REGULATORY & CONTROL

POLICIES & FRAMEWORKS

A policy nobody uses is a risk, not a control.

The situation

Policy libraries grow by accretion. Each audit, incident and certification adds a document, and few are ever retired.

What remains is a structure where standards contradict procedures, approval dates matter more than content, and the people expected to comply have never read any of it.

The question

If we removed this document, what would actually change?

The work

We rationalise the hierarchy: what belongs in policy, what belongs in standards, what belongs in procedure, and what should not be written down at all.

Each document gets an owner, a purpose and an audience. Language is rewritten for the people who have to follow it, and requirements are made testable so that control design and assurance have something to attach to.

Where management-system disciplines are already in use, we keep them coherent with the wider governance structure rather than running them in parallel.

The outcome

Fewer documents, clearly owned, that describe how the organisation actually works and can be maintained without a project.

From your seat

How we might work