10 steps for a successful policy and procedure update process in 2026

A policy and procedure update process keeps organisational documents accurate, compliant and trusted.

It runs through planning, assessment, structured organisation, stakeholder input, revision, approval, and finally publication – in that order, so nothing gets drafted or signed off before you actually know what needs to change. By not defining the process and allowing consequences of skipping a stage or running them out of order, you will often cause the process to stall or, worse, to produce a version nobody trusts. The ten steps below cover what to do at each stage to resolve where document updates typically go wrong.

https://xoralia.com/policy-management-software/policy-management-software-attestation/

A document update usually gets triggered one of three ways: a policy reaching its expiry date on a regular scheduled cycle (annually or six-monthly, set in advance), a specific event such as a regulatory change or an incident, or a wider overhaul where an organisation is standardising how it manages policies altogether. Whatever the trigger, the steps that follow are the same – and the order matters as much as the steps themselves. Updating policies is one part of the wider policy management discipline; the structured update is where you manage most of the actual risk.

The 10 steps

Infographic showing the 10 steps: plan the review, establish a team, collect policies, review content, assess compliance, evaluate effectiveness, seek stakeholder input, revise content, approve changes, publish and communicate.

Plan the update

Before anyone touches a document, define the scope, timeline, and goal of the update. Is this one policy or a whole category? Is it a scheduled annual update or something triggered by a regulatory change or incident? What does “done” actually look like – a refreshed document, or a broader restructure? Do we even need this policy now, or is it redundant?

Set a deadline now for when this entire policy validation and update process needs to be done by, not once the work is already underway. An update with no end date drifts, and a policy owner juggling other priorities will always find something more urgent to do first.

What we usually recommend: build the timeline into a workflow rather than a shared calendar reminder. A workflow assigns the update to a named owner, sets the deadline, and flags it if nothing happens by that date – which is the difference between an update someone actually does on schedule and one someone remembers three months late. Workflow tools exist specifically to take this off someone’s personal to-do list.

Establish a team

Decide who owns the stages throughout the document update. Who needs to contribute, and who has final sign-off – and get this agreed before you start collecting documents, not halfway through. Most policies have an obvious owner, and most need some input from legal, compliance, and the departments that use the policy day to day, and that list needs to be explicit from the outset.

A clear team also means a clear escalation path if the update stalls – there’s a named person to chase, rather than a task that quietly belongs to nobody.

Collect policies

Gather the current versions of every document in scope. This sounds basic, but it’s a common source of wasted effort: updating a copy that isn’t actually the live version, or missing a related policy that should be updated at the same time.

Centralising your policy library removes most of the risk here – if there’s one authoritative source for every current version, nobody starts an update from the wrong document by mistake.

Zeelandia ran into this before centralising: documents lived in Teams, anyone could edit them directly, and, in Deniz Can Karaca’s words, “sometimes when we accessed a document expecting a blank template, we found that someone had already filled it out and left their changes behind.” Outdated versions also continued to circulate alongside current ones. Moving to a single source plus a clear and semi-automated way to create policies resolves both problems – and the manual follow-up and email traffic that came with them – out entirely.

Review content

Read the document itself with a critical eye. Is it clear? Is it actionable? Would someone unfamiliar with the topic understand what they’re supposed to do? Is there any other policy that covers this topic? Does this topic require its own policy? This is a content and clarity pass, separate from any review of whether the policy is still legally correct.

Assess compliance

Check the policy against current legal and regulatory requirements. Regulation, industry standards, and internal risk appetite all shift over time, and a policy that was correct at the last update can quietly fall out of alignment without anyone noticing until an audit or incident exposes it.

For regulated industries, this step doubles as audit preparation. Zeelandia, which operates in food manufacturing, now has a document management system it can point to directly during food certification audits – replacing what Deniz Can Karaca describes as previously having “to prove the process manually.”

Worth keeping separate in your own mind: this step is about document compliance against standards and regulations – is the document itself current and does it meet requirements? This stage is not about attestation compliance or whether people have read and comply with it. A document can be perfectly compliant yet poorly attested, or well attested against an out-of-date version. They’re measured differently, for different reasons.

Evaluate effectiveness

Separately from compliance, look at whether the policy is actually being used. Usage and read-rate data will tell you whether people are engaging with a policy at all – and if attestation rates for one document consistently trail the rest of the library, that’s usually a sign the document itself needs work, not just a reminder to staff.

Before centralising this, Zeelandia had no way to answer that question at all. “We could never be sure whether emails had actually been read,” says Deniz Can Karaca, Zeelandia. With policies and procedures also circulating by email, tracking which version was current – and whether anyone had seen it – became close to impossible; even the policy owner could lose track of an instruction they’d previously sent and later contradict it.

Reporting that surfaces attestation by policy, not just organisation-wide, is what actually makes this step useful rather than a guess.

If steps 3 to 6 sound like more manual checking than your team has time for, learn more about how Xoralia handles this.

Seek stakeholder input

Take your findings from steps 4 to 6 to the people who’ll actually use the policy – not just legal and compliance, but the departments and end users affected by it. A compliance sign-off tells you the policy is correct. Input from the people using it tells you whether anyone will actually follow it.

A situation worth avoiding: an update clears legal sign-off, goes live, and six months later usage data shows barely anyone has engaged with it. The content was correct – nobody had asked the people using it whether it actually made sense to them. Getting that input here, before the final revision, is what catches the problem before publication rather than after.

Revise content

Turn steps 4 to 7 into an updated draft: fix what’s unclear, correct what’s out of compliance, and address the gaps stakeholders raised. Keep the scope disciplined – if new issues come up that weren’t already flagged, note them for the next update rather than letting this one expand indefinitely.

