Policy management tools: the 4 things organisations actually use, and what each one costs you

Updated

Policy management tools is a category with four genuinely different answers in it, and the right one depends almost entirely on how many documents you have and whether anybody is going to configure anything. Most organisations pass through two or three of them. This page sets out the four, what each is good at, and the specific point at which each one stops working, so you can tell where you are rather than being sold the largest one.

A shared drive with a naming convention

Free, immediate, and adequate for perhaps a dozen documents held by one person who cares. It fails on version and on evidence: two files called final and final-v2 is a coin toss, and there is no way to show anybody read anything. It usually stops working the first time somebody follows an out-of-date document and something goes wrong.

The intranet or wiki with metadata columns

Much better, genuinely capable, and dependent on somebody building and maintaining owner columns, review-date reminders and an approval flow. Organisations with that person get an excellent result for no extra licence. Organisations that had that person and lost them get a system nobody can change, which is the worst of the four.

A learning system used as a policy store

This is common because the attestation problem looks like a training problem. It works for read-and-sign and is poor at version history and review dates, because a course is not a document with a lifecycle. The tell is that updating a policy means republishing a course, and the old version becomes hard to retrieve.

A dedicated register

One row per procedure with an owner, a version, a review date and the signatures against it. It is the shape this site sells and it earns its price at the point where nobody can tell you the overdue share today. On the worked example that is 14.4 documents of 48 already past their date, and 36 hours of work to clear.

Questions people ask about policy management tools

Can we just use SharePoint?

Yes, if somebody will build the columns and the reminders and keep them working. That person is the whole decision, and assuming them is the usual mistake.

Is a learning system good enough?

For read-and-sign, often. For version history and review dates it is poor, because a course is not a document with a lifecycle.

When does a shared drive stop working?

The first time somebody follows an out-of-date document. The failure is not gradual and it is not usually discovered by the person who owns the folder.

Sources

Related answers

Keep the register: start Sopvo ProStop guessing which version is current: start Pro