Find out which policies and procedures need fixing

Your policies and procedures are often spread across SharePoint, shared drives, an intranet and people’s inboxes.

A Cherryleaf Policy and Procedure Audit gives you a clear record of what you have and what condition it is in, so you know which ones:

  • Are current and valid.
  • Refer to teams that no longer exist, systems you stopped using years ago or processes that staff no longer follow.
  • Overlap and cover the same subject.
  • Might be missing.

We identify gaps, duplication, outdated content, ownership problems and documents that are hard to use. You receive a prioritised plan for fixing them, together with an estimate of the work involved.

Book a free scoping call

Why policy and procedure sets fall out of control

Most document sets do not fail all at once.

Over time:

  • A policy is written after an audit.
  • A procedure is created for a new system.
  • A team copies an existing document and changes it for its own use.
  • Someone leaves, but their name remains on the approval page.
  • A replacement process goes live, while the old instructions stay on SharePoint.

After a few years, the result is:

  • Nobody has a complete view.
  • Staff find two versions of the same procedure and choose the shorter one.
  • Managers ask colleagues how something works instead of checking the official guidance.
  • Document owners inherit files they did not write and do not understand.
  • Review dates pass because there is no agreed process for dealing with them.

The audit gives you a reliable starting point.

What we examine

We agree the scope before the work begins. You might ask us to review one department, a selected group of high-risk documents, or the whole policy and procedure set.

The audit can cover the following areas.

What exists

We create or check an inventory of the documents in scope.

We record where they are stored, what they cover and who owns them. We also identify:

  • Missing policies and procedures
  • Duplicate documents
  • Documents that overlap or contradict each other
  • Obsolete versions that are still available
  • Undocumented work that depends on staff knowledge
  • Documents stored outside the official system
  • Gaps between the formal document register and the files people use

Whether the content is current

We look for evidence that the documents no longer match the organisation.

Examples include:

  • Old department names
  • Job titles that no longer exist
  • References to retired software
  • Broken links
  • Process steps that staff skip
  • Approval dates from several years ago
  • Conflicting responsibilities
  • Forms that have been replaced
  • Instructions that no longer match the work

Your legal, compliance and subject specialists remain responsible for confirming whether the content is correct. We identify what needs their attention and why.

Whether people can use it

A procedure can contain the right information and still fail its users.

We check whether someone can tell when the document applies, what they need to do and what happens when the normal process does not fit.

We look at:

  • Headings and structure
  • The order of the instructions
  • missing decision points
  • undefined terms
  • unclear responsibilities
  • buried warnings
  • unexplained exceptions
  • links to forms, systems and related documents
  • the difference between mandatory rules and optional guidance

We also check whether the document gives too much detail, too little detail or the wrong detail for its audience.

Whether the set is consistent

Consistency makes the documents easier to find, use and maintain. It also reduces the risk that staff will treat two conflicting documents as equally authoritative.

We identify these differences and recommend a common approach to:

  • Document types
  • Titles and file names
  • Templates
  • Terminology
  • Roles and responsibilities
  • Version information
  • Approval records
  • Links and cross-references
  • Review dates

Who is responsible

Outdated documents usually have an ownership problem behind them.

We check whether each document has a named owner, whether that person knows what the role involves and whether changes to systems or working practices trigger a document update.

We also examine how documents are reviewed, approved, published, archived and withdrawn.

What you receive

The deliverables depend on the size and scope of the audit.

A document inventory

You receive a structured record of the policies and procedures covered by the review.

The inventory can include:

    • Title
    • Document type
    • Business area
    • Owner
    • Storage location
    • Approval date
    • Review date
    • Current status
    • Problems found
    • Recommended action

You can continue using the inventory after the project as the basis for document control and future reviews.

A findings report

The report sets out what we found across the document set. It separates isolated errors from repeated problems.

We explain which findings affect day-to-day work, which create avoidable risk, and which make the content expensive to maintain.

A prioritised action plan

You don’t normally need to rewrite everything at once.

