Governance and Policy
Govern policies, procedures and board approvals from one platform.
Prepare, review, approve, publish and maintain policies, guidelines and departmental procedures through controlled workflows and a complete audit history.
Overview
Policies are written, reviewed and approved without leaving the platform, and stay connected to the controls, risks and compliance obligations they govern — so a reviewer is never working from a document with no traceable link to what it actually affects.
The business problem
- Policy drafts circulate by email with no single source of truth for the current version.
- Board review and sign-off happens outside the system that tracks everything else, breaking the audit trail.
- Review dates and renewal deadlines are tracked manually and get missed.
- Departmental SOPs and staff acknowledgement have no reliable completion record.
Key capabilities
Policy preparation
- Create from a template or from scratch
- Assign owner and department
- Link to regulations, controls, risks and compliance requirements
- Attach supporting documents
- Invite reviewers and manage comments
- Submit for review and track status
Review and approval
- Multi-level review: legal, compliance, management, board
- Comment, request changes, approve, or reject with a reason
- Digital signature with date and timestamp
- Full approval history retained against the policy
Board governance
- Secure, restricted board-level access
- Policy packs assembled for board review
- Approval or voting with a recorded decision
- Sign-off history with review deadlines
Guidelines and procedures
- Create SOPs per department from templates
- Define a process owner and step-by-step instructions
- Management review and sign-off before publishing
- Scheduled training with tracked completion and overdue acknowledgement
How it works
- 1A policy owner drafts a policy and links it to the controls and risks it governs.
- 2Legal and compliance reviewers comment and request changes.
- 3The revised draft goes to management, then to the board, for approval.
- 4A board member signs off digitally; the decision, date, and timestamp are recorded.
- 5The policy publishes with a scheduled review date and a reminder set in advance of it.
- 6Staff acknowledge the policy; overdue acknowledgements are tracked and escalated.
How this works by department
The same module, applied to how each department actually uses it.
Finance
Finance policies — expense authority, treasury limits, financial reporting standards — are drafted, reviewed by Legal and the CFO, and signed off by the board before they take effect.
HR
HR SOPs — onboarding, leave, disciplinary process — are versioned and routed for management sign-off, with staff acknowledgement tracked per policy.
Legal/Compliance
Legal and Compliance own the review stage for every policy in the platform, checking regulatory alignment before a draft reaches the board.
Procurement/Vendor Management
Procurement policies — approval thresholds, vendor onboarding standards — link directly to the Vendor Management module, so a policy change is reflected in vendor review criteria immediately.
IT/Security
IT security policies — access control, data handling, incident response — are reviewed by IT and Legal jointly, then published with a mandatory acknowledgement for all technical staff.
Risk & Audit
Risk and Audit confirm that every published policy maps to the control or risk it's meant to govern before sign-off is considered complete.
See it in the platform
Product screenshots for Governance and Policy are available in a live walkthrough with a specialist.
View Product Demo →Dashboards and reports
Typical users
Business outcomes
- Replace email-based approval chains with a controlled, auditable workflow
- Give the board secure, purpose-built access instead of ad hoc document packs
- Never miss a scheduled review or renewal
- Prove staff acknowledgement, not just publication
Frequently asked questions
- Can board members review and approve policies without a separate tool?
- Yes — board members get secure, restricted access to policy packs, review comments, and a digital sign-off with a recorded decision, date, and timestamp.
- Can we track SOP training and acknowledgement, not just publish the document?
- Yes — SOPs can carry a scheduled training requirement, and the platform tracks completion and flags overdue acknowledgement per staff member.
Part of the connected GRC platform