How Often Should Boards Review Their Policies? A Practical Governance Approach
How Often Should Boards Review Their Policies? A Practical Governance Approach
David Cantrick-Brooks | 03/10/2026

Good governance requires more than having the right policies.

It also requires knowing when to revisit them.

An organisation can have a comprehensive suite of beautifully drafted policies which, over time, cease to reflect how the organisation operates, the risks it faces, the technology it uses or the expectations placed upon it.

Conversely, reviewing every policy every year simply because “that is what good governance requires” can consume significant management and board time without necessarily improving governance.

The better approach lies somewhere between those two extremes.

There is no universal review cycle

One of the first questions organisations commonly ask is:

Should board-approved policies be reviewed annually, every two years or every three years?

There is no single Australian rule.

Some legislation, regulatory standards and governance guidance impose or recommend particular review periods for particular frameworks or policies. Others do not.

For example, the ASX Corporate Governance Principles and Recommendations contemplate annual board review of a listed entity's risk management framework. ASIC's guidance on whistleblower policies describes periodic review as good practice and suggests every two years as an example. APRA-regulated entities can face more prescriptive requirements relating to their risk management and operational resilience frameworks. Australian Securities Exchange

The lesson is that frequency should follow risk, not convention.

A useful starting principle might therefore be:

Every board-approved policy or governance document should have a defined maximum review period, but that period should reflect the nature, significance and volatility of the subject matter rather than applying one arbitrary interval to everything.

Scheduled reviews should then be supplemented by event-driven reviews whenever circumstances materially change.

Which documents belong on the board's review schedule?

Not every organisational policy needs board approval.

Boards should generally concentrate on policies and governance documents dealing with matters sufficiently significant to warrant board ownership or oversight. The precise suite will depend on the organisation's legal form, industry, activities, scale, complexity and risk profile.

An indicative suite might include the following.

Policy or governance document

Indicative normal review cycle*

Risk management framework / policy and risk appetite

Annual

Delegations of authority

Annual or 1–2 years

Conflicts of interest / related-party dealings

Annual

Cybersecurity / information security

Annual

Privacy and data governance

Annual

AI governance / responsible AI use

6–12 months while the area remains rapidly developing

Business continuity / crisis management

Annual

Work health and safety – where board-approved

Annual, particularly in higher-risk environments

Compliance framework / policy

1–2 years

Anti-bribery and corruption

1–2 years

Fraud control

1–2 years

Whistleblower / speak-up policy

Approximately 2 years, subject to earlier triggers

Code of conduct

1–2 years

Remuneration governance policy

Annual or 1–2 years depending on circumstances

Modern slavery / human rights

1–2 years where applicable

Sustainability / environmental policy

1–2 years where material

Board charter

1–2 years

Board committee charters

1–2 years

Diversity / inclusion policy

1–2 years

Records / information governance

2 years

Procurement / supplier governance – where board-approved

2 years

Continuous disclosure policy – listed entities

Annual or 1–2 years

Securities trading policy – listed entities

Annual or 1–2 years

Shareholder communications policy – listed entities

1–2 years

*These periods are governance starting points, not general statutory requirements. Any specific legal, regulatory, licence, contractual or prudential requirement takes precedence.

Some organisations will need additional policies covering matters such as AML/CTF, outsourcing and material service providers, responsible investment, safeguarding, clinical governance, credit, investment, insurance, fundraising or volunteer management.

Others may reasonably combine subjects into fewer documents.

The objective is not to accumulate policies. It is to maintain the right governance architecture for the organisation concerned.

ASX itself provides a useful illustration of how extensive that architecture can become in a substantial listed organisation: its published governance suite includes policies dealing with anti-bribery and corruption, conflicts management, continuous disclosure, securities dealing, diversity, fraud control, modern slavery, shareholder communications and whistleblowing, among others. Australian Securities Exchange

What should determine the review frequency?

Several factors should influence the answer.

1. Consequence of getting the policy wrong

What could happen if the policy became outdated?

A stale cyber policy, delegation framework or risk appetite may create substantially greater exposure than an outdated policy governing a relatively stable administrative matter.

Higher consequence generally warrants a shorter review cycle.

2. Rate of change

Some areas simply move faster than others.

Technology, AI, cyber risk, privacy, fraud typologies and regulatory compliance are obvious examples.

The AICD's guidance on AI governance recommends that relevant AI, privacy, data governance, cyber and procurement policies be reviewed periodically for currency – a particularly important consideration given the continuing evolution of AI systems and their use within organisations. AICD

3. Operational experience

Reviews should not merely compare current wording against the previous wording.

Boards and management should ask:

ASIC's whistleblower work illustrates this distinction particularly well: reviewing the document is not the same thing as assessing the effectiveness of the underlying program. ASIC Download

4. Organisational change

Growth, restructuring, acquisitions, disposals, entry into another jurisdiction or business line, significant outsourcing, changes to technology or a revised strategy may all justify an earlier review.

Delegations provide a simple example. Approval thresholds appropriate to a small organisation can become unworkable following significant growth.

5. Industry and regulatory environment

A small unregulated proprietary company should not necessarily maintain the same review architecture as a bank, insurer, listed company or large charity.

Proportionality matters.

APRA's risk-management requirements expressly recognise size, business mix and complexity in determining the appropriate framework. APRA

Scheduled reviews are only half the answer

A policy register should not merely say:

Next review: March 2028.

