Policy review cycle checklist

Policies decay without anyone noticing, because nothing breaks when they go stale. The document still opens, the wording still sounds reasonable, and it has quietly stopped describing how the company works. An annual pass catches the drift while it is still small.

Annually per policy, staggered so a handful fall due each quarter rather than all in one month. Half a day per quarter for a dozen policies.

The checklist

  1. 01List every published policy with its owner and last edit dateOwner: HR
  2. 02Flag anything not edited in twelve months as dueOwner: HR
  3. 03Ask each owner whether practice has changed since the last editOwner: HR lead
  4. 04Check every policy against the support tickets it should have preventedOwner: HR lead
  5. 05Rewrite what changed, and delete what nobody follows any moreOwner: Policy owner
  6. 06Check the categories still make sense and nothing is filed oddlyOwner: HR
  7. 07Republish, and confirm the document was reindexed for searchOwner: HR
  8. 08Ask the policy assistant three real questions and read the answersOwner: HR
  9. 09Tell people what changed, in a sentence, rather than resending the documentOwner: HR lead
  10. 10Set the next review date and name its ownerOwner: HR lead

What goes wrong

  • Reviewing by reading rather than by asking. A policy reads fine and still describes a process that changed last spring.
  • Republishing without checking the document was reindexed, so search keeps returning the previous version.
  • Keeping a rule nobody follows. An unenforced policy teaches people that policies are optional.
  • Sending the whole document instead of the change, so nobody reads either.
  • No named owner for the next review, which is how twelve months becomes three years.

Questions people ask

How often should a policy be reviewed?

Annually for most, and immediately after any real change in practice. Staggering the dates avoids a single month where everything is due.

How do you know a republished policy is searchable?

The authoring screen shows how many chunks were indexed. A policy that produced none did not index, whatever the publish button said.

What should trigger a review outside the schedule?

A change in how the work actually happens, or a cluster of support tickets about the same topic. Both mean the document has fallen behind.