
Stage 5 · Govern & Assure
Close the loop: controls, audits, ESG reporting and benchmarking against competitors.
GRC Audit Defensibility
Phase 4 — closes the ServiceNow/Archer gap (policy lifecycle, third-party risk, auditor portal, regulatory horizon).
Published
2
Awaiting attestation
1
Expiring (60d)
1
Avg attestation %
58%
| ID | Title | Owner | Ver | Status | Attestation | Expires | |
|---|---|---|---|---|---|---|---|
| POL-001 | Information Security Policy | CISO | v3.2 | Published | 142/156 | 2027-01-15 | |
| POL-002 | Anti-Bribery & Corruption | Legal | v2.1 | Attesting | 89/156 | 2026-11-30 | |
| POL-003 | Site Safety Code (ISO 45001) | HSE | v4.0 | Published | 156/156 | 2027-04-01 | |
| POL-004 | Modern Slavery Statement | Legal | v1.3 | In Review | 0/156 | — | |
| POL-005 | Data Retention & Privacy (GDPR) | DPO | v2.0 | Expiring | 156/156 | 2026-06-12 | |
| POL-006 | Sustainable Procurement (ISO 20400) | Procurement | v1.0 | Draft | 0/156 | — |
Lifecycle: Draft → In Review → Published → Attesting → Expiring → Retired. Each transition writes to immutable audit log. Workers receive in-app + email attestation requests; signature is stored against user + timestamp + policy version hash.