Feature Compliance Strategy
Policy Management KRIs: Overdue Reviews, Exception Volume, and Attestation Gaps
Five key risk indicators that show whether your policy management program is actually working — before your examiner finds the policies that haven't been meaningfully reviewed in three years.
Table of Contents
TL;DR
- Policy management KRIs measure lifecycle health — not whether policies exist, but whether they are current, owned, connected to controls, and enforced
- The most common exam finding in policy management is a gap between what the policy says and what actually happens — and it almost always traces back to a policy that hasn’t been substantively reviewed in years
- Five KRIs that close the visibility gap: overdue review rate, policy-to-control mapping gaps, exception volume and aging, attestation completion rate, and policy owner vacancy rate
- None of these are difficult to track — most programs just haven’t built the measurement framework around them
Here is how policy management failures actually happen. A compliance team inherits a policy library with 80 documents. They update ten of the high-profile ones each year — the ones that got exam questions or touched a regulation that changed. The other 70 get their review date incremented and get marked reviewed. Nothing actually changes in them.
Three years later, the policy language describes a process the operations team stopped using two years ago. The examiner asks to see policy-to-procedure alignment and immediately finds six policies where the stated control doesn’t match what anyone does. That’s a finding — not because the policy was wrong when written, but because the program was managing the document count instead of the policy lifecycle.
Policy management KRIs fix this by making the decay visible. Not as an annual audit exercise, but as a continuous signal that can be tracked, reported, and acted on before an examiner shows you where the gaps are.
What Policy Management KRIs Measure — and Why They’re Different
A policy management KRI is not a count of policies. It’s not a measure of page length or coverage area. It’s a metric that tells you whether the policy lifecycle — drafting, review, ownership, exception management, attestation, and enforcement — is actually functioning.
Most policy management reporting looks like activity: “We have 85 policies. We reviewed 42 this year.” What it should look like is risk: “17% of policies are past their review date. Exception volume is up 30% in the last quarter. Eight policies have no current owner.”
The Compliance KRIs article covers the broader compliance program health metric set. This piece goes deeper on the policy management subset — the five indicators that tell you whether your policy library is an asset or a liability at the moment an examiner asks for it.
The 5 Policy Management KRIs
KRI 1: Overdue Policy Review Rate
What it measures: The percentage of policies in your inventory that have exceeded their required review date without a completed substantive review.
Why it matters: Every bank examination standard — OCC, FDIC, FFIEC — treats policy currency as a baseline expectation. The FDIC’s Risk Management Manual of Examination Policies reinforces that management must maintain policies that reflect current operations and regulatory requirements. A policy that hasn’t been meaningfully reviewed in 18 months does neither.
The overdue review rate is also a leading indicator of a capacity problem. If more than 20% of your policies are overdue, you likely have a structural gap in your policy management function — not just isolated missed dates. That pattern shows up when examiners ask why the same two or three policy owners are listed on 40% of the inventory while half the library is past due.
How to track it:
- Maintain a policy inventory with required review frequency and last review date for every document
- Distinguish between a date update (pro forma) and a substantive review (content confirmed current, changes noted)
- Track: total policies in inventory, count past required review date, percentage overdue — segmented by policy tier (core compliance, operational procedures, technical standards)
Threshold guidance: Most programs set amber at 10% overdue and red at 20%. For tier-1 policies covering AML, UDAAP, data security, and consumer protection, any overdue review should trigger an amber flag — these track regulatory requirements that change, and currency matters more than schedule.
KRI 2: Policy-to-Control Mapping Gap Rate
What it measures: The percentage of policies where a documented control testing or monitoring activity cannot be traced to the policy’s requirements — meaning the policy says something is being done, but there is no control in your testing universe to confirm it.
Why it matters: This is the disconnect examiners find when they compare policy language to the testing calendar. The policy says payments are reconciled daily. Control testing covers weekly reconciliation. The gap is a finding — not because the policy is wrong, but because no one connected the policy requirement to an active, tested control standard.
OCC and FDIC internal control standards are consistent on this: effective control environments require that policies be supported by procedures and controls that are actually tested. A policy unsupported by a tested control is a policy that is not enforced — which means it is not actually a control, it is documentation.
This mapping also forms the foundation of a defensible RCSA. If your RCSA identifies risks without tracing them to the policy requirements those controls are designed to satisfy, you have a coverage gap that is difficult to explain in an exam.
How to track it:
- Map each core compliance policy to its related controls in your control universe
- Track: total policies with documented control linkages, count with no control mapped or with gaps in coverage, percentage unmapped by policy area
Threshold guidance: Unmapped policies in AML, data security, or consumer protection are high-severity gaps — address before the next exam cycle. An overall unmapped rate above 15% is an amber signal that warrants a full control-to-policy reconciliation project.
