Policy Management Best Practices: How to Keep Your Organisation's Policies Alive and Effective
Most organisations across Africa have policies. The question that matters is whether those policies are doing any useful work.
A policy that sits in a shared drive, last reviewed three years ago, known to exist by the team that wrote it but rarely consulted by anyone else, is not an asset. It is a liability. If it is cited in an audit, its outdated provisions may actually undermine the organisation's compliance position. If an incident occurs, a poorly maintained policy can be used as evidence of negligence rather than diligence.
Policy management is not a documentation exercise. It is a governance discipline - one that, when done well, shapes behaviour, reduces risk and provides an auditable record of the organisation's standards. This article sets out the practices that distinguish effective policy programmes from the kind that accumulate documents without generating value.
Start with Ownership, Not Documents in Africa
The most common failure in policy management is creating policies without assigning meaningful ownership. A policy that is owned by "the compliance team" or "the legal department" as a collective entity tends to drift. Nobody feels personally accountable for keeping it current. Review deadlines pass without consequence. When a question arises about whether a policy still reflects current practice, nobody is sure who to ask.
Effective policy management assigns each policy to a named individual who is responsible for its accuracy, its review schedule and its communication to relevant staff. That owner has the authority to initiate updates, to escalate for approval and to confirm that the policy reflects current operating practice. Without individual ownership, policies become institutional fiction.
Define the Lifecycle Before You Write the Policy
Every policy should be created with its full lifecycle in mind. This means answering several questions before the first draft is written: Who has the authority to approve this policy? Who needs to be consulted during drafting? How often does it need to be reviewed? What circumstances would trigger an unscheduled review? When this policy is eventually retired, what will replace it?
Building lifecycle thinking into the policy creation process prevents the accumulation of zombie policies - documents that exist in the system but have no clear owner, no defined review schedule and no living connection to current practice. A GRC platform enforces lifecycle discipline by requiring these fields to be populated before a policy can be published, and by automating the review scheduling and notification processes that keep policies current.
The Five Stages of the Policy Lifecycle
A well-managed policy moves through five stages:
- Draft: The policy is being written and refined. It is not yet in effect. Relevant stakeholders are consulted and drafts are circulated for comment.
- Approval: The draft is submitted to the designated approver. This may involve legal review, senior leadership sign-off or board approval depending on the policy's scope and significance.
- Published: The approved policy is active and communicated to all relevant personnel. The effective date is recorded.
- Under Review: The policy has reached its scheduled review date, or a triggering event has initiated an unscheduled review. The owner is actively assessing whether updates are required.
- Retired: The policy has been superseded or is no longer required. Its retirement is documented, and where a replacement exists, the relationship is recorded.
Tracking policies against these stages gives compliance officers and leadership an accurate picture of the organisation's policy health at any point in time. Policies pending review are visible. Policies overdue for review are flagged. No policy falls through the cracks because the system is tracking every one.
Link Policies to Compliance Requirements
One of the most powerful things an organisation can do with its policy programme is link each policy explicitly to the compliance requirements it satisfies. When a policy is approved and published, the compliance management system records which regulatory requirements - SOC2 controls, ISO 27001 clauses, NIST control families - that policy addresses.
This linkage has two immediate benefits. First, it makes audit preparation dramatically faster. When an auditor asks for evidence that a specific control is in place, the system can immediately identify which policy addresses that control and confirm its current status. Second, it provides an early warning system for compliance gaps. If a policy is retired without a replacement, the compliance requirements it was satisfying are immediately flagged as potentially uncovered.
Communication is Part of the Policy
A policy that is approved but not communicated is almost as ineffective as a policy that does not exist. The people who need to follow a policy need to know it exists, understand what it requires of them, and have a way to access it when they need it.
This sounds obvious, but the communication step is frequently underinvested. Policies are published to a shared drive and an email is sent to announce them. Six months later, new staff who joined after the announcement have never been made aware of the policy. Existing staff who received the announcement email have forgotten its contents.
Effective policy communication involves role-based access - so that staff only see the policies relevant to their function, making the policy library a useful tool rather than an overwhelming archive. It also involves acknowledgement workflows for high-significance policies, ensuring that there is a record of who has read and understood critical governance documents.
Use Technology to Enforce the Discipline
The practices described above are not difficult to understand. The challenge is implementing them consistently across an organisation with hundreds of policies, dozens of policy owners and competing operational demands. Manual processes struggle to maintain the discipline over time. Review deadlines are missed. Ownership becomes unclear when staff change roles. Communication steps are skipped under time pressure.
GRC platforms like EliteGRC automate the discipline. Review schedules are set once and generate notifications automatically. Policy owners are reminded of upcoming reviews. Approvals are tracked through defined workflows. The system maintains a full audit trail of every policy's history - who approved it, when it was communicated, when it was last reviewed and what changes were made.
The result is a policy programme that runs continuously rather than in bursts, and that produces the audit-ready documentation that compliance requires without demanding constant manual effort from the compliance team.
Automate Your Policy Lifecycle with EliteGRC
EliteGRC Policy Management tracks every policy from creation through approval, publication and review - automatically. Get started free or talk to us about a Pro plan.