It should also identify circumstances that could bring that date forward.

Typical review triggers include:

The scheduled review date is therefore best regarded as the latest date by which a review should ordinarily occur, not a reason to ignore developments in the meantime.

Build policy reviews into board and committee workplans

There is also a practical issue: board capacity.

Putting eight major policy reviews into the meeting that also approves the financial statements, annual report and AGM materials is unlikely to produce thoughtful governance.

Reviews should instead be distributed across the board and committee calendar.

A risk committee might undertake detailed preliminary consideration of the risk framework, cyber or compliance policies.

A people and culture committee might review remuneration, conduct and workforce-related policies.

A nomination or governance committee might undertake the detailed work on board charters, delegations and governance policies.

The committee can then recommend the policy to the board where final board approval is appropriate.

This is not about removing responsibility from the board. It is about using the governance architecture efficiently so that the board's attention is directed to the issues that matter most.

A policy register should do more than record dates

At minimum, a useful board-policy register might identify:

Larger organisations may also identify interconnected policies so that changing one prompts consideration of others.

For example, a significant change to an AI policy might have consequential implications for privacy, cybersecurity, data governance, records management, procurement and acceptable-use policies.

What should a policy review actually involve?

A review does not necessarily require rewriting the document.

A proportionate process might comprise:

confirming the policy's purpose and continuing need;

checking changes in the organisation and its risk profile;

considering operational experience, incidents, breaches, complaints and exceptions;

considering assurance findings and stakeholder feedback;

checking relevant external requirements and benchmarking where appropriate;

identifying consequential changes to related documents, systems and training;

obtaining committee scrutiny where appropriate;

seeking board approval of material amendments; and

communicating, implementing and recording the approved version.

Importantly, the result may legitimately be:

“Reviewed – no amendment required.”

That is very different from simply rolling the review date forward without undertaking the review.

Is a “Policy on Policies” worthwhile?

For medium-sized and larger organisations, often yes.

A short policy governance framework can establish:

For a small organisation, the same principles may instead sit within a governance manual or policy register rather than requiring another standalone policy.

The objective should always be control without unnecessary bureaucracy.

The governance test

Ultimately, the question is not:

“Has every policy been reviewed within three years?”

A much better set of questions is:

Do we know which policies matter most? Are their review periods proportionate to their risks? Do we know what would trigger an earlier review? And can the board demonstrate that those policies remain current, understood and effective?

That is the difference between maintaining a library of documents and maintaining a functioning governance framework.

Governance in Action Pty Ltd can assist clients with determining appropriate review dates and reviewing policies (and procedures, etc.).

David Cantrick-Brooks FGIA FCG, Principal & Director of Governance in Action Pty Ltd, would be pleased to assist with enquiries. Please feel free to reach out via LinkedIn or via gia.net.au.

AI-assisted tools and techniques were used here to support the research, drafting and editing of this publication. Responsibility for the final content rests with David Cantrick-Brooks.

Whilst accounting and legal terms and references may be contained in this publication, it does not constitute or purport to be or represent accounting or legal advice of any kind – whatsoever. Readers should seek their own independent professional advice.

PreviousNext

Related Articles

From More Board Papers to Better Board Questions: What Telstra’s AI Agent Tells Us About the Future

Artificial intelligence may have a more important role in the boardroom than simply drafting papers, summarising reports or producing minutes. Telstra’s purpose-built Board AI agent points to a different possibility: using AI to help directors retrieve, connect and interrogate trusted board information so they can ask better questions. This article explores what that development may mean for board effectiveness, board reporting, company secretaries and the governance of AI itself – and why the objective should not be to automate board judgement, but to create more space for informed challenge, institutional memory and sound decision-making.

10/01/2026

External Audits: A Director’s Guide from Planning to Sign-off

External audits are an important source of independent assurance – but they do not relieve directors of responsibility for the financial report. This practical guide explains the external audit process from a director’s governance perspective, from auditor selection and planning through to year-end testing, written representations and the final audit opinion. It examines where boards and Audit Committees should engage, how to approach auditor independence and non-audit services, why uncorrected audit differences deserve attention, and the particular care required when legal professional privilege is involved. It also considers auditors’ statutory reporting obligations to ASIC, the growing use of AI in audit, sustainability assurance and forthcoming changes to Australian auditing standards. Above all, it explains why directors must continue to bring their own informed and enquiring judgement to financial reporting rather than treating external audit as a substitute for board oversight.

09/20/2026

Keeping Your Governance Records in Shape: Why Periodic Health Checks Matter

Good governance leaves a record. But when did your organisation last examine whether its governance records are complete, accurate, current, secure and genuinely fit for purpose? Governance records extend well beyond financial books and records. They include statutory registers, board and committee records, constitutions and charters, policies, director appointment and induction materials, regulatory lodgements, workplans, delegations and the systems used to create, approve, store, retrieve, retain and ultimately destroy them. A periodic independent governance health check can provide a fresh perspective on whether these records and processes remain compliant, consistent and effective. Properly scoped, such a review complements rather than duplicates the work of the company secretary, internal audit and external audit. It can also identify opportunities to simplify processes, strengthen assurance, improve information security and make responsible use of AI. This article considers what a governance health check should cover, how often one might be undertaken and why good governance hygiene increasingly requires attention to the complete lifecycle of an organisation's records.

09/19/2026