How To Set Up Policy Management In GRC: A Six Step Build For Australian Businesses
Quick answer: Setting up policy management in GRC is a six step build. You audit and consolidate the library, assign owners and an approval path, standardise format and version control, distribute to the right people, capture acknowledgement, then schedule review and retirement. Most Australian organisations write good policies and then fall over at distribution and acknowledgement. Start where most businesses actually start If your policies live in a shared drive with names like "Code of Conduct FINAL v3 (updated).docx", you are in the same place as most Australian businesses under 200 people. Nothing is broken yet. Nothing is evidenced either. This is a practical guide to building policy management in GRC from that starting point. Not the theory of why policies matter, which the original article covers well, but the actual sequence of moves that takes a scattered folder and turns it into a managed system. One thing to hold onto as you read. The hard part is almost never wr...