
How Often Should Policies Be Reviewed? Cycles, Triggers and Version Control
Ask a regulator how often policies should be reviewed and you will rarely get a number. The law mostly says "regularly", inspectors say "current", and the practical answer that satisfies both is a cycle plus triggers.
The cycle is annual review as a baseline. The triggers are the events that force a review early, and in a period when employment law is changing every few months, the triggers are doing most of the work.
The Review Framework at a Glance
| Trigger | Examples | What to check |
|---|---|---|
| Annual baseline | Scheduled review date on every document | Accuracy, named roles, legal references, whether practice still matches |
| Legislation changes | The Employment Rights Act waves, data protection reform | Every policy citing the changed rules, plus handbook knock-ons |
| An incident or near miss | Accident, data breach, grievance, tribunal claim | Whether the procedure worked, and whether anyone followed it |
| Restructure or staff change | New sites, departures, new managers | Named responsibilities and reporting routes |
| New contract, tender or accreditation | Client due diligence, CHAS, ISO, funding rules | Whether documents meet the new external standard |
Why Annual Is the Baseline
Annual review is not plucked from the air; it is what external readers increasingly require. The apprenticeship provider register expects every policy reviewed annually with the last review date shown, pharmacy regulations require procedures to be "reviewed regularly", and the HSE expects a health and safety policy to reflect current arrangements, not historic ones.
Insurers and client due diligence questionnaires ask the same question in their own way, usually as "date of last review" fields. A blank field reads as "never", and our training providers page shows how far some sectors have moved: their register will not accept generic or unreviewed documents at all.
The Triggers That Do Not Wait for the Anniversary
Legislation is the loudest trigger right now. The Employment Rights Act timeline alone lands changes in April, August and October 2026 and January 2027, and each wave quietly dates every policy that cites the old position.
Incidents are the second trigger, and the review question is double-barrelled: did the procedure work, and did anyone follow it? A policy that failed in practice needs revision; a policy nobody followed needs either revision or retraining, and the review should decide which.
The third is any new external reader: a tender, an accreditation, a big client's due diligence. Reviewing just before an external audience arrives is cheaper than explaining stale documents to them.
Version Control That Proves It Happened
A review that leaves no trace might as well not have happened. Every document needs an owner, a version number, a last-reviewed date and a next-review date, plus a one-line review log recording what changed and why, even when the answer is "nothing".
The same evidential logic now runs through employment law itself: the six-year holiday records duty exists because regulators check documents, not memories. Free sources such as Acas templates can start a document, but the review log is what makes it defensible years later.
Why "Last Reviewed 2019" Is Itself a Liability
An old review date does damage before anyone reads a word of the policy. It tells a tribunal the document may not reflect current law, tells an assessor your management system is not operating, and tells a buyer you may treat their contract terms the same way.
Libraries in that state usually need more than a date change; our guide to updating an out-of-date policy library covers the consolidation exercise that repairs accumulated documents properly.
Building a Review Cycle That Actually Runs
Spread review dates through the year rather than stacking them all in January, and put them in a calendar someone owns. Group related documents so they are reviewed together and stay consistent, and record the outcome every time.
The part businesses outsource is the checking itself. Our policy reviewing service reviews documents against current law and practice on a standing cycle, so the review dates on your documents mean what they say.
Policy and Procedure Writers
Policy Pros writes and reviews policies for UK businesses, with version control, review dates and a review log built into every document we deliver. Whether you need one overdue policy checked or a whole library put onto a working review cycle, contact us for a free quote, or call 020 3951 2875.
Frequently Asked Questions
Is there a legal requirement to review policies annually?
Rarely in those words. Most legislation requires policies and procedures to be kept up to date or reviewed regularly, and specific regimes go further, such as the apprenticeship register's annual review requirement. Annual review is the baseline that satisfies almost every regulator, insurer and auditor at once.
What should a policy review actually check?
Four things: the law it cites is current, the named roles and routes still exist, the procedure matches what the business actually does, and the document is consistent with the rest of the library. A review that checks only the legal references misses the failures assessors find most often.
What events should trigger an early review?
Legislation changes affecting the policy, any incident or dispute that tested the procedure, restructures that change named responsibilities, and any new external requirement such as a tender, accreditation or major client contract. Each of these dates a document immediately, whatever its review schedule says.
How do we prove policies have been reviewed?
With version control: an owner, version number, last-reviewed and next-review dates on the document, and a review log recording what was checked and changed. Recording a review that changed nothing is still worth doing, because the log is the evidence external readers ask for.