Company policies rot quietly. The security policy references a tool you retired; the data-retention policy predates the product feature it should constrain. Reviewing them is everyone's job and no one's, so updates happen in bulk panic before an audit or after an incident.
When updates do happen, the chain of custody is murky: a doc edited by several hands, approved in a meeting nobody minuted, published to a wiki without versions. For documents whose entire value is being authoritative, that's self-defeating.