System of record
Policy management ends at the policy
Policy lifecycles govern the document. They stop short of the sentence an employee is handed when they ask an assistant what the policy says, and that sentence is what people act on.
Cognatum Team · Sep 18, 2026 · 5 min read
Ask a compliance team how a policy gets made and the answer is clean. Someone drafts it, a named owner approves it, it goes out to the people it binds, they attest that they have read it, and a review date lands in the calendar. The lifecycle is well understood, and the software that runs it is mature.
Cognatum governs the entry
source · version · approver · permissions
Then somebody asks a question about that policy, and almost none of it applies.
The lifecycle every vendor draws
MetricStream's guide describes policy management as establishing workflows, communicating requirements, tracking attestations, managing exceptions and monitoring compliance. Read the guide.
Wolters Kluwer's account is the one that names the failure modes: poor policy maintenance, unclear accountability, and outdated documents still in circulation. Read the analysis.
What it actually governs
Read either list closely and the object under management is always the document. The policy gets drafted, approved, versioned, distributed and reviewed, and the controls attach to that artifact. They attach well. What no step in the lifecycle reaches is the sentence an employee is handed when they ask what the policy says.
Attestation is not an answer
An attestation record proves that a named person opened a named version on a named date. That is real evidence, and examiners ask for it. It says nothing about the answer that same person receives eight months later, when they put the question to an assistant rather than reopening a forty page document.
The derivative problem
Policies breed derivatives. A summary deck built for onboarding. An intranet page written by someone in operations. A Q and A from a training session. An email from legal interpreting one clause for one business unit. None of those is the policy. All of them sit in the systems your assistant reads, and most of them outlive the version they were made from.
And then the exceptions
Exception handling appears in every description of the category, MetricStream's included. An exception is a decision that the rule does not apply in one case, granted by someone with the authority to grant it and recorded in a ticket or a register that nothing else reads. The policy stays unchanged and stays correct. The answer an assistant gives about that case is now wrong in a way no version control will ever catch.
Supervision assumed the procedure would speak for itself
FINRA Rule 3110 requires each member to establish and maintain a supervisory system reasonably designed to achieve compliance, including the establishment and maintenance of written procedures. Read the rule.
Supervision attaches to the procedures. The rule was drafted for a world in which somebody who wanted to know the procedure went and read the procedure. That assumption has quietly stopped holding. The question now gets answered by a system that reads several documents at once and returns one fluent paragraph, and the paragraph does not say which of them governed.
Grounding does not close the gap
The usual reassurance is that the assistant is grounded in company documents. Grounding helps. It does not settle anything on its own.
The first preregistered evaluation of retrieval based legal research tools found that products from LexisNexis and Thomson Reuters each hallucinated between 17 and 33 percent of the time, against marketing that described the problem as eliminated. Read the study.
And when two of your documents disagree
A survey of knowledge conflicts in large language models names the enterprise case directly as inter context conflict, where two retrieved passages contradict each other and the system resolves it quietly, often in favor of whichever reads more confidently. Read the survey.
Put a policy and four of its derivatives in the same index and that is not an edge case. It is an ordinary Tuesday.
What the instruments expect you to show
The EU AI Act requires high risk systems to technically allow the automatic recording of events over the lifetime of the system, which presumes there is something worth recording. Read Article 12.
NIST's Generative AI Profile treats information integrity as a risk category in its own right, separate from security and privacy. See the profile.
ISO/IEC 42001 applies management system discipline to artificial intelligence, including the evidence an organization is expected to keep. See the standard.
What software can and cannot claim
Each of these describes what an organization has to be able to demonstrate. Software can align with them and produce the evidence a demonstration rests on. No tool confers compliance or certification on the company running it.
Govern the answer, not only the document
None of this argues for replacing policy management software. That software does the part it was built for. What is missing is a governed layer above it, covering the policy and every place the policy has been restated since.
That layer does not ask anyone to move their content. Policies stay in the policy system, the decks and the intranet pages stay where they live, and the layer reads across all of it while holding what each item is and who stands behind it.
Three things have to travel with the answer itself:
- The named person who approved this wording for this use.
- The version that was in force at the moment the answer was given.
- The source it came from, named, rather than a confidence score.
When the source moves
Revise the policy and every entry derived from it is flagged, then routed to a named person who decides what the change means before it is approved again. Nothing rewrites itself, and no knowledge base should be sold as always current. Where two sources disagree, both are shown and the disagreement is named, rather than a model picking a winner.
The gate that stays human
That gate is what the Cognatum Knowledge Loop is built around. The finding, gathering and surfacing is increasingly done with tooling. Approve stays with a person, because deciding what is true about your own policy is not work to hand to a model. Your company's knowledge isn't missing. It's unusable. Cognatum changes that.
Sources
- Policy Management in 2026, A Detailed Guide (metricstream.com)
- Policy management challenges, best practices and considerations (wolterskluwer.com)
- FINRA Rule 3110: Supervision (finra.org)
- Hallucination-Free? Assessing the Reliability of Leading AI Legal Research Tools (arxiv.org)
- Knowledge Conflicts for LLMs: A Survey (arxiv.org)
- EU AI Act Article 12: Record-Keeping (artificialintelligenceact.eu)
- Artificial Intelligence Risk Management Framework: Generative AI Profile (nist.gov)
- ISO/IEC 42001:2023 Artificial intelligence, Management system (iso.org)
- The Cognatum Knowledge Loop (cognatum.ai)
Common questions
Questions this raises.
What is policy management?
Policy management is the process of drafting, approving, distributing, attesting to, monitoring and periodically reviewing an organization's written policies and procedures. Vendors in the category describe it as workflows, communication, attestation tracking, exception handling and compliance monitoring. In every version of that lifecycle, the object under management is the policy document itself.
Does attestation prove employees are following the policy?
It proves something narrower. An attestation record shows that a named person opened a named version on a named date. It does not show what answer that person was given months later when they asked a question about the policy, or which version of the wording that answer was drawn from.
Why does an AI assistant complicate policy management?
Because an assistant does not read the policy in isolation. It reads the policy along with the summary deck, the intranet page, the training Q and A and the interpretive email, then returns one blended paragraph. The governed document and its ungoverned derivatives are treated as equally usable material.
Is grounding an assistant in our own documents enough?
Grounding reduces the problem without resolving it. The first preregistered evaluation of retrieval based legal research tools found leading products hallucinated between 17 and 33 percent of the time despite claims to the contrary. Grounding says the answer came from source material. It does not say who approved that material or which version it was.
What should happen when the policy is updated?
Every entry derived from the old version should be flagged and routed to a named person who decides what the change means before the entry is approved again. Nothing should rewrite itself silently, and no knowledge base should be described as always current. Where two sources disagree, both should be surfaced with the disagreement named.