant rather than generating plausible text, so an empty field reads as empty rather than filled in for you.
Frequently asked questions
What is a maintenance policy?
A maintenance policy is the governance document that states an organization's position on maintaining its assets. It sets out the commitments made, who holds which decision rights and what they may spend, the legislation and standards adopted, which maintenance strategies are permitted, the requirements that always apply, and how compliance with the policy itself is reviewed.
It is deliberately not a task list. A policy states position and authority; a plan states what will be done this year. Keeping dates and frequencies out is what allows a policy to stay valid for years.
What should a maintenance policy include?
Document control and the scope, including whether contractors are bound by it. The principles the organization commits to, each with how it is evidenced. Roles, authority and spend limits by role with a deputy. The legislation, standards, manufacturer instructions and insurer requirements adopted.
Then a strategy statement covering which approaches are permitted and when run to failure is acceptable, how deferrals are authorized and by whom, the requirements that always apply, an annual compliance review, how the policy is communicated and acknowledged, and what triggers a review out of cycle.
What is the difference between a maintenance policy and a maintenance plan?
The policy says what the organization commits to and who is allowed to decide what. The plan says which assets get maintained this period, under which strategy, at what cost, and how success will be measured. The policy lasts years; the plan is rewritten each period.
The practical test is dates. If your policy contains frequencies, task lists or a calendar, it has become a plan and will be out of date within months. Put those in the plan and have the plan reference the policy for authority.
Who should approve a maintenance policy?
Whoever can commit the organization to the position it states, which usually means a board member or a senior responsible owner rather than the facilities team that wrote it. The commitments in section 3 include things like never deferring statutory work for budget reasons, and that is a promise only a budget holder can actually make.
The policy owner is a separate role and is normally the head of facilities or estates. They maintain and enforce it; the approver is accountable for it.
What spend limits should we set?
There is no universal answer, which is why the template gives you a table rather than figures. What matters more than the numbers is that every role has one, that a deputy is named so authority does not evaporate during leave, and that the limits are stated once here instead of being re-argued job by job.
One row is worth setting deliberately: deferral of a statutory task. Reserve it at a named level and consider refusing a deputy for it, because that is the decision most likely to be taken informally under time pressure.
How often should a maintenance policy be reviewed?
Annually as a default, plus whenever a trigger fires. The template lists the usual triggers: a major incident, a change in the law, a significant change to the assets, or a failed audit.
The annual review is the part that gives the document teeth. Ten requirement areas marked met, partly met or not met, with the evidence actually seen recorded against each. A policy that scores the same gaps every year is a policy nobody is enforcing.
Does a maintenance policy apply to contractors?
Only if you say so, and that line is in the header for exactly that reason. On a site where most of the work is delivered under contract, a policy that binds only employees governs a minority of the activity, which is usually the opposite of what was intended.
If contractors are bound, several requirements need to follow through: approval before work is issued, competence assessed, permits, isolation under a written procedure, and records retained in your system rather than only in theirs.
Can I edit and rebrand this template?
Yes. It is free to use, edit, rename and put your own logo on, internally or for clients. No attribution required.
Work in the Word version, since a policy is prose, tables and signatures rather than calculation. The Excel adds the annual compliance review, which is the one place the workbook does arithmetic: mark the ten areas and the policy compliance figure follows, with a Review History tab to show the trend at board level.
In one paragraph
A maintenance policy states position and authority, and the fastest way to ruin one is to let task lists and dates into it, at which point it becomes a plan and starts dating within months. Say in the header who it binds, and be explicit about contractors, because on a contracted site that single line decides most of the document's reach. Write ten commitments you would genuinely be willing to be held to, each paired with how anyone would know it had been honored. Then set authority and spend limits once, by role, with a deputy named, since that is the section people actually open the policy for and stating it once removes the question from every job. Name who may authorize a deferral of a statutory task and consider refusing a deputy for that one decision. Then make it testable: twelve requirements with evidence and owners, reviewed annually and marked honestly.
The template is the floor, not the ceiling
Take the policy; it will give you a position a board can approve and an authority table that stops the same question arriving every week. When the gap between what the policy says and what actually happens is only visible at the annual review, a connected CMMS closes it: approval limits applied as work is raised, deferrals recorded as events with a name against them, contractor approval checked before work is issued, and the annual review read from evidence rather than assembled from memory.