We group the documents by the action they need. For example:

  • Withdraw
  • Merge
  • Correct
  • Review with a subject specialist
  • Rewrite
  • Create from scratch

We then rank the work according to business impact, use, risk, dependencies and effort.

The result is a practical work programme, rather than a long list of faults.

An estimate of the work

We estimate the effort needed to carry out the recommended changes.

The estimate can separate quick corrections from substantial rewriting, new document creation, interviews with subject experts and changes to templates or governance.

This gives you evidence for a budget, a project plan or a request for internal resources.

A review meeting

We present the findings to your team and explain the priorities.

You can challenge the recommendations, add information that was not available during the review and decide how to divide the work between internal staff and external writers.

When to commission an audit

A Policy and Procedure Audit is useful when:

  • Staff cannot tell which version is current
  • Policies and procedures are stored in several places
  • An audit has found document control problems
  • The organisation has merged or reorganised
  • A new intranet or document management system is being introduced
  • Teams have created their own versions of central procedures
  • Review dates have passed
  • Ownership is unclear
  • You need to estimate the cost of a rewriting programme
  • You plan to use internal content with an ai assistant
  • Due diligence has exposed gaps in the document set
  • Senior managers want evidence before approving a larger project

The scope can cover the whole organisation, or one area (such as HR, Finance, IT, Operations, Customer Service, or Procurement).

Policy and Procedure Audit or Documentation Debt Audit?

These services deal with related problems, but they have different scopes.

Choose the Policy and Procedure Audit when the main problem sits within your policies and procedures.

You need to know:

  • Which documents exist
  • Which ones are missing
  • Which ones conflict
  • Which ones should be withdrawn
  • Who owns them
  • What it will take to put the set in order

The audit goes into detail on the condition and management of that document set.

Choose the Documentation Debt Audit when the problem extends beyond policies and procedures.

That wider audit can include product documentation, knowledge bases, help content, internal guidance, API documentation and other business-critical content. It examines the cost and effect of documentation problems across the organisation.

A Policy and Procedure Audit can form one part of a Documentation Debt Audit, but the two services are not interchangeable.

We will recommend one scope. We will not sell you two audits that repeat the same work.

What the review does not cover

We do not provide legal advice or certify that a document meets a law, regulation or industry standard.

Your legal, compliance and subject specialists must confirm those points.

We assess whether the documents are complete, current, consistent, usable and properly managed. We also identify where a specialist review is needed.

The audit does not assume that every document deserves to survive. Deleting or combining files is often the right answer.

How it works

1. We agree the scope

We start with a scoping call.

We discuss the number and type of documents, where they are stored, the problems you have already found and what decision the audit needs to support.

For a small document set, we may review every file. For several hundred documents, it might make more sense to begin with a selected business area or a representative sample.

2. We build or check the inventory

We gather the available document lists and compare them with the files that exist.

This stage exposes missing metadata, duplicate records and documents stored outside the agreed location.

3. We assess the documents

We review the content against the criteria agreed at the start.

Depending on the project, we might also interview document owners, managers or users. Their answers help us distinguish between a document that looks outdated and one that staff know is outdated.

4. We set priorities

We compare the findings across the document set.

A spelling error in a rarely used procedure does not carry the same weight as an incorrect safety instruction used every day. The plan reflects that difference.

5. We report the findings

You receive the agreed inventory, report, action plan and work estimate.

We then take you through the recommendations and discuss the next step.

What happens next

You can use the findings to run the improvement work internally.

You might assign documents to existing owners, build a business case for extra staff, prepare content for a migration, or send selected policies to legal and compliance advisers.

Cherryleaf can also carry out the writing work.

Our policy and procedure writers can interview your subject experts, rewrite unclear documents, create missing procedures, and introduce templates that make future updates easier.

See: Policy and procedure writing services

There is no obligation to ask us to complete the remediation work.

Book a free scoping call

You do not need an accurate document count before contacting us.

Tell us where the documents are stored, which parts of the organisation they cover and what has prompted the review. We will help you decide whether to audit the whole set, one department or a sample.

You will then receive a proposed scope, deliverables and price.

Email: info@cherryleaf.com

Book a free scoping call