Good governance requires more than having the right policies.
It also requires knowing when to revisit them.
An organisation can have a comprehensive suite of beautifully drafted policies which, over time, cease to reflect how the organisation operates, the risks it faces, the technology it uses or the expectations placed upon it.
Conversely, reviewing every policy every year simply because “that is what good governance requires” can consume significant management and board time without necessarily improving governance.
The better approach lies somewhere between those two extremes.
There is no universal review cycle
One of the first questions organisations commonly ask is:
Should board-approved policies be reviewed annually, every two years or every three years?
There is no single Australian rule.
Some legislation, regulatory standards and governance guidance impose or recommend particular review periods for particular frameworks or policies. Others do not.
For example, the ASX Corporate Governance Principles and Recommendations contemplate annual board review of a listed entity's risk management framework. ASIC's guidance on whistleblower policies describes periodic review as good practice and suggests every two years as an example. APRA-regulated entities can face more prescriptive requirements relating to their risk management and operational resilience frameworks. Australian Securities Exchange
The lesson is that frequency should follow risk, not convention.
A useful starting principle might therefore be:
Every board-approved policy or governance document should have a defined maximum review period, but that period should reflect the nature, significance and volatility of the subject matter rather than applying one arbitrary interval to everything.
Scheduled reviews should then be supplemented by event-driven reviews whenever circumstances materially change.
Which documents belong on the board's review schedule?
Not every organisational policy needs board approval.
Boards should generally concentrate on policies and governance documents dealing with matters sufficiently significant to warrant board ownership or oversight. The precise suite will depend on the organisation's legal form, industry, activities, scale, complexity and risk profile.
An indicative suite might include the following.
Policy or governance document
Indicative normal review cycle*
Risk management framework / policy and risk appetite
Annual
Delegations of authority
Annual or 1–2 years
Conflicts of interest / related-party dealings
Annual
Cybersecurity / information security
Annual
Privacy and data governance
Annual
AI governance / responsible AI use
6–12 months while the area remains rapidly developing
Business continuity / crisis management
Annual
Work health and safety – where board-approved
Annual, particularly in higher-risk environments
Compliance framework / policy
1–2 years
Anti-bribery and corruption
1–2 years
Fraud control
1–2 years
Whistleblower / speak-up policy
Approximately 2 years, subject to earlier triggers
Code of conduct
1–2 years
Remuneration governance policy
Annual or 1–2 years depending on circumstances
Modern slavery / human rights
1–2 years where applicable
Sustainability / environmental policy
1–2 years where material
Board charter
1–2 years
Board committee charters
1–2 years
Diversity / inclusion policy
1–2 years
Records / information governance
2 years
Procurement / supplier governance – where board-approved
2 years
Continuous disclosure policy – listed entities
Annual or 1–2 years
Securities trading policy – listed entities
Annual or 1–2 years
Shareholder communications policy – listed entities
1–2 years
*These periods are governance starting points, not general statutory requirements. Any specific legal, regulatory, licence, contractual or prudential requirement takes precedence.
Some organisations will need additional policies covering matters such as AML/CTF, outsourcing and material service providers, responsible investment, safeguarding, clinical governance, credit, investment, insurance, fundraising or volunteer management.
Others may reasonably combine subjects into fewer documents.
The objective is not to accumulate policies. It is to maintain the right governance architecture for the organisation concerned.
ASX itself provides a useful illustration of how extensive that architecture can become in a substantial listed organisation: its published governance suite includes policies dealing with anti-bribery and corruption, conflicts management, continuous disclosure, securities dealing, diversity, fraud control, modern slavery, shareholder communications and whistleblowing, among others. Australian Securities Exchange
What should determine the review frequency?
Several factors should influence the answer.
1. Consequence of getting the policy wrong
What could happen if the policy became outdated?
A stale cyber policy, delegation framework or risk appetite may create substantially greater exposure than an outdated policy governing a relatively stable administrative matter.
Higher consequence generally warrants a shorter review cycle.
2. Rate of change
Some areas simply move faster than others.
Technology, AI, cyber risk, privacy, fraud typologies and regulatory compliance are obvious examples.
The AICD's guidance on AI governance recommends that relevant AI, privacy, data governance, cyber and procurement policies be reviewed periodically for currency – a particularly important consideration given the continuing evolution of AI systems and their use within organisations. AICD
3. Operational experience
Reviews should not merely compare current wording against the previous wording.
Boards and management should ask:
- Has the policy actually worked?
- Have breaches or exceptions occurred?
- Is it understood?
- Is it being followed?
- Have internal audit or assurance activities identified weaknesses?
- Is management routinely seeking workarounds?
- Are responsibilities clear?
- Have employees or other users identified practical problems?
