Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Compliance Strategy

Policy Management KRIs: Overdue Reviews, Exception Volume, and Attestation Gaps

Five key risk indicators that show whether your policy management program is actually working — before your examiner finds the policies that haven't been meaningfully reviewed in three years.

Table of Contents

TL;DR

  • Policy management KRIs measure lifecycle health — not whether policies exist, but whether they are current, owned, connected to controls, and enforced
  • The most common exam finding in policy management is a gap between what the policy says and what actually happens — and it almost always traces back to a policy that hasn’t been substantively reviewed in years
  • Five KRIs that close the visibility gap: overdue review rate, policy-to-control mapping gaps, exception volume and aging, attestation completion rate, and policy owner vacancy rate
  • None of these are difficult to track — most programs just haven’t built the measurement framework around them

Here is how policy management failures actually happen. A compliance team inherits a policy library with 80 documents. They update ten of the high-profile ones each year — the ones that got exam questions or touched a regulation that changed. The other 70 get their review date incremented and get marked reviewed. Nothing actually changes in them.

Three years later, the policy language describes a process the operations team stopped using two years ago. The examiner asks to see policy-to-procedure alignment and immediately finds six policies where the stated control doesn’t match what anyone does. That’s a finding — not because the policy was wrong when written, but because the program was managing the document count instead of the policy lifecycle.

Policy management KRIs fix this by making the decay visible. Not as an annual audit exercise, but as a continuous signal that can be tracked, reported, and acted on before an examiner shows you where the gaps are.


What Policy Management KRIs Measure — and Why They’re Different

A policy management KRI is not a count of policies. It’s not a measure of page length or coverage area. It’s a metric that tells you whether the policy lifecycle — drafting, review, ownership, exception management, attestation, and enforcement — is actually functioning.

Most policy management reporting looks like activity: “We have 85 policies. We reviewed 42 this year.” What it should look like is risk: “17% of policies are past their review date. Exception volume is up 30% in the last quarter. Eight policies have no current owner.”

The Compliance KRIs article covers the broader compliance program health metric set. This piece goes deeper on the policy management subset — the five indicators that tell you whether your policy library is an asset or a liability at the moment an examiner asks for it.


The 5 Policy Management KRIs

KRI 1: Overdue Policy Review Rate

What it measures: The percentage of policies in your inventory that have exceeded their required review date without a completed substantive review.

Why it matters: Every bank examination standard — OCC, FDIC, FFIEC — treats policy currency as a baseline expectation. The FDIC’s Risk Management Manual of Examination Policies reinforces that management must maintain policies that reflect current operations and regulatory requirements. A policy that hasn’t been meaningfully reviewed in 18 months does neither.

The overdue review rate is also a leading indicator of a capacity problem. If more than 20% of your policies are overdue, you likely have a structural gap in your policy management function — not just isolated missed dates. That pattern shows up when examiners ask why the same two or three policy owners are listed on 40% of the inventory while half the library is past due.

How to track it:

  • Maintain a policy inventory with required review frequency and last review date for every document
  • Distinguish between a date update (pro forma) and a substantive review (content confirmed current, changes noted)
  • Track: total policies in inventory, count past required review date, percentage overdue — segmented by policy tier (core compliance, operational procedures, technical standards)

Threshold guidance: Most programs set amber at 10% overdue and red at 20%. For tier-1 policies covering AML, UDAAP, data security, and consumer protection, any overdue review should trigger an amber flag — these track regulatory requirements that change, and currency matters more than schedule.


KRI 2: Policy-to-Control Mapping Gap Rate

What it measures: The percentage of policies where a documented control testing or monitoring activity cannot be traced to the policy’s requirements — meaning the policy says something is being done, but there is no control in your testing universe to confirm it.

Why it matters: This is the disconnect examiners find when they compare policy language to the testing calendar. The policy says payments are reconciled daily. Control testing covers weekly reconciliation. The gap is a finding — not because the policy is wrong, but because no one connected the policy requirement to an active, tested control standard.

OCC and FDIC internal control standards are consistent on this: effective control environments require that policies be supported by procedures and controls that are actually tested. A policy unsupported by a tested control is a policy that is not enforced — which means it is not actually a control, it is documentation.

This mapping also forms the foundation of a defensible RCSA. If your RCSA identifies risks without tracing them to the policy requirements those controls are designed to satisfy, you have a coverage gap that is difficult to explain in an exam.

How to track it:

  • Map each core compliance policy to its related controls in your control universe
  • Track: total policies with documented control linkages, count with no control mapped or with gaps in coverage, percentage unmapped by policy area

Threshold guidance: Unmapped policies in AML, data security, or consumer protection are high-severity gaps — address before the next exam cycle. An overall unmapped rate above 15% is an amber signal that warrants a full control-to-policy reconciliation project.


KRI 3: Exception Volume and Aging

What it measures: The total count of open policy exceptions, their average age, and the percentage that have exceeded their approved duration without re-approval or documented closure.

