GRC SaaS

Governance and Policy

Govern policies, procedures and board approvals from one platform.

Prepare, review, approve, publish and maintain policies, guidelines and departmental procedures through controlled workflows and a complete audit history.

Overview

Policies are written, reviewed and approved without leaving the platform, and stay connected to the controls, risks and compliance obligations they govern — so a reviewer is never working from a document with no traceable link to what it actually affects.

The business problem

  • Policy drafts circulate by email with no single source of truth for the current version.
  • Board review and sign-off happens outside the system that tracks everything else, breaking the audit trail.
  • Review dates and renewal deadlines are tracked manually and get missed.
  • Departmental SOPs and staff acknowledgement have no reliable completion record.

Key capabilities

Policy preparation

  • Create from a template or from scratch
  • Assign owner and department
  • Link to regulations, controls, risks and compliance requirements
  • Attach supporting documents
  • Invite reviewers and manage comments
  • Submit for review and track status

Review and approval

  • Multi-level review: legal, compliance, management, board
  • Comment, request changes, approve, or reject with a reason
  • Digital signature with date and timestamp
  • Full approval history retained against the policy

Board governance

  • Secure, restricted board-level access
  • Policy packs assembled for board review
  • Approval or voting with a recorded decision
  • Sign-off history with review deadlines

Guidelines and procedures

  • Create SOPs per department from templates
  • Define a process owner and step-by-step instructions
  • Management review and sign-off before publishing
  • Scheduled training with tracked completion and overdue acknowledgement

How it works

  1. 1A policy owner drafts a policy and links it to the controls and risks it governs.
  2. 2Legal and compliance reviewers comment and request changes.
  3. 3The revised draft goes to management, then to the board, for approval.
  4. 4A board member signs off digitally; the decision, date, and timestamp are recorded.
  5. 5The policy publishes with a scheduled review date and a reminder set in advance of it.
  6. 6Staff acknowledge the policy; overdue acknowledgements are tracked and escalated.

How this works by department

The same module, applied to how each department actually uses it.

Finance

Finance policies — expense authority, treasury limits, financial reporting standards — are drafted, reviewed by Legal and the CFO, and signed off by the board before they take effect.

HR

HR SOPs — onboarding, leave, disciplinary process — are versioned and routed for management sign-off, with staff acknowledgement tracked per policy.

Legal/Compliance

Legal and Compliance own the review stage for every policy in the platform, checking regulatory alignment before a draft reaches the board.

Procurement/Vendor Management

Procurement policies — approval thresholds, vendor onboarding standards — link directly to the Vendor Management module, so a policy change is reflected in vendor review criteria immediately.

IT/Security

IT security policies — access control, data handling, incident response — are reviewed by IT and Legal jointly, then published with a mandatory acknowledgement for all technical staff.

Risk & Audit

Risk and Audit confirm that every published policy maps to the control or risk it's meant to govern before sign-off is considered complete.

See it in the platform

Product screenshots for Governance and Policy are available in a live walkthrough with a specialist.

View Product Demo →

Dashboards and reports

Policy status across the organisation
Policies awaiting review or board approval
Overdue policies
Policies by department
Staff acknowledgement completion
SOP training status
Change and approval history

Typical users

Policy OwnerCompliance OfficerLegal CounselBoard MemberDepartment Head

Business outcomes

  • Replace email-based approval chains with a controlled, auditable workflow
  • Give the board secure, purpose-built access instead of ad hoc document packs
  • Never miss a scheduled review or renewal
  • Prove staff acknowledgement, not just publication

Frequently asked questions

Can board members review and approve policies without a separate tool?
Yes — board members get secure, restricted access to policy packs, review comments, and a digital sign-off with a recorded decision, date, and timestamp.
Can we track SOP training and acknowledgement, not just publish the document?
Yes — SOPs can carry a scheduled training requirement, and the platform tracks completion and flags overdue acknowledgement per staff member.

Build a more connected governance and policy programme.