ASIC's whistleblower work illustrates this distinction particularly well: reviewing the document is not the same thing as assessing the effectiveness of the underlying program. ASIC Download
4. Organisational change
Growth, restructuring, acquisitions, disposals, entry into another jurisdiction or business line, significant outsourcing, changes to technology or a revised strategy may all justify an earlier review.
Delegations provide a simple example. Approval thresholds appropriate to a small organisation can become unworkable following significant growth.
5. Industry and regulatory environment
A small unregulated proprietary company should not necessarily maintain the same review architecture as a bank, insurer, listed company or large charity.
Proportionality matters.
APRA's risk-management requirements expressly recognise size, business mix and complexity in determining the appropriate framework. APRA
Scheduled reviews are only half the answer
A policy register should not merely say:
Next review: March 2028.
It should also identify circumstances that could bring that date forward.
Typical review triggers include:
- material legislative, regulatory or standards changes;
- a serious incident, breach or near miss;
- internal or external audit findings;
- regulatory investigation or enforcement action;
- material changes to strategy or risk appetite;
- acquisition, divestment or restructuring;
- entry into a new jurisdiction or business activity;
- significant technological change;
- material outsourcing;
- significant changes in organisational scale;
- recurring policy exceptions;
- evidence that employees do not understand or follow the policy;
- benchmarking indicating materially better practice; and
- substantial changes in stakeholder expectations.
The scheduled review date is therefore best regarded as the latest date by which a review should ordinarily occur, not a reason to ignore developments in the meantime.
Build policy reviews into board and committee workplans
There is also a practical issue: board capacity.
Putting eight major policy reviews into the meeting that also approves the financial statements, annual report and AGM materials is unlikely to produce thoughtful governance.
Reviews should instead be distributed across the board and committee calendar.
A risk committee might undertake detailed preliminary consideration of the risk framework, cyber or compliance policies.
A people and culture committee might review remuneration, conduct and workforce-related policies.
A nomination or governance committee might undertake the detailed work on board charters, delegations and governance policies.
The committee can then recommend the policy to the board where final board approval is appropriate.
This is not about removing responsibility from the board. It is about using the governance architecture efficiently so that the board's attention is directed to the issues that matter most.
A policy register should do more than record dates
At minimum, a useful board-policy register might identify:
- document title;
- accountable executive or policy owner;
- approving authority;
- responsible board committee;
- current version;
- date last approved;
- normal review frequency;
- next scheduled review;
- applicable regulatory or governance requirements;
- relevant review triggers; and
- current status.
Larger organisations may also identify interconnected policies so that changing one prompts consideration of others.
For example, a significant change to an AI policy might have consequential implications for privacy, cybersecurity, data governance, records management, procurement and acceptable-use policies.
What should a policy review actually involve?
A review does not necessarily require rewriting the document.
A proportionate process might comprise:
confirming the policy's purpose and continuing need;
checking changes in the organisation and its risk profile;
considering operational experience, incidents, breaches, complaints and exceptions;
considering assurance findings and stakeholder feedback;
checking relevant external requirements and benchmarking where appropriate;
identifying consequential changes to related documents, systems and training;
obtaining committee scrutiny where appropriate;
seeking board approval of material amendments; and
communicating, implementing and recording the approved version.
Importantly, the result may legitimately be:
“Reviewed – no amendment required.”
That is very different from simply rolling the review date forward without undertaking the review.
Is a “Policy on Policies” worthwhile?
For medium-sized and larger organisations, often yes.
A short policy governance framework can establish:
- document classifications;
- who may approve each class;
- minimum contents;
- responsibilities of policy owners;
- review methodology;
- maximum review periods;
- out-of-cycle triggers;
- consultation requirements;
- version control;
- publication;
- training;
- exceptions; and
- archival arrangements.
For a small organisation, the same principles may instead sit within a governance manual or policy register rather than requiring another standalone policy.
The objective should always be control without unnecessary bureaucracy.
The governance test
Ultimately, the question is not:
“Has every policy been reviewed within three years?”
A much better set of questions is:
Do we know which policies matter most? Are their review periods proportionate to their risks? Do we know what would trigger an earlier review? And can the board demonstrate that those policies remain current, understood and effective?
That is the difference between maintaining a library of documents and maintaining a functioning governance framework.
Governance in Action Pty Ltd can assist clients with determining appropriate review dates and reviewing policies (and procedures, etc.).
David Cantrick-Brooks FGIA FCG, Principal & Director of Governance in Action Pty Ltd, would be pleased to assist with enquiries. Please feel free to reach out via LinkedIn or via gia.net.au.
AI-assisted tools and techniques were used here to support the research, drafting and editing of this publication. Responsibility for the final content rests with David Cantrick-Brooks.
Whilst accounting and legal terms and references may be contained in this publication, it does not constitute or purport to be or represent accounting or legal advice of any kind – whatsoever. Readers should seek their own independent professional advice.