Why it matters: Policy exceptions are not inherently a problem. Business reality sometimes requires a departure from policy standard: a temporary operational workaround, a technology transition window, an approved accommodation during a system migration. The problem is when exceptions become permanent by default — initially approved for 90 days, still open at 18 months, never substantively re-reviewed.

Examiners treat aged exceptions as evidence of two simultaneous failures: the policy requirement isn’t being enforced (the business has found a permanent workaround), and the exception process isn’t functioning (approvals are administrative rather than substantive). Either interpretation is a finding. Together they suggest a policy that exists on paper but not in practice.

The Regulatory Change KRIs article covers how missed regulatory implementation deadlines create policy gaps. Exceptions that pre-date a regulation change — and were never updated to reflect the new requirement — are a version of the same failure mode: the exception is now a non-compliance, not just a deviation.

How to track it:

  • Maintain an exception register with: policy name, provision being excepted, business reason, interim control in place, approver, approval date, approved duration, expiration date, remediation path
  • Track: total open exceptions, count exceeding approved duration, average age of open exceptions, count by tier (high-risk policies vs. operational)

Threshold guidance: Any exception exceeding its approved duration without documented re-approval is a process failure — not just an amber metric. Exception volume trending upward quarter-over-quarter warrants root cause review: either the policy standard is unworkable in the current operating environment, or the exception approval process has become a rubber stamp.


KRI 4: Policy Attestation Completion Rate

What it measures: The percentage of required staff who have completed attestations for relevant policies within the required period — tracked by policy, by department, and specifically for high-risk staff categories.

Why it matters: Policy attestations are not a formality. They are the mechanism by which the organization demonstrates that policy requirements were communicated, understood, and acknowledged. When an examiner asks how your AML training connects to specific policy requirements, the attestation completion record is your answer. A 67% completion rate among compliance staff does not constitute an answer.

Attestation completion also functions as a leading indicator of enforcement. Low rates in a policy area typically mean the policy isn’t being operationalized. If 30% of customer-facing staff haven’t attested to your data handling policy, the operating assumption has to be that they are not consistently following it either — and that the policy is a document rather than a control.

Bank partner oversight reviews increasingly ask for attestation completion rates as part of their assessment of your compliance program’s operational maturity. A well-maintained attestation record is one of the faster evidence artifacts to produce if someone asks for it.

How to track it:

  • Track attestation completion by policy, by department, and by staff category — with separate tracking for high-risk roles including compliance, AML, customer service, and sales
  • Track: required attestations per period, completed attestations, percentage complete by policy and department, count of overdue attestations by staff category

Threshold guidance: High-risk staff attestation (AML, BSA, data security policies) below 90% is an amber signal. Below 80% is red. For general population policies, amber at 85% and red below 75% — with separate tracking for new employee onboarding completion to catch new-hire attestation gaps before the 90-day mark.


KRI 5: Policy Owner Vacancy Rate

What it measures: The percentage of policies in your inventory where the named owner is either vacant (role unfilled), departed (person has left the organization), or overloaded (single person named owner on more than a defined threshold of core policies).

Why it matters: A policy with no effective owner won’t be reviewed when a regulation changes. It won’t be updated when the business process evolves. It won’t be enforced when an exception is requested. It will sit in the inventory with a stale date and the name of someone who stopped working at the company eighteen months ago.

Owner vacancy is one of the easiest root causes to fix — and one of the most consistently overlooked until it causes a problem. Most programs discover it during exam prep when someone tries to schedule a review and finds out the named owner no longer exists in the org chart. At that point several review cycles have already been missed.

Overloaded ownership is a subtler version of the same problem. When one person is the named owner of 40 policies, the reviews they complete are inevitably lighter. The policies with the least regulatory exposure get the least attention. The KRI surfaces both types of failure: vacancy (easy to identify) and overloading (harder to see without an inventory metric).

How to track it:

  • Maintain policy inventory with named owner, their current employment status, and current role
  • Define an owner concentration threshold — most programs set this at 10 to 15 core compliance policies per owner
  • Track: total policies, count with vacant owner (role unfilled), count with departed owner, count where owner exceeds concentration threshold

Threshold guidance: Any high-risk policy — AML, data security, consumer protection, model risk — with a vacant owner is an immediate action item. Overall vacancy rate above 5% in core compliance policies is amber. Owner concentration above threshold for key policies warrants succession planning and redistribution before the next annual review cycle.