KRI 3: Exception Volume and Aging
What it measures: The total count of open policy exceptions, their average age, and the percentage that have exceeded their approved duration without re-approval or documented closure.
Why it matters: Policy exceptions are not inherently a problem. Business reality sometimes requires a departure from policy standard: a temporary operational workaround, a technology transition window, an approved accommodation during a system migration. The problem is when exceptions become permanent by default — initially approved for 90 days, still open at 18 months, never substantively re-reviewed.
Examiners treat aged exceptions as evidence of two simultaneous failures: the policy requirement isn’t being enforced (the business has found a permanent workaround), and the exception process isn’t functioning (approvals are administrative rather than substantive). Either interpretation is a finding. Together they suggest a policy that exists on paper but not in practice.
The Regulatory Change KRIs article covers how missed regulatory implementation deadlines create policy gaps. Exceptions that pre-date a regulation change — and were never updated to reflect the new requirement — are a version of the same failure mode: the exception is now a non-compliance, not just a deviation.
How to track it:
- Maintain an exception register with: policy name, provision being excepted, business reason, interim control in place, approver, approval date, approved duration, expiration date, remediation path
- Track: total open exceptions, count exceeding approved duration, average age of open exceptions, count by tier (high-risk policies vs. operational)
Threshold guidance: Any exception exceeding its approved duration without documented re-approval is a process failure — not just an amber metric. Exception volume trending upward quarter-over-quarter warrants root cause review: either the policy standard is unworkable in the current operating environment, or the exception approval process has become a rubber stamp.
KRI 4: Policy Attestation Completion Rate
What it measures: The percentage of required staff who have completed attestations for relevant policies within the required period — tracked by policy, by department, and specifically for high-risk staff categories.
Why it matters: Policy attestations are not a formality. They are the mechanism by which the organization demonstrates that policy requirements were communicated, understood, and acknowledged. When an examiner asks how your AML training connects to specific policy requirements, the attestation completion record is your answer. A 67% completion rate among compliance staff does not constitute an answer.
Attestation completion also functions as a leading indicator of enforcement. Low rates in a policy area typically mean the policy isn’t being operationalized. If 30% of customer-facing staff haven’t attested to your data handling policy, the operating assumption has to be that they are not consistently following it either — and that the policy is a document rather than a control.
Bank partner oversight reviews increasingly ask for attestation completion rates as part of their assessment of your compliance program’s operational maturity. A well-maintained attestation record is one of the faster evidence artifacts to produce if someone asks for it.
How to track it:
- Track attestation completion by policy, by department, and by staff category — with separate tracking for high-risk roles including compliance, AML, customer service, and sales
- Track: required attestations per period, completed attestations, percentage complete by policy and department, count of overdue attestations by staff category
Threshold guidance: High-risk staff attestation (AML, BSA, data security policies) below 90% is an amber signal. Below 80% is red. For general population policies, amber at 85% and red below 75% — with separate tracking for new employee onboarding completion to catch new-hire attestation gaps before the 90-day mark.
KRI 5: Policy Owner Vacancy Rate
What it measures: The percentage of policies in your inventory where the named owner is either vacant (role unfilled), departed (person has left the organization), or overloaded (single person named owner on more than a defined threshold of core policies).
Why it matters: A policy with no effective owner won’t be reviewed when a regulation changes. It won’t be updated when the business process evolves. It won’t be enforced when an exception is requested. It will sit in the inventory with a stale date and the name of someone who stopped working at the company eighteen months ago.
Owner vacancy is one of the easiest root causes to fix — and one of the most consistently overlooked until it causes a problem. Most programs discover it during exam prep when someone tries to schedule a review and finds out the named owner no longer exists in the org chart. At that point several review cycles have already been missed.
Overloaded ownership is a subtler version of the same problem. When one person is the named owner of 40 policies, the reviews they complete are inevitably lighter. The policies with the least regulatory exposure get the least attention. The KRI surfaces both types of failure: vacancy (easy to identify) and overloading (harder to see without an inventory metric).
How to track it:
- Maintain policy inventory with named owner, their current employment status, and current role
- Define an owner concentration threshold — most programs set this at 10 to 15 core compliance policies per owner
- Track: total policies, count with vacant owner (role unfilled), count with departed owner, count where owner exceeds concentration threshold
Threshold guidance: Any high-risk policy — AML, data security, consumer protection, model risk — with a vacant owner is an immediate action item. Overall vacancy rate above 5% in core compliance policies is amber. Owner concentration above threshold for key policies warrants succession planning and redistribution before the next annual review cycle.
