Workflow Template
Policy Review and Approval Workflow
Governance workflow for reviewing and approving policy drafts or revisions. The policy owner submits the policy, reason for review, and draft. Stakeholders review it, with legal/compliance review where required, then the approval authority signs off. Approved policies are published, prior versions superseded, and the next review date set. Requested changes are routed back to the owner for revision.
This workflow is designed for governance, risk, and policy teams responsible for keeping organisational policies current, compliant, and properly authorised. It automates the full lifecycle from draft submission through stakeholder review, conditional legal/compliance review, and approval authority sign-off, routing revisions back to the owner whenever changes are required. The result is a fully traceable approval trail, faster turnaround on policy updates, and automatic supersession of prior versions with a next review date set on publication.
Business Outcomes
- Reduce policy approval cycle time by removing manual follow-ups between owners, reviewers, and approvers
- Create a complete audit trail of every review, revision, and sign-off decision for compliance evidence
- Ensure legal/compliance review is applied consistently only where required, avoiding unnecessary delays
- Eliminate version control errors by automatically superseding prior policies on approval
- Guarantee every published policy has a scheduled next review date, closing governance gaps
Workflow Steps
Steps
- 1Create Policy Review Recordcreate record
Registers the submitted policy draft and review request.
- 2Set Status: Submittedupdate record
Marks the policy review as submitted and awaiting stakeholder review.
- 3Notify Owner: Submission Receivedsend email
Confirms receipt of the policy submission to the owner.
- 4Set Status: Under Stakeholder Reviewupdate record
Updates the policy status as stakeholder review begins.
- 5Stakeholder Reviewcreate task
Stakeholders review the draft policy and record feedback and an outcome.
- 6Route on Stakeholder Review Outcome
Determines whether the policy proceeds or is returned to the owner for revision.
stakeholder_outcome: "Approve to Proceed"→Route on Legal/Compliance Review Requirementstakeholder_outcome: "Request Changes"→Set Status: Returned for RevisionDefault→Set Status: Returned for Revision - 7Set Status: Returned for Revisionupdate record
Marks the policy as returned for revision following stakeholder feedback.
- 8Notify Owner: Changes Requested (Stakeholder)send email
Informs the owner that changes were requested during stakeholder review.
- 9Restart for Revisionrestart from step
Restarts the workflow from stakeholder review so the revised draft can be reassessed.
- 10Route on Legal/Compliance Review Requirement
Determines whether a legal or compliance review is required before approval.
requires_legal_review: "Yes"→Set Status: Under Legal Reviewrequires_legal_review: "No"→Set Status: Pending ApprovalDefault→Set Status: Under Legal Review - 11Set Status: Under Legal Reviewupdate record
Updates the policy status as it enters legal/compliance review.
- 12Legal/Compliance Reviewcreate task
Legal or compliance reviews the policy draft for regulatory and legal risk.
- 13Route on Legal Review Outcome
Determines whether the policy proceeds to approval or is returned to the owner.
legal_review_outcome: "Cleared"→Set Status: Pending Approvallegal_review_outcome: "Request Changes"→Set Status: Returned for Revision (Legal)Default→Set Status: Returned for Revision (Legal) - 14Set Status: Returned for Revision (Legal)update record
Marks the policy as returned for revision following legal/compliance feedback.
- 15Notify Owner: Changes Requested (Legal)send email
Informs the owner that legal/compliance has requested changes.
- 16Restart for Revision (Legal)restart from step
Restarts the workflow from stakeholder review so the revised draft can be reassessed.
- 17Set Status: Pending Approvalupdate record
Updates the policy status as it moves to the approval authority for sign-off.
- 18Approval Authority Sign-offrequest approval
The designated approval authority reviews and approves or rejects the policy.
- 19Route on Approval Authority Decision
Determines whether the policy is published or returned to the owner for revision.
approval_status: "approved"→Set Status: Publishedapproval_status: "rejected"→Set Status: Returned for Revision (Approval)Default→End - 20Set Status: Returned for Revision (Approval)update record
Marks the policy as returned for revision following the approval authority's rejection.
