Documents and policies, and how they differ
Both documents and policies are Records, and they share the same layout and lifecycle. The difference is worker sign-off:
A document is a record, register, plan, assessment, procedure, or other piece of documentation tied to controls and framework obligations.
A policy is a document workers are expected to read and acknowledge or sign, with sign-off tracked against each worker. See Workers acknowledging policies.
Adding a policy or document
Open Records and either:
Pick a pre-built template and fill it out in the in-platform editor, or
Upload your own document that satisfies the requirement.
ReFresh ships with a large library of pre-built document and policy templates covering registers, procedures, assessments, plans, communications, logs, reports, checklists, and training records. When you activate a framework, its relevant templates appear in Records with Incomplete status, ready for you to complete or replace with your own document.
Template and requirement counts change: The library grows as ReFresh adds framework coverage. Read the current numbers from the app rather than relying on a fixed figure.
The review and version lifecycle
Each policy or document moves through a draft, then submitted for review, then current evidence flow. Once current, it counts as evidence for every control that references it, and updating it once updates every linked control. Reviews are where a person approves the record or requests changes; see Assigning and completing reviews.
Policies carry an extra layer: version history, renewal cadence, and worker acknowledgement tracking. How a policy is versioned and how its renewal is tracked over time is covered in Policy version control and renewal tracking.
