we have a number of policies (ie - lending, wire) that require annual ratification by the Board, even if there are no changes. 3 months prior to the December BOD meeting, the BOD secretary notifies each of those areas asking if there are changes to policy.
other policies are changed as circumstances dictate (ie - disaster recovery, social media).
procedures are housed within LOBs, managers/line staff are responsible for updating as needed and, depending on the area, reviews may need to be done by areas such as internal audit, enterprise risk, and compliance.
Policy never includes procedures, but procedures frequently quote policy.
Providing alternative truths since the invention of time