Policy & Procedure Management
Author, approve, publish and attest — every policy, versioned and evidenced
The full lifecycle of policies and procedures on one platform — drafting, review, approval, publication, attestation and scheduled review — with every version, approval and acknowledgement preserved. OnyxOne replaces shared drives full of conflicting documents and email attestation chases with a single library where the current version is unambiguous, the right people have approved it, staff have acknowledged it, and mapped controls show the policy is actually enforced.
How it works, visually
How an obligation or event is triaged, escalated when it matters, and recorded either way.
The problems this module solves
The operational realities that make this hard for compliance and risk teams today.
Nobody knows which version is current
Policies live on shared drives and in email attachments, in multiple near-identical versions. Staff follow whichever copy they happened to save, approvers can't tell what they signed off, and 'the current policy' becomes a matter of debate rather than fact.
Approvals are informal and untraceable
Policy sign-off happens over email or in a meeting with no durable record. When an auditor asks who approved a policy and when, the answer is buried in an inbox — if it exists at all.
Attestation is a manual chase
Confirming that staff have read and understood a policy means chasing acknowledgements by email and tracking them in a spreadsheet. Coverage is never complete, reminders are manual, and there is no clean evidence of who has attested to what.
Reviews lapse and policies go stale
Policies are supposed to be reviewed on a cycle, but without automated scheduling, reviews slip. Out-of-date policies stay in force, no longer matching regulation or actual practice, and the gap only surfaces when something goes wrong.
Policies aren't connected to the controls that enforce them
A policy states a requirement, but nothing links it to the controls that implement it. There's no line of sight from an obligation, to the policy that addresses it, to the control that enforces it — so 'we have a policy' is asserted rather than evidenced.
How OnyxOne addresses it
A single, versioned policy library
Every policy and procedure lives in one library with a clear current version, full version history and status. There is never ambiguity about what is in force — the platform is the single source of truth, and superseded versions are retained for the record.
Structured authoring, review and approval
Policies move through configurable draft, review and approval stages with defined owners and reviewers. Each approval is captured with who approved it, when and against which version — a durable, auditable sign-off rather than an email thread.
Targeted attestation with automated tracking
Publish a policy to the roles or groups it applies to and require acknowledgement. The platform tracks who has attested, sends reminders automatically, and shows coverage at a glance — no spreadsheet, no manual chasing.
Scheduled reviews that don't lapse
Each policy carries a review cadence, and the platform prompts owners before it falls due. Reviews are logged, so a policy is provably current rather than quietly stale.
Policies mapped to controls and obligations
Policies link to the controls that enforce them and the obligations they address, creating a traceable line from regulation to policy to control. 'We have a policy and here is the control that enforces it' becomes evidenced, not asserted.
What's in the module
Turn on what you need and add more as your programme scales.
Central policy library
One versioned library for every policy and procedure, with an unambiguous current version and full history.
Authoring & drafting
Draft and edit policies with structure and templates, keeping work-in-progress separate from the published version.
Review & approval workflow
Configurable draft → review → approve stages with defined owners, reviewers and durable sign-off.
Version control
Every change produces a new version; superseded versions are retained and comparable.
Publication & distribution
Publish the approved version to the roles and groups it applies to, so staff always see what's in force.
Attestation & acknowledgement
Require and track read-and-understood acknowledgements with automated reminders and coverage reporting.
Scheduled review cycles
Set a review cadence per policy and prompt owners before it falls due, logging each review.
Control & obligation mapping
Link policies to the controls that enforce them and the obligations they address for full traceability.
Exceptions & waivers
Record, approve and time-box policy exceptions with owners and expiry, rather than leaving them undocumented.
Immutable audit trail
Every draft, approval, publication, attestation and review is written to an append-only record.
The enterprise workflow
A defined, end-to-end process with clear ownership at every stage.
Every result, decision and override is captured against the record it belongs to.
Draft
An owner drafts or revises a policy from a template, with work-in-progress kept separate from the version currently in force.
Review
Reviewers provide input and changes on a defined stage, so the right stakeholders shape the policy before approval.
Approve
Designated approvers sign the policy off against a specific version, with the approval captured durably for audit.
