Saga insight
A policy should change when the work changes
Keep policies connected to the rules, activities and approvals that give them meaning.

A file is not a control
A policy can look complete and still be out of step with daily work. The useful question is not only which version is newest. It is which requirement the policy addresses, which activities it covers and whether the people doing those activities know what changed.
Connect change to review
When a rule or business process changes, identify the affected sections. Assign someone to draft the update and someone with the right authority to approve it. Preserve the prior version, the source of the change and the decision. That makes the policy reviewable without turning every review into a document hunt.
Follow through in operations
A changed policy may also change a checklist, training instruction or recurring control. Track those follow-on actions and acknowledgements. The work is complete when people can use the new instruction and the organisation can show how it was introduced.
Try this now: Open one important policy. Can you see the requirement behind it, its owner, the last approved change and the operational checks it affects?