Policy Lifecycle Manager
Most policy estates fail supervision for the same reason: the document exists, but nothing connects it to the control it was supposed to govern. The lifecycle here is built the other way round — a clause without a control mapping cannot be approved.
Six stages, one audit trail
Obligation trigger
A regulatory change, supervisory finding or internal event opens a drafting mandate. Nothing enters the lifecycle without a traceable cause.
Draft and control mapping
Each clause is mapped to the controls it governs, so a policy statement is never orphaned from the control that evidences it.
Review and challenge
Second-line challenge with recorded dissent. Disagreements are retained, not resolved silently.
Approval and attestation
Named accountable executive approves. Attestation is bound to the version, not to the document title.
Publication and acknowledgement
Distribution tracked by population, with acknowledgement gaps surfaced as an exception rather than a report footnote.
Periodic review and retirement
Review clocks run against the obligation, not the calendar. Retired versions stay retrievable for the supervisory look-back window.
What the record holds
- Version lineage with diff-level change history
- Clause-to-control mapping for every material statement
- Named approver and attestation timestamp per version
- Acknowledgement coverage by population and role
- Overdue-review exceptions rolled into the resilience position
Scope boundary
This is policy governance, not policy digitisation. We do not convert document libraries, run authoring services, or generate policy text as a deliverable. The platform governs the lifecycle, holds the evidence, and surfaces the exceptions; the institution retains authorship and ownership of its own policy.