The problem is rarely a shortage of policies. It is the absence of a coherent system for managing them. Written without coordination, stored across multiple locations, reviewed inconsistently, and communicated through a combination of email attachments and intranet pages that half the workforce has never visited, most organisational policy libraries drift into a state of partial obsolescence that nobody is quite able to fix because nobody is quite able to see the whole picture.
Good policy management is not primarily about writing better individual policies. It is about treating the complete set of policies as something that requires a lifecycle: creation, approval, publication, communication, attestation, review, and retirement, applied consistently to every policy in the library.
Before addressing how to manage policies well, it is worth being honest about why organisations so frequently manage them badly. Several patterns appear consistently.
Policies are written in response to an immediate need, a new regulatory requirement, an incident, or an audit finding, and then filed without a clear owner or review date. The person who wrote the policy moves on. The risk that prompted it evolves. And the policy remains unchanged, quietly becoming less accurate and less relevant while continuing to be cited as evidence of the organisation's approach.
Version control breaks down because there is no single authoritative location. The current version of a policy is wherever someone last saved it, which may be a personal drive, an intranet folder, a shared mailbox, or a document management system that was not properly maintained. When multiple versions circulate, staff compliance with a policy that does not match the version they were given is not meaningful.
Approval processes are nominal rather than substantive. A policy that is approved by the person who wrote it, or approved without the approver having reviewed it in any meaningful sense, has not received genuine independent oversight.
Communication defaults to publishing. A policy that has been uploaded to an intranet that nobody regularly visits has been made technically available rather than genuinely communicated. The assumption that publication is equivalent to awareness is one of the most common governance failures in policy management.
The foundation of good policy management is a single, maintained register of every policy the organisation holds. Not policies by function, not policies by system, not policies that individual teams happen to remember they have. Every policy.
The register should capture, for each policy: the title and a brief description of what it covers, the policy owner, the date of the most recent review, the date of the next scheduled review, the approval status and who approved it, the current version number, where the authoritative copy is held, and the population to which the policy applies.
Building this register from scratch is often the moment at which the true state of an organisation's policy landscape becomes visible. Outdated policies that should have been retired years ago. Gaps where a required policy was never written. Multiple policies covering overlapping territory, written by different functions without coordination. These are findings worth surfacing, because they represent genuine governance risk.
Every policy needs a named owner who is personally responsible for ensuring it remains accurate, reviewed on schedule, and fit for purpose. Ownership without accountability is just a name on a document. The owner needs to understand the subject matter the policy covers, understand the risks it addresses, have the authority to initiate review and update processes, and be held accountable if the policy drifts out of date.
In practice, ownership often defaults to the function that wrote the policy. This is a reasonable starting point but needs to be reviewed. A data protection policy written by the IT department may be better owned by a qualified data protection officer. An anti-bribery policy written by the legal function may be better owned by the compliance function. Ownership should reflect expertise and accountability, not historical authorship.
Every policy should have a defined review date, and that date should appear both in the policy document itself and in the central register. The review cycle should reflect the pace at which the relevant risk environment changes.
Policies covering fast-moving areas, including data protection, information security, and anything connected to a recently changed regulatory framework, warrant annual review at minimum and may need more frequent attention. Policies in stable, well-established areas may be reviewed every two or three years without material governance risk.
Scheduled reviews are the baseline. Triggered reviews happen when something changes that makes the current policy potentially inadequate: a regulatory change, a significant incident, a material change to the organisation's business or risk profile, or the identification of a gap through audit or a near-miss. Triggered reviews should be initiated promptly and should not wait for the next scheduled cycle.
The review itself should be substantive, not perfunctory. A review that produces the conclusion "no changes required" after fifteen minutes of consideration is not genuinely evaluating whether the policy remains fit for purpose. A meaningful review asks: does this policy still reflect current regulatory requirements? Does it accurately describe how the organisation actually operates? Have any significant risks it addresses changed? Is the language still clear and accessible to its intended audience?
A policy can only serve its purpose if everyone interacting with it is using the same version. Multiple versions in circulation is a governance failure: it means that different staff members, managers, auditors, and regulators may be looking at different, potentially contradictory, documents when they ask what the organisation's position is on a particular matter.
Effective version control requires a single, clearly identified authoritative source for each policy. This should be a location that is accessible to the relevant population, clearly identified as the current version, and updated when the policy changes with the previous version archived rather than deleted.
Version numbering should be consistent across the policy library and should be visible on the document itself. The date of the most recent review and the name of the approver should also appear on the document, both because this is good governance practice and because it provides immediate visible evidence of whether a policy is current when it is produced during an audit.
Policy approval should be genuinely independent of the drafting process. A policy approved by the same person who wrote it has not been subjected to meaningful oversight. Depending on the significance of the policy, approval may appropriately sit with a named executive, a governance or risk committee, or the board.
The approval should be documented in a form that is maintainable over time. An email approval that exists in one person's inbox and disappears when they leave the organisation is not adequate governance evidence. Approval records should be held in the central register alongside the policy itself.
For significant policies, particularly those covering high-risk areas or those required by regulators, approval by a named individual on a specified date should be a matter of permanent record that can be produced on demand.
There is a material difference between a policy having been published and a policy having been communicated. Publication is a necessary condition. It is not sufficient.
Effective communication means ensuring that the people subject to a policy are aware of it, understand its requirements in relation to their role, and have had a genuine opportunity to ask questions. For most policies, this means proactive communication when a policy is first published and when it is materially updated, not simply an expectation that staff will monitor the intranet for new additions to the policy library.
Attestation is the mechanism that converts communication from an assumed outcome to an evidenced one. A recorded confirmation from an individual that they have read and understood a policy, typically captured through a system-generated acknowledgement, provides evidence that staff were genuinely informed. It also has the practical benefit of prompting actual engagement with the content rather than nominal receipt.
The value of attestation as governance evidence should not be underestimated. When a regulator asks whether staff were aware of a particular policy requirement, an attestation record provides a direct, timestamped answer. A claim that the policy "was available on the intranet" does not.
Policies that are no longer relevant should be formally retired rather than left in circulation. An outdated policy that contradicts current practice, or that applies to activities the organisation no longer undertakes, creates confusion and undermines the credibility of the policy library as a whole.
Retirement should be documented: the reason for retirement, the date, and who authorised it. Retired policies should be archived rather than deleted, so that historical evidence of the organisation's approach at a particular time remains available if needed for regulatory or legal purposes.
The state of an organisation's policy library is one of the most visible indicators of governance quality when seen from the outside. A regulator investigating an incident, an external auditor performing a governance review, or an acquirer conducting due diligence will typically examine policies early in the process.
What they are looking for is not just the existence of a policy but evidence that it has been actively managed: reviewed recently by someone with relevant expertise, approved by an appropriate authority, communicated to the relevant population, and maintained in a form that reflects current practice.
A policy last reviewed six years ago with no identifiable owner tells a very different story than one reviewed within the past twelve months, approved by a named executive, with an attestation record showing that staff engaged with it. The latter is evidence of governance. The former raises questions about whether the governance it describes was ever genuinely in place.
References