GAN Integrity Platform

Policy Management Software for the evidence your program stands on

Connect policy to procedure for easy employee adoption. Connect procedure to proof for everyone else.

Request a demo
PolicyMgmt_Hero

Customer outcomes

Results from organizations around the globe

90%
employee disclosure rate. Up from under 40% a year earlier.
Global defense manufacturer
80%
of prior years' employee disclosures recorded on day 1 of go-live
Global payments technology organization
1 Hour
to review employee disclosures vs. days with prior solution.
US-based energy company

Every policy, its owner, and every version it has ever had

One library with the current version live, the history behind it, and a named owner for each one.

  • Scheduled review cycles that prompt the owner before a policy goes out of date
  • Every version retained with its effective dates, so you can show which rule applied when
  • Distribution to the people a policy covers, with a record of who has received it
PolicyMgmt_Centralized Policies

Employees see the policies that apply to them

Targeted distribution and search, so nobody reads a 90-page handbook to find one rule.

  • Campaigns that reach the roles, regions, or entities a policy covers, not the whole company
  • Attestation recorded per person per version
  • Available in 50+ languages
PolicyMgmt_Employee usage

Know whether your policies reached the people they govern

Attestation progress by policy, region, and business unit, plus the compliance activity happening around each policy area.

  • See which policies have low attestation and where, so you can act before the audit does
  • Track where gift, conflict, and incident volume clusters against a policy area
  • Build the board view yourself
PolicyMgmt_Reporting

“The platform allowed us to build in the detailed steps, approvals, and tracking necessary for a transparent and accountable process.”

Kristy Shires Group Compliance Director, Spectris

Resources

Policy Management resources for compliance teams managing high-risk interactions

Res_600x406_ebk_Disclosures-Reporting
Guide

How Unified Policy and Disclosure Management Drives Ethical Culture

WBN_Res_PolicyMgmt_Watch (1)
Webinar

Policy Management: Considerations, Outcomes and Technology Choices

Frequently Asked Questions

What is policy management?
Policy management is the process organizations use to create, review, approve, distribute, and track compliance with internal policies, such as a code of conduct, anti-bribery policy, or data privacy policy. It covers the full lifecycle of a policy: drafting and version control, stakeholder review and approval, employee distribution and acknowledgment, and ongoing updates as regulations or business operations change.
Why do companies need policy management tools?
Companies need policy management software because manually tracking policies at scale creates compliance gaps and legal exposure. Without a centralized system, organizations can't reliably prove which policy version was in effect at a given time, who approved it, or which employees acknowledged it — information regulators and investigators routinely request during audits or enforcement actions. Policy management software closes these gaps by automating version control, distribution, and acknowledgment tracking in one auditable system.
How is policy management software better than share drives and emails?
A shared drive can store a policy, but it can't prove anything about it. If a regulator or investigator asks which version of your code of conduct was in effect on a specific date, who approved it, and who acknowledged it, a folder of Word docs won't answer that. There's no audit trail, no version control, and no way to confirm an employee actually saw the current policy instead of an outdated one still floating around in their inbox. Most compliance teams hit a breaking point once they're managing policies across multiple business units, languages, or regulations.
How do you keep hundreds of policies straight across regions, languages, and business units?
This is where manual tracking falls apart fastest. Without version control in one place, it is common for an employee in one region to be acknowledging a translated policy that is two revisions behind the original, while a business unit somewhere else applies a local variation nobody upstream knows exists. The problem compounds when jurisdictions require different things of the same policy, and when approval has to run through multiple subsidiaries before anything can be published.
A policy management system handles this by keeping one master policy with every translation, localization, and revision tied back to it. When the master changes, you can see which versions are live, which are retired, which regions have been notified, and who still has an outdated copy in front of them. Most compliance teams hit the breaking point at exactly this scale, when policies multiply across languages and entities faster than anyone can reconcile by hand.
What is the difference between policy management and document management?
Document management stores and organizes files. Policy management does that plus the compliance-specific functions document management systems don't handle: routing policies through approval workflows, targeting distribution to specific employees by role or region, tracking acknowledgment and attestation, and maintaining an audit trail that ties each policy version to who saw it, when, and whether they accepted it. A generic document management system can hold a PDF of a policy; it can't tell you if the right people read and understood it.
How do you know whether a policy is working?
Acknowledgment rates tell you it was delivered, not that it changed anything. What tells you more is what happens in the programs the policy governs: whether disclosures cluster in one business unit, whether gift requests keep arriving above the threshold, whether the same policy area keeps generating cases.
What is attestation, and how is it different from acknowledgment?
Acknowledgment records that an employee received a policy and confirmed they saw it. Attestation records that they affirmed something about their own conduct against it — that they have read and will comply, that they have no conflict to declare, that they have not offered anything of value to a public official. The first evidences distribution. The second is a statement by the employee that can be relied on later, which is why attestations are tied to a specific policy version and retained with it.

See GAN Integrity in action

Request a demonstration built around your compliance program.