Resources · Diagnostic

The policy test.

Eight questions, run against one policy at a time. Most organisations have a shelf of policies and very little idea which of them would survive being tested. This tells you, one document at a time.

Everything stays on this page. Nothing is recorded, stored or sent to us — the result is worked out in your own browser.

Optional — it simply personalises your result. Test one policy, then run it again for the next.

1.Was this policy written for your organisation — or adapted from a template without changing its substance?

A policy describing an organisation that does not exist protects nobody.

2.Does it serve a stated objective of the organisation — and can you say which one?

A policy that exists only because someone said you should have one will be applied that way too.

3.Does it identify the law, standard or founding document it gives effect to?

Anchoring a policy to its source is what tells a reader — or a regulator — where its authority comes from.

4.Does it say what someone must actually do — rather than what the organisation is “committed to”?

Every clause should answer: what does a person do differently because this exists?

5.Can you name the person accountable for applying it — and do they know?

An unowned policy is nobody’s job, which means it is nobody’s failure either.

6.Does it carry a version number, an approval date, and the body that approved it?

Without approval evidence, you may struggle to show which version applied on the day it mattered.

7.Has it been reviewed within the last two years — or since the last relevant change in the law?

Whichever came first. Two years is the outer limit, not the target.

8.If someone breached it tomorrow, does it say what happens next — and could those bound by it find it within five minutes?

A rule with no consequence is guidance. A rule nobody can locate is nothing at all.

0 of 8 answered

How often should a policy be reviewed?

Two years is a sound outer limit, and the discipline of a fixed cycle is worth more than a perfect schedule nobody keeps. But a calendar alone is not enough, because policies do not age at the same rate.

  • Annually — where the law moves or the risk is severe: data protection, disciplinary and grievance, health and safety, procurement, delegation of authority.
  • Every two years — the default for everything else, as an outer limit rather than a target.
  • Immediately, on a trigger — a change in the law, a restructure, an incident or near-miss, an audit or regulator finding, a new system, or a new funder requirement.

A review does not have to produce a new version. Recording that the policy was considered and remains fit is a legitimate outcome — and it is evidence of a functioning control.

The uncomfortable part

A policy nobody follows is not a neutral document sitting harmlessly in a folder. It is a written record of a standard you set for yourself and did not meet — and in a dispute, an arbitration or a regulator’s inquiry, your own policy is often the first document produced against you.

Which is why the honest answer to a failing policy is rarely “add more policies”. It is to make the ones you have shorter, sharper and genuinely applied.

This diagnostic is a general indicator, not an audit or legal advice. What a specific policy must contain depends on your organisation’s form, sector, founding documents and the legislation that applies to it.

Start here

Tell us the decision your organisation needs to make.

The first conversation is thirty minutes, confidential and free. You will leave it knowing which of our services you need and which you do not.

Book a scoping call