Skip to main content
Category: Policy Management

Policy Author

Also known as: Policy Writer, Policy Drafter
Simply put

A policy author is the person, or group of people, responsible for drafting and maintaining an organization's internal policies. This role focuses on writing the policy text and keeping it current, and is typically kept separate from the person who formally approves the policy. The evidence available here relates mainly to authorship in academic policy publishing rather than to the internal-policy-management use of the term in a GRC setting.

Formal definition

In governance and policy-management practice, a policy author is the individual or role assigned responsibility for developing, drafting, and revising the content of an internal policy document within a defined policy lifecycle. The author role is commonly distinguished from the reviewer and approver (owner/authorizing authority) roles as part of segregation of duties in policy governance: authoring produces and maintains the policy text, whereas approval confers organizational authority and accountability for issuing it. Note that the supplied evidence addresses authorship primarily in the context of scholarly policy journals and publication ethics, and one source (Kelaita, 2025) examines the theoretical 'policy author-function' in analyzing public policy texts; these do not directly document the GRC internal-policy meaning. This entry does not cover specific policy-management tooling, jurisdiction-specific documentation requirements, or the assignment of author responsibilities under any particular control framework, and readers should verify against their organization's own policy-management standard.

Why it matters

The policy author role sits at the point where governance intent becomes documented instruction. Policies are the mechanism by which an organization's leadership communicates expected behavior, defines control requirements, and demonstrates that governance structures translate into operating practice. If the person drafting a policy is unclear, the text can drift out of date, contradict other documents, or fail to reflect the organization's actual risk decisions, undermining the reliability of the whole policy framework.

Who it's relevant to

Governance professionals
Those responsible for the organization's policy framework rely on a clearly assigned author role to ensure policy text is drafted, maintained, and kept current, and to preserve the separation between authoring content and approving it.
Compliance officers
Compliance functions often draft or maintain internal policies that translate external obligations and internal requirements into documented expectations, making the author role central to keeping those documents accurate and up to date.
Internal auditors and assurance functions
Assurance providers examine whether policy governance maintains appropriate segregation of duties, for example, whether authoring and approval are held by distinct roles, while remaining independent of the drafting activity itself.
Policy owners and approvers
Those who hold authorizing authority for a policy depend on the author to produce and revise the text they ultimately review and approve, so a clear author assignment supports accountable issuance.

Inside Policy Author

Drafting responsibility
The core function of a policy author is to draft and revise the text of an internal policy, translating governance direction, risk decisions, and applicable legal or regulatory requirements into clear, actionable written statements. This is a management activity within the first or second line, not an assurance activity.
Subject-matter alignment
Policy authors typically work with or hold relevant subject-matter expertise (for example, information security, privacy, finance, or health and safety) so that policy content reflects the actual obligations and control expectations for the domain the policy addresses.
Separation from the approver
In many policy-management lifecycles, the author role is distinct from the approver or policy owner. The author prepares content, while an accountable owner or governing body formally approves and sponsors the policy. Keeping these roles separate supports accountability and reduces the risk of self-authorization. The specific approval hierarchy varies by organization, jurisdiction, and framework.
Lifecycle and maintenance duties
Beyond initial drafting, authors are commonly responsible for periodic review and updates so that policies remain current with changing laws, regulations, risks, and internal structures. Frameworks that address policy lifecycle management, such as ISO/IEC 27001 information security policy guidance and NIST SP 800-53 policy and procedure controls (for example the '-1' controls like PM-1 and PL-1), expect policies to be established, maintained, and reviewed, though they generally describe the outcomes rather than prescribe a specific author job title.
Traceability to requirements
A policy author commonly documents the linkage between policy provisions and their driving sources, laws, regulations, standards, or risk decisions, so that reviewers and auditors can trace why a provision exists. The author does not assess the policy's own effectiveness; independent evaluation is an assurance function.

Common questions

Answers to the questions practitioners most commonly ask about Policy Author.