Policy Management KRI Summary Table
| KRI | What It Measures | Amber Signal | Red Signal | Owner |
|---|---|---|---|---|
| Overdue Review Rate | % policies past required review date | >10% | >20% or any tier-1 overdue | Policy Manager |
| Policy-to-Control Mapping Gap | % policies with no linked tested control | >15% | Any gap in AML / data security | Compliance / Risk |
| Exception Volume and Aging | Count exceeding approved duration | Rising trend | Any open >6 months without re-approval | Policy Manager |
| Attestation Completion Rate | % required staff completing attestation | <85% general; <90% high-risk staff | <80% for any high-risk role | Compliance |
| Owner Vacancy Rate | % policies with vacant or departed owner | >5% core compliance policies | Any high-risk policy owner vacant | Policy Manager |
Connecting Policy KRIs to the Broader Compliance Program
Examiners don’t read policy documents in isolation. They compare policy language to evidence of what actually happens — testing results, exception logs, audit findings, and process walk-throughs. A well-maintained policy library with active KRI monitoring closes that gap before the comparison reveals it.
These five KRIs connect directly to the operational monitoring program. The Compliance Monitoring and Testing article covers how to build the broader monitoring framework that these policy metrics plug into — specifically the risk-based scoping decisions that determine which policies get heavier monitoring attention in a given cycle.
Policy management KRIs are one component of a compliance program health dashboard, sitting alongside issue management metrics, regulatory change tracking, training KRIs, and exam readiness indicators. The KRIs compound on each other: an overdue policy in an area with open exceptions and low attestation completion is a tier-1 finding waiting to happen. Tracking them separately misses that compounding signal.
For each policy, the evidence standard is straightforward: can you show when it was last substantively reviewed, who reviewed it, whether controls are mapped and tested against it, who the current owner is, and whether applicable staff have attested to it? If the answer to any of those questions is uncertain, the KRI is showing you exactly where to look.
So What? What This Means for Your Program
Most compliance teams have policies. Fewer have a policy management program. The difference is measurement.
Running these five KRIs quarterly — and reporting them to your risk committee or audit function — converts policy management from an annual scramble into an ongoing monitoring activity. That is the operational difference between finding the 2022 policy in exam prep and never encountering it because your overdue review rate flagged it in Q3 the prior year.
If your program tracks some of these informally — you know certain policies are overdue, you have a rough sense of attestation completion, you remember which owner left six months ago — the next step is formalizing the measurement: a policy inventory with required fields, a reporting cadence, and defined thresholds that generate action rather than just observation.
The Compliance Essentials bundle includes the policy templates, compliance monitoring framework, and the evidence structure these KRIs are designed to surface gaps in. It’s built for programs that have the documentation but need the management framework around it — available directly at this link.
Sources used in this article: FDIC Risk Management Manual of Examination Policies (updated March 2026); OCC Internal Control Comptroller’s Handbook; FFIEC IT Examination Handbook — Management.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Compliance Essentials
Multi-domain compliance coverage: data privacy, incident response, BCP/DR, and SOC 2 — 43% off.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What are policy management KRIs?
How often should compliance policies be reviewed?
What does an examiner look for in policy management?
How do you track policy exceptions as a KRI?
Why does policy owner vacancy matter as a KRI?
What is the relationship between policy attestations and exam readiness?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Compliance Essentials
Multi-domain compliance coverage: data privacy, incident response, BCP/DR, and SOC 2 — 43% off.
◆ Keep reading
Related posts.
Compliance Strategy
GRC Framework for a Small Risk Team: One Control Library, Five Workflows, No Enterprise Platform
A GRC program that runs on one control library, five traceable workflows, and a set of spreadsheets beats a half-implemented enterprise platform every time. Here's how to build it.
Jul 24, 2026
Compliance Strategy
Compliance Monitoring Plan in Excel: Convert the Risk Assessment Into a Defensible Test Universe
Build a compliance monitoring plan template in Excel that traces risks and obligations to scope, evidence, exceptions, and remediation.
Jul 23, 2026
Compliance Strategy
Your Reg E Program Wasn't Built for FedNow: The Error Resolution Timeline Trap in Instant Payments
Reg E's 10-business-day provisional credit requirement applies to FedNow and RTP consumer transactions—but instant payment irrevocability means the fraud money is gone before you finish the investigation. Here's what your error resolution procedures actually need to say for instant payments, and where most programs have a documented gap.
Jul 22, 2026