Publish
The approved version is published to the roles and groups it applies to and becomes the unambiguous current version.
Attest
Staff acknowledge the policy; the platform tracks coverage, sends reminders and records each attestation.
Review on cycle
The policy is scheduled for periodic review, prompting the owner before it falls due so it never quietly goes stale.
What your team gains
No more version confusion
One library with an unambiguous current version means staff, approvers and auditors all reference the same policy.
Durable approval evidence
Every approval is captured with who, when and which version, so policy sign-off can be produced instantly on request.
Attestation without the chase
Automated acknowledgement tracking and reminders replace the spreadsheet and the email chase, with coverage visible at a glance.
Policies that don't go stale
Scheduled reviews prompt owners before policies fall due, so what's in force is provably up to date.
Traceable from obligation to control
Mapping policies to obligations and enforcing controls turns 'we have a policy' into an evidenced line of assurance.
Cleaner audits and examinations
Because approvals, attestations and reviews are captured as they happen, evidence is retrieved rather than reconstructed.
Industries it serves
Works with your existing systems
Described as capabilities — OnyxOne connects to the systems your deployment requires, configured per implementation.
- Links policies to your internal-controls and compliance-obligation modules for end-to-end traceability
- Targets attestation to the right roles and groups using your existing identity provider and HR directory
- Connects to your existing document stores while keeping the authoritative, versioned copy in the policy library
- Aligns policy attestation with your existing training and learning systems where acknowledgement and training go together
- Routes review requests, approvals and attestation reminders through your existing email and messaging channels
Security, compliance & reporting
Security & data handling
- Policy content, approvals and attestations are encrypted in transit and at rest.
- Role-based access controls who can author, review, approve and publish, keeping drafts separate from the published version.
- Segregation of duties can prevent the same person from both authoring and approving a policy where policy requires it.
- Every draft, approval, publication, attestation and review is written to an append-only audit trail.
- Superseded versions are retained, so the exact policy in force at any past date can be produced.
- Retention of policy versions and attestation records is configurable to your regulatory obligations.
Compliance support
- Supports policy-governance expectations across AML, data-protection and conduct regimes
- Provides documented approval and attestation evidence for regulatory examination
- Underpins the policy layer of a three-lines-of-defence model
- Supports GDPR and information-governance policy requirements
- Links policies to obligations and controls for demonstrable regulatory coverage
Reports & exports
- Policy inventory with current version and status
- Approval history and sign-off reports
- Attestation coverage and outstanding-acknowledgement reports
- Overdue and upcoming policy-review reports
- Exception / waiver register with expiry tracking
- Policy-to-control and policy-to-obligation coverage reports
How to get the most from it
Make the library the only source
Retire shared-drive copies and point everyone to the library. The value collapses the moment a second 'current' version exists elsewhere.
Target attestation, don't broadcast it
Publish policies to the roles they actually apply to. Blanket attestation dilutes coverage evidence and irritates staff who don't need it.
Schedule reviews at creation
Set the review cadence when a policy is first approved, so it enters the review cycle immediately rather than being remembered later.
Map policies to controls
Link each policy to the controls that enforce it. Traceability from obligation to policy to control is what turns documentation into assurance.
Questions, answered
How does version control work?
Every change creates a new version while the published version remains unambiguous. Superseded versions are retained and comparable, so the exact policy in force at any past date can always be produced.
Can we require staff to attest to policies?
Yes. Publish a policy to the roles or groups it applies to and require read-and-understood acknowledgement. The platform tracks coverage, sends reminders automatically and records each attestation as evidence.
How are policy approvals evidenced?
Approvals are captured durably with who approved, when and against which version, replacing email sign-off with an auditable record you can produce on request.
Does it stop policies going out of date?
Each policy carries a review cadence, and owners are prompted before a review falls due. Reviews are logged, so a policy is provably current rather than quietly stale.
Can we link policies to controls and obligations?
Yes. Policies map to the controls that enforce them and the obligations they address, creating a traceable line from regulation to policy to control for demonstrable coverage.
Related modules
See Policy & Procedure Management in your programme
Book a walkthrough and we'll show how this module fits your policy, workflows and obligations — then scope an implementation.