Is 'policy author' a term without a recognized meaning in GRC?
No. The term is commonly used in policy-management literature and industry practice to denote the individual or individuals who draft and maintain internal policies. It appears in the context of policy lifecycle activities discussed in standards such as ISO/IEC 27001 and control families such as PM-1 and PL-1 in NIST SP 800-53. While 'policy author' is not always a formally defined job title, the function it describes is well recognized.
Does the policy author also approve the policy they write?
Typically not. In many governance frameworks the drafting and the approval of a policy are separated so that authority and accountability are distinguished from the act of writing. The policy author commonly prepares and maintains the document, while a designated owner, sponsor, or governing body approves it. This separation supports accountability and reduces the risk that a single individual both creates and authorizes an internal control instrument. Specific arrangements vary by organization, jurisdiction, and sector.
Who should be assigned as a policy author within an organization?
The role is commonly assigned to a subject-matter expert in the relevant domain, often working with governance, risk, or compliance functions to ensure alignment with the policy framework. In many organizations the author is drawn from the first line where the activity is performed, with review support from second-line functions. The precise assignment depends on the organization's size, structure, and how it allocates policy ownership.
How does the policy author fit within the three lines model?
Drafting and maintaining policies is generally a management activity rather than an assurance activity. Authors typically sit in the first or second line, depending on the policy's subject. Independent assurance functions, such as internal audit in the third line, do not usually author the policies they later evaluate, in order to preserve their independence and objectivity. Blurring these boundaries can compromise assurance.
How should policy authorship be documented for audit and review purposes?
Organizations commonly record the author, owner, approver, version history, and review dates as part of the policy document's metadata or a policy register. Maintaining a clear record of who drafted and revised each version supports traceability and periodic review. The level of formality varies with organizational maturity and applicable regulatory expectations.
How often should a policy author revisit and update a policy?
Policies are typically reviewed on a defined cycle, often annually or at another interval set by the policy framework, and additionally when triggered by changes in law, regulation, the risk environment, or business operations. The author usually initiates or supports these reviews, but approval of changes generally rests with the designated owner or governing body. Review frequency should reflect the policy's risk relevance and any applicable regulatory requirements.

Common misconceptions

The policy author is the same as the policy owner or approver.
These are commonly separated in policy-management practice. The author drafts and maintains content, while an accountable owner or governing body approves and sponsors the policy. Combining the roles can weaken accountability, though the exact split depends on organizational design.
Authoring a policy means the author is responsible for auditing or assuring compliance with it.
Drafting a policy is a management activity. Evaluating whether the policy is adhered to and effective is typically an assurance activity performed by an independent function, such as internal audit. Blending these compromises the independence and objectivity expected of assurance functions.
Frameworks prescribe a formal 'policy author' job title with defined duties.
Standards and frameworks such as ISO/IEC 27001 and NIST SP 800-53 expect policies to be established, documented, maintained, and reviewed, but they generally describe these outcomes and responsibilities rather than mandating a specific author role or title. How the role is named and scoped varies by organization.

Best practices

Keep the author role distinct from the approver or policy owner so that drafting and formal authorization are performed by different parties, supporting accountability.
Document the linkage between each policy provision and its driving source, such as an applicable law, regulation, standard, or risk decision, to enable traceability during review and audit.
Establish and follow a defined review cycle so that policies are updated when relevant laws, regulations, risks, or organizational structures change.
Coordinate with subject-matter experts and, where applicable, legal or regulatory specialists to confirm that policy content accurately reflects obligations for the relevant jurisdiction and sector.
Preserve the independence of assurance functions by ensuring the author does not also perform the independent evaluation of the policy's adherence or effectiveness.
Confirm how the framework relevant to your organization (for example ISO/IEC 27001 policy lifecycle guidance or NIST SP 800-53 policy controls) expects policies to be maintained, and map internal author responsibilities to those expected outcomes rather than assuming a universal role definition.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide