Compliance

Policy Lifecycle Tracker

A policy lifecycle tracker records the last review date of each policy and the cycle it should be reviewed on, then calculates the next due date and flags anything within 30 days. It exists because auditors ask for evidence that policies are reviewed at planned intervals, and a spreadsheet nobody opens is not evidence.

Last reviewed by the Radiatus Cloud team

Going for ISO 27001, SOC 2, HIPAA or GDPR?

Radiatus runs end-to-end compliance & GRC programs.

Get a free readiness review

What auditors expect

ISO 27001 clause 5.2 and Annex A control 5.1 require the information security policy to be reviewed at planned intervals and when significant changes occur. SOC 2 does not name a frequency, but auditors under the Trust Services Criteria almost universally expect annual review with dated approval. PCI DSS requirement 12.1 is explicit: review the security policy at least once every 12 months. The practical evidence is a document with a review date, a reviewer and a version, and a schedule showing the next one.

How the tracker works

  • Enter the policy name, the date of its last approved review, and the cycle: annual by default, or quarterly, six-monthly or two-yearly.
  • The next review date is the last review plus the cycle. Anything due within 30 days turns red.
  • The list is saved in your browser's local storage, so it survives a reload on the same device. It is not synced anywhere and clearing site data removes it.

Choosing a cycle

Annual suits the top-level information security policy, acceptable use and access control. Quarterly is worth it for anything tied to fast-moving systems: the AI acceptable use policy, cloud configuration standards, incident response contacts. Two-yearly is defensible for stable documents such as the physical security policy of a single office, but state the reasoning in the document itself, because an auditor will ask.

What a review actually involves

A review is not a re-approval with a new date. It checks that the policy still matches how the organisation operates, that referenced standards and laws are current, that owners named in it still exist, and that any exceptions granted during the year are either closed or written in. A review that changes nothing should still record that it happened and why nothing changed.

Limits

The tracker holds names and dates only. It does not store the documents, route approvals or send reminders. Pair it with a calendar entry on the due date, and keep the signed policy in your document system with the review date in its metadata.

Related tools

  • Compliance Calendar — Enter your frameworks and a start date to lay out a year of recurring compliance obligations (SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, NIST CSF) with dates and an .ics download.
  • Audit Readiness Planner — Plan your compliance audit timeline (SOC2, ISO) backwards from deadline.
  • Policy Gap Identifier — Identify missing critical security policies based on frameworks.
  • ISO 27001 Checklist — Step-by-step checklist for ISO 27001 certification readiness.

Frequently Asked Questions

Where is my policy list stored?

In your browser's local storage on this device. Nothing is sent to a server. A different browser or a cleared cache starts empty, so export the list into your compliance system once it is set up.

How often must policies be reviewed for ISO 27001?

At planned intervals, which the standard leaves to you to define and justify. Annual review is the convention and the safe answer; longer intervals need a documented rationale.

What happens when a review is overdue?

The tracker shows a negative day count in red. For an audit, an overdue review is a finding; the remedy is to complete it promptly and record why it slipped.

Does a review have to change the policy?

No. Confirming a policy is still fit for purpose is a valid outcome, but record the review, the reviewer and the confirmation. A document whose only evidence of review is an updated footer date is weak.

Can I track procedures and standards as well as policies?

Yes. The tool does not distinguish. Standards and runbooks often warrant shorter cycles than policies because they describe specific systems that change.

Privacy & Security

Tracking done locally.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.