2.8 Policy Access, Version Control & Role-Relevant Updates

Key Takeaways

  • Performance indicator I.B.2 requires that employees can access the policies and procedures that apply to their role, and receive updates relative to that role — access and currency are both tested.
  • The document hierarchy runs policy (what and why, board-approved) to standard (mandatory specifics) to procedure (step-by-step) to guideline (recommended practice); confusing the tiers is a recurring distractor.
  • Every governing document needs an owner, an approver, a version number, an effective date, a review cycle and a change log — an undated policy cannot be evidence.
  • Push the change, do not just publish it: role-filtered notification, a plain-language summary of what changed, and attestation for material changes.
  • Contractors and third-party staff are inside indicator II.D's training population and must receive role-relevant policy access on the same terms as employees.
Last updated: August 2026

"We Have a Policy" Is Not a Defence

Performance indicator I.B.2 is deceptively specific: ensure employees have access to policies and procedures and updates relative to their role(s). Three obligations are packed into one line — access, role relevance, and currency. A regulator or auditor asking about this indicator does not ask whether a policy exists. They ask: show me that the support agent who handled this request could find the identity-verification procedure, in the version that was in force on the day they handled it.

The document hierarchy

TierAnswersApproved byChangesExample
PolicyWhat we require and whyBoard or executiveRarely"Personal data is collected only for specified, documented purposes."
StandardThe mandatory specificsPrivacy or security leadershipOccasionally"Special-category data is encrypted at rest with keys held by the organization."
ProcedureThe step-by-step methodProcess ownerOften"How to verify identity on an inbound deletion request."
GuidelineRecommended, not mandatorySubject-matter ownerFreely"Suggested wording for a just-in-time notice."

A common exam distractor buries an operational instruction inside a board-approved policy. That is a governance error: it means routine process improvements require board approval, so in practice the document stops being updated and drifts out of alignment with reality. Policies should be stable; procedures should be alive.

The metadata that makes a document defensible

Every governing document should carry: a named owner, an approver, a version number, an effective date, a review cycle (annual is the common floor, with event-driven review on regulatory change, incidents or new processing), a change log, and an audience/applicability field. That last field is what makes role filtering possible at all.

Retention of superseded versions matters more than candidates expect. To evidence what an employee was required to do in March, the March version must still exist. Regulators, litigants and auditors routinely ask for the version in force on a specific date, so archive superseded versions with their effective-date ranges rather than overwriting.

From publish to push

Publishing a new version to a document repository is not communication. The exam-credited model is role-filtered push:

  1. Tag each document with the roles it governs.
  2. Classify the change as editorial, minor or material.
  3. Notify only the affected roles, with a plain-language summary of what changed and what you must now do differently — not a diff of the legal text.
  4. Attest for material changes, capturing acknowledgement with a timestamp.
  5. Reinforce through the manager or privacy champion for that team.
  6. Verify through a spot check that behaviour actually changed.

Organization-wide blasts for every change train people to ignore them, which is why role filtering is the credited answer rather than broader distribution.

Accessibility in practice

Access fails in mundane ways the exam likes to describe:

  • Documents live in a system that frontline or deskless staff cannot reach.
  • Access requires a licence contractors do not have.
  • Search returns three near-identical drafts with no indication which is current.
  • The only copy is a PDF attached to a two-year-old email.
  • Content exists only in a language a large part of the workforce does not read.

The fixes are equally mundane: one authoritative location, clear "current version" labelling, mobile access for deskless staff, contractor accounts, translation where the workforce needs it, and embedding the relevant procedure link at the point of the task — inside the ticketing tool where the rights request is worked, not three clicks into an intranet.

Contractors are in scope

Competency II.D names employees, management and contractors. Contractors and agency staff handle personal data on the same systems as employees, and the frequent gap is that they are onboarded through a vendor process that never touches the privacy policy set. The contract should require it, the onboarding checklist should evidence it, and access should be provisioned to the same document set.

Worked scenario

A support agent releases account data to a caller who fails identity verification. Investigation shows the verification standard was tightened four months earlier; the update was posted to the intranet, announced in an all-staff newsletter, and never routed to the support organization. The agent was following the procedure printed in their team's onboarding pack. Nothing about this is a training-content failure — it is an I.B.2 failure across all three limbs: the current version was not accessible where the work happened, the change was not filtered to the affected role, and no attestation captured the update. The credited remediation embeds the current procedure in the support tooling, tags it to the support role, pushes material changes with attestation, and retires the stale onboarding pack.

Test Your Knowledge

An organization publishes every privacy document update to a company-wide intranet feed. After an incident, a business unit says it never saw the change that applied to it. Which correction best satisfies indicator I.B.2?

A
B
C
D
Test Your Knowledge

During a regulatory inquiry, an organization is asked which identity-verification procedure was in force on a specific date eight months ago. The repository holds only the current version, because updates overwrite the prior file. What is the primary governance failure?

A
B
C
D