*the risk assessment shall contain the objectives /targets which consistency with policy & legal /statuary/ regularity requirements , i.e : European directives /DOT, the mandatory of CE--NB # ---etc. & other product mandatory STDs should be part of organization regularity ; ---
*the manufacture / commercial license could be against national/legal regulation ;it's a requirement because it's part of management system , it should be under controls for continuing valid; the old or obsolete license as any sanction / legal deviation could close the organization activity “ i.e : OSHA Reg. , -the black list of importers , ---etc. “
*the policies could be short & simple to be easy for understanding by all stakeholders / interested parties ; the important high weight of the interested parties in any organization are the employees &the workers, there’s no needs for detailed obligatory requirements in published policy , the risk assessment determination could indicate the detailed requirements & the essential controls ;
* the policy may have 4 pages or more because it could be integrated in the company & covering many managements STDs ; the point is : when I publish the policy to one of interested party ‘ I can issue the relevant statements only , as example : I can summarize many social issues when I issue the policy to product notified body , otherwise I shall keep the detailed social issues when the policies are issued to international companies which is interest of social core subjects & other global & climate changes issues .