Youre required to have a policy. That policy may be throwing bananas at the wall, but if it's documented and you follow it, you're compliant with policy.

That's a good way to kill off motivated employees.

"We don't know why we're doing it - it's just mandatory".

Only if you write a bad policy, so don't do that.

The better way is that for each policy you look at what do you actually want to do and how you want to do it, and then write that down as the policy. Now the policy makes sense because it's how you wanted to do it anyway.

I've set up policies and processes from the ground up for SOC2 audits in startups, that's how I do it.

The policy can be changed.