Everything stays on this page. Nothing is recorded, stored or sent to us — the result is worked out in your own browser.
Thank you — your result is on its way. We reply within three (3) working days.
How often should a policy be reviewed?
Two years is a sound outer limit, and the discipline of a fixed cycle is worth more than a perfect schedule nobody keeps. But a calendar alone is not enough, because policies do not age at the same rate.
- Annually — where the law moves or the risk is severe: data protection, disciplinary and grievance, health and safety, procurement, delegation of authority.
- Every two years — the default for everything else, as an outer limit rather than a target.
- Immediately, on a trigger — a change in the law, a restructure, an incident or near-miss, an audit or regulator finding, a new system, or a new funder requirement.
A review does not have to produce a new version. Recording that the policy was considered and remains fit is a legitimate outcome — and it is evidence of a functioning control.
The uncomfortable part
A policy nobody follows is not a neutral document sitting harmlessly in a folder. It is a written record of a standard you set for yourself and did not meet — and in a dispute, an arbitration or a regulator’s inquiry, your own policy is often the first document produced against you.
Which is why the honest answer to a failing policy is rarely “add more policies”. It is to make the ones you have shorter, sharper and genuinely applied.
This diagnostic is a general indicator, not an audit or legal advice. What a specific policy must contain depends on your organisation’s form, sector, founding documents and the legislation that applies to it.
