A policy written two years ago stops reflecting how a business actually operates the moment the business changes and the policy does not. New tools get adopted, new vendors come on board, staff structures shift, and none of that gets written down unless someone deliberately goes back and checks. Having the right policies in place, covering acceptable use, data protection, and incident response, is only half the job. The other half is checking, on a genuine schedule, whether those policies still describe how the business actually works.
This is where “set and forget” quietly takes over, even at businesses that got the initial policy set right. The policies get written, filed, and signed off once, and nobody circles back to check whether they still hold up against how the business actually runs today.
Policies drift out of step with the business long before anyone notices
A policy is a snapshot of how a business operated on the day it was written. Businesses do not stay still. Tools change, vendors change, and the way people actually work changes gradually enough that no single moment feels like the trigger for a rewrite. By the time someone notices the policy no longer matches reality, it may have been out of date for a year or more.
New tools, vendors, and ways of working outpace static documents
A remote work policy written before hybrid working became standard, or a data protection policy written before an AI tool was adopted company-wide, is not wrong so much as incomplete. It answers questions the business used to ask and stays silent on the ones it asks now. That gap is invisible until an incident, an audit, or a new client contract forces someone to check.
Certain events should trigger a review outside the annual cycle
An annual review catches drift that has built up gradually. Some changes are significant enough that waiting for the calendar to come around is the wrong call.
- A new client requirement. A client’s own security or compliance expectations may go beyond what your current policies cover.
- A security incident. Even a minor one often reveals a specific gap that the existing policy did not anticipate.
- A certification pursued. Working toward Cyber Essentials, Cyber Essentials Plus, or ISO 27001 typically surfaces policy gaps that a routine review would eventually catch, but sooner is better.
- A change in staff structure. New leadership, a new department, or a shift in who holds decision-making authority changes who a policy needs to be written for.
A policy that hasn’t been touched in two years is a policy in name only
Dr Logic can run a genuine review that checks what’s actually changed, not just whether the document still exists.
A genuine review checks more than whether the document still exists
Confirming a policy is still on file is not the same as confirming it still works. A genuine review asks whether the policy reflects current tools, current risks, and current expectations, not just whether the file has a recent modification date.
Aligning to what clients and regulators now expect
Standards move. What was considered adequate data protection practice two years ago may fall short of what a client’s due diligence process, an insurer, or a regulator now expects. A review that only checks internal consistency misses this entirely.
Documenting what changed and why
A review that results in no changes is still worth recording, including the date it happened and who signed it off. A review that results in changes needs those changes documented clearly enough that the next reviewer, who may not be the same person, understands why the policy looks the way it does.
Annual calendar review compared with trigger-based review
| Aspect | Annual calendar review | Trigger-based review |
|---|---|---|
| What it catches | Gradual drift accumulated over the year | Specific, significant changes as they happen |
| Timing | Fixed date, regardless of what has changed | Triggered by an event: new client, incident, certification, staff change |
| Effort | Predictable, scheduled in advance | Variable, but usually smaller and more focused |
| Best used | As a baseline safety net | Alongside the annual review, not instead of it |
In Dr Logic’s experience, the businesses most exposed are rarely the ones without IT policies at all. They are the ones with a solid policy set from two or three years ago that nobody has revisited since, and that now quietly no longer matches how the business actually runs.
Treating policy review as an ongoing discipline, rather than a one-off project completed when the policies were first written, is what keeps a business’s compliance position honest rather than nominal.
Ask this one question before booking a full review
Here is the single question worth putting to whoever owns IT policy in your business: when was the policy last checked against how the business actually operates today, not just opened or filed? If nobody can answer that with a date, the policies are due a genuine review, whatever the calendar says.
That question is deliberately small. It needs no project, no budget sign-off, just five minutes and an honest answer. Where the answer reveals a gap, the next step is the same conversation Dr Logic’s IT strategy team has with clients before any formal review begins: what has actually changed, and where the risk now sits as a result.
Related articles
- Your breach reporting policy may be weaker than you think
- Your AI tools are now in scope for cyber essentials. Here’s how to build a policy that covers you
- The 72-hour window: what insurance and regulatory coordination covers
FAQs
Why do IT policies need an annual review?
IT policies describe how a business operates at the point they are written, and businesses change continuously as tools, vendors, and staff structures evolve. Without a scheduled review, a policy can quietly stop matching how the business actually works, often for a year or more before anyone notices.
What should trigger an IT policy review outside the annual cycle?
A new client security requirement, a security incident, pursuing a certification such as Cyber Essentials or ISO 27001, or a significant change in staff structure should all trigger a review before the next scheduled date. Waiting for the calendar to catch up risks leaving a known gap open.
What does a genuine policy review actually check?
A genuine review checks whether a policy still reflects current tools, current risks, and current client or regulatory expectations, not just whether the document exists and has a recent date on it. It should also result in a documented record of what changed and why.



















