- 21Notify Owner: Changes Requested (Approval Authority)send email
Informs the owner that the approval authority requested changes.
- 22Restart for Revision (Approval)restart from step
Restarts the workflow from stakeholder review so the revised draft can be reassessed.
- 23Set Status: Publishedupdate record
Marks the policy as approved and published.
- 24Mark Prior Version Supersededupdate record
Records that any prior version of this policy is now superseded by the newly published version.
- 25Set Next Review Dateset due date
Sets the SLA/reporting due date for the next scheduled policy review, one year out.
- 26Persist Next Review Date on Recordupdate record
Writes the resolved next review date onto the record so it is visible in reports and table views.
- 27Notify Owner: Policy Publishedsend email
Confirms to the owner that the policy has been approved, published, and any prior version superseded.
Fields
- Policy Owner Name*
- Policy Owner Email*
- Policy Title*
- Reason for Review*
- Draft or Revised Policy Document*
- Requires Legal/Compliance Review?*
- +7 more fields
Forms
Policy Submission Form
7 fields
Data Views
All Policy Reviews
policy_title, owner_name, policy_status, requires_legal_review +1 more
Dashboard Widgets
Recommended integrations
Setup the following integrations to extend workflow capability.
Send email in the workflow
AWS SES
Similar Workflows
Similar Categories
FAQs
Why should we automate policy review instead of managing it by email and shared documents?
Email and shared drives create version confusion and leave no reliable audit trail of who approved what and when. This workflow captures every submission, review outcome, and sign-off decision in one record, so status is always visible and evidence is ready for audit without manual reconstruction.
What is the ROI of using this workflow versus a manual governance process?
The main returns are time saved chasing reviewers and approvers, fewer errors from outdated policy versions circulating, and reduced compliance risk from missed review dates. Because the template publishes in minutes and requires no development work, the payback period is immediate rather than tied to a long implementation project.
How does this compare to using a generic approval tool or ticketing system?
Generic ticketing tools handle status tracking but lack purpose-built logic for conditional legal review, revision loops, and automatic version supersession. This workflow is pre-built for policy governance specifically, so teams get the right structure out of the box rather than configuring it from scratch.
How long does it take to implement this workflow?
There is no implementation project. The template is ready to use, and once published it is live within minutes, letting the policy owner submit their first draft immediately.
Can we customise the review steps and approval logic?
Yes. Roles, notification triggers, and the conditions that route a policy into legal/compliance review can all be adjusted directly inside assess.one. Teams can add or reorder steps to match their specific governance structure without any external development work.
Who needs access to this workflow?
Typically the policy owner, relevant stakeholders, legal/compliance reviewers, and the designated approval authority each need access to their respective steps. Access and notifications for each role are configured within the platform, so only the right people are prompted at each stage.
What happens when legal or compliance review is not required?
The workflow routes automatically based on the legal/compliance review requirement set at submission. If it is not required, the policy moves directly from stakeholder review to pending approval, skipping the legal review stage entirely and saving unnecessary handoffs.
What happens when a reviewer or approver requests changes?
Whenever a stakeholder, legal reviewer, or approval authority requests changes, the status updates to 'Returned for Revision,' the owner is notified with the reason, and the record restarts at the revision stage. This keeps the full history of each round of feedback attached to the same policy record.
How does this workflow support compliance and audit requirements?
Every status change, review outcome, and approval decision is logged against the policy record, creating a defensible audit trail. This is particularly valuable for demonstrating that legal/compliance review was applied where required and that sign-off occurred before publication.
What happens after a policy is approved?
On approval, the policy is published, the prior version is marked as superseded, and the next review date is automatically set. This closes the governance loop without requiring a separate manual step to schedule the follow-up review.
Ready to use this workflow?
Create a free account and customise this workflow for your business.
