Policies are often treated as static documents when they should be managed as living controls. In many audits and supervisory reviews, policies are among the first documents requested because they show how leaders expect the organisation to operate, how obligations are translated into rules and whether accountability has been formalised.
This is worth sitting with for a moment, because it explains why policy management deserves far more attention than it typically receives. A policy is not simply a record of intent. It is the formal articulation of how the board and senior management expect risk to be controlled across the organisation, and it is the first thing most auditors and supervisors reach for when assessing whether a firm's stated practices match its documented expectations. A firm with strong informal practices but poor policy documentation will struggle to demonstrate this alignment, regardless of how well things actually function day to day.
Why policy management matters more than policy writing
Writing a policy is relatively easy. Making sure it is approved, current, communicated, understood, attested to and exception-managed is much harder. That is why policy management should be treated as a lifecycle discipline rather than an authorship exercise.
The temptation, particularly under time pressure, is to treat policy work as complete once a document has been drafted and signed off. In practice, that is closer to the beginning of the work than the end. A policy that sits unread on a shared drive, or that staff technically acknowledged receiving years ago but have never been retrained on, provides very little real protection, regardless of how well it was written. The genuine value of a policy comes from the surrounding process: ensuring it reflects current regulatory and operational reality, ensuring people actually understand what is expected of them, and ensuring senior management periodically confirms it is being followed in practice rather than simply assuming it is.
The policy lifecycle that works in practice
Drafting and approval
Each policy needs a clear owner, sponsor, purpose and approval route. Senior leaders should know who is accountable for content and who decides when material changes are approved. For example, the Operational Risk Policy might be owned by the Chief Risk Officer, Head of Risk or equivalent.
Ownership clarity matters more than it might seem at first glance, particularly in smaller organisations where responsibilities can blur. If nobody is explicitly accountable for a policy's content and currency, it tends to drift out of date quietly, with nobody noticing until an audit or a regulatory examination surfaces the gap. Each significant policy should have a named owner, typically a senior manager with genuine subject matter expertise and authority over the area the policy covers, and an approval route that is appropriate to the policy's significance: board approval for the most material policies, such as the overarching risk management or compliance policy, and senior management or committee approval for more operational, narrower-scope documents.
Version control and register management
Maintain a centralised policy register with clear version numbers and review dates. Every new version should be date-stamped and old versions archived for audit. Without one, firms struggle to prove which policy was active at the time of a decision, incident or audit test.
This sounds like a purely administrative concern until the moment it genuinely matters, which is usually during an investigation into a past incident or a regulatory inquiry into a historical decision. Being able to demonstrate precisely which version of a policy was in force at a specific point in time, and what it required at that point, can be the difference between a straightforward explanation and a much more difficult conversation with a supervisor. A simple, centrally maintained register, with clear version numbering, effective dates, and archived copies of every prior version, is not a sophisticated capability to build, but it is one that pays for itself the first time it is genuinely needed.
Communication, training and attestation
Publication is not the same as communication. Staff need training where appropriate, and senior managers should periodically attest that policies are implemented in their areas. This turns policy ownership into a management responsibility rather than a compliance filing task.
The distinction between publishing a policy and actually communicating it is genuinely important, and it is one regulators have become increasingly focused on. Publishing a policy means making the document available somewhere staff could, in theory, find it. Communicating it means ensuring the people whose work the policy governs actually understand what it requires of them, which usually means some combination of structured training, briefings, or e-learning modules tailored to the relevant audience, followed by a mechanism for confirming that understanding, such as a staff attestation. Senior manager attestations add a further layer that regulators look for specifically: a periodic, formal confirmation from the people accountable for a business area that the relevant policies are genuinely being implemented in practice, not just acknowledged on paper. This cascades accountability downward in a way that a one-off training session at onboarding never quite achieves.
Exceptions and waivers
Every policy environment needs a controlled waiver process. Approved exceptions should be documented, time-bound, risk-assessed and reviewed before expiry. That protects the integrity of the framework while recognising operational reality.
No policy framework survives contact with real operational complexity without some mechanism for managing legitimate exceptions. The alternative to a controlled exception process is not perfect policy compliance; it is uncontrolled, undocumented deviation that nobody is tracking, which is considerably worse from a risk management perspective. A proper waiver process requires that any deviation from policy be formally requested, assessed for the additional risk it introduces, approved at an appropriate level given that risk, time-bound rather than open-ended, and accompanied by any compensating controls needed to manage the gap in the interim. Crucially, the process needs a mechanism to confirm, when the waiver's expiry date arrives, that the underlying issue has actually been resolved and the firm has returned to full policy compliance, rather than the waiver simply being quietly extended indefinitely.
The failure points to watch
Organisations usually struggle with four things: duplicate policies, missed review dates, weak evidence of communication and untracked exceptions. A mature process reduces each of those by centralising policy data, linking policies to obligations and controls, and assigning owners for every lifecycle stage.
Duplicate or conflicting policies tend to emerge organically in growing organisations, where different teams independently draft guidance covering overlapping ground, sometimes with subtly inconsistent requirements that create genuine confusion for staff trying to follow them. Missed review dates are a function of poor calendar discipline more than anything else, and they are entirely preventable with a properly maintained register and review schedule. Weak evidence of communication, as discussed above, is one of the most commonly cited findings in audits and supervisory reviews, precisely because firms often assume that publication equals communication when supervisors expect to see something more substantive. And untracked exceptions, left unmanaged, gradually erode the practical meaning of the policy itself, until the documented requirement and the actual operating practice diverge so far that the policy no longer reflects reality.
Conclusion
Policy management is not glamorous, but it is foundational. If the organisation cannot show which policies apply, who owns them and whether people follow them, every other risk and compliance process becomes harder to evidence.
A disciplined approach to the policy lifecycle, covering drafting, approval, communication, attestation and exception management, is exactly the kind of foundational work that strengthens every other part of the operational risk framework. Our full whitepaper covers this lifecycle in detail, with practical guidance on building a policy register and embedding accountability at each stage. Download the complete Operational Risk whitepaper for the full approach.