Approve changes

Route the final draft for formal sign-off against an approval deadline. Keep the approval chain as short as the policy genuinely requires – an approval workflow with too many people in it tends to circle rather than progress. Some policies clear approval first time; more complex ones, or those with multiple stakeholders, will go through further revisions before they do.

Workflow: Single response required

Publish and communicate

Make the approved policy available and issue the communications, assigning readers a read-by date to confirm they’ve seen it. This is also where version control matters most – if the previous (legacy) version is still accessible anywhere, some staff will keep referring to it.

Audience targeting is what makes this manageable at scale: rather than pushing every policy update to every employee, you can target communications to the department, role, or location where they apply, which keeps mandatory reads relevant and prevents notification fatigue.

Attestation read report for a policy

Boyum IT Solutions, which moved away from a manual, email-based process for exactly this reason, now runs a 99% attestation rate against its policy library, according to Nadja Boyum, VP Marketing & HR. Centralising attestation into one system is what makes a number like that possible – no duplicate versions circulating, no one attesting to the wrong document by mistake.

What happens if you skip a step

Skipping step 2 – establishing a clear team upfront – is the most common failure point we see: no named owner means the update has no one to chase, and it stalls quietly rather than failing loudly. Though skipping step 7 – stakeholder input – is the quietest failure, because the update still “happens” on schedule and clears approval, but produces a policy nobody reads any more clearly than the last one. Neither failure shows up immediately. Both show up in attestation and audit data eventually.

How Xoralia supports each stage

Updates don’t fail because organisations lack good intentions – they fail because the admin around them is manual, and manual processes are the first thing to slip when someone’s busy. Content Formula, a Microsoft 365 consultancy that’s been building intranet and compliance solutions since 2005, builds Xoralia to remove the manual overhead from most of the steps above: automated timelines and reminders for step 1, a centralised library for step 3, usage reporting for step 6, workflow routing for steps 7 to 9, and targeted communication and attestation for step 10.

LifeArc operates in a strictly regulated sector where compliance and information security are critical. It's essential that our workforce has easy and effortless access to the latest up-to-date policies and procedures - which is the structure Xoralia gave us."

LifeArc got Xoralia live for 500 employees in three days and now maintains an 87.5% employee attestation rate against its policy library – part of what supported its ISO 27001 certification. See the full LifeArc case study.

Ready to see what a structured update process would look like for your policy library?

Frequently asked questions

About the author

How policy management software can help

team xmas 2024 1 jpg We think the best place to store your policies is inside SharePoint. Most companies already have SharePoint as part of their Microsoft 365 subscription. Using SharePoint means you have full control of your policies, and many best practices can be achieved right out of the box. However, there are gaps and certain best practices are hard to achieve.

To fill these gaps, and for best results we recommend using purpose-built policy management software for SharePoint and Microsoft 365.

We’ve developed a dedicated solution called Xoralia (pronounced Zor-ra-lee-a) that will ensure you have the best overall approach to policy management, supporting your users, policy owners and administrators.

We learned all about policy management from many years of building custom solutions for our clients on SharePoint. But we kept coming up against the same challenges, mostly caused by feature gaps in SharePoint. One day, a client asked us to build a policy management tool that filled these gaps. The trouble was, they didn’t have a lot of budget. But we had a good relationship with them and so we decided to collaborate on it provided we got to keep the code. Looking back, it was a pretty simple tool but over the years we have added more features and relaunched it. We’re now on version 3 and our original customer is still using it!

3 benefits you can expect from Xoralia

Make it easy to find policies

Centralised policy library with powerful search and filtering.

Reduce administrative burden

Automations and notifications so that all policy tasks are carried out on time

Demonstrate compliance and best practice

Sophisticated tracking and dashboards to drive and measure compliance.

And lots more!

What our clients say

logo MS AppSource 500x500 jpg
AppSource review

A great time saver and tool for document management

We have found Xoralia to be very beneficial to us as it has allowed us to focus on other area’s as Xoralia will take care of who has read the documents and notify them if they have not. A great time saver and tool for document management all together.

Ideal partner for our regulated environment

LifeArc operates in a strictly regulated sector where compliance and information security are critical. It is essential that LifeArc’s workforce have easy and effortless access to the latest up-to-date policies and procedures, which is the structure Xoralia gave us.

How to get started with Xoralia

Step 1: Explore or request a demo

Start a free trial for instant, hands-on access, or fill out our form to book a personalised demo at a time that suits you.

Step 2: Get a price proposal

If Xoralia looks right for your organisation, ask us for a tailored quote. We’ll outline any options and packages to fit your needs.

Step 3: Install and launch

Set up Xoralia in your environment with our support. We’ll provide onboarding, training, and full assistance to get your team up and running quickly.

Here's what you'll get

And last but not least:

Ready to get started?

Connect with us to streamline your policy management and ensure effortless compliance.

Related articles

logo G2 500x500 jpg
G2 review

Great quality improvements for our organisation

The policy approval workflows are perfect for us to build customisability into our processes – streamlining policy approval and creating a more structured process for policy reviews.

logo MS AppSource 500x500 jpg
AppSource review

Uniting excellence in integration and features for seamless policy management

As the newly appointed IT Manager at our company, I was tasked with implementing the Xoralia policy management tool, and the experience has been nothing short of impressive.

Start your FREE Xoralia trial!
See how Xoralia enhances your SharePoint policy management
Explore how Xoralia helped global organisations
See how much manual policy management is costing your organisation
eBook: Effective policy management and compliance best practices
eBook: Effective policy management and compliance best practices
Start your FREE Xoralia trial!