Compliance
A policy register that tracks who has actually read the policy
A policy that nobody has read is not a control. It is a document. The distinction matters most at the exact moment you would rather it did not - after an incident, when an investigator asks whether the person involved had been made aware of the rule they broke. "We have a policy" is a much weaker answer than "we have a policy, and here is the record that this person acknowledged it on this date."
Policies fail quietly in two ways, and a register exists to catch both. They drift past their review date and go stale. And they never quite reach everyone who is supposed to accept them. Neither failure announces itself. Both surface only when someone asks for evidence, which is the worst possible time to discover you do not have any.
Policy lifecycle: the part most registers get right
The first half of the job is the same discipline as any controlled document. Each policy needs a reference, a name, a category, an owner, the person who approved it, the approved date, a version and a review frequency. From the approved date and the frequency, the next review date and the days remaining are pure calculation - so a status can flag green Current, amber Due soon and red Overdue on its own, without anyone maintaining it by hand.
This is the lifecycle: draft, approve, publish, review, revise, retire. A register that computes the review dates keeps the whole set from going stale, because the reds appear before the deadline rather than after it. Most decent policy trackers manage this much.
Attestation: the part most registers skip
Here is the harder and more valuable half. Existence and awareness are different things, and only one of them is a control. It is not enough that a policy exists on a drive; the people it governs have to have read it and, ideally, positively acknowledged it. That acknowledgement has a name - attestation - and it is the evidence that converts a document into an operating rule.
A policy proves intent. An attestation record proves reach. An auditor, and an incident investigation, care far more about reach.
Tracking attestation does not require an HR platform. What it requires is a single visible number per policy: what proportion of the people who should have acknowledged it actually have. An Acknowledged percentage, with a simple in-cell bar beside it, turns roll-out from an assumption into a measurement. At a glance you can see that the information security policy is at 100 percent, the new remote-working policy is at 40 percent and still spreading, and the code of conduct has three stragglers to chase. That is a management view you can act on before the gap becomes a finding.
Two numbers, one dashboard
Put the two halves together and every policy carries the two facts that actually matter: when it is next due for review, and how far it has rolled out. Those are the questions a governance meeting should be able to answer in seconds, and a register that surfaces them on a single dashboard - the review-status split, the mix by category, the policies due soonest, the roll-out gaps - makes the meeting shorter and the answers defensible.
The trap to avoid is treating the policy library as a folder of files. A folder tells you a policy exists. It cannot tell you whether the policy is current, or whether the people it binds have seen it. Those two blind spots are precisely where policy-related findings come from, and they are exactly what a proper register removes.
Run it before the meeting, not after the incident
The habit that makes this pay is small: open the register before each governance or management review, not in response to a problem. The overdue policies are already flagged. The roll-out gaps are already visible. You spend the meeting deciding what to do about them, rather than discovering that you should have known. A policy register earns its place the first time it lets you say, with a record to back it, exactly who had read what and when.
Review dates and roll-out, both tracked
Every policy with a computing review status - green, amber, red - plus an Acknowledged percentage with an in-cell bar so you can see how far each has rolled out, on one live dashboard. A tool to run your own policy governance, not legal advice.