Policy approval best practices

Just thinking out loud here - I see two requirements for Policy approvals - 1. All policies are reviewed and approved on at least an annual basis and 2. All policies that are changed are approved.

For 1, that’s just setting your review interval and running with it.

For 2, with the assumption you link back to your Wiki, I could see adding a Control that’s performed quarterly to see if there are any policies with modification dates since the last approval and confirm that approvals were applied in Eramba (this would be outside of the Policy Management process screens).

The other consideration here is whether your policies are too granular - in general, they shouldn’t change significantly year over year unless there has been a major organization change or a new set of requirements. Pushing some of the policy specifics into Standards and Procedures may be worthwhile (assuming you have a higher threshold for approval of Policies than those). The other thought would be - do we really want to make this update now or wait until the next policy cycle?

The other consideration with policy changes is communication to end users. When you look at various audit requirements (i.e. SOC 2 where I tend to live), if you change a policy you then need to communicate it to relevant individuals. To me, this makes an additional point for trying to limit updates to annually unless your face is melting in need of a change…