Quarterly Policy Review
Quarterly review report with policy update outcomes. Updated policies published with change notifications. Past-due flagged and escalated. Org notified of substantive changes.
Before you start
- Policy library indexed (security, IT, HR, finance, ops)
- Owners assigned per policy
- Review cadence (typically annual minimum, quarterly for fast-changing)
- Policy library current state
- Recent incidents or issues that touched policies
- Regulatory or industry changes since last review
The steps
- Pull policies due for review — Filter the policy library: any policy hitting its quarterly or annual review date in the next 30 days. Group by owner and policy type. Flag any policy past due.
- Identify policies with material change drivers — Beyond cadence, surface policies that should be reviewed because: a related incident happened, regulation changed, vendor changed, organization changed (M&A, headcount, region expansion). Those are urgent reviews.
- Send to owners with review checklist — Each owner gets: their policies due for review, the change drivers (if any), a review checklist (still accurate? still complete? still enforceable? are exceptions documented?), and a 14-business-day SLA.
- Track owner responses and escalate — Track responses. At T-7 days, send reminder. At T-3, escalate to owner's manager. Past-due policies are a compliance risk — owners must respond or be reassigned.
- Consolidate updates and coordinate cross-policy impact — When updates come in, check for cross-policy impact (e.g., a security policy change may affect HR onboarding policy). Coordinate via legal/compliance to prevent contradictory policies.
- Publish updated policies and notify the org — Once finalized, publish updated versions. Send change-summary notifications to affected employees (don't expect them to read the entire policy). Update training materials if substantive change.
- Generate the policy review summary — Quarterly summary: policies reviewed, policies updated, policies past-due, policies retired, new policies created. Distribute to compliance, legal, and exec team. Pattern over time = compliance maturity.
If it goes wrong
Policies sit in 'past due' forever
Hard SLA + escalation path. If owner can't or won't respond, reassign. Past-due is a compliance audit finding, not an inconvenience.
Policy updates contradict other policies
Cross-policy review is a hard step before publishing. If updates contradict, coordinate resolution before either policy ships.
Employees unaware of policy changes
Change-summary notifications, not just publish-and-pray. Tie acknowledgment to the policy via the LMS or policy tool. 'I read it' is the audit trail.
All OpenLabor playbooks