Policy Management KRI Summary Table

KRIWhat It MeasuresAmber SignalRed SignalOwner
Overdue Review Rate% policies past required review date>10%>20% or any tier-1 overduePolicy Manager
Policy-to-Control Mapping Gap% policies with no linked tested control>15%Any gap in AML / data securityCompliance / Risk
Exception Volume and AgingCount exceeding approved durationRising trendAny open >6 months without re-approvalPolicy Manager
Attestation Completion Rate% required staff completing attestation<85% general; <90% high-risk staff<80% for any high-risk roleCompliance
Owner Vacancy Rate% policies with vacant or departed owner>5% core compliance policiesAny high-risk policy owner vacantPolicy Manager

Connecting Policy KRIs to the Broader Compliance Program

Examiners don’t read policy documents in isolation. They compare policy language to evidence of what actually happens — testing results, exception logs, audit findings, and process walk-throughs. A well-maintained policy library with active KRI monitoring closes that gap before the comparison reveals it.

These five KRIs connect directly to the operational monitoring program. The Compliance Monitoring and Testing article covers how to build the broader monitoring framework that these policy metrics plug into — specifically the risk-based scoping decisions that determine which policies get heavier monitoring attention in a given cycle.

Policy management KRIs are one component of a compliance program health dashboard, sitting alongside issue management metrics, regulatory change tracking, training KRIs, and exam readiness indicators. The KRIs compound on each other: an overdue policy in an area with open exceptions and low attestation completion is a tier-1 finding waiting to happen. Tracking them separately misses that compounding signal.

For each policy, the evidence standard is straightforward: can you show when it was last substantively reviewed, who reviewed it, whether controls are mapped and tested against it, who the current owner is, and whether applicable staff have attested to it? If the answer to any of those questions is uncertain, the KRI is showing you exactly where to look.


So What? What This Means for Your Program

Most compliance teams have policies. Fewer have a policy management program. The difference is measurement.

Running these five KRIs quarterly — and reporting them to your risk committee or audit function — converts policy management from an annual scramble into an ongoing monitoring activity. That is the operational difference between finding the 2022 policy in exam prep and never encountering it because your overdue review rate flagged it in Q3 the prior year.

If your program tracks some of these informally — you know certain policies are overdue, you have a rough sense of attestation completion, you remember which owner left six months ago — the next step is formalizing the measurement: a policy inventory with required fields, a reporting cadence, and defined thresholds that generate action rather than just observation.

The Compliance Essentials bundle includes the policy templates, compliance monitoring framework, and the evidence structure these KRIs are designed to surface gaps in. It’s built for programs that have the documentation but need the management framework around it — available directly at this link.


Sources used in this article: FDIC Risk Management Manual of Examination Policies (updated March 2026); OCC Internal Control Comptroller’s Handbook; FFIEC IT Examination Handbook — Management.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What are policy management KRIs?
Policy management KRIs are key risk indicators that measure the lifecycle health of your policy program — whether policies are being reviewed on schedule, who owns them, whether exceptions are tracked and managed, and whether required attestations are completed. They shift the question from 'do we have a policy?' to 'is the policy actually maintained and enforced?'
How often should compliance policies be reviewed?
Most regulatory guidance and audit standards expect an annual review cycle for core compliance and risk policies, with triggered reviews when regulations change, business activities change, or audit or exam findings relate to a policy area. The review should be substantive — checking that policy language reflects actual current practice — not a pro forma date update. The overdue review rate KRI measures how many policies have exceeded their required review date without a completed substantive review.
What does an examiner look for in policy management?
Examiners look for evidence that policies are current (review date, version control), owned (named owner responsible for maintenance), aligned with actual practice (the policy says X, the controls do X), and enforced (exceptions are tracked, approved, and managed to closure). A policy dated 2021 that hasn't been updated since is a finding. A policy with five open exceptions and no approval documentation is a larger finding. The combination of stale date plus no control linkage plus vacant owner is what drives a policy management MRA.
How do you track policy exceptions as a KRI?
Policy exception tracking should capture: the policy and specific provision being excepted, the business reason, the interim control in place, the approver and approval date, the expiration date, and the remediation or closure path. The KRI tracks exception volume trend, average age, percentage that have exceeded their approved duration without re-approval, and whether exceptions are receiving substantive renewal review or just rolling forward automatically.
Why does policy owner vacancy matter as a KRI?
A policy with no current owner — because the named owner left the company, changed roles, or has too many policies to manage effectively — is a policy that won't get reviewed when a regulation changes, won't be updated when the business process evolves, and won't be enforced consistently. Owner vacancy rate tracks how many policies in the inventory have a vacant, departed, or overloaded owner. It is one of the most common root causes of overdue review findings and one of the easiest to fix before it becomes an exam issue.
What is the relationship between policy attestations and exam readiness?
Policy attestations — signed acknowledgments from relevant staff confirming they have read and understood a policy — are both a compliance control and an evidence artifact. When an examiner asks whether your staff knew this policy existed and what it required, the attestation record is your answer. Low attestation completion rates in high-risk areas such as AML, BSA, and data security are a recurring finding in compliance exam reports and bank partner oversight reviews.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Compliance Essentials

Multi-domain compliance coverage: data privacy, incident response, BCP/DR, and SOC 2 — 43% off.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.