Creating Review Policies
Review policies define when and how often content should be reviewed, and who receives reminders. Once you create a policy, you can assign it to documents or risk assessments so they're regularly checked for accuracy and currency. This keeps content up to date, supports regulatory compliance, and creates an audit trail. You'll need the review interval, the people or groups who should review, and a clear name that describes what the policy is for.
Before you start
You need the Manager or Admin role for your site to create review policies. If you don't see the governance settings, contact your site administrator.
Policy names must be unique within your site. If you try to use a name that already exists, the form will show an error after you attempt to submit.
How to create a review policy
Go to Settings > Governance and select the Review Policies tab.
Click New Review Policy or Create Policy.
Enter a Name (e.g. "Annual Policy Review" or "Quarterly Risk Assessment Review").
Include the interval in the name so it's clear how often reviews occur.
If you enter a name that already exists at this site, an inline error appears after you try to submit: A review policy with this name already exists at this site.
(Optional) Add a Description explaining when to use this policy and what content it's for.
Set the Review interval—how often content should be reviewed (e.g. 3 months, 6 months, 1 year, 2 years). The default interval is 1 month.
Match the interval to regulatory requirements (e.g. annual for H&S policies).
If you leave the interval empty, the form defaults to 1 month.
Add Recipients—who receives review reminders:
Click Add Users to add individuals.
Click Add Groups to add teams or groups (use groups for flexibility when people are unavailable).
You can add both individuals and groups.
If you try to submit without any recipients, an inline error appears: Add at least one user or group as a reviewer.
(Optional) If your site has child sites, toggle Share with child sites so they can use this policy—they can't edit or delete it.
Click Save or Create Policy.
Your new review policy appears in the list and is ready to assign to content.
Validation behavior
Validation errors only appear after you click the submit button. The form does not disable the submit button while you are filling it out. If required fields are missing or the name is a duplicate, the form blocks submission and shows inline errors so you can correct them before trying again.
Archive, restore, or delete a review policy
Archive a review policy when it has been assigned to content and you want to stop new documents from using it. Archived policies remain linked to existing content and continue to generate review reminders, but they can't be edited and new content can't be assigned to them. Delete a policy only when it has never been used and is still active. For the shared pattern, see Archive, restore, and permanently delete records.
Go to Settings > Governance and select the Review Policies tab.
Use the filter bar to narrow the list: All, Active, Archived, This Site, Inherited, or Shared with Child Sites.
For an active policy that has been used, click Archive to retire it without affecting existing assignments.
For an archived policy, click Restore to return it to active use. It becomes available for new documents or policies again. Existing assignments and review history are unchanged.
For a policy that has never been used, click Delete to remove it completely.
Archived policies cannot be deleted. Restore the policy first if you need to remove it, then delete it while it is active.
Common questions
What happens when I change a policy's interval? CalmCompliance recalculates the next review due dates for all content using that policy.
Can I assign multiple review policies to one document? No. Each document or assessment can have one active review policy. If you need different frequencies, consider splitting into multiple documents.
What if I delete a group that's used in a review policy? The policy continues but won't have recipients from that group. Update the policy to add new recipients.
What happens if no one completes a review? The content stays published but is marked overdue. Notifications continue until the review is completed.