Create a policy when a distinct purpose, audience and scope warrant a maintained document. Search the policy register first and identify whether the content belongs in an existing policy instead.

Create the document

  1. Open Policies in the intended workspace.
  2. Choose Add policy.
  3. Review or enter the Display code.
  4. Enter the Name and a Description explaining its purpose and scope.
  5. Choose Create policy.
  6. Open the new policy and confirm its first editable version.

The display code is reader-facing. The fixed registered reference remains the internal identity used for traceability.

Develop the content

Write the context and high-level requirements in the policy description. Add categories to organise related subjects, then subcategories or controls where the hierarchy requires them.

Controls describe actionable measures. Use names that make their intended outcome clear, and document who operates them, what evidence supports them and how they are reviewed.

Prepare for review

Assign owners and connect relevant framework requirements. Review the text, implementation work and evidence separately. Creating a policy does not approve it or distribute it externally.

When the draft is ready, use the version menu and the workspace's approval process. Use sharing only after reviewing the version and